All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 7.1 0000/2077] 7.1.5-rc1 review
@ 2026-07-21 14:54 Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0001/2077] crypto: algif_skcipher - force synchronous processing Greg Kroah-Hartman
                   ` (997 more replies)
  0 siblings, 998 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, linux-kernel, torvalds, akpm, linux,
	shuah, patches, lkft-triage, pavel, jonathanh, f.fainelli,
	sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr

This is the start of the stable review cycle for the 7.1.5 release.
There are 2077 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Thu, 23 Jul 2026 15:23:00 +0000.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.1.5-rc1.gz
or in the git tree and branch at:
	git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.1.y
and the diffstat can be found below.

thanks,

greg k-h

-------------
Pseudo-Shortlog of commits:

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Linux 7.1.5-rc1

Thomas Gleixner <tglx@kernel.org>
    posix-cpu-timers: Prevent UAF caused by non-leader exec() race

Thomas Gleixner <tglx@kernel.org>
    posix-timers: Expand timer_[re]arm() callbacks with a boolean return value

Dillon Varone <Dillon.Varone@amd.com>
    drm/amd/display: Fix Color Manager (3DLUT, Shaper, Blend)

Christoph Hellwig <hch@lst.de>
    iomap: consolidate bio submission

Namjae Jeon <linkinjeon@kernel.org>
    exfat: fix implicit declaration of brelse()

Namjae Jeon <linkinjeon@kernel.org>
    exfat: add data_start_bytes and exfat_cluster_to_phys_bytes() helper

Namjae Jeon <linkinjeon@kernel.org>
    exfat: add balloc parameter to exfat_map_cluster() for iomap support

Namjae Jeon <linkinjeon@kernel.org>
    exfat: replace unsafe macros with static inline functions

Eric Biggers <ebiggers@kernel.org>
    crypto: xilinx-trng - Remove crypto_rng interface

Pratyush Yadav (Google) <pratyush@kernel.org>
    liveupdate: validate session type before performing operation

Mauricio Faria de Oliveira <mfo@igalia.com>
    usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()

Mauricio Faria de Oliveira <mfo@igalia.com>
    usb: atm: ueagle-atm: remove function entry/exit debug messages

Mauricio Faria de Oliveira <mfo@igalia.com>
    usb: atm: ueagle-atm: use dev_dbg() for 'device found' message

Christoph Hellwig <hch@lst.de>
    xfs: add newly added RTGs to the free pool in growfs

Christoph Hellwig <hch@lst.de>
    xfs: factor out a xfs_zone_mark_free helper

Namjae Jeon <linkinjeon@kernel.org>
    ksmbd: use opener credentials for FSCTL mutations

ChenXiaoSong <chenxiaosong@kylinos.cn>
    smb: move compression definitions into common/fscc.h

Davide Ornaghi <d.ornaghi97@gmail.com>
    ksmbd: fix path resolution in ksmbd_vfs_kern_path_create

Siwei Zhang <oss@fourdim.xyz>
    Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()

Pauli Virtanen <pav@iki.fi>
    Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister

Chris Mason <clm@meta.com>
    binder: cache secctx size before release zeroes it

Jisheng Zhang <jszhang@kernel.org>
    binder: Use LIST_HEAD() to initialize on stack list head

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ALSA: hda/tas2781: Cancel async firmware request at unbind

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    firmware_loader: Add cancel helper for async requests

Geoffrey D. Bennett <g@b4.vu>
    ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417

Geoffrey D. Bennett <g@b4.vu>
    ALSA: scarlett2: Allow selecting config_set by firmware version

Zhang Lixu <lixu.zhang@intel.com>
    iio: hid-sensor-rotation: Fix stale or zero output when reading raw values

Keshav Verma <iganschel@gmail.com>
    f2fs: fix listxattr handling of corrupted xattr entries

Chao Yu <chao@kernel.org>
    f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()

Ruipeng Qi <ruipengqi3@gmail.com>
    f2fs: fix potential deadlock in f2fs_balance_fs()

Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
    device property: initialize the remaining fields of fwnode_handle in fwnode_init()

Zenghui Yu <yuzenghui@huawei.com>
    samples/damon/mtier: fail early if address range parameters are invalid

SeongJae Park <sj@kernel.org>
    mm/damon/core: trace esz at first setup

Sun Jian <sun.jian.kdev@gmail.com>
    bpf: Reject negative const offsets for buffer pointers

Luke Wang <ziniu.wang_1@nxp.com>
    mmc: sdhci-esdhc-imx: fix resume error handling

Luke Wang <ziniu.wang_1@nxp.com>
    mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend

Luke Wang <ziniu.wang_1@nxp.com>
    mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend

Luke Wang <ziniu.wang_1@nxp.com>
    mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt

Luke Wang <ziniu.wang_1@nxp.com>
    mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore

Luke Wang <ziniu.wang_1@nxp.com>
    mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume

Luke Wang <ziniu.wang_1@nxp.com>
    mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore

Sergey Shtylyov <s.shtylyov@auroraos.dev>
    mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method

Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
    mmc: mmc_test: Fix __counted_by handling after kzalloc_flex() conversion

Ao Sun <ao.sun@transsion.com>
    mmc: block: fix RPMB device unregister ordering

Pengpeng Hou <pengpeng@iscas.ac.cn>
    mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout

Pengpeng Hou <pengpeng@iscas.ac.cn>
    mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout

Pengpeng Hou <pengpeng@iscas.ac.cn>
    mtd: rawnand: fsl_ifc: return errors for failed page reads

Runyu Xiao <runyu.xiao@seu.edu.cn>
    mmc: vub300: defer reset until cmd_mutex is unlocked

Pengpeng Hou <pengpeng@iscas.ac.cn>
    mtd: mchp23k256: use SPI match data for chip caps

Pengpeng Hou <pengpeng@iscas.ac.cn>
    mtd: onenand: samsung: report DMA completion timeouts

Xu Rao <raoxu@uniontech.com>
    mtd: virt-concat: free duplicate generated name

Rafael Beims <rafael.beims@toradex.com>
    wifi: mwifiex: fix permanently busy scans after multiple roam iterations

Zhao Li <enderaoelyther@gmail.com>
    wifi: mac80211: validate extension-frame layout before RX

Zhiling Zou <roxy520tt@gmail.com>
    wifi: mac80211: free ack status frame on TX header build failure

Zhao Li <enderaoelyther@gmail.com>
    wifi: ieee80211: validate MLE common info length

Haofeng Li <lihaofeng@kylinos.cn>
    wifi: cfg80211: validate EHT MLE before MLD ID read

Ethan Nelson-Moore <enelsonmoore@gmail.com>
    powerpc/uaccess: correct check for CONFIG_PPC_E500 in mask_user_address()

Junrui Luo <moonafterrain@outlook.com>
    powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()

Zhao Dongdong <zhaodongdong@kylinos.cn>
    reset: sunxi: fix memory region leak on ioremap failure

Robby Cai <robby.cai@nxp.com>
    reset: imx7: Correct polarity of MIPI CSI resets on i.MX8MQ

Florian Westphal <fw@strlen.de>
    ipvs: reload ip header after head reallocation

Julian Anastasov <ja@ssi.bg>
    ipvs: fix more places with wrong ipv6 transport offsets

Maoyi Xie <maoyixie.tju@gmail.com>
    memstick: ms_block: reject a card that reports too many blocks

James Raphael Tiovalen <jamestiotio@gmail.com>
    macsec: fix promiscuity refcount leak in macsec_dev_open()

Xuanqiang Luo <luoxuanqiang@kylinos.cn>
    llc: fix SAP refcount leak when creating incoming sockets

Eric Biggers <ebiggers@kernel.org>
    crypto: aes - Fix conditions for selecting MAC dependencies

Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
    Bluetooth: btrtl: validate firmware patch bounds

Asim Viladi Oglu Manizada <manizada@pm.me>
    net: openvswitch: reject oversized nested action attrs

Abhishek Ojha <Abhishek.ojha@savoirfairelinux.com>
    regulator: ltc3676: Fix incorrect IRQSTAT bit offsets

Aurelien Jarno <aurelien@aurel32.net>
    arch/riscv: vdso: remove CFI landing pad from rt_sigreturn

Thomas Weißschuh <thomas.weissschuh@linutronix.de>
    riscv: vdso: Do not use LTO for the vDSO

Maoyi Xie <maoyixie.tju@gmail.com>
    wifi: brcmfmac: cyw: fix heap overflow on a short auth frame

Dawei Feng <dawei.feng@seu.edu.cn>
    wifi: mac80211: fix memory leak in ieee80211_register_hw()

Rafael Beims <rafael.beims@toradex.com>
    wifi: mwifiex: fix roaming to different channel in host_mlme mode

Runyu Xiao <runyu.xiao@seu.edu.cn>
    wifi: rt2x00: avoid full teardown before work setup in probe

Zhiping Zhang <zhipingz@meta.com>
    net/mlx5: free mlx5_st_idx_data on final dealloc

Thorsten Blum <thorsten.blum@linux.dev>
    powerpc/pseries: fix memory leak on krealloc failure in papr_init

Luke Wang <ziniu.wang_1@nxp.com>
    mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume

Thomas Huth <thuth@redhat.com>
    selftests/landlock: Fix screwed up pointers in the scoped_signal_test

Thomas Huth <thuth@redhat.com>
    selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available

Peng Fan <peng.fan@nxp.com>
    pmdomain: imx: Fix i.MX8MP VC8000E power up sequence

Peng Fan <peng.fan@nxp.com>
    pmdomain: imx: Fix i.MX8MP power notifier

AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
    pmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check

Guoniu Zhou <guoniu.zhou@oss.nxp.com>
    pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI

Farhad Alemi <farhad.alemi@berkeley.edu>
    cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed

Hui Wang <hui.wang@canonical.com>
    selftests/rseq: Fix a building error for riscv arch

Gerald Schaefer <gerald.schaefer@linux.ibm.com>
    s390/mm: Fix type mismatch in get_align_mask().

Heiko Carstens <hca@linux.ibm.com>
    s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()

Crystal Wood <crwood@redhat.com>
    tracing/osnoise: Call synchronize_rcu() when unregistering

Tao Liu <ltao@redhat.com>
    riscv: Prevent NULL pointer dereference in machine_kexec_prepare()

Michael Bommarito <michael.bommarito@gmail.com>
    drbd: reject data replies with an out-of-range payload size

TJ Adams <tadamsjr@google.com>
    ata: libata-core: Allow capacity transition to zero for locked drives

TJ Adams <tadamsjr@google.com>
    ata: libata-core: Skip HPA resize for locked drives

Reinette Chatre <reinette.chatre@intel.com>
    fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list

Tony Luck <tony.luck@intel.com>
    fs/resctrl: Free mon_data structures on rdt_get_tree() failure

Jinjie Ruan <ruanjinjie@huawei.com>
    cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()

Jinjie Ruan <ruanjinjie@huawei.com>
    arm64: smp: Fix hot-unplug tearing by forcing unregistration

Zhu Lingshan <lingshan.zhu@amd.com>
    amdkfd: properly free secondary context id

Théo Lebrun <theo.lebrun@bootlin.com>
    net: macb: drop in-flight Tx SKBs on close

Dust Li <dust.li@linux.alibaba.com>
    dibs: loopback: validate offset and size in move_data()

Daehyeon Ko <4ncienth@gmail.com>
    macsec: don't read an unset MAC header in macsec_encrypt()

Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
    ipvs: reset full ip_vs_seq structs in ip_vs_conn_new

Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
    ipvs: use parsed transport offset in SCTP state lookup

Shuangpeng Bai <shuangpeng.kernel@gmail.com>
    llc: fix SAP refcount leak in llc_ui_autobind()

Nirmoy Das <nirmoyd@nvidia.com>
    selftests: net: make busywait timeout clock portable

Dawei Feng <dawei.feng@seu.edu.cn>
    octeontx2-pf: fix SQB pointer leak on init failure

Yousef Alhouseen <alhouseenyousef@gmail.com>
    mac802154: remove interfaces with RCU list deletion

Gerald Schaefer <gerald.schaefer@linux.ibm.com>
    s390/monwriter: Reject buffer reuse with different data length

Haoxiang Li <haoxiang_li2024@163.com>
    irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure

Zi Yan <ziy@nvidia.com>
    mm/compaction: handle free_pages_prepare() properly in compaction_free()

Martin Kaiser <martin@kaiser.cx>
    riscv: probes: save original sp in rethook trampoline

HyeongJun An <sammiee5311@gmail.com>
    hwmon: (asus_atk0110) Check package count before accessing element

Haoxiang Li <haoxiang_li2024@163.com>
    net: ipa: fix SMEM state handle leaks in SMP2P init

Maoyi Xie <maoyixie.tju@gmail.com>
    net: wwan: iosm: bound device offsets in the MUX downlink decoder

Bryam Vargas <hexlabsecurity@proton.me>
    ata: libata-core: Reject an invalid concurrent positioning ranges count

Wentao Liang <vulab@iscas.ac.cn>
    ata: pata_pxa: Fix DMA channel leak on probe error

Bryam Vargas <hexlabsecurity@proton.me>
    ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD

Dawei Feng <dawei.feng@seu.edu.cn>
    net/mlx5: HWS, fix matcher leak on resize target setup failure

Bryam Vargas <hexlabsecurity@proton.me>
    orangefs: keep the readdir entry size 64-bit in fill_from_part()

Masami Hiramatsu (Google) <mhiramat@kernel.org>
    tracing/probes: Fix double addition of offset for @+FOFFSET

Joshua Crofts <joshua.crofts1@gmail.com>
    hwmon: (max1619) add missing 'select REGMAP' to Kconfig

David Lee <david.lee@trailofbits.com>
    fhandle: reject detached mounts in capable_wrt_mount()

Bryam Vargas <hexlabsecurity@proton.me>
    net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked

Bryam Vargas <hexlabsecurity@proton.me>
    net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked

Andrea Righi <arighi@nvidia.com>
    net: lan743x: Initialize eth_syslock spinlock before use

Haoxiang Li <haoxiang_li2024@163.com>
    fsl/fman: Free init resources on KeyGen failure in fman_init()

Runyu Xiao <runyu.xiao@seu.edu.cn>
    hwmon: (occ) unregister sysfs devices outside occ lock

Xu Rao <raoxu@uniontech.com>
    ACPI: TAD: Check AC wake capability before enabling wakeup

Haoxiang Li <haoxiang_li2024@163.com>
    net: liquidio: fix BAR resource leak on PF number failure

Pengpeng Hou <pengpeng@iscas.ac.cn>
    hwmon: (w83793) remove vrm sysfs file on probe failure

Pengpeng Hou <pengpeng@iscas.ac.cn>
    hwmon: (w83627hf) remove VID sysfs files on error and remove

Conor Dooley <conor.dooley@microchip.com>
    rtc: mpfs: fix counter upload completion condition

Eric Biggers <ebiggers@kernel.org>
    fscrypt: Replace mk_users keyring with simple list

Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
    rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()

Wentao Liang <vulab@iscas.ac.cn>
    ipmi: fix refcount leak in i_ipmi_request()

Sabrina Dubroca <sd@queasysnail.net>
    espintcp: use sk_msg_free_partial to fix partial send

Matt Fleming <mfleming@cloudflare.com>
    ipmi: Fix user refcount underflow in event delivery

Hongchen Zhang <zhanghongchen@loongson.cn>
    LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()

Xuewen Wang <wangxuewen@kylinos.cn>
    LoongArch: Fix nr passing in set_direct_map_valid_noflush()

Biju Das <biju.das.jz@bp.renesas.com>
    pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64

Thomas Weißschuh <thomas.weissschuh@linutronix.de>
    riscv: vdso: Always declare vdso_start symbols

Marc Zyngier <maz@kernel.org>
    KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms()

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nfnetlink_cthelper: cap to maximum number of expectation per master on updates

Shuicheng Lin <shuicheng.lin@intel.com>
    drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    ACPICA: Define acpi_ut_safe_strncpy() as strscpy_pad() alias

Jamal Hadi Salim <jhs@mojatatu.com>
    net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants

Daniel Gibson <daniel@gibson.sh>
    platform/x86/amd/pmc: Avoid logging "(null)" for DMI values

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nfnetlink_cthelper: cap to maximum number of expectation per master

Gil Portnoy <dddhkts1@gmail.com>
    ksmbd: fix stack buffer overflow in multichannel session-key copy

Junrui Luo <moonafterrain@outlook.com>
    octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF

Ankit Garg <nktgrg@google.com>
    gve: fix header buffer corruption with header-split and HW-GRO

Shitalkumar Gandhi <shital.gandhi45@gmail.com>
    ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit

Shitalkumar Gandhi <shital.gandhi45@gmail.com>
    ieee802154: ca8210: fix cas_ctl leak on spi_async failure

Michael Bommarito <michael.bommarito@gmail.com>
    ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation

Michael Bommarito <michael.bommarito@gmail.com>
    ieee802154: admin-gate legacy LLSEC dump operations

Haoxiang Li <haoxiang_li2024@163.com>
    octeontx2-af: Free BPID bitmap on setup failure

Maoyi Xie <maoyixie.tju@gmail.com>
    net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink

Maoyi Xie <maoyixie.tju@gmail.com>
    net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink

Maoyi Xie <maoyixie.tju@gmail.com>
    net: ipip: require CAP_NET_ADMIN in the device netns for changelink

Maoyi Xie <maoyixie.tju@gmail.com>
    net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink

Maoyi Xie <maoyixie.tju@gmail.com>
    net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink

Dawei Feng <dawei.feng@seu.edu.cn>
    net: ena: clean up XDP TX queues when regular TX setup fails

Ross Porter <ross.porter@canonical.com>
    selftests: net: fix file owner for broadcast_ether_dst test

Zihan Xi <xizh2024@lzu.edu.cn>
    net/sched: act_ct: preserve tc_skb_cb across defragmentation

Haoxiang Li <haoxiang_li2024@163.com>
    net: ixp4xx_hss: fix duplicate HDLC netdev allocation

Haoxiang Li <haoxiang_li2024@163.com>
    net: wwan: t7xx: destroy DMA pool on CLDMA late init failure

Philippe Schenker <philippe.schenker@impulsing.ch>
    net: ethernet: ti: icssg: guard PA stat lookups

Maoyi Xie <maoyixie.tju@gmail.com>
    net: sit: require CAP_NET_ADMIN in the device netns for changelink

Andreas Kemnade <andreas@kemnade.info>
    gpios: palmas: add .get_direction() op

Sergio Paracuellos <sergio.paracuellos@gmail.com>
    gpio: mt7621: avoid corruption of shared interrupt trigger state

Paul Louvel <paul.louvel@bootlin.com>
    gpio-f7188x: Add support for NCT6126D version B

Sergio Paracuellos <sergio.paracuellos@gmail.com>
    gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips

Runyu Xiao <runyu.xiao@seu.edu.cn>
    gpio: tegra: do not call pinctrl for GPIO direction

Sergio Paracuellos <sergio.paracuellos@gmail.com>
    gpio: mt7621: more robust management of IRQ domain teardown

Dexuan Cui <decui@microsoft.com>
    net: mana: Sync page pool RX frags for CPU

Dexuan Cui <decui@microsoft.com>
    net: mana: Validate the packet length reported by the NIC

Bradley Morgan <include@grrlz.net>
    cpu: hotplug: Bound hotplug states sysfs output

Bradley Morgan <include@grrlz.net>
    cpu: hotplug: Preserve per instance callback errors

Cao Ruichuang <create0818@163.com>
    selftests/ftrace: Drop invalid top-level local in test_ownership

Zhan Xusheng <zhanxusheng1024@gmail.com>
    posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()

Thomas Gleixner <tglx@kernel.org>
    locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()

Maoyi Xie <maoyixie.tju@gmail.com>
    wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()

Michael Bommarito <michael.bommarito@gmail.com>
    tracing/user_events: Fix use-after-free in user_event_mm_dup()

Doruk Tan Ozturk <doruk@0sec.ai>
    net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete

Guangshuo Li <lgs201920130244@gmail.com>
    mmc: vub300: fix use-after-free on probe failure

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - fix type confusion in CDC union descriptor parsing

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - fix race condition in reset_device sysfs callback

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - fix logic error in packet reset

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - fix firmware leak in async update

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - fix DMA mapping violation in line setup

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - add response length checks

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - validate control endpoint type

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - release data interface on disconnect

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - only expose sysfs attributes on control interface

Dmitry Torokhov <dmitry.torokhov@gmail.com>
    Input: ims-pcu - fix use-after-free and double-free in disconnect

Tony Luck <tony.luck@intel.com>
    fs/resctrl: Fix use-after-free during unmount

Haoxiang Li <haoxiang_li2024@163.com>
    scsi: elx: efct: Fix I/O leak on unsupported additional CDB

WenTao Liang <vulab@iscas.ac.cn>
    scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()

Bryam Vargas <hexlabsecurity@proton.me>
    scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE

Bryam Vargas <hexlabsecurity@proton.me>
    scsi: target: Bound PR-OUT TransportID parsing to the received buffer

Michael Bommarito <michael.bommarito@gmail.com>
    scsi: xen: scsiback: Free unsubmitted command instead of double-putting it

Michael Bommarito <michael.bommarito@gmail.com>
    scsi: xen: scsiback: Free the command tag on the TMR submit-failure path

Xu Rao <raoxu@uniontech.com>
    scsi: sg: Report request-table problems when any status is set

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()

Haoxiang Li <haoxiang_li2024@163.com>
    scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path

Jhonraushan <raushan.jhon@gmail.com>
    accel/ivpu: Reject firmware log with size smaller than header

Shuvam Pandey <shuvampandey1@gmail.com>
    accel/amdxdna: Use caller client for debug BO sync

Doruk Tan Ozturk <doruk@0sec.ai>
    accel/amdxdna: reject user command submission without a command BO

Doruk Tan Ozturk <doruk@0sec.ai>
    accel/amdxdna: reject command submission on devices without a submit op

Wentao Liang <vulab@iscas.ac.cn>
    accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()

Philipp Stanner <phasta@kernel.org>
    dma-buf: dma-fence: Fix potential NULL pointer dereference

André Draszik <andre.draszik@linaro.org>
    dma-fence: use correct callback in dma_fence_timeline_name()

Baineng Shou <shoubaineng@gmail.com>
    dma-fence: Make dma_fence_dedup_array() robust against 0-count input

Mikulas Patocka <mpatocka@redhat.com>
    dm-verity: make error counter atomic

Mikulas Patocka <mpatocka@redhat.com>
    dm-verity: increase sprintf buffer size

Mikulas Patocka <mpatocka@redhat.com>
    dm-verity: fix a possible NULL pointer dereference

Mikulas Patocka <mpatocka@redhat.com>
    dm-verity: avoid double increment of &use_bh_wq_enabled

Mikulas Patocka <mpatocka@redhat.com>
    dm-verity: fix buffer overflow in FEC calculation

Mikulas Patocka <mpatocka@redhat.com>
    dm-integrity: don't increment hash_offset twice

Mikulas Patocka <mpatocka@redhat.com>
    dm-integrity: fix a bug if the bio is out of limits

Mikulas Patocka <mpatocka@redhat.com>
    dm-integrity: fix leaking uninitialized kernel memory

Mikulas Patocka <mpatocka@redhat.com>
    dm_early_create: fix freeing used table on dm_resume failure

Ingo Blechschmidt <iblech@speicherleck.de>
    dm: avoid leaking the caller's thread keyring via the table device file

Mikulas Patocka <mpatocka@redhat.com>
    dm-stats: fix merge accounting

Mikulas Patocka <mpatocka@redhat.com>
    dm-stats: fix dm_jiffies_to_msec64

Samuel Moelius <sam.moelius@trailofbits.com>
    dm-pcache: reject option groups without values

Benjamin Marzinski <bmarzins@redhat.com>
    dm-log: fix a bitset_size overflow on 32bit machines

Mikulas Patocka <mpatocka@redhat.com>
    dm-ioctl: fix a possible overflow in list_version_get_info

Mikulas Patocka <mpatocka@redhat.com>
    dm-bufio: fix wrong count calculation in dm_bufio_issue_discard

Samuel Moelius <sam.moelius@trailofbits.com>
    dm era: fix out-of-bounds memory access for non-zero start sector

Ming-Hung Tsai <mtsai@redhat.com>
    dm thin metadata: fix metadata snapshot consistency on commit failure

Genjian Zhang <zhanggenjian@kylinos.cn>
    dm thin metadata: fix superblock refcount leak on snapshot shadow failure

Haoxiang Li <haoxiang_li2024@163.com>
    net: sparx5: unregister blocking notifier on init failure

Yitang Yang <yi1tang.yang@gmail.com>
    block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd

Mike Waychison <mike@waychison.com>
    block: fix race in blk_time_get_ns() returning 0

Connor Williamson <connordw@amazon.com>
    block: remove redundant GD_NEED_PART_SCAN in add_disk_final()

Sun Jian <sun.jian.kdev@gmail.com>
    selftests/bpf: Cover negative buffer pointer offsets

Jiri Olsa <jolsa@kernel.org>
    bpf: Add missing access_ok call to copy_user_syms

Jann Horn <jannh@google.com>
    bpf,fork: wipe ->bpf_storage before bailouts that access it

Tristan Madani <tristan@talencesecurity.com>
    bpf: Reset register bounds before narrowing retval range in check_mem_access()

Woraphat Khiaodaeng <worapat.kd2@gmail.com>
    io_uring/bpf-ops: reject re-registration of an already-bound ops

Oliver Hartkopp <socketcan@hartkopp.net>
    can: bcm: add missing device refcount for CAN filter removal

Oliver Hartkopp <socketcan@hartkopp.net>
    can: bcm: validate frame length in bcm_rx_setup() for RTR replies

Oliver Hartkopp <socketcan@hartkopp.net>
    can: bcm: track a single source interface for ANYDEV timeout/throttle ops

Oliver Hartkopp <socketcan@hartkopp.net>
    can: bcm: fix stale rx/tx ops after device removal

Oliver Hartkopp <socketcan@hartkopp.net>
    can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()

Oliver Hartkopp <socketcan@hartkopp.net>
    can: bcm: fix CAN frame rx/tx statistics

Oliver Hartkopp <socketcan@hartkopp.net>
    can: bcm: extend bcm_tx_lock usage for data and timer updates

Oliver Hartkopp <socketcan@hartkopp.net>
    can: bcm: add missing rcu list annotations and operations

Oliver Hartkopp <socketcan@hartkopp.net>
    can: bcm: add locking when updating filter and timer values

Oliver Hartkopp <socketcan@hartkopp.net>
    can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure

Lee Jones <lee@kernel.org>
    can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF

Oliver Hartkopp <socketcan@hartkopp.net>
    can: isotp: serialize TX state transitions under so->rx_lock

Oliver Hartkopp <socketcan@hartkopp.net>
    can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER

Oliver Hartkopp <socketcan@hartkopp.net>
    can: isotp: use unconditional synchronize_rcu() in isotp_release()

Fan Wu <fanwu01@zju.edu.cn>
    can: esd_usb: kill anchored URBs before freeing netdevs

Souvik Banerjee <souvik@amlalabs.com>
    ovl: use linked upper dentry in copy-up tmpfile

Maoyi Xie <maoyixie.tju@gmail.com>
    netdev-genl: report NAPI thread PID in the caller's pid namespace

Wentao Liang <vulab@iscas.ac.cn>
    nvmet: fix refcount leak in nvmet_sq_create()

Bryam Vargas <hexlabsecurity@proton.me>
    nvmet-rdma: handle inline data with a nonzero offset

Michael Bommarito <michael.bommarito@gmail.com>
    nvmet-auth: reject short AUTH_RECEIVE buffers

Nick Chan <towinchenmi@gmail.com>
    nvme-apple: Prevent shared tags across queues on Apple A11

Benjamin Coddington <ben.coddington@hammerspace.com>
    NFS: Charge unstable writes by request size, not folio size

Weiming Shi <bestswngs@gmail.com>
    sctp: validate STALE_COOKIE cause length before reading staleness

Kunihiko Hayashi <hayashi.kunihiko@socionext.com>
    spi: uniphier: Fix completion initialization order before devm_request_irq()

Javier Fernandez Pastrana <javier.pastrana@linutronix.de>
    spi: imx: reconfigure for PIO when DMA cannot be started

Wang Yan <wangyan01@kylinos.cn>
    time: Fix off-by-one in compat settimeofday() usec validation

Jaewon Yang <yong010301@gmail.com>
    tpm: Make the TPM character devices non-seekable

Thorsten Blum <thorsten.blum@linux.dev>
    tpm: fix event_size output in tpm1_binary_bios_measurements_show

Maoyi Xie <maoyixie.tju@gmail.com>
    xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink

Sanman Pradhan <psanman@juniper.net>
    xfrm: use compat translator only for u64 alignment mismatch

Qianyu Luo <qianyuluo3@gmail.com>
    xfrm: nat_keepalive: avoid double free on send error

Wentao Liang <vulab@iscas.ac.cn>
    xen/gntdev: fix error handling in ioctl

Steven Rostedt <rostedt@goodmis.org>
    ufs: core: tracing: Do not dereference pointers in TP_printk()

Dmitry Safonov <0x7f454c46@gmail.com>
    tcp: Decrement tcp_md5_needed static branch

Michael Bommarito <michael.bommarito@gmail.com>
    tcp: defer md5sig_info kfree past RCU grace period in tcp_connect

Paul Greenwalt <paul.greenwalt@intel.com>
    ice: fix ice_init_link() error return preventing probe

Pei Xiao <xiaopei01@kylinos.cn>
    i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED

Xuanqiang Luo <luoxuanqiang@kylinos.cn>
    i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()

Roman Vivchar <rva333@protonmail.com>
    i2c: mediatek: fix WRRD for SoCs without auto_restart option

Vincent Jardin <vjardin@free.fr>
    i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)

Vincent Jardin <vjardin@free.fr>
    i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)

Joshua Crofts <joshua.crofts1@gmail.com>
    hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig

Joshua Crofts <joshua.crofts1@gmail.com>
    hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig

Ibrahim Hashimov <security@auditcode.ai>
    ksmbd: fix integer overflow in set_file_allocation_info()

Fredric Cover <fredric.cover.lkernel@gmail.com>
    smb: client: use kvzalloc() for megabyte buffer in simple fallocate

Holger Dengler <dengler@linux.ibm.com>
    pkey: Move keytype check from pkey api to handler

Daniel Gibson <daniel@gibson.sh>
    platform/x86/amd/pmc: Don't log during intermediate wakeups

Daniel Gibson <daniel@gibson.sh>
    platform/x86/amd/pmc: Add delay_suspend module parameter

Daniel Gibson <daniel@gibson.sh>
    platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops

Daniel Gibson <daniel@gibson.sh>
    platform/x86/amd/pmc: Check for intermediate wakeup in function

Srinivas Pandruvada <srinivas.pandruvada@intel.com>
    platform/x86: ISST: Restore SST-PP control to all domains

Krishna Chomal <krishna.chomal108@gmail.com>
    platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8E35)

Krishna Chomal <krishna.chomal108@gmail.com>
    platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8D26)

Haoxiang Li <lihaoxiang@isrc.iscas.ac.cn>
    platform/x86: dell-laptop: fix missing cleanups in init error path

ZhaoJinming <zhaojinming@uniontech.com>
    platform/x86/intel/tpmi: use cleanup helpers in mem_write()

Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
    dmaengine: sh: rz-dmac: Move interrupt request after everything is set up

Koichiro Den <den@valinux.co.jp>
    dmaengine: dw-edma-pcie: Reject devices without driver data

Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
    dmaengine: sh: rz-dmac: Fix incorrect NULL check for list_first_entry()

Frank Li <Frank.Li@nxp.com>
    dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK

Kartik Rajput <kkartik@nvidia.com>
    dmaengine: tegra: Fix burst size calculation

Hongling Zeng <zenghongling@kylinos.cn>
    sunrpc: fix uninitialized xprt_create_args structure

Michael Bommarito <michael.bommarito@gmail.com>
    tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt

Jarkko Sakkinen <jarkko@kernel.org>
    tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()

Baoli Zhang <baoli.zhang@linux.intel.com>
    tpm: restore timeout for key creation commands

Bhargav Joshi <j.bhargav.u@gmail.com>
    irqchip/crossbar: Use correct index in crossbar_domain_free()

Yiyang Chen <cyyzero16@gmail.com>
    taskstats: retain dead thread stats in TGID queries

Florian Fuchs <fuchsfl@gmail.com>
    mtd: maps: vmu-flash: fix NULL pointer dereference in initialization

Stafford Horne <shorne@gmail.com>
    openrisc: Fix jump_label smp syncing

Miquel Raynal <miquel.raynal@bootlin.com>
    mtd: rawnand: Pause continuous reads at block boundaries

Takahiro Kuwano <takahiro.kuwano@infineon.com>
    mtd: spi-nor: spansion: use die erase for multi-die devices only

Miquel Raynal <miquel.raynal@bootlin.com>
    mtd: spi-nor: swp: Improve locking user experience

Holger Dengler <dengler@linux.ibm.com>
    s390/pkey: Check length in pkey_pckmo handler implementation

Holger Dengler <dengler@linux.ibm.com>
    s390/pkey: Check length in PKEY_VERIFYPROTK ioctl

Sebastian Alba Vives <sebasjosue84@gmail.com>
    fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()

Maoyi Xie <maoyixie.tju@gmail.com>
    net: thunderbolt: Fix frags[] overflow by bounding frame_count

Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
    bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path

Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
    bus: mhi: host: pci_generic: Fix the physical function check

Sebastian Alba Vives <sebasjosue84@gmail.com>
    fpga: dfl: add bounds check in dfh_get_param_size()

Michael Bommarito <michael.bommarito@gmail.com>
    ocfs2: reject non-inline dinodes with i_size and zero i_clusters

Michael Bommarito <michael.bommarito@gmail.com>
    ocfs2: reject dinodes whose i_rdev disagrees with the file type

Michael Bommarito <michael.bommarito@gmail.com>
    ocfs2: reject dinodes with non-canonical i_mode type

Joseph Qi <joseph.qi@linux.alibaba.com>
    ocfs2: add journal NULL check in ocfs2_checkpoint_inode()

Ian Bridges <icb@fastmail.org>
    ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec

Ian Bridges <icb@fastmail.org>
    ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits

Kyle Zeng <kylebot@openai.com>
    ocfs2: avoid moving extents to occupied clusters

Arseniy Krasnov <avkrasnov@rulkc.org>
    mtd: rawnand: fix condition in 'nand_select_target()'

Vasiliy Kovalev <kovalev@altlinux.org>
    net/9p: fix infinite loop in p9_client_rpc on fatal signal

Bastien Curutchet <bastien.curutchet@bootlin.com>
    mtd: rawnand: pl353: fix probe resource allocation

Tristan Madani <tristan@talencesecurity.com>
    ocfs2: use kzalloc for quota recovery bitmap allocation

Florian Fuchs <fuchsfl@gmail.com>
    mtd: maps: vmu-flash: fix fault in unaligned fixup

Stafford Horne <shorne@gmail.com>
    openrisc: Add full instruction cache invalidate functions

Ionut Nechita <ionut.nechita@windriver.com>
    scsi: sas: Skip opt_sectors when DMA reports no real optimization hint

Pratyush Yadav (Google) <pratyush@kernel.org>
    kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES

Martin Wilck <martin.wilck@suse.com>
    scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()

Alexey Charkov <alchark@flipper.net>
    power: supply: bq257xx: Fix VSYSMIN clamping logic

Breno Leitao <leitao@debian.org>
    9p: skip nlink update in cacheless mode to fix WARN_ON

Ruoyu Wang <ruoyuw560@gmail.com>
    mtd: slram: remove failed entries from the device list

Karl Mehltretter <kmehltretter@gmail.com>
    kcov: use WRITE_ONCE() for selftest mode stores

Muchun Song <muchun.song@linux.dev>
    mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE

Amit Machhiwal <amachhiw@linux.ibm.com>
    powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors

Jinjiang Tu <tujinjiang@huawei.com>
    fs/proc: fix KPF_KSM reported for all anonymous pages

Krzysztof Wilczyński <kwilczynski@kernel.org>
    proc: only bump parent nlink when registering directories

Dev Jain <dev.jain@arm.com>
    fs/proc/task_mmu: do not warn on seeing non-migration pmd entry

Kiryl Shutsemau (Meta) <kas@kernel.org>
    fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()

Kiryl Shutsemau (Meta) <kas@kernel.org>
    fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()

Kiryl Shutsemau (Meta) <kas@kernel.org>
    fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race

SeongJae Park <sj@kernel.org>
    mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error

SeongJae Park <sj@kernel.org>
    mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()

SeongJae Park <sj@kernel.org>
    mm/damon/core: always put unsuccessfully committed target pids

Zishun Yi <vulab@iscas.ac.cn>
    riscv: cacheinfo: Fix node reference leak in populate_cache_leaves

Kiryl Shutsemau (Meta) <kas@kernel.org>
    mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade

Aaron Tomlin <atomlin@atomlin.com>
    mips: sched: Fix CPUMASK_OFFSTACK memory corruption

Bryam Vargas <hexlabsecurity@proton.me>
    selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path

WenTao Liang <vulab@iscas.ac.cn>
    power: supply: charger-manager: fix refcount leak in is_full_charged()

Bryam Vargas <hexlabsecurity@proton.me>
    landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path

Peiyang He <peiyang_he@smail.nju.edu.cn>
    ntfs: fix hole runlist memory leak in insert range error path

Namjae Jeon <linkinjeon@kernel.org>
    ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock()

Namjae Jeon <linkinjeon@kernel.org>
    ntfs: make system files immutable to prevent corruption

Hyunchul Lee <hyc.lee@gmail.com>
    ntfs: avoid self-deadlock during inode eviction

Namjae Jeon <linkinjeon@kernel.org>
    ntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name()

Peiyang He <peiyang_he@smail.nju.edu.cn>
    ntfs: fail attrlist updates when the superblock is inactive

Peiyang He <peiyang_he@smail.nju.edu.cn>
    ntfs: fix mrec_lock ABBA deadlock in rename

Tristan Madani <tristan@talencesecurity.com>
    ntfs3: fix out-of-bounds read in decompress_lznt

Michael Bommarito <michael.bommarito@gmail.com>
    ntfs3: validate split-point offset in indx_insert_into_buffer

Michael Bommarito <michael.bommarito@gmail.com>
    ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head

Michael Bommarito <michael.bommarito@gmail.com>
    ntfs3: cap RESTART_TABLE free-chain walker at rt->used

Michael Bommarito <michael.bommarito@gmail.com>
    fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}

Michael Bommarito <michael.bommarito@gmail.com>
    fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow

Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
    fs/ntfs3: validate lcns_follow in log_replay conversion

Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
    fs/ntfs3: bound attr_off in UpdateResidentValue against data_off

Michael Bommarito <michael.bommarito@gmail.com>
    fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass

Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
    fs/ntfs3: bound DeleteIndexEntryAllocation memmove length

Zhan Xusheng <zhanxusheng1024@gmail.com>
    fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename

DaeMyung Kang <charsyam@gmail.com>
    ntfs: reject non-resident records for resident-only attributes

DaeMyung Kang <charsyam@gmail.com>
    ntfs: validate resident index root values on lookup

DaeMyung Kang <charsyam@gmail.com>
    ntfs: validate resident volume name values on lookup

DaeMyung Kang <charsyam@gmail.com>
    ntfs: do not replace volume name after lookup errors

Samuel Moelius <sam.moelius@trailofbits.com>
    ntfs: detect mapping-pairs LCN accumulator overflow

Hyunchul Lee <hyc.lee@gmail.com>
    ntfs: validate index entries on reading

DaeMyung Kang <charsyam@gmail.com>
    ntfs: avoid heap allocation for free-cluster readahead state

DaeMyung Kang <charsyam@gmail.com>
    ntfs: only alias volume $UpCase to default on exact match

DaeMyung Kang <charsyam@gmail.com>
    ntfs: reinit search context before volume information lookup

Hyunchul Lee <hyc.lee@gmail.com>
    ntfs: skip extent mft records in writeback to prevent deadlock

Hyunchul Lee <hyc.lee@gmail.com>
    ntfs: centalize $INDEX_ROOT header validation

DaeMyung Kang <charsyam@gmail.com>
    ntfs: update index root allocated size before shrink

DaeMyung Kang <charsyam@gmail.com>
    ntfs: free volume-wide resources on fill_super failure

Hyunchul Lee <hyc.lee@gmail.com>
    ntfs: validate index block header more strictly

Hyunchul Lee <hyc.lee@gmail.com>
    ntfs: not change 0-byte $DATA attribute to non-resident

Hyunchul Lee <hyc.lee@gmail.com>
    ntfs: add bounds check before accessing EA entries

DaeMyung Kang <charsyam@gmail.com>
    ntfs: validate attribute values on lookup

Marco Crivellari <marco.crivellari@suse.com>
    ntfs: Add WQ_PERCPU to alloc_workqueue users

Ron de Bruijn <rmbruijn@gmail.com>
    ntfs: fix off-by-one in mapping pairs decoding bounds checks

Hyunchul Lee <hyc.lee@gmail.com>
    ntfs: fix incorrect size of symbolic link

DaeMyung Kang <charsyam@gmail.com>
    ntfs: grow index root value before reparent header update

SeongJae Park <sj@kernel.org>
    mm/damon/core: make charge_addr_from aware of end-address exclusivity

Muchun Song <muchun.song@linux.dev>
    mm/memory_hotplug: fix incorrect altmap passing in error path

Deepanshu Kartikey <kartikey406@gmail.com>
    mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch

Johan Hovold <johan@kernel.org>
    power: supply: max17042: fix OF node reference imbalance

Ma Ke <make24@iscas.ac.cn>
    power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak

Muchun Song <muchun.song@linux.dev>
    mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages

Maciej W. Rozycki <macro@orcam.me.uk>
    MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()

Johan Hovold <johan@kernel.org>
    MIPS: ip22-gio: fix device reference leak in probe

Johan Hovold <johan@kernel.org>
    MIPS: ip22-gio: fix kfree() of static object

Johan Hovold <johan@kernel.org>
    MIPS: ip22-gio: fix gio device memory leak

Muchun Song <muchun.song@linux.dev>
    mm/sparse-vmemmap: fix vmemmap accounting underflow

Tanmay Shah <tanmay.shah@amd.com>
    remoteproc: xlnx: Check remote core state

Wasim Nazir <wasim.nazir@oss.qualcomm.com>
    remoteproc: qcom: Fix leak when custom dump_segments addition fails

Chuck Lever <chuck.lever@oracle.com>
    SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing

Chuck Lever <chuck.lever@oracle.com>
    lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure

Chuck Lever <chuck.lever@oracle.com>
    lockd: Plug nlm_file leak when nlm_do_fopen() fails

Luxiao Xu <rakukuip@gmail.com>
    sunrpc: harden rq_procinfo lifecycle to prevent double-free

Chuck Lever <chuck.lever@oracle.com>
    sunrpc: wait for in-flight TLS handshake callback when cancel loses race

Chris Mason <clm@meta.com>
    sunrpc: pin svc_xprt across the asynchronous TLS handshake callback

Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
    pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    nvdimm/btt: Free arena sub-allocations on discover_arenas() error path

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    nvdimm/btt: Free arenas on btt_init() error paths

Junrui Luo <moonafterrain@outlook.com>
    jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()

Terry Bowman <terry.bowman@amd.com>
    cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size

Duje Mihanović <duje@dujemihanovic.xyz>
    backlight: ktd2801: Enable BL_CORE_SUSPENDRESUME

Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
    mfd: tps6586x: Fix OF node refcount

Shyam Prasad N <sprasad@microsoft.com>
    cifs: invalidate cfid on unlink/rename/rmdir

Sven Eckelmann <sven@narfation.org>
    batman-adv: tt: prevent TVLV OOB check overflow

Sven Eckelmann <sven@narfation.org>
    batman-adv: mcast: avoid OOB read of num_dests header

Sven Eckelmann <sven@narfation.org>
    batman-adv: frag: fix primary_if leak on failed linearization

Sven Eckelmann <sven@narfation.org>
    batman-adv: clean untagged VLAN on netdev registration failure

Sven Eckelmann <sven@narfation.org>
    batman-adv: frag: free unfragmentable packet

Sven Eckelmann <sven@narfation.org>
    batman-adv: fix VLAN priority offset

Sven Eckelmann <sven@narfation.org>
    batman-adv: tt: avoid request storms during pending request

Sven Eckelmann <sven@narfation.org>
    batman-adv: dat: fix tie-break for candidate selection

Sven Eckelmann <sven@narfation.org>
    batman-adv: ensure minimal ethernet header on TX

Sven Eckelmann <sven@narfation.org>
    batman-adv: dat: ensure accessible eth_hdr proto field

Sven Eckelmann <sven@narfation.org>
    batman-adv: bla: reacquire gw address after skb realloc

Sven Eckelmann <sven@narfation.org>
    batman-adv: dat: acquire ARP hw source only after skb realloc

Sven Eckelmann <sven@narfation.org>
    batman-adv: access unicast_ttvn skb->data only after skb realloc

Sven Eckelmann <sven@narfation.org>
    batman-adv: retrieve ethhdr after potential skb realloc on RX

Sven Eckelmann <sven@narfation.org>
    batman-adv: gw: acquire ethernet header only after skb realloc

Sumanth Korikkar <sumanthk@linux.ibm.com>
    s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()

Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
    cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf() path

Sandipan Das <sandipan.das@amd.com>
    perf/x86/amd/lbr: Fix kernel address leakage

Sandipan Das <sandipan.das@amd.com>
    perf/x86/amd/brs: Fix kernel address leakage

Thorsten Blum <thorsten.blum@linux.dev>
    x86/boot: Reject too long acpi_rsdp= values

Thorsten Blum <thorsten.blum@linux.dev>
    x86/boot: Validate console=uart8250 baud rate to fix early boot hang

Tycho Andersen (AMD) <tycho@kernel.org>
    x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN"

Mario Limonciello <mario.limonciello@amd.com>
    x86/video: Only fall back to vga_default_device() without screen info

Ali Ahmet MEMIS <dev@unknownbbqr.xyz>
    tools/power/x86/intel-speed-select: Harden daemon pidfile open

Guangshuo Li <lgs201920130244@gmail.com>
    mfd: sm501: Fix reference leak on failed device registration

Armin Wolf <W_Armin@gmx.de>
    leds: uleds: Fix potential buffer overread

Ondrej Mosnacek <omosnace@redhat.com>
    selinux: fix incorrect execmem checks on overlayfs

Tristan Madani <tristan@talencesecurity.com>
    selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()

Stephen Smalley <stephen.smalley.work@gmail.com>
    selinux: check connect-related permissions on TCP Fast Open

Wang Jun <1742789905@qq.com>
    soc: fsl: qe: panic on ioremap() failure in qe_reset()

Siddharth Vadapalli <s-vadapalli@ti.com>
    soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy

Arunpravin Paneer Selvam <Arunpravin.PaneerSelvam@amd.com>
    gpu/buddy: bail out of try_harder when alignment cannot be honoured

Guangshuo Li <lgs201920130244@gmail.com>
    gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path

Eliot Courtney <ecourtney@nvidia.com>
    gpu: nova-core: simplify and_then with condition to filter

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: flowtable: use correct direction to set up tunnel route

Xiang Mei (Microsoft) <xmei5@asu.edu>
    netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()

Wyatt Feng <bronzed_45_vested@icloud.com>
    netfilter: xt_nat: reject unsupported target families

Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
    netfilter: ecache: fix inverted time_after() check

Florian Westphal <fw@strlen.de>
    netfilter: xt_physdev: masks are not c-strings

Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
    netfilter: nf_conncount: fix zone comparison in tuple dedup

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: flowtable: support IPIP tunnel with direct xmit

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: flowtable: use dst in this direction when pushing IPIP header

Xiang Mei <xmei5@asu.edu>
    netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag

Florian Westphal <fw@strlen.de>
    netfilter: nf_nat_sip: reload possible stale data pointer

Florian Westphal <fw@strlen.de>
    netfilter: nft_set_pipapo: don't leak bad clone into future transaction

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nf_conntrack_sip: validate skb_dst() before accessing it

Theodor Arsenij Larionov-Trichkine <theodorlarionov@gmail.com>
    netfilter: nft_fib: reject fib expression on the netdev egress hook

Haoze Xie <royenheart@gmail.com>
    netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst

Wyatt Feng <bronzed_45_vested@icloud.com>
    netfilter: xt_cluster: reject template conntracks in hash match

David Carlier <devnexen@gmail.com>
    netfilter: nfnl_cthelper: apply per-class values when updating policies

Muhammad Bilal <meatuni001@gmail.com>
    netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read

Srinivas Kandagatla <srinivas.kandagatla@oss.qualcomm.com>
    ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ASoC: mediatek: mt8183: Release reserved memory on cleanup

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ASoC: mediatek: mt8183: Check runtime resume during probe

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ASoC: mediatek: mt8192: Release reserved memory on cleanup

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ASoC: mediatek: mt8192: Check runtime resume during probe

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get

Zhao Dongdong <zhaodongdong@kylinos.cn>
    ASoC: SOF: topology: fix memory leak in snd_sof_load_topology

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: tridentfb: fix potential memory leak in trident_pci_probe()

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: nvidia: fix potential memory leak in nvidiafb_probe()

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: vesafb: fix memory leak in vesafb_probe()

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: uvesafb: fix potential memory leak in uvesafb_probe()

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: s3fb: fix potential memory leak in s3_pci_probe()

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: i740fb: fix potential memory leak in i740fb_probe()

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: radeon: fix potential memory leak in radeonfb_pci_register()

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: efifb: fix memory leak in efifb_probe()

Li RongQing <lirongqing@baidu.com>
    fbdev: sm712: Fix operator precedence in big_swap macro

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: hecubafb: fix potential memory leak in hecubafb_probe()

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    fbdev: metronomefb: fix potential memory leak in metronomefb_probe()

Oliver Upton <oupton@kernel.org>
    KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory

Oliver Upton <oupton@kernel.org>
    KVM: arm64: nv: Re-translate VNCR before injecting abort

Oliver Upton <oupton@kernel.org>
    KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN

Oliver Upton <oupton@kernel.org>
    KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR

Weiming Shi <bestswngs@gmail.com>
    KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()

Fuad Tabba <tabba@google.com>
    KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions

Oliver Upton <oupton@kernel.org>
    KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2

Oliver Upton <oupton@kernel.org>
    KVM: arm64: Ensure level is always initialized when relaxing perms

Bradley Morgan <include@grrlz.net>
    KVM: arm64: account pKVM reclaim against the VM mm

Marc Zyngier <maz@kernel.org>
    KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers

Sean Christopherson <seanjc@google.com>
    KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state

leixiang <leixiang@kylinos.cn>
    KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails

Sean Christopherson <seanjc@google.com>
    KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs

Binbin Wu <binbin.wu@linux.intel.com>
    KVM: TDX: Reject concurrent change to CPUID entry count

Atish Patra <atishp@meta.com>
    KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs

Matthew Rosato <mjrosato@linux.ibm.com>
    KVM: s390: pci: Fix handling of AIF enable without AISB

Sean Christopherson <seanjc@google.com>
    KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks

Marc Zyngier <maz@kernel.org>
    KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling

Hyunwoo Kim <imv4bel@gmail.com>
    KVM: arm64: vgic: Check the interrupt is still ours before migrating it

Haoxiang Li <haoxiang_li2024@163.com>
    KVM: s390: pci: Fix GISC refcount leak on AIF enable failure

Gautam Menghani <gautam@linux.ibm.com>
    powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM

Claudio Imbrenda <imbrenda@linux.ibm.com>
    KVM: s390: Fix unlikely race in try_get_locked_pte()

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory

Claudio Imbrenda <imbrenda@linux.ibm.com>
    KVM: s390: vsie: Use mmu cache to allocate rmap

Claudio Imbrenda <imbrenda@linux.ibm.com>
    KVM: s390: Silence potential warnings in _gmap_crstep_xchg_atomic()

Claudio Imbrenda <imbrenda@linux.ibm.com>
    KVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault()

Claudio Imbrenda <imbrenda@linux.ibm.com>
    KVM: s390: vsie: Fix allocation of struct vsie_rmap

Qiang Ma <maqianga@uniontech.com>
    LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()

Bibo Mao <maobibo@loongson.cn>
    LoongArch: KVM: Fix FPU register width with user access API

Qiang Ma <maqianga@uniontech.com>
    LoongArch: KVM: Check the return values for put_user()

Bibo Mao <maobibo@loongson.cn>
    LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()

Yanfei Xu <yanfei.xu@bytedance.com>
    LoongArch: KVM: Validate irqchip index in irqfd routing

David Jander <david@protonic.nl>
    ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files

David Jander <david@protonic.nl>
    ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo

David Jander <david@protonic.nl>
    ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files

Abel Vesa <abel.vesa@oss.qualcomm.com>
    arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers

David Jander <david@protonic.nl>
    ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags

David Jander <david@protonic.nl>
    ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference

Judith Mendez <jm@ti.com>
    arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc

David Jander <david@protonic.nl>
    ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files

David Jander <david@protonic.nl>
    ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times

Quentin Schulz <quentin.schulz@cherry.de>
    arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck

Nickolay Goppen <setotau@mainlining.org>
    arm64: dts: qcom: sdm630: describe adsp_mem region properly

Hugo Villeneuve <hvilleneuve@dimonoff.com>
    ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply property

Marek Vasut <marek.vasut+renesas@mailbox.org>
    arm64: dts: renesas: ironhide: Describe inline ECC carveouts

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    arm64: dts: s32g3: Fix SWT8 watchdog address

Mark Rutland <mark.rutland@arm.com>
    arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()

Yong Wang <edragain@163.com>
    net: ife: require ETH_HLEN to be pullable in ife_decode()

Runyu Xiao <runyu.xiao@seu.edu.cn>
    octeontx2-vf: clear stale mailbox IRQ state before request_irq()

Runyu Xiao <runyu.xiao@seu.edu.cn>
    octeontx2-pf: clear stale mailbox IRQ state before request_irq()

Zhengchuan Liang <zcliangcn@gmail.com>
    net: atm: reject out-of-range traffic classes in QoS validation

Michael Bommarito <michael.bommarito@gmail.com>
    net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()

Li Xiasong <lixiasong1@huawei.com>
    tipc: restrict socket queue dumps in enqueue tracepoints

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ASoC: SOF: topology: validate vendor array size before parsing

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: SOF: ipc4-control: Validate notification payload size

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put

Jason Wang <jasowang@redhat.com>
    VDUSE: avoid leaking information to userspace

Zhang Tianci <zhangtianci.1997@bytedance.com>
    vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter

Wentao Liang <vulab@iscas.ac.cn>
    mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()

Wentao Liang <vulab@iscas.ac.cn>
    mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()

Przemyslaw Korba <przemyslaw.korba@intel.com>
    idpf: add padding to PTP virtchnl structures

Vincent Donnefort <vdonnefort@google.com>
    ring-buffer: Allow sparse CPU masks in ring_buffer_desc()

Vincent Donnefort <vdonnefort@google.com>
    tracing/remotes: Fix struct_len in trace_remote_alloc_buffer()

Vincent Donnefort <vdonnefort@google.com>
    tracing/remotes: Fix leak in trace_remote_alloc_buffer() error path

Ben Dooks <ben.dooks@codethink.co.uk>
    drm/imagination: make pvr_fw_trace_init_mask_ops static

Guangshuo Li <lgs201920130244@gmail.com>
    smb: client: fix overflow in passthrough ioctl bounds check

Guangshuo Li <lgs201920130244@gmail.com>
    drm/xe: free madvise VMA array on L2 flush failure

Anas Khan <anxkhn28@gmail.com>
    drm/xe: remove duplicate <kunit/test-bug.h> include

Harman Kalra <hkalra@marvell.com>
    octeontx2-af: fix VF bringup affecting PF promiscuous state

Gal Pressman <gal@nvidia.com>
    ethtool: rss: Fix hfunc and input_xfrm parsing on big endian

Li RongQing <lirongqing@baidu.com>
    net/mlx5: Fix L3 tunnel entropy refcount leak

Wang Yan <wangyan01@kylinos.cn>
    selftests/net: fix EVP_MD_CTX leak in tcp_mmap

Thomas Zimmermann <tzimmermann@suse.de>
    drm/fb-helper: Only consider active CRTCs for vblank sync

Timur Tabi <ttabi@nvidia.com>
    regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK

Zizhi Wo <wozizhi@huawei.com>
    smb: client: fix busy dentry warning on unmount after DIO

Cao Guanghui <caoguanghui@kylinos.cn>
    dm era: fix NULL pointer dereference in metadata_open()

Chuck Lever <chuck.lever@oracle.com>
    SUNRPC: pin upper rpc_clnt across the TLS connect_worker

Chuck Lever <chuck.lever@oracle.com>
    SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED

Guangshuo Li <lgs201920130244@gmail.com>
    cifs: validate DFS referral string offsets

Rongguang Wei <weirongguang@kylinos.cn>
    s390/zcrypt: Remove the empty file

Julian Anastasov <ja@ssi.bg>
    ipvs: ensure inner headers in ICMP errors are in headroom

Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
    ipvs: fix PMTU for GUE/GRE tunnel ICMP errors

Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
    ipvs: use parsed transport offset in TCP state lookup

Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
    ipvs: pass parsed transport offset to state handlers

Tamaki Yanagawa <ty@000ty.net>
    netfilter: nft_lookup: fix catchall element handling with inverted lookups

Eric Dumazet <edumazet@google.com>
    ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()

Yuyang Huang <yuyanghuang@google.com>
    ipv4: igmp: annotate data-races around timer-related fields

Yuyang Huang <sigefriedhyy@gmail.com>
    ipv4: igmp: annotate data-races around im->users

Eric Dumazet <edumazet@google.com>
    ipv6: mcast: Fix potential UAF in MLD delayed work

Eric Dumazet <edumazet@google.com>
    ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()

Rosen Penev <rosenp@gmail.com>
    gpio: mvebu: free generic chips on unbind

Sandipan Das <sandipan.das@amd.com>
    perf/x86/amd/core: Avoid enabling BRS from the SVM reload path

Suman Ghosh <sumang@marvell.com>
    octeontx2-pf: check DMAC extraction support before filtering

Samuel Moelius <sam.moelius@trailofbits.com>
    net/sched: cake: reject overhead values that underflow length

Rosen Penev <rosenp@gmail.com>
    net: mdio: select REGMAP_MMIO instead of depending on it

Cihan Karadag <cihan.cihan@gmail.com>
    selftests: gpio: add gpio-cdev-uaf to .gitignore

Maíra Canal <mcanal@igalia.com>
    drm/v3d: Reject invalid indirect BO handle in indirect CSD setup

Lizhi Hou <lizhi.hou@amd.com>
    accel/amdxdna: Fix potential amdxdna_umap lifetime race

Ben Dooks <ben.dooks@codethink.co.uk>
    tracing: Make tracepoint_printk static as not exported

Robert Mader <robert.mader@collabora.com>
    drm: Guard DRM_CLIENT_CAP_PLANE_COLOR_PIPELINE

Jia Wang <wangjia@ultrarisc.com>
    gpio: dwapb: Defer clock gating until noirq

Enrico Pozzobon <enrico.pozzobon@dissecto.com>
    net: usb: lan78xx: disable VLAN filter in promiscuous mode

Yuho Choi <dbgh9129@gmail.com>
    net/liquidio: drop cached VF pci_dev LUT

Dong Yibo <dong100@mucse.com>
    net: rnpgbe: fix mailbox endianness and remove pointer casts

Chuck Lever <chuck.lever@oracle.com>
    net/tls: Consume empty data records in tls_sw_read_sock()

Lizhi Hou <lizhi.hou@amd.com>
    accel/amdxdna: Fix VMA access race

Lizhi Hou <lizhi.hou@amd.com>
    accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register()

Lizhi Hou <lizhi.hou@amd.com>
    accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo()

Hui Wang <hui.wang@canonical.com>
    ring-buffer: Fix event length with forced 8-byte alignment

Stig Hornang <stig@hornang.me>
    Bluetooth: L2CAP: fix tx ident leak for commands without a response

Weiming Shi <bestswngs@gmail.com>
    Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()

Pauli Virtanen <pav@iki.fi>
    Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length

Pauli Virtanen <pav@iki.fi>
    Bluetooth: ISO: fix malformed ISO_END/CONT handling

Kiran K <kiran.k@intel.com>
    Bluetooth: btintel_pcie: Refactor FLR to use device_reprobe()

Ravindra <ravindra@intel.com>
    Bluetooth: btintel_pcie: Separate coredump work from RX work

Kiran K <kiran.k@intel.com>
    Bluetooth: btintel_pcie: Add support for smart trigger dump

Chandrashekar Devegowda <chandrashekar.devegowda@intel.com>
    Bluetooth: btintel_pcie: Support Product level reset

Sungwoo Kim <iam@sung-woo.kim>
    Bluetooth: sco: Fix a race condition in sco_sock_timeout()

Cen Zhang <zzzccc427@gmail.com>
    Bluetooth: MGMT: Fix adv monitor add failure cleanup

Cen Zhang <zzzccc427@gmail.com>
    Bluetooth: 6lowpan: hold L2CAP conn across debugfs control

Cen Zhang <zzzccc427@gmail.com>
    Bluetooth: 6lowpan: avoid untracked enable work

Suraj Kandpal <suraj.kandpal@intel.com>
    drm/i915/ltphy: Fix SSC Enablement bit in PORT_CLOCK_CTL

Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
    gpio: shared: make the voting mechanism adaptable

Steve French <stfrench@microsoft.com>
    smb: client: preserve leading slash for POSIX absolute symlink targets

Namjae Jeon <linkinjeon@kernel.org>
    ksmbd: fix multichannel binding and enforce channel limit

Eric Dumazet <edumazet@google.com>
    amt: fix size calculation in amt_get_size()

Xiang Mei <xmei5@asu.edu>
    net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket

Jamal Hadi Salim <jhs@mojatatu.com>
    net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload

Xiang Mei <xmei5@asu.edu>
    net: qualcomm: rmnet: validate MAP frame length before ingress parsing

Shigeru Yoshida <syoshida@redhat.com>
    qede: fix off-by-one in BD ring consumption on build_skb failure

Jens Emil Schulz Østergaard <jensemil.schulzostergaard@microchip.com>
    net: microchip: vcap: fix races on the shared Super VCAP block

Feng Liu <feliu@nvidia.com>
    net/mlx5e: Fix publication race for priv->channel_stats[]

Feng Liu <feliu@nvidia.com>
    net/mlx5e: Fix HV VHCA stats agent registration race

Feng Liu <feliu@nvidia.com>
    net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation

Damon Ding <damon.ding@rock-chips.com>
    drm/bridge: analogix_dp: Fix PE/VS value shift mismatch during link training

Shay Drory <shayd@nvidia.com>
    net/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable

Shay Drory <shayd@nvidia.com>
    net/mlx5: LAG, MPESW, Fix missing complete() on devcom error

Shay Drory <shayd@nvidia.com>
    net/mlx5: LAG, Fix off-by-one in single-FDB error rollback

Shay Drory <shayd@nvidia.com>
    net/mlx5: LAG, extend shared FDB API with group_id filter

Shay Drory <shayd@nvidia.com>
    net/mlx5: LAG, prepare for SD device integration

Shay Drory <shayd@nvidia.com>
    net/mlx5: LAG, replace peer count check with direct peer lookup

Shay Drory <shayd@nvidia.com>
    net/mlx5: LAG, factor out shared FDB code into dedicated file

Mark Bloch <mbloch@nvidia.com>
    net/mlx5: Lag, avoid LAG and representor lock cycles

Mark Bloch <mbloch@nvidia.com>
    net/mlx5: E-Switch, add representor lifecycle lock

Mark Bloch <mbloch@nvidia.com>
    net/mlx5: Lag: refactor representor reload handling

Mingyou Chen <qby140326@gmail.com>
    platform/x86: bitland-mifs-wmi: Fix NULL pointer dereference during suspend/resume

Wyatt Feng <bronzed_45_vested@icloud.com>
    netfilter: xt_connmark: reject invalid shift parameters

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nft_set_rbtree: get command skips end element with open interval

Zhixing Chen <running910@gmail.com>
    netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop

Feng Wu <wufengwufengwufeng@gmail.com>
    netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()

Wyatt Feng <bronzed_45_vested@icloud.com>
    netfilter: xt_u32: reject invalid shift counts

Qihang <q.h.hack.winter@gmail.com>
    gue: validate REMCSUM private option length

Xiang Mei <xmei5@asu.edu>
    net: usb: net1080: validate packet_len before pad-byte access in rx_fixup

Jia He <justin.he@arm.com>
    arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1

Yiyang Chen <chenyy23@mails.tsinghua.edu.cn>
    selftests/hid: Cover hid_bpf_get_data() size overflow

Yiyang Chen <chenyy23@mails.tsinghua.edu.cn>
    selftests/hid: Load only requested struct_ops maps

Yiyang Chen <chenyy23@mails.tsinghua.edu.cn>
    HID: bpf: Fix hid_bpf_get_data() range check

Cen Zhang <zzzccc427@gmail.com>
    ntfs: avoid stale runlist element dereference in fallocate

Ariana Lazar <ariana.lazar@microchip.com>
    iio: dac: mcp47feb02: Fix passing uninitialized vref1_uV for no Vref1 case

Anshuman Khandual <anshuman.khandual@arm.com>
    arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()

Catalin Marinas <catalin.marinas@arm.com>
    arm64: Avoid eager DVMSync reclaim batches with C1-Pro SME erratum

Lee Jones <lee@kernel.org>
    HID: core: Fix OOB read in hid_get_report for numbered reports

Georgiy Osokin <g.osokin@auroraos.dev>
    HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()

Cen Zhang <zzzccc427@gmail.com>
    ntfs: avoid stale runlist element dereference in MFT writeback

David Howells <dhowells@redhat.com>
    netfs: Fix barriering when walking subrequest list

Karuna Ramkumar <rkaruna@google.com>
    ata: libata-scsi: limit simulated SCSI command copy to response length

Myeonghun Pak <mhun512@gmail.com>
    ata: sata_gemini: unwind clocks on IDE pinctrl errors

David Howells <dhowells@redhat.com>
    cifs: Fix missing credit release on failure in cifs_issue_read()

Jiri Olsa <jolsa@kernel.org>
    uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline

David Windsor <dwindsor@gmail.com>
    x86/uprobes: Keep shadow stack in sync for emulated CALLs

Matthew Auld <matthew.auld@intel.com>
    drm/xe/pt: prevent invalid cursor access for purged BOs

Matthew Auld <matthew.auld@intel.com>
    drm/xe: fix NPD in bo_meminfo()

Michal Wajdeczko <michal.wajdeczko@intel.com>
    drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays

Shuicheng Lin <shuicheng.lin@intel.com>
    drm/xe/hw_engine: Fix double-free of managed BO in error path

Shuicheng Lin <shuicheng.lin@intel.com>
    drm/xe/userptr: Drop bogus static from finish in force_invalidate

Shuicheng Lin <shuicheng.lin@intel.com>
    drm/xe/userptr: Hold notifier_lock for write on inject test path

Brajesh Gupta <brajesh.gupta@imgtec.com>
    drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY

Francois Dugast <francois.dugast@intel.com>
    drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()

David Howells <dhowells@redhat.com>
    netfs: Fix folio state after ENOMEM whilst under writeback iteration

David Howells <dhowells@redhat.com>
    netfs: Fix writeback error handling

David Howells <dhowells@redhat.com>
    netfs: Fix writethrough to use collection offload

David Howells <dhowells@redhat.com>
    cachefiles: Fix file burial to take lock when unsetting S_KERNEL_FILE

David Howells <dhowells@redhat.com>
    netfs: Fix netfs_create_write_req() to handle async cache object creation

Morduan Zang <zhangdandan@uniontech.com>
    iomap: guard io_size EOF trim against concurrent truncate underflow

Amir Goldstein <amir73il@gmail.com>
    ovl: fix comment about locking order

Hongling Zeng <zenghongling@kylinos.cn>
    cachefiles: Fix double unlock in nomem_d_alloc error path

Michael Bommarito <michael.bommarito@gmail.com>
    minix: avoid overflow in bitmap block count calculation

Fengnan Chang <changfengnan@bytedance.com>
    iomap: release pages on atomic dio size mismatch

David Howells <dhowells@redhat.com>
    afs: Fix unchecked-length string display in debug statement

David Howells <dhowells@redhat.com>
    afs: Fix the volume AFS_VOLUME_RM_TREE is set on

David Howells <dhowells@redhat.com>
    afs: Fix premature cell exposure through /afs

David Howells <dhowells@redhat.com>
    afs: Fix lack of locking around modifications of net->cells_dyn_ino

David Howells <dhowells@redhat.com>
    afs: Fix vllist leak

David Howells <dhowells@redhat.com>
    afs: Fix leak of ungot volume

David Howells <dhowells@redhat.com>
    afs: Use scoped_seqlock_read() rather than manually doing seqlock stuff

David Howells <dhowells@redhat.com>
    afs: Fix missing NULL pointer check in afs_break_some_callbacks()

David Howells <dhowells@redhat.com>
    afs: Fix callback service message parsers to pass through -EAGAIN

David Howells <dhowells@redhat.com>
    afs: Fix reinitialisation of the inode, in particular ->lock_work

David Howells <dhowells@redhat.com>
    afs: Fix misplaced inc of net->cells_outstanding

David Howells <dhowells@redhat.com>
    afs: Fix bulk lookup malfunction due to change in dir_emit() API

Li RongQing <lirongqing@baidu.com>
    afs: Remove erroneous seq |= 1 in volume lookup loop

Zilin Guan <zilin@seu.edu.cn>
    afs: use kvfree() to free memory allocated by kvcalloc()

David Howells <dhowells@redhat.com>
    afs: Fix directory inode initialisation order

David Howells <dhowells@redhat.com>
    afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints

David Howells <dhowells@redhat.com>
    afs: Fix double netfs initialisation in afs_root_iget()

Dan Carpenter <error27@gmail.com>
    afs: Fix error code in afs_extract_vl_addrs()

Christian Brauner <brauner@kernel.org>
    fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid

Samuel Moelius <sam.moelius@trailofbits.com>
    net/sched: hhf: clear heavy-hitter state on reset

Samuel Moelius <sam.moelius@trailofbits.com>
    net/sched: dualpi2: clear stale classification on filter miss

Michael Bommarito <michael.bommarito@gmail.com>
    xen/pvcalls: bound backend response req_id before indexing rsp[]

Viacheslav Bocharov <v@baodeep.com>
    pinctrl: meson: restore non-sleeping GPIO access

Vladimir Zapolskiy <vz@kernel.org>
    gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe

Gil Portnoy <dddhkts1@gmail.com>
    ksmbd: fix use-after-free of fp->owner.name in durable handle owner check

Haofeng Li <lihaofeng@kylinos.cn>
    ksmbd: reject undersized DACLs before parsing ACEs

Sechang Lim <rhkrqnwk98@gmail.com>
    net/sched: act_bpf: use rcu_dereference_bh() to read the filter

Jakub Kicinski <kuba@kernel.org>
    selftests: drv-net: tso: don't touch dangerous feature bits

Gleb Markov <markov.gi@npc-ksb.ru>
    cxgb4: Fix decode strings dump for T6 adapters

Longjun Tang <tanglongjun@kylinos.cn>
    virtio_net: disable cb when NAPI is busy-polled

Xin Long <lucien.xin@gmail.com>
    sctp: fix addr_wq_timer race in sctp_free_addr_wq()

Felix Gu <ustc.gu@gmail.com>
    spi: rzv2h-rspi: Fix DMA transfer error handling for signal interruption

Qingshuang Fu <fuqingshuang@kylinos.cn>
    irqchip/ts4800: Fix missing chained handler cleanup on remove

Yuho Choi <dbgh9129@gmail.com>
    irqchip/gic-v3-its: Fix OF node reference leak

Masami Hiramatsu (Google) <mhiramat@kernel.org>
    tracing/probes: Make the $ prefix mandatory for comm access

Sechang Lim <rhkrqnwk98@gmail.com>
    tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()

Martin Kaiser <martin@kaiser.cx>
    tracing: eprobe: read the complete FILTER_PTR_STRING pointer

Masami Hiramatsu (Google) <mhiramat@kernel.org>
    tracing/events: Fix to check the simple_tsk_fn creation

Masami Hiramatsu (Google) <mhiramat@kernel.org>
    tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg

Steven Rostedt <rostedt@goodmis.org>
    tracing/eprobes: Allow use of BTF names to dereference pointers

Boris Brezillon <boris.brezillon@collabora.com>
    drm/panthor: Interrupt group start/resumption if group_bind_locked() fails

Boris Brezillon <boris.brezillon@collabora.com>
    drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced

Boris Brezillon <boris.brezillon@collabora.com>
    drm/panthor: Fix panthor_pwr_unplug()

Boris Brezillon <boris.brezillon@collabora.com>
    drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick()

Boris Brezillon <boris.brezillon@collabora.com>
    drm/panthor: Fix theoretical IOMEM access in suspended state

Karunika Choo <karunika.choo@arm.com>
    drm/panthor: Store IRQ register base iomem pointer in panthor_irq

Karunika Choo <karunika.choo@arm.com>
    drm/panthor: Split register definitions by components

Karunika Choo <karunika.choo@arm.com>
    drm/panthor: Pass an iomem pointer to GPU register access helpers

Boris Brezillon <boris.brezillon@collabora.com>
    drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()

Boris Brezillon <boris.brezillon@collabora.com>
    drm/panthor: Keep the reset work disabled until everything is initialized

Boris Brezillon <boris.brezillon@collabora.com>
    drm/panthor: Always use the IRQ-safe variant when acquiring the fence lock

Viacheslav Bocharov <v@baodeep.com>
    gpio: shared-proxy: always serialize with a sleeping mutex

Ido Schimmel <idosch@nvidia.com>
    bridge: stp: Fix a potential use-after-free when deleting a bridge

Jamal Hadi Salim <jhs@mojatatu.com>
    net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF

Rosen Penev <rosenp@gmail.com>
    net: gianfar: dispose irq mappings on probe failure and device removal

Jiawen Wu <jiawenwu@trustnetic.com>
    net: libwx: fix VMDQ mask for 1-queue mode

Petr Wozniak <petr.wozniak@gmail.com>
    net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy

Xiang Mei <xmei5@asu.edu>
    usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()

Pengfei Zhang <zhangfeionline@gmail.com>
    ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump

Jakub Kicinski <kuba@kernel.org>
    eth: fbnic: don't cache shinfo across skb realloc

Guenter Roeck <linux@roeck-us.net>
    hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero

Guenter Roeck <linux@roeck-us.net>
    hwmon: (pmbus) Fix passing events to regulator core

Matti Vaittinen <mazziesaccount@gmail.com>
    hwmon: adm1275: Prevent reading uninitialized stack

Lizhi Hou <lizhi.hou@amd.com>
    accel/amdxdna: Fix iommu domain lifetime race during device removal

Abdurrahman Hussain <abdurrahman@nexthop.ai>
    hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()

Luca Weiss <luca.weiss@fairphone.com>
    ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280

Kyle Hendry <kylehendrydev@gmail.com>
    MIPS: mm: Add check for highmem before removing memory block

Maciej W. Rozycki <macro@orcam.me.uk>
    MIPS: DEC: Ensure RTC platform device deregistration upon failure

Xin Long <lucien.xin@gmail.com>
    sctp: add INIT verification after cookie unpacking

Yousef Alhouseen <alhouseenyousef@gmail.com>
    sctp: fix SCTP_RESET_STREAMS stream list length limit

Wei Fang <wei.fang@nxp.com>
    net: enetc: check the number of BDs needed for xdp_frame

Matvey Kovalev <matvey.kovalev@ispras.ru>
    qede: fix out-of-bounds check for cqe->len_list[]

Nuoqi Gui <gnq25@mails.tsinghua.edu.cn>
    seg6: validate SRH length before reading fixed fields

Corey Leavitt <corey@leavitt.info>
    net: pse-pd: scope pse_control regulator handle to kref lifetime

Pengpeng Hou <pengpeng@iscas.ac.cn>
    gpio: htc-egpio: use managed gpiochip registration

Pengpeng Hou <pengpeng@iscas.ac.cn>
    gpio: mvebu: fail probe if gpiochip registration fails

KaFai Wan <kafai.wan@linux.dev>
    bpf: Fix insn_aux_data leak on verifier err_free_env path

Nuoqi Gui <gnq25@mails.tsinghua.edu.cn>
    bpf: Mask pseudo pointer values in verifier logs

Samuel Holland <samuel.holland@sifive.com>
    riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI

Yicong Yang <yang.yicong@picoheart.com>
    ACPI: RIMT: Only defer the IOMMU configuration in init stage

Pengpeng Hou <pengpeng@iscas.ac.cn>
    spi: sh-msiof: abort transfers when reset times out

Martin Kaiser <martin@kaiser.cx>
    tracing: probes: fix typo in a log message

Jiaming Zhang <r772577952@gmail.com>
    ALSA: FCP: Fix NULL pointer dereference in interface lookup

Shuaisong Yang <yangshuaisong@h-partners.com>
    net: hns3: differentiate autoneg default values between copper and fiber

Shuaisong Yang <yangshuaisong@h-partners.com>
    net: hns3: fix permanent link down deadlock after reset

Shuaisong Yang <yangshuaisong@h-partners.com>
    net: hns3: refactor MAC autoneg and speed configuration

Shuaisong Yang <yangshuaisong@h-partners.com>
    net: hns3: unify copper port ksettings configuration path

Nirmoy Das <nirmoyd@nvidia.com>
    selftests: tls: size splice_short pipe by page size

Eric Dumazet <edumazet@google.com>
    tipc: avoid busy looping in tipc_exit_net()

Eric Dumazet <edumazet@google.com>
    tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()

Kuniyuki Iwashima <kuniyu@google.com>
    tipc: Store struct sock in struct udp_bearer.

Kuniyuki Iwashima <kuniyu@google.com>
    udp_tunnel: Pass struct sock to setup_udp_tunnel_sock().

Kuniyuki Iwashima <kuniyu@google.com>
    udp_tunnel: Pass struct sock to udp_tunnel_sock_release().

Wei Fang <wei.fang@nxp.com>
    net: enetc: fix potential divide-by-zero when num_vsi is zero

Rob Herring (Arm) <robh@kernel.org>
    dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback

Eric Dumazet <edumazet@google.com>
    net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync

Shengjiu Wang <shengjiu.wang@nxp.com>
    ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count

Tiezhu Yang <yangtiezhu@loongson.cn>
    LoongArch: BPF: Fix off-by-one error in tail call

Tiezhu Yang <yangtiezhu@loongson.cn>
    LoongArch: BPF: Fix outdated tail call comments

谢致邦 (XIE Zhibang) <Yeking@Red54.com>
    LoongArch: Move struct kimage forward declaration before use

Inochi Amaoto <inochiama@gmail.com>
    net: stmmac: dwmac-spacemit: Fix wrong irq definition

Inochi Amaoto <inochiama@gmail.com>
    net: stmmac: dwmac-spacemit: Fix wrong phy interface definition

Shitalkumar Gandhi <shital.gandhi45@gmail.com>
    net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove

Ruoyu Wang <ruoyuw560@gmail.com>
    net: sungem: fix probe error cleanup

Greg Thelen <gthelen@google.com>
    tools: ynl: build archives with $(AR)

Xiang Mei <xmei5@asu.edu>
    geneve: validate inner network offset in geneve_gro_complete()

Xiang Mei <xmei5@asu.edu>
    geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint

Yun Zhou <yun.zhou@windriver.com>
    net: mvneta: re-enable percpu interrupt on resume

Ratheesh Kannoth <rkannoth@marvell.com>
    octeontx2-af: fix CGX debugfs RVU AF PCI reference leaks

Subbaraya Sundeep <sbhatta@marvell.com>
    octeontx2-af: Validate NIX maximum LFs correctly

Jan Klos <honza.klos@gmail.com>
    net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit

Erni Sri Satya Vennela <ernis@linux.microsoft.com>
    net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0

Daniel Golle <daniel@makrotopia.org>
    net: dsa: mxl862xx: fix use-after-free of DSA ports in crc_err_work

Daniel Golle <daniel@makrotopia.org>
    net: dsa: mxl862xx: avoid unaligned 16-bit access in api_wrap

David Yang <mmyangfl@gmail.com>
    net: dsa: realtek: fix memory leak in rtl8366rb_setup_led()

Haoxiang Li <haoxiang_li2024@163.com>
    rtc: cmos: unregister HPET IRQ handler on probe failure

Fredrik M Olsson <fredrik.m.olsson@axis.com>
    rtc: ds1307: Fix off-by-one issue with wday for rx8130

Huiwen He <hehuiwen@kylinos.cn>
    smb/client: preserve errors from smb2_set_sparse()

Li RongQing <lirongqing@baidu.com>
    ACPI: processor_idle: Mark LPI enter functions as __cpuidle

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    ACPICA: Unbreak tools build after switching over to strscpy_pad()

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    thermal: testing: zone: Flush work items during cleanup

Claudio Imbrenda <imbrenda@linux.ibm.com>
    s390/mm: Fix handling of _PAGE_UNUSED pte bit

Jakub Kicinski <kuba@kernel.org>
    eth: fbnic: fix ordering of heartbeat vs ownership

Fernando Fernandez Mancera <fmancera@suse.de>
    ipv6: fix missing notification for ignore_routes_with_linkdown

Fernando Fernandez Mancera <fmancera@suse.de>
    ipv6: fix state corruption during proxy_ndp sysctl restart

Fernando Fernandez Mancera <fmancera@suse.de>
    ipv6: fix error handling in disable_policy sysctl

Fernando Fernandez Mancera <fmancera@suse.de>
    ipv6: fix error handling in forwarding sysctl

Fernando Fernandez Mancera <fmancera@suse.de>
    ipv6: fix error handling in ignore_routes_with_linkdown sysctl

Fernando Fernandez Mancera <fmancera@suse.de>
    ipv6: fix error handling in disable_ipv6 sysctl

Xin Long <lucien.xin@gmail.com>
    sctp: fix err_chunk memory leaks in INIT handling

Jamal Hadi Salim <jhs@mojatatu.com>
    net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle

Jakub Sitnicki <jakub@cloudflare.com>
    net: lwtunnel: Drop skb metadata before LWT encapsulation

Nicolai Buchwitz <nb@tipi-net.de>
    net: usb: lan78xx: restore VLAN and hash filters after link up

Eric Dumazet <edumazet@google.com>
    veth: fix NAPI leak in XDP enable error path

Meghana Malladi <m-malladi@ti.com>
    net: ti: icssg: Fix XSK zero copy TX during application wakeup

Aleksandrova Alyona <aga@itb.spb.ru>
    net: dsa: sja1105: round up PTP perout pin duration

Eric Dumazet <edumazet@google.com>
    net: do not acquire dev->tx_global_lock in netdev_watchdog_up()

Xiang Mei <xmei5@asu.edu>
    net, bpf: check master for NULL in xdp_master_redirect()

Doehyun Baek <doehyunbaek@gmail.com>
    Docs/driver-api/uio-howto: document mmap_prepare callback

Krzysztof Wilczyński <kwilczynski@kernel.org>
    alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs

Krzysztof Wilczyński <kwilczynski@kernel.org>
    alpha/PCI: Add security_locked_down() check to pci_mmap_resource()

Koichiro Den <den@valinux.co.jp>
    NTB: epf: Fix doorbell bitmask and IRQ vector handling

Koichiro Den <den@valinux.co.jp>
    NTB: epf: Report 0-based doorbell vector via ntb_db_event()

Koichiro Den <den@valinux.co.jp>
    NTB: epf: Make db_valid_mask cover only real doorbell bits

Koichiro Den <den@valinux.co.jp>
    PCI: endpoint: pci-epf-vntb: Exclude reserved slots from db_valid_mask

Oder Chiou <oder_chiou@realtek.com>
    ASoC: rt5575: Use __le32 for SPI burst write address

HyeongJun An <sammiee5311@gmail.com>
    ASoC: SDCA: Validate written enum value in ge_put_enum_double()

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    cpuidle: Allow exit latency to exceed target residency

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nf_conntrack_helper: cap maximum number of expectation at helper registration

Florian Westphal <fw@strlen.de>
    netfilter: nft_ct: expectation timeouts are passed in milliseconds

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nf_conntrack_expect: run expectation eviction with no helper

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nf_conntrack_expect: store master_tuple in expectation

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nf_conntrack_expect: use conntrack GC to reap expectations

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: conntrack: check NULL when retrieving ct extension

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper

Qingshuang Fu <fuqingshuang@kylinos.cn>
    gpio: davinci: fix IRQ domain leak on devm_kzalloc failure

Florian Westphal <fw@strlen.de>
    netfilter: nft_compat: ebtables emulation must reject non-bridge targets

Runyu Xiao <runyu.xiao@seu.edu.cn>
    netfilter: nft_synproxy: stop bypassing the priv->info snapshot

Lorenzo Bianconi <lorenzo@kernel.org>
    netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()

Fernando Fernandez Mancera <fmancera@suse.de>
    netfilter: nf_conncount: prevent connlimit drops for early confirmed ct

Mathias Krause <minipli@grsecurity.net>
    netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()

Bradley Morgan <include@grrlz.net>
    bpf: Disable xfrm_decode_session hook attachment

Chen Cheng <chencheng@fnnas.com>
    md/raid5: avoid R5_Overlap races while breaking stripe batches

Chen Cheng <chencheng@fnnas.com>
    md/raid5: use stripe state snapshot in break_stripe_batch_list()

Kuniyuki Iwashima <kuniyu@google.com>
    ipv4: fib: Don't ignore error route in local/main tables.

Jakub Kicinski <kuba@kernel.org>
    eth: bnxt: improve the timing of stats

Xiang Mei <xmei5@asu.edu>
    ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().

Gil Portnoy <dddhkts1@gmail.com>
    ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE

Yiyang Chen <chenyy23@mails.tsinghua.edu.cn>
    selftests/bpf: Cover small conntrack opts error writes

Yiyang Chen <chenyy23@mails.tsinghua.edu.cn>
    bpf: Guard conntrack opts error writes

Stepan Ionichev <sozdayvek@gmail.com>
    rtc: msc313: fix NULL deref in shared IRQ handler at probe

Dima Ruinskiy <dima.ruinskiy@intel.com>
    e1000e: Reconfigure PLL clock gate timeout and re-enable K1 on Meteor Lake

Mohamed Khalfella <mkhalfella@purestorage.com>
    i40e: Fix i40e_debug() to use struct i40e_hw argument

ZhaoJinming <zhaojinming@uniontech.com>
    ice: dpll: fix memory leak in ice_dpll_init_info error paths

ZhaoJinming <zhaojinming@uniontech.com>
    ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info

John Madieu <john.madieu.xa@bp.renesas.com>
    rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on cleanup

Marcin Szycik <marcin.szycik@intel.com>
    ice: call netif_keep_dst() once when entering switchdev mode

Lukasz Czapnik <lukasz.czapnik@intel.com>
    ice: fix AQ error code comparison in ice_set_pauseparam()

Dawid Osuchowski <dawid.osuchowski@linux.intel.com>
    ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()

Nuoqi Gui <gnq25@mails.tsinghua.edu.cn>
    bpf: Preserve pointer spill metadata during half-slot cleanup

Koichiro Den <den@valinux.co.jp>
    PCI: endpoint: pci-epf-vntb: Report 0-based doorbell vector via ntb_db_event()

Koichiro Den <den@valinux.co.jp>
    PCI: endpoint: pci-epf-vntb: Defer pci_epc_raise_irq() out of atomic context

Koichiro Den <den@valinux.co.jp>
    PCI: endpoint: pci-epf-vntb: Document legacy MSI doorbell offset

Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
    PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0

Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
    PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0

Ahmad Fatoum <a.fatoum@pengutronix.de>
    ASoC: cs530x: Fix expected MCLK rates for CS5302/4/8

Zhan Xusheng <zhanxusheng@xiaomi.com>
    erofs: handle 48-bit blocks_hi for compressed inodes

Xiang Mei <xmei5@asu.edu>
    drm/edid: fix OOB read in drm_parse_tiled_block()

Ruoyu Wang <ruoyuw560@gmail.com>
    gpiolib: initialize return value in gpiochip_set_multiple()

Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
    power: sequencing: fix ABBA deadlock in pwrseq_device_unregister()

Amery Hung <ameryhung@gmail.com>
    bpf: Fix effective prog array index with BPF_F_PREORDER

Thiébaud Weksteen <tweek@google.com>
    bpf: Fix BPF_PROG_ASSOC_STRUCT_OPS last field check

Avinash Duduskar <avinash.duduskar@gmail.com>
    bpf: zero-initialize the fib lookup flow struct

Yichong Chen <chenyichong@uniontech.com>
    bpftool: Fix vmlinux BTF leak in cgroup commands

Sun Jian <sun.jian.kdev@gmail.com>
    bpf: Fix partial copy of non-linear test_run output

Nuoqi Gui <gnq25@mails.tsinghua.edu.cn>
    bpf: Fix stack slot index in nospec checks

Ronan Dalton <ronan.dalton@alliedtelesis.co.nz>
    rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231

Antoni Pokusinski <apokusinski01@gmail.com>
    rtc: abx80x: fix the RTC_VL_CLR clearing all status flags

Ioana Ciornei <ioana.ciornei@nxp.com>
    dpaa2-switch: do not accept VLAN uppers while bridged

Jiayuan Chen <jiayuan.chen@linux.dev>
    ipv6: ioam: fix type confusion of dst_entry

Weiming Shi <bestswngs@gmail.com>
    ipv6: ndisc: fix NULL deref in accept_untracked_na()

Wayen Yan <win847@gmail.com>
    net: airoha: Fix skb->priority underflow in airoha_dev_select_queue()

Michael Bommarito <michael.bommarito@gmail.com>
    net/sched: act_ct: fix nf_connlabels leak on two error paths

Rosen Penev <rosenp@gmail.com>
    net: emac: Fix NULL pointer dereference in emac_probe

Geetha sowjanya <gakula@marvell.com>
    octeontx2-pf: mcs: Fix mcs resources free on PF shutdown

Subbaraya Sundeep <sbhatta@marvell.com>
    octeontx2-pf: Clear stats of all resources when freeing resources

Geetha sowjanya <gakula@marvell.com>
    octeontx2-af: mcs: Fix unsupported secy stats read

Ratheesh Kannoth <rkannoth@marvell.com>
    octeontx2-af: npc: cn20k: fix NPC defrag

Wayen Yan <win847@gmail.com>
    net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths

Ilya Maximets <i.maximets@ovn.org>
    net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone

Weiming Shi <bestswngs@gmail.com>
    tipc: fix use-after-free of the discoverer in tipc_disc_rcv()

Ruoyu Wang <ruoyuw560@gmail.com>
    net: marvell: prestera: initialize err in prestera_port_sfp_bind

Aboorva Devarajan <aboorvad@linux.ibm.com>
    selftests/mm: fix exclusive_cow test fork() handling

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: remove hardcoded THP sizing assumptions in hmm tests

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: allow PUD-level entries in compound testcase of hmm tests

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: clarify alternate unmapping in compaction_test

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: move hwpoison setup into run_test() and silence modprobe output for memory-failure category

Mike Rapoport (Microsoft) <rppt@kernel.org>
    selftests/mm: run_vmtests.sh: free memory if available memory is low

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap

Sayali Patil <sayalip@linux.ibm.com>
    selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: free dynamically allocated PMD-sized buffers in split_huge_page_test

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: size tmpfs according to PMD page size in split_huge_page_test

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: fix cgroup task placement and drop memory.current checks in hugetlb_reparenting_test.sh

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: fix hugetlb pathname construction in hugetlb_reparenting_test.sh

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: restore default nr_hugepages value via exit trap in hugetlb_reparenting_test.sh

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: fix hugetlb pathname construction in charge_reserved_hugetlb.sh

Sayali Patil <sayalip@linux.ibm.com>
    selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh

Hao Ge <hao.ge@linux.dev>
    alloc_tag: fix use-after-free in /proc/allocinfo after module unload

Bhargav Joshi <j.bhargav.u@gmail.com>
    irqchip/crossbar: Fix parent domain resource leak

Sebastian Andrzej Siewior <bigeasy@linutronix.de>
    mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    tpm_crb: Check ACPI_COMPANION() against NULL during probe

Florian Westphal <fw@strlen.de>
    netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak

Florian Westphal <fw@strlen.de>
    netfilter: nf_reject: skip iphdr options when looking for icmp header

Florian Westphal <fw@strlen.de>
    netfilter: nft_flow_offload: zero device address for non-ether case

Florian Westphal <fw@strlen.de>
    netfilter: nft_meta_bridge: add validate callback for get operations

Florian Westphal <fw@strlen.de>
    netfilter: nft_payload: reject offsets exceeding 65535 bytes

Jozsef Kadlecsik <kadlec@netfilter.org>
    netfilter: ipset: make sure gc is properly stopped

Jozsef Kadlecsik <kadlec@netfilter.org>
    netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()

Jozsef Kadlecsik <kadlec@netfilter.org>
    netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap types

Jozsef Kadlecsik <kadlec@netfilter.org>
    netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types

Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
    md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry

Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
    md/raid1: honor REQ_NOWAIT when waiting for behind writes

Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
    md/raid10: fix writes_pending and barrier reference leaks on discard failures

Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
    md/raid10: fix writes_pending leak on write request failures

Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
    md/raid1: fix writes_pending and barrier reference leaks on write failures

Robertus Diawan Chris <robertusdchris@gmail.com>
    mac802154: Prevent overwrite return code in mac802154_perform_association()

Aleksandr Nogikh <nogikh@google.com>
    ieee802154: fix kernel-infoleak in dgram_recvmsg()

Ivan Abramov <i.abramov@mt-integration.ru>
    ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()

Ivan Abramov <i.abramov@mt-integration.ru>
    ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()

Ivan Abramov <i.abramov@mt-integration.ru>
    ieee802154: Restore initial state on failed device_rename() in cfg802154_switch_netns()

Xu Rao <raoxu@uniontech.com>
    ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()

Andy Shevchenko <andriy.shevchenko@linux.intel.com>
    ACPI: resource: Amend kernel-doc style

Ricardo Neri <ricardo.neri-calderon@linux.intel.com>
    thermal: intel: Fix dangling resources on thermal_throttle_online() failure

Breno Leitao <leitao@debian.org>
    arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS

Arnd Bergmann <arnd@arndb.de>
    arm64: static_call: include asm/insns.h

Lorenzo Bianconi <lorenzo@kernel.org>
    netfilter: flowtable: fix and simplify IP6IP6 tunnel handling

Cen Zhang <zzzccc427@gmail.com>
    ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints

Daniel Zahka <daniel.zahka@gmail.com>
    eth: fbnic: take netif_addr_lock_bh() around rx mode address programming

Ido Schimmel <idosch@nvidia.com>
    selftests: vlan_bridge_binding: Fix flaky operational state check

Breno Leitao <leitao@debian.org>
    netconsole: don't drop the last byte of a full-sized message

Yun Zhou <yun.zhou@windriver.com>
    flow_dissector: check device type before reading ETH_ADDRS

Lukasz Raczylo <lukasz@raczylo.com>
    net: macb: add TX stall timeout callback to recover from lost TSTART write

Wayen Yan <win847@gmail.com>
    net: airoha: fix foe_check_time allocation size

Cosmin Ratiu <cratiu@nvidia.com>
    devlink: Fix parent ref leak on tc-bw failure

Cosmin Ratiu <cratiu@nvidia.com>
    devlink: Fix parent ref leak in devl_rate_node_create()

Ioana Ciornei <ioana.ciornei@nxp.com>
    dpaa2-switch: fix VLAN upper check not rejecting bridge join

Xiang Mei <xmei5@asu.edu>
    virtio-net: fix len check in receive_big()

Quang Nguyen <quang.nguyen.wx@renesas.com>
    spi: rpc-if: Use correct device for hardware reinitialization on resume

Mark Tomlinson <mark.tomlinson@alliedtelesis.co.nz>
    PCI: iproc: Restore .map_irq() for the platform bus driver

Michael Bommarito <michael.bommarito@gmail.com>
    ALSA: usb-audio: qcom: clear opened when stream enable fails

Michael Bommarito <michael.bommarito@gmail.com>
    ALSA: usb-audio: qcom: reject stream disable with no active interface

Xin Long <lucien.xin@gmail.com>
    sctp: hold socket lock when dumping endpoints in sctp_diag

Jakub Kicinski <kuba@kernel.org>
    net: psample: fix info leak in PSAMPLE_ATTR_DATA

Ratheesh Kannoth <rkannoth@marvell.com>
    octeontx2-af: npc: Log successful MCAM drop-on-non-hit install at debug level

Ratheesh Kannoth <rkannoth@marvell.com>
    octeontx2-pf: Fix leak of SQ timestamp buffer on teardown

Tianchen Ding <dtcccc@linux.alibaba.com>
    selftests/ftrace: Fix trace_marker_raw test on 64K page kernels

Christian Marangi <ansuelsmth@gmail.com>
    net: ethernet: mtk_eth_soc: fix supported_interface set after phylink_create

Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
    drm/amdgpu: initialize irq.lock spinlock earlier

Mario Limonciello <mario.limonciello@amd.com>
    drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm

Matthew Schwartz <matthew.schwartz@linux.dev>
    drm/amd/display: Fix mem_type change detection for async flips

Roman Li <Roman.Li@amd.com>
    drm/amd/display: Skip PHY SSC reduction on some 8K panels

Qiang Yu <Qiang.Yu@amd.com>
    drm/amdgpu: initialize iter.start in amdgpu_devcoredump_format

Yunxiang Li <Yunxiang.Li@amd.com>
    drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free

Sen Wang <sen@ti.com>
    ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf dso: Set standard errno on decompression failure

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf bpf: Validate array presence before casting BPF prog info pointers

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf c2c: Fix hist entry and format list leaks in c2c_he_free()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf c2c: Free format list entries when c2c_hists__init() fails

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf cs-etm: Bounds-check CPU in cs_etm__get_queue()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf cs-etm: Require full global header in auxtrace_info size check

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf cs-etm: Validate num_cpu before metadata allocation

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf machine: Use snprintf() for guestmount path construction

Eric Dumazet <edumazet@google.com>
    xfrm: validate selector family and prefixlen during match

Eric Dumazet <edumazet@google.com>
    xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[]

Herbert Xu <herbert@gondor.apana.org.au>
    xfrm: Fix xfrm state cache insertion race

Xu Rao <raoxu@uniontech.com>
    ALSA: usb-audio: qcom: Free sideband sg_table objects

Gao Xiang <xiang@kernel.org>
    erofs: call erofs_exit_ishare() before rcu_barrier()

Adrian Hunter <adrian.hunter@intel.com>
    i3c: master: Add missing runtime PM get in dev_nack_retry_count_store()

Adrian Hunter <adrian.hunter@intel.com>
    i3c: master: Update dev_nack_retry_count under maintenance lock

Jisheng Zhang <jszhang@kernel.org>
    spi: dw: fix wrong BAUDR setting after resume

Thomas Hellström <thomas.hellstrom@linux.intel.com>
    drm/xe: Fix wa_oob codegen recipe for external module builds

Guangshuo Li <lgs201920130244@gmail.com>
    drm/i915: clear CRTC color blob pointers after dropping refs

Francesco Lavra <flavra@baylibre.com>
    regcache: Do not overwrite error code when finalizing cache after error

Pengpeng Hou <pengpeng@iscas.ac.cn>
    gpio: mlxbf3: fail probe if gpiochip registration fails

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf cs-etm: Reject CPU IDs that would overflow signed comparison

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf c2c: Free format list entries when releasing c2c hist entries

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf bpf: Bounds-check array offsets in bpil_offs_to_addr()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf bpf: Reject oversized BPF metadata events that truncate header.size

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf bpf: Validate func_info_rec_size and sub_id in synthesize_bpf_prog_name()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Replace (void*)1 sentinel with proper runtime allocation

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Use snprintf() for root_dir path construction

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf dso: Set error code when open() fails on uncompressed fallback path

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf dso: Fix heap overflow in dso__get_filename() on decompressed path

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf symbols: Break infinite loop on zero-filled notes in sysfs__read_build_id()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf symbols: Validate p_filesz before use in filename__read_build_id()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz

Ian Rogers <irogers@google.com>
    perf maps: Add maps__mutate_mapping

Pengpeng Hou <pengpeng@iscas.ac.cn>
    sparc: led: avoid trimming a newline from empty writes

Karol Wachowski <karol.wachowski@linux.intel.com>
    accel/ivpu: fix HWS command queue leak on registration failure

John Johansen <john.johansen@canonical.com>
    apparmor: fix label can not be immediately before a declaration

Adrian Hunter <adrian.hunter@intel.com>
    i3c: master: Prevent reuse of dynamic address on device add failure

Adrian Hunter <adrian.hunter@intel.com>
    i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()

Adrian Hunter <adrian.hunter@intel.com>
    i3c: master: Defer new-device registration out of DAA caller context

Adrian Hunter <adrian.hunter@intel.com>
    i3c: master: Ensure Hot-Join operations are stopped on shutdown

Adrian Hunter <adrian.hunter@intel.com>
    i3c: master: Consolidate Hot-Join DAA work in the core

Adrian Hunter <adrian.hunter@intel.com>
    i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock

Adrian Hunter <adrian.hunter@intel.com>
    i3c: master: Make hot-join workqueue freezable to block hot-join during suspend

Adrian Hunter <adrian.hunter@intel.com>
    i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring

Adrian Hunter <adrian.hunter@intel.com>
    i3c: mipi-i3c-hci: Fix suspend behavior when bus disable falls back to software reset

Eduardo Vasconcelos <eduardo@eduardovasconcelos.com>
    apparmor: Fix inverted comparison in cache_hold_inc()

Maciek Borzecki <maciek.borzecki@gmail.com>
    apparmor: fix uninitialised pointer passed to audit_log_untrustedstring()

Georgia Garcia <georgia.garcia@canonical.com>
    apparmor: don't audit files pointing to aa_null.dentry

Zygmunt Krynicki <me@zygoon.pl>
    apparmor: put secmark label after secid lookup

Zygmunt Krynicki <me@zygoon.pl>
    apparmor: aa_getprocattr free procattr leak on format failure

John Johansen <john.johansen@canonical.com>
    apparmor: remove unnecessary goto and associated label

Zygmunt Krynicki <me@zygoon.pl>
    apparmor: release exe file resources on path failure

Zygmunt Krynicki <me@zygoon.pl>
    apparmor: fail policy unpack on accept2 allocation failure

Hongling Zeng <zenghongling@kylinos.cn>
    apparmor: Fix return in ns_mkdir_op

Georgia Garcia <georgia.garcia@canonical.com>
    apparmor: remove or add symlinks to rawdata according to export_binary

Georgia Garcia <georgia.garcia@canonical.com>
    apparmor: fix NULL pointer dereference in unpack_pdb

Maxime Bélair <maxime.belair@canonical.com>
    apparmor: fix potential UAF in aa_replace_profiles

Ryan Lee <ryan.lee@canonical.com>
    apparmor: grab ns lock and refresh when looking up changehat child profiles

John Johansen <john.johansen@canonical.com>
    apparmor: fix rawdata_f_data implicit flex array

Zygmunt Krynicki <me@zygoon.pl>
    apparmor: aa_label_alloc use aa_label_free on alloc failure

Ruoyu Wang <ruoyuw560@gmail.com>
    apparmor: check label build before no_new_privs test

Andrew Morton <akpm@linux-foundation.org>
    security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref()

John Johansen <john.johansen@canonical.com>
    apparmor: fix refcount leak when updating the sk_ctx

John Johansen <john.johansen@canonical.com>
    apparmor: fix race in unix socket mediation when peer_path is used

John Johansen <john.johansen@canonical.com>
    apparmor: fix shadowing of plabel that prevents cache from being updated

Yuanhe Shu <xiangzao@linux.alibaba.com>
    Revert "PCI/MSI: Unmap MSI-X region on error"

Randy Dunlap <rdunlap@infradead.org>
    Documentation: ABI: sysfs-class-reboot-mode-reboot_modes: fix doc warnings

Thomas Weißschuh <linux@weissschuh.net>
    sparc: Avoid -Wunused-but-set-parameter in clear_user_page()

Dong Chenchen <dongchenchen2@huawei.com>
    xfrm: Fix dev use-after-free in xfrm async resumption

Shuvam Pandey <shuvampandey1@gmail.com>
    PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability

Felix Gu <ustc.gu@gmail.com>
    phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing pm_runtime_disable() on probe error path

Felix Gu <ustc.gu@gmail.com>
    phy: freescale: phy-fsl-imx8qm-lvds-phy: Use synchronous PM runtime put in reset

Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
    PCI: mediatek: Use actual physical address instead of virt_to_phys()

Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
    dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on Purwa

Inochi Amaoto <inochiama@gmail.com>
    dt-bindings: dma: snps,dw-axi-dmac: Add fallback compatible for CV1800B

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf symbols: Add bounds checks to read_build_id() note iteration in minimal build

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf symbols: Add bounds checks to elf_read_build_id() note iteration

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate insert

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf bpf: Add NULL check for btf__type_by_id() in synthesize_bpf_prog_name()

Arnaldo Carvalho de Melo <acme@redhat.com>
    tools lib api: Fix mount_overload() snprintf truncation and toupper range

Arnaldo Carvalho de Melo <acme@redhat.com>
    tools lib api: Fix filename__write_int() writing uninitialized stack data

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Use snprintf() in dso__read_running_kernel_build_id()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf hwmon: Guard label read against empty or failed reads

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Fix uninitialized pathname on uncompressed fallback in filename__decompress()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf hwmon: Fix off-by-one null termination on sysfs reads

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Fix thread__set_comm_from_proc() on empty comm file

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf intel-pt: Fix snprintf size tracking bug in insn decoder

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Use mkostemp() for O_CLOEXEC on temporary files

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf symbols: Bounds-check .gnu_debuglink section data

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf symbols: Fix signed overflow in sysfs__read_build_id() size check

Arnaldo Carvalho de Melo <acme@redhat.com>
    tools lib api: Fix missing null termination in filename__read_int/ull()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs file

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf pmu: Fix pmu_id() heap underwrite on empty identifier file

James Clark <james.clark@linaro.org>
    perf cs-etm: Queue context packets for frontend

Tanushree Shah <tshah@linux.ibm.com>
    perf data convert json: Fix addr_location leak on time-filtered samples

Jens Remus <jremus@linux.ibm.com>
    perf s390: Fix TEXTREL in Python extension by compiling as PIC

Chuck Lever <chuck.lever@oracle.com>
    xprtrdma: Return sendctx slot after Send preparation failure

Chuck Lever <chuck.lever@oracle.com>
    xprtrdma: Repost Receive buffers for malformed replies

Chuck Lever <chuck.lever@oracle.com>
    xprtrdma: Sanitize the reply credit grant after parsing

Chris Mason <clm@meta.com>
    xprtrdma: Fix bcall rep leak and unbounded peek

Chuck Lever <chuck.lever@oracle.com>
    xprtrdma: Resize reply buffers before reposting receives

Chuck Lever <chuck.lever@oracle.com>
    xprtrdma: Document and assert reply-handler invariants

Chuck Lever <chuck.lever@oracle.com>
    xprtrdma: Check frwr_wp_create() during connect

Chris Mason <clm@meta.com>
    xprtrdma: Initialize re_id before removal registration

Chris Mason <clm@meta.com>
    xprtrdma: Fix ep kref imbalance on ADDR_CHANGE

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Use scnprintf() in build_id__snprintf() and hwmon read_events()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Fix idle-hist callchain display using wrong rb_first variant

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Bounds-check prio before test_bit() in timehist

Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
    PCI: rcar-host: Remove unused LIST_HEAD(res)

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: NULL bitmap pointers after bitmap_free()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Use perf_env__get_cpu_topology() in machine__resolve()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Fix get_max_num() size_t underflow on empty sysfs file

David E. Box <david.e.box@linux.intel.com>
    platform/x86/intel/vsec: Restore BAR fallback for header walk

Jamie Nguyen <jamien@nvidia.com>
    fs/ntfs3: resize log->one_page_buf when adopting on-disk page size

Edward Adam Davis <eadavis@qq.com>
    fs/ntfs3: prevent potential lcn remains uninitialized

Christian Fontanez <christfontanez@gmail.com>
    virtio: add missing kernel-doc for map and vmap members

Chuck Lever <chuck.lever@oracle.com>
    lockd: Correct kernel-doc status descriptions for NLMv4 GRANTED

Shuvam Pandey <shuvampandey1@gmail.com>
    PCI: meson: Add missing remove callback

Shuvam Pandey <shuvampandey1@gmail.com>
    PCI: meson: Propagate devm_add_action_or_reset() failure

Biju Das <biju.das.jz@bp.renesas.com>
    pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages

Li RongQing <lirongqing@baidu.com>
    PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro

Yang Erkun <yangerkun@huawei.com>
    nfs: use nfsi->rwsem to protect traversal of the file lock list

Mike Snitzer <snitzer@kernel.org>
    NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write

Mike Snitzer <snitzer@kernel.org>
    NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors

Clark Wang <xiaoning.wang@nxp.com>
    nfs: keep PG_UPTODATE clear after read errors in page groups

Dai Ngo <dai.ngo@oracle.com>
    NFSv4/pnfs: defer return_range callbacks until after inode unlock

Chuck Lever <chuck.lever@oracle.com>
    xprtrdma: Decouple req recycling from RPC completion

Chuck Lever <chuck.lever@oracle.com>
    xprtrdma: Use sendctx DMA state for Send signaling

Sagi Grimberg <sagi@grimberg.me>
    pNFS/filelayout: fix cheking if a layout is striped

Hongling Zeng <zenghongling@kylinos.cn>
    sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store()

Phillip Varney <pbvarney@protonmail.com>
    clk: qcom: a53: Corrected frequency multiplier for 1152MHz

Nuno Sá <nuno.sa@analog.com>
    dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor

Nuno Sá <nuno.sa@analog.com>
    dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc

Nuno Sá <nuno.sa@analog.com>
    dmaengine: Fix possible use after free

Icenowy Zheng <zhengxingda@iscas.ac.cn>
    dmaengine: qcom: gpi: set DMA_PRIVATE capability

Junrui Luo <moonafterrain@outlook.com>
    mshv: add bounds check on vp_index in mshv_intercept_isr()

Pratyush Yadav (Google) <pratyush@kernel.org>
    docs: memfd_preservation: fix rendering of ABI documentation

Jagadeesh Kona <jagadeesh.kona@oss.qualcomm.com>
    clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks

Jagadeesh Kona <jagadeesh.kona@oss.qualcomm.com>
    dt-bindings: clock: qcom: Add X1P42100 camera clock controller

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Free callchain nodes in idle thread cleanup

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf timechart: Fix cpu2y() OOB read on untrusted CPU index

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf c2c: Fix use-after-free in he__get_c2c_hists() error path

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf mmap: Fix NULL deref in aio cleanup on alloc failure

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Replace BUG_ON and add NULL checks in replay event helpers

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Use thread__put() in free_idle_threads()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Fix thread reference leak in idle hist processing

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Use is_idle_sample() for idle thread runtime cast guard

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Clean up idle_threads entry on init failure

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf c2c: Bounds-check CPU and node IDs before bitmap and array access

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf stat: Bounds-check CPU index in topology aggregation callbacks

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf mmap: Guard cpu__get_node() return in aio_bind()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Fix register_pid() overflow, strcpy, and BUG_ON

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Fix thread reference leaks in timehist_get_thread()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Add bounds check to cpu__get_node()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Guard remaining test_bit calls from OOB sample CPU

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Fix comp_cpus heap overflow with cross-machine recordings

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Fix NULL dereference in latency_runtime_event

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Replace BUG_ON on invalid CPU with graceful skip

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf sched: Fix thread reference leak in latency_switch_event

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf tools: Guard test_bit from out-of-bounds sample CPU

James Clark <james.clark@linaro.org>
    perf annotate: Fix crashes on empty annotate windows

Rui Qi <qirui.001@bytedance.com>
    perf: Fix off-by-one stack buffer overflow in kallsyms__parse()

Akhil R <akhilrajeev@nvidia.com>
    dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional

Shengjiu Wang <shengjiu.wang@nxp.com>
    dmaengine: imx-sdma: Refine spba bus searching in probe

Xu Rao <raoxu@uniontech.com>
    thunderbolt: debugfs: Fix margining error counter buffer leak

Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>
    drm/amd/display: Add missing kdoc for ALLM parameters

Jamie Nguyen <jamien@nvidia.com>
    fs/ntfs3: fix mount failure on 64K page-size kernels

Arnd Bergmann <arnd@arndb.de>
    ntfs3: avoid another -Wmaybe-uninitialized warning

Mihai Brodschi <m.brodschi@gmail.com>
    ntfs3: Allocate iomap inline_data using alloc_page

Helen Koike <koike@igalia.com>
    fs/ntfs3: call _ntfs_bad_inode() when failing to rename

Zhan Xusheng <zhanxusheng1024@gmail.com>
    fs/ntfs3: fix wrong LCN in run_remove_range() when splitting a run

Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
    fs/ntfs3: add bounds check to run_get_highest_vcn()

Yixun Lan <dlan@kernel.org>
    clk: spacemit: k3: Fix PCIe clock register offset

Yixun Lan <dlan@kernel.org>
    clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock

Zhan Xusheng <zhanxusheng1024@gmail.com>
    docs: changes.rst: restore pahole 1.26 minimum (regressed by sort)

Rosen Penev <rosenp@gmail.com>
    HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter

Yuho Choi <dbgh9129@gmail.com>
    clk: at91: keep securam node alive while mapping it

Aldo Conte <aldocontelk@gmail.com>
    iio: tcs3472: power down chip on probe failure

Sanjay Chitroda <sanjayembeddedse@gmail.com>
    iio: accel: mma8452: handle I2C read error(s) in mma8452_read()

Guilherme Ivo Bozi <guilherme.bozi@usp.br>
    iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling

Joshua Crofts <joshua.crofts1@gmail.com>
    iio: magnetometer: ak8975: fix potential kernel stack memory leak

Joshua Crofts <joshua.crofts1@gmail.com>
    iio: light: si1133: prevent race condition on timeout

Joshua Crofts <joshua.crofts1@gmail.com>
    iio: light: si1133: reset counter to prevent race condition

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf header: Validate bitmap size before allocating in do_read_bitmap()

Arnaldo Carvalho de Melo <acme@redhat.com>
    perf header: Sanity check HEADER_EVENT_DESC attr.size before swap

Zhan Xusheng <zhanxusheng@xiaomi.com>
    timers/migration: Update stale @online doc to @available

Shawn Guo <shengchao.guo@oss.qualcomm.com>
    PCI: qcom: Disable ASPM L0s for SA8775P

Athira Rajeev <atrajeev@linux.ibm.com>
    powerpc tools perf: Initialize error code in auxtrace_record_init function

Baruch Siach <baruch@tkos.co.il>
    docs: threat-model: add missing closing parenthesis

Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
    clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing

Hongling Zeng <zenghongling@kylinos.cn>
    gpib: cb7210: Fix region leak when request_irq fails

Adam Crosser <adam.crosser@praetorian.com>
    gpib: fix double decrement of descriptor_busy in command_ioctl()

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    sonypi: Check ACPI_COMPANION() against NULL at probe time

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    hpet: Check ACPI_COMPANION() against NULL at probe time

James Kim <james010kim@gmail.com>
    char: tlclk: fix use-after-free in tlclk_cleanup()

Dave Penkler <dpenkler@gmail.com>
    gpib: Fix inappropriate ioctl error return

Ravi Bangoria <ravi.bangoria@amd.com>
    perf test amd ibs: Fix incorrect kernel version check

Seungjin Bae <eeodqql09@gmail.com>
    usb: host: max3421: Reject hub port requests for non-existent ports

Seungjin Bae <eeodqql09@gmail.com>
    usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()

Guangshuo Li <lgs201920130244@gmail.com>
    staging: most: video: avoid double free on video register failure

Ian Rogers <irogers@google.com>
    perf inject: Fix itrace branch stack synthesis

Ian Rogers <irogers@google.com>
    perf event: Fix size of synthesized sample with branch stacks

Michael Petlan <mpetlan@redhat.com>
    perf build-id: Fix off-by-one bug when printing kernel/module build-id

Conor Dooley <conor.dooley@microchip.com>
    clk: microchip: mpfs-ccc: fix peripheral driver registration failures after oob fix

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    platform/x86: classmate-laptop: Address memory leaks on driver removal

Chen-Yu Tsai <wenst@chromium.org>
    PCI: mediatek-gen3: Fix incorrectly skipped pwrctrl error message

Dan Carpenter <error27@gmail.com>
    PCI: dwc: Fix signedness bug in fault injection test code

Jie Gan <jie.gan@oss.qualcomm.com>
    coresight: platform: defer connection counter increment until alloc succeeds

Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
    PCI/pwrctrl: Lock device when calling device_is_bound()

Wolfram Sang <wsa+renesas@sang-engineering.com>
    mailbox: don't free the channel if the startup callback failed

Sergey Senozhatsky <senozhatsky@chromium.org>
    mailbox: mtk-adsp: fix UAF during device teardown

Conor Dooley <conor.dooley@microchip.com>
    mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr()

Chen-Yu Tsai <wenst@chromium.org>
    PCI: mediatek-gen3: Do full device power down on removal

Leo Yan <leo.yan@arm.com>
    coresight: Handle helper enable failure properly

Jie Gan <jie.gan@oss.qualcomm.com>
    coresight: Fix source not disabled on idr_alloc_u32 failure

Bard Liao <yung-chuan.liao@linux.intel.com>
    soundwire: intel_ace2x: release bpt_stream when close it

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    iio: light: acpi-als: Check ACPI_COMPANION() against NULL

Mihai Sain <mihai.sain@microchip.com>
    clk: at91: sam9x7: Fix gmac_gclk clock definition

Leo Yan <leo.yan@arm.com>
    perf pmu: Skip test on Arm64 when #slots is zero

Ian Rogers <irogers@google.com>
    perf unwind: Refactor get_entries to allow dynamic libdw/libunwind selection

Ian Rogers <irogers@google.com>
    perf pmu-events AMD: Switch l2_itlb_misses to bp_l1_tlb_miss_l2_tlb_miss.all

Andy Shevchenko <andriy.shevchenko@linux.intel.com>
    phy: phy-can-transceiver: Check driver match and driver data against NULL

Qiang Yu <qiang.yu@oss.qualcomm.com>
    PCI: qcom: Set max OPP before DBI access during resume

Manikanta Maddireddy <mmaddireddy@nvidia.com>
    PCI: dwc: Apply ECRC workaround for DesignWare cores prior to 5.10a

Biswapriyo Nath <nathbappai@gmail.com>
    dt-bindings: clock: qcom,sm6125-dispcc: reference qcom,gcc.yaml

Luo Jie <jie.luo@oss.qualcomm.com>
    clk: qcom: cmnpll: Account for reference clock divider

Jie Gan <jie.gan@oss.qualcomm.com>
    coresight: fix missing error code when trace ID is invalid

Sumit Kumar <sumit.kumar@oss.qualcomm.com>
    bus: mhi: ep: Add missing state_lock protection for mhi_state access

Sumit Kumar <sumit.kumar@oss.qualcomm.com>
    bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()

Hsiu Che Yu <yu.whisper.personal@gmail.com>
    rust: alloc: fix assert in `Vec::reserve` doc test

Rong Zhang <i@rong.moe>
    PCI: loongson: Do not ignore downstream devices on external bridges

Florian Eckert <fe@dev.tdt.de>
    PCI: intel-gw: Add .start_link() callback

Florian Eckert <fe@dev.tdt.de>
    PCI: intel-gw: Enable clock before PHY init

Florian Eckert <fe@dev.tdt.de>
    PCI: intel-gw: Move interrupt enable to own function

Ian Rogers <irogers@google.com>
    perf tool: Fix missing schedstat delegates and dont_split_sample_group in delegate_tool

Ian Rogers <irogers@google.com>
    perf sched: Add missing mmap2 handler in timehist

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    platform/x86: xo15-ebook: Fix wakeup source and GPE handling

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    x86/platform/olpc: xo15: Drop wakeup source on driver removal

Guixin Liu <kanie@linux.alibaba.com>
    PCI: Check ROM header and data structure addr before accessing

Guixin Liu <kanie@linux.alibaba.com>
    PCI: Introduce named defines for PCI ROM

Carlos Bilbao <carlos.bilbao@kernel.org>
    PCI/ASPM: Don't reconfigure ASPM entering low-power state

Leo Yan <leo.yan@arm.com>
    coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore

James Clark <james.clark@linaro.org>
    coresight: ete: Always save state on power down

Leo Yan <leo.yan@arm.com>
    coresight: tmc: Fix overflow when calculating is bigger than 2GiB

Baoli.Zhang <baoli.zhang@linux.intel.com>
    soundwire: fix bug in sdw_add_element_group_count found by syzkaller

Bard Liao <yung-chuan.liao@linux.intel.com>
    soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral

Yingchao Deng <yingchao.deng@oss.qualcomm.com>
    coresight: cti: Fix DT filter signals silently ignored

Thomas Richter <tmricht@linux.ibm.com>
    perf callchain: Handle multiple address spaces

Ian Rogers <irogers@google.com>
    perf debuginfo: Fix libdw API contract violations

Ian Rogers <irogers@google.com>
    perf annotate-data: Fix libdw API contract violations

Ian Rogers <irogers@google.com>
    perf probe-finder: Fix libdw API contract violations

Ian Rogers <irogers@google.com>
    perf libdw: Fix libdw API contract violations and memory leaks

Ian Rogers <irogers@google.com>
    perf dwarf-aux: Fix libdw API contract violations

Ian Rogers <irogers@google.com>
    perf dwarf-aux: Fix libdw segmentation fault in cu_walk_functions_at

Alexandru Hossu <hossu.alexandru@gmail.com>
    staging: nvec: fix use-after-free in nvec_rx_completed()

Maksym Pikhotskyi <mpikhotskyi@gmail.com>
    staging: rtl8723bs: fix stainfo check in rtw_aes_decrypt

Stanley Chu <yschu@nuvoton.com>
    i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845

Mario Limonciello <mario.limonciello@amd.com>
    gpiolib: acpi: Only trigger ActiveBoth interrupts on boot

Nam Cao <namcao@linutronix.de>
    eventpoll: Fix epoll_wait() report false negative

Christian Brauner <brauner@kernel.org>
    eventpoll: rename epi->next and txlist for clarity

Christian Brauner <brauner@kernel.org>
    eventpoll: expand top-of-file overview / locking doc

Gui-Dong Han <hanguidong02@gmail.com>
    9p: Add missing read barrier in virtio zero-copy path

Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
    net/9p: fix race condition on rdma->state in trans_rdma.c

Hongling Zeng <zenghongling@kylinos.cn>
    9p: avoid returning ERR_PTR(0) from mkdir operations

Aleksandr Nogikh <nogikh@google.com>
    ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write

Charles Keepax <ckeepax@opensource.cirrus.com>
    mfd: cs42l43: Sanity check firmware size

Matthew Bystrin <dev.mbstr@gmail.com>
    mfd: rsmu: Fix page register setup

Matti Vaittinen <mazziesaccount@gmail.com>
    mfd: bd72720: Drop BUCK11 ID

Guangshuo Li <lgs201920130244@gmail.com>
    ksmbd: fix use-after-free in same_client_has_lease()

Eric Dumazet <edumazet@google.com>
    net: serialize netif_running() check in enqueue_to_backlog()

Jacob Moroni <jmoroni@google.com>
    RDMA/irdma: Replace waitqueue and flag with completion

Junxian Huang <huangjunxian6@hisilicon.com>
    RDMA/hns: Fix memory leak of bonding resources

Selvin Xavier <selvin.xavier@broadcom.com>
    RDMA/bnxt_re: Reject GET_TOGGLE_MEM when toggle page was not allocated

Selvin Xavier <selvin.xavier@broadcom.com>
    RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled

Selvin Xavier <selvin.xavier@broadcom.com>
    RDMA/bnxt_re: Avoid repeated requests to allocate WC pages

Selvin Xavier <selvin.xavier@broadcom.com>
    RDMA/bnxt_re: Proper rollback if the ioremap fails

Selvin Xavier <selvin.xavier@broadcom.com>
    RDMA/bnxt_re: Add a max slot check for SQ

Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
    RDMA/bnxt_re: Enable app allocated QPs

Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
    RDMA/bnxt_re: Support doorbells for app allocated QPs

Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
    RDMA/bnxt_re: Enhance dbr usecnt logic in doorbell uapis

Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
    RDMA/bnxt_re: Update msn table size for app allocated QPs

Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
    RDMA/bnxt_re: Refactor bnxt_re_init_user_qp()

Selvin Xavier <selvin.xavier@broadcom.com>
    RDMA/bnxt_re: Avoid displaying the kernel pointer

Selvin Xavier <selvin.xavier@broadcom.com>
    RDMA/bnxt_re: Free CQ toggle page after firmware teardown

Selvin Xavier <selvin.xavier@broadcom.com>
    RDMA/bnxt_re: Free SRQ toggle page after firmware teardown

Selvin Xavier <selvin.xavier@broadcom.com>
    RDMA/bnxt_re: Initialize dpi variable to zero

Brett Creeley <brett.creeley@amd.com>
    ionic: Fix check in ionic_get_link_ext_stats

Selvamani Rajagopal <Selvamani.Rajagopal@onsemi.com>
    dt-bindings: net: updated interrupt type to be active low, level triggered

Selvamani Rajagopal <Selvamani.Rajagopal@onsemi.com>
    net: ethernet: oa_tc6: Remove FCS size in RX frame

Selvamani Rajagopal <Selvamani.Rajagopal@onsemi.com>
    net: ethernet: oa_tc6: mdiobus->parent initialized with NULL

Meghana Malladi <m-malladi@ti.com>
    net: ti: icssg: Use undirected TX tag for XDP zero copy in HSR offload mode

Meghana Malladi <m-malladi@ti.com>
    net: ti: icssg: Use undirected TX tag for native XDP in HSR offload mode

Meghana Malladi <m-malladi@ti.com>
    net: ti: icssg-prueth: Fix AF_XDP fill ring alloc and wakeup condition

Wayen.Yan <win847@gmail.com>
    net: airoha: Fix always-true condition in PPE1 queue reservation loop

Eric Dumazet <edumazet@google.com>
    tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)

Eric Dumazet <edumazet@google.com>
    tipc: fix UAF in tipc_l2_send_msg()

Gui-Dong Han <hanguidong02@gmail.com>
    KEYS: Use acquire when reading state in keyring search

Aboorva Devarajan <aboorvad@linux.ibm.com>
    powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus

Aboorva Devarajan <aboorvad@linux.ibm.com>
    powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down

Aboorva Devarajan <aboorvad@linux.ibm.com>
    powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del

Yadan Fan <ydfan@suse.com>
    MIPS: mm: Fix out-of-bounds write in maar_res_walk()

Sechang Lim <rhkrqnwk98@gmail.com>
    bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check

Kuniyuki Iwashima <kuniyu@google.com>
    sockmap: Fix use-after-free in udp_bpf_recvmsg()

Weiming Shi <bestswngs@gmail.com>
    bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()

Al Viro <viro@zeniv.linux.org.uk>
    udf: fix nls leak on udf_fill_super() failure

Leon Hwang <leon.hwang@linux.dev>
    bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket

Leo Yan <leo.yan@arm.com>
    selftests/bpf: Initialize operation name before use

Jiri Olsa <jolsa@kernel.org>
    selftests/bpf: Fix typo in verify_umulti_link_info

Jiri Olsa <jolsa@kernel.org>
    bpf: Guard __get_user acesss with access_ok for uprobe_multi data

Nathan Chancellor <nathan@kernel.org>
    btrfs: Drop WQ_PERCPU from ordered_flags in btrfs_init_workqueues()

Huiwen He <hehuiwen@kylinos.cn>
    smb/client: always return a value for FS_IOC_GETFLAGS

Jian Zhang <zhangjian496@huawei.com>
    cifs: remove all cifs files before kill super

Henrique Carvalho <henrique.carvalho@suse.com>
    smb: client: fix conflicting option validation for new mount API

Takashi Iwai <tiwai@suse.de>
    ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()

Alice Mikityanska <alice@isovalent.com>
    geneve: Fix off-by-one comparing with GRO_LEGACY_MAX_SIZE

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them

Florian Westphal <fw@strlen.de>
    netfilter: nf_conncount: callers must hold rcu read lock

Cen Zhang <zzzccc427@gmail.com>
    ALSA: seq: avoid stale FIFO cells during resize

Cen Zhang <zzzccc427@gmail.com>
    ALSA: seq: oss: Serialize readq reset state with q->lock

Runyu Xiao <runyu.xiao@seu.edu.cn>
    kcm: use WRITE_ONCE() when changing lower socket callbacks

Wayen.Yan <win847@gmail.com>
    net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries

Wayen.Yan <win847@gmail.com>
    net: airoha: Fix register index for Tx-fwd counter configuration

Ratheesh Kannoth <rkannoth@marvell.com>
    octeontx2-af: fix NPC mailbox codes in mbox.h

Ovidiu Panait <ovidiu.panait.rb@renesas.com>
    net: bcmgenet: Use weighted round-robin TX DMA arbitration

Matthieu Buffet <matthieu@buffet.re>
    landlock: Fix unmarked concurrent access to socket family

Grzegorz Nitka <grzegorz.nitka@intel.com>
    dpll: balance create/delete notifications in __dpll_pin_(un)register

Grzegorz Nitka <grzegorz.nitka@intel.com>
    dpll: guard sync-pair removal on full pin unregister

Grzegorz Nitka <grzegorz.nitka@intel.com>
    dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()

Grzegorz Nitka <grzegorz.nitka@intel.com>
    dpll: send delete notification before unregister in on-pin rollback

Grzegorz Nitka <grzegorz.nitka@intel.com>
    dpll: fix stale iteration in dpll_pin_on_pin_unregister()

Ruoyu Wang <ruoyuw560@gmail.com>
    net: wwan: t7xx: check skb_clone in control TX

Wentao Guan <guanwentao@uniontech.com>
    net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show()

Wayen.Yan <win847@gmail.com>
    net: airoha: Fix error handling in airoha_ppe_flush_sram_entries()

Ratheesh Kannoth <rkannoth@marvell.com>
    octeontx2-af: npc: Fix size of entry2cntr_map

Xu Kuohai <xukuohai@huawei.com>
    bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno

Dragos Tatulea <dtatulea@nvidia.com>
    net/mlx5: Check max_macs devlink param value against max capability

Sun Jian <sun.jian.kdev@gmail.com>
    bpf: Run generic devmap egress prog on private skb

Victor Nogueira <victor@mojatatu.com>
    net/sched: sch_dualpi2: Add missing module alias

Zhi-Jun You <hujy652@gmail.com>
    net: ethernet: mtk_wed: fix loading WO firmware for MT7986

Eric Dumazet <edumazet@google.com>
    net: watchdog: fix refcount tracking races

Aditya Garg <gargaditya@linux.microsoft.com>
    net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check

Aditya Garg <gargaditya@linux.microsoft.com>
    net: mana: initialize gdma queue id to INVALID_QUEUE_ID

Victor Nogueira <victor@mojatatu.com>
    net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen

Victor Nogueira <victor@mojatatu.com>
    net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen

Victor Nogueira <victor@mojatatu.com>
    net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen

Paolo Abeni <pabeni@redhat.com>
    virtio_net: do not allow tunnel csum offload for non GSO packets

Sechang Lim <rhkrqnwk98@gmail.com>
    tcp: clear sock_ops cb flags before force-closing a child socket

Joe Damato <joe@dama.to>
    bnxt: fix head underflow on XDP head-grow

Chuck Lever <chuck.lever@oracle.com>
    handshake: Require admin permission for DONE command

Lucas Tsai <lucas_tsai@richtek.com>
    power: supply: core: fix supplied_from allocations

Dan Williams <djbw@kernel.org>
    cxl/memdev: Pin parents for entire memdev lifetime

Dan Williams <djbw@kernel.org>
    cxl/region: Resolve region deletion races

Dan Williams <djbw@kernel.org>
    cxl/region: Block region delete during region creation

Guangshuo Li <lgs201920130244@gmail.com>
    ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO

David Matlack <dmatlack@google.com>
    vfio: selftests: Ensure libvfio output dirs are always created

Li Ming <ming.li@zohomail.com>
    cxl/region: Fill first free targets[] slot during auto-discovery

Li Ming <ming.li@zohomail.com>
    cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach()

Chia-Lin Kao (AceLan) <acelan.kao@canonical.com>
    ASoC: sdw_utils: fix missing component_name for cs42l43 part_id 0x2A3B

Nicolin Chen <nicolinc@nvidia.com>
    iommu: Avoid copying the user array twice in the full-array copy helper

Lars Pöschel <lars.poeschel@edag.com>
    spi: xilinx: use FIFO occupancy register to determine buffer size

Alex Mastro <amastro@fb.com>
    iommufd: Clarify IOAS_MAP_FILE dma-buf support

Li RongQing <lirongqing@baidu.com>
    iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path

HanQuan <eilaimemedsnaimel@gmail.com>
    ALSA: seq: Fix kernel heap address leak in bounce_error_event()

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ALSA: usb-audio: qcom: Guard sideband endpoint removal

Herbert Xu <herbert@gondor.apana.org.au>
    crypto: rng - Free default RNG on module exit

Felix Gu <ustc.gu@gmail.com>
    crypto: cavium/cpt - fix DMA cleanup using wrong loop index

Felix Gu <ustc.gu@gmail.com>
    crypto: marvell/octeontx - fix DMA cleanup using wrong loop index

Dave Jiang <dave.jiang@intel.com>
    cxl/test: Add check after kzalloc() memory in alloc_mock_res()

Dave Jiang <dave.jiang@intel.com>
    cxl/test: Unregister cxl_acpi in cxl_test_init() error path

Michael Bommarito <michael.bommarito@gmail.com>
    tipc: reject inverted service ranges from peer bindings

Michael Bommarito <michael.bommarito@gmail.com>
    tipc: prevent snt_unacked underflow on CONN_ACK

Michael Bommarito <michael.bommarito@gmail.com>
    tipc: require net admin for TIPCv2 netlink mutators

Victor Nogueira <victor@mojatatu.com>
    net/sched: sch_hfsc: Don't make class passive twice

Daniel Borkmann <daniel@iogearbox.net>
    net: Stop leased rxq before uninstalling its memory provider

Samuel Moelius <sam.moelius@trailofbits.com>
    net: pfcp: allocate per-cpu tstats for PFCP netdevs

Xin Long <lucien.xin@gmail.com>
    sctp: validate embedded address parameter length

Xiang Mei <xmei5@asu.edu>
    bridge: cfm: reject invalid CCM interval at configuration time

Kuniyuki Iwashima <kuniyu@google.com>
    net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().

Kuniyuki Iwashima <kuniyu@google.com>
    ipv4: fib: Don't dump dying fib_info in fib_leaf_notify().

Jamal Hadi Salim <jhs@mojatatu.com>
    net/sched: cls_flow: Dont expose folded kernel pointers

George Moussalem <george.moussalem@outlook.com>
    net: dsa: qca8k: fix led devicename when using external mdio bus

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ASoC: topology: Check PCM and DAI name strings before use

HyeongJun An <sammiee5311@gmail.com>
    ASoC: tegra: tegra210_ahub: Validate written enum value

HyeongJun An <sammiee5311@gmail.com>
    ASoC: fsl: fsl_audmix: Validate written enum values

HyeongJun An <sammiee5311@gmail.com>
    ASoC: meson: aiu: Validate written enum values

HyeongJun An <sammiee5311@gmail.com>
    ASoC: codecs: hdac_hdmi: Validate written enum value

Arnd Bergmann <arnd@arndb.de>
    ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly

Arnd Bergmann <arnd@arndb.de>
    ASoC: SOF: Intel: select SND_SOC_SDW_UTILS=y from SND_SOC_SOF_HDA_GENERIC=y

Richard Fitzgerald <rf@opensource.cirrus.com>
    ASoC: cs35l56: Fix wrong error test on simple_write_to_buffer()

Leon Romanovsky <leon@kernel.org>
    RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one

Maher Sanalla <msanalla@nvidia.com>
    RDMA/mlx5: Fix undefined shift of user RQ WQE size

Patrisious Haddad <phaddad@nvidia.com>
    RDMA/mlx5: Remove raw RSS QP restrack tracking

Patrisious Haddad <phaddad@nvidia.com>
    RDMA/mlx5: Remove DCT restrack tracking

Maxwell Doose <m32285159@gmail.com>
    fs: efs: remove unneeded debug prints

Michael Guralnik <michaelgur@nvidia.com>
    RDMA/mlx5: Drop FRMR pool handle on UMR revoke failure

Michael Guralnik <michaelgur@nvidia.com>
    RDMA/core: Add ib_frmr_pool_drop for unrecoverable handles

Michael Guralnik <michaelgur@nvidia.com>
    RDMA/core: Fix FRMR handle leak on push failure

Michael Guralnik <michaelgur@nvidia.com>
    RDMA/core: Avoid NULL dereference on FRMR bad usage

Michael Guralnik <michaelgur@nvidia.com>
    RDMA/core: Fix FRMR set pinned push error path

Michael Guralnik <michaelgur@nvidia.com>
    RDMA/core: Fix FRMR aging push to queue error flow

Michael Guralnik <michaelgur@nvidia.com>
    RDMA/core: Fix skipped usage for driver built FRMR key

Michael Guralnik <michaelgur@nvidia.com>
    RDMA/mlx5: Fix TPH extraction in FRMR pool key

Michael Guralnik <michaelgur@nvidia.com>
    RDMA/mlx5: Fix mkey creation error flow rollback

Samuel Moelius <sam.moelius@trailofbits.com>
    Bluetooth: vhci: validate devcoredump state before side effects

Samuel Moelius <sam.moelius@trailofbits.com>
    Bluetooth: hci: validate codec capability element length

Sai Teja Aluvala <aluvala.sai.teja@intel.com>
    Bluetooth: btintel_pcie: Load IOSF debug regs by controller variant

Zhao Dongdong <zhaodongdong@kylinos.cn>
    Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path

Jordan Walters <jaggyaur@gmail.com>
    Bluetooth: hci_core: Fix UAF in hci_unregister_dev()

Jiajia Liu <liujiajia@kylinos.cn>
    Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING

Weiming Shi <bestswngs@gmail.com>
    Bluetooth: eir: Fix stack OOB write when prepending the Flags AD

Zijun Hu <zijun.hu@oss.qualcomm.com>
    Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device

Zijun Hu <zijun.hu@oss.qualcomm.com>
    Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device

Heiko Carstens <hca@linux.ibm.com>
    s390/process: Fix kernel thread function pointer type

Richard Fitzgerald <rf@opensource.cirrus.com>
    ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset()

Andre Przywara <andre.przywara@arm.com>
    arm64: dts: allwinner: a523: Add missing GPIO interrupt

Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
    pinctrl: airoha: an7583: remove undefined groups from pcm_spi pin function

Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
    pinctrl: airoha: an7583: fix phy1_led1 pin function

Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
    pinctrl: airoha: an7583: add missed gpio22 pin group

Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
    pinctrl: airoha: an7583: fix gpio21 pin group

Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
    pinctrl: airoha: fix pwm pin function for an7581 and an7583

Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
    pinctrl: airoha: an7583: fix incorrect led mapping in phy4_led1 pin function

Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
    pinctrl: airoha: an7581: fix incorrect led mapping in phy4_led1 pin function

Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
    pinctrl: airoha: an7583: fix misprint in gpio19 pinconf

Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
    pinctrl: airoha: an7581: fix misprint in gpio19 pinconf

Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
    pinctrl: airoha: an7583: add missed gpio32 pin group

Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
    pinctrl: airoha: an7581: add missed gpio32 pin group

Andre Przywara <andre.przywara@arm.com>
    pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag

Angelo Dureghello <adureghello@baylibre.com>
    m68k: mcf5441x: fix clocks numbering

Daniel Borkmann <daniel@iogearbox.net>
    bpf: Tighten cgroup storage cookie checks for prog arrays

Giovanni Cabiddu <giovanni.cabiddu@intel.com>
    vfio/qat: fix f_pos race in qat_vf_resume_write()

Sergey Shtylyov <s.shtylyov@auroraos.dev>
    of: cpu: add check in __of_find_n_match_cpu_property()

Dave Jiang <dave.jiang@intel.com>
    cxl/test: Zero out LSA backing memory to avoid leaking to user

Dave Jiang <dave.jiang@intel.com>
    cxl/test: Fix integer overflow in mock LSA bounds checks

Dave Jiang <dave.jiang@intel.com>
    cxl/test: Verify cmd->size_in before accessing payload

Yonghong Song <yonghong.song@linux.dev>
    selftests/bpf: Fix bpf_iter/task_vma test

Yun Zhou <yun.zhou@windriver.com>
    ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT

Aditya Prakash Srivastava <aditya.ansh182@gmail.com>
    ext4: fix kernel BUG in ext4_write_inline_data_end

Louis Scalbert <louis.scalbert@6wind.com>
    bonding: 3ad: fix mux port state on oper down

Louis Scalbert <louis.scalbert@6wind.com>
    bonding: 3ad: fix carrier when no usable slaves

Louis Scalbert <louis.scalbert@6wind.com>
    bonding: 3ad: add lacp_strict configuration knob

Louis Scalbert <louis.scalbert@6wind.com>
    netlink: specs: rt-link: missed broadcast-neigh

Louis Scalbert <louis.scalbert@6wind.com>
    tools: missed broadcast_neigh if_link uapi header

Hongling Zeng <zenghongling@kylinos.cn>
    ext4: fix ERR_PTR(0) in ext4_mkdir()

Pei Xiao <xiaopei01@kylinos.cn>
    hwmon: (gpd-fan): fix race condition between device removal and sysfs access

Pei Xiao <xiaopei01@kylinos.cn>
    hwmon: (gpd-fan): Initialize EC before registering hwmon device

Pei Xiao <xiaopei01@kylinos.cn>
    hwmon: (gpd-fan): drop global driver data and use per-device allocation

Richard Fitzgerald <rf@opensource.cirrus.com>
    ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails

Richard Fitzgerald <rf@opensource.cirrus.com>
    ASoC: cs35l56: Cleanup if component_probe fails

Richard Fitzgerald <rf@opensource.cirrus.com>
    ASoC: cs35l56: Prevent double-free of debugfs

Richard Fitzgerald <rf@opensource.cirrus.com>
    ASoC: cs35l56: Fix missing calls to wm_adsp2_remove()

Christoph Hellwig <hch@lst.de>
    iomap: pass the correct len to fserror_report_io in __iomap_write_begin

Srujana Challa <schalla@marvell.com>
    vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler

Srujana Challa <schalla@marvell.com>
    vdpa/octeon_ep: Fix PF->VF mailbox data address calculation

Arnd Bergmann <arnd@arndb.de>
    vduse: fix compat handling for VDUSE_IOTLB_GET_FD/VDUSE_VQ_GET_INFO

longlong yan <yanlonglong@kylinos.cn>
    tools/virtio: check mmap return value in vringh_test

Qing Ming <a0yami@mailbox.org>
    vhost/net: complete zerocopy ubufs only once

Zhang Tianci <zhangtianci.1997@bytedance.com>
    vduse: Requeue failed read to send_list head

Filip Hejsek <filip.hejsek@gmail.com>
    virtio_console: read size from config space during device init

Jia Jia <physicalmtea@gmail.com>
    virtio: rtc: tear down old virtqueues before restore

Qihang Tang <q.h.hack.winter@gmail.com>
    vhost/vdpa: validate virtqueue index in mmap and fault paths

Qihang Tang <q.h.hack.winter@gmail.com>
    vduse: hold vduse_lock across IDR lookup in open path

Enric Balletbo i Serra <eballetb@redhat.com>
    clocksource: move NXP timer selection to drivers/clocksource

Justin Suess <utilityemal77@gmail.com>
    bpf: Cancel special fields on map value recycle

Val Packett <val@packett.cool>
    ASoC: codecs: aw88261: fix incorrect masks for boost regs

Ruoyu Wang <ruoyuw560@gmail.com>
    spi: meson-spifc: fix runtime PM leak on remove

Chuck Lever <chuck.lever@oracle.com>
    lockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file()

Chuck Lever <chuck.lever@oracle.com>
    lockd: Do not monitor when looking up the LOCK_MSG callback host

Chuck Lever <chuck.lever@oracle.com>
    lockd: Translate nlm__int__deadlock in __nlm4svc_proc_lock_msg()

Chuck Lever <chuck.lever@oracle.com>
    lockd: Stop warning on nlm__int__drop_reply in !V4 cast_status

Chuck Lever <chuck.lever@oracle.com>
    NFSD: Handle layout stid in nfsd4_drop_revoked_stid()

Jason Gunthorpe <jgg@ziepe.ca>
    IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ASoC: sma1307: Fix uevent string leaks in fault worker

KhaiWenTan <khai.wen.tan@linux.intel.com>
    igc: skip RX timestamp header for frame preemption verification

Larysa Zaremba <larysa.zaremba@intel.com>
    ixgbe: do not configure xps for XDP queues

Weiming Shi <bestswngs@gmail.com>
    btrfs: lzo: reject compressed segment that overflows the compressed input

Filipe Manana <fdmanana@suse.com>
    btrfs: fix deadlock cloning inline extent when using flushoncommit

Cen Zhang <zzzccc427@gmail.com>
    btrfs: annotate lockless read of defrag_bytes in should_nocow()

Johannes Thumshirn <johannes.thumshirn@wdc.com>
    btrfs: zoned: always set max_active_zones for zoned devices

Matthew Wilcox (Oracle) <willy@infradead.org>
    Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()"

Johannes Thumshirn <johannes.thumshirn@wdc.com>
    btrfs: zoned: fix deadlock waiting for ticket during data relocation

Johannes Thumshirn <johannes.thumshirn@wdc.com>
    btrfs: zoned: don't account data relocation space-info in statfs free space

Yuho Choi <dbgh9129@gmail.com>
    PM: QoS: Fix misc device registration unwind

Nikita Zhandarovich <n.zhandarovich@fintech.ru>
    hwmon: (it87) Clamp negative values to zero in set_fan()

Jeff Layton <jlayton@kernel.org>
    vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS

Sumit Gupta <sumitg@nvidia.com>
    memory: tegra186-emc: stop borrowing MC aggregate hook for EMC

David Laight <david.laight.linux@gmail.com>
    fbdev: sm501fb: Fix buffer errors in OF binding code

Helge Deller <deller@gmx.de>
    fbdev/arm: Export acorndata_8x8 font symbol for bootloader

Wen Gong <quic_wgong@quicinc.com>
    wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is reported

Baochen Qiang <baochen.qiang@oss.qualcomm.com>
    wifi: ath12k: fix EAPOL TX failure caused by stale tcl_metadata bits

Sergio Paracuellos <sergio.paracuellos@gmail.com>
    gpio: mt7621: fix interrupt banks mapping on gpio chips

Takashi Iwai <tiwai@suse.de>
    ALSA: aloop: Drop superfluous break

Filipe Manana <fdmanana@suse.com>
    btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()

Ryder Lee <ryder.lee@mediatek.com>
    wifi: mt76: mt7996: fix potential tx_retries underflow

Ryder Lee <ryder.lee@mediatek.com>
    wifi: mt76: mt7925: fix potential tx_retries underflow

Ryder Lee <ryder.lee@mediatek.com>
    wifi: mt76: mt7921: fix potential tx_retries underflow

Ryder Lee <ryder.lee@mediatek.com>
    wifi: mt76: mt7915: fix potential tx_retries underflow

Bjoern A. Zeeb <bz@FreeBSD.org>
    wifi: mt76: fix argument to ieee80211_is_first_frag()

Dylan Eskew <dylan.eskew@candelatech.com>
    wifi: mt76: mt7996: limit work in set_bitrate_mask

Lorenzo Bianconi <lorenzo@kernel.org>
    wifi: mt76: mt7996: remove redundant pdev->bus check in probe

Lorenzo Bianconi <lorenzo@kernel.org>
    wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add()

Lorenzo Bianconi <lorenzo@kernel.org>
    wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211()

Lorenzo Bianconi <lorenzo@kernel.org>
    wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb()

Aviel Zohar <avielzohar123@gmail.com>
    wifi: mt76: mt7925: validate skb length in testmode query

Sean Wang <sean.wang@mediatek.com>
    wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX

Sean Wang <sean.wang@mediatek.com>
    wifi: mt76: mt7925: keep TX BA state in the primary WCID

Javier Tia <floss@jetm.me>
    wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links

Lorenzo Bianconi <lorenzo@kernel.org>
    wifi: mt76: mt7996: Fix NULL pointer dereference in mt7996_init_tx_queues()

Felix Fietkau <nbd@nbd.name>
    wifi: mt76: mt7996: add missing max_remain_on_channel_duration

Rajat Gupta <rajat.gupta@oss.qualcomm.com>
    wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link

Hongling Zeng <zenghongling@kylinos.cn>
    wifi: mt76: mt7921: fix resource leak in probe error path

Myeonghun Pak <mhun512@gmail.com>
    wifi: mt76: mt7925: clean up DMA on probe failure

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    ARM: configs: Drop duplicated CONFIG_EXT4_FS

Hongyan Xia <hongyan.xia@transsion.com>
    sched/fair: Fix cpu_util runnable_avg arithmetic

Wolfram Sang <wsa+renesas@sang-engineering.com>
    hwspinlock: qcom: avoid uninitialized struct members

Alexandru Gagniuc <mr.nuke.me@gmail.com>
    remoteproc: qcom_q6v5_wcss: drop redundant wcss_q6_bcr_reset

Miguel Ojeda <ojeda@kernel.org>
    rust: kbuild: show the right `quiet_cmd_rustc_procmacrolibrary`

Hui Zhu <zhuhui@kylinos.cn>
    vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()

Hao Ge <hao.ge@linux.dev>
    lib/test_hmm: fix memory leak in dmirror_migrate_to_system()

Jason Gunthorpe <jgg@ziepe.ca>
    iommufd: Destroy the pages content after detaching from dmabuf

Ankit Soni <Ankit.Soni@amd.com>
    iommufd: Take dma_resv lock before dma_buf_unpin() in release path

Timur Tabi <ttabi@nvidia.com>
    pinctrl: PINCTRL_STMFX should depend on CONFIG_OF

Yu-Chun Lin <eleanor.lin@realtek.com>
    dt-bindings: pinctrl: realtek,rtd1625: Fix input voltage property name

Luca Leonardo Scorcia <l.scorcia@gmail.com>
    pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39

Luca Leonardo Scorcia <l.scorcia@gmail.com>
    pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39

Mike Christie <michael.christie@oracle.com>
    scsi: target: Remove tcm_loop target reset handling

Hongjie Fang <hongjiefang@asrmicro.com>
    scsi: ufs: core: Handle PM commands timeout before SCSI EH

David Disseldorp <ddiss@suse.de>
    scsi: target: Fix hexadecimal CHAP_I handling

Sneh Mankad <sneh.mankad@oss.qualcomm.com>
    pinctrl: qcom: Fix resolving register base address from device node

Yuho Choi <dbgh9129@gmail.com>
    watchdog: unregister PM notifier on watchdog unregister

Al Viro <viro@zeniv.linux.org.uk>
    configfs: fix lockless traversals of ->s_children

Dmitry Vyukov <dvyukov@google.com>
    firmware_loader: Fix recursive lock in device_cache_fw_images()

Aaron Ma <aaron.ma@canonical.com>
    ASoC: amd: acp-sdw-sof: Bound DAI link iteration

Aaron Ma <aaron.ma@canonical.com>
    ASoC: amd: acp-sdw-legacy: Bound DAI link iteration

Felix Gu <ustc.gu@gmail.com>
    spi: ep93xx: fix double-free of zeropage on DMA setup failure

Jason Gunthorpe <jgg@ziepe.ca>
    IB/mlx5: Don't mangle the mr->pd inside the rereg callback

Jason Gunthorpe <jgg@ziepe.ca>
    IB/mlx5: Pull the pdn out of the depths of the umr machinery

Jason Gunthorpe <jgg@ziepe.ca>
    IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift()

Jason Gunthorpe <jgg@ziepe.ca>
    RDMA/nldev: Fix locking when accessing mr->pd

Jason Gunthorpe <jgg@ziepe.ca>
    IB/mlx5: Properly support implicit ODP rereg_mr

Jason Gunthorpe <jgg@ziepe.ca>
    IB/mlx5: Don't take the rereg_mr fallback without a new translation

Bryam Vargas <hexlabsecurity@proton.me>
    ntfs: fix u16 truncation of restart-area length check

Bryam Vargas <hexlabsecurity@proton.me>
    ntfs: bound the attribute-list entry in ntfs_read_inode_mount()

Bryam Vargas <hexlabsecurity@proton.me>
    ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find()

Bryam Vargas <hexlabsecurity@proton.me>
    ntfs: validate resident attribute lists and harden the validator

Mark Harmstone <mark@harmstone.com>
    btrfs: don't force DIO writes to be serialized

Samuel Moelius <sam.moelius@trailofbits.com>
    thermal: testing: reject missing command arguments

Pengjie Zhang <zhangpengjie2@huawei.com>
    cpufreq: Documentation: fix conservative governor freq_step description

Tony W Wang-oc <TonyWWang-oc@zhaoxin.com>
    ACPI: processor: Add cpuidle driver check in acpi_processor_register_idle_driver()

Yuho Choi <dbgh9129@gmail.com>
    ACPI: IPMI: Fix message kref handling on dead device

Sechang Lim <rhkrqnwk98@gmail.com>
    bpf: Fix NULL pointer dereference in bpf_task_from_vpid()

Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
    powerpc/8xx: implement get_direction() in cpm1

Bryam Vargas <hexlabsecurity@proton.me>
    wifi: mac80211: bound S1G TIM PVB walk to the TIM element

David Gow <david@davidgow.net>
    kunit:tool: Don't write to stdout when it should be disabled

Mykyta Yatsenko <yatsenko@meta.com>
    bpf: Fix NMI/tracepoint re-entry deadlock on lru locks

Christian Brauner <brauner@kernel.org>
    filelock: fix break_lease() stub signature for CONFIG_FILE_LOCKING=n

David Carlier <devnexen@gmail.com>
    netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag

David Windsor <dwindsor@gmail.com>
    bpf: Reject sleepable BPF_LSM_CGROUP programs at load time

Mykyta Yatsenko <yatsenko@meta.com>
    bpf: Verifier support for sleepable tracepoint programs

Thomas Weißschuh <thomas.weissschuh@linutronix.de>
    riscv: alternative: Also patch the CFI vDSO

Thomas Weißschuh <thomas.weissschuh@linutronix.de>
    riscv: alternative: Pass vDSO start as parameter to apply_vdso_alternatives()

Thomas Weißschuh <thomas.weissschuh@linutronix.de>
    riscv: alternative: Use IS_ENABLED() over ifdeffery for apply_vdso_alternatives()

Kyle Zeng <kylebot@openai.com>
    ALSA: seq: Clear variable event pointer on read

Rui Qi <qirui.001@bytedance.com>
    riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe

Hui Wang <hui.wang@canonical.com>
    riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ALSA: pcm: Fix unlocked runtime state reads in xfer ioctls

HyeongJun An <sammiee5311@gmail.com>
    ALSA: seq: Fix partial userptr event expansion

Tristan Madani <tristan@talencesecurity.com>
    wifi: wcn36xx: fix OOB read from short trigger BA firmware response

Tristan Madani <tristan@talencesecurity.com>
    wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication

Tristan Madani <tristan@talencesecurity.com>
    wifi: wcn36xx: fix heap overflow from oversized firmware HAL response

Christian Brauner <brauner@kernel.org>
    kernfs: link kn to its parent before the LSM init hook

Miklos Szeredi <mszeredi@redhat.com>
    simpe_xattr: use per-sb cache

Miklos Szeredi <mszeredi@redhat.com>
    simple_xattr: change interface to pass struct simple_xattrs **

Miklos Szeredi <mszeredi@redhat.com>
    tmpfs: simplify constructing "security.foo" xattr names

Miklos Szeredi <mszeredi@redhat.com>
    kernfs: fix xattr race condition with multiple superblocks

Leon Hwang <leon.hwang@linux.dev>
    bpf: Update transport_header when encapsulating UDP tunnel in lwt

Leon Hwang <leon.hwang@linux.dev>
    bpf: Check tail zero of bpf_prog_info

Leon Hwang <leon.hwang@linux.dev>
    bpf: Check tail zero of bpf_map_info

Kaitao Cheng <chengkaitao@kylinos.cn>
    bpf: Clear rb node linkage when freeing bpf_rb_root

Mykyta Yatsenko <yatsenko@meta.com>
    selftests/bpf: Fix flaky file_reader test

Bernard Metzler <bernard.metzler@linux.dev>
    RDMA/siw: Fix endpoint/socket association handling

Nora Schiffer <nora.schiffer@ew.tq-group.com>
    arm64: dts: freescale: fsl-ls1028a-tqmls1028a-mbls1028a: switch mmc aliases

Frieder Schrempf <frieder.schrempf@kontron.de>
    arm64: dts: imx8mp-kontron: Fix GPIO for display power switch

Alexander Stein <alexander.stein@ew.tq-group.com>
    arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well

Josua Mayer <josua@solid-run.com>
    arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi

Richard Zhu <hongxing.zhu@nxp.com>
    arm64: dts: imx95: Correct PCIe outbound address space configuration

Alice Guo <alice.guo@nxp.com>
    arm64: dts: imx94: fix DDR PMU interrupt number

Frieder Schrempf <frieder.schrempf@kontron.de>
    arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency

Jacob Moroni <jmoroni@google.com>
    RDMA/irdma: Initialize iwmr->access during MR registration

Jacob Moroni <jmoroni@google.com>
    RDMA/irdma: Fix OOB read during CQ MR registration

Oliver Hartkopp <socketcan@hartkopp.net>
    ALSA: hda: fix Kconfig dependency of HD Audio PCI

Jason Gunthorpe <jgg@ziepe.ca>
    IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path()

Arnd Bergmann <arnd@arndb.de>
    RDMA/hfi1: Open-code rvt_set_ibdev_name()

DaeMyung Kang <charsyam@gmail.com>
    ntfs: free link name from ntfs_name_cache

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: conntrack: revert ct extension genid infrastructure

Junxiao Chang <junxiao.chang@intel.com>
    x86/cpu: Remove obsolete aperfmperf_get_khz() declaration

Shengming Hu <hu.shengming@zte.com.cn>
    mm/slub: preserve original size in _kmalloc_nolock_noprof retry path

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ALSA: usb-audio: qcom: Initialize offload control return value

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount

Fernando Fernandez Mancera <fmancera@suse.de>
    netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock

Fernando Fernandez Mancera <fmancera@suse.de>
    netfilter: synproxy: fix unaligned memory access in timestamp adjustment

Fernando Fernandez Mancera <fmancera@suse.de>
    netfilter: synproxy: adjust duplicate timestamp options

Fernando Fernandez Mancera <fmancera@suse.de>
    netfilter: synproxy: drop packets if timestamp adjustment fails

Pablo Neira Ayuso <pablo@netfilter.org>
    netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags

Fernando Fernandez Mancera <fmancera@suse.de>
    netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures

Dave Jiang <dave.jiang@intel.com>
    cxl/pci: Convert PCIBIOS errors to errno on DVSEC config accesses

Dave Jiang <dave.jiang@intel.com>
    cxl/pci: Fix the incorrect check of pci_read_config_word() return

Ian Bridges <icb@fastmail.org>
    ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent

Joseph Qi <joseph.qi@linux.alibaba.com>
    ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release()

Zhang Cen <rollkingzzc@gmail.com>
    ocfs2/dlm: require a ref for locking_state debugfs open

Zhang Cen <rollkingzzc@gmail.com>
    ocfs2: reject FITRIM ranges shorter than a cluster

Zhang Cen <rollkingzzc@gmail.com>
    ocfs2: validate fast symlink target during inode read

Dmitry Antipov <dmantipov@yandex.ru>
    ocfs2: fix buffer head management in ocfs2_read_blocks()

Thomas Weißschuh <linux@weissschuh.net>
    lib: kunit_iov_iter: repeatedly call alloc_pages_bulk()

Zhang Cen <rollkingzzc@gmail.com>
    ocfs2: rebase copied fsdlm LVB pointers in locking_state

Wandun Chen <chenwandun@lixiang.com>
    of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails

Alex Deucher <alexander.deucher@amd.com>
    drm/amdkfd: always resume_all after suspend_all

Alexei Starovoitov <ast@kernel.org>
    bpf: Take mmap_lock in zap_pages()

Dan Williams <djbw@kernel.org>
    cxl/test: Fix __fortify_panic

Dan Williams <djbw@kernel.org>
    cxl/fwctl: Fix __fortify_panic

Andreas Kemnade <andreas@kemnade.info>
    wifi: wlcore: enable the right set of ciphers

Antony Antony <antony.antony@secunet.com>
    xfrm: fix NAT-related field inheritance in SA migration

Sandipan Das <sandipan.das@amd.com>
    perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains

Zide Chen <zide.chen@intel.com>
    perf/x86/intel/uncore: Fix PCI device refcount leak in UPI discovery

Zide Chen <zide.chen@intel.com>
    perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems

Sandipan Das <sandipan.das@amd.com>
    perf/x86/amd/core: Always use the NMI latency mitigation

Christian Brauner <brauner@kernel.org>
    eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers

Christian Brauner <brauner@kernel.org>
    eventpoll: extract ep_deliver_event() from ep_send_events()

Christian Brauner <brauner@kernel.org>
    eventpoll: split ep_insert() into alloc + register stages

Christian Brauner <brauner@kernel.org>
    eventpoll: rename attach_epitem() to ep_attach_file()

Jeff Layton <jlayton@kernel.org>
    mm: preserve PG_dropbehind flag during folio split

Pranjal Shrivastava <praan@google.com>
    iommu/vt-d: Fix RB-tree corruption in probe error path

Michael S. Tsirkin <mst@redhat.com>
    vhost: fix vhost_get_avail_idx for a non empty ring

Woojin Ji <random6.xyz@gmail.com>
    bpftool: Use libbpf error code for flow dissector query

Lizhi Hou <lizhi.hou@amd.com>
    accel/amdxdna: Return errors for failed debug BO commands

Yunxiang Li <Yunxiang.Li@amd.com>
    drm/amdgpu: set sub_block_index for mca ras sub-blocks

Vitaly Prosyak <vitaly.prosyak@amd.com>
    drm/amd/pm: Add empty string validation to sysfs store functions

Vitaly Prosyak <vitaly.prosyak@amd.com>
    drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump

Marek Szyprowski <m.szyprowski@samsung.com>
    irqchip/exynos-combiner: Remove useless spinlock

Li Chen <me@linux.beauty>
    ext4: fix fast commit wait/wake bit mapping on 64-bit

Karl Mehltretter <kmehltretter@gmail.com>
    lockdep/selftests: Restore sched_rt_mutex state on PREEMPT_RT

Karl Mehltretter <kmehltretter@gmail.com>
    lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT

Al Viro <viro@zeniv.linux.org.uk>
    configfs_lookup(): don't leave ->s_dentry dangling on failure

Inochi Amaoto <inochiama@gmail.com>
    riscv: dts: sophgo: sg2042: use hex for CPU unit address

Inochi Amaoto <inochiama@gmail.com>
    riscv: dts: sophgo: sg2044: use hex for CPU unit address

Alexander Potapenko <glider@google.com>
    lib/test_meminit: use && for bools

Frederic Weisbecker <frederic@kernel.org>
    tick/sched: Fix TOCTOU in nohz idle time fetch

Daniel Borkmann <daniel@iogearbox.net>
    bpf: Reject exclusive maps for bpf_map_elem iterators

Nathan Chancellor <nathan@kernel.org>
    driver core: Use system_percpu_wq instead of system_wq

liuxixin <gliuxen@gmail.com>
    nvme: fix FDP fdpcidx bounds check

Guanyou.Chen <chenguanyou9338@gmail.com>
    sched: restore timer_slack_ns when resetting RT policy on fork

Danila Chernetsov <listdansp@mail.ru>
    ext2: fix ignored return value of generic_write_sync()

Sang-Heon Jeon <ekffu200098@gmail.com>
    mm/fake-numa: fix under-allocation detection in uniform split

Deepanshu Kartikey <kartikey406@gmail.com>
    bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs

Chanwoo Lee <cw9316.lee@samsung.com>
    scsi: ufs: Fix wrong value printed in unexpected UPIU response case

Dan Carpenter <error27@gmail.com>
    scsi: pm8001: Fix error code in non_fatal_log_show()

Daniel Borkmann <daniel@iogearbox.net>
    libbpf: Skip max_entries override on signed loaders

Daniel Borkmann <daniel@iogearbox.net>
    libbpf: Skip initial_value override on signed loaders

KP Singh <kpsingh@kernel.org>
    libbpf: Reject non-exclusive metadata maps in the signed loader

Daniel Borkmann <daniel@iogearbox.net>
    bpf: Reject exclusive maps as inner maps in map-in-map

Martin Wilck <martin.wilck@suse.com>
    scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans"

Neal Cardwell <ncardwell@google.com>
    tcp_bbr: fix SPDX-License-Identifier to be GPL-2.0 OR BSD-3-Clause

Alison Schofield <alison.schofield@intel.com>
    nvdimm/btt: Handle preemption in BTT lane acquisition

Randy Dunlap <rdunlap@infradead.org>
    x86/cpu: Keep the PROCESSOR_SELECT menu together

Yuho Choi <dbgh9129@gmail.com>
    ARM: imx31: Fix IIM mapping leak in revision check

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    ACPI: button: Fix lid_device value leak past driver removal

Bart Van Assche <bvanassche@acm.org>
    ata: libata: Fix ata_exec_internal()

Wei Zhang <wei.zhang@oss.qualcomm.com>
    wifi: ath12k: fix NULL deref in change_sta_links for unready link

Wei Zhang <wei.zhang@oss.qualcomm.com>
    wifi: ath12k: fix inconsistent arvif state in vdev_create error paths

Miaoqing Pan <miaoqing.pan@oss.qualcomm.com>
    wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic()

Kwan Lai Chee Hou <laicheehou9@gmail.com>
    wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode

J. Neuschäfer <j.ne@posteo.net>
    HID: wiimote: Fix table layout and whitespace errors

Yuho Choi <dbgh9129@gmail.com>
    ARM: imx3: Fix CCM node reference leak

Chuck Lever <chuck.lever@oracle.com>
    NFSD: Fix delegation reference leak in nfsd4_revoke_states

John Madieu <john.madieu.xa@bp.renesas.com>
    ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble

Carlos Song <carlos.song@nxp.com>
    spi: imx: replace dmaengine_terminate_all() with dmaengine_terminate_sync()

Felix Gu <ustc.gu@gmail.com>
    spi: atmel: fix DMA channel and bounce buffer leaks

Zhang Yi <yi.zhang@huawei.com>
    ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback

Pasha Tatashin <pasha.tatashin@soleen.com>
    liveupdate: fix u-a-f in luo_file_unpreserve_files() and luo_file_finish()

Pasha Tatashin <pasha.tatashin@soleen.com>
    liveupdate: block session mutations during reboot

Pasha Tatashin <pasha.tatashin@soleen.com>
    liveupdate: fix TOCTOU race in luo_session_retrieve()

Pasha Tatashin <pasha.tatashin@soleen.com>
    liveupdate: skip serialization for context-preserving kexec

Daniel Borkmann <daniel@iogearbox.net>
    libbpf: Skip endianness swap when loader generation failed

Daniel Borkmann <daniel@iogearbox.net>
    libbpf: Skip hash computation when loader generation failed

David Matlack <dmatlack@google.com>
    liveupdate: Reference count incoming FLB data

David Matlack <dmatlack@google.com>
    liveupdate: Use refcount_t for FLB reference counts

Yuyang Huang <yuyanghuang@google.com>
    selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries

Yuyang Huang <yuyanghuang@google.com>
    bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat

Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
    raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path

Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
    md/raid1,raid10: fix bio accounting for split md cloned bios

Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
    md/raid1,raid10: fix error-path detection with md_cloned_bio()

Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
    md/raid1,raid10: fix deadlock in read error recovery path

Chen Cheng <chencheng@fnnas.com>
    md/raid10: reset read_slot when reusing r10bio for discard

Marek Vasut <marek.vasut+renesas@mailbox.org>
    arm64: dts: renesas: ironhide: Describe all reserved memory

Marek Vasut <marek.vasut+renesas@mailbox.org>
    arm64: dts: renesas: r8a78000: Fix GIC-720AE View 1 Redistributor description

Danilo Krummrich <dakr@kernel.org>
    rpmsg: use generic driver_override infrastructure

Danilo Krummrich <dakr@kernel.org>
    Drivers: hv: vmbus: use generic driver_override infrastructure

Danilo Krummrich <dakr@kernel.org>
    cdx: use generic driver_override infrastructure

Danilo Krummrich <dakr@kernel.org>
    amba: use generic driver_override infrastructure

Renjiang Han <renjiang.han@oss.qualcomm.com>
    media: qcom: venus: relax encoder frame/blur step size on v6

Renjiang Han <renjiang.han@oss.qualcomm.com>
    media: qcom: venus: relax encoder frame/blur dimension steps on v4

Renjiang Han <renjiang.han@oss.qualcomm.com>
    media: qcom: venus: drop extra padding in NV12 raw size calculation

Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
    Revert "media: venus: hfi_platform: Correct supported codecs for sc7280"

Yixun Lan <dlan@kernel.org>
    dts: riscv: spacemit: k3: Fix I/O power settings

Tristan Madani <tristmd@gmail.com>
    RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path

Tristan Madani <tristmd@gmail.com>
    RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe

Jiri Pirko <jiri@resnulli.us>
    RDMA/umem: Add ib_umem_is_contiguous() stub for !CONFIG_INFINIBAND_USER_MEM

Jinseok Kim <always.starving0@gmail.com>
    arm: dts: bcm2711: Fix typo in gpio-line-names

Marek Vasut <marex@nabladev.com>
    arm64: dts: st: Fix SAI addresses on stm32mp251

zhoumin <teczm@foxmail.com>
    EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info

Qiuxu Zhuo <qiuxu.zhuo@intel.com>
    EDAC/igen6: Fix memory topology parsing for Panther Lake-H SoCs

Qiuxu Zhuo <qiuxu.zhuo@intel.com>
    EDAC/igen6: Fix call trace due to missing release()

Akhil P Oommen <akhilpo@oss.qualcomm.com>
    drm/msm/a8xx: Fix RSCC offset

Akhil P Oommen <akhilpo@oss.qualcomm.com>
    drm/msm/a8xx: Make a8xx_recover IFPC safe

Arnd Bergmann <arnd@arndb.de>
    firmware: samsung: acpm: remove compile-testing stubs

Tudor Ambarus <tudor.ambarus@linaro.org>
    firmware: samsung: acpm: Add devm_acpm_get_by_phandle helper

Jessica Zhang <jesszhan0024@gmail.com>
    drm/msm/dp: Fix the ISR_* enum values

Jessica Zhang <jesszhan0024@gmail.com>
    drm/msm/dp: fix HPD state status bit shift value

Andrea Righi <arighi@nvidia.com>
    sched/deadline: Reject debugfs dl_server writes for offline CPUs

Alexey Kardashevskiy <aik@amd.com>
    crypto: ccp/tsm - Enable the root port after the endpoint

Herbert Xu <herbert@gondor.apana.org.au>
    crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm

Herbert Xu <herbert@gondor.apana.org.au>
    crypto: tegra - Fix dma_free_coherent size error

Aleksander Jan Bajkowski <olek2@wp.pl>
    crypto: inside-secure/eip93 - Add check for devm_request_threaded_irq

Weili Qian <qianweili@huawei.com>
    crypto: hisilicon/qm - disable error report before flr

Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
    ocfs2: kill osb->system_file_mutex lock

ZhengYuan Huang <gality369@gmail.com>
    ocfs2: don't BUG_ON an invalid journal dinode

Dan Carpenter <error27@gmail.com>
    rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()

Yury Norov <ynorov@nvidia.com>
    uaccess: minimize INLINE_COPY_USER-related ifdefery

Yury Norov <ynorov@nvidia.com>
    uaccess: unify inline vs outline copy_{from,to}_user() selection

Yury Norov <ynorov@nvidia.com>
    rust: uaccess: use INLINE_COPY_TO_USER to guard copy_to_user()

Josh Law <objecting@objecting.org>
    lib/base64: validate before writing in decode tail path

Davidlohr Bueso <dave@stgolabs.net>
    dax/kmem: account for partial discontiguous resource upon removal

Danilo Krummrich <dakr@kernel.org>
    rust: devres: add 'static bound to Devres<T>

Brian Norris <briannorris@chromium.org>
    arm64: tegra: Add #{address,size}-cells to Chromium-based /firmware

Brian Norris <briannorris@chromium.org>
    ARM: tegra: Add #{address,size}-cells to Chromium-based /firmware

Carlos Llamas <cmllamas@google.com>
    libbpf: Fix UAF in strset__add_str()

Siddharth Nayyar <sidnayyar@google.com>
    bpftool: Fix typo in struct_ops map FD generation for light skeleton

Michael Bommarito <michael.bommarito@gmail.com>
    libbpf: Harden parse_vma_segs() path parsing

Timur Tabi <ttabi@nvidia.com>
    drm/nouveau/bios: specify correct display fuse register for Ampere and Ada

Mikko Perttunen <mperttunen@nvidia.com>
    drm/tegra: Fix iommu_map_sgtable() return value check

Mikko Perttunen <mperttunen@nvidia.com>
    gpu: host1x: Fix iommu_map_sgtable() return value check

Felix Gu <ustc.gu@gmail.com>
    drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output()

Felix Gu <ustc.gu@gmail.com>
    gpu: host1x: mipi: Fix device_node reference leak in tegra_mipi_request()

Thomas Zimmermann <tzimmermann@suse.de>
    drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info

Mikko Perttunen <mperttunen@nvidia.com>
    gpu: host1x: Allow entries in BO caches to be freed

Ion Agorria <ion@agorria.com>
    drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove

Svyatoslav Ryhel <clamor95@gmail.com>
    drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered

Tomas Glozar <tglozar@redhat.com>
    rtla/actions: Restore continue flag in actions_perform()

Linus Walleij <linusw@kernel.org>
    dt-bindings: vendor-prefixes: Add Verbatim Corporation

Jackie Dong <xy-jackie@139.com>
    ALSA: hda/realtek:ALC269 fixup for Yoga Pro 7 15ASH11 mic mute LED

Vasant Hegde <vasant.hegde@amd.com>
    iommu/amd: Fix premature break in init_iommu_one()

Jiayuan Chen <jiayuan.chen@linux.dev>
    net/sched: cls_bpf: prevent unbounded recursion in offload rollback

Eric Dumazet <edumazet@google.com>
    ipv6: guard against possible NULL deref in __in6_dev_stats_get()

Breno Leitao <leitao@debian.org>
    workqueue: drop spurious '*' from print_worker_info() fn declaration

Mateusz Nowicki <mateusz.nowicki@posteo.net>
    nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools

Nilay Shroff <nilay@linux.ibm.com>
    nvme-multipath: fix flex array size in struct nvme_ns_head

Geliang Tang <geliang@kernel.org>
    nvmet-tcp: check return value of nvmet_tcp_set_queue_sock

Geliang Tang <geliang@kernel.org>
    nvmet-tcp: fix page fragment cache leak in error path

Jia He <justin.he@arm.com>
    init/initramfs_test: wait_for_initramfs() before running

Charles Keepax <ckeepax@opensource.cirrus.com>
    pinctrl: cs42l43: Fix polarity on debounce

Charles Keepax <ckeepax@opensource.cirrus.com>
    pinctrl: cs42l43: Fix leaked pm reference on error path

Joey Lu <a0987203069@gmail.com>
    pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table

Florian Schmaus <flo@geekplace.eu>
    selftests: Fix Makefile target for nsfs

Zhang Cen <rollkingzzc@gmail.com>
    ALSA: seq: midi: Serialize output teardown with event_input

Takashi Iwai <tiwai@suse.de>
    ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ALSA: xen-front: Connect event channel after stream prepare

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ALSA: xen-front: Reset event channel state on stream clear

Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
    cpufreq: governor: Fix stale prev_cpu_nice spike when enabling ignore_nice_load

Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
    cpufreq: governor: Fix data races on per-CPU idle/nice baselines

Ripan Deuri <ripan.deuri@oss.qualcomm.com>
    wifi: ath12k: fix error unwind on arch_init() failure in PCI probe

Miquel Raynal <miquel.raynal@bootlin.com>
    mtd: spi-nor: Drop duplicate Kconfig dependency

Miquel Raynal <miquel.raynal@bootlin.com>
    mtd: spi-nor: debugfs: Fix the flags list

Jon Hunter <jonathanh@nvidia.com>
    arm64: tegra: Fix address of Tegra264 main GPIO controller

Danilo Krummrich <dakr@kernel.org>
    driver core: Guard deferred probe timeout extension with delayed_work_pending()

Danilo Krummrich <dakr@kernel.org>
    driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout()

Rosen Penev <rosenp@gmail.com>
    mips: n64: add __iomem for writel call

Rosen Penev <rosenp@gmail.com>
    mips: ralink: mt7621: add missing __iomem

Maciej W. Rozycki <macro@orcam.me.uk>
    MIPS: DEC: Remove do_IRQ() call indirection

Maciej W. Rozycki <macro@orcam.me.uk>
    MIPS: Fix big-endian stack argument fetching in o32 wrapper

Jiakai Xu <xujiakai24@mails.ucas.ac.cn>
    PM: sleep: Use complete() in device_pm_sleep_init()

Xianwei Zhao <xianwei.zhao@amlogic.com>
    pinctrl: meson: amlogic-a4: fix gpio output glitch

Tao Cui <cuitao@kylinos.cn>
    RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    ACPI: PAD: Fix teardown ordering in acpi_pad_remove()

Lianfa Weng <wenglianfa@huawei.com>
    RDMA/hns: Fix log flood after cmd_mbox failure

Lianfa Weng <wenglianfa@huawei.com>
    RDMA/hns: Fix warning in poll cq direct mode

Eliot Courtney <ecourtney@nvidia.com>
    gpu: nova-core: vbios: use checked accesses in `setup_falcon_data`

Eliot Courtney <ecourtney@nvidia.com>
    gpu: nova-core: vbios: use checked access in `FwSecBiosImage::header`

Eliot Courtney <ecourtney@nvidia.com>
    gpu: nova-core: vbios: use checked ops and accesses in `FwSecBiosImage::ucode`

Eliot Courtney <ecourtney@nvidia.com>
    gpu: nova-core: vbios: read BitToken using FromBytes

Eliot Courtney <ecourtney@nvidia.com>
    gpu: nova-core: vbios: avoid reading too far in read_more_at_offset

Eliot Courtney <ecourtney@nvidia.com>
    gpu: nova-core: vbios: use checked arithmetic for bios image range end

Eliot Courtney <ecourtney@nvidia.com>
    gpu: nova-core: vbios: stop scanning at BIOS_MAX_SCAN_LEN

Guangshuo Li <lgs201920130244@gmail.com>
    IB/mlx4: Fix refcount leak in add_port() error path

Zhu Yanjun <yanjun.zhu@linux.dev>
    RDMA/rxe: Fix a use-after-free problem in rxe_mmap

Jacob Moroni <jmoroni@google.com>
    RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs

Chancel Liu <chancel.liu@nxp.com>
    ASoC: dapm: Fix widget lookup with prefixed names across DAPM contexts

Han Gao <gaohan@iscas.ac.cn>
    pinctrl: spacemit: fix NULL check in spacemit_pin_set_config

Samuel Holland <samuel@sholland.org>
    bus: sunxi-rsb: Always check register address validity

Daniel Palmer <daniel@thingy.jp>
    tools/nolibc: stackprotector: Avoid stalling program startup if crng is not init yet

Shiraz Saleem <shirazsaleem@microsoft.com>
    RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed

Ronaldo Nunez <rnunez@baylibre.com>
    pwm: imx27: Fix variable truncation in .apply()

Lifeng Zheng <zhenglifeng1@huawei.com>
    cpufreq: conservative: Simplify frequency limit handling

Pengjie Zhang <zhangpengjie2@huawei.com>
    cpufreq: Documentation: fix sampling_down_factor range

Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
    drm/msm/mdss: correct UBWC programming sequences

Cássio Gabriel <cassiogabrielcontato@gmail.com>
    ASoC: mediatek: mt8189: Fix probe resource cleanup

Aleksander Jan Bajkowski <olek2@wp.pl>
    crypto: eip93 - fix reset ring register definition

Saravana Kannan <saravanak@kernel.org>
    of: dynamic: Fix overlayed devices not probing because of fw_devlink

Saravana Kannan <saravanak@kernel.org>
    Revert "treewide: Fix probing of devices in DT overlays"

Zhang Yuwei <zhangyuwei20@huawei.com>
    driver core: Use mod_delayed_work to prevent lost deferred probe work

Stepan Ionichev <sozdayvek@gmail.com>
    device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id()

Conor Kotwasinski <conorkotwasinski2024@u.northwestern.edu>
    kernfs: fix suspicious RCU usage in kernfs_put()

Baokun Li <libaokun@linux.alibaba.com>
    writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount()

Joel Selvaraj <foss@joelselvaraj.com>
    arm64: dts: qcom: sdm845-xiaomi-beryllium: Correct IPA FW path

Gopikrishna Garmidi <gopikrishna.garmidi@oss.qualcomm.com>
    arm64: dts: qcom: glymur: Fix wrong interrupt number for i2c19

Ritesh Kumar <quic_riteshk@quicinc.com>
    arm64: dts: qcom: lemans: Add eDP ref clock for eDP PHYs

Pengpeng Hou <pengpeng@iscas.ac.cn>
    tracing: Bound synthetic-field strings with seq_buf

Harshal Dev <harshal.dev@oss.qualcomm.com>
    arm64: dts: qcom: sm8750: Add power-domain and iface clk for ice node

Harshal Dev <harshal.dev@oss.qualcomm.com>
    arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node

Harshal Dev <harshal.dev@oss.qualcomm.com>
    arm64: dts: qcom: sm8550: Add power-domain and iface clk for ice node

Harshal Dev <harshal.dev@oss.qualcomm.com>
    arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node

Harshal Dev <harshal.dev@oss.qualcomm.com>
    arm64: dts: qcom: kodiak: Add power-domain and iface clk for ice node

Harshal Dev <harshal.dev@oss.qualcomm.com>
    arm64: dts: qcom: sc7180: Add power-domain and iface clk for ice node

Harshal Dev <harshal.dev@oss.qualcomm.com>
    arm64: dts: qcom: monaco: Add power-domain and iface clk for ice node

Harshal Dev <harshal.dev@oss.qualcomm.com>
    arm64: dts: qcom: lemans: Add power-domain and iface clk for ice node

Harshal Dev <harshal.dev@oss.qualcomm.com>
    arm64: dts: qcom: kaanapali: Add power-domain and iface clk for ice node

Abel Vesa <abel.vesa@oss.qualcomm.com>
    arm64: dts: qcom: eliza-mtp: Fix the debug UART index

Geert Uytterhoeven <geert+renesas@glider.be>
    firmware: arm_scmi: Fix OOB in scmi_power_name_get()

Sven Püschel <s.pueschel@pengutronix.de>
    media: rockchip: rga: fix too small buffer size

Nishanth Sampath Kumar <nissampa@cisco.com>
    regmap-i2c: fix sparse warning in regmap_smbus_word_write_reg16

Eric Dumazet <edumazet@google.com>
    net/sched: sch_drr: annotate data-races around cl->deficit

GuoHan Zhao <zhaoguohan@kylinos.cn>
    vfio/xe: avoid duplicate reset in xe_vfio_pci_reset_done

Hongling Zeng <zenghongling@kylinos.cn>
    nilfs2: Fix return in nilfs_mkdir

David Matlack <dmatlack@google.com>
    vfio: selftests: Allow builds when ARCH=x86

Jason Gunthorpe <jgg@ziepe.ca>
    vfio: selftests: Fix out-of-tree build with make O=

Daniel Palmer <daniel@thingy.jp>
    tools/nolibc: getopt: Fix potential out of bounds access

Chen-Yu Tsai <wenst@chromium.org>
    regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions

Randy Dunlap <rdunlap@infradead.org>
    bitops: use common function parameter names

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    sysfs: clamp show() return value in sysfs_kf_read()

Guoniu Zhou <guoniu.zhou@oss.nxp.com>
    media: synopsys: Fix IPI using hardcoded datatype

Sudeep Holla <sudeep.holla@kernel.org>
    firmware: arm_scmi: Read sensor config as 32-bit value

Andre Przywara <andre.przywara@arm.com>
    firmware: smccc: Fix Arm SMCCC SOC_ID name call

Aurelien Jarno <aurelien@aurel32.net>
    riscv: dts: spacemit: fix uboot partition offset on Milk-V Jupiter

Aurelien Jarno <aurelien@aurel32.net>
    riscv: dts: spacemit: set console baud rate on Milk-V Jupiter

Jose A. Perez de Azpillaga <azpijr@gmail.com>
    staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy()

Yuho Choi <dbgh9129@gmail.com>
    media: atomisp: gc2235: fix UAF and memory leak

Zilin Guan <zilin@seu.edu.cn>
    media: atomisp: Fix memory leak in atomisp_fixed_pattern_table()

Viacheslav Dubeyko <slava@dubeyko.com>
    hfs: fix incorrect inode ID assignment in hfs_new_inode()

Sherry Sun <sherry.sun@nxp.com>
    arm64: dts: imx95-19x19-evk: Fix PCIe EP vpcie-supply

Sherry Sun <sherry.sun@nxp.com>
    arm64: dts: imx8qxp-mek: Remove unnecessary PCIe EP vpcie-supply

Sherry Sun <sherry.sun@nxp.com>
    arm64: dts: imx8dxl-evk: Remove unnecessary PCIe EP properties

Francesco Dolcini <francesco.dolcini@toradex.com>
    arm64: dts: freescale: imx95-verdin-ivy: fix RS485 RTS polarity

Jamie Nguyen <jamien@nvidia.com>
    firmware: arm_ffa: Honor partition info descriptor size

Kevin Brodsky <kevin.brodsky@arm.com>
    selftests/mm: Fix resv_sz when parsing arm64 signal frame

Vincent Guittot <vincent.guittot@linaro.org>
    sched/fair: Update util_est after updating util_avg during dequeue

Bibek Kumar Patro <bibek.patro@oss.qualcomm.com>
    iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match table

Paul Chaignon <paul.chaignon@gmail.com>
    selftests/bpf: Fix test for refinement of single-value tnum

Roman Kvasnytskyi <roman@kvasnytskyi.net>
    selftests/bpf: Reject unsupported -k option in vmtest.sh

Paul Chaignon <paul.chaignon@gmail.com>
    selftests/bpf: Override EXTRA_LDFLAGS for static builds

Fengnan Chang <changfengnan@bytedance.com>
    dm: limit target bio polling to one shot

Liviu Dudau <liviu.dudau@arm.com>
    drm/syncobj: Fix memory leak in drm_syncobj_find_fence()

Crystal Wood <crwood@redhat.com>
    rtla: Stop the record trace on interrupt

Costa Shulyupin <costa.shul@redhat.com>
    tools/rtla: Fix --dump-tasks usage in timerlat

Junxian Huang <huangjunxian6@hisilicon.com>
    RDMA/hns: Initialize seqfile before creating file

Sara Venkatesh <sarajvenkatesh@gmail.com>
    RDMA/srpt: fix integer overflow in immediate data length check

Prathamesh Deshpande <prathameshdeshpande7@gmail.com>
    RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference

Prathamesh Deshpande <prathameshdeshpande7@gmail.com>
    RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure

Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
    RDMA/hns: Fix arithmetic overflow in calc_hem_config()

Prathamesh Deshpande <prathameshdeshpande7@gmail.com>
    IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier

Linmao Li <lilinmao@kylinos.cn>
    ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD

Eric Dumazet <edumazet@google.com>
    net/sched: sch_htb: annotate data-races (I)

Eric Dumazet <edumazet@google.com>
    net/sched: sch_htb: do not change sch->flags in htb_dump()

Eric Dumazet <edumazet@google.com>
    net/sched: sch_dualpi2: annotate data-races in dualpi2_dump_stats()

Eric Dumazet <edumazet@google.com>
    net/sched: add qdisc_qlen_inc() and qdisc_qlen_dec()

Qiang Ma <maqianga@uniontech.com>
    spi: hisi-kunpeng: Use dev_err_probe() for host registration failure

Abdun Nihaal <nihaal@cse.iitm.ac.in>
    crypto: safexcel - Fix potential memory leak in safexcel_pci_probe()

Stepan Ionichev <sozdayvek@gmail.com>
    crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL

Herbert Xu <herbert@gondor.apana.org.au>
    crypto: af_alg - Cap AEAD AD length to 0x80000000

Sean Christopherson <seanjc@google.com>
    crypto: ccp - Treat zero-length cert chain as query for blob lengths

Yihang Li <liyihang9@huawei.com>
    scsi: hisi_sas: Add slave_destroy interface for v3 hw

Eric Dumazet <edumazet@google.com>
    net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats()

Stepan Ionichev <sozdayvek@gmail.com>
    clk: scpi: Unregister child clock providers on remove

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    thermal: hwmon: Register a hwmon device for each thermal zone

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    thermal: hwmon: Fix critical temperature attribute removal

Pengpeng Hou <pengpeng@iscas.ac.cn>
    evm: terminate and bound the evm_xattrs read buffer

Lin He <helin52@huawei.com>
    drm/hisilicon/hibmc: use clock to look up the PLL value

Lin He <helin52@huawei.com>
    drm/hisilicon/hibmc: move display contrl config to hibmc_probe()

Lin He <helin52@huawei.com>
    drm/hisilicon/hibmc: fix no showing when no connectors connected

Lin He <helin52@huawei.com>
    drm/hisilicon/hibmc: add updating link cap in DP detect()

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    platform/chrome: wilco_ec: event: Check ACPI_COMPANION()

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    platform/chrome: chromeos_tbmc: Check ACPI_COMPANION()

Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    platform/chrome: chromeos_privacy_screen: Check ACPI_COMPANION()

Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
    arm64: dts: qcom: sm8450: Fix ICE reg size

Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
    arm64: dts: qcom: kodiak: Fix ICE reg size

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    arm64: dts: qcom: sm8750: Fix DSI1 phy reference clock rate

Cristian Marussi <cristian.marussi@arm.com>
    clk: scmi: Fix clock rate rounding

Hsiu Che Yu <yu.whisper.personal@gmail.com>
    rust: alloc: fix `Vec::extend_with` SAFETY comment

Christian Brauner <brauner@kernel.org>
    rhashtable: give each instance its own lockdep class

Abel Vesa <abel.vesa@oss.qualcomm.com>
    arm64: dts: qcom: glymur: Mark USB SS1 and SS2 as role-switch capable

Abel Vesa <abel.vesa@oss.qualcomm.com>
    arm64: dts: qcom: glymur-crd: Drop forced host mode for USB SS0 and SS1

Yang Wang <kevinyang.wang@amd.com>
    drm/amdgpu: fix error return code in mes_v12_1_map_test_bo

Breno Leitao <leitao@debian.org>
    workqueue: forbid TEST_WORKQUEUE from being built-in

Chen-Yu Tsai <wenst@chromium.org>
    arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host

Frank Wunderlich <frank-w@public-files.de>
    arm64: dts: mediatek: mt7988a-bpi-r4pro: rework pcie gpio-hog handling

Stefan Metzmacher <metze@samba.org>
    sockptr: fix usize check in copy_struct_from_sockptr() for user pointers

Stefan Metzmacher <metze@samba.org>
    uaccess: fix ignored_trailing logic in copy_struct_to_user()

Matt Bobrowski <mattbobrowski@google.com>
    bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries

Luca Leonardo Scorcia <l.scorcia@gmail.com>
    soc: mediatek: mtk-mmsys: Restore MT8167 routing masks lost during merge

Sean Christopherson <seanjc@google.com>
    iommu/amd: Fix a stale comment about which legacy mode is user visible

Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
    media: venus: scale MMCX power domain on SM8250

Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
    media: iris: scale MMCX power domain on SM8250

Shawn Guo <shengchao.guo@oss.qualcomm.com>
    arm64: dts: qcom: lemans: Move PCIe devices into soc node

Nickolay Goppen <setotau@mainlining.org>
    arm64: dts: qcom: sdm630: set adsp compute-cbs' regs properly

Nickolay Goppen <setotau@mainlining.org>
    arm64: dts: qcom: sdm660: set cdsp compute-cbs' regs properly

Yixun Lan <dlan@kernel.org>
    dts: riscv: spacemit: correct 32k clock frequency

Wenmeng Liu <wenmeng.liu@oss.qualcomm.com>
    media: qcom: camss: vfe: fix PIX subdev naming on VFE lite

Leon Romanovsky <leon@kernel.org>
    ntb: Use consistent DMA attributes when freeing DMA mappings

Leon Romanovsky <leon@kernel.org>
    ntb: Store original DMA address for future release

Shuangpeng Bai <shuangpeng.kernel@gmail.com>
    nilfs2: fix backing_dev_info reference leak

Alexander Aring <aahringo@redhat.com>
    dlm: fix add msg handle in send_queue ordered

Lizhi Hou <lizhi.hou@amd.com>
    accel/amdxdna: Fix clflush buffer size

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD

Weiming Shi <bestswngs@gmail.com>
    crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents

Thorsten Blum <thorsten.blum@linux.dev>
    crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve

Lothar Rubusch <l.rubusch@gmail.com>
    crypto: atmel-sha204a - fix blocking and non-blocking rng logic

Tycho Andersen (AMD) <tycho@kernel.org>
    crypto: ccp - Initialize data during __sev_snp_init_locked()

Tycho Andersen (AMD) <tycho@kernel.org>
    crypto: ccp - Check for page allocation failure correctly in TIO

Tycho Andersen (AMD) <tycho@kernel.org>
    crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one

Tycho Andersen (AMD) <tycho@kernel.org>
    crypto: ccp - Reverse the cleanup order in psp_dev_destroy()

Di Shen <di.shen@unisoc.com>
    OPP: Fix race between OPP addition and lookup

Zhan Xusheng <zhanxusheng1024@gmail.com>
    alarmtimer: Remove stale return description from alarm_handle_timer()

Chris Brandt <chris.brandt@renesas.com>
    drm: renesas: rz-du: mipi_dsi: Fix return path on error

Kuniyuki Iwashima <kuniyu@google.com>
    vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().

Peng Fan <peng.fan@nxp.com>
    Revert "arm64: dts: imx8mp-kontron: Add support for reading SD_VSEL signal"

Peng Fan <peng.fan@nxp.com>
    Revert "arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL signal"

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    arm64: dts: imx8mp-ab2: Correct interrupt flags

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    arm64: dts: imx8mn-vhip4-evalboard-v2: Correct interrupt flags

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    arm64: dts: imx8mn-vhip4-evalboard-v1: Correct interrupt flags

Peng Fan <peng.fan@nxp.com>
    arm64: dts: imx8x-colibri: Correct SODIMM PAD settings

Weixin Guo <2298701336@qq.com>
    arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc

Brian Norris <briannorris@chromium.org>
    arm64: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware

Brian Norris <briannorris@chromium.org>
    ARM: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware

Duje Mihanović <duje@dujemihanovic.xyz>
    arm64: dts: marvell: samsung-coreprimevelte: Increase touchscreen voltage

Conor Dooley <conor.dooley@microchip.com>
    riscv: dts: microchip: fix pic64gx gpio interrupt-cells

Conor Dooley <conor.dooley@microchip.com>
    riscv: dts: microchip: update pic64gx gpio interrupts to better match the SoC

David Heidelberg <david@ixit.cz>
    drm/panel: Clean up S6E3HA2 config dependencies and fill help text

David Heidelberg <david@ixit.cz>
    drm/panel: Clean up S6E3FC2X01 config dependencies

Marijn Suijten <marijn.suijten@somainline.org>
    drm/panel: Clean up SOFEF00 config dependencies

Peddolla Harshavardhan Reddy <peddolla.reddy@oss.qualcomm.com>
    wifi: cfg80211: restrict LMR feedback check to TB and non-TB ranging

Alice Ryhl <aliceryhl@google.com>
    drm/gpuvm: take refcount on DRM device

Marek Vasut <marex@nabladev.com>
    dt-bindings: vendor-prefixes: Add Displaytech Ltd.

Conor Dooley <conor.dooley@microchip.com>
    riscv: dts: microchip: remove gpio hogs from beaglev-fire

Conor Dooley <conor.dooley@microchip.com>
    riscv: dts: microchip: gpio controllers on mpfs need 2 interrupt cells

Felix Gu <ustc.gu@gmail.com>
    pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path

Conor Dooley <conor.dooley@microchip.com>
    dts: spacemit: set console baud rate on bpif3

Masami Hiramatsu (Google) <mhiramat@kernel.org>
    lib/vsprintf: Fix to check field_width and precision

Damian Muszynski <damian.muszynski@intel.com>
    crypto: qat - fix heartbeat error injection

Josh Poimboeuf <jpoimboe@kernel.org>
    klp-build: Fix patch cleanup on interrupt

Josh Poimboeuf <jpoimboe@kernel.org>
    klp-build: Fix checksum comparison for changed offsets

Josh Poimboeuf <jpoimboe@kernel.org>
    klp-build: Fix hang on out-of-date .config

Josh Poimboeuf <jpoimboe@kernel.org>
    objtool: Fix reloc hash collision in find_reloc_by_dest_range()

Josh Poimboeuf <jpoimboe@kernel.org>
    objtool: Replace iterator callback with for_each_sym_by_mangled_name()

Josh Poimboeuf <jpoimboe@kernel.org>
    objtool/klp: Fix relocation conversion failures for R_X86_64_NONE

Josh Poimboeuf <jpoimboe@kernel.org>
    objtool/klp: Fix extraction of text annotations for alternatives

Josh Poimboeuf <jpoimboe@kernel.org>
    objtool/klp: Fix cloning of zero-length section symbols

Josh Poimboeuf <jpoimboe@kernel.org>
    objtool/klp: Fix handling of zero-length .altinstr_replacement sections

Joe Lawrence <joe.lawrence@redhat.com>
    objtool/klp: Fix create_fake_symbols() skipping entsize-based sections

Josh Poimboeuf <jpoimboe@kernel.org>
    objtool/klp: Fix .data..once static local non-correlation

Joe Lawrence <joe.lawrence@redhat.com>
    objtool/klp: Fix is_uncorrelated_static_local() for Clang

Ashish Mhetre <amhetre@nvidia.com>
    memory: tegra: Wire up system sleep PM ops

Icenowy Zheng <zhengxingda@iscas.ac.cn>
    drm: verisilicon: call atomic helper's plane state check even if no CRTC

Nas Chung <nas.chung@chipsnmedia.com>
    media: v4l2-common: Add YUV24 format info

Samuel Holland <samuel@sholland.org>
    media: cedrus: Fix failure to clean up hardware on probe failure

Felix Gu <ustc.gu@gmail.com>
    watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure

Balakrishnan Sambath <balakrishnan.s@microchip.com>
    watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5

Yingjie Gao <gaoyingjie@uniontech.com>
    watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH

Gabriele Monaco <gmonaco@redhat.com>
    Documentation/rv: Replace stale website link

Aleksandr Loktionov <aleksandr.loktionov@intel.com>
    ixgbe: fix unaligned u32 access in ixgbe_update_flash_X550()

Jihed Chaibi <jihed.chaibi.dev@gmail.com>
    ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint

Wei Zhang <wei.zhang@oss.qualcomm.com>
    wifi: ath11k: cancel SSR work items during PCI shutdown

Tristan Madani <tristan@talencesecurity.com>
    wifi: ath9k: fix OOB access from firmware tx status queue ID

Chen-Yu Tsai <wenst@chromium.org>
    pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask()

Prasanna Kumar T S M <ptsm@linux.microsoft.com>
    soc: xilinx: Shutdown and free rx mailbox channel

Prasanna Kumar T S M <ptsm@linux.microsoft.com>
    soc: xilinx: Fix race condition in event registration

Xingjing Deng <micro6947@gmail.com>
    kconfig: fix potential NULL pointer dereference in conf_askvalue

Tristan Madani <tristan@talencesecurity.com>
    wifi: rtw89: add bounds check on firmware mac_id in link lookup

Tristan Madani <tristan@talencesecurity.com>
    wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer

Shin-Yi Lin <isaiah@realtek.com>
    wifi: rtw89: Correct data type for scan index to avoid infinite loop

Chin-Yen Lee <timlee@realtek.com>
    wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers

Christos Longros <chris.longros@gmail.com>
    wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers

Timur Tabi <ttabi@nvidia.com>
    gpu: nova-core: use correct fwsignature for GA100

Danilo Krummrich <dakr@kernel.org>
    driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()

Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>
    drm/amdkfd: Validate CRIU-restored IDs before idr_alloc

Felix Gu <ustc.gu@gmail.com>
    pinctrl: pinconf-generic: fix properties bitmap leak in parse_fw_cfg()

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    dt-bindings: pinctrl: nvidia,tegra234: Add missing required block

Jon Hunter <jonathanh@nvidia.com>
    arm64: tegra: Fix Tegra234 MGBE PTP clock

Louis Kotze <loukot@gmail.com>
    wifi: cfg80211: fix grammar in MLO group key error message

Edward Adam Davis <eadavis@qq.com>
    hfsplus: Add a sanity check for btree node size

Edward Adam Davis <eadavis@qq.com>
    hfsplus: Remove the duplicate attr inode dirty marking action

David Heidelberg <david@ixit.cz>
    arm64: dts: qcom: sdm845-shift-axolotl: Correct touchscreen sleep state

Kamal Wadhwa <kamal.wadhwa@oss.qualcomm.com>
    arm64: dts: qcom: fix temp-alarm probe failure for PMH0104 on Glymur

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    arm64: dts: qcom: ipq5424: Fix USB simple_bus_reg warnings

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    arm64: dts: qcom: glymur: Fix cache and SRAM simple_bus_reg warnings

Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
    arm64: dts: qcom: glymur: Fix USB simple_bus_reg warning

David Heidelberg <david@ixit.cz>
    arm64: dts: qcom: sdm845-oneplus: Drop address from framebuffer node

Alexander Koskovich <akoskovich@pm.me>
    arm64: dts: qcom: milos: Reduce rmtfs_mem size to 2.5MiB

Sean Christopherson <seanjc@google.com>
    x86/bug: Add printf() validation to HAVE_ARCH_BUG_FORMAT_ARGS WARNs

Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
    dt-bindings: net: bluetooth: qualcomm: Fix WCN6855 regulator names

Kamlesh Kumar <kamlesh0hrs@gmail.com>
    ima: Fix sigv3 signature handling for EVM_IMA_XATTR_DIGSIG

Diederik de Haas <diederik@cknow-tech.com>
    arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S

Quentin Schulz <quentin.schulz@cherry.de>
    arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Cobra

Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
    arm64: dts: rockchip: Update vdec register blocks order on RK3588

Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
    arm64: dts: rockchip: Fix vdec register blocks order on RK3576

Baolin Liu <liubaolin@kylinos.cn>
    Documentation: proc: fix section numbering in table of contents

Gregory Bell <grbell@redhat.com>
    selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern

Gregory Bell <grbell@redhat.com>
    selftests/bpf: Use local type for flow_offload_tuple_rhash in xdp_flowtable

Felix Gu <ustc.gu@gmail.com>
    spi: atcspi200: fix use-after-free when driver unbind

Yang Wang <kevinyang.wang@amd.com>
    drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro

Antoine Tenart <atenart@kernel.org>
    libbpf: Fix deduplication of typedef with base definitions

Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
    wifi: ath12k: Fix invalid IRQ requests during AHB probe

Nick Hu <nick.hu@sifive.com>
    dt-bindings: timer: Remove sifive,fine-ctr-bits property

Matt Bobrowski <mattbobrowski@google.com>
    selftests/bpf: Fix off-by-one in bpf_cpumask_populate related selftest

Aaron Tomlin <atomlin@atomlin.com>
    libbpf: Report error when a negative kprobe offset is specified

Yuho Choi <dbgh9129@gmail.com>
    drm/radeon: fix memory leak in radeon_ring_restore() on lock failure

Werner Kasselman <werner@verivus.ai>
    drm/radeon: fix integer overflow in radeon_align_pitch()

Alex Sierra <alex.sierra@amd.com>
    drm/amdkfd: fix redundant MQD iterations in GFX v12.1

Werner Kasselman <werner@verivus.ai>
    drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch()

Max Zhen <max.zhen@amd.com>
    accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer

Jonathan Cavitt <jonathan.cavitt@intel.com>
    drm/gpuvm: Do not prepare NULL objects

Felix Gu <ustc.gu@gmail.com>
    accel/amdxdna: Fix memory leak in amdxdna_iommu_alloc()

Max Zhen <max.zhen@amd.com>
    accel/amdxdna: Fix fatal_error_info layout in firmware interface

Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
    dma-fence: Fix potential tracepoint null pointer dereferences

Lizhi Hou <lizhi.hou@amd.com>
    accel/amdxdna: Fix order of canceled mailbox messages

Lizhi Hou <lizhi.hou@amd.com>
    accel/amdxdna: Fix iommu_map_sgtable() return value handling

Max Zhen <max.zhen@amd.com>
    accel/amdxdna: Handle DETACH_DEBUG_BO through config_debug_bo path

Lizhi Hou <lizhi.hou@amd.com>
    accel/amdxdna: Adjust size for copy_to_user()

Lizhi Hou <lizhi.hou@amd.com>
    accel/amdxdna: Create shared functions for AIE2 and AIE4

Matthew Brost <matthew.brost@intel.com>
    drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges

Tomi Valkeinen <tomi.valkeinen@ideasonboard.com>
    drm/tidss: Drop extra drm_mode_config_reset() call

Thomas Zimmermann <tzimmermann@suse.de>
    drm/rockchip: Test for imported buffers with drm_gem_is_imported()

Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
    drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove()

Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
    drm/rockchip: dw_dp: Switch to drmm_kzalloc()

Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
    drm/rockchip: inno-hdmi: Switch to drmm_kzalloc()

Max Zhen <max.zhen@amd.com>
    accel/amdxdna: Fix leak when pinning ubuf pages

Chen Ni <nichen@iscas.ac.cn>
    clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive()

Stafford Horne <shorne@gmail.com>
    openrisc: mm: Fix section mismatch between map_page and __set_fixmap

Felix Gu <ustc.gu@gmail.com>
    soc: fsl: qe_ports_ic: Add missing cleanup on device removal

Jiacheng Yu <yujiacheng3@huawei.com>
    fbcon: Use correct type for vc_resize() return value

Ian Bridges <icb@fastmail.org>
    fbcon: fix NULL pointer dereference for a console without vc_data

David Howells <dhowells@redhat.com>
    afs: Fix uncancelled rxrpc OOB message handler

David Howells <dhowells@redhat.com>
    afs: Fix further netns teardown to cancel the preallocation charger

Nan Li <tonanli66@gmail.com>
    afs: handle CB.InitCallBackState3 requests without a server record

Matvey Kovalev <matvey.kovalev@ispras.ru>
    afs: fix NULL pointer dereference in afs_get_tree()

David Howells <dhowells@redhat.com>
    afs: Fix netns teardown to cancel the preallocation charger

David Howells <dhowells@redhat.com>
    rxrpc: Fix double unlock in rxrpc_recvmsg()

David Howells <dhowells@redhat.com>
    rxrpc: Fix leak of connection from OOB challenge

David Howells <dhowells@redhat.com>
    rxrpc: Fix the reception of a reply packet before data transmission

Wyatt Feng <bronzed_45_vested@icloud.com>
    rxrpc: Fix ACKALL packet handling

David Howells <dhowells@redhat.com>
    rxrpc: Fix oob challenge leak in cleanup after notification failure

David Howells <dhowells@redhat.com>
    rxrpc: Fix rxrpc_rotate_tx_rotate() to check there's something to rotate

David Howells <dhowells@redhat.com>
    rxrpc: Fix potential infinite loop in rxrpc_recvmsg()

David Howells <dhowells@redhat.com>
    rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)

David Howells <dhowells@redhat.com>
    rxrpc: Fix socket notification race

David Howells <dhowells@redhat.com>
    rxrpc: Fix UAF in rxgk_issue_challenge()

Hyunwoo Kim <imv4bel@gmail.com>
    rxrpc: Don't move a peeked OOB message onto the pending queue

Jeffrey Altman <jaltman@auristor.com>
    rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc

Li Daming <d4n.for.sec@gmail.com>
    rxrpc: serialize kernel accept preallocation with socket teardown

Matthias Feser <mfe@KBSgmbhfr.onmicrosoft.com>
    serial: 8250_omap: clear rx_running on zero-length DMA completes

Tapio Reijonen <tapio.reijonen@vaisala.com>
    serial: max310x: implement gpio_chip::get_direction()

Stephan Gerhold <stephan.gerhold@linaro.org>
    serial: msm: Disable DMA for kernel console UART

Guoniu Zhou <guoniu.zhou@oss.nxp.com>
    dt-bindings: power: imx93: Add MIPI PHY power domain

Chen-Yu Tsai <wens@kernel.org>
    dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties

Ricardo Ribalda <ribalda@chromium.org>
    media: uvcvideo: Fix sequence number when no EOF

Ricardo Ribalda <ribalda@chromium.org>
    media: uvcvideo: Relax the constrains for interpolating the hw clock

Ricardo Ribalda <ribalda@chromium.org>
    media: uvcvideo: Do not add clock samples with small sof delta

Ricardo Ribalda <ribalda@chromium.org>
    media: uvcvideo: Fix dev_sof filtering in hw timestamp

Ricardo Ribalda <ribalda@chromium.org>
    media: uvcvideo: Fix buffer sequence in frame gaps

Ricardo Ribalda <ribalda@chromium.org>
    media: uvcvideo: Avoid partial metadata buffers

Ricardo Ribalda <ribalda@chromium.org>
    media: uvcvideo: Use hw timestaming if the clock buffer is full

Damien Laine <damien.laine@gmail.com>
    ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID 17aa:38a7

Xu Rao <raoxu@uniontech.com>
    ALSA: hda: Fix cached processing coefficient verbs

Zhang Heng <zhangheng@kylinos.cn>
    ALSA: hda: conexant: Remove mic bias threshold override

Eckhart Mohr <e.mohr@tuxedocomputers.com>
    ALSA: hda/realtek: Add quirk for TongFang X6xx45xU

Sean Anderson <sean.anderson@linux.dev>
    media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work

Eric Biggers <ebiggers@kernel.org>
    crypto: sun4i-ss - Remove insecure and unused rng_alg

Michael Bommarito <michael.bommarito@gmail.com>
    iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry

Muhammet Kaan KILINÇ <muhammetkaankilinc@gmail.com>
    crypto: algif_skcipher - force synchronous processing


-------------

Diffstat:

 .../testing/sysfs-class-reboot-mode-reboot_modes   |  13 +-
 Documentation/admin-guide/pm/cpufreq.rst           |   6 +-
 Documentation/arch/arm64/cpu-hotplug.rst           |  28 +-
 .../bindings/clock/qcom,dispcc-sm6125.yaml         |  17 +-
 .../bindings/clock/qcom,x1e80100-camcc.yaml        |   1 +
 .../bindings/dma/nvidia,tegra186-gpc-dma.yaml      |  23 +-
 .../devicetree/bindings/dma/snps,dw-axi-dmac.yaml  |   5 +-
 .../media/allwinner,sun4i-a10-video-engine.yaml    |  10 +
 .../bindings/net/bluetooth/qcom,wcn6855-bt.yaml    |   7 +-
 .../devicetree/bindings/net/microchip,lan8650.yaml |   2 +-
 .../devicetree/bindings/net/renesas,ether.yaml     |   3 +-
 .../bindings/phy/qcom,sc8280xp-qmp-pcie-phy.yaml   |  13 +-
 .../pinctrl/nvidia,tegra234-pinmux-aon.yaml        |   4 +
 .../bindings/pinctrl/nvidia,tegra234-pinmux.yaml   |   4 +
 .../bindings/pinctrl/realtek,rtd1625-pinctrl.yaml  |   2 +-
 .../bindings/regulator/mt6359-regulator.yaml       |  43 --
 .../devicetree/bindings/timer/sifive,clint.yaml    |  16 -
 .../devicetree/bindings/vendor-prefixes.yaml       |   4 +
 Documentation/driver-api/nvdimm/btt.rst            |   5 +-
 Documentation/driver-api/uio-howto.rst             |   4 +-
 Documentation/filesystems/proc.rst                 |  14 +-
 Documentation/mm/memfd_preservation.rst            |   2 +-
 Documentation/netlink/specs/handshake.yaml         |   1 +
 Documentation/netlink/specs/rt-link.yaml           |   6 +
 Documentation/networking/bonding.rst               |  23 +
 Documentation/process/changes.rst                  |   7 +-
 Documentation/process/threat-model.rst             |   2 +-
 Documentation/trace/eprobetrace.rst                |   4 +
 Documentation/trace/rv/monitor_sched.rst           |   7 +-
 Makefile                                           |   4 +-
 arch/alpha/kernel/pci-sysfs.c                      |  13 +-
 arch/arc/include/asm/uaccess.h                     |   3 +-
 arch/arm/boot/compressed/Makefile                  |   2 +-
 arch/arm/boot/dts/broadcom/bcm2711-rpi-4-b.dts     |   2 +-
 arch/arm/boot/dts/broadcom/bcm2711-rpi-cm4-io.dts  |   2 +-
 arch/arm/boot/dts/nvidia/tegra124-nyan.dtsi        |   5 +
 arch/arm/boot/dts/nvidia/tegra124-venice2.dts      |   5 +
 arch/arm/boot/dts/nxp/imx/imx6ul-var-som.dtsi      |   4 -
 arch/arm/boot/dts/rockchip/rk3288-veyron.dtsi      |   5 +
 arch/arm/boot/dts/st/stm32mp151c-mecio1r0.dts      | 128 ++++
 arch/arm/boot/dts/st/stm32mp153c-mecio1r1.dts      | 144 +++++
 arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi     | 146 +----
 arch/arm/boot/dts/ti/omap/am335x-sl50.dts          |   4 +-
 arch/arm/configs/axm55xx_defconfig                 |   1 -
 arch/arm/configs/dove_defconfig                    |   1 -
 arch/arm/configs/ep93xx_defconfig                  |   1 -
 arch/arm/configs/mmp2_defconfig                    |   1 -
 arch/arm/configs/multi_v7_defconfig                |   4 +-
 arch/arm/configs/mv78xx0_defconfig                 |   1 -
 arch/arm/configs/sunxi_defconfig                   |   1 -
 arch/arm/include/asm/uaccess.h                     |   3 +-
 arch/arm/mach-imx/Kconfig                          |  21 -
 arch/arm/mach-imx/cpu-imx31.c                      |   9 +-
 arch/arm/mach-imx/mm-imx3.c                        |   2 +
 arch/arm64/boot/dts/allwinner/sun55i-a523.dtsi     |   3 +-
 .../fsl-ls1028a-tqmls1028a-mbls1028a.dtsi          |   4 +-
 .../boot/dts/freescale/fsl-lx2162a-clearfog.dts    |   2 +-
 arch/arm64/boot/dts/freescale/imx8dxl-evk.dts      |   2 -
 .../arm64/boot/dts/freescale/imx8mm-kontron-bl.dts |  10 +-
 .../boot/dts/freescale/imx8mm-kontron-osm-s.dtsi   |   7 +-
 .../dts/freescale/imx8mn-vhip4-evalboard-v1.dts    |   2 +-
 .../dts/freescale/imx8mn-vhip4-evalboard-v2.dts    |   2 +-
 arch/arm64/boot/dts/freescale/imx8mp-ab2.dts       |   2 +-
 .../boot/dts/freescale/imx8mp-kontron-bl-osm-s.dts |  14 +-
 .../boot/dts/freescale/imx8mp-kontron-osm-s.dtsi   |   7 +-
 .../dts/freescale/imx8mp-tqma8mpql-mba8mpxl.dts    |   3 +
 arch/arm64/boot/dts/freescale/imx8qxp-mek.dts      |   1 -
 arch/arm64/boot/dts/freescale/imx8ulp-evk.dts      |   4 +-
 arch/arm64/boot/dts/freescale/imx8x-colibri.dtsi   |   4 +-
 arch/arm64/boot/dts/freescale/imx94.dtsi           |   2 +-
 arch/arm64/boot/dts/freescale/imx95-19x19-evk.dts  |   2 +-
 .../arm64/boot/dts/freescale/imx95-verdin-ivy.dtsi |   1 -
 arch/arm64/boot/dts/freescale/imx95.dtsi           |  10 +-
 arch/arm64/boot/dts/freescale/s32g3.dtsi           |   2 +-
 .../marvell/mmp/pxa1908-samsung-coreprimevelte.dts |   2 +-
 arch/arm64/boot/dts/mediatek/Makefile              |   8 +
 .../mediatek/mt7988a-bananapi-bpi-r4-pro-cn13.dtso |  20 +
 .../mediatek/mt7988a-bananapi-bpi-r4-pro-cn14.dtso |  20 +
 .../dts/mediatek/mt7988a-bananapi-bpi-r4-pro.dtsi  |   2 -
 arch/arm64/boot/dts/mediatek/mt8192-asurada.dtsi   |   2 +-
 arch/arm64/boot/dts/nvidia/tegra132-norrin.dts     |   5 +
 arch/arm64/boot/dts/nvidia/tegra210-smaug.dts      |   5 +
 arch/arm64/boot/dts/nvidia/tegra234.dtsi           |   8 +-
 arch/arm64/boot/dts/nvidia/tegra264.dtsi           |  88 +--
 arch/arm64/boot/dts/qcom/eliza-mtp.dts             |   4 +-
 arch/arm64/boot/dts/qcom/eliza.dtsi                |   6 +-
 arch/arm64/boot/dts/qcom/glymur-crd.dts            |   4 -
 arch/arm64/boot/dts/qcom/glymur.dtsi               |  12 +-
 arch/arm64/boot/dts/qcom/hamoa.dtsi                |  77 +--
 arch/arm64/boot/dts/qcom/ipq5424.dtsi              |   4 +-
 arch/arm64/boot/dts/qcom/kaanapali.dtsi            |   6 +-
 arch/arm64/boot/dts/qcom/kodiak.dtsi               |   8 +-
 arch/arm64/boot/dts/qcom/lemans.dtsi               | 710 +++++++++++----------
 arch/arm64/boot/dts/qcom/milos-fairphone-fp6.dts   |   5 +
 arch/arm64/boot/dts/qcom/milos.dtsi                |   2 +-
 arch/arm64/boot/dts/qcom/monaco.dtsi               |   6 +-
 arch/arm64/boot/dts/qcom/pmh0104-glymur.dtsi       |   2 +-
 arch/arm64/boot/dts/qcom/sc7180.dtsi               |   6 +-
 arch/arm64/boot/dts/qcom/sc8180x.dtsi              |   2 +-
 arch/arm64/boot/dts/qcom/sdm630.dtsi               |  37 +-
 arch/arm64/boot/dts/qcom/sdm660.dtsi               |  36 +-
 .../qcom/sdm845-db845c-navigation-mezzanine.dtso   |   5 +
 .../arm64/boot/dts/qcom/sdm845-oneplus-common.dtsi |   2 +-
 arch/arm64/boot/dts/qcom/sdm845-shift-axolotl.dts  |   2 +-
 .../dts/qcom/sdm845-xiaomi-beryllium-common.dtsi   |   2 +-
 arch/arm64/boot/dts/qcom/sm8450.dtsi               |   8 +-
 arch/arm64/boot/dts/qcom/sm8550.dtsi               |   6 +-
 arch/arm64/boot/dts/qcom/sm8650.dtsi               |   6 +-
 arch/arm64/boot/dts/qcom/sm8750.dtsi               |   8 +-
 arch/arm64/boot/dts/renesas/r8a78000-ironhide.dts  |  76 ++-
 arch/arm64/boot/dts/renesas/r8a78000.dtsi          |  36 +-
 arch/arm64/boot/dts/rockchip/px30-cobra.dtsi       |   2 +-
 arch/arm64/boot/dts/rockchip/px30-ringneck.dtsi    |   2 +-
 arch/arm64/boot/dts/rockchip/rk3399-gru.dtsi       |   5 +
 arch/arm64/boot/dts/rockchip/rk3566-roc-pc.dts     |   2 +-
 arch/arm64/boot/dts/rockchip/rk3568-nanopi-r5s.dts |   6 +-
 arch/arm64/boot/dts/rockchip/rk3576.dtsi           |   6 +-
 arch/arm64/boot/dts/rockchip/rk3588-base.dtsi      |  12 +-
 arch/arm64/boot/dts/st/stm32mp251.dtsi             |   8 +-
 arch/arm64/boot/dts/ti/k3-am62a7-sk.dts            |   2 +
 arch/arm64/include/asm/kvm_nested.h                |   8 +
 arch/arm64/include/asm/tlbbatch.h                  |  10 +-
 arch/arm64/include/asm/tlbflush.h                  |  49 +-
 arch/arm64/include/asm/uaccess.h                   |   3 +-
 arch/arm64/kernel/acpi.c                           |   2 +
 arch/arm64/kernel/entry-fpsimd.S                   |   8 +-
 arch/arm64/kernel/fpsimd.c                         |  10 +-
 arch/arm64/kernel/hw_breakpoint.c                  |   9 +
 arch/arm64/kernel/process.c                        |  35 -
 arch/arm64/kernel/smp.c                            |  28 +-
 arch/arm64/kernel/static_call.c                    |   1 +
 arch/arm64/kvm/at.c                                |   8 -
 arch/arm64/kvm/emulate-nested.c                    |   1 +
 arch/arm64/kvm/hyp/include/hyp/switch.h            |  11 +-
 arch/arm64/kvm/hyp/pgtable.c                       |   3 +-
 arch/arm64/kvm/nested.c                            | 166 ++---
 arch/arm64/kvm/pkvm.c                              |   2 +-
 arch/arm64/kvm/vgic/vgic-its.c                     |   2 +
 arch/arm64/kvm/vgic/vgic.c                         |  20 +-
 arch/arm64/mm/mmu.c                                |  11 +-
 arch/arm64/tools/sysreg                            |   2 +-
 arch/hexagon/include/asm/uaccess.h                 |   3 +-
 arch/loongarch/include/asm/kexec.h                 |   3 +-
 arch/loongarch/include/asm/pgtable.h               |   4 +
 arch/loongarch/include/asm/uaccess.h               |   3 +-
 arch/loongarch/kvm/exit.c                          |   1 -
 arch/loongarch/kvm/irqfd.c                         |   3 +-
 arch/loongarch/kvm/vcpu.c                          |  11 +-
 arch/loongarch/mm/pageattr.c                       |   2 +-
 arch/loongarch/net/bpf_jit.c                       |  28 +-
 arch/m68k/coldfire/m5441x.c                        |  18 +-
 arch/m68k/include/asm/uaccess.h                    |   3 +-
 arch/microblaze/include/asm/uaccess.h              |   3 +-
 arch/mips/dec/int-handler.S                        |   2 +-
 arch/mips/dec/platform.c                           |   6 +-
 arch/mips/dec/prom/init.c                          |   6 +-
 arch/mips/dec/setup.c                              |   6 -
 arch/mips/fw/lib/call_o32.S                        |   2 +-
 arch/mips/include/asm/dec/prom.h                   |  15 +-
 arch/mips/include/asm/uaccess.h                    |   3 +-
 arch/mips/kernel/mips-mt-fpaff.c                   |  28 +-
 arch/mips/mm/init.c                                |  17 +-
 arch/mips/n64/init.c                               |   2 +-
 arch/mips/ralink/mt7621.c                          |   2 +-
 arch/mips/sgi-ip22/ip22-gio.c                      |   7 +-
 arch/nios2/include/asm/uaccess.h                   |   3 +-
 arch/openrisc/include/asm/cacheflush.h             |   4 +
 arch/openrisc/include/asm/uaccess.h                |   3 +-
 arch/openrisc/kernel/jump_label.c                  |   2 +-
 arch/openrisc/kernel/patching.c                    |   3 +
 arch/openrisc/kernel/smp.c                         |  21 +
 arch/openrisc/mm/cache.c                           |  16 +
 arch/openrisc/mm/init.c                            |   2 +-
 arch/parisc/include/asm/uaccess.h                  |   3 +-
 arch/powerpc/include/asm/uaccess.h                 |   2 +-
 arch/powerpc/kernel/dt_cpu_ftrs.c                  |   9 +
 arch/powerpc/kexec/core_64.c                       |   4 +-
 arch/powerpc/perf/core-fsl-emb.c                   |   3 +-
 arch/powerpc/platforms/8xx/cpm1.c                  |  26 +
 arch/powerpc/platforms/cell/spufs/file.c           |   6 +-
 arch/powerpc/platforms/powernv/setup.c             |   3 +-
 arch/powerpc/platforms/pseries/Kconfig             |   1 +
 .../platforms/pseries/papr_platform_attributes.c   |   8 +-
 .../riscv/boot/dts/microchip/mpfs-beaglev-fire.dts |  25 +-
 arch/riscv/boot/dts/microchip/mpfs.dtsi            |   6 +-
 .../boot/dts/microchip/pic64gx-curiosity-kit.dts   |  47 +-
 arch/riscv/boot/dts/microchip/pic64gx.dtsi         |  38 +-
 arch/riscv/boot/dts/sophgo/sg2042-cpus.dtsi        | 236 +++----
 arch/riscv/boot/dts/sophgo/sg2044-cpus.dtsi        | 236 +++----
 arch/riscv/boot/dts/spacemit/k1-bananapi-f3.dts    |   2 +-
 arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts  |   4 +-
 arch/riscv/boot/dts/spacemit/k1.dtsi               |   2 +-
 arch/riscv/boot/dts/spacemit/k3.dtsi               |   3 +-
 arch/riscv/include/asm/cpu_ops.h                   |   2 +-
 arch/riscv/include/asm/vdso.h                      |  10 +-
 arch/riscv/kernel/alternative.c                    |  14 +-
 arch/riscv/kernel/asm-offsets.c                    |   4 +-
 arch/riscv/kernel/cacheinfo.c                      |   2 +-
 arch/riscv/kernel/cpu-hotplug.c                    |   4 +-
 arch/riscv/kernel/cpu_ops_sbi.c                    |  11 +-
 arch/riscv/kernel/entry.S                          |   8 +-
 arch/riscv/kernel/machine_kexec.c                  |   3 +
 arch/riscv/kernel/probes/rethook_trampoline.S      |   3 +
 arch/riscv/kernel/stacktrace.c                     |   2 +-
 arch/riscv/kernel/vdso/Makefile                    |   6 +-
 arch/riscv/kernel/vdso/rt_sigreturn.S              |  10 +-
 arch/s390/include/asm/pgtable.h                    |   4 +-
 arch/s390/include/asm/uaccess.h                    |   3 +-
 arch/s390/kernel/diag/diag310.c                    |   7 +-
 arch/s390/kernel/perf_cpum_cf.c                    |   3 +
 arch/s390/kernel/process.c                         |   2 +-
 arch/s390/kvm/dat.c                                |   2 +-
 arch/s390/kvm/gaccess.c                            |  73 ++-
 arch/s390/kvm/gmap.c                               |   7 +-
 arch/s390/kvm/gmap.h                               |  14 +-
 arch/s390/kvm/kvm-s390.c                           |   2 +-
 arch/s390/kvm/pci.c                                |  12 +-
 arch/s390/mm/gmap_helpers.c                        |   9 +-
 arch/s390/mm/mmap.c                                |   2 +-
 arch/sh/include/asm/uaccess.h                      |   3 +-
 arch/sparc/include/asm/page_32.h                   |   2 +
 arch/sparc/include/asm/uaccess_32.h                |   3 +-
 arch/sparc/include/asm/uaccess_64.h                |   3 +-
 arch/sparc/kernel/led.c                            |   2 +-
 arch/um/include/asm/uaccess.h                      |   3 +-
 arch/x86/Kconfig.cpu                               |   8 +-
 arch/x86/boot/compressed/acpi.c                    |   7 +-
 arch/x86/boot/early_serial_console.c               |  11 +-
 arch/x86/events/amd/brs.c                          |  10 +-
 arch/x86/events/amd/core.c                         |  18 +-
 arch/x86/events/amd/lbr.c                          |   3 +-
 arch/x86/events/amd/uncore.c                       |   6 +-
 arch/x86/events/intel/uncore_discovery.c           |   4 +-
 arch/x86/events/intel/uncore_snbep.c               |   6 +-
 arch/x86/include/asm/bug.h                         |   2 +
 arch/x86/kernel/cpu/cpu.h                          |   1 -
 arch/x86/kernel/uprobes.c                          |  26 +-
 arch/x86/kvm/irq.c                                 |   4 +-
 arch/x86/kvm/lapic.c                               |   8 +-
 arch/x86/kvm/svm/sev.c                             |   6 +-
 arch/x86/kvm/vmx/nested.c                          |  68 +-
 arch/x86/kvm/vmx/tdx.c                             |   6 +-
 arch/x86/platform/olpc/olpc-xo15-sci.c             |   1 +
 arch/x86/video/video-common.c                      |  23 +-
 arch/x86/virt/svm/sev.c                            |   2 +
 arch/xtensa/include/asm/uaccess.h                  |   3 +-
 block/blk.h                                        |  13 +-
 block/genhd.c                                      |   4 -
 block/ioctl.c                                      |   2 +-
 crypto/Kconfig                                     |   4 +-
 crypto/af_alg.c                                    |   2 +
 crypto/algif_skcipher.c                            |  75 +--
 crypto/asymmetric_keys/verify_pefile.c             |   2 +
 crypto/ecrdsa.c                                    |   2 +-
 crypto/rng.c                                       |  11 +
 drivers/accel/amdxdna/Makefile                     |   1 +
 drivers/accel/amdxdna/aie.c                        |  89 +++
 drivers/accel/amdxdna/aie.h                        |  31 +
 drivers/accel/amdxdna/aie2_ctx.c                   |  26 +-
 drivers/accel/amdxdna/aie2_error.c                 |  17 +-
 drivers/accel/amdxdna/aie2_message.c               | 164 ++---
 drivers/accel/amdxdna/aie2_msg_priv.h              |   2 +-
 drivers/accel/amdxdna/aie2_pci.c                   | 166 ++---
 drivers/accel/amdxdna/aie2_pci.h                   |  26 +-
 drivers/accel/amdxdna/aie2_pm.c                    |   6 +-
 drivers/accel/amdxdna/aie2_smu.c                   |  22 +-
 drivers/accel/amdxdna/amdxdna_ctx.c                |  40 +-
 drivers/accel/amdxdna/amdxdna_gem.c                |  37 +-
 drivers/accel/amdxdna/amdxdna_gem.h                |   1 -
 drivers/accel/amdxdna/amdxdna_iommu.c              |  56 +-
 drivers/accel/amdxdna/amdxdna_mailbox.c            |  10 +-
 drivers/accel/amdxdna/amdxdna_pci_drv.h            |   8 +
 drivers/accel/amdxdna/amdxdna_ubuf.c               |  12 +-
 drivers/accel/amdxdna/npu1_regs.c                  |   4 +-
 drivers/accel/amdxdna/npu4_regs.c                  |   4 +-
 drivers/accel/amdxdna/npu5_regs.c                  |   2 +-
 drivers/accel/amdxdna/npu6_regs.c                  |   2 +-
 drivers/accel/ivpu/ivpu_fw_log.c                   |   4 +
 drivers/accel/ivpu/ivpu_job.c                      |  10 +-
 drivers/acpi/acpi_ipmi.c                           |   4 +-
 drivers/acpi/acpi_pad.c                            |   6 +-
 drivers/acpi/acpi_tad.c                            |   2 +-
 drivers/acpi/acpica/acutils.h                      |   2 -
 drivers/acpi/acpica/utnonansi.c                    |   7 -
 drivers/acpi/button.c                              |  26 +-
 drivers/acpi/processor_idle.c                      |  13 +-
 drivers/acpi/resource.c                            |   6 +-
 drivers/acpi/riscv/cpuidle.c                       |   2 +-
 drivers/acpi/riscv/rimt.c                          |   7 +-
 drivers/amba/bus.c                                 |  37 +-
 drivers/android/binder.c                           |  18 +-
 drivers/ata/libata-core.c                          |  44 +-
 drivers/ata/libata-scsi.c                          |   9 +-
 drivers/ata/libata.h                               |   9 +
 drivers/ata/pata_pxa.c                             |   1 +
 drivers/ata/sata_gemini.c                          |   2 +-
 drivers/base/core.c                                |  83 ++-
 drivers/base/dd.c                                  |   7 +-
 drivers/base/firmware_loader/main.c                |  71 ++-
 drivers/base/power/main.c                          |   6 +-
 drivers/base/property.c                            |   4 +-
 drivers/base/regmap/regcache.c                     |   2 +-
 drivers/base/regmap/regmap-i2c.c                   |   2 +-
 drivers/block/drbd/drbd_receiver.c                 |   5 +
 drivers/bluetooth/Kconfig                          |   2 +-
 drivers/bluetooth/bpa10x.c                         |   8 +-
 drivers/bluetooth/btintel.c                        |  10 +-
 drivers/bluetooth/btintel.h                        |   9 +
 drivers/bluetooth/btintel_pcie.c                   | 531 ++++++++++++---
 drivers/bluetooth/btintel_pcie.h                   |  26 +-
 drivers/bluetooth/btmtk.c                          |   4 +-
 drivers/bluetooth/btrtl.c                          |   5 +-
 drivers/bluetooth/hci_qca.c                        |  11 +-
 drivers/bluetooth/hci_vhci.c                       |  10 +
 drivers/bus/imx-weim.c                             |   6 -
 drivers/bus/mhi/ep/main.c                          |  11 +-
 drivers/bus/mhi/host/pci_generic.c                 |  20 +-
 drivers/bus/sunxi-rsb.c                            |   3 +
 drivers/cdx/cdx.c                                  |  40 +-
 drivers/char/hpet.c                                |   6 +-
 drivers/char/ipmi/ipmi_msghandler.c                |  10 +-
 drivers/char/sonypi.c                              |   6 +-
 drivers/char/tlclk.c                               |   4 +
 drivers/char/tpm/eventlog/tpm1.c                   |   4 +-
 drivers/char/tpm/tpm-dev.c                         |   2 +-
 drivers/char/tpm/tpm2-cmd.c                        |   6 +-
 drivers/char/tpm/tpm2-sessions.c                   |  45 +-
 drivers/char/tpm/tpm_crb.c                         |   6 +-
 drivers/char/tpm/tpm_tis_core.c                    |  35 +-
 drivers/char/tpm/tpmrm-dev.c                       |   2 +-
 drivers/char/virtio_console.c                      |  52 +-
 drivers/clk/at91/pmc.c                             |   2 +-
 drivers/clk/at91/sam9x7.c                          |  18 +-
 drivers/clk/clk-scmi.c                             |   4 +-
 drivers/clk/clk-scpi.c                             |   2 +-
 drivers/clk/microchip/clk-mpfs-ccc.c               |  15 +-
 drivers/clk/qcom/a53-pll.c                         |   2 +-
 drivers/clk/qcom/camcc-x1e80100.c                  |  64 ++
 drivers/clk/qcom/ipq-cmn-pll.c                     |  11 +-
 drivers/clk/renesas/rzg2l-cpg.c                    |   6 +-
 drivers/clk/samsung/Kconfig                        |   2 +-
 drivers/clk/spacemit/ccu-k3.c                      |  20 +-
 drivers/clocksource/Kconfig                        |  31 +
 drivers/clocksource/timer-sun5i.c                  |   3 +
 drivers/cpufreq/cpufreq_conservative.c             |  12 +-
 drivers/cpufreq/cpufreq_governor.c                 |  42 +-
 drivers/cpufreq/intel_pstate.c                     |   6 +-
 drivers/cpuidle/driver.c                           |   8 -
 drivers/crypto/Kconfig                             |   1 -
 drivers/crypto/allwinner/Kconfig                   |   8 -
 drivers/crypto/allwinner/sun4i-ss/Makefile         |   1 -
 drivers/crypto/allwinner/sun4i-ss/sun4i-ss-core.c  |  36 --
 drivers/crypto/allwinner/sun4i-ss/sun4i-ss-prng.c  |  69 --
 drivers/crypto/allwinner/sun4i-ss/sun4i-ss.h       |  20 -
 drivers/crypto/atmel-sha204a.c                     |   8 +-
 drivers/crypto/cavium/cpt/cptvf_reqmanager.c       |   4 +-
 drivers/crypto/ccp/psp-dev.c                       |  12 +-
 drivers/crypto/ccp/sev-dev-tsm.c                   |  23 +-
 drivers/crypto/ccp/sev-dev.c                       |  26 +-
 drivers/crypto/hisilicon/qm.c                      |   4 +-
 drivers/crypto/inside-secure/eip93/eip93-main.c    |   2 +
 drivers/crypto/inside-secure/eip93/eip93-regs.h    |   2 +-
 drivers/crypto/inside-secure/safexcel.c            |   2 +-
 .../crypto/intel/qat/qat_common/adf_common_drv.h   |   1 -
 .../intel/qat/qat_common/adf_heartbeat_inject.c    |   6 +-
 .../crypto/intel/qat/qat_common/adf_hw_arbiter.c   |  25 -
 drivers/crypto/marvell/octeontx/otx_cptvf_reqmgr.c |   4 +-
 drivers/crypto/tegra/tegra-se-aes.c                |  33 +-
 drivers/crypto/xilinx/xilinx-trng.c                |  85 +--
 drivers/cxl/core/core.h                            |   2 +
 drivers/cxl/core/features.c                        |   2 +-
 drivers/cxl/core/memdev.c                          |   4 +-
 drivers/cxl/core/pci.c                             |  26 +-
 drivers/cxl/core/port.c                            |   7 +-
 drivers/cxl/core/ras.c                             |  27 +-
 drivers/cxl/core/region.c                          | 125 ++--
 drivers/cxl/core/trace.h                           |  24 +-
 drivers/cxl/cxl.h                                  |  22 +-
 drivers/dax/kmem.c                                 |   6 +
 drivers/dibs/dibs_loopback.c                       |   5 +
 drivers/dma-buf/dma-fence-unwrap.c                 |   3 +
 drivers/dma-buf/dma-fence.c                        |   9 +-
 drivers/dma/dma-axi-dmac.c                         |  68 +-
 drivers/dma/dmaengine.c                            |   3 +-
 drivers/dma/dw-edma/dw-edma-core.h                 |   2 +-
 drivers/dma/dw-edma/dw-edma-pcie.c                 |   3 +
 drivers/dma/dw-edma/dw-edma-v0-core.c              |   6 +
 drivers/dma/imx-sdma.c                             |   4 +-
 drivers/dma/qcom/gpi.c                             |   1 +
 drivers/dma/sh/rz-dmac.c                           |  92 +--
 drivers/dma/tegra186-gpc-dma.c                     |   7 +
 drivers/dpll/dpll_core.c                           |  20 +-
 drivers/edac/igen6_edac.c                          | 405 +++++++++---
 drivers/edac/skx_common.c                          |   3 +
 drivers/firmware/arm_ffa/driver.c                  |  27 +-
 drivers/firmware/arm_scmi/power.c                  |   6 +-
 drivers/firmware/arm_scmi/sensors.c                |   2 +-
 drivers/firmware/samsung/exynos-acpm.c             |  23 +
 drivers/firmware/smccc/soc_id.c                    |   2 +-
 drivers/firmware/xilinx/zynqmp.c                   |  28 +
 drivers/fpga/dfl.c                                 |   2 +
 drivers/fpga/microchip-spi.c                       |   3 +
 drivers/gpib/cb7210/cb7210.c                       |   1 +
 drivers/gpib/common/gpib_os.c                      |   4 +-
 drivers/gpio/gpio-davinci.c                        |   4 +-
 drivers/gpio/gpio-dwapb.c                          |  83 ++-
 drivers/gpio/gpio-f7188x.c                         |   6 +-
 drivers/gpio/gpio-htc-egpio.c                      |   6 +-
 drivers/gpio/gpio-mlxbf3.c                         |   3 +-
 drivers/gpio/gpio-mt7621.c                         | 283 ++++++--
 drivers/gpio/gpio-mvebu.c                          |   6 +-
 drivers/gpio/gpio-palmas.c                         |  19 +
 drivers/gpio/gpio-shared-proxy.c                   | 136 ++--
 drivers/gpio/gpio-tegra.c                          |  18 +-
 drivers/gpio/gpio-timberdale.c                     |   2 +-
 drivers/gpio/gpiolib-acpi-core.c                   |  19 +-
 drivers/gpio/gpiolib-shared.c                      |   9 +-
 drivers/gpio/gpiolib-shared.h                      |  31 +-
 drivers/gpio/gpiolib.c                             |   2 +-
 drivers/gpu/buddy.c                                |  67 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd_gpuvm.c   |  16 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c   |   3 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_device.c         |   2 +
 drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c            |  25 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_irq.c            |   2 -
 drivers/gpu/drm/amd/amdgpu/amdgpu_mca.c            |   3 +
 drivers/gpu/drm/amd/amdgpu/mes_v12_1.c             |   2 +-
 drivers/gpu/drm/amd/amdkfd/kfd_chardev.c           |   3 +
 .../gpu/drm/amd/amdkfd/kfd_device_queue_manager.c  |  20 +-
 drivers/gpu/drm/amd/amdkfd/kfd_events.c            |   5 +
 drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c |   6 +-
 drivers/gpu/drm/amd/amdkfd/kfd_process.c           |   2 +-
 drivers/gpu/drm/amd/amdkfd/kfd_svm.c               |   1 +
 drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c  |  10 +-
 .../drm/amd/display/amdgpu_dm/amdgpu_dm_helpers.c  |  13 +-
 drivers/gpu/drm/amd/display/dc/core/dc.c           |  81 ++-
 drivers/gpu/drm/amd/display/dc/core/dc_stream.c    |   2 +
 drivers/gpu/drm/amd/display/dc/dc.h                |  58 +-
 drivers/gpu/drm/amd/display/dc/dc_types.h          |  24 -
 .../drm/amd/display/dc/hubp/dcn401/dcn401_hubp.c   | 229 +++----
 .../drm/amd/display/dc/hubp/dcn401/dcn401_hubp.h   |  23 +-
 .../gpu/drm/amd/display/dc/hubp/dcn42/dcn42_hubp.c |  78 +--
 .../gpu/drm/amd/display/dc/hubp/dcn42/dcn42_hubp.h |  10 +-
 .../drm/amd/display/dc/hwss/dcn401/dcn401_hwseq.c  | 431 ++++++++-----
 .../drm/amd/display/dc/hwss/dcn42/dcn42_hwseq.c    | 495 +++++++++++++-
 .../drm/amd/display/dc/hwss/dcn42/dcn42_hwseq.h    |   9 +-
 drivers/gpu/drm/amd/display/dc/inc/hw/hubp.h       |  35 +-
 drivers/gpu/drm/amd/display/dc/inc/hw/mpc.h        |  79 +--
 .../gpu/drm/amd/display/dc/mpc/dcn401/dcn401_mpc.c | 177 +++--
 .../gpu/drm/amd/display/dc/mpc/dcn401/dcn401_mpc.h |  25 +-
 .../gpu/drm/amd/display/dc/mpc/dcn42/dcn42_mpc.c   | 392 +++++++++++-
 .../gpu/drm/amd/display/dc/mpc/dcn42/dcn42_mpc.h   |  49 +-
 .../amd/display/dc/resource/dcn42/dcn42_resource.c |   1 -
 .../amd/display/modules/info_packet/info_packet.c  |   2 +
 drivers/gpu/drm/amd/pm/amdgpu_pm.c                 |  26 +-
 drivers/gpu/drm/bridge/analogix/analogix_dp_core.c |   4 +
 drivers/gpu/drm/drm_edid.c                         |   8 +
 drivers/gpu/drm/drm_fb_helper.c                    |  92 ++-
 drivers/gpu/drm/drm_gpusvm.c                       |   5 +
 drivers/gpu/drm/drm_gpuvm.c                        |   9 +-
 drivers/gpu/drm/drm_ioctl.c                        |  14 +-
 drivers/gpu/drm/drm_syncobj.c                      |  10 +-
 drivers/gpu/drm/hisilicon/hibmc/dp/dp_comm.h       |   1 +
 drivers/gpu/drm/hisilicon/hibmc/dp/dp_hw.h         |   1 +
 drivers/gpu/drm/hisilicon/hibmc/dp/dp_link.c       |   2 +-
 drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c     |  78 ++-
 drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_dp.c     |  35 +-
 drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c    |  14 +
 drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.h    |   1 +
 drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_vdac.c   |  75 ++-
 drivers/gpu/drm/i915/display/intel_atomic.c        |   6 +
 drivers/gpu/drm/i915/display/intel_lt_phy.c        |   6 +-
 drivers/gpu/drm/imagination/pvr_drv.c              |   6 +-
 drivers/gpu/drm/imagination/pvr_fw_trace.c         |   2 +-
 drivers/gpu/drm/imagination/pvr_vm.c               |   6 +-
 drivers/gpu/drm/msm/adreno/a6xx_gmu.c              |   7 +-
 drivers/gpu/drm/msm/adreno/a8xx_gpu.c              |  15 +-
 drivers/gpu/drm/msm/dp/dp_display.c                |   4 +-
 drivers/gpu/drm/msm/dp/dp_reg.h                    |   4 +-
 drivers/gpu/drm/msm/msm_mdss.c                     | 113 ++--
 .../gpu/drm/nouveau/nvkm/subdev/bios/shadowramin.c |   3 +-
 drivers/gpu/drm/panel/Kconfig                      |  13 +-
 drivers/gpu/drm/panthor/panthor_device.c           |   9 +-
 drivers/gpu/drm/panthor/panthor_device.h           | 100 +--
 drivers/gpu/drm/panthor/panthor_drv.c              |   8 +-
 drivers/gpu/drm/panthor/panthor_fw.c               |  29 +-
 drivers/gpu/drm/panthor/panthor_fw_regs.h          |  32 +
 drivers/gpu/drm/panthor/panthor_gpu.c              |  50 +-
 drivers/gpu/drm/panthor/panthor_gpu_regs.h         | 123 ++++
 drivers/gpu/drm/panthor/panthor_heap.c             |   2 +-
 drivers/gpu/drm/panthor/panthor_hw.c               |  50 +-
 drivers/gpu/drm/panthor/panthor_hw.h               |   2 +-
 drivers/gpu/drm/panthor/panthor_mmu.c              |  37 +-
 drivers/gpu/drm/panthor/panthor_mmu_regs.h         |  73 +++
 drivers/gpu/drm/panthor/panthor_pwr.c              |  73 ++-
 drivers/gpu/drm/panthor/panthor_pwr_regs.h         |  83 +++
 drivers/gpu/drm/panthor/panthor_regs.h             | 291 ---------
 drivers/gpu/drm/panthor/panthor_sched.c            | 113 ++--
 drivers/gpu/drm/radeon/radeon_gem.c                |  13 +-
 drivers/gpu/drm/radeon/radeon_ring.c               |   4 +-
 drivers/gpu/drm/renesas/rz-du/rzg2l_mipi_dsi.c     |  12 +-
 drivers/gpu/drm/rockchip/dw_dp-rockchip.c          |   7 +-
 drivers/gpu/drm/rockchip/inno_hdmi-rockchip.c      |   3 +-
 drivers/gpu/drm/rockchip/rockchip_drm_gem.c        |   2 +-
 drivers/gpu/drm/tegra/dc.c                         |   4 +-
 drivers/gpu/drm/tegra/fbdev.c                      |   1 -
 drivers/gpu/drm/tegra/gem.c                        |  22 +-
 drivers/gpu/drm/tegra/gr2d.c                       |  19 +-
 drivers/gpu/drm/tegra/gr3d.c                       |  19 +-
 drivers/gpu/drm/tegra/submit.c                     |   3 +-
 drivers/gpu/drm/tidss/tidss_kms.c                  |   2 -
 drivers/gpu/drm/v3d/v3d_submit.c                   |   2 +
 drivers/gpu/drm/verisilicon/vs_primary_plane.c     |  10 +-
 drivers/gpu/drm/xe/Makefile                        |   4 +-
 drivers/gpu/drm/xe/tests/xe_pci.c                  |   1 -
 drivers/gpu/drm/xe/xe_drm_client.c                 |  12 +-
 drivers/gpu/drm/xe/xe_guc_relay.c                  |  13 +-
 drivers/gpu/drm/xe/xe_hw_engine.c                  |   4 +-
 drivers/gpu/drm/xe/xe_pt.c                         |  72 ++-
 drivers/gpu/drm/xe/xe_svm.h                        |  15 +-
 drivers/gpu/drm/xe/xe_userptr.c                    |   2 +-
 drivers/gpu/drm/xe/xe_vm_madvise.c                 |   2 +-
 drivers/gpu/host1x/bus.c                           |  62 +-
 drivers/gpu/host1x/job.c                           |  10 +-
 drivers/gpu/host1x/mipi.c                          |   6 +-
 drivers/gpu/nova-core/firmware.rs                  |   8 +-
 drivers/gpu/nova-core/firmware/gsp.rs              |   3 +-
 drivers/gpu/nova-core/vbios.rs                     | 118 ++--
 drivers/hid/bpf/hid_bpf_dispatch.c                 |   5 +-
 drivers/hid/hid-core.c                             |   7 +
 drivers/hid/hid-logitech-hidpp.c                   |   1 -
 drivers/hid/hid-picolcd_core.c                     |   3 +-
 drivers/hid/hid-wiimote-modules.c                  |  58 +-
 drivers/hv/mshv_synic.c                            |   5 +
 drivers/hv/vmbus_drv.c                             |  43 +-
 drivers/hwmon/Kconfig                              |   3 +
 drivers/hwmon/aspeed-g6-pwm-tach.c                 |   5 +-
 drivers/hwmon/asus_atk0110.c                       |   3 +
 drivers/hwmon/gpd-fan.c                            | 224 ++++---
 drivers/hwmon/it87.c                               |   3 +
 drivers/hwmon/occ/common.c                         |  34 +-
 drivers/hwmon/occ/common.h                         |   1 +
 drivers/hwmon/pmbus/adm1275.c                      |   2 +-
 drivers/hwmon/pmbus/pmbus_core.c                   |  37 +-
 drivers/hwmon/w83627hf.c                           |   4 +
 drivers/hwmon/w83793.c                             |   1 +
 drivers/hwspinlock/qcom_hwspinlock.c               |   5 +-
 drivers/hwtracing/coresight/coresight-core.c       |  34 +-
 .../hwtracing/coresight/coresight-cti-platform.c   |   1 +
 drivers/hwtracing/coresight/coresight-etm-perf.c   |   5 +-
 drivers/hwtracing/coresight/coresight-etm4x-core.c |  52 +-
 drivers/hwtracing/coresight/coresight-platform.c   |  12 +-
 drivers/hwtracing/coresight/coresight-priv.h       |   2 +-
 drivers/hwtracing/coresight/coresight-sysfs.c      |   8 +-
 drivers/hwtracing/coresight/coresight-tmc-etr.c    |   4 +-
 drivers/i2c/busses/i2c-imx.c                       |  36 +-
 drivers/i2c/busses/i2c-k1.c                        |   2 +-
 drivers/i2c/busses/i2c-mlxbf.c                     |   4 +-
 drivers/i2c/busses/i2c-mt65xx.c                    |   2 +-
 drivers/i2c/i2c-core-of.c                          |   5 -
 drivers/i3c/master.c                               | 145 ++++-
 drivers/i3c/master/dw-i3c-master.c                 |  15 +-
 drivers/i3c/master/dw-i3c-master.h                 |   2 -
 drivers/i3c/master/i3c-master-cdns.c               |  14 +-
 drivers/i3c/master/mipi-i3c-hci/core.c             |  48 +-
 drivers/i3c/master/mipi-i3c-hci/dma.c              |   9 +-
 drivers/i3c/master/mipi-i3c-hci/hci.h              |   1 +
 drivers/i3c/master/mipi-i3c-hci/ibi.h              |  13 +-
 drivers/i3c/master/mipi-i3c-hci/pio.c              |   7 +-
 drivers/i3c/master/svc-i3c-master.c                |  30 +-
 drivers/iio/accel/mma8452.c                        |   2 +
 drivers/iio/adc/xilinx-ams.c                       |   5 +
 drivers/iio/dac/mcp47feb02.c                       |  37 +-
 drivers/iio/light/acpi-als.c                       |   6 +-
 drivers/iio/light/si1133.c                         |  14 +-
 drivers/iio/light/tcs3472.c                        |  38 +-
 drivers/iio/magnetometer/ak8975.c                  |  14 +
 drivers/iio/orientation/hid-sensor-rotation.c      |  40 +-
 drivers/infiniband/core/cm.c                       |  13 +-
 drivers/infiniband/core/counters.c                 |   2 +-
 drivers/infiniband/core/frmr_pools.c               | 106 ++-
 drivers/infiniband/core/nldev.c                    |  15 +-
 drivers/infiniband/core/restrack.c                 |  49 ++
 drivers/infiniband/core/restrack.h                 |   1 +
 drivers/infiniband/core/uverbs_cmd.c               |  10 +-
 drivers/infiniband/hw/bnxt_re/ib_verbs.c           | 217 +++++--
 drivers/infiniband/hw/bnxt_re/ib_verbs.h           |   5 +-
 drivers/infiniband/hw/bnxt_re/main.c               |   2 -
 drivers/infiniband/hw/bnxt_re/qplib_res.c          |  11 +
 drivers/infiniband/hw/bnxt_re/qplib_sp.h           |   1 +
 drivers/infiniband/hw/bnxt_re/uapi.c               |  83 ++-
 drivers/infiniband/hw/hfi1/init.c                  |  13 +-
 drivers/infiniband/hw/hns/hns_roce_cq.c            |   6 +-
 drivers/infiniband/hw/hns/hns_roce_debugfs.c       |  19 +-
 drivers/infiniband/hw/hns/hns_roce_hem.c           |   8 +-
 drivers/infiniband/hw/hns/hns_roce_hw_v2.c         |  20 +-
 drivers/infiniband/hw/hns/hns_roce_main.c          |   2 +-
 drivers/infiniband/hw/hns/hns_roce_mr.c            |   6 +-
 drivers/infiniband/hw/hns/hns_roce_srq.c           |   2 +-
 drivers/infiniband/hw/irdma/hw.c                   |   7 +-
 drivers/infiniband/hw/irdma/main.h                 |   3 +-
 drivers/infiniband/hw/irdma/utils.c                |  12 +-
 drivers/infiniband/hw/irdma/verbs.c                |  19 +-
 drivers/infiniband/hw/irdma/verbs.h                |   1 -
 drivers/infiniband/hw/mana/main.c                  |   3 +-
 drivers/infiniband/hw/mlx4/mlx4_ib.h               |   1 +
 drivers/infiniband/hw/mlx4/mr.c                    |   9 +-
 drivers/infiniband/hw/mlx4/sysfs.c                 |  45 +-
 drivers/infiniband/hw/mlx5/devx.c                  |  30 +-
 drivers/infiniband/hw/mlx5/main.c                  |  17 +-
 drivers/infiniband/hw/mlx5/mlx5_ib.h               |   9 +
 drivers/infiniband/hw/mlx5/mr.c                    |  60 +-
 drivers/infiniband/hw/mlx5/odp.c                   |  12 +-
 drivers/infiniband/hw/mlx5/qp.c                    |  13 +-
 drivers/infiniband/hw/mlx5/restrack.c              |   3 -
 drivers/infiniband/hw/mlx5/umr.c                   |  93 ++-
 drivers/infiniband/hw/mlx5/umr.h                   |   9 +-
 drivers/infiniband/sw/rxe/rxe_mmap.c               |  19 +-
 drivers/infiniband/sw/rxe/rxe_net.c                |   6 +-
 drivers/infiniband/sw/rxe/rxe_ns.c                 |   4 +-
 drivers/infiniband/sw/rxe/rxe_resp.c               |  33 +-
 drivers/infiniband/sw/siw/siw_cm.c                 |  30 +-
 drivers/infiniband/ulp/srpt/ib_srpt.c              |   5 +-
 drivers/input/misc/ims-pcu.c                       | 131 +++-
 drivers/iommu/amd/amd_iommu_types.h                |  11 +-
 drivers/iommu/amd/init.c                           |   7 +-
 drivers/iommu/arm/arm-smmu/arm-smmu-qcom.c         |   2 +-
 drivers/iommu/dma-iommu.c                          |   2 +-
 drivers/iommu/intel/iommu.c                        |   6 +-
 drivers/iommu/intel/pasid.c                        |   4 +-
 drivers/iommu/iommufd/pages.c                      |  10 +-
 drivers/irqchip/exynos-combiner.c                  |   4 -
 drivers/irqchip/irq-crossbar.c                     |  10 +-
 drivers/irqchip/irq-gic-v3-its.c                   |   6 +-
 drivers/irqchip/irq-riscv-imsic-early.c            |  15 +-
 drivers/irqchip/irq-ts4800.c                       |  10 +
 drivers/leds/uleds.c                               |   3 +-
 drivers/mailbox/imx-mailbox.c                      |   3 +-
 drivers/mailbox/mailbox-mpfs.c                     |   2 +-
 drivers/mailbox/mailbox.c                          |  26 +-
 drivers/mailbox/mtk-adsp-mailbox.c                 |   9 +-
 drivers/md/dm-bufio.c                              |   4 +-
 drivers/md/dm-era-target.c                         |  10 +-
 drivers/md/dm-integrity.c                          |  12 +-
 drivers/md/dm-ioctl.c                              |   4 +-
 drivers/md/dm-log.c                                |   3 +
 drivers/md/dm-pcache/dm_pcache.c                   |   8 +
 drivers/md/dm-stats.c                              |  10 +-
 drivers/md/dm-thin-metadata.c                      |  67 +-
 drivers/md/dm-verity-fec.c                         |   4 +-
 drivers/md/dm-verity-fec.h                         |   2 +-
 drivers/md/dm-verity-loadpin.c                     |   2 +-
 drivers/md/dm-verity-target.c                      |  16 +-
 drivers/md/dm-verity.h                             |   2 +-
 drivers/md/dm.c                                    |  24 +-
 drivers/md/md-bitmap.c                             |   9 +-
 drivers/md/md-bitmap.h                             |   2 +-
 drivers/md/md-llbitmap.c                           |  13 +-
 drivers/md/md.c                                    |  27 +-
 drivers/md/md.h                                    |   5 +
 drivers/md/raid1.c                                 |  54 +-
 drivers/md/raid10.c                                |  57 +-
 drivers/md/raid5.c                                 |  55 +-
 drivers/media/platform/qcom/camss/camss-vfe.c      |   2 +-
 .../media/platform/qcom/iris/iris_platform_gen1.c  |   2 +-
 drivers/media/platform/qcom/iris/iris_probe.c      |   7 +
 drivers/media/platform/qcom/venus/core.c           |   7 +-
 drivers/media/platform/qcom/venus/core.h           |   1 +
 drivers/media/platform/qcom/venus/helpers.c        |   4 +-
 drivers/media/platform/qcom/venus/hfi_parser.c     |   6 +-
 drivers/media/platform/qcom/venus/hfi_platform.c   |  24 -
 drivers/media/platform/qcom/venus/hfi_platform.h   |   2 -
 .../media/platform/qcom/venus/hfi_platform_v4.c    |  20 +-
 .../media/platform/qcom/venus/hfi_platform_v6.c    |  16 +-
 drivers/media/platform/qcom/venus/pm_helpers.c     |   8 +-
 drivers/media/platform/rockchip/rga/rga-hw.c       |   2 +-
 drivers/media/platform/rockchip/rga/rga-hw.h       |   2 +-
 drivers/media/platform/synopsys/dw-mipi-csi2rx.c   |  15 +-
 drivers/media/usb/uvc/uvc_status.c                 |  28 +-
 drivers/media/usb/uvc/uvc_video.c                  | 179 ++++--
 drivers/media/v4l2-core/v4l2-common.c              |   1 +
 drivers/memory/tegra/mc.c                          |  14 +
 drivers/memory/tegra/tegra186-emc.c                |   4 +-
 drivers/memstick/core/ms_block.c                   |   4 +
 drivers/mfd/cs42l43.c                              |   2 +-
 drivers/mfd/rsmu_i2c.c                             |   6 +-
 drivers/mfd/rsmu_spi.c                             |   5 +-
 drivers/mfd/sm501.c                                |   4 +-
 drivers/mfd/tps6586x.c                             |   2 +-
 drivers/mmc/core/block.c                           |   3 +-
 drivers/mmc/core/mmc_test.c                        |  18 +-
 drivers/mmc/host/sdhci-esdhc-imx.c                 |  91 ++-
 drivers/mmc/host/sdhci-of-dwcmshc.c                |  14 +-
 drivers/mmc/host/vub300.c                          |  36 +-
 drivers/mtd/devices/mchp23k256.c                   |   2 +-
 drivers/mtd/devices/slram.c                        |  22 +-
 drivers/mtd/maps/vmu-flash.c                       |   7 +-
 drivers/mtd/mtd_virt_concat.c                      |   4 +-
 drivers/mtd/nand/onenand/onenand_samsung.c         |   7 +-
 drivers/mtd/nand/raw/fsl_ifc_nand.c                |   9 +-
 drivers/mtd/nand/raw/lpc32xx_mlc.c                 |  12 +-
 drivers/mtd/nand/raw/lpc32xx_slc.c                 |  12 +-
 drivers/mtd/nand/raw/nand_base.c                   |  24 +-
 drivers/mtd/nand/raw/pl35x-nand-controller.c       |   2 +-
 drivers/mtd/spi-nor/Kconfig                        |   1 -
 drivers/mtd/spi-nor/debugfs.c                      |   1 +
 drivers/mtd/spi-nor/spansion.c                     |   4 +-
 drivers/mtd/spi-nor/swp.c                          |  11 +-
 drivers/net/amt.c                                  |  10 +-
 drivers/net/bareudp.c                              |   4 +-
 drivers/net/bonding/bond_3ad.c                     |  27 +-
 drivers/net/bonding/bond_main.c                    |   1 +
 drivers/net/bonding/bond_netlink.c                 |  16 +
 drivers/net/bonding/bond_options.c                 |  27 +
 drivers/net/can/usb/esd_usb.c                      |   5 +-
 drivers/net/dsa/mxl862xx/mxl862xx-host.c           |  18 +-
 drivers/net/dsa/qca/qca8k-leds.c                   |   3 +-
 drivers/net/dsa/realtek/rtl8366rb-leds.c           |   8 +-
 drivers/net/dsa/sja1105/sja1105_ptp.c              |   2 +-
 drivers/net/ethernet/airoha/airoha_eth.c           |   6 +-
 drivers/net/ethernet/airoha/airoha_ppe.c           |   9 +-
 drivers/net/ethernet/airoha/airoha_ppe_debugfs.c   |   2 -
 drivers/net/ethernet/amazon/ena/ena_netdev.c       |  23 +-
 drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c    |   3 +-
 drivers/net/ethernet/broadcom/bnxt/bnxt.c          |  58 +-
 drivers/net/ethernet/broadcom/bnxt/bnxt.h          |   6 +
 drivers/net/ethernet/broadcom/bnxt/bnxt_ethtool.c  |   1 +
 drivers/net/ethernet/broadcom/genet/bcmgenet.c     |  23 +-
 drivers/net/ethernet/cadence/macb_main.c           |  29 +-
 .../ethernet/cavium/liquidio/cn23xx_pf_device.c    |  18 +-
 drivers/net/ethernet/cavium/liquidio/lio_main.c    |  27 -
 .../net/ethernet/cavium/liquidio/octeon_device.h   |   3 -
 .../net/ethernet/cavium/liquidio/octeon_mailbox.c  |  33 +-
 drivers/net/ethernet/chelsio/cxgb4/t4_hw.c         |   8 -
 .../net/ethernet/freescale/dpaa2/dpaa2-switch.c    |  10 +-
 drivers/net/ethernet/freescale/enetc/enetc.c       |   7 +
 drivers/net/ethernet/freescale/enetc/enetc4_pf.c   |   3 +
 drivers/net/ethernet/freescale/fman/fman.c         |   4 +-
 drivers/net/ethernet/freescale/gianfar.c           |  16 +-
 drivers/net/ethernet/google/gve/gve_rx_dqo.c       |  28 +-
 drivers/net/ethernet/hisilicon/hns3/hns3_ethtool.c |  31 +-
 .../ethernet/hisilicon/hns3/hns3pf/hclge_main.c    | 108 +++-
 .../ethernet/hisilicon/hns3/hns3pf/hclge_main.h    |   1 +
 drivers/net/ethernet/ibm/emac/core.c               |  13 +-
 drivers/net/ethernet/intel/e1000e/ich8lan.c        |   3 +
 drivers/net/ethernet/intel/e1000e/netdev.c         |  15 +-
 drivers/net/ethernet/intel/i40e/i40e_debug.h       |   2 +-
 drivers/net/ethernet/intel/ice/ice_common.c        |   1 -
 drivers/net/ethernet/intel/ice/ice_dpll.c          |  20 +-
 drivers/net/ethernet/intel/ice/ice_eswitch.c       |   4 +-
 drivers/net/ethernet/intel/ice/ice_ethtool.c       |  12 +-
 drivers/net/ethernet/intel/ice/ice_main.c          |  16 +-
 drivers/net/ethernet/intel/ice/ice_vf_lib.c        |   2 +-
 drivers/net/ethernet/intel/idpf/virtchnl2.h        |  12 +-
 drivers/net/ethernet/intel/igc/igc_main.c          |   2 +-
 drivers/net/ethernet/intel/ixgbe/ixgbe_main.c      |   3 +-
 drivers/net/ethernet/intel/ixgbe/ixgbe_type.h      |   1 +
 drivers/net/ethernet/intel/ixgbe/ixgbe_x550.c      |   2 +-
 drivers/net/ethernet/marvell/mvneta.c              |   3 +
 .../net/ethernet/marvell/octeontx2/af/cn20k/npc.c  |   9 +-
 drivers/net/ethernet/marvell/octeontx2/af/mbox.h   |  31 +-
 drivers/net/ethernet/marvell/octeontx2/af/mcs.c    |   6 +-
 .../net/ethernet/marvell/octeontx2/af/rvu_cn10k.c  |   9 +
 .../ethernet/marvell/octeontx2/af/rvu_debugfs.c    |  59 +-
 .../ethernet/marvell/octeontx2/af/rvu_devlink.c    |  27 +-
 .../net/ethernet/marvell/octeontx2/af/rvu_nix.c    |  15 +-
 .../net/ethernet/marvell/octeontx2/af/rvu_npc.c    |  40 +-
 .../net/ethernet/marvell/octeontx2/af/rvu_npc_fs.c |   2 +-
 .../ethernet/marvell/octeontx2/nic/cn10k_macsec.c  |  10 +-
 .../net/ethernet/marvell/octeontx2/nic/otx2_pf.c   |  83 ++-
 .../net/ethernet/marvell/octeontx2/nic/otx2_vf.c   |  22 +-
 .../net/ethernet/marvell/prestera/prestera_main.c  |   2 +-
 drivers/net/ethernet/mediatek/mtk_eth_soc.c        |  10 +-
 drivers/net/ethernet/mediatek/mtk_ppe.c            |   4 +-
 drivers/net/ethernet/mediatek/mtk_wed_debugfs.c    |   6 +-
 drivers/net/ethernet/mediatek/mtk_wed_mcu.c        |   8 +-
 drivers/net/ethernet/mellanox/mlx5/core/Makefile   |   2 +-
 drivers/net/ethernet/mellanox/mlx5/core/en.h       |  12 +
 .../ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c |  37 +-
 .../ethernet/mellanox/mlx5/core/en_accel/macsec.c  |  47 +-
 drivers/net/ethernet/mellanox/mlx5/core/en_main.c  |  14 +-
 drivers/net/ethernet/mellanox/mlx5/core/en_stats.c |   9 +-
 drivers/net/ethernet/mellanox/mlx5/core/en_tc.c    |   3 +
 drivers/net/ethernet/mellanox/mlx5/core/eswitch.h  |  17 +-
 .../ethernet/mellanox/mlx5/core/eswitch_offloads.c |  24 +
 .../net/ethernet/mellanox/mlx5/core/ipoib/ipoib.c  |   3 +-
 drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c  | 507 +++++++++------
 drivers/net/ethernet/mellanox/mlx5/core/lag/lag.h  | 102 ++-
 .../net/ethernet/mellanox/mlx5/core/lag/mpesw.c    |  41 +-
 .../ethernet/mellanox/mlx5/core/lag/shared_fdb.c   | 235 +++++++
 .../net/ethernet/mellanox/mlx5/core/lib/devcom.c   |   8 +
 .../net/ethernet/mellanox/mlx5/core/lib/devcom.h   |   1 +
 .../net/ethernet/mellanox/mlx5/core/lib/hv_vhca.c  |   8 +-
 .../net/ethernet/mellanox/mlx5/core/lib/hv_vhca.h  |   6 +-
 .../net/ethernet/mellanox/mlx5/core/lib/port_tun.c |   3 +-
 drivers/net/ethernet/mellanox/mlx5/core/lib/sd.c   |  10 +
 drivers/net/ethernet/mellanox/mlx5/core/lib/sd.h   |  10 +
 drivers/net/ethernet/mellanox/mlx5/core/lib/st.c   |   1 +
 drivers/net/ethernet/mellanox/mlx5/core/main.c     |  12 +-
 .../ethernet/mellanox/mlx5/core/steering/hws/bwc.c |   1 +
 drivers/net/ethernet/mellanox/mlxsw/spectrum.c     |   2 +-
 .../net/ethernet/mellanox/mlxsw/spectrum_router.c  |   1 +
 drivers/net/ethernet/meta/fbnic/fbnic_fw.c         |   9 +-
 drivers/net/ethernet/meta/fbnic/fbnic_netdev.c     |   7 +-
 drivers/net/ethernet/meta/fbnic/fbnic_pci.c        |   4 +
 drivers/net/ethernet/meta/fbnic/fbnic_rpc.c        |   2 +
 drivers/net/ethernet/meta/fbnic/fbnic_txrx.c       |  11 +-
 drivers/net/ethernet/microchip/lan743x_main.c      |   2 +-
 .../ethernet/microchip/lan966x/lan966x_vcap_impl.c |   5 +-
 .../ethernet/microchip/sparx5/sparx5_switchdev.c   |   4 +-
 .../ethernet/microchip/sparx5/sparx5_vcap_impl.c   |   5 +-
 drivers/net/ethernet/microchip/vcap/vcap_api.c     |  72 ++-
 drivers/net/ethernet/microchip/vcap/vcap_api.h     |   3 +-
 .../net/ethernet/microchip/vcap/vcap_api_debugfs.c |   8 +-
 .../microchip/vcap/vcap_api_debugfs_kunit.c        |   3 +-
 .../net/ethernet/microchip/vcap/vcap_api_kunit.c   |   3 +-
 .../net/ethernet/microchip/vcap/vcap_api_private.h |   3 +
 drivers/net/ethernet/microsoft/mana/gdma_main.c    |   2 +
 drivers/net/ethernet/microsoft/mana/mana_bpf.c     |   3 +-
 drivers/net/ethernet/microsoft/mana/mana_en.c      |  80 ++-
 drivers/net/ethernet/mucse/rnpgbe/rnpgbe_mbx.c     |  26 +-
 drivers/net/ethernet/mucse/rnpgbe/rnpgbe_mbx.h     |   5 +-
 drivers/net/ethernet/mucse/rnpgbe/rnpgbe_mbx_fw.c  |  82 +--
 drivers/net/ethernet/mucse/rnpgbe/rnpgbe_mbx_fw.h  |  14 +
 drivers/net/ethernet/oa_tc6.c                      |  14 +-
 .../net/ethernet/pensando/ionic/ionic_ethtool.c    |  11 +-
 drivers/net/ethernet/qlogic/qede/qede_fp.c         |   9 +-
 .../net/ethernet/qualcomm/rmnet/rmnet_handlers.c   |   5 +-
 drivers/net/ethernet/qualcomm/rmnet/rmnet_map.h    |   1 +
 .../net/ethernet/qualcomm/rmnet/rmnet_map_data.c   |  78 ++-
 .../net/ethernet/stmicro/stmmac/dwmac-spacemit.c   |  13 +-
 drivers/net/ethernet/sun/sungem.c                  |  13 +-
 drivers/net/ethernet/sunplus/spl2sw_phy.c          |   6 +-
 drivers/net/ethernet/ti/icssg/icssg_common.c       | 120 ++--
 drivers/net/ethernet/wangxun/libwx/wx_lib.c        |   1 +
 drivers/net/ethernet/wangxun/libwx/wx_type.h       |   1 +
 drivers/net/geneve.c                               |  24 +-
 drivers/net/gtp.c                                  |  10 +-
 drivers/net/ieee802154/ca8210.c                    |   9 +-
 drivers/net/ipa/ipa_smp2p.c                        |  30 +-
 drivers/net/macsec.c                               |   9 +-
 drivers/net/mdio/Kconfig                           |   3 +-
 drivers/net/netconsole.c                           |  12 +-
 drivers/net/ovpn/udp.c                             |   2 +-
 drivers/net/pfcp.c                                 |   5 +-
 drivers/net/phy/realtek/realtek_main.c             |   3 +-
 drivers/net/phy/sfp.c                              |   1 +
 drivers/net/pse-pd/pse_core.c                      |   6 +-
 drivers/net/thunderbolt/main.c                     |   8 +-
 drivers/net/usb/gl620a.c                           |   6 +-
 drivers/net/usb/lan78xx.c                          |  55 +-
 drivers/net/usb/net1080.c                          |   2 +-
 drivers/net/veth.c                                 |   2 +
 drivers/net/virtio_net.c                           |  27 +-
 drivers/net/vxlan/vxlan_core.c                     |  14 +-
 drivers/net/wan/ixp4xx_hss.c                       |   4 +-
 drivers/net/wireguard/socket.c                     |   8 +-
 drivers/net/wireless/ath/ath11k/mhi.c              |   4 +-
 drivers/net/wireless/ath/ath11k/pci.c              |   8 +
 drivers/net/wireless/ath/ath12k/ahb.c              |  25 +-
 drivers/net/wireless/ath/ath12k/dp.c               |  10 +-
 drivers/net/wireless/ath/ath12k/dp_mon.c           |   6 +-
 drivers/net/wireless/ath/ath12k/mac.c              |  21 +-
 drivers/net/wireless/ath/ath12k/pci.c              |   2 +-
 drivers/net/wireless/ath/ath12k/wifi7/dp_rx.c      |   4 +-
 drivers/net/wireless/ath/ath9k/xmit.c              |   5 +
 drivers/net/wireless/ath/wcn36xx/smd.c             |  13 +
 .../broadcom/brcm80211/brcmfmac/cyw/core.c         |   6 +
 drivers/net/wireless/marvell/libertas_tf/main.c    |   2 +-
 drivers/net/wireless/marvell/mwifiex/cfg80211.c    |   2 +-
 drivers/net/wireless/marvell/mwifiex/join.c        |   1 -
 drivers/net/wireless/mediatek/mt76/channel.c       |   2 +-
 drivers/net/wireless/mediatek/mt76/mac80211.c      |   4 +-
 drivers/net/wireless/mediatek/mt76/mt7615/init.c   |   1 -
 drivers/net/wireless/mediatek/mt76/mt7915/mac.c    |  10 +-
 drivers/net/wireless/mediatek/mt76/mt7921/mac.c    |   5 +-
 drivers/net/wireless/mediatek/mt76/mt7921/pci.c    |  17 +-
 drivers/net/wireless/mediatek/mt76/mt7925/mac.c    |  20 +-
 drivers/net/wireless/mediatek/mt76/mt7925/main.c   |   4 +-
 drivers/net/wireless/mediatek/mt76/mt7925/pci.c    |   4 +-
 .../net/wireless/mediatek/mt76/mt7925/testmode.c   |   5 +
 drivers/net/wireless/mediatek/mt76/mt792x_core.c   |   4 +-
 drivers/net/wireless/mediatek/mt76/mt7996/dma.c    |   2 +-
 drivers/net/wireless/mediatek/mt76/mt7996/mac.c    |  35 +-
 drivers/net/wireless/mediatek/mt76/mt7996/main.c   |   9 +-
 drivers/net/wireless/mediatek/mt76/mt7996/mcu.c    |   5 +-
 drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h |   3 +-
 drivers/net/wireless/mediatek/mt76/mt7996/pci.c    |   2 +-
 drivers/net/wireless/mediatek/mt76/tx.c            |   2 +-
 drivers/net/wireless/ralink/rt2x00/rt2x00dev.c     |  12 +-
 drivers/net/wireless/realtek/rtw88/pci.c           |  13 +-
 drivers/net/wireless/realtek/rtw89/core.h          |   3 +
 drivers/net/wireless/realtek/rtw89/fw.c            |   2 +-
 drivers/net/wireless/realtek/rtw89/pci.c           |   8 +-
 drivers/net/wireless/ti/wlcore/main.c              |  23 +-
 drivers/net/wwan/iosm/iosm_ipc_mux_codec.c         |  40 +-
 drivers/net/wwan/t7xx/t7xx_hif_cldma.c             |   3 +
 drivers/net/wwan/t7xx/t7xx_port_wwan.c             |   2 +
 drivers/ntb/hw/epf/ntb_hw_epf.c                    |  81 ++-
 drivers/ntb/ntb_transport.c                        |  10 +-
 drivers/nvdimm/btt.c                               |  14 +-
 drivers/nvdimm/nd.h                                |  11 +-
 drivers/nvdimm/region_devs.c                       |  66 +-
 drivers/nvme/host/apple.c                          |  12 +-
 drivers/nvme/host/core.c                           |   4 +-
 drivers/nvme/host/pci.c                            |   9 +-
 drivers/nvme/target/core.c                         |   2 +-
 drivers/nvme/target/fabrics-cmd-auth.c             |  26 +-
 drivers/nvme/target/rdma.c                         |  18 +-
 drivers/nvme/target/tcp.c                          |  11 +-
 drivers/of/cpu.c                                   |   2 +-
 drivers/of/dynamic.c                               |   1 -
 drivers/of/of_reserved_mem.c                       |  28 +-
 drivers/of/overlay.c                               |  15 +
 drivers/of/platform.c                              |   5 -
 drivers/opp/core.c                                 |   5 +-
 drivers/pci/controller/dwc/pci-meson.c             |  13 +-
 .../pci/controller/dwc/pcie-designware-debugfs.c   |  10 +-
 drivers/pci/controller/dwc/pcie-designware.c       |  16 +-
 drivers/pci/controller/dwc/pcie-designware.h       |   1 +
 drivers/pci/controller/dwc/pcie-intel-gw.c         |  46 +-
 drivers/pci/controller/dwc/pcie-qcom.c             |  43 +-
 drivers/pci/controller/pci-loongson.c              |  31 +-
 drivers/pci/controller/pcie-iproc-bcma.c           |   2 +-
 drivers/pci/controller/pcie-iproc-platform.c       |   2 +-
 drivers/pci/controller/pcie-iproc.c                |   1 -
 drivers/pci/controller/pcie-iproc.h                |   2 -
 drivers/pci/controller/pcie-mediatek-gen3.c        |   4 +-
 drivers/pci/controller/pcie-mediatek.c             |  19 +-
 drivers/pci/controller/pcie-rcar-host.c            |   1 -
 drivers/pci/endpoint/functions/pci-epf-ntb.c       |  21 +-
 drivers/pci/endpoint/functions/pci-epf-vntb.c      | 130 +++-
 drivers/pci/msi/msi.c                              |   4 +-
 drivers/pci/pci.c                                  |   3 -
 drivers/pci/pwrctrl/core.c                         |  26 +-
 drivers/pci/rom.c                                  | 149 ++++-
 drivers/phy/freescale/phy-fsl-imx8qm-lvds-phy.c    |  26 +-
 drivers/phy/phy-can-transceiver.c                  |   3 +
 drivers/pinctrl/Kconfig                            |   1 +
 drivers/pinctrl/cirrus/pinctrl-cs42l43.c           |   6 +-
 drivers/pinctrl/mediatek/mtk-eint.c                |   6 +-
 drivers/pinctrl/mediatek/pinctrl-airoha.c          | 122 +++-
 drivers/pinctrl/mediatek/pinctrl-mt8167.c          |   2 +-
 drivers/pinctrl/mediatek/pinctrl-mt8516.c          |   2 +-
 drivers/pinctrl/meson/pinctrl-amlogic-a4.c         |  15 +-
 drivers/pinctrl/meson/pinctrl-meson.c              |   2 +-
 drivers/pinctrl/nuvoton/pinctrl-ma35.c             |   3 +-
 drivers/pinctrl/nuvoton/pinctrl-ma35d1.c           | 470 ++++++++------
 drivers/pinctrl/pinconf-generic.c                  |   5 +-
 drivers/pinctrl/qcom/tlmm-test.c                   |  19 +-
 drivers/pinctrl/renesas/pinctrl-rzg2l.c            |   8 +-
 drivers/pinctrl/spacemit/pinctrl-k1.c              |   2 +-
 drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c      |   1 -
 drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c        |   1 -
 drivers/pinctrl/sunxi/pinctrl-sunxi.c              |   2 +-
 drivers/platform/chrome/chromeos_privacy_screen.c  |   3 +
 drivers/platform/chrome/chromeos_tbmc.c            |   6 +-
 drivers/platform/chrome/wilco_ec/event.c           |   8 +-
 drivers/platform/x86/amd/pmc/pmc-quirks.c          |  39 ++
 drivers/platform/x86/amd/pmc/pmc.c                 |  83 ++-
 drivers/platform/x86/amd/pmc/pmc.h                 |   2 +
 drivers/platform/x86/bitland-mifs-wmi.c            |   8 +
 drivers/platform/x86/classmate-laptop.c            |  12 +-
 drivers/platform/x86/dell/dell-laptop.c            |   5 +
 drivers/platform/x86/hp/hp-wmi.c                   |   8 +
 .../x86/intel/speed_select_if/isst_tpmi_core.c     |   2 +-
 drivers/platform/x86/intel/vsec.c                  |  17 +-
 drivers/platform/x86/intel/vsec_tpmi.c             |  25 +-
 drivers/platform/x86/xo15-ebook.c                  |   7 +-
 drivers/pmdomain/imx/imx8m-blk-ctrl.c              |  46 +-
 drivers/pmdomain/imx/imx93-blk-ctrl.c              |  60 +-
 drivers/pmdomain/mediatek/mtk-pm-domains.c         |  40 +-
 drivers/power/sequencing/core.c                    |   9 +-
 drivers/power/supply/bq257xx_charger.c             |   7 +-
 drivers/power/supply/charger-manager.c             |   6 +-
 drivers/power/supply/cpcap-battery.c               |  11 +-
 drivers/power/supply/max17042_battery.c            |   3 +-
 drivers/power/supply/power_supply_core.c           |  11 +-
 drivers/pwm/pwm-imx27.c                            |   8 +-
 drivers/pwm/pwm-rzg2l-gpt.c                        |   8 +-
 drivers/rapidio/devices/tsi721.c                   |   3 +-
 drivers/regulator/core.c                           |   4 +-
 drivers/regulator/ltc3676.c                        |  10 +-
 drivers/remoteproc/qcom_common.c                   |  14 +-
 drivers/remoteproc/qcom_q6v5_wcss.c                |  23 +-
 drivers/remoteproc/xlnx_r5_remoteproc.c            |  46 +-
 drivers/reset/reset-imx7.c                         |   6 +
 drivers/reset/reset-sunxi.c                        |   4 +-
 drivers/rpmsg/qcom_glink_native.c                  |   2 -
 drivers/rpmsg/rpmsg_core.c                         |  43 +-
 drivers/rpmsg/virtio_rpmsg_bus.c                   |   1 -
 drivers/rtc/rtc-abx80x.c                           |   3 +-
 drivers/rtc/rtc-cmos.c                             |   6 +
 drivers/rtc/rtc-ds1307.c                           |  30 +-
 drivers/rtc/rtc-isl1208.c                          |  15 +-
 drivers/rtc/rtc-mpfs.c                             |   2 +-
 drivers/rtc/rtc-msc313.c                           |   4 +-
 drivers/rtc/rtc-renesas-rtca3.c                    |   2 +-
 drivers/s390/char/monwriter.c                      |   3 +
 drivers/s390/crypto/pkey_api.c                     |   8 +-
 drivers/s390/crypto/pkey_pckmo.c                   |   4 +
 drivers/s390/crypto/zcrypt_cex2a.c                 |   0
 drivers/s390/crypto/zcrypt_cex2a.h                 |   0
 drivers/s390/crypto/zcrypt_cex2c.c                 |   0
 drivers/s390/crypto/zcrypt_cex2c.h                 |   0
 drivers/scsi/elx/efct/efct_hw.c                    |   2 +
 drivers/scsi/elx/efct/efct_unsol.c                 |   1 +
 drivers/scsi/hisi_sas/hisi_sas_v3_hw.c             |  12 +-
 drivers/scsi/hpsa.c                                |   4 +
 drivers/scsi/lpfc/lpfc_init.c                      |   3 +-
 drivers/scsi/pm8001/pm8001_ctl.c                   |   5 +-
 drivers/scsi/scsi_scan.c                           |   2 +-
 drivers/scsi/scsi_transport_sas.c                  | 101 ++-
 drivers/scsi/sg.c                                  |   7 +-
 drivers/scsi/smartpqi/smartpqi_init.c              |   2 +-
 drivers/soc/fsl/qe/qe.c                            |   3 +
 drivers/soc/fsl/qe/qe_ports_ic.c                   |  21 +-
 drivers/soc/mediatek/mt8167-mmsys.h                |  11 +-
 drivers/soc/ti/k3-ringacc.c                        |   4 +-
 drivers/soc/xilinx/zynqmp_power.c                  |  47 +-
 drivers/soundwire/generic_bandwidth_allocation.c   |  57 +-
 drivers/soundwire/intel_ace2x.c                    |   1 +
 drivers/soundwire/stream.c                         |   7 +
 drivers/spi/spi-atcspi200.c                        |  13 +-
 drivers/spi/spi-atmel.c                            | 133 ++--
 drivers/spi/spi-dw.h                               |   1 +
 drivers/spi/spi-ep93xx.c                           |   1 +
 drivers/spi/spi-hisi-kunpeng.c                     |   6 +-
 drivers/spi/spi-imx.c                              |  19 +-
 drivers/spi/spi-meson-spifc.c                      |   1 +
 drivers/spi/spi-rpc-if.c                           |   6 +-
 drivers/spi/spi-rzv2h-rspi.c                       |   4 +-
 drivers/spi/spi-sh-msiof.c                         |  10 +-
 drivers/spi/spi-uniphier.c                         |   4 +-
 drivers/spi/spi-xilinx.c                           |  11 +-
 drivers/spi/spi.c                                  |   5 -
 drivers/staging/media/atomisp/i2c/atomisp-gc2235.c |  29 +-
 drivers/staging/media/atomisp/pci/atomisp_cmd.c    |   6 +-
 drivers/staging/media/atomisp/pci/sh_css.c         |   8 +-
 drivers/staging/media/sunxi/cedrus/cedrus.c        |   4 +-
 drivers/staging/most/video/video.c                 |   7 +-
 drivers/staging/nvec/nvec.c                        |   4 +-
 drivers/staging/rtl8723bs/core/rtw_security.c      |   2 +-
 drivers/target/iscsi/iscsi_target_auth.c           |   6 +-
 drivers/target/loopback/tcm_loop.c                 |  64 --
 drivers/target/target_core_fabric_lib.c            |  89 ++-
 drivers/target/target_core_internal.h              |   3 +-
 drivers/target/target_core_pr.c                    |  12 +-
 drivers/thermal/intel/therm_throt.c                |   7 +-
 drivers/thermal/testing/command.c                  |  48 +-
 drivers/thermal/testing/thermal_testing.h          |   8 +
 drivers/thermal/testing/zone.c                     |   7 +-
 drivers/thermal/thermal_hwmon.c                    | 156 ++---
 drivers/thunderbolt/debugfs.c                      |   8 +-
 drivers/tty/serial/8250/8250_omap.c                |   3 +-
 drivers/tty/serial/max310x.c                       |  12 +
 drivers/tty/serial/msm_serial.c                    |   3 +-
 drivers/ufs/core/ufs_trace.h                       |  36 +-
 drivers/ufs/core/ufshcd.c                          |  36 +-
 drivers/usb/atm/ueagle-atm.c                       |  94 ++-
 drivers/usb/host/max3421-hcd.c                     |   8 +
 drivers/vdpa/octeon_ep/octep_vdpa_main.c           |  20 +-
 drivers/vdpa/vdpa_user/iova_domain.c               |   2 +-
 drivers/vdpa/vdpa_user/vduse_dev.c                 | 197 +++++-
 drivers/vfio/pci/qat/main.c                        |  18 +-
 drivers/vfio/pci/xe/main.c                         |   2 -
 drivers/vhost/net.c                                |  15 +-
 drivers/vhost/vdpa.c                               |  29 +-
 drivers/vhost/vhost.c                              |  11 +-
 drivers/video/backlight/ktd2801-backlight.c        |   1 +
 drivers/video/fbdev/aty/radeon_base.c              |   1 +
 drivers/video/fbdev/broadsheetfb.c                 |   8 +-
 drivers/video/fbdev/carminefb.c                    |   1 +
 drivers/video/fbdev/core/fbcon.c                   |  10 +-
 drivers/video/fbdev/efifb.c                        |   1 +
 drivers/video/fbdev/hecubafb.c                     |   6 +-
 drivers/video/fbdev/i740fb.c                       |   1 +
 drivers/video/fbdev/metronomefb.c                  |   8 +-
 drivers/video/fbdev/nvidia/nvidia.c                |   1 +
 drivers/video/fbdev/s3fb.c                         |   1 +
 drivers/video/fbdev/sm501fb.c                      |  16 +-
 drivers/video/fbdev/sm712.h                        |   2 +-
 drivers/video/fbdev/tdfxfb.c                       |   1 +
 drivers/video/fbdev/tridentfb.c                    |   1 +
 drivers/video/fbdev/uvesafb.c                      |   4 +-
 drivers/video/fbdev/vesafb.c                       |   1 +
 drivers/virtio/virtio_rtc_driver.c                 |  28 +-
 drivers/watchdog/sama5d4_wdt.c                     |  48 +-
 drivers/watchdog/sp5100_tco.c                      |   3 +-
 drivers/watchdog/sprd_wdt.c                        |   5 +-
 drivers/watchdog/watchdog_core.c                   |   3 +
 drivers/xen/gntdev.c                               |   8 +-
 drivers/xen/pvcalls-front.c                        |  88 ++-
 drivers/xen/xen-scsiback.c                         |  30 +-
 fs/9p/vfs_inode.c                                  |  28 +-
 fs/9p/vfs_inode_dotl.c                             |   4 +-
 fs/afs/callback.c                                  |  17 +-
 fs/afs/cell.c                                      |  27 +-
 fs/afs/cm_security.c                               |   3 +-
 fs/afs/cmservice.c                                 |   7 +-
 fs/afs/dir.c                                       |  40 +-
 fs/afs/dynroot.c                                   |   2 +-
 fs/afs/fs_operation.c                              |   2 +-
 fs/afs/inode.c                                     |  15 +-
 fs/afs/internal.h                                  |   3 +-
 fs/afs/rxrpc.c                                     |  16 +-
 fs/afs/super.c                                     |   5 +-
 fs/afs/vl_list.c                                   |  10 +-
 fs/afs/volume.c                                    |   2 +-
 fs/bpf_fs_kfuncs.c                                 |  10 +-
 fs/btrfs/compression.c                             |  18 +-
 fs/btrfs/delalloc-space.c                          |   2 +
 fs/btrfs/disk-io.c                                 |   2 +-
 fs/btrfs/extent-tree.c                             |   5 +-
 fs/btrfs/inode.c                                   |   2 +-
 fs/btrfs/lzo.c                                     |  11 +
 fs/btrfs/reflink.c                                 | 101 +--
 fs/btrfs/space-info.c                              |   2 +
 fs/btrfs/space-info.h                              |  11 +
 fs/btrfs/super.c                                   |   4 +-
 fs/btrfs/zoned.c                                   |  64 +-
 fs/cachefiles/namei.c                              |   3 +-
 fs/configfs/dir.c                                  |  57 +-
 fs/crypto/fscrypt_private.h                        |  32 +-
 fs/crypto/keyring.c                                | 216 +++----
 fs/dlm/midcomms.c                                  |   4 +-
 fs/efs/file.c                                      |  21 +-
 fs/erofs/inode.c                                   |   5 +-
 fs/erofs/super.c                                   |   4 +-
 fs/eventpoll.c                                     | 609 ++++++++++++------
 fs/exfat/balloc.c                                  |   2 +-
 fs/exfat/dir.c                                     |  48 +-
 fs/exfat/exfat_fs.h                                | 131 +++-
 fs/exfat/fatent.c                                  |   4 +-
 fs/exfat/file.c                                    |   8 +-
 fs/exfat/inode.c                                   |  26 +-
 fs/exfat/namei.c                                   |  26 +-
 fs/exfat/super.c                                   |   5 +-
 fs/ext2/file.c                                     |   9 +-
 fs/ext4/ext4.h                                     |  20 +
 fs/ext4/fast_commit.c                              |  50 +-
 fs/ext4/inode.c                                    |   3 +-
 fs/ext4/ioctl.c                                    |  15 +-
 fs/ext4/namei.c                                    |   2 +-
 fs/f2fs/data.c                                     |  29 +
 fs/f2fs/f2fs.h                                     |   1 +
 fs/f2fs/segment.c                                  |   8 +
 fs/f2fs/xattr.c                                    |   6 +-
 fs/fhandle.c                                       |   2 +-
 fs/fs-writeback.c                                  |   5 -
 fs/hfs/inode.c                                     |   2 +-
 fs/hfsplus/btree.c                                 |   2 +
 fs/hfsplus/xattr.c                                 |   1 -
 fs/iomap/bio.c                                     |  13 +-
 fs/iomap/buffered-io.c                             |   2 +-
 fs/iomap/direct-io.c                               |   7 +-
 fs/iomap/ioend.c                                   |   8 +-
 fs/jbd2/journal.c                                  |   2 +
 fs/kernfs/dir.c                                    |  33 +-
 fs/kernfs/file.c                                   |  13 +-
 fs/kernfs/inode.c                                  |  36 +-
 fs/kernfs/kernfs-internal.h                        |  24 +-
 fs/kernfs/mount.c                                  |   2 +-
 fs/lockd/lockd.h                                   |   8 +
 fs/lockd/svc4proc.c                                |  19 +-
 fs/lockd/svcproc.c                                 |   2 +-
 fs/lockd/svcsubs.c                                 |   7 +-
 fs/minix/minix.h                                   |   2 +-
 fs/namei.c                                         |   4 +
 fs/netfs/read_retry.c                              |   7 +-
 fs/netfs/write_issue.c                             |  18 +-
 fs/netfs/write_retry.c                             |   7 +-
 fs/nfs/callback_proc.c                             |   9 +-
 fs/nfs/delegation.c                                |   9 +-
 fs/nfs/filelayout/filelayout.c                     |   2 +
 fs/nfs/flexfilelayout/flexfilelayout.c             |  29 +
 fs/nfs/flexfilelayout/flexfilelayout.h             |  16 +
 fs/nfs/fs_context.c                                |   8 +-
 fs/nfs/internal.h                                  |  12 +-
 fs/nfs/nfs4proc.c                                  |  22 +-
 fs/nfs/pnfs.c                                      |   4 +-
 fs/nfs/pnfs_nfs.c                                  |   2 +-
 fs/nfs/read.c                                      |  25 +-
 fs/nfs/write.c                                     |  14 +-
 fs/nfsd/nfs4state.c                                |  16 +-
 fs/nilfs2/namei.c                                  |   2 +-
 fs/nilfs2/super.c                                  |   2 -
 fs/ntfs/aops.c                                     |  23 +-
 fs/ntfs/attrib.c                                   | 345 +++++++---
 fs/ntfs/attrib.h                                   |   4 +
 fs/ntfs/attrlist.c                                 |  20 +-
 fs/ntfs/dir.c                                      |  79 +--
 fs/ntfs/ea.c                                       |  16 +-
 fs/ntfs/index.c                                    | 297 ++++++---
 fs/ntfs/index.h                                    |  12 +-
 fs/ntfs/inode.c                                    |  38 +-
 fs/ntfs/logfile.c                                  |   2 +-
 fs/ntfs/mft.c                                      | 137 +---
 fs/ntfs/namei.c                                    |  67 +-
 fs/ntfs/runlist.c                                  |  12 +-
 fs/ntfs/super.c                                    |  53 +-
 fs/ntfs3/attrib.c                                  |  10 +-
 fs/ntfs3/frecord.c                                 |  17 +-
 fs/ntfs3/fslog.c                                   | 147 ++++-
 fs/ntfs3/index.c                                   |  45 +-
 fs/ntfs3/inode.c                                   |   9 +-
 fs/ntfs3/lznt.c                                    |   2 +-
 fs/ntfs3/namei.c                                   |   2 +-
 fs/ntfs3/ntfs_fs.h                                 |   3 +-
 fs/ntfs3/run.c                                     |  14 +-
 fs/ocfs2/alloc.c                                   |   2 +-
 fs/ocfs2/aops.c                                    |  13 +-
 fs/ocfs2/buffer_head_io.c                          |   7 +-
 fs/ocfs2/dlm/dlmdebug.c                            |  16 +-
 fs/ocfs2/dlmglue.c                                 |  17 +
 fs/ocfs2/inode.c                                   | 206 +++++-
 fs/ocfs2/journal.c                                 |  13 +-
 fs/ocfs2/journal.h                                 |   3 +
 fs/ocfs2/move_extents.c                            |   4 +-
 fs/ocfs2/ocfs2.h                                   |   2 -
 fs/ocfs2/quota_local.c                             |   2 +-
 fs/ocfs2/refcounttree.c                            |   9 +-
 fs/ocfs2/stack_user.c                              |  10 +-
 fs/ocfs2/super.c                                   |   2 -
 fs/ocfs2/sysfile.c                                 |   9 +-
 fs/orangefs/dir.c                                  |   7 +-
 fs/overlayfs/copy_up.c                             |  12 +-
 fs/overlayfs/inode.c                               |   4 +-
 fs/pidfs.c                                         |  45 +-
 fs/proc/generic.c                                  |   9 +-
 fs/proc/page.c                                     |   2 +-
 fs/proc/task_mmu.c                                 |  74 ++-
 fs/resctrl/rdtgroup.c                              |  33 +-
 fs/smb/client/cifs_fs_sb.h                         |   1 +
 fs/smb/client/cifsfs.c                             |  12 +
 fs/smb/client/connect.c                            |   4 +
 fs/smb/client/file.c                               |   6 +
 fs/smb/client/fs_context.c                         | 102 +--
 fs/smb/client/inode.c                              |  30 +-
 fs/smb/client/ioctl.c                              |  12 +-
 fs/smb/client/misc.c                               |   8 +
 fs/smb/client/reparse.c                            |  17 +-
 fs/smb/client/smb1pdu.h                            |   5 -
 fs/smb/client/smb2ops.c                            |  38 +-
 fs/smb/client/smb2pdu.h                            |   4 -
 fs/smb/common/fscc.h                               |  18 +
 fs/smb/server/auth.c                               |  47 +-
 fs/smb/server/auth.h                               |   7 +-
 fs/smb/server/mgmt/user_session.c                  |   4 +-
 fs/smb/server/mgmt/user_session.h                  |   1 +
 fs/smb/server/misc.c                               |  33 -
 fs/smb/server/misc.h                               |   1 -
 fs/smb/server/oplock.c                             |   6 +
 fs/smb/server/smb2pdu.c                            | 171 +++--
 fs/smb/server/smb2pdu.h                            |   3 -
 fs/smb/server/smbacl.c                             |   7 +-
 fs/smb/server/vfs.c                                |  55 +-
 fs/smb/server/vfs_cache.c                          |  29 +-
 fs/super.c                                         |  11 +-
 fs/sysfs/file.c                                    |   4 +
 fs/udf/super.c                                     |   2 +-
 fs/xattr.c                                         | 265 ++++----
 fs/xfs/xfs_aops.c                                  |   3 +-
 fs/xfs/xfs_rtalloc.c                               |   8 +
 fs/xfs/xfs_zone_alloc.c                            |  11 +-
 fs/xfs/xfs_zone_alloc.h                            |   1 +
 fs/xfs/xfs_zone_gc.c                               |   4 +-
 include/acpi/platform/aclinuxex.h                  |   1 +
 include/asm-generic/bitops/lock.h                  |  22 +-
 include/asm-generic/uaccess.h                      |   3 +-
 include/dt-bindings/clock/qcom,x1e80100-camcc.h    |   3 +
 include/dt-bindings/power/fsl,imx93-power.h        |   1 +
 include/linux/amba/bus.h                           |   5 -
 include/linux/arm-smccc.h                          |   5 +
 include/linux/bpf-cgroup.h                         |   5 +-
 include/linux/bpf.h                                |   2 +
 include/linux/bpf_lsm.h                            |   6 +
 include/linux/cdx/cdx_bus.h                        |   4 -
 include/linux/device.h                             |   5 +-
 include/linux/edac.h                               |   3 +
 include/linux/filelock.h                           |   2 +-
 include/linux/firmware.h                           |  10 +
 .../linux/firmware/samsung/exynos-acpm-protocol.h  |  10 +-
 include/linux/firmware/xlnx-zynqmp.h               |  21 +
 include/linux/fs.h                                 |   1 +
 include/linux/fwnode.h                             |   3 +
 include/linux/hfs_common.h                         |   1 +
 include/linux/host1x.h                             |   7 +
 include/linux/hyperv.h                             |   5 -
 include/linux/i3c/master.h                         |  14 +-
 include/linux/ieee80211-eht.h                      |  12 +-
 include/linux/ieee80211-s1g.h                      |   2 +-
 include/linux/inetdevice.h                         |   5 +
 include/linux/iomap.h                              |   2 +
 include/linux/iommu.h                              |   1 +
 include/linux/kernfs.h                             |  11 +-
 include/linux/liveupdate.h                         |   9 +-
 include/linux/mfd/rohm-bd72720.h                   |   1 -
 include/linux/netdevice.h                          |   4 +
 include/linux/nfs_page.h                           |   1 +
 include/linux/nfs_xdr.h                            |   1 -
 include/linux/rhashtable-types.h                   |  22 +-
 include/linux/rpmsg.h                              |   4 -
 include/linux/shmem_fs.h                           |   3 +-
 include/linux/sockptr.h                            |   2 +-
 include/linux/sunrpc/clnt.h                        |   1 +
 include/linux/uaccess.h                            |  27 +-
 include/linux/virtio.h                             |   2 +
 include/linux/vmalloc.h                            |   4 +-
 include/linux/xattr.h                              |  35 +-
 include/net/addrconf.h                             |  10 +-
 include/net/bluetooth/hci.h                        |   5 +-
 include/net/bluetooth/l2cap.h                      |  10 +-
 include/net/bond_options.h                         |   1 +
 include/net/bonding.h                              |   1 +
 include/net/dst_metadata.h                         |   7 +-
 include/net/fib_rules.h                            |   5 +
 include/net/gue.h                                  |   2 +-
 include/net/ip_fib.h                               |  12 +-
 include/net/ip_vs.h                                |   3 +-
 include/net/mana/mana.h                            |   8 +
 include/net/netfilter/ipv4/nf_conntrack_ipv4.h     |   4 +
 include/net/netfilter/nf_conntrack_expect.h        |  17 +-
 include/net/netfilter/nf_conntrack_extend.h        |  12 -
 include/net/netfilter/nf_conntrack_helper.h        |  18 +-
 include/net/netfilter/nf_conntrack_timeout.h       |  27 +-
 include/net/netfilter/nf_dup_netdev.h              |  36 +-
 include/net/netfilter/nf_flow_table.h              |   5 +-
 include/net/netfilter/nf_queue.h                   |   1 +
 include/net/netfilter/nft_meta.h                   |   2 +
 include/net/sch_generic.h                          |  32 +-
 include/net/sctp/sctp.h                            |   3 +-
 include/net/tc_act/tc_pedit.h                      |  18 +-
 include/net/tcp.h                                  |   9 +
 include/net/udp_tunnel.h                           |   4 +-
 include/net/xfrm.h                                 |  15 +-
 include/rdma/frmr_pools.h                          |   3 +-
 include/rdma/ib_umem.h                             |   4 +
 include/rdma/ib_verbs.h                            |   5 +
 include/rdma/rdma_vt.h                             |  20 -
 include/soc/spacemit/k3-syscon.h                   |   4 +-
 include/sound/soc-dapm.h                           |   1 +
 include/trace/events/dma_fence.h                   |  40 +-
 include/uapi/linux/bpf.h                           |   2 +
 include/uapi/linux/if_link.h                       |   1 +
 include/uapi/linux/iommufd.h                       |  12 +-
 include/uapi/linux/netfilter/nf_conntrack_common.h |   1 +
 include/uapi/rdma/bnxt_re-abi.h                    |   7 +-
 include/ufs/ufshcd.h                               |   3 -
 init/initramfs_test.c                              |  17 +-
 io_uring/bpf-ops.c                                 |   2 +
 kernel/bpf/arena.c                                 |  61 +-
 kernel/bpf/arraymap.c                              |   8 +-
 kernel/bpf/bpf_lru_list.c                          | 165 +++--
 kernel/bpf/bpf_lru_list.h                          |  25 +-
 kernel/bpf/bpf_lsm.c                               |  23 +
 kernel/bpf/cgroup.c                                | 168 +++--
 kernel/bpf/core.c                                  |   2 +-
 kernel/bpf/devmap.c                                |  12 +
 kernel/bpf/disasm.c                                |   5 +-
 kernel/bpf/hashtab.c                               |  32 +-
 kernel/bpf/helpers.c                               |  17 +-
 kernel/bpf/inode.c                                 |  13 +-
 kernel/bpf/map_in_map.c                            |   5 +-
 kernel/bpf/map_iter.c                              |   4 +
 kernel/bpf/states.c                                |  13 +-
 kernel/bpf/syscall.c                               |  35 +-
 kernel/bpf/verifier.c                              |  56 +-
 kernel/cgroup/cpuset.c                             |   7 +-
 kernel/cpu.c                                       |  20 +-
 kernel/exit.c                                      |   7 +-
 kernel/fork.c                                      |   9 +-
 kernel/kcov.c                                      |   4 +-
 kernel/kexec_core.c                                |   8 +-
 kernel/liveupdate/kexec_handover.c                 |  32 +-
 kernel/liveupdate/luo_file.c                       |   5 +-
 kernel/liveupdate/luo_flb.c                        |  52 +-
 kernel/liveupdate/luo_session.c                    |  99 ++-
 kernel/locking/spinlock_rt.c                       |  27 +-
 kernel/power/qos.c                                 |  11 +-
 kernel/sched/core.c                                |   1 +
 kernel/sched/cpufreq_schedutil.c                   |   1 +
 kernel/sched/debug.c                               |   3 +
 kernel/sched/fair.c                                | 211 +++---
 kernel/signal.c                                    |  10 +-
 kernel/taskstats.c                                 |  62 +-
 kernel/time/alarmtimer.c                           |   8 +-
 kernel/time/posix-cpu-timers.c                     | 187 ++++--
 kernel/time/posix-timers.c                         |   6 +-
 kernel/time/posix-timers.h                         |   4 +-
 kernel/time/tick-sched.c                           |  11 +-
 kernel/time/time.c                                 |   2 +-
 kernel/time/timer_migration.h                      |  18 +-
 kernel/trace/bpf_trace.c                           |  22 +-
 kernel/trace/fprobe.c                              |  10 +
 kernel/trace/ring_buffer.c                         |   8 +-
 kernel/trace/trace.c                               |   2 +-
 kernel/trace/trace_eprobe.c                        |   2 +-
 kernel/trace/trace_events_hist.c                   |  41 +-
 kernel/trace/trace_events_user.c                   |  43 +-
 kernel/trace/trace_osnoise.c                       |   4 +-
 kernel/trace/trace_probe.c                         | 174 ++++-
 kernel/trace/trace_probe.h                         |   7 +-
 kernel/trace/trace_remote.c                        |  18 +-
 kernel/workqueue.c                                 |   2 +-
 lib/Kconfig.debug                                  |   5 +
 lib/alloc_tag.c                                    |   9 +-
 lib/base64.c                                       |   3 +-
 lib/crypto/Kconfig                                 |   3 +-
 lib/fonts/font_acorn_8x8.c                         |   5 +
 lib/locking-selftest.c                             |   7 +-
 lib/rhashtable.c                                   |  17 +-
 lib/test_hmm.c                                     |   6 +-
 lib/test_meminit.c                                 |   2 +-
 lib/tests/kunit_iov_iter.c                         |  12 +-
 lib/tests/liveupdate.c                             |   3 +
 lib/usercopy.c                                     |   4 +-
 lib/vsprintf.c                                     |  36 +-
 mm/compaction.c                                    |   7 +-
 mm/damon/core.c                                    |  59 +-
 mm/damon/sysfs-schemes.c                           |  17 +-
 mm/huge_memory.c                                   |   3 +
 mm/hugetlb.c                                       |   7 +-
 mm/memory_hotplug.c                                |   2 +-
 mm/mm_init.c                                       |  47 +-
 mm/numa_emulation.c                                |  17 +-
 mm/shmem.c                                         |  50 +-
 mm/slub.c                                          |   7 +-
 mm/sparse-vmemmap.c                                |  20 +-
 net/9p/client.c                                    |   2 +
 net/9p/trans_rdma.c                                |  19 +-
 net/9p/trans_virtio.c                              |   5 +
 net/atm/common.c                                   |   2 +
 net/batman-adv/distributed-arp-table.c             |  30 +-
 net/batman-adv/fragmentation.c                     |   8 +-
 net/batman-adv/gateway_client.c                    |   3 +-
 net/batman-adv/main.c                              |  13 +-
 net/batman-adv/mesh-interface.c                    |  17 +-
 net/batman-adv/mesh-interface.h                    |   2 +
 net/batman-adv/multicast_forw.c                    |   7 +-
 net/batman-adv/routing.c                           |   3 +-
 net/batman-adv/translation-table.c                 |   5 +-
 net/bluetooth/6lowpan.c                            |  83 ++-
 net/bluetooth/eir.c                                |   8 +-
 net/bluetooth/hci_codec.c                          |   2 +-
 net/bluetooth/hci_core.c                           |   2 +
 net/bluetooth/hci_event.c                          |   7 +
 net/bluetooth/iso.c                                |  31 +-
 net/bluetooth/l2cap_core.c                         |  94 ++-
 net/bluetooth/l2cap_sock.c                         | 103 ++-
 net/bluetooth/mgmt.c                               |   2 +
 net/bluetooth/msft.c                               |   2 +-
 net/bluetooth/sco.c                                |  15 +-
 net/bluetooth/smp.c                                |  27 +-
 net/bpf/test_run.c                                 |   8 +-
 net/bridge/br_cfm.c                                |   6 +
 net/bridge/br_cfm_netlink.c                        |   4 +-
 net/bridge/br_if.c                                 |   3 +
 net/bridge/br_stp.c                                |   3 +-
 net/bridge/netfilter/nft_meta_bridge.c             |  23 +-
 net/can/bcm.c                                      | 654 ++++++++++++++-----
 net/can/isotp.c                                    | 298 ++++++---
 net/core/dev.c                                     |   9 +-
 net/core/fib_rules.c                               |   6 +-
 net/core/filter.c                                  |  28 +-
 net/core/flow_dissector.c                          |  12 +-
 net/core/lwt_bpf.c                                 |  12 +
 net/core/lwtunnel.c                                |   6 +
 net/core/netdev-genl.c                             |   4 +-
 net/core/netdev_rx_queue.c                         |   8 +-
 net/devlink/rate.c                                 |  25 +-
 net/ethtool/netlink.h                              |  28 +
 net/ethtool/rss.c                                  |  14 +-
 net/handshake/genl.c                               |   2 +-
 net/ieee802154/core.c                              |  49 +-
 net/ieee802154/header_ops.c                        |   9 +-
 net/ieee802154/ieee802154.h                        |  17 +
 net/ieee802154/netlink.c                           |  36 +-
 net/ife/ife.c                                      |   2 +-
 net/ipv4/fib_trie.c                                |   4 +
 net/ipv4/fou_core.c                                |   9 +-
 net/ipv4/igmp.c                                    |  63 +-
 net/ipv4/inet_connection_sock.c                    |   1 +
 net/ipv4/ip_vti.c                                  |   3 +
 net/ipv4/ipip.c                                    |   3 +
 net/ipv4/netfilter/nf_nat_h323.c                   |  12 +
 net/ipv4/netfilter/nf_nat_pptp.c                   |  14 +-
 net/ipv4/netfilter/nf_nat_snmp_basic_main.c        |  27 +-
 net/ipv4/netfilter/nf_reject_ipv4.c                |   2 +-
 net/ipv4/tcp_bbr.c                                 |   2 +-
 net/ipv4/tcp_ipv4.c                                |   4 +-
 net/ipv4/tcp_output.c                              |   8 +-
 net/ipv4/udp_bpf.c                                 |   9 +
 net/ipv4/udp_tunnel_core.c                         |  10 +-
 net/ipv4/udp_tunnel_nic.c                          |   2 +-
 net/ipv4/xfrm4_input.c                             |   2 -
 net/ipv6/addrconf.c                                |  55 +-
 net/ipv6/ioam6_iptunnel.c                          |   8 +-
 net/ipv6/ip6_fib.c                                 |  17 +-
 net/ipv6/ip6_gre.c                                 |   6 +
 net/ipv6/ip6_tunnel.c                              |  10 +
 net/ipv6/ip6_vti.c                                 |   3 +
 net/ipv6/mcast.c                                   |  40 +-
 net/ipv6/ndisc.c                                   |   8 +-
 net/ipv6/netfilter.c                               |   4 +-
 net/ipv6/netfilter/ip6t_ah.c                       |   5 +
 net/ipv6/netfilter/ip6t_hbh.c                      |   1 +
 net/ipv6/netfilter/ip6t_rt.c                       |   3 +-
 net/ipv6/netfilter/nf_conntrack_reasm.c            |   3 +-
 net/ipv6/route.c                                   |   9 +-
 net/ipv6/seg6.c                                    |   3 +
 net/ipv6/sit.c                                     |   3 +
 net/ipv6/xfrm6_input.c                             |   2 -
 net/kcm/kcmsock.c                                  |   8 +-
 net/l2tp/l2tp_core.c                               |   2 +-
 net/llc/af_llc.c                                   |   1 +
 net/llc/llc_conn.c                                 |   1 -
 net/mac80211/main.c                                |   3 +-
 net/mac80211/rx.c                                  |  34 +-
 net/mac80211/tx.c                                  |  17 +-
 net/mac80211/util.c                                |   3 +
 net/mac802154/iface.c                              |   2 +-
 net/mac802154/scan.c                               |   1 +
 net/netfilter/ipset/ip_set_bitmap_gen.h            |   4 +-
 net/netfilter/ipset/ip_set_bitmap_ip.c             |   2 +-
 net/netfilter/ipset/ip_set_bitmap_ipmac.c          |   2 +-
 net/netfilter/ipset/ip_set_bitmap_port.c           |   2 +-
 net/netfilter/ipset/ip_set_core.c                  |   4 +-
 net/netfilter/ipset/ip_set_hash_gen.h              |  12 +-
 net/netfilter/ipvs/ip_vs_app.c                     |  10 +-
 net/netfilter/ipvs/ip_vs_conn.c                    |   4 +-
 net/netfilter/ipvs/ip_vs_core.c                    |  36 +-
 net/netfilter/ipvs/ip_vs_proto_sctp.c              |  18 +-
 net/netfilter/ipvs/ip_vs_proto_tcp.c               |  11 +-
 net/netfilter/ipvs/ip_vs_proto_udp.c               |   3 +-
 net/netfilter/ipvs/ip_vs_xmit.c                    |   6 +-
 net/netfilter/nf_conncount.c                       |  23 +-
 net/netfilter/nf_conntrack_amanda.c                |  39 +-
 net/netfilter/nf_conntrack_bpf.c                   |  35 +-
 net/netfilter/nf_conntrack_broadcast.c             |   4 +
 net/netfilter/nf_conntrack_core.c                  | 122 ++--
 net/netfilter/nf_conntrack_ecache.c                |   2 +-
 net/netfilter/nf_conntrack_expect.c                | 184 +++---
 net/netfilter/nf_conntrack_extend.c                |  32 +-
 net/netfilter/nf_conntrack_ftp.c                   |  11 +-
 net/netfilter/nf_conntrack_h323_main.c             | 129 ++--
 net/netfilter/nf_conntrack_helper.c                |  94 ++-
 net/netfilter/nf_conntrack_irc.c                   |  11 +-
 net/netfilter/nf_conntrack_netbios_ns.c            |  20 +-
 net/netfilter/nf_conntrack_netlink.c               |  32 +-
 net/netfilter/nf_conntrack_pptp.c                  |  92 +--
 net/netfilter/nf_conntrack_proto_gre.c             |  70 ++
 net/netfilter/nf_conntrack_sane.c                  |   8 +-
 net/netfilter/nf_conntrack_seqadj.c                |  19 +-
 net/netfilter/nf_conntrack_sip.c                   |  66 +-
 net/netfilter/nf_conntrack_snmp.c                  |  21 +-
 net/netfilter/nf_conntrack_tftp.c                  |   5 +-
 net/netfilter/nf_conntrack_timeout.c               |  27 +-
 net/netfilter/nf_dup_netdev.c                      |  15 +-
 net/netfilter/nf_flow_table_core.c                 |  12 +-
 net/netfilter/nf_flow_table_ip.c                   | 107 +---
 net/netfilter/nf_flow_table_path.c                 |   7 +-
 net/netfilter/nf_nat_core.c                        |  10 +
 net/netfilter/nf_nat_sip.c                         |  23 +
 net/netfilter/nf_queue.c                           |  14 +
 net/netfilter/nf_synproxy_core.c                   |  40 +-
 net/netfilter/nf_tables_api.c                      |   3 +
 net/netfilter/nfnetlink_cthelper.c                 |  81 ++-
 net/netfilter/nfnetlink_cttimeout.c                | 112 ++--
 net/netfilter/nfnetlink_osf.c                      |   6 +-
 net/netfilter/nfnetlink_queue.c                    |   3 +
 net/netfilter/nft_compat.c                         |  24 +-
 net/netfilter/nft_ct.c                             |  29 +-
 net/netfilter/nft_fib.c                            |   9 +
 net/netfilter/nft_fib_netdev.c                     |  29 +-
 net/netfilter/nft_fwd_netdev.c                     |  17 +-
 net/netfilter/nft_lookup.c                         |  10 +-
 net/netfilter/nft_meta.c                           |   5 +-
 net/netfilter/nft_payload.c                        |  16 +-
 net/netfilter/nft_set_pipapo.c                     |  34 +-
 net/netfilter/nft_set_pipapo.h                     |   8 +
 net/netfilter/nft_set_rbtree.c                     |   8 +-
 net/netfilter/nft_synproxy.c                       |   9 +-
 net/netfilter/xt_CT.c                              |   2 +-
 net/netfilter/xt_cluster.c                         |   2 +-
 net/netfilter/xt_connmark.c                        |  14 +-
 net/netfilter/xt_nat.c                             |   9 +
 net/netfilter/xt_physdev.c                         |   5 -
 net/netfilter/xt_rateest.c                         |   2 +-
 net/netfilter/xt_u32.c                             |  12 +-
 net/openvswitch/conntrack.c                        |   2 +-
 net/openvswitch/flow_netlink.c                     | 201 ++++--
 net/psample/psample.c                              |   6 +-
 net/qrtr/af_qrtr.c                                 |   2 +-
 net/rxrpc/ar-internal.h                            |   6 +-
 net/rxrpc/call_accept.c                            |  25 +-
 net/rxrpc/call_event.c                             |   5 +-
 net/rxrpc/call_object.c                            |   2 +
 net/rxrpc/conn_client.c                            |   2 +-
 net/rxrpc/conn_event.c                             |   9 +-
 net/rxrpc/input.c                                  |  39 +-
 net/rxrpc/local_object.c                           |   2 +-
 net/rxrpc/oob.c                                    |  12 +-
 net/rxrpc/recvmsg.c                                |  23 +-
 net/rxrpc/rxgk.c                                   |   3 +-
 net/rxrpc/sendmsg.c                                |   3 +-
 net/sched/act_api.c                                |  13 +-
 net/sched/act_bpf.c                                |   2 +-
 net/sched/act_ct.c                                 |  13 +-
 net/sched/act_pedit.c                              |  13 +-
 net/sched/cls_api.c                                |  25 +-
 net/sched/cls_bpf.c                                |  10 +-
 net/sched/cls_flow.c                               |  12 +-
 net/sched/sch_api.c                                |   2 +-
 net/sched/sch_cake.c                               |  13 +-
 net/sched/sch_cbs.c                                |   4 +-
 net/sched/sch_choke.c                              |   8 +-
 net/sched/sch_codel.c                              |  48 +-
 net/sched/sch_drr.c                                |  12 +-
 net/sched/sch_dualpi2.c                            | 122 ++--
 net/sched/sch_etf.c                                |   8 +-
 net/sched/sch_ets.c                                |   4 +-
 net/sched/sch_fq.c                                 |   6 +-
 net/sched/sch_fq_codel.c                           |  48 +-
 net/sched/sch_fq_pie.c                             |   4 +-
 net/sched/sch_generic.c                            |  51 +-
 net/sched/sch_hfsc.c                               |  28 +-
 net/sched/sch_hhf.c                                |  34 +-
 net/sched/sch_htb.c                                |  18 +-
 net/sched/sch_mq.c                                 |   5 +-
 net/sched/sch_mqprio.c                             |  18 +-
 net/sched/sch_multiq.c                             |   6 +-
 net/sched/sch_netem.c                              |  10 +-
 net/sched/sch_prio.c                               |   4 +-
 net/sched/sch_qfq.c                                |   6 +-
 net/sched/sch_red.c                                |   4 +-
 net/sched/sch_sfb.c                                |   4 +-
 net/sched/sch_sfq.c                                |   9 +-
 net/sched/sch_skbprio.c                            |   4 +-
 net/sched/sch_taprio.c                             |   6 +-
 net/sched/sch_tbf.c                                |   6 +-
 net/sched/sch_teql.c                               | 128 ++--
 net/sctp/diag.c                                    |  67 +-
 net/sctp/protocol.c                                |  13 +-
 net/sctp/sm_make_chunk.c                           |  15 +-
 net/sctp/sm_statefuns.c                            |  64 +-
 net/sctp/socket.c                                  |  38 +-
 net/smc/smc_cdc.c                                  |  15 +-
 net/socket.c                                       |  30 +-
 net/sunrpc/clnt.c                                  |  19 +-
 net/sunrpc/svc.c                                   |  10 +
 net/sunrpc/svcsock.c                               |  10 +
 net/sunrpc/sysfs.c                                 |   4 +-
 net/sunrpc/xdr.c                                   |  14 +-
 net/sunrpc/xprtrdma/backchannel.c                  |   5 +-
 net/sunrpc/xprtrdma/frwr_ops.c                     |   2 +-
 net/sunrpc/xprtrdma/rpc_rdma.c                     | 157 +++--
 net/sunrpc/xprtrdma/transport.c                    |  68 +-
 net/sunrpc/xprtrdma/verbs.c                        | 126 +++-
 net/sunrpc/xprtrdma/xprt_rdma.h                    |   4 +-
 net/sunrpc/xprtsock.c                              |  16 +-
 net/tipc/bearer.c                                  |   1 +
 net/tipc/core.c                                    |   9 +-
 net/tipc/discover.c                                |  14 +-
 net/tipc/name_distr.c                              |  13 +-
 net/tipc/netlink.c                                 |  12 +
 net/tipc/socket.c                                  |   9 +-
 net/tipc/udp_media.c                               |  53 +-
 net/tls/tls_sw.c                                   |  11 +
 net/wireless/nl80211.c                             |   2 +-
 net/wireless/pmsr.c                                |   4 +-
 net/wireless/scan.c                                |   5 +-
 net/xfrm/espintcp.c                                |  34 +-
 net/xfrm/xfrm_input.c                              |  29 +-
 net/xfrm/xfrm_interface_core.c                     |   3 +
 net/xfrm/xfrm_nat_keepalive.c                      |  15 +-
 net/xfrm/xfrm_policy.c                             |  27 +-
 net/xfrm/xfrm_state.c                              |  26 +-
 net/xfrm/xfrm_user.c                               |  20 +-
 rust/Makefile                                      |   2 +-
 rust/helpers/uaccess.c                             |   2 +-
 rust/kernel/alloc/kvec.rs                          |   4 +-
 rust/kernel/devres.rs                              |   6 +-
 samples/damon/mtier.c                              |   3 +
 samples/trace_events/trace-events-sample.c         |   4 +
 scripts/kconfig/conf.c                             |   6 +-
 scripts/livepatch/klp-build                        |  41 +-
 security/apparmor/af_unix.c                        |  65 +-
 security/apparmor/apparmorfs.c                     | 113 +++-
 security/apparmor/domain.c                         |  58 +-
 security/apparmor/file.c                           |  12 +-
 security/apparmor/include/apparmorfs.h             |  12 +
 security/apparmor/label.c                          |   2 +-
 security/apparmor/lsm.c                            |   2 +-
 security/apparmor/net.c                            |   1 +
 security/apparmor/policy.c                         |  20 +-
 security/apparmor/policy_unpack.c                  |   6 +-
 security/apparmor/procattr.c                       |   2 +
 security/apparmor/task.c                           |   2 +-
 security/integrity/evm/evm_secfs.c                 |  16 +-
 security/integrity/ima/ima_appraise.c              |   5 +-
 security/integrity/ima/ima_policy.c                |   3 +-
 security/keys/keyring.c                            |   2 +-
 security/landlock/fs.c                             |  14 +
 security/landlock/fs.h                             |  10 +
 security/landlock/net.c                            |  11 +-
 security/landlock/task.c                           |  11 +
 security/selinux/hooks.c                           |  80 ++-
 sound/core/init.c                                  |  11 +-
 sound/core/pcm_compat.c                            |   4 +-
 sound/core/pcm_native.c                            |   7 +-
 sound/core/seq/oss/seq_oss_event.c                 |   6 +-
 sound/core/seq/oss/seq_oss_event.h                 |   3 +-
 sound/core/seq/oss/seq_oss_ioctl.c                 |   5 +-
 sound/core/seq/oss/seq_oss_midi.c                  |   6 +-
 sound/core/seq/oss/seq_oss_midi.h                  |   2 +-
 sound/core/seq/oss/seq_oss_readq.c                 |  77 ++-
 sound/core/seq/oss/seq_oss_rw.c                    |   5 +-
 sound/core/seq/seq_clientmgr.c                     |  33 +-
 sound/core/seq/seq_fifo.c                          |  52 +-
 sound/core/seq/seq_memory.c                        |   2 +-
 sound/core/seq/seq_midi.c                          |  55 +-
 sound/drivers/aloop.c                              |   1 -
 sound/hda/codecs/conexant.c                        |   3 -
 sound/hda/codecs/realtek/alc269.c                  |  12 +-
 sound/hda/codecs/side-codecs/tas2781_hda_i2c.c     |   3 +
 sound/hda/codecs/side-codecs/tas2781_hda_spi.c     |   3 +
 sound/hda/controllers/Kconfig                      |   2 +-
 sound/hda/core/regmap.c                            |   4 +-
 sound/soc/amd/acp/acp-sdw-legacy-mach.c            |   7 +-
 sound/soc/amd/acp/acp-sdw-sof-mach.c               |   7 +-
 sound/soc/codecs/adau1372.c                        |   5 +
 sound/soc/codecs/aw88261.c                         |  12 +-
 sound/soc/codecs/cs35l56-shared.c                  |   4 +-
 sound/soc/codecs/cs35l56.c                         |  27 +-
 sound/soc/codecs/cs530x.c                          |  29 +-
 sound/soc/codecs/cs530x.h                          |   6 -
 sound/soc/codecs/hdac_hdmi.c                       |   4 +-
 sound/soc/codecs/lpass-va-macro.c                  |   7 +-
 sound/soc/codecs/rt5575-spi.c                      |   2 +-
 sound/soc/codecs/sma1307.c                         |  35 +-
 sound/soc/codecs/tlv320aic3x.c                     |  25 +-
 sound/soc/codecs/wm_adsp.c                         |   7 +
 sound/soc/fsl/fsl_asrc_dma.c                       |  20 +
 sound/soc/fsl/fsl_audmix.c                         |   6 +
 sound/soc/mediatek/mt8183/mt8183-afe-pcm.c         |  23 +-
 sound/soc/mediatek/mt8189/mt8189-afe-pcm.c         |  38 +-
 sound/soc/mediatek/mt8192/mt8192-afe-pcm.c         |  21 +-
 sound/soc/meson/aiu-acodec-ctrl.c                  |   3 +
 sound/soc/meson/aiu-codec-ctrl.c                   |   3 +
 sound/soc/qcom/qdsp6/q6apm.c                       |   8 +
 sound/soc/renesas/rcar/rsnd.h                      |   2 +-
 sound/soc/sdca/sdca_asoc.c                         |   3 +
 sound/soc/sdw_utils/soc_sdw_utils.c                |   1 +
 sound/soc/soc-dapm.c                               |  49 +-
 sound/soc/soc-topology.c                           |  37 +-
 sound/soc/sof/intel/Kconfig                        |   6 +-
 sound/soc/sof/ipc3-control.c                       |  79 ++-
 sound/soc/sof/ipc4-control.c                       |  34 +-
 sound/soc/sof/topology.c                           |   7 +-
 sound/soc/tegra/tegra210_ahub.c                    |   4 +-
 sound/usb/fcp.c                                    |   2 +
 sound/usb/midi2.c                                  |   5 +
 sound/usb/mixer_scarlett2.c                        | 201 +++++-
 sound/usb/qcom/mixer_usb_offload.c                 |   2 +-
 sound/usb/qcom/qc_audio_offload.c                  |  30 +-
 sound/xen/xen_snd_front_alsa.c                     |  17 +-
 sound/xen/xen_snd_front_evtchnl.c                  |  28 +-
 sound/xen/xen_snd_front_evtchnl.h                  |   6 +-
 tools/bpf/bpftool/cgroup.c                         |  14 +-
 tools/bpf/bpftool/gen.c                            |   2 +-
 tools/bpf/bpftool/net.c                            |   4 +-
 tools/include/nolibc/getopt.h                      |   2 +-
 tools/include/nolibc/stackprotector.h              |   3 +-
 tools/include/uapi/linux/bpf.h                     |   2 +
 tools/include/uapi/linux/if_link.h                 |   2 +
 tools/lib/api/fs/fs.c                              |  19 +-
 tools/lib/bpf/btf.c                                |   4 +-
 tools/lib/bpf/gen_loader.c                         |  81 ++-
 tools/lib/bpf/libbpf.c                             |   9 +-
 tools/lib/bpf/strset.c                             |  62 +-
 tools/lib/bpf/usdt.c                               |  16 +-
 tools/lib/symbol/kallsyms.c                        |   5 +-
 tools/net/ynl/Makefile                             |   2 +-
 tools/net/ynl/generated/Makefile                   |   2 +-
 tools/net/ynl/lib/Makefile                         |   2 +-
 tools/objtool/elf.c                                |  75 +--
 tools/objtool/include/objtool/elf.h                |  32 +-
 tools/objtool/klp-diff.c                           | 133 ++--
 tools/perf/Makefile.config                         |   1 +
 tools/perf/arch/common.c                           |   4 +-
 tools/perf/arch/powerpc/util/auxtrace.c            |   6 +
 tools/perf/arch/x86/tests/amd-ibs-period.c         |   2 +-
 tools/perf/bench/inject-buildid.c                  |   9 +-
 tools/perf/builtin-annotate.c                      |   3 +-
 tools/perf/builtin-buildid-list.c                  |   4 +-
 tools/perf/builtin-c2c.c                           |  28 +-
 tools/perf/builtin-diff.c                          |   3 +-
 tools/perf/builtin-inject.c                        | 172 ++++-
 tools/perf/builtin-record.c                        |   2 +
 tools/perf/builtin-report.c                        |   7 +-
 tools/perf/builtin-sched.c                         | 177 +++--
 tools/perf/builtin-script.c                        |   6 +-
 tools/perf/builtin-stat.c                          |  50 +-
 tools/perf/pmu-events/amd_metrics.py               |   2 +-
 tools/perf/pmu-events/metric.py                    |   1 -
 tools/perf/tests/code-reading.c                    |   7 +-
 tools/perf/tests/dlfilter-test.c                   |   8 +-
 tools/perf/tests/pmu-events.c                      |  24 +-
 tools/perf/tests/sample-parsing.c                  |   5 +-
 tools/perf/ui/browser.c                            |   3 +
 tools/perf/ui/browsers/annotate.c                  |   5 +-
 tools/perf/util/Build                              |   1 +
 tools/perf/util/annotate-data.c                    |  27 +-
 tools/perf/util/arm-spe.c                          |  28 +-
 tools/perf/util/auxtrace.c                         |   3 +-
 tools/perf/util/bpf-event.c                        |  52 +-
 tools/perf/util/bpf-event.h                        |   4 +-
 tools/perf/util/bpf-utils.c                        |  16 +
 tools/perf/util/build-id.c                         |   7 +-
 tools/perf/util/callchain.c                        |  15 +
 tools/perf/util/callchain.h                        |   1 +
 tools/perf/util/config.c                           |   4 +
 tools/perf/util/cpumap.c                           |  49 +-
 tools/perf/util/cs-etm-base.c                      |   4 +-
 tools/perf/util/cs-etm-decoder/cs-etm-decoder.c    |  21 +-
 tools/perf/util/cs-etm.c                           | 310 ++++++---
 tools/perf/util/cs-etm.h                           |   8 +-
 tools/perf/util/data-convert-json.c                |   1 +
 tools/perf/util/debuginfo.c                        |   9 +-
 tools/perf/util/disasm.c                           |   7 +-
 tools/perf/util/dso.c                              |  48 +-
 tools/perf/util/dwarf-aux.c                        |  39 +-
 tools/perf/util/dwarf-aux.h                        |   5 +
 tools/perf/util/env.h                              |  14 +
 tools/perf/util/event.c                            |  15 +-
 tools/perf/util/header.c                           |  91 ++-
 tools/perf/util/hist.c                             |   9 +-
 tools/perf/util/hist.h                             |   1 +
 tools/perf/util/hwmon_pmu.c                        |  36 +-
 tools/perf/util/intel-bts.c                        |   3 +-
 .../util/intel-pt-decoder/intel-pt-insn-decoder.c  |  11 +-
 tools/perf/util/intel-pt.c                         |  35 +-
 tools/perf/util/libdw.c                            |  49 +-
 tools/perf/util/machine.c                          |  42 +-
 tools/perf/util/maps.c                             | 156 ++++-
 tools/perf/util/maps.h                             |   3 +
 tools/perf/util/mmap.c                             |  20 +-
 tools/perf/util/pmu.c                              |  10 +-
 tools/perf/util/probe-finder.c                     | 102 +--
 tools/perf/util/svghelper.c                        |  10 +-
 tools/perf/util/symbol-elf.c                       | 121 ++--
 tools/perf/util/symbol-minimal.c                   |  16 +-
 tools/perf/util/symbol.c                           |  19 +-
 tools/perf/util/symbol_conf.h                      |  10 +
 tools/perf/util/synthetic-events.c                 |  25 +-
 tools/perf/util/synthetic-events.h                 |   6 +-
 tools/perf/util/thread.c                           |   5 +
 tools/perf/util/tool.c                             |   6 +
 tools/perf/util/unwind-libdw.c                     |  20 +-
 tools/perf/util/unwind-libunwind-local.c           |  27 +-
 tools/perf/util/unwind-libunwind.c                 |   2 +-
 tools/perf/util/unwind.c                           | 104 +++
 tools/perf/util/unwind.h                           |  65 +-
 tools/power/x86/intel-speed-select/isst-daemon.c   |   9 +-
 tools/testing/cxl/test/cxl.c                       |  10 +-
 tools/testing/cxl/test/cxl_translate.c             |   2 +-
 tools/testing/cxl/test/mem.c                       |  45 +-
 tools/testing/kunit/kunit_parser.py                |  12 +-
 tools/testing/selftests/Makefile                   |   2 +-
 tools/testing/selftests/bpf/README.rst             |   2 +-
 .../selftests/bpf/prog_tests/bpf_attr_size.c       |  69 ++
 tools/testing/selftests/bpf/prog_tests/bpf_nf.c    |   6 +
 .../selftests/bpf/prog_tests/fill_link_info.c      |   2 +-
 .../testing/selftests/bpf/prog_tests/htab_update.c |   4 +-
 .../testing/selftests/bpf/prog_tests/linked_list.c |  33 +-
 tools/testing/selftests/bpf/prog_tests/map_kptr.c  |  10 +-
 .../prog_tests/raw_tp_writable_reject_bad_access.c |  57 ++
 .../raw_tp_writable_reject_nbd_invalid.c           |  43 --
 .../selftests/bpf/prog_tests/refcounted_kptr.c     |   8 +-
 tools/testing/selftests/bpf/prog_tests/verifier.c  |   2 +
 .../selftests/bpf/prog_tests/verifier_log.c        |   1 +
 .../selftests/bpf/progs/bpf_iter_task_vmas.c       |   2 +-
 .../testing/selftests/bpf/progs/cpumask_success.c  |   2 +-
 tools/testing/selftests/bpf/progs/file_reader.c    |   2 +-
 tools/testing/selftests/bpf/progs/htab_update.c    |   4 +-
 tools/testing/selftests/bpf/progs/linked_list.c    |  71 +++
 .../testing/selftests/bpf/progs/refcounted_kptr.c  |  20 +-
 tools/testing/selftests/bpf/progs/test_bpf_nf.c    |  26 +
 .../testing/selftests/bpf/progs/test_tunnel_kern.c |  13 +-
 .../testing/selftests/bpf/progs/verifier_bounds.c  |  14 +-
 .../selftests/bpf/progs/verifier_ptr_to_buf.c      |  27 +
 .../selftests/bpf/progs/verifier_raw_tp_writable.c |  16 +
 tools/testing/selftests/bpf/progs/xdp_flowtable.c  |   7 +-
 tools/testing/selftests/bpf/vmtest.sh              |   2 +-
 tools/testing/selftests/drivers/net/hw/tso.py      |  16 +-
 .../ftrace/test.d/00basic/test_ownership.tc        |   2 +-
 .../ftrace/test.d/00basic/trace_marker_raw.tc      |  14 +-
 tools/testing/selftests/gpio/.gitignore            |   1 +
 tools/testing/selftests/hid/Makefile               |   2 +-
 tools/testing/selftests/hid/hid_bpf.c              |  36 +-
 tools/testing/selftests/hid/progs/hid.c            |  15 +
 .../selftests/landlock/scoped_signal_test.c        | 237 ++++++-
 .../selftests/mm/charge_reserved_hugetlb.sh        |  45 +-
 tools/testing/selftests/mm/compaction_test.c       |   3 +
 tools/testing/selftests/mm/hmm-tests.c             | 125 +++-
 tools/testing/selftests/mm/hugepage-mremap.c       |  32 +-
 .../selftests/mm/hugetlb_reparenting_test.sh       |  60 +-
 tools/testing/selftests/mm/pkey-arm64.h            |   3 +-
 tools/testing/selftests/mm/run_vmtests.sh          |  66 +-
 tools/testing/selftests/mm/split_huge_page_test.c  |  27 +-
 tools/testing/selftests/mm/uffd-stress.c           |   5 +-
 tools/testing/selftests/net/broadcast_ether_dst.sh |   2 +-
 tools/testing/selftests/net/lib.sh                 |  25 +-
 .../selftests/net/netfilter/nft_flowtable.sh       |   8 +-
 tools/testing/selftests/net/tcp_mmap.c             |   4 +
 tools/testing/selftests/net/tls.c                  |   8 +-
 tools/testing/selftests/net/vlan_bridge_binding.sh |   2 +-
 tools/testing/selftests/rseq/Makefile              |   6 +-
 tools/testing/selftests/vfio/Makefile              |   7 +-
 tools/testing/selftests/vfio/lib/libvfio.mk        |   6 +-
 tools/tracing/rtla/src/actions.c                   |   2 +
 tools/tracing/rtla/src/common.c                    |  19 +-
 tools/tracing/rtla/src/common.h                    |   1 -
 tools/tracing/rtla/src/timerlat.c                  |   2 +-
 tools/tracing/rtla/src/timerlat_hist.c             |   4 +-
 tools/tracing/rtla/src/timerlat_top.c              |   3 +-
 tools/virtio/vringh_test.c                         |   5 +
 virt/kvm/kvm_main.c                                |  16 +-
 1929 files changed, 28193 insertions(+), 14617 deletions(-)



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0001/2077] crypto: algif_skcipher - force synchronous processing
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0002/2077] iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry Greg Kroah-Hartman
                   ` (996 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Muhammet Kaan KILINÇ,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Muhammet Kaan KILINÇ <muhammetkaankilinc@gmail.com>

The AIO/async path in skcipher_recvmsg() passes the socket-wide ctx->iv
directly into the skcipher request. After io_submit() the socket lock is
dropped and the request is processed asynchronously by a worker (e.g.
cryptd), which dereferences ctx->iv only later.

A concurrent sendmsg(ALG_SET_IV) on the same socket can overwrite ctx->iv
inside this window, so the in-flight request runs under an
attacker-controlled IV. For CTR and other stream modes this causes
IV/keystream reuse and allows an unprivileged user to recover the
plaintext of a concurrent operation.

Snapshotting ctx->iv into per-request storage for the async path is not
sufficient here. For ciphers with statesize == 0 - which includes cbc
and ctr - skcipher_prepare_alg() installs skcipher_noimport()/
skcipher_noexport(), so ctx->state carries nothing and the MSG_MORE
inter-chunk IV chaining is carried solely by the in-place req->iv
writeback. A snapshot redirects that writeback into per-request memory
that af_alg_free_resources() releases on completion, so AIO + MSG_MORE
with cbc/ctr would silently produce wrong output. Writing the IV back
from the completion callback instead is not possible either: that would
require lock_sock() there, but the callback can run in softirq/atomic
context, so it must not sleep.

Make the operation synchronous instead. ctx->iv is then only ever
dereferenced under the socket lock held by recvmsg(), which removes the
race, and the req->iv writeback lands in ctx->iv as before, which keeps
MSG_MORE chaining intact for statesize == 0 ciphers. The ctx->state
import/export path is unchanged for ciphers that do have state.

This is equivalent to the upstream resolution: commit fcc77d33a34c
("net: Remove support for AIO on sockets") removed the AIO socket path
across net/ entirely, producing the same end state for this file -
algif_skcipher never processes an AIO request asynchronously. After this
patch, _skcipher_recvmsg() matches mainline's crypto/algif_skcipher.c as
it stands today, including the same now-dead -EIOCBQUEUED check. This
patch deviates from that commit deliberately: rather than removing AIO
socket support tree-wide, which would be far too invasive for stable, it
removes only the AIO branch in crypto/algif_skcipher.c. io_submit() now
completes synchronously, which is valid for the AIO interface; AF_ALG
async is rarely used in practice.

The -EIOCBQUEUED check in skcipher_recvmsg() is now dead but harmless,
and is left alone to keep the fix minimal.

Fixes: e870456d8e7c ("crypto: algif_skcipher - overhaul memory management")
Cc: <stable@vger.kernel.org>
Reported-by: Muhammet Kaan KILINÇ <muhammetkaankilinc@gmail.com>
Signed-off-by: Muhammet Kaan KILINÇ <muhammetkaankilinc@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 crypto/algif_skcipher.c | 75 +++++++++++++----------------------------
 1 file changed, 24 insertions(+), 51 deletions(-)

diff --git a/crypto/algif_skcipher.c b/crypto/algif_skcipher.c
index ba0a17fd95aca2..35ebc3e0201b04 100644
--- a/crypto/algif_skcipher.c
+++ b/crypto/algif_skcipher.c
@@ -79,20 +79,6 @@ static int algif_skcipher_export(struct sock *sk, struct skcipher_request *req)
 	return err;
 }
 
-static void algif_skcipher_done(void *data, int err)
-{
-	struct af_alg_async_req *areq = data;
-	struct sock *sk = areq->sk;
-
-	if (err)
-		goto out;
-
-	err = algif_skcipher_export(sk, &areq->cra_u.skcipher_req);
-
-out:
-	af_alg_async_cb(data, err);
-}
-
 static int _skcipher_recvmsg(struct socket *sock, struct msghdr *msg,
 			     size_t ignored, int flags)
 {
@@ -171,43 +157,30 @@ static int _skcipher_recvmsg(struct socket *sock, struct msghdr *msg,
 		cflags |= CRYPTO_SKCIPHER_REQ_CONT;
 	}
 
-	if (msg->msg_iocb && !is_sync_kiocb(msg->msg_iocb)) {
-		/* AIO operation */
-		sock_hold(sk);
-		areq->iocb = msg->msg_iocb;
-
-		/* Remember output size that will be generated. */
-		areq->outlen = len;
-
-		skcipher_request_set_callback(&areq->cra_u.skcipher_req,
-					      cflags |
-					      CRYPTO_TFM_REQ_MAY_SLEEP,
-					      algif_skcipher_done, areq);
-		err = ctx->enc ?
-			crypto_skcipher_encrypt(&areq->cra_u.skcipher_req) :
-			crypto_skcipher_decrypt(&areq->cra_u.skcipher_req);
-
-		/* AIO operation in progress */
-		if (err == -EINPROGRESS)
-			return -EIOCBQUEUED;
-
-		sock_put(sk);
-	} else {
-		/* Synchronous operation */
-		skcipher_request_set_callback(&areq->cra_u.skcipher_req,
-					      cflags |
-					      CRYPTO_TFM_REQ_MAY_SLEEP |
-					      CRYPTO_TFM_REQ_MAY_BACKLOG,
-					      crypto_req_done, &ctx->wait);
-		err = crypto_wait_req(ctx->enc ?
-			crypto_skcipher_encrypt(&areq->cra_u.skcipher_req) :
-			crypto_skcipher_decrypt(&areq->cra_u.skcipher_req),
-						 &ctx->wait);
-
-		if (!err)
-			err = algif_skcipher_export(
-				sk, &areq->cra_u.skcipher_req);
-	}
+	/*
+	 * Force synchronous processing.  The async (AIO) path passed the
+	 * socket-wide ctx->iv into the request, which the worker
+	 * dereferenced after the socket lock had been dropped, letting a
+	 * concurrent sendmsg(ALG_SET_IV) inject an attacker IV.  Mainline
+	 * removed the AIO socket path in commit fcc77d33a34c ("net: Remove
+	 * support for AIO on sockets"); the minimal stable fix is to always
+	 * complete synchronously, so ctx->iv is only ever dereferenced under
+	 * the socket lock.  This also keeps the IV chaining intact: for
+	 * ciphers with statesize == 0 (e.g. ctr, cbc) the chained IV is
+	 * carried by the req->iv writeback into ctx->iv, which is only
+	 * consistent on the synchronous path.
+	 */
+	skcipher_request_set_callback(&areq->cra_u.skcipher_req,
+				      cflags |
+				      CRYPTO_TFM_REQ_MAY_SLEEP |
+				      CRYPTO_TFM_REQ_MAY_BACKLOG,
+				      crypto_req_done, &ctx->wait);
+	err = crypto_wait_req(ctx->enc ?
+		crypto_skcipher_encrypt(&areq->cra_u.skcipher_req) :
+		crypto_skcipher_decrypt(&areq->cra_u.skcipher_req),
+				 &ctx->wait);
+	if (!err)
+		err = algif_skcipher_export(sk, &areq->cra_u.skcipher_req);
 
 free:
 	af_alg_free_resources(areq);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0002/2077] iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0001/2077] crypto: algif_skcipher - force synchronous processing Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0003/2077] crypto: sun4i-ss - Remove insecure and unused rng_alg Greg Kroah-Hartman
                   ` (995 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Lu Baolu,
	Joerg Roedel, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Bommarito <michael.bommarito@gmail.com>

[ Upstream commit f46452c3df7a8d8a5addc0926e76ef19ea7da0a0 ]

device_pasid_table_teardown() zeroes the 128-bit scalable-mode context
entry with context_clear_entry() while the Present bit is still set. This
creates a window where the hardware can fetch a torn entry, with some
fields already zeroed while Present is still set, leading to unpredictable
behavior or spurious faults. The context-cache invalidation is issued only
after the entry has been zeroed, and intel_pasid_free_table() then frees
the PASID directory pages, so the IOMMU can keep walking a stale Present=1
entry that points at freed memory.

While x86 provides strong write ordering, the compiler may reorder the two
64-bit writes to the entry, and the hardware fetch is not guaranteed to be
atomic with respect to multiple CPU writes.

Commit c1e4f1dccbe9d ("iommu/vt-d: Clear Present bit before tearing down
context entry") fixed this exact pattern in domain_context_clear_one() and
the copied-context path, but device_pasid_table_teardown() was not
converted.

Align it with the "Guidance to Software for Invalidations" in the VT-d
spec, Section 6.5.3.3, using the same ownership handshake as the sibling
fix: clear only the Present bit, flush it to the IOMMU, perform the
context-cache invalidation, and only then zero the rest of the entry.

Fixes: 81e921fd32161 ("iommu/vt-d: Fix NULL domain on device release")
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Assisted-by: Claude:claude-opus-4-7
Link: https://lore.kernel.org/r/20260528025557.3209367-1-michael.bommarito@gmail.com
Signed-off-by: Lu Baolu <baolu.lu@linux.intel.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iommu/intel/pasid.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/drivers/iommu/intel/pasid.c
+++ b/drivers/iommu/intel/pasid.c
@@ -748,10 +748,12 @@ static void device_pasid_table_teardown(
 	}
 
 	did = context_domain_id(context);
-	context_clear_entry(context);
+	context_clear_present(context);
 	__iommu_flush_cache(iommu, context, sizeof(*context));
 	spin_unlock(&iommu->lock);
 	intel_context_flush_no_pasid(info, context, did);
+	context_clear_entry(context);
+	__iommu_flush_cache(iommu, context, sizeof(*context));
 }
 
 static int pci_pasid_table_teardown(struct pci_dev *pdev, u16 alias, void *data)



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0003/2077] crypto: sun4i-ss - Remove insecure and unused rng_alg
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0001/2077] crypto: algif_skcipher - force synchronous processing Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0002/2077] iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0004/2077] media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work Greg Kroah-Hartman
                   ` (994 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tianchu Chen, Corentin LABBE,
	Eric Biggers, Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Biggers <ebiggers@kernel.org>

commit b2c41fa9dd8fc740c489e060b199165771f268d1 upstream.

Remove sun4i_ss_rng, as it is insecure and unused:

- It has multiple vulnerabilities.  sun4i_ss_prng_seed() is missing
  locking and has a buffer overflow.  sun4i_ss_prng_generate() fails to
  fill the entire buffer with cryptographic random bytes, because it
  rounds the destination length down and also doesn't actually wait for
  the hardware to be ready before pulling bytes from it.

- No user of this code is known.  It's usable only theoretically via the
  "rng" algorithm type of AF_ALG.  But userspace actually just uses the
  actual Linux RNG (/dev/random etc) instead.  And rng_algs don't
  contribute entropy to the actual Linux RNG either.  (This may have
  been confused with hwrng, which does contribute entropy.)

The sun4i_ss_prng_seed() buffer overflow was reported by Tianchu Chen
and discovered by Atuin - Automated Vulnerability Discovery Engine

There's no point in fixing all these vulnerabilities individually when
this is unused code, so let's just remove it.

Fixes: b8ae5c7387ad ("crypto: sun4i-ss - support the Security System PRNG")
Cc: stable@vger.kernel.org
Reported-by: Tianchu Chen <flynnnchen@tencent.com>
Closes: https://lore.kernel.org/r/af749a8447bd7f0e9dd26ca6c87e9c6afecb09d9@linux.dev/
Acked-by: Corentin LABBE <clabbe.montjoie@gmail.com>
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm/configs/sunxi_defconfig              |  1 -
 drivers/crypto/allwinner/Kconfig              |  8 ---
 drivers/crypto/allwinner/sun4i-ss/Makefile    |  1 -
 .../crypto/allwinner/sun4i-ss/sun4i-ss-core.c | 36 ----------
 .../crypto/allwinner/sun4i-ss/sun4i-ss-prng.c | 69 -------------------
 drivers/crypto/allwinner/sun4i-ss/sun4i-ss.h  | 20 ------
 6 files changed, 135 deletions(-)
 delete mode 100644 drivers/crypto/allwinner/sun4i-ss/sun4i-ss-prng.c

diff --git a/arch/arm/configs/sunxi_defconfig b/arch/arm/configs/sunxi_defconfig
index a83d29fed17563..f4b8d8f7dbefbb 100644
--- a/arch/arm/configs/sunxi_defconfig
+++ b/arch/arm/configs/sunxi_defconfig
@@ -170,7 +170,6 @@ CONFIG_ROOT_NFS=y
 CONFIG_NLS_CODEPAGE_437=y
 CONFIG_NLS_ISO8859_1=y
 CONFIG_CRYPTO_DEV_SUN4I_SS=y
-CONFIG_CRYPTO_DEV_SUN4I_SS_PRNG=y
 CONFIG_CRYPTO_DEV_SUN8I_CE=y
 CONFIG_CRYPTO_DEV_SUN8I_SS=y
 CONFIG_DMA_CMA=y
diff --git a/drivers/crypto/allwinner/Kconfig b/drivers/crypto/allwinner/Kconfig
index 7270e5fbc57387..1048f8e95ba803 100644
--- a/drivers/crypto/allwinner/Kconfig
+++ b/drivers/crypto/allwinner/Kconfig
@@ -25,14 +25,6 @@ config CRYPTO_DEV_SUN4I_SS
 	  To compile this driver as a module, choose M here: the module
 	  will be called sun4i-ss.
 
-config CRYPTO_DEV_SUN4I_SS_PRNG
-	bool "Support for Allwinner Security System PRNG"
-	depends on CRYPTO_DEV_SUN4I_SS
-	select CRYPTO_RNG
-	help
-	  Select this option if you want to provide kernel-side support for
-	  the Pseudo-Random Number Generator found in the Security System.
-
 config CRYPTO_DEV_SUN4I_SS_DEBUG
 	bool "Enable sun4i-ss stats"
 	depends on CRYPTO_DEV_SUN4I_SS
diff --git a/drivers/crypto/allwinner/sun4i-ss/Makefile b/drivers/crypto/allwinner/sun4i-ss/Makefile
index c0a2797d316827..06a9ae81f9f808 100644
--- a/drivers/crypto/allwinner/sun4i-ss/Makefile
+++ b/drivers/crypto/allwinner/sun4i-ss/Makefile
@@ -1,4 +1,3 @@
 # SPDX-License-Identifier: GPL-2.0-only
 obj-$(CONFIG_CRYPTO_DEV_SUN4I_SS) += sun4i-ss.o
 sun4i-ss-y += sun4i-ss-core.o sun4i-ss-hash.o sun4i-ss-cipher.o
-sun4i-ss-$(CONFIG_CRYPTO_DEV_SUN4I_SS_PRNG) += sun4i-ss-prng.o
diff --git a/drivers/crypto/allwinner/sun4i-ss/sun4i-ss-core.c b/drivers/crypto/allwinner/sun4i-ss/sun4i-ss-core.c
index 58a76e2ba64e25..35ef0930e77f1a 100644
--- a/drivers/crypto/allwinner/sun4i-ss/sun4i-ss-core.c
+++ b/drivers/crypto/allwinner/sun4i-ss/sun4i-ss-core.c
@@ -213,23 +213,6 @@ static struct sun4i_ss_alg_template ss_algs[] = {
 		}
 	}
 },
-#ifdef CONFIG_CRYPTO_DEV_SUN4I_SS_PRNG
-{
-	.type = CRYPTO_ALG_TYPE_RNG,
-	.alg.rng = {
-		.base = {
-			.cra_name		= "stdrng",
-			.cra_driver_name	= "sun4i_ss_rng",
-			.cra_priority		= 300,
-			.cra_ctxsize		= 0,
-			.cra_module		= THIS_MODULE,
-		},
-		.generate               = sun4i_ss_prng_generate,
-		.seed                   = sun4i_ss_prng_seed,
-		.seedsize               = SS_SEED_LEN / BITS_PER_BYTE,
-	}
-},
-#endif
 };
 
 static int sun4i_ss_debugfs_show(struct seq_file *seq, void *v)
@@ -247,12 +230,6 @@ static int sun4i_ss_debugfs_show(struct seq_file *seq, void *v)
 				   ss_algs[i].stat_req, ss_algs[i].stat_opti, ss_algs[i].stat_fb,
 				   ss_algs[i].stat_bytes);
 			break;
-		case CRYPTO_ALG_TYPE_RNG:
-			seq_printf(seq, "%s %s reqs=%lu tsize=%lu\n",
-				   ss_algs[i].alg.rng.base.cra_driver_name,
-				   ss_algs[i].alg.rng.base.cra_name,
-				   ss_algs[i].stat_req, ss_algs[i].stat_bytes);
-			break;
 		case CRYPTO_ALG_TYPE_AHASH:
 			seq_printf(seq, "%s %s reqs=%lu\n",
 				   ss_algs[i].alg.hash.halg.base.cra_driver_name,
@@ -471,13 +448,6 @@ static int sun4i_ss_probe(struct platform_device *pdev)
 				goto error_alg;
 			}
 			break;
-		case CRYPTO_ALG_TYPE_RNG:
-			err = crypto_register_rng(&ss_algs[i].alg.rng);
-			if (err) {
-				dev_err(ss->dev, "Fail to register %s\n",
-					ss_algs[i].alg.rng.base.cra_name);
-			}
-			break;
 		}
 	}
 
@@ -497,9 +467,6 @@ static int sun4i_ss_probe(struct platform_device *pdev)
 		case CRYPTO_ALG_TYPE_AHASH:
 			crypto_unregister_ahash(&ss_algs[i].alg.hash);
 			break;
-		case CRYPTO_ALG_TYPE_RNG:
-			crypto_unregister_rng(&ss_algs[i].alg.rng);
-			break;
 		}
 	}
 error_pm:
@@ -520,9 +487,6 @@ static void sun4i_ss_remove(struct platform_device *pdev)
 		case CRYPTO_ALG_TYPE_AHASH:
 			crypto_unregister_ahash(&ss_algs[i].alg.hash);
 			break;
-		case CRYPTO_ALG_TYPE_RNG:
-			crypto_unregister_rng(&ss_algs[i].alg.rng);
-			break;
 		}
 	}
 
diff --git a/drivers/crypto/allwinner/sun4i-ss/sun4i-ss-prng.c b/drivers/crypto/allwinner/sun4i-ss/sun4i-ss-prng.c
deleted file mode 100644
index 491fcb7b81b40b..00000000000000
--- a/drivers/crypto/allwinner/sun4i-ss/sun4i-ss-prng.c
+++ /dev/null
@@ -1,69 +0,0 @@
-// SPDX-License-Identifier: GPL-2.0-or-later
-#include "sun4i-ss.h"
-
-int sun4i_ss_prng_seed(struct crypto_rng *tfm, const u8 *seed,
-		       unsigned int slen)
-{
-	struct sun4i_ss_alg_template *algt;
-	struct rng_alg *alg = crypto_rng_alg(tfm);
-
-	algt = container_of(alg, struct sun4i_ss_alg_template, alg.rng);
-	memcpy(algt->ss->seed, seed, slen);
-
-	return 0;
-}
-
-int sun4i_ss_prng_generate(struct crypto_rng *tfm, const u8 *src,
-			   unsigned int slen, u8 *dst, unsigned int dlen)
-{
-	struct sun4i_ss_alg_template *algt;
-	struct rng_alg *alg = crypto_rng_alg(tfm);
-	int i, err;
-	u32 v;
-	u32 *data = (u32 *)dst;
-	const u32 mode = SS_OP_PRNG | SS_PRNG_CONTINUE | SS_ENABLED;
-	size_t len;
-	struct sun4i_ss_ctx *ss;
-	unsigned int todo = (dlen / 4) * 4;
-
-	algt = container_of(alg, struct sun4i_ss_alg_template, alg.rng);
-	ss = algt->ss;
-
-	err = pm_runtime_resume_and_get(ss->dev);
-	if (err < 0)
-		return err;
-
-	if (IS_ENABLED(CONFIG_CRYPTO_DEV_SUN4I_SS_DEBUG)) {
-		algt->stat_req++;
-		algt->stat_bytes += todo;
-	}
-
-	spin_lock_bh(&ss->slock);
-
-	writel(mode, ss->base + SS_CTL);
-
-	while (todo > 0) {
-		/* write the seed */
-		for (i = 0; i < SS_SEED_LEN / BITS_PER_LONG; i++)
-			writel(ss->seed[i], ss->base + SS_KEY0 + i * 4);
-
-		/* Read the random data */
-		len = min_t(size_t, SS_DATA_LEN / BITS_PER_BYTE, todo);
-		readsl(ss->base + SS_TXFIFO, data, len / 4);
-		data += len / 4;
-		todo -= len;
-
-		/* Update the seed */
-		for (i = 0; i < SS_SEED_LEN / BITS_PER_LONG; i++) {
-			v = readl(ss->base + SS_KEY0 + i * 4);
-			ss->seed[i] = v;
-		}
-	}
-
-	writel(0, ss->base + SS_CTL);
-	spin_unlock_bh(&ss->slock);
-
-	pm_runtime_put(ss->dev);
-
-	return 0;
-}
diff --git a/drivers/crypto/allwinner/sun4i-ss/sun4i-ss.h b/drivers/crypto/allwinner/sun4i-ss/sun4i-ss.h
index 6c5d4aa6453c7f..f7d1c79ac677d8 100644
--- a/drivers/crypto/allwinner/sun4i-ss/sun4i-ss.h
+++ b/drivers/crypto/allwinner/sun4i-ss/sun4i-ss.h
@@ -31,8 +31,6 @@
 #include <crypto/internal/skcipher.h>
 #include <crypto/aes.h>
 #include <crypto/internal/des.h>
-#include <crypto/internal/rng.h>
-#include <crypto/rng.h>
 
 #define SS_CTL            0x00
 #define SS_KEY0           0x04
@@ -62,10 +60,6 @@
 
 /* SS_CTL configuration values */
 
-/* PRNG generator mode - bit 15 */
-#define SS_PRNG_ONESHOT		(0 << 15)
-#define SS_PRNG_CONTINUE	(1 << 15)
-
 /* IV mode for hash */
 #define SS_IV_ARBITRARY		(1 << 14)
 
@@ -94,14 +88,10 @@
 #define SS_OP_3DES		(2 << 4)
 #define SS_OP_SHA1		(3 << 4)
 #define SS_OP_MD5		(4 << 4)
-#define SS_OP_PRNG		(5 << 4)
 
 /* Data end bit - bit 2 */
 #define SS_DATA_END		(1 << 2)
 
-/* PRNG start bit - bit 1 */
-#define SS_PRNG_START		(1 << 1)
-
 /* SS Enable bit - bit 0 */
 #define SS_DISABLED		(0 << 0)
 #define SS_ENABLED		(1 << 0)
@@ -128,9 +118,6 @@
 #define SS_RXFIFO_EMP_INT_ENABLE	(1 << 2)
 #define SS_TXFIFO_AVA_INT_ENABLE	(1 << 0)
 
-#define SS_SEED_LEN 192
-#define SS_DATA_LEN 160
-
 /*
  * struct ss_variant - Describe SS hardware variant
  * @sha1_in_be:		The SHA1 digest is given by SS in BE, and so need to be inverted.
@@ -151,9 +138,6 @@ struct sun4i_ss_ctx {
 	char buf[4 * SS_RX_MAX];/* buffer for linearize SG src */
 	char bufo[4 * SS_TX_MAX]; /* buffer for linearize SG dst */
 	spinlock_t slock; /* control the use of the device */
-#ifdef CONFIG_CRYPTO_DEV_SUN4I_SS_PRNG
-	u32 seed[SS_SEED_LEN / BITS_PER_LONG];
-#endif
 	struct dentry *dbgfs_dir;
 	struct dentry *dbgfs_stats;
 };
@@ -164,7 +148,6 @@ struct sun4i_ss_alg_template {
 	union {
 		struct skcipher_alg crypto;
 		struct ahash_alg hash;
-		struct rng_alg rng;
 	} alg;
 	struct sun4i_ss_ctx *ss;
 	unsigned long stat_req;
@@ -231,6 +214,3 @@ int sun4i_ss_des_setkey(struct crypto_skcipher *tfm, const u8 *key,
 			unsigned int keylen);
 int sun4i_ss_des3_setkey(struct crypto_skcipher *tfm, const u8 *key,
 			 unsigned int keylen);
-int sun4i_ss_prng_generate(struct crypto_rng *tfm, const u8 *src,
-			   unsigned int slen, u8 *dst, unsigned int dlen);
-int sun4i_ss_prng_seed(struct crypto_rng *tfm, const u8 *seed, unsigned int slen);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0004/2077] media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (2 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0003/2077] crypto: sun4i-ss - Remove insecure and unused rng_alg Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0005/2077] ALSA: hda/realtek: Add quirk for TongFang X6xx45xU Greg Kroah-Hartman
                   ` (993 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sean Anderson, Ricardo Ribalda,
	Laurent Pinchart, Hans de Goede, Hans Verkuil, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Anderson <sean.anderson@linux.dev>

[ Upstream commit 6d27f92c54ce28cfbd2a8a479a96d6f4a781b7d2 ]

If a UVC camera has an asynchronous control, uvc_status_stop may be
called from async_ctrl.work:

uvc_ctrl_status_event_work()
    uvc_ctrl_status_event()
        uvc_ctrl_clear_handle()
	    uvc_pm_put()
	        uvc_status_put()
		    uvc_status_stop()
		        cancel_work_sync()

This will cause a deadlock, since cancel_work_sync will wait for
uvc_ctrl_status_event_work to complete before returning.

Fix this by returning early from uvc_status_stop if we are currently in
the work function. flush_status now remains false until uvc_status_start
is called again, ensuring that uvc_ctrl_status_event_work won't resubmit
the URB.

Fixes: a32d9c41bdb8 ("media: uvcvideo: Make power management granular")
Cc: stable@vger.kernel.org
Closes: https://lore.kernel.org/all/6733bdfb-3e88-479f-8956-ab09c04c433e@linux.dev/
Signed-off-by: Sean Anderson <sean.anderson@linux.dev>
Link: https://patch.msgid.link/20260316155823.1855434-1-sean.anderson@linux.dev
Reviewed-by: Ricardo Ribalda <ribalda@chromium.org>
Tested-by: Ricardo Ribalda <ribalda@chromium.org>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/media/usb/uvc/uvc_status.c | 28 +++++++++++++++++++---------
 1 file changed, 19 insertions(+), 9 deletions(-)

diff --git a/drivers/media/usb/uvc/uvc_status.c b/drivers/media/usb/uvc/uvc_status.c
index 65f5356bebb399..b632cf5e3fe9b2 100644
--- a/drivers/media/usb/uvc/uvc_status.c
+++ b/drivers/media/usb/uvc/uvc_status.c
@@ -316,6 +316,16 @@ static int uvc_status_start(struct uvc_device *dev, gfp_t flags)
 	if (!dev->int_urb)
 		return 0;
 
+	/*
+	 * If the previous uvc_status_stop() call was from the async work,
+	 * the work may still be running. Wait for it to finish before we submit
+	 * the urb.
+	 */
+	flush_work(&dev->async_ctrl.work);
+
+	/* Clear the flush status if we were previously stopped. */
+	smp_store_release(&dev->flush_status, false);
+
 	return usb_submit_urb(dev->int_urb, flags);
 }
 
@@ -336,6 +346,15 @@ static void uvc_status_stop(struct uvc_device *dev)
 	 */
 	smp_store_release(&dev->flush_status, true);
 
+	/*
+	 * If we are called from the event work function, the URB is guaranteed
+	 * to not be in flight as it has completed and has not been resubmitted.
+	 * There's no need to cancel the work (which would deadlock), or to kill
+	 * the URB.
+	 */
+	if (current_work() == &w->work)
+		return;
+
 	/*
 	 * Cancel any pending asynchronous work. If any status event was queued,
 	 * process it synchronously.
@@ -354,15 +373,6 @@ static void uvc_status_stop(struct uvc_device *dev)
 	 */
 	if (cancel_work_sync(&w->work))
 		uvc_ctrl_status_event(w->chain, w->ctrl, w->data);
-
-	/*
-	 * From this point, there are no events on the queue and the status URB
-	 * is dead. No events will be queued until uvc_status_start() is called.
-	 * The barrier is needed to make sure that flush_status is visible to
-	 * uvc_ctrl_status_event_work() when uvc_status_start() will be called
-	 * again.
-	 */
-	smp_store_release(&dev->flush_status, false);
 }
 
 int uvc_status_resume(struct uvc_device *dev)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0005/2077] ALSA: hda/realtek: Add quirk for TongFang X6xx45xU
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (3 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0004/2077] media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0006/2077] ALSA: hda: conexant: Remove mic bias threshold override Greg Kroah-Hartman
                   ` (992 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eckhart Mohr, Werner Sembach,
	Takashi Iwai

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eckhart Mohr <e.mohr@tuxedocomputers.com>

commit d595255241e5fec0c94adeebf2565524398e37c5 upstream.

Fix microphone detection on built in headphone jack for some devices.

Signed-off-by: Eckhart Mohr <e.mohr@tuxedocomputers.com>
Cc: stable@vger.kernel.org
Signed-off-by: Werner Sembach <wse@tuxedocomputers.com>
Link: https://patch.msgid.link/20260708132135.102680-1-wse@tuxedocomputers.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/hda/codecs/realtek/alc269.c |    1 +
 1 file changed, 1 insertion(+)

--- a/sound/hda/codecs/realtek/alc269.c
+++ b/sound/hda/codecs/realtek/alc269.c
@@ -7840,6 +7840,7 @@ static const struct hda_quirk alc269_fix
 	SND_PCI_QUIRK(0x1d05, 0x300f, "TongFang X6AR5xxY", ALC2XX_FIXUP_HEADSET_MIC),
 	SND_PCI_QUIRK(0x1d05, 0x3019, "TongFang X6FR5xxY", ALC2XX_FIXUP_HEADSET_MIC),
 	SND_PCI_QUIRK(0x1d05, 0x3031, "TongFang X6AR55xU", ALC2XX_FIXUP_HEADSET_MIC),
+	SND_PCI_QUIRK(0x1d05, 0x3034, "TongFang X6xx45xU", ALC2XX_FIXUP_HEADSET_MIC),
 	SND_PCI_QUIRK(0x1d17, 0x3288, "Haier Boyue G42", ALC269VC_FIXUP_ACER_VCOPPERBOX_PINS),
 	SND_PCI_QUIRK(0x1d72, 0x1602, "RedmiBook", ALC255_FIXUP_XIAOMI_HEADSET_MIC),
 	SND_PCI_QUIRK(0x1d72, 0x1701, "XiaomiNotebook Pro", ALC298_FIXUP_DELL1_MIC_NO_PRESENCE),



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0006/2077] ALSA: hda: conexant: Remove mic bias threshold override
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (4 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0005/2077] ALSA: hda/realtek: Add quirk for TongFang X6xx45xU Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0007/2077] ALSA: hda: Fix cached processing coefficient verbs Greg Kroah-Hartman
                   ` (991 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Zhang Heng, Takashi Iwai

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhang Heng <zhangheng@kylinos.cn>

commit f52524da7084c1a54683ae9fbc73e93fff19dd64 upstream.

Remove the mic bias current comparator threshold override (NID 0x1c,
verb 0x320, value 0x010) from Conexant codec driver.

This override was originally intended to support volume up/down controls on
headsets with inline remote controls, but it causes microphone detection
failures on some headsets with impedance less than 1k ohm.

After consulting with the vendor's engineers, it was confirmed that this
setting is board-specific and should be handled by BIOS/firmware rather
than the generic codec driver, especially since inline remote support
is not currently implemented.

Fixes: 7aeb25908648 ("ALSA: hda/conexant: Fix headset auto detect fail in cx8070 and SN6140")
Cc: stable@vger.kernel.org
Signed-off-by: Zhang Heng <zhangheng@kylinos.cn>
Link: https://patch.msgid.link/20260713100329.306892-1-zhangheng@kylinos.cn
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/hda/codecs/conexant.c |    3 ---
 1 file changed, 3 deletions(-)

--- a/sound/hda/codecs/conexant.c
+++ b/sound/hda/codecs/conexant.c
@@ -162,9 +162,6 @@ static void cx_fixup_headset_recog(struc
 {
 	unsigned int mic_present;
 
-	/* fix some headset type recognize fail issue, such as EDIFIER headset */
-	/* set micbias output current comparator threshold from 66% to 55%. */
-	snd_hda_codec_write(codec, 0x1c, 0, 0x320, 0x010);
 	/* set OFF voltage for DFET from -1.2V to -0.8V, set headset micbias register
 	 * value adjustment trim from 2.2K ohms to 2.0K ohms.
 	 */



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0007/2077] ALSA: hda: Fix cached processing coefficient verbs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (5 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0006/2077] ALSA: hda: conexant: Remove mic bias threshold override Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0008/2077] ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID 17aa:38a7 Greg Kroah-Hartman
                   ` (990 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Xu Rao, Takashi Iwai

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xu Rao <raoxu@uniontech.com>

commit f67be28fdf8b5d31ac1cc1152bb17250f9f8f513 upstream.

Intel HD Audio defines Coefficient Index and Processing Coefficient as
separate audio widget controls in the Audio Widget Verb Definitions:
Coefficient Index selects the coefficient slot, while Processing
Coefficient accesses the value at the selected slot.

hda_reg_read_coef() selects the slot with AC_VERB_SET_COEF_INDEX, but
then uses AC_VERB_GET_COEF_INDEX for the value read.  That reads back the
selected index instead of the coefficient value.  hda_reg_write_coef()
has the same issue and builds the value write from AC_VERB_GET_COEF_INDEX
instead of AC_VERB_SET_PROC_COEF.

This only affects the regmap coefficient cache path used by codecs that
set codec->cache_coef.  Direct coefficient helpers already use the normal
SET_COEF_INDEX followed by GET_PROC_COEF or SET_PROC_COEF sequence, which
is likely why this has not been noticed widely.

Use AC_VERB_GET_PROC_COEF for cached coefficient reads and
AC_VERB_SET_PROC_COEF for cached coefficient writes.

Fixes: 40ba66a702b8 ("ALSA: hda - Add cache support for COEF read/write")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Link: https://patch.msgid.link/DB9023BF2920BA99+20260707132419.1731342-1-raoxu@uniontech.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/hda/core/regmap.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/sound/hda/core/regmap.c
+++ b/sound/hda/core/regmap.c
@@ -214,7 +214,7 @@ static int hda_reg_read_coef(struct hdac
 	err = snd_hdac_exec_verb(codec, verb, 0, NULL);
 	if (err < 0)
 		return err;
-	verb = (reg & ~0xfffff) | (AC_VERB_GET_COEF_INDEX << 8);
+	verb = (reg & ~0xfffff) | (AC_VERB_GET_PROC_COEF << 8);
 	return snd_hdac_exec_verb(codec, verb, 0, val);
 }
 
@@ -232,7 +232,7 @@ static int hda_reg_write_coef(struct hda
 	err = snd_hdac_exec_verb(codec, verb, 0, NULL);
 	if (err < 0)
 		return err;
-	verb = (reg & ~0xfffff) | (AC_VERB_GET_COEF_INDEX << 8) |
+	verb = (reg & ~0xfffff) | (AC_VERB_SET_PROC_COEF << 8) |
 		(val & 0xffff);
 	return snd_hdac_exec_verb(codec, verb, 0, NULL);
 }



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0008/2077] ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID 17aa:38a7
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (6 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0007/2077] ALSA: hda: Fix cached processing coefficient verbs Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0009/2077] media: uvcvideo: Use hw timestaming if the clock buffer is full Greg Kroah-Hartman
                   ` (989 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Damien Laine, Takashi Iwai

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Damien Laine <damien.laine@gmail.com>

commit d35dfb6329accfe1cfa0b57e35214b5cbbe0f9ae upstream.

Some units of the Lenovo Legion Pro 7 16ARX8H (82WS) report codec
subsystem ID 17aa:38a7 instead of 17aa:38a8. Since only 38a8 has a
codec SSID quirk, these machines fall through to the PCI SSID match
17aa:386f (Legion Pro 7i 16IAX7) and get ALC287_FIXUP_CS35L41_I2C_2,
which probes the Cirrus amplifiers of the Intel variant. The TI
TAS2781 amplifier (ACPI TIAS2781:00) present on this AMD variant is
never bound and the internal speakers remain silent.

Add a codec SSID quirk for 17aa:38a7 pointing to
ALC287_FIXUP_TAS2781_I2C, mirroring the existing 38a8 entry.

Tested on a Legion Pro 7 16ARX8H (82WS, BIOS LPCN62WW): with the codec
SSID overridden to 17aa:38a8 via the HDA patch loader, the TAS2781
amplifier binds and the internal speakers work.

Cc: <stable@vger.kernel.org>
Signed-off-by: Damien Laine <damien.laine@gmail.com>
Link: https://patch.msgid.link/20260712213708.1835469-1-damien.laine@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/hda/codecs/realtek/alc269.c |    1 +
 1 file changed, 1 insertion(+)

--- a/sound/hda/codecs/realtek/alc269.c
+++ b/sound/hda/codecs/realtek/alc269.c
@@ -7723,6 +7723,7 @@ static const struct hda_quirk alc269_fix
 	HDA_CODEC_QUIRK(0x17aa, 0x386e, "Legion Y9000X 2022 IAH7", ALC287_FIXUP_CS35L41_I2C_2),
 	SND_PCI_QUIRK(0x17aa, 0x386e, "Yoga Pro 7 14ARP8", ALC285_FIXUP_SPEAKER2_TO_DAC1),
 	HDA_CODEC_QUIRK(0x17aa, 0x38a8, "Legion Pro 7 16ARX8H", ALC287_FIXUP_TAS2781_I2C), /* this must match before PCI SSID 17aa:386f below */
+	HDA_CODEC_QUIRK(0x17aa, 0x38a7, "Legion Pro 7 16ARX8H", ALC287_FIXUP_TAS2781_I2C), /* this must match before PCI SSID 17aa:386f below */
 	SND_PCI_QUIRK(0x17aa, 0x386f, "Legion Pro 7i 16IAX7", ALC287_FIXUP_CS35L41_I2C_2),
 	SND_PCI_QUIRK(0x17aa, 0x3870, "Lenovo Yoga 7 14ARB7", ALC287_FIXUP_YOGA7_14ARB7_I2C),
 	SND_PCI_QUIRK(0x17aa, 0x3877, "Lenovo Legion 7 Slim 16ARHA7", ALC287_FIXUP_CS35L41_I2C_2),



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0009/2077] media: uvcvideo: Use hw timestaming if the clock buffer is full
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (7 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0008/2077] ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID 17aa:38a7 Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0010/2077] media: uvcvideo: Avoid partial metadata buffers Greg Kroah-Hartman
                   ` (988 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hans de Goede, Yunke Cao,
	Ricardo Ribalda, Hans Verkuil

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ricardo Ribalda <ribalda@chromium.org>

commit ede7de6e6b3db552d10ac50557d69c50d1b08486 upstream.

In some situations, even with a full clock buffer, it does not contain
250msec of data. This results in the driver jumping back from software
to hardware timestapsing creating a nasty artifact in the video.

If the clock buffer is full, use it to calculate the timestamp instead
of defaulting to software stamps, the reduced accuracy is less visible
than jumping from one timestamping mechanism to the other.

Fixes: 6243c83be6ee8 ("media: uvcvideo: Allow hw clock updates with buffers not full")
Cc: stable@vger.kernel.org
Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Tested-by: Yunke Cao <yunkec@google.com>
Signed-off-by: Ricardo Ribalda <ribalda@chromium.org>
Link: https://patch.msgid.link/20260513-uvc-hwtimestamp-v3-2-7a64838b0b02@chromium.org
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/uvc/uvc_video.c |   17 ++++++++++++-----
 1 file changed, 12 insertions(+), 5 deletions(-)

--- a/drivers/media/usb/uvc/uvc_video.c
+++ b/drivers/media/usb/uvc/uvc_video.c
@@ -833,15 +833,22 @@ void uvc_video_clock_update(struct uvc_s
 		y2 += 2048 << 16;
 
 	/*
-	 * Have at least 1/4 of a second of timestamps before we
-	 * try to do any calculation. Otherwise we do not have enough
-	 * precision. This value was determined by running Android CTS
-	 * on different devices.
+	 * If the buffer is not full, we want to gather at least 1/4th of
+	 * timestamps before using HW timestamping. We do this to avoid jitter
+	 * on the initial frames.
+	 *
+	 * If the buffer is full we would use it regardless of how much data
+	 * it represents. This could be solved with an infinite big circular
+	 * buffer, but RAM is expensive these days, specially the infinitely
+	 * big.
+	 *
+	 * The value of 1/4th of a second was determined by running Android's
+	 * CTS on different devices.
 	 *
 	 * dev_sof runs at 1KHz, and we have a fixed point precision of
 	 * 16 bits.
 	 */
-	if ((y2 - y1) < ((1000 / 4) << 16))
+	if (clock->size != clock->count && (y2 - y1) < ((1000 / 4) << 16))
 		goto done;
 
 	y = (u64)(y2 - y1) * (1ULL << 31) + (u64)y1 * (u64)x2



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0010/2077] media: uvcvideo: Avoid partial metadata buffers
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (8 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0009/2077] media: uvcvideo: Use hw timestaming if the clock buffer is full Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0011/2077] media: uvcvideo: Fix buffer sequence in frame gaps Greg Kroah-Hartman
                   ` (987 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ricardo Ribalda, Hans de Goede,
	Hans Verkuil

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ricardo Ribalda <ribalda@chromium.org>

commit a15b773fe4ffa450b56347cc506b2d1405600f5d upstream.

If the metadata queue that is empty receives a new buffer while we are
in the middle of processing a frame, the first metadata buffer will
contain partial information.

Avoid this by tracking the state of the metadata buffer and making sure
that it is in sync with the data buffer.

Now that we are at it, make sure that we skip buffers of size 1 or 0.
They are not allowed by the spec... but it is a simple check to add and
better be safe than sorry.

Fixes: 088ead255245 ("media: uvcvideo: Add a metadata device node")
Cc: stable@vger.kernel.org
Signed-off-by: Ricardo Ribalda <ribalda@chromium.org>
Link: https://patch.msgid.link/20260417-uvc-meta-partial-v2-2-31d274af7d2d@chromium.org
Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/uvc/uvc_video.c |   13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

--- a/drivers/media/usb/uvc/uvc_video.c
+++ b/drivers/media/usb/uvc/uvc_video.c
@@ -1156,7 +1156,9 @@ static void uvc_video_stats_stop(struct
  * uvc_video_decode_end will never be called with a NULL buffer.
  */
 static int uvc_video_decode_start(struct uvc_streaming *stream,
-		struct uvc_buffer *buf, const u8 *data, int len)
+				  struct uvc_buffer *buf,
+				  struct uvc_buffer *meta_buf,
+				  const u8 *data, int len)
 {
 	u8 header_len;
 	u8 fid;
@@ -1229,6 +1231,8 @@ static int uvc_video_decode_start(struct
 
 		/* TODO: Handle PTS and SCR. */
 		buf->state = UVC_BUF_STATE_ACTIVE;
+		if (meta_buf)
+			meta_buf->state = UVC_BUF_STATE_ACTIVE;
 	}
 
 	/*
@@ -1431,7 +1435,7 @@ static void uvc_video_decode_meta(struct
 	ktime_t time;
 	const u8 *scr;
 
-	if (!meta_buf || length == 2)
+	if (length <= 2 || !meta_buf || meta_buf->state != UVC_BUF_STATE_ACTIVE)
 		return;
 
 	has_pts = mem[1] & UVC_STREAM_PTS;
@@ -1548,7 +1552,7 @@ static void uvc_video_decode_isoc(struct
 		/* Decode the payload header. */
 		mem = urb->transfer_buffer + urb->iso_frame_desc[i].offset;
 		do {
-			ret = uvc_video_decode_start(stream, buf, mem,
+			ret = uvc_video_decode_start(stream, buf, meta_buf, mem,
 				urb->iso_frame_desc[i].actual_length);
 			if (ret == -EAGAIN)
 				uvc_video_next_buffers(stream, &buf, &meta_buf);
@@ -1597,7 +1601,8 @@ static void uvc_video_decode_bulk(struct
 	 */
 	if (stream->bulk.header_size == 0 && !stream->bulk.skip_payload) {
 		do {
-			ret = uvc_video_decode_start(stream, buf, mem, len);
+			ret = uvc_video_decode_start(stream, buf, meta_buf, mem,
+						     len);
 			if (ret == -EAGAIN)
 				uvc_video_next_buffers(stream, &buf, &meta_buf);
 		} while (ret == -EAGAIN);



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0011/2077] media: uvcvideo: Fix buffer sequence in frame gaps
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (9 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0010/2077] media: uvcvideo: Avoid partial metadata buffers Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0012/2077] media: uvcvideo: Fix dev_sof filtering in hw timestamp Greg Kroah-Hartman
                   ` (986 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Ricardo Ribalda,
	Hans de Goede, Hans Verkuil

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ricardo Ribalda <ribalda@chromium.org>

commit 2f24ac8dd87983a55f0498898f34a5f2b735b802 upstream.

In UVC, the FID flips with every frame. For every FID flip, we increase
the stream sequence number.

Now, if a FID flips multiple times and there is no data transferred between
the flips, the buffer sequence number will be set to the value of the
stream sequence number after the first flip.

Userspace uses the buffer sequence number to determine if there have been
missing frames. With the current behaviour, userspace will think that the
gap is in the wrong location.

This patch modifies uvc_video_decode_start() to provide the correct buffer
sequence number and timestamp.

Cc: stable@kernel.org
Fixes: 650b95feee35 ("[media] uvcvideo: Generate discontinuous sequence numbers when frames are lost")
Signed-off-by: Ricardo Ribalda <ribalda@chromium.org>
Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/uvc/uvc_video.c |   17 +++++++++++++----
 1 file changed, 13 insertions(+), 4 deletions(-)

--- a/drivers/media/usb/uvc/uvc_video.c
+++ b/drivers/media/usb/uvc/uvc_video.c
@@ -1185,6 +1185,19 @@ static int uvc_video_decode_start(struct
 		stream->sequence++;
 		if (stream->sequence)
 			uvc_video_stats_update(stream);
+
+		/*
+		 * On a FID flip initialize sequence number and timestamp.
+		 *
+		 * The driver already takes care of injecting FID flips for
+		 * UVC_QUIRK_STREAM_NO_FID and UVC_QUIRK_MJPEG_NO_EOF.
+		 */
+		if (buf) {
+			buf->buf.field = V4L2_FIELD_NONE;
+			buf->buf.sequence = stream->sequence;
+			buf->buf.vb2_buf.timestamp =
+					ktime_to_ns(uvc_video_get_time());
+		}
 	}
 
 	uvc_video_clock_decode(stream, buf, data, len);
@@ -1225,10 +1238,6 @@ static int uvc_video_decode_start(struct
 			return -ENODATA;
 		}
 
-		buf->buf.field = V4L2_FIELD_NONE;
-		buf->buf.sequence = stream->sequence;
-		buf->buf.vb2_buf.timestamp = ktime_to_ns(uvc_video_get_time());
-
 		/* TODO: Handle PTS and SCR. */
 		buf->state = UVC_BUF_STATE_ACTIVE;
 		if (meta_buf)



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0012/2077] media: uvcvideo: Fix dev_sof filtering in hw timestamp
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (10 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0011/2077] media: uvcvideo: Fix buffer sequence in frame gaps Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0013/2077] media: uvcvideo: Do not add clock samples with small sof delta Greg Kroah-Hartman
                   ` (985 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hans de Goede, Yunke Cao,
	Ricardo Ribalda, Hans Verkuil

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ricardo Ribalda <ribalda@chromium.org>

commit edc1917599c5339aedc83135cade66517e0a2972 upstream.

To avoid filling the clock circular buffer with duplicated data we only
add it if the new value sof is different than the last added sof.

The issue is that we compare the unprocess sof with the processed sof.
If there is a sof_offset, or UVC_QUIRK_INVALID_DEVICE_SOF is enabled,
the comparison will not work as expected.

This patch moves the comparison to the right place.

Fixes: 141270bd95d4 ("media: uvcvideo: Refactor clock circular buffer")
Cc: stable@vger.kernel.org
Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Tested-by: Yunke Cao <yunkec@google.com>
Signed-off-by: Ricardo Ribalda <ribalda@chromium.org>
Link: https://patch.msgid.link/20260513-uvc-hwtimestamp-v3-1-7a64838b0b02@chromium.org
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/uvc/uvc_video.c |   19 ++++++++++---------
 1 file changed, 10 insertions(+), 9 deletions(-)

--- a/drivers/media/usb/uvc/uvc_video.c
+++ b/drivers/media/usb/uvc/uvc_video.c
@@ -583,16 +583,7 @@ uvc_video_clock_decode(struct uvc_stream
 	if (!has_scr)
 		return;
 
-	/*
-	 * To limit the amount of data, drop SCRs with an SOF identical to the
-	 * previous one. This filtering is also needed to support UVC 1.5, where
-	 * all the data packets of the same frame contains the same SOF. In that
-	 * case only the first one will match the host_sof.
-	 */
 	sample.dev_sof = get_unaligned_le16(&data[header_size - 2]);
-	if (sample.dev_sof == stream->clock.last_sof)
-		return;
-
 	sample.dev_stc = get_unaligned_le32(&data[header_size - 6]);
 
 	/*
@@ -664,6 +655,16 @@ uvc_video_clock_decode(struct uvc_stream
 	}
 
 	sample.dev_sof = (sample.dev_sof + stream->clock.sof_offset) & 2047;
+
+	/*
+	 * To limit the amount of data, drop SCRs with an SOF identical to the
+	 * previous one. This filtering is also needed to support UVC 1.5, where
+	 * all the data packets of the same frame contains the same SOF. In that
+	 * case only the first one will match the host_sof.
+	 */
+	if (sample.dev_sof == stream->clock.last_sof)
+		return;
+
 	uvc_video_clock_add_sample(&stream->clock, &sample);
 	stream->clock.last_sof = sample.dev_sof;
 }



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0013/2077] media: uvcvideo: Do not add clock samples with small sof delta
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (11 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0012/2077] media: uvcvideo: Fix dev_sof filtering in hw timestamp Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0014/2077] media: uvcvideo: Relax the constrains for interpolating the hw clock Greg Kroah-Hartman
                   ` (984 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yunke Cao, Hans de Goede,
	Ricardo Ribalda, Hans Verkuil

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ricardo Ribalda <ribalda@chromium.org>

commit ba649fff36c1fe68489a86d00285224907edd436 upstream.

Some UVC 1.1 cameras running in fast isochronous mode tend to spam the
USB host with a lot of empty packets. These packets contain clock
information and are added to the clock buffer but do not add any
accuracy to the calculation. In fact, it is quite the opposite, in our
calculations, only the first and the last timestamp is used, and we only
have 32 slots.

Ignore the samples that will produce less than MIN_HW_TIMESTAMP_DIFF
data.

Fixes: 141270bd95d4 ("media: uvcvideo: Refactor clock circular buffer")
Cc: stable@vger.kernel.org
Tested-by: Yunke Cao <yunkec@google.com>
Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Ricardo Ribalda <ribalda@chromium.org>
Link: https://patch.msgid.link/20260513-uvc-hwtimestamp-v3-4-7a64838b0b02@chromium.org
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/uvc/uvc_video.c |   14 ++++++++++++--
 1 file changed, 12 insertions(+), 2 deletions(-)

--- a/drivers/media/usb/uvc/uvc_video.c
+++ b/drivers/media/usb/uvc/uvc_video.c
@@ -537,6 +537,15 @@ static void uvc_video_clock_add_sample(s
 	spin_unlock_irqrestore(&clock->lock, flags);
 }
 
+static inline u16 sof_diff(u16 a, u16 b)
+{
+	/*
+	 * Because the result is modulo 2048 (via & 2047), we do not need a
+	 * special case for a < b.
+	 */
+	return (a - b) & 2047;
+}
+
 static void
 uvc_video_clock_decode(struct uvc_streaming *stream, struct uvc_buffer *buf,
 		       const u8 *data, int len)
@@ -657,12 +666,13 @@ uvc_video_clock_decode(struct uvc_stream
 	sample.dev_sof = (sample.dev_sof + stream->clock.sof_offset) & 2047;
 
 	/*
-	 * To limit the amount of data, drop SCRs with an SOF identical to the
+	 * To limit the amount of data, drop SCRs with an SOF similar to the
 	 * previous one. This filtering is also needed to support UVC 1.5, where
 	 * all the data packets of the same frame contains the same SOF. In that
 	 * case only the first one will match the host_sof.
 	 */
-	if (sample.dev_sof == stream->clock.last_sof)
+	if (sof_diff(sample.dev_sof, stream->clock.last_sof) <=
+	    (UVC_MIN_HW_TIMESTAMP_DIFF / stream->clock.size))
 		return;
 
 	uvc_video_clock_add_sample(&stream->clock, &sample);



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0014/2077] media: uvcvideo: Relax the constrains for interpolating the hw clock
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (12 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0013/2077] media: uvcvideo: Do not add clock samples with small sof delta Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0015/2077] media: uvcvideo: Fix sequence number when no EOF Greg Kroah-Hartman
                   ` (983 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hans de Goede, Yunke Cao,
	Ricardo Ribalda, Hans Verkuil

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ricardo Ribalda <ribalda@chromium.org>

commit 1719d78f832dda8dd3f09a867ba74e05d6f11308 upstream.

In the initial version we set the min value to 250msec. Looks like
100msec can also provide a good value.

Now that we are at it, add a macro to make it cleaner.

Fixes: 6243c83be6ee8 ("media: uvcvideo: Allow hw clock updates with buffers not full")
Cc: stable@vger.kernel.org
Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Tested-by: Yunke Cao <yunkec@google.com>
Signed-off-by: Ricardo Ribalda <ribalda@chromium.org>
Link: https://patch.msgid.link/20260513-uvc-hwtimestamp-v3-3-7a64838b0b02@chromium.org
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/uvc/uvc_video.c |   17 ++++++++++++-----
 1 file changed, 12 insertions(+), 5 deletions(-)

--- a/drivers/media/usb/uvc/uvc_video.c
+++ b/drivers/media/usb/uvc/uvc_video.c
@@ -494,6 +494,13 @@ static int uvc_commit_video(struct uvc_s
  * Clocks and timestamps
  */
 
+/*
+ * The accuracy of the hardware timestamping depends on having enough data to
+ * interpolate between the different clock domains. This value is sof cycles,
+ * this is, milliseconds.
+ */
+#define UVC_MIN_HW_TIMESTAMP_DIFF 100
+
 static inline ktime_t uvc_video_get_time(void)
 {
 	if (uvc_clock_param == CLOCK_MONOTONIC)
@@ -853,13 +860,13 @@ void uvc_video_clock_update(struct uvc_s
 	 * buffer, but RAM is expensive these days, specially the infinitely
 	 * big.
 	 *
-	 * The value of 1/4th of a second was determined by running Android's
-	 * CTS on different devices.
+	 * The value of UVC_MIN_HW_TIMESTAMP_DIFF was determined by running
+	 * Android's CTS on different devices.
 	 *
-	 * dev_sof runs at 1KHz, and we have a fixed point precision of
-	 * 16 bits.
+	 * y1 and y2 are dev_sof with a fixed point precision of 16 bits.
 	 */
-	if (clock->size != clock->count && (y2 - y1) < ((1000 / 4) << 16))
+	if (clock->size != clock->count &&
+	    (y2 - y1) < (UVC_MIN_HW_TIMESTAMP_DIFF << 16))
 		goto done;
 
 	y = (u64)(y2 - y1) * (1ULL << 31) + (u64)y1 * (u64)x2



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0015/2077] media: uvcvideo: Fix sequence number when no EOF
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (13 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0014/2077] media: uvcvideo: Relax the constrains for interpolating the hw clock Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0016/2077] dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties Greg Kroah-Hartman
                   ` (982 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Hans de Goede,
	Ricardo Ribalda, Laurent Pinchart, Hans de Goede, Hans Verkuil

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ricardo Ribalda <ribalda@chromium.org>

commit f078966ca1fb1b3865d8e6bbe2705cfd277fc637 upstream.

If the driver could not detect the EOF, the sequence number is increased
twice:
 1) When we enter uvc_video_decode_start() with the old buffer and FID has
   flipped => We return -EAGAIN and last_fid is not flipped
 2) When we enter uvc_video_decode_start() with the new buffer.

Fix this issue by moving the new frame detection logic earlier in
uvc_video_decode_start().

This also has some nice side affects:

- The error status from the new packet will no longer get propagated
  to the previous frame-buffer.
- uvc_video_clock_decode() will no longer update the previous frame
  buf->stf with info from the new packet.
- uvc_video_clock_decode() and uvc_video_stats_decode() will no longer
  get called twice for the same packet.

Cc: stable@kernel.org
Fixes: 650b95feee35 ("[media] uvcvideo: Generate discontinuous sequence numbers when frames are lost")
Reported-by: Hans de Goede <hansg@kernel.org>
Closes: https://lore.kernel.org/linux-media/CANiDSCuj4cPuB5_v2xyvAagA5FjoN8V5scXiFFOeD3aKDMqkCg@mail.gmail.com/T/#me39fb134e8c2c085567a31548c3403eb639625e4
Signed-off-by: Ricardo Ribalda <ribalda@chromium.org>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/uvc/uvc_video.c |   92 +++++++++++++++++++-------------------
 1 file changed, 47 insertions(+), 45 deletions(-)

--- a/drivers/media/usb/uvc/uvc_video.c
+++ b/drivers/media/usb/uvc/uvc_video.c
@@ -1196,6 +1196,53 @@ static int uvc_video_decode_start(struct
 	fid = data[1] & UVC_STREAM_FID;
 
 	/*
+	 * Mark the buffer as done if we're at the beginning of a new frame.
+	 * End of frame detection is better implemented by checking the EOF
+	 * bit (FID bit toggling is delayed by one frame compared to the EOF
+	 * bit), but some devices don't set the bit at end of frame (and the
+	 * last payload can be lost anyway). We thus must check if the FID has
+	 * been toggled.
+	 *
+	 * stream->last_fid is initialized to -1, and buf->bytesused to 0,
+	 * so the first isochronous frame will never trigger an end of frame
+	 * detection.
+	 *
+	 * Empty buffers (bytesused == 0) don't trigger end of frame detection
+	 * as it doesn't make sense to return an empty buffer. This also
+	 * avoids detecting end of frame conditions at FID toggling if the
+	 * previous payload had the EOF bit set.
+	 */
+	if (fid != stream->last_fid && buf && buf->bytesused != 0) {
+		uvc_dbg(stream->dev, FRAME,
+			"Frame complete (FID bit toggled)\n");
+		buf->state = UVC_BUF_STATE_READY;
+
+		return -EAGAIN;
+	}
+
+	/*
+	 * Some cameras, when running two parallel streams (one MJPEG alongside
+	 * another non-MJPEG stream), are known to lose the EOF packet for a frame.
+	 * We can detect the end of a frame by checking for a new SOI marker, as
+	 * the SOI always lies on the packet boundary between two frames for
+	 * these devices.
+	 */
+	if (stream->dev->quirks & UVC_QUIRK_MJPEG_NO_EOF &&
+	    (stream->cur_format->fcc == V4L2_PIX_FMT_MJPEG ||
+	     stream->cur_format->fcc == V4L2_PIX_FMT_JPEG) &&
+	    buf && buf->bytesused != 0) {
+		const u8 *packet = data + header_len;
+
+		if (len >= header_len + 2 &&
+		    packet[0] == 0xff && packet[1] == JPEG_MARKER_SOI) {
+			buf->state = UVC_BUF_STATE_READY;
+			buf->error = 1;
+			stream->last_fid ^= UVC_STREAM_FID;
+			return -EAGAIN;
+		}
+	}
+
+	/*
 	 * Increase the sequence number regardless of any buffer states, so
 	 * that discontinuous sequence numbers always indicate lost frames.
 	 */
@@ -1262,51 +1309,6 @@ static int uvc_video_decode_start(struct
 			meta_buf->state = UVC_BUF_STATE_ACTIVE;
 	}
 
-	/*
-	 * Mark the buffer as done if we're at the beginning of a new frame.
-	 * End of frame detection is better implemented by checking the EOF
-	 * bit (FID bit toggling is delayed by one frame compared to the EOF
-	 * bit), but some devices don't set the bit at end of frame (and the
-	 * last payload can be lost anyway). We thus must check if the FID has
-	 * been toggled.
-	 *
-	 * stream->last_fid is initialized to -1, so the first isochronous
-	 * frame will never trigger an end of frame detection.
-	 *
-	 * Empty buffers (bytesused == 0) don't trigger end of frame detection
-	 * as it doesn't make sense to return an empty buffer. This also
-	 * avoids detecting end of frame conditions at FID toggling if the
-	 * previous payload had the EOF bit set.
-	 */
-	if (fid != stream->last_fid && buf->bytesused != 0) {
-		uvc_dbg(stream->dev, FRAME,
-			"Frame complete (FID bit toggled)\n");
-		buf->state = UVC_BUF_STATE_READY;
-		return -EAGAIN;
-	}
-
-	/*
-	 * Some cameras, when running two parallel streams (one MJPEG alongside
-	 * another non-MJPEG stream), are known to lose the EOF packet for a frame.
-	 * We can detect the end of a frame by checking for a new SOI marker, as
-	 * the SOI always lies on the packet boundary between two frames for
-	 * these devices.
-	 */
-	if (stream->dev->quirks & UVC_QUIRK_MJPEG_NO_EOF &&
-	    (stream->cur_format->fcc == V4L2_PIX_FMT_MJPEG ||
-	    stream->cur_format->fcc == V4L2_PIX_FMT_JPEG)) {
-		const u8 *packet = data + header_len;
-
-		if (len >= header_len + 2 &&
-		    packet[0] == 0xff && packet[1] == JPEG_MARKER_SOI &&
-		    buf->bytesused != 0) {
-			buf->state = UVC_BUF_STATE_READY;
-			buf->error = 1;
-			stream->last_fid ^= UVC_STREAM_FID;
-			return -EAGAIN;
-		}
-	}
-
 	stream->last_fid = fid;
 
 	return header_len;



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0016/2077] dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (14 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0015/2077] media: uvcvideo: Fix sequence number when no EOF Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0017/2077] dt-bindings: power: imx93: Add MIPI PHY power domain Greg Kroah-Hartman
                   ` (981 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chen-Yu Tsai, Rob Herring (Arm),
	Jernej Skrabec, Nicolas Dufresne, Hans Verkuil

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chen-Yu Tsai <wens@kernel.org>

commit 018f2dc3a42098d3b04edd1480adc51d268adb14 upstream.

The Allwinner video engine sits behind the MBUS that is represented as
an interconnect.

Make sure that the interconnect properties are valid in the binding.

Fixes: d41662e52a03 ("media: dt-bindings: media: allwinner,sun4i-a10-video-engine: Add R40 compatible")
Cc: stable@vger.kernel.org
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Acked-by: Rob Herring (Arm) <robh@kernel.org>
Acked-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 Documentation/devicetree/bindings/media/allwinner,sun4i-a10-video-engine.yaml |   10 ++++++++++
 1 file changed, 10 insertions(+)

--- a/Documentation/devicetree/bindings/media/allwinner,sun4i-a10-video-engine.yaml
+++ b/Documentation/devicetree/bindings/media/allwinner,sun4i-a10-video-engine.yaml
@@ -63,6 +63,16 @@ properties:
       CMA pool to use for buffers allocation instead of the default
       CMA pool.
 
+  # FIXME: This should be made required eventually once every SoC will
+  # have the MBUS declared.
+  interconnects:
+    maxItems: 1
+
+  # FIXME: This should be made required eventually once every SoC will
+  # have the MBUS declared.
+  interconnect-names:
+    const: dma-mem
+
 required:
   - compatible
   - reg



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0017/2077] dt-bindings: power: imx93: Add MIPI PHY power domain
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (15 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0016/2077] dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0018/2077] serial: msm: Disable DMA for kernel console UART Greg Kroah-Hartman
                   ` (980 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guoniu Zhou, Frank Li,
	Krzysztof Kozlowski, Peng Fan, Ulf Hansson

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guoniu Zhou <guoniu.zhou@oss.nxp.com>

commit 6aa38ef0eab32df5409b72d62509de6ba09cea50 upstream.

Add MIPI PHY power domain for shared PHY resources used by both
MIPI DSI and CSI blocks.

Signed-off-by: Guoniu Zhou <guoniu.zhou@oss.nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Acked-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Peng Fan <peng.fan@nxp.com>
Fixes: e9aa77d413c9 ("soc: imx: add i.MX93 media blk ctrl driver")
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 include/dt-bindings/power/fsl,imx93-power.h |    1 +
 1 file changed, 1 insertion(+)

--- a/include/dt-bindings/power/fsl,imx93-power.h
+++ b/include/dt-bindings/power/fsl,imx93-power.h
@@ -11,5 +11,6 @@
 #define IMX93_MEDIABLK_PD_PXP			2
 #define IMX93_MEDIABLK_PD_LCDIF			3
 #define IMX93_MEDIABLK_PD_ISI			4
+#define IMX93_MEDIABLK_PD_MIPI_PHY		5
 
 #endif



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0018/2077] serial: msm: Disable DMA for kernel console UART
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (16 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0017/2077] dt-bindings: power: imx93: Add MIPI PHY power domain Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0019/2077] serial: max310x: implement gpio_chip::get_direction() Greg Kroah-Hartman
                   ` (979 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Stephan Gerhold,
	Konrad Dybcio

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stephan Gerhold <stephan.gerhold@linaro.org>

commit 22dd2777e6c180e1c945b00f6d18550979436324 upstream.

At the moment, concurrent writes from userspace and the kernel to the
console can trigger a race condition that results in an infinite loop of
the same messages printed over and over again. This is most likely to
happen during system startup or shutdown when the init system starts/stops
a large number of system services that interact with various kernel code.

When userspace writes to the TTY device, the driver initiates an
asynchronous DMA transfer and releases the port lock. At the same moment,
the kernel printk path might grab the port lock and re-configure the UART
controller for PIO, without waiting for the DMA operation to complete. It
seems like this collision results in zero progress being reported for the
DMA engine, so the same text is printed to the console over and over again.

For the kernel console, we want a reliable output path that will be
functional even during crashes etc. So rather than implementing complex
code to synchronize the kernel console write routines with the userspace
DMA write routines, simply disable DMA for the console UART instance.

Similar checks exist in many other serial drivers, e.g. 8250_port.c,
imx.c, sh-sci.c etc.

Cc: stable <stable@kernel.org>
Fixes: 3a878c430fd6 ("tty: serial: msm: Add TX DMA support")
Signed-off-by: Stephan Gerhold <stephan.gerhold@linaro.org>
Acked-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://patch.msgid.link/20260706-serial-msm-console-dma-collision-v1-1-3179b8cb1d89@linaro.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/tty/serial/msm_serial.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/tty/serial/msm_serial.c
+++ b/drivers/tty/serial/msm_serial.c
@@ -1228,7 +1228,8 @@ static int msm_startup(struct uart_port
 	data |= MSM_UART_MR1_AUTO_RFR_LEVEL0 & rfr_level;
 	msm_write(port, data, MSM_UART_MR1);
 
-	if (msm_port->is_uartdm) {
+	/* Disable DMA for console to prevent PIO/DMA collisions */
+	if (msm_port->is_uartdm && !uart_console(port)) {
 		msm_request_tx_dma(msm_port, msm_port->uart.mapbase);
 		msm_request_rx_dma(msm_port, msm_port->uart.mapbase);
 	}



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0019/2077] serial: max310x: implement gpio_chip::get_direction()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (17 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0018/2077] serial: msm: Disable DMA for kernel console UART Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0020/2077] serial: 8250_omap: clear rx_running on zero-length DMA completes Greg Kroah-Hartman
                   ` (978 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Tapio Reijonen,
	Linus Walleij, Bartosz Golaszewski, Hugo Villeneuve

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tapio Reijonen <tapio.reijonen@vaisala.com>

commit a483b1a91b33b7533280e7c3efd2bc1275caef18 upstream.

It's strongly recommended for GPIO drivers to always implement the
.get_direction() callback - even when the direction is tracked in
software. The GPIO core emits a warning when the callback is missing
and a user reads the direction of a line, e.g. via
/sys/kernel/debug/gpio.

The MAX310X keeps the GPIO direction in the GPIOCFG register (a set bit
selects output), which the existing direction_input/output callbacks
already program, so the current direction can be read back directly.

Fixes: f65444187a66 ("serial: New serial driver MAX310X")
Cc: stable <stable@kernel.org>
Signed-off-by: Tapio Reijonen <tapio.reijonen@vaisala.com>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Reviewed-by: Hugo Villeneuve <hvilleneuve@dimonoff.com>
Link: https://patch.msgid.link/20260615-b4-serial-max310x-gpio-get-direction-v2-1-4704ba2b181a@vaisala.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/tty/serial/max310x.c |   12 ++++++++++++
 1 file changed, 12 insertions(+)

--- a/drivers/tty/serial/max310x.c
+++ b/drivers/tty/serial/max310x.c
@@ -1212,6 +1212,17 @@ static int max310x_gpio_set(struct gpio_
 	return 0;
 }
 
+static int max310x_gpio_get_direction(struct gpio_chip *chip, unsigned int offset)
+{
+	struct max310x_port *s = gpiochip_get_data(chip);
+	struct uart_port *port = &s->p[offset / 4].port;
+	unsigned int val;
+
+	val = max310x_port_read(port, MAX310X_GPIOCFG_REG);
+
+	return val & BIT(offset % 4) ? GPIO_LINE_DIRECTION_OUT : GPIO_LINE_DIRECTION_IN;
+}
+
 static int max310x_gpio_direction_input(struct gpio_chip *chip, unsigned int offset)
 {
 	struct max310x_port *s = gpiochip_get_data(chip);
@@ -1421,6 +1432,7 @@ static int max310x_probe(struct device *
 	s->gpio.owner		= THIS_MODULE;
 	s->gpio.parent		= dev;
 	s->gpio.label		= devtype->name;
+	s->gpio.get_direction	= max310x_gpio_get_direction;
 	s->gpio.direction_input	= max310x_gpio_direction_input;
 	s->gpio.get		= max310x_gpio_get;
 	s->gpio.direction_output= max310x_gpio_direction_output;



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0020/2077] serial: 8250_omap: clear rx_running on zero-length DMA completes
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (18 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0019/2077] serial: max310x: implement gpio_chip::get_direction() Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0021/2077] rxrpc: serialize kernel accept preallocation with socket teardown Greg Kroah-Hartman
                   ` (977 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Matthias Feser, Moteen Shah

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matthias Feser <mfe@KBSgmbhfr.onmicrosoft.com>

commit 061b627ba534230a18ec4d7251562af12325d06a upstream.

On AM33xx RX DMA only triggers when the FIFO reaches the
configured threshold (typically 48 bytes). For smaller bursts
no DMA request is issued and the FIFO is drained by RX timeout.

In this case __dma_rx_do_complete() can legitimately see count == 0.

The current code exits early in this case and does not clear
dma->rx_running, leaving the DMA state inconsistent. This can
prevent RX DMA from restarting and may cause
omap_8250_rx_dma_flush() to fail, marking DMA as broken.

Fix this by clearing dma->rx_running once the DMA transfer has
completed or been terminated, even if no data was transferred.

Fixes: a5fd8945a478 ("serial: 8250: 8250_omap.c: Clear DMA RX running status only after DMA termination is done")
Cc: stable <stable@kernel.org>
Signed-off-by: Matthias Feser <mfe@KBSgmbhfr.onmicrosoft.com>
Reviewed-by: Moteen Shah <m-shah@ti.com>
Link: https://patch.msgid.link/BE3P281MB55155F2F5795E411F5A65282EE0B2@BE3P281MB5515.DEUP281.PROD.OUTLOOK.COM
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/tty/serial/8250/8250_omap.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/tty/serial/8250/8250_omap.c
+++ b/drivers/tty/serial/8250/8250_omap.c
@@ -944,11 +944,12 @@ static void __dma_rx_do_complete(struct
 				dev_err(p->port.dev, "teardown incomplete\n");
 		}
 	}
+
+	dma->rx_running = 0;
 	if (!count)
 		goto out;
 	ret = tty_insert_flip_string(tty_port, dma->rx_buf, count);
 
-	dma->rx_running = 0;
 	p->port.icount.rx += ret;
 	p->port.icount.buf_overrun += count - ret;
 out:



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0021/2077] rxrpc: serialize kernel accept preallocation with socket teardown
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (19 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0020/2077] serial: 8250_omap: clear rx_running on zero-length DMA completes Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0022/2077] rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc Greg Kroah-Hartman
                   ` (976 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuan Tan, Yifan Wu, Juefei Pu,
	Xin Liu, Li Daming, Ren Wei, David Howells, Marc Dionne,
	Jeffrey Altman, Simon Horman, linux-afs, stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Li Daming <d4n.for.sec@gmail.com>

commit dc175389b18c29a5303ee83169ec653adfae3e17 upstream.

rxrpc_kernel_charge_accept() reads rx->backlog without any
socket/backlog synchronization and passes that raw pointer into
rxrpc_service_prealloc_one(). A concurrent rxrpc_discard_prealloc()
sets rx->backlog = NULL and frees the backlog rings, so a kernel
preallocation worker can keep using a freed struct rxrpc_backlog
while updating *_backlog_head/tail and array slots.

Serialize the state check and backlog lookup with the socket lock,
and reject kernel preallocation once teardown has disabled
listening or discarded the service backlog.

Fixes: 00e907127e6f ("rxrpc: Preallocate peers, conns and calls for incoming service requests")
Reported-by: Yuan Tan <yuantan098@gmail.com>
Reported-by: Yifan Wu <yifanwucs@gmail.com>
Reported-by: Juefei Pu <tomapufckgml@gmail.com>
Reported-by: Xin Liu <bird@lzu.edu.cn>
Signed-off-by: Li Daming <d4n.for.sec@gmail.com>
Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260609140911.838677-6-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/call_accept.c |   25 +++++++++++++++++++------
 1 file changed, 19 insertions(+), 6 deletions(-)

--- a/net/rxrpc/call_accept.c
+++ b/net/rxrpc/call_accept.c
@@ -471,13 +471,26 @@ int rxrpc_kernel_charge_accept(struct so
 			       unsigned long user_call_ID, gfp_t gfp,
 			       unsigned int debug_id)
 {
-	struct rxrpc_sock *rx = rxrpc_sk(sock->sk);
-	struct rxrpc_backlog *b = rx->backlog;
+	struct rxrpc_backlog *b;
+	struct rxrpc_sock *rx;
+	struct sock *sk;
+	int ret;
 
-	if (sock->sk->sk_state == RXRPC_CLOSE)
-		return -ESHUTDOWN;
+	sk = sock->sk;
+	rx = rxrpc_sk(sk);
 
-	return rxrpc_service_prealloc_one(rx, b, notify_rx, user_call_ID,
-					  gfp, debug_id);
+	lock_sock(sk);
+	if (sk->sk_state != RXRPC_SERVER_LISTENING || !rx->backlog) {
+		ret = -ESHUTDOWN;
+		goto out;
+	}
+
+	b = rx->backlog;
+	ret = rxrpc_service_prealloc_one(rx, b, notify_rx, user_call_ID,
+					 gfp, debug_id);
+
+out:
+	release_sock(sk);
+	return ret;
 }
 EXPORT_SYMBOL(rxrpc_kernel_charge_accept);



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0022/2077] rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (20 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0021/2077] rxrpc: serialize kernel accept preallocation with socket teardown Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0023/2077] rxrpc: Dont move a peeked OOB message onto the pending queue Greg Kroah-Hartman
                   ` (975 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Simon Horman, Jeffrey Altman,
	David Howells, Jiayuan Chen, Marc Dionne, linux-afs, stable,
	Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jeffrey Altman <jaltman@auristor.com>

commit 16c8ae9735c5bd7e54dd7478d6348e0fc860842d upstream.

rxrpc_recvmsg_data() calls rxrpc_verify_data() whenever the
rxrpc_call.rx_dec_buffer is unallocated and assumes that upon
successful return that rx_dec_buffer must be allocated.
However, rxrpc_verify_data() does not request an allocation if
the rxrpc_skb_priv.len is zero.

In addition, failure to allocate rx_dec_buffer will result in a
call to skb_copy_bits() with a NULL destination which can
trigger a NULL pointer dereference.

To prevent these issues rxrpc_verify_data() is modified to
always attempt to allocate the rxrpc_call.rx_dec_buffer if it
is NULL.

This issue was identified with assistance of a private
sashiko instance.

Fixes: d2bc90cf6c75cb ("rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg")
Reported-by: Simon Horman <simon.horman@redhat.com>
Signed-off-by: Jeffrey Altman <jaltman@auristor.com>
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Jiayuan Chen <jiayuan.chen@linux.dev>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260609140911.838677-2-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/recvmsg.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/net/rxrpc/recvmsg.c
+++ b/net/rxrpc/recvmsg.c
@@ -161,7 +161,7 @@ static int rxrpc_verify_data(struct rxrp
 	struct rxrpc_skb_priv *sp = rxrpc_skb(skb);
 	int ret;
 
-	if (sp->len > call->rx_dec_bsize) {
+	if (sp->len > call->rx_dec_bsize || !call->rx_dec_buffer) {
 		/* Make sure we can hold a 1412-byte jumbo subpacket and make
 		 * sure that the buffer size is aligned to a crypto blocksize.
 		 */



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0023/2077] rxrpc: Dont move a peeked OOB message onto the pending queue
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (21 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0022/2077] rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0024/2077] rxrpc: Fix UAF in rxgk_issue_challenge() Greg Kroah-Hartman
                   ` (974 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hyunwoo Kim, David Howells,
	Marc Dionne, Simon Horman, linux-afs, stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hyunwoo Kim <imv4bel@gmail.com>

commit 5801cff7d5d7b4e9d877dfb627b23eb63167f02c upstream.

rxrpc_recvmsg_oob() takes a received oob message off recvmsg_oobq and,
if a response is needed, moves it onto the pending_oobq tree. However,
only the unlink from recvmsg_oobq is guarded by MSG_PEEK; the move onto
pending_oobq always runs.

As a result, reading a challenge with MSG_PEEK leaves the skb on
recvmsg_oobq while also adding it to pending_oobq. Since struct
sk_buff's rbnode shares storage with its next and prev pointers,
rb_insert_color() overwrites the list linkage, and the skb, which holds
a single reference, becomes reachable from both queues at once.

When the socket is closed both queues are drained in turn. While
draining recvmsg_oobq, __skb_unlink() follows the next and prev
pointers that rbnode has overwritten and writes to a bad address. Also,
as the skb holds a single reference but is freed from each queue, both
the skb and the connection reference it holds are released twice. This
leads to memory corruption and to a use-after-free caused by the
connection refcount underflow.

MSG_PEEK does not consume the message from the queue, so only unlink it
from recvmsg_oobq and then move it onto pending_oobq or free it when
the message is actually consumed.

Fixes: 5800b1cf3fd8 ("rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE")
Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260609140911.838677-3-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/recvmsg.c |   11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

--- a/net/rxrpc/recvmsg.c
+++ b/net/rxrpc/recvmsg.c
@@ -262,12 +262,13 @@ static int rxrpc_recvmsg_oob(struct sock
 		break;
 	}
 
-	if (!(flags & MSG_PEEK))
+	if (!(flags & MSG_PEEK)) {
 		skb_unlink(skb, &rx->recvmsg_oobq);
-	if (need_response)
-		rxrpc_add_pending_oob(rx, skb);
-	else
-		rxrpc_free_skb(skb, rxrpc_skb_put_oob);
+		if (need_response)
+			rxrpc_add_pending_oob(rx, skb);
+		else
+			rxrpc_free_skb(skb, rxrpc_skb_put_oob);
+	}
 	return ret;
 }
 



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0024/2077] rxrpc: Fix UAF in rxgk_issue_challenge()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (22 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0023/2077] rxrpc: Dont move a peeked OOB message onto the pending queue Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0025/2077] rxrpc: Fix socket notification race Greg Kroah-Hartman
                   ` (973 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Marc Dionne, David Howells,
	Simon Horman, linux-afs, stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit 107a4cb0d47e735830f852d83970d5c81f8e1e08 upstream.

Fix rxgk_issue_challenge() to free the page containing the challenge
content after invoking the tracepoint as the whdr passed to the tracepoint
points into the page just freed.

Fixes: 9d1d2b59341f ("rxrpc: rxgk: Implement the yfs-rxgk security class (GSSAPI)")
Reported-by: Marc Dionne <marc.dionne@auristor.com>
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260609140911.838677-4-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/rxgk.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/net/rxrpc/rxgk.c
+++ b/net/rxrpc/rxgk.c
@@ -687,16 +687,17 @@ static int rxgk_issue_challenge(struct r
 	ret = do_udp_sendmsg(conn->local->socket, &msg, len);
 	if (ret > 0)
 		rxrpc_peer_mark_tx(conn->peer);
-	__free_page(page);
 
 	if (ret < 0) {
 		trace_rxrpc_tx_fail(conn->debug_id, serial, ret,
 				    rxrpc_tx_point_rxgk_challenge);
+		__free_page(page);
 		return -EAGAIN;
 	}
 
 	trace_rxrpc_tx_packet(conn->debug_id, whdr,
 			      rxrpc_tx_point_rxgk_challenge);
+	__free_page(page);
 	_leave(" = 0");
 	return 0;
 }



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0025/2077] rxrpc: Fix socket notification race
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (23 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0024/2077] rxrpc: Fix UAF in rxgk_issue_challenge() Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0026/2077] rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) Greg Kroah-Hartman
                   ` (972 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Howells, Marc Dionne,
	Jeffrey Altman, Simon Horman, linux-afs, stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit e66f8f32f50116670dbbee5bc9e692cd2cd0c8f8 upstream.

There's a race between rxrpc_recvmsg() and rxrpc_notify_socket(), whereby
the latter's attempt to avoid disabling interrupts and taking the socket's
recvmsg_lock if the call is already queued may happen simultaneously with
the former's discarding of a call that has nothing queued.

Fix this by removing the shortcut.  Note that this only affects userspace's
use of AF_RXRPC; the AFS filesystem driver doesn't use the socket queue.

Fixes: 248f219cb8bc ("rxrpc: Rewrite the data and ack handling code")
Link: https://sashiko.dev/#/patchset/20260616155749.2125907-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260624163819.3017002-10-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/recvmsg.c |    2 --
 1 file changed, 2 deletions(-)

--- a/net/rxrpc/recvmsg.c
+++ b/net/rxrpc/recvmsg.c
@@ -27,8 +27,6 @@ void rxrpc_notify_socket(struct rxrpc_ca
 
 	_enter("%d", call->debug_id);
 
-	if (!list_empty(&call->recvmsg_link))
-		return;
 	if (test_bit(RXRPC_CALL_RELEASED, &call->flags)) {
 		rxrpc_see_call(call, rxrpc_call_see_notify_released);
 		return;



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0026/2077] rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (24 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0025/2077] rxrpc: Fix socket notification race Greg Kroah-Hartman
@ 2026-07-21 14:54 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0027/2077] rxrpc: Fix potential infinite loop in rxrpc_recvmsg() Greg Kroah-Hartman
                   ` (971 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:54 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Howells, Marc Dionne,
	Jeffrey Altman, Simon Horman, linux-afs, stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit 4bdb9e471f5b1ac9cbe4add5de7ff085a0ec303c upstream.

Fix rxrpc_recvmsg() to also drop the ref it holds on an already-released
call if MSG_PEEK is in force (the function holds a ref on the call
irrespective of whether MSG_PEEK is specified or not).

Fixes: 962fb1f651c2 ("rxrpc: Fix recv-recv race of completed call")
Link: https://sashiko.dev/#/patchset/20260616155749.2125907-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260624163819.3017002-11-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/recvmsg.c |    3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

--- a/net/rxrpc/recvmsg.c
+++ b/net/rxrpc/recvmsg.c
@@ -528,8 +528,7 @@ try_again:
 	if (test_bit(RXRPC_CALL_RELEASED, &call->flags)) {
 		rxrpc_see_call(call, rxrpc_call_see_already_released);
 		mutex_unlock(&call->user_mutex);
-		if (!(flags & MSG_PEEK))
-			rxrpc_put_call(call, rxrpc_call_put_recvmsg);
+		rxrpc_put_call(call, rxrpc_call_put_recvmsg);
 		goto try_again;
 	}
 



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0027/2077] rxrpc: Fix potential infinite loop in rxrpc_recvmsg()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (25 preceding siblings ...)
  2026-07-21 14:54 ` [PATCH 7.1 0026/2077] rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0028/2077] rxrpc: Fix rxrpc_rotate_tx_rotate() to check theres something to rotate Greg Kroah-Hartman
                   ` (970 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Howells, Marc Dionne,
	Jeffrey Altman, Simon Horman, linux-afs, stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit 67a0332f442ef07713cd2d9c13d59db0f1c23648 upstream.

Fix the wait in rxrpc_recvmsg() also take check the oob queue.

Fixes: 5800b1cf3fd8 ("rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE")
Link: https://sashiko.dev/#/patchset/20260616155749.2125907-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260624163819.3017002-9-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/recvmsg.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/net/rxrpc/recvmsg.c
+++ b/net/rxrpc/recvmsg.c
@@ -436,7 +436,8 @@ try_again:
 		return -EAGAIN;
 	}
 
-	if (list_empty(&rx->recvmsg_q)) {
+	if (list_empty(&rx->recvmsg_q) &&
+	    skb_queue_empty_lockless(&rx->recvmsg_oobq)) {
 		ret = -EWOULDBLOCK;
 		if (timeo == 0) {
 			call = NULL;



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0028/2077] rxrpc: Fix rxrpc_rotate_tx_rotate() to check theres something to rotate
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (26 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0027/2077] rxrpc: Fix potential infinite loop in rxrpc_recvmsg() Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0029/2077] rxrpc: Fix oob challenge leak in cleanup after notification failure Greg Kroah-Hartman
                   ` (969 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Howells, Marc Dionne,
	Jeffrey Altman, Simon Horman, linux-afs, stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit a5462da5a349fc7f17ad5ebd899380260d03e7ed upstream.

Fix rxrpc_rotate_tx_rotate() to check that there's something in the
transmission buffer to be rotated before it attempts to rotate anything.

Fixes: b341a0263b1b ("rxrpc: Implement progressive transmission queue struct")
Link: https://sashiko.dev/#/patchset/20260618134802.2477777-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260624163819.3017002-12-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/input.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/net/rxrpc/input.c
+++ b/net/rxrpc/input.c
@@ -236,6 +236,9 @@ static bool rxrpc_rotate_tx_window(struc
 		call->acks_lowest_nak = to;
 	}
 
+	if (after(seq, to))
+		return false;
+
 	/* We may have a left over fully-consumed buffer at the front that we
 	 * couldn't drop before (rotate_and_keep below).
 	 */



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0029/2077] rxrpc: Fix oob challenge leak in cleanup after notification failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (27 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0028/2077] rxrpc: Fix rxrpc_rotate_tx_rotate() to check theres something to rotate Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0030/2077] rxrpc: Fix ACKALL packet handling Greg Kroah-Hartman
                   ` (968 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Howells, Marc Dionne,
	Jeffrey Altman, Simon Horman, linux-afs, stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit 092275882aec4a70ba55c3efb66fff947c81656a upstream.

Fix rxrpc_notify_socket_oob() to return an indication of failure in the
event that it failed to queue a packet and fix rxrpc_post_challenge() to
clean up the connection ref in such an event.

Fixes: 5800b1cf3fd8 ("rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE")
Link: https://sashiko.dev/#/patchset/20260616155749.2125907-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260624163819.3017002-8-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/ar-internal.h |    4 ++--
 net/rxrpc/conn_event.c  |    9 +++++++--
 net/rxrpc/oob.c         |    7 +++++--
 3 files changed, 14 insertions(+), 6 deletions(-)

--- a/net/rxrpc/ar-internal.h
+++ b/net/rxrpc/ar-internal.h
@@ -1355,9 +1355,9 @@ static inline struct rxrpc_net *rxrpc_ne
 }
 
 /*
- * out_of_band.c
+ * oob.c
  */
-void rxrpc_notify_socket_oob(struct rxrpc_call *call, struct sk_buff *skb);
+bool rxrpc_notify_socket_oob(struct rxrpc_call *call, struct sk_buff *skb);
 void rxrpc_add_pending_oob(struct rxrpc_sock *rx, struct sk_buff *skb);
 int rxrpc_sendmsg_oob(struct rxrpc_sock *rx, struct msghdr *msg, size_t len);
 
--- a/net/rxrpc/conn_event.c
+++ b/net/rxrpc/conn_event.c
@@ -436,7 +436,7 @@ static bool rxrpc_post_challenge(struct
 	struct rxrpc_skb_priv *sp = rxrpc_skb(skb);
 	struct rxrpc_call *call = NULL;
 	struct rxrpc_sock *rx;
-	bool respond = false;
+	bool respond = false, queued = false;
 
 	sp->chall.conn =
 		rxrpc_get_connection(conn, rxrpc_conn_get_challenge_input);
@@ -472,8 +472,13 @@ static bool rxrpc_post_challenge(struct
 	}
 
 	if (call)
-		rxrpc_notify_socket_oob(call, skb);
+		queued = rxrpc_notify_socket_oob(call, skb);
 	rcu_read_unlock();
+	if (call && !queued) {
+		rxrpc_put_connection(conn, rxrpc_conn_put_challenge_input);
+		sp->chall.conn = NULL;
+		return false;
+	}
 
 	if (!call)
 		rxrpc_post_packet_to_conn(conn, skb);
--- a/net/rxrpc/oob.c
+++ b/net/rxrpc/oob.c
@@ -32,11 +32,12 @@ struct rxrpc_oob_params {
  * Post an out-of-band message for attention by the socket or kernel service
  * associated with a reference call.
  */
-void rxrpc_notify_socket_oob(struct rxrpc_call *call, struct sk_buff *skb)
+bool rxrpc_notify_socket_oob(struct rxrpc_call *call, struct sk_buff *skb)
 {
 	struct rxrpc_skb_priv *sp = rxrpc_skb(skb);
 	struct rxrpc_sock *rx;
 	struct sock *sk;
+	bool queued = false;
 
 	rcu_read_lock();
 
@@ -49,6 +50,7 @@ void rxrpc_notify_socket_oob(struct rxrp
 			skb->skb_mstamp_ns = rx->oob_id_counter++;
 			rxrpc_get_skb(skb, rxrpc_skb_get_post_oob);
 			skb_queue_tail(&rx->recvmsg_oobq, skb);
+			queued = true;
 
 			trace_rxrpc_notify_socket(call->debug_id, sp->hdr.serial);
 			if (rx->app_ops)
@@ -56,11 +58,12 @@ void rxrpc_notify_socket_oob(struct rxrp
 		}
 
 		spin_unlock_irq(&rx->recvmsg_lock);
-		if (!rx->app_ops && !sock_flag(sk, SOCK_DEAD))
+		if (queued && !rx->app_ops && !sock_flag(sk, SOCK_DEAD))
 			sk->sk_data_ready(sk);
 	}
 
 	rcu_read_unlock();
+	return queued;
 }
 
 /*



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0030/2077] rxrpc: Fix ACKALL packet handling
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (28 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0029/2077] rxrpc: Fix oob challenge leak in cleanup after notification failure Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0031/2077] rxrpc: Fix the reception of a reply packet before data transmission Greg Kroah-Hartman
                   ` (967 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuan Tan, Yifan Wu, Juefei Pu,
	Zhengchuan Liang, Xin Liu, Wyatt Feng, David Howells, Ren Wei,
	Marc Dionne, linux-afs, Jeffrey Altman, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wyatt Feng <bronzed_45_vested@icloud.com>

commit 9b6ce594808580b2a19e6e1aa459ef56c0153ac1 upstream.

rxrpc_input_ackall() accepts ACKALL packets without checking whether the
call is in a state that can legitimately have outstanding transmit buffers.
A forged ACKALL can therefore reach a new service call in
RXRPC_CALL_SERVER_RECV_REQUEST before any reply packets have been queued.

In that state call->tx_top is zero and call->tx_queue is NULL, so
rxrpc_rotate_tx_window() dereferences a NULL txqueue and triggers a
null-pointer dereference.

Fix the handling of ACKALL packets by the following means:

 (1) Add two new call states: RXRPC_CALL_CLIENT_PRE_SEND which indicates
     that the client call is connected, but nothing has been transmitted as
     yet; and RXRPC_CALL_CLIENT_AWAIT_ACK, which indicates that everything
     has been transmitted at least once, but we're now waiting for the
     stuff remaining in the Tx buffer to be ACK'd (retransmissions may
     still happen).

     The RXRPC_CALL_CLIENT_PRE_SEND state is set when the call is assigned
     a channel and transitions to RXRPC_CALL_CLIENT_SEND_REQUEST when the
     first packet is transmitted.

     RXRPC_CALL_CLIENT_AWAIT_REPLY is then narrowed in scope to indicate
     that all Tx packets have been ACK'd and we're now waiting for the
     reply to be received.

 (2) As per Wyatt Feng's original patch[1], the ACKALL handler then checks
     that the call state is one in which there might be stuff in the Tx
     buffer to ACK, but now this includes AWAIT_ACK rather than
     AWAIT_REPLY.  ACKALL packets are ignored if received in the wrong
     state.

     Note that unlike Wyatt Feng's patch, it's no longer necessary to check
     to see if the Tx buffer exists as this the state set now covers this.

 (3) Make the ACKALL handler use call->tx_transmitted rather than
     call->tx_top as the former is explicitly the highest packet seq number
     transmitted, whereas the latter has a looser definition.

Thanks to Jeffrey Altman for a description of the history of the ACKALL
packet[1].

Fixes: b341a0263b1b ("rxrpc: Implement progressive transmission queue struct")
Reported-by: Yuan Tan <yuantan098@gmail.com>
Reported-by: Yifan Wu <yifanwucs@gmail.com>
Reported-by: Juefei Pu <tomapufckgml@gmail.com>
Reported-by: Zhengchuan Liang <zcliangcn@gmail.com>
Reported-by: Xin Liu <bird@lzu.edu.cn>
Signed-off-by: Wyatt Feng <bronzed_45_vested@icloud.com>
Co-developed-by: David Howells <dhowells@redhat.com>
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Ren Wei <n05ec@lzu.edu.cn>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: linux-afs@lists.infradead.org
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/r/20260616155749.2125907-2-dhowells@redhat.com/ [1]
Link: https://lore.kernel.org/r/c0fd4fec-1576-4070-b31e-a37d5506f5ed@auristor.com/ [2]
Reviewed-by: Jeffrey Altman <jaltman@auristor.com>
Link: https://patch.msgid.link/20260624163819.3017002-2-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/ar-internal.h |    2 ++
 net/rxrpc/call_event.c  |    5 ++++-
 net/rxrpc/call_object.c |    2 ++
 net/rxrpc/conn_client.c |    2 +-
 net/rxrpc/input.c       |   23 +++++++++++++++++++----
 net/rxrpc/sendmsg.c     |    3 ++-
 6 files changed, 30 insertions(+), 7 deletions(-)

--- a/net/rxrpc/ar-internal.h
+++ b/net/rxrpc/ar-internal.h
@@ -650,7 +650,9 @@ enum rxrpc_call_event {
 enum rxrpc_call_state {
 	RXRPC_CALL_UNINITIALISED,
 	RXRPC_CALL_CLIENT_AWAIT_CONN,	/* - client waiting for connection to become available */
+	RXRPC_CALL_CLIENT_PRE_SEND,	/* - client is connected, but hasn't sent anything yet */
 	RXRPC_CALL_CLIENT_SEND_REQUEST,	/* - client sending request phase */
+	RXRPC_CALL_CLIENT_AWAIT_ACK,	/* - client awaiting ACKs of request */
 	RXRPC_CALL_CLIENT_AWAIT_REPLY,	/* - client awaiting reply */
 	RXRPC_CALL_CLIENT_RECV_REPLY,	/* - client receiving reply phase */
 	RXRPC_CALL_SERVER_PREALLOC,	/* - service preallocation */
--- a/net/rxrpc/call_event.c
+++ b/net/rxrpc/call_event.c
@@ -178,7 +178,7 @@ static void rxrpc_close_tx_phase(struct
 
 	switch (__rxrpc_call_state(call)) {
 	case RXRPC_CALL_CLIENT_SEND_REQUEST:
-		rxrpc_set_call_state(call, RXRPC_CALL_CLIENT_AWAIT_REPLY);
+		rxrpc_set_call_state(call, RXRPC_CALL_CLIENT_AWAIT_ACK);
 		break;
 	case RXRPC_CALL_SERVER_SEND_REPLY:
 		rxrpc_set_call_state(call, RXRPC_CALL_SERVER_AWAIT_ACK);
@@ -244,6 +244,8 @@ static void rxrpc_transmit_fresh_data(st
 				break;
 		} while (req.n < limit && before(seq, send_top));
 
+		if (__rxrpc_call_state(call) == RXRPC_CALL_CLIENT_PRE_SEND)
+			rxrpc_set_call_state(call, RXRPC_CALL_CLIENT_SEND_REQUEST);
 		if (txb->flags & RXRPC_LAST_PACKET) {
 			rxrpc_close_tx_phase(call);
 			tq = NULL;
@@ -267,6 +269,7 @@ void rxrpc_transmit_some_data(struct rxr
 		fallthrough;
 
 	case RXRPC_CALL_SERVER_SEND_REPLY:
+	case RXRPC_CALL_CLIENT_PRE_SEND:
 	case RXRPC_CALL_CLIENT_SEND_REQUEST:
 		if (!rxrpc_tx_window_space(call))
 			return;
--- a/net/rxrpc/call_object.c
+++ b/net/rxrpc/call_object.c
@@ -18,7 +18,9 @@
 const char *const rxrpc_call_states[NR__RXRPC_CALL_STATES] = {
 	[RXRPC_CALL_UNINITIALISED]		= "Uninit  ",
 	[RXRPC_CALL_CLIENT_AWAIT_CONN]		= "ClWtConn",
+	[RXRPC_CALL_CLIENT_PRE_SEND]		= "ClPreSnd",
 	[RXRPC_CALL_CLIENT_SEND_REQUEST]	= "ClSndReq",
+	[RXRPC_CALL_CLIENT_AWAIT_ACK]		= "ClAwtAck",
 	[RXRPC_CALL_CLIENT_AWAIT_REPLY]		= "ClAwtRpl",
 	[RXRPC_CALL_CLIENT_RECV_REPLY]		= "ClRcvRpl",
 	[RXRPC_CALL_SERVER_PREALLOC]		= "SvPrealc",
--- a/net/rxrpc/conn_client.c
+++ b/net/rxrpc/conn_client.c
@@ -449,7 +449,7 @@ static void rxrpc_activate_one_channel(s
 	trace_rxrpc_connect_call(call);
 	call->tx_last_sent = ktime_get_real();
 	rxrpc_start_call_timer(call);
-	rxrpc_set_call_state(call, RXRPC_CALL_CLIENT_SEND_REQUEST);
+	rxrpc_set_call_state(call, RXRPC_CALL_CLIENT_PRE_SEND);
 	wake_up(&call->waitq);
 }
 
--- a/net/rxrpc/input.c
+++ b/net/rxrpc/input.c
@@ -181,7 +181,8 @@ void rxrpc_congestion_degrade(struct rxr
 	if (call->cong_ca_state != RXRPC_CA_SLOW_START &&
 	    call->cong_ca_state != RXRPC_CA_CONGEST_AVOIDANCE)
 		return;
-	if (__rxrpc_call_state(call) == RXRPC_CALL_CLIENT_AWAIT_REPLY)
+	if (__rxrpc_call_state(call) == RXRPC_CALL_CLIENT_AWAIT_ACK ||
+	    __rxrpc_call_state(call) == RXRPC_CALL_CLIENT_AWAIT_REPLY)
 		return;
 
 	rtt = ns_to_ktime(call->srtt_us * (NSEC_PER_USEC / 8));
@@ -359,6 +360,7 @@ static void rxrpc_end_tx_phase(struct rx
 
 	switch (__rxrpc_call_state(call)) {
 	case RXRPC_CALL_CLIENT_SEND_REQUEST:
+	case RXRPC_CALL_CLIENT_AWAIT_ACK:
 	case RXRPC_CALL_CLIENT_AWAIT_REPLY:
 		if (reply_begun) {
 			rxrpc_set_call_state(call, RXRPC_CALL_CLIENT_RECV_REPLY);
@@ -697,6 +699,7 @@ static void rxrpc_input_data(struct rxrp
 
 	switch (__rxrpc_call_state(call)) {
 	case RXRPC_CALL_CLIENT_SEND_REQUEST:
+	case RXRPC_CALL_CLIENT_AWAIT_ACK:
 	case RXRPC_CALL_CLIENT_AWAIT_REPLY:
 		/* Received data implicitly ACKs all of the request
 		 * packets we sent when we're acting as a client.
@@ -1157,10 +1160,12 @@ static void rxrpc_input_ack(struct rxrpc
 	if (hard_ack + 1 == 0)
 		return rxrpc_proto_abort(call, 0, rxrpc_eproto_ackr_zero);
 
-	/* Ignore ACKs unless we are or have just been transmitting. */
+	/* Ignore ACKs unless we are transmitting or are waiting for
+	 * acknowledgement of the packets we've just been transmitting.
+	 */
 	switch (__rxrpc_call_state(call)) {
 	case RXRPC_CALL_CLIENT_SEND_REQUEST:
-	case RXRPC_CALL_CLIENT_AWAIT_REPLY:
+	case RXRPC_CALL_CLIENT_AWAIT_ACK:
 	case RXRPC_CALL_SERVER_SEND_REPLY:
 	case RXRPC_CALL_SERVER_AWAIT_ACK:
 		break;
@@ -1218,7 +1223,17 @@ static void rxrpc_input_ackall(struct rx
 {
 	struct rxrpc_ack_summary summary = { 0 };
 
-	if (rxrpc_rotate_tx_window(call, call->tx_top, &summary))
+	switch (__rxrpc_call_state(call)) {
+	case RXRPC_CALL_CLIENT_SEND_REQUEST:
+	case RXRPC_CALL_CLIENT_AWAIT_ACK:
+	case RXRPC_CALL_SERVER_SEND_REPLY:
+	case RXRPC_CALL_SERVER_AWAIT_ACK:
+		break;
+	default:
+		return;
+	}
+
+	if (rxrpc_rotate_tx_window(call, call->tx_transmitted, &summary))
 		rxrpc_end_tx_phase(call, false, rxrpc_eproto_unexpected_ackall);
 }
 
--- a/net/rxrpc/sendmsg.c
+++ b/net/rxrpc/sendmsg.c
@@ -366,7 +366,8 @@ reload:
 	if (state >= RXRPC_CALL_COMPLETE)
 		goto maybe_error;
 	ret = -EPROTO;
-	if (state != RXRPC_CALL_CLIENT_SEND_REQUEST &&
+	if (state != RXRPC_CALL_CLIENT_PRE_SEND &&
+	    state != RXRPC_CALL_CLIENT_SEND_REQUEST &&
 	    state != RXRPC_CALL_SERVER_ACK_REQUEST &&
 	    state != RXRPC_CALL_SERVER_SEND_REPLY) {
 		/* Request phase complete for this client call */



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0031/2077] rxrpc: Fix the reception of a reply packet before data transmission
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (29 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0030/2077] rxrpc: Fix ACKALL packet handling Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0032/2077] rxrpc: Fix leak of connection from OOB challenge Greg Kroah-Hartman
                   ` (966 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Howells, Marc Dionne,
	Jeffrey Altman, Simon Horman, linux-afs, stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit a58e33405acd2584e730c1da72635f822ada6b49 upstream.

Fix rxrpc_receiving_reply() to handle the reception of an apparent reply
DATA packet before rxrpc has had a chance to send any request DATA packets
on a client call by checking to see if the call has been exposed yet by
sending the first packet.

Without this, rxrpc_rotate_tx_window() might oops.

Also fix rxrpc_rotate_tx_window() to handle the Tx queue being empty by
changing the do...while loop into a while loop, just in case a call is
abnormally terminated by an early reply before the last request packet is
transmitted.

Fixes: b341a0263b1b ("rxrpc: Implement progressive transmission queue struct")
Link: https://sashiko.dev/#/patchset/20260616155749.2125907-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260624163819.3017002-7-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/input.c |   13 ++++++++++---
 1 file changed, 10 insertions(+), 3 deletions(-)

--- a/net/rxrpc/input.c
+++ b/net/rxrpc/input.c
@@ -251,7 +251,7 @@ static bool rxrpc_rotate_tx_window(struc
 		tq = call->tx_queue;
 	}
 
-	do {
+	while (before_eq(seq, to)) {
 		unsigned int ix = seq - call->tx_qbase;
 
 		_debug("tq=%x seq=%x i=%d f=%x", tq->qbase, seq, ix, tq->bufs[ix]->flags);
@@ -321,8 +321,7 @@ static bool rxrpc_rotate_tx_window(struc
 				break;
 			}
 		}
-
-	} while (before_eq(seq, to));
+	}
 
 	if (trace)
 		trace_rxrpc_rack_update(call, summary);
@@ -397,6 +396,14 @@ static bool rxrpc_receiving_reply(struct
 		trace_rxrpc_timer_can(call, rxrpc_timer_trace_delayed_ack);
 	}
 
+	/* Deal with an apparent reply coming in before we've got the request
+	 * queued or transmitted.
+	 */
+	if (!test_bit(RXRPC_CALL_EXPOSED, &call->flags)) {
+		rxrpc_proto_abort(call, top, rxrpc_eproto_early_reply);
+		return false;
+	}
+
 	if (!test_bit(RXRPC_CALL_TX_LAST, &call->flags)) {
 		if (!rxrpc_rotate_tx_window(call, top, &summary)) {
 			rxrpc_proto_abort(call, top, rxrpc_eproto_early_reply);



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0032/2077] rxrpc: Fix leak of connection from OOB challenge
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (30 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0031/2077] rxrpc: Fix the reception of a reply packet before data transmission Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0033/2077] rxrpc: Fix double unlock in rxrpc_recvmsg() Greg Kroah-Hartman
                   ` (965 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Howells, Marc Dionne,
	Simon Horman, linux-afs, stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit 4b28876e78fd60979afa91fd2ec6ad9cc8b7a6d0 upstream.

Fix leak of connection object from OOB challenge queue when response is
provided by userspace.

Fixes: 5800b1cf3fd8 ("rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE")
Link: https://sashiko.dev/#/patchset/20260609140911.838677-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260624163819.3017002-3-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/oob.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/net/rxrpc/oob.c
+++ b/net/rxrpc/oob.c
@@ -213,6 +213,11 @@ static int rxrpc_respond_to_oob(struct r
 		break;
 	}
 
+	switch (skb->mark) {
+	case RXRPC_OOB_CHALLENGE:
+		rxrpc_put_connection(sp->chall.conn, rxrpc_conn_put_oob);
+		break;
+	}
 	rxrpc_free_skb(skb, rxrpc_skb_put_oob);
 	return ret;
 }



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0033/2077] rxrpc: Fix double unlock in rxrpc_recvmsg()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (31 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0032/2077] rxrpc: Fix leak of connection from OOB challenge Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0034/2077] afs: Fix netns teardown to cancel the preallocation charger Greg Kroah-Hartman
                   ` (964 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Howells, Marc Dionne,
	Simon Horman, linux-afs, stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit a2f299b4d5510147fa8629a6aba2869bbcc88aea upstream.

Fix a double unlock in rxrpc_recvmsg() when dealing with OOB messages.

Fixes: 5800b1cf3fd8 ("rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE")
Link: https://sashiko.dev/#/patchset/20260609140911.838677-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260624163819.3017002-4-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/rxrpc/recvmsg.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/net/rxrpc/recvmsg.c
+++ b/net/rxrpc/recvmsg.c
@@ -470,7 +470,7 @@ try_again:
 		release_sock(&rx->sk);
 		if (ret == -EAGAIN)
 			goto try_again;
-		goto error_no_call;
+		goto error_trace;
 	}
 
 	/* Find the next call and dequeue it if we're not just peeking.  If we



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0034/2077] afs: Fix netns teardown to cancel the preallocation charger
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (32 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0033/2077] rxrpc: Fix double unlock in rxrpc_recvmsg() Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0035/2077] afs: fix NULL pointer dereference in afs_get_tree() Greg Kroah-Hartman
                   ` (963 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Simon Horman, David Howells,
	Li Daming, Ren Wei, Marc Dionne, Jeffrey Altman, linux-afs,
	stable, Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit 47694fbc9d24ab6bf210f91e8efe06a10a478064 upstream.

Fix the teardown of an afs network namespace to make sure it cancels the
work item that keeps the preallocated rxrpc call/conn/peer queue charged
before incoming calls are disabled (i.e. listen 0).

Also, if net->live is false because the afs netns is being deleted, make
afs_charge_preallocation() skip charging and make afs_rx_new_call() avoid
requeuing the charger.

(This was found by AI review).

Fixes: 00e907127e6f ("rxrpc: Preallocate peers, conns and calls for incoming service requests")
Reported-by: Simon Horman <horms@kernel.org>
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Li Daming <d4n.for.sec@gmail.com>
cc: Ren Wei <n05ec@lzu.edu.cn>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260609140911.838677-5-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/afs/rxrpc.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/fs/afs/rxrpc.c
+++ b/fs/afs/rxrpc.c
@@ -127,6 +127,7 @@ void afs_close_socket(struct afs_net *ne
 {
 	_enter("");
 
+	cancel_work_sync(&net->charge_preallocation_work);
 	kernel_listen(net->socket, 0);
 	flush_workqueue(afs_async_calls);
 
@@ -742,7 +743,7 @@ void afs_charge_preallocation(struct wor
 		container_of(work, struct afs_net, charge_preallocation_work);
 	struct afs_call *call = net->spare_incoming_call;
 
-	for (;;) {
+	while (READ_ONCE(net->live)) {
 		if (!call) {
 			call = afs_alloc_call(net, &afs_RXCMxxxx, GFP_KERNEL);
 			if (!call)
@@ -792,7 +793,8 @@ static void afs_rx_new_call(struct sock
 	if (!call->server)
 		trace_afs_cm_no_server(call, rxrpc_kernel_remote_srx(call->peer));
 
-	queue_work(afs_wq, &net->charge_preallocation_work);
+	if (net->live)
+		queue_work(afs_wq, &net->charge_preallocation_work);
 }
 
 /*



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0035/2077] afs: fix NULL pointer dereference in afs_get_tree()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (33 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0034/2077] afs: Fix netns teardown to cancel the preallocation charger Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0036/2077] afs: handle CB.InitCallBackState3 requests without a server record Greg Kroah-Hartman
                   ` (962 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Matvey Kovalev, David Howells,
	Marc Dionne, linux-afs, Christian Brauner (Amutable)

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matvey Kovalev <matvey.kovalev@ispras.ru>

commit 0b70716081c6462be9b2928ad736d0d527b09678 upstream.

afs_alloc_sbi() uses kzalloc for memory allocation. And, if
ctx->dyn_root is not null, as->cell and as->volume are null.
In trace_afs_get_tree() they are dereferenced.

KASAN error message:

KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1
04/01/2014
RIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550
include/trace/events/afs.h:1365

Call Trace:
trace_afs_get_tree include/trace/events/afs.h:1365 [inline]
afs_get_tree+0x922/0x1350 fs/afs/super.c:599
vfs_get_tree+0x8e/0x300 fs/super.c:1572
do_new_mount fs/namespace.c:3011 [inline]
path_mount+0x14a5/0x2220 fs/namespace.c:3341
do_mount fs/namespace.c:3354 [inline]
__do_sys_mount fs/namespace.c:3562 [inline]
__se_sys_mount fs/namespace.c:3539 [inline]
__x64_sys_mount+0x283/0x300 fs/namespace.c:3539
 do_syscall_64+0x33/0x50 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x67/0xd1

Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

Fixes: 80548b03991f5 ("afs: Add more tracepoints")
Cc: stable@vger.kernel.org
Signed-off-by: Matvey Kovalev <matvey.kovalev@ispras.ru>
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://patch.msgid.link/20260622090856.2746629-4-dhowells@redhat.com
cc: Marc Dionne <marc.dionne@auristor.com>
cc: linux-afs@lists.infradead.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/afs/super.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/fs/afs/super.c
+++ b/fs/afs/super.c
@@ -587,7 +587,8 @@ static int afs_get_tree(struct fs_contex
 	}
 
 	fc->root = dget(sb->s_root);
-	trace_afs_get_tree(as->cell, as->volume);
+	if (!ctx->dyn_root)
+		trace_afs_get_tree(as->cell, as->volume);
 	_leave(" = 0 [%p]", sb);
 	return 0;
 



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0036/2077] afs: handle CB.InitCallBackState3 requests without a server record
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (34 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0035/2077] afs: fix NULL pointer dereference in afs_get_tree() Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0037/2077] afs: Fix further netns teardown to cancel the preallocation charger Greg Kroah-Hartman
                   ` (961 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Yuan Tan, Yifan Wu,
	Juefei Pu, Xin Liu, Nan Li, Ren Wei, David Howells, Marc Dionne,
	linux-afs, Christian Brauner (Amutable)

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nan Li <tonanli66@gmail.com>

commit f3cf725cd284b7912d5522babb44721bf38c8887 upstream.

The cache manager callback path now attaches the server record to an
incoming call through the rxrpc peer's app data.  That association is
not guaranteed to exist for every callback request, and most callback
handlers already tolerate that case.

Make CB.InitCallBackState3 follow the same pattern by checking whether a
server record was attached before using it.  If the peer is not mapped
to a server record, trace the request and ignore it, matching the
existing behaviour for other unmatched callback requests.

This keeps the callback handler consistent with the rest of the cache
manager service and avoids depending on peer state that may not be
available for a given request.

Fixes: 40e8b52fe8c8 ("afs: Use the per-peer app data provided by rxrpc")
Cc: stable@kernel.org
Reported-by: Yuan Tan <yuantan098@gmail.com>
Reported-by: Yifan Wu <yifanwucs@gmail.com>
Reported-by: Juefei Pu <tomapufckgml@gmail.com>
Reported-by: Xin Liu <bird@lzu.edu.cn>
Signed-off-by: Nan Li <tonanli66@gmail.com>
Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://patch.msgid.link/20260622090856.2746629-2-dhowells@redhat.com
cc: Marc Dionne <marc.dionne@auristor.com>
cc: linux-afs@lists.infradead.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/afs/cmservice.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/fs/afs/cmservice.c
+++ b/fs/afs/cmservice.c
@@ -364,6 +364,11 @@ static int afs_deliver_cb_init_call_back
 	if (!afs_check_call_state(call, AFS_CALL_SV_REPLYING))
 		return afs_io_error(call, afs_io_error_cm_reply);
 
+	if (!call->server) {
+		trace_afs_cm_no_server_u(call, call->request);
+		return 0;
+	}
+
 	if (memcmp(call->request, &call->server->_uuid, sizeof(call->server->_uuid)) != 0) {
 		pr_notice("Callback UUID does not match fileserver UUID\n");
 		trace_afs_cm_no_server_u(call, call->request);



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0037/2077] afs: Fix further netns teardown to cancel the preallocation charger
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (35 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0036/2077] afs: handle CB.InitCallBackState3 requests without a server record Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0038/2077] afs: Fix uncancelled rxrpc OOB message handler Greg Kroah-Hartman
                   ` (960 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jakub Kicinski, David Howells,
	Li Daming, Ren Wei, Marc Dionne, Jeffrey Altman, Simon Horman,
	linux-afs, stable

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit 2daf8ac812c3d78c642fe7652f62e29df5e3da20 upstream.

When an afs network namespace is torn down, it cancels and waits for the
work item that keeps the preallocated rxrpc call/conn/peer queue charged
before disabling incoming (i.e. listen 0), but there's a small window in
which it can be requeued by an incoming call wending through the I/O
thread.

Fix this by cancelling the charger work item again after reducing the
listen backlog to zero.

Fixes: 47694fbc9d24 ("afs: Fix netns teardown to cancel the preallocation charger")
Reported-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://sashiko.dev/#/patchset/20260609140911.838677-1-dhowells%40redhat.com
cc: Li Daming <d4n.for.sec@gmail.com>
cc: Ren Wei <n05ec@lzu.edu.cn>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260624163819.3017002-5-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/afs/rxrpc.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/fs/afs/rxrpc.c
+++ b/fs/afs/rxrpc.c
@@ -128,8 +128,13 @@ void afs_close_socket(struct afs_net *ne
 	_enter("");
 
 	cancel_work_sync(&net->charge_preallocation_work);
+	/* Future work items should now see ->live is false. */
+
 	kernel_listen(net->socket, 0);
+
+	/* Make sure work items are no longer running. */
 	flush_workqueue(afs_async_calls);
+	cancel_work_sync(&net->charge_preallocation_work);
 
 	if (net->spare_incoming_call) {
 		afs_put_call(net->spare_incoming_call);



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0038/2077] afs: Fix uncancelled rxrpc OOB message handler
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (36 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0037/2077] afs: Fix further netns teardown to cancel the preallocation charger Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0039/2077] fbcon: fix NULL pointer dereference for a console without vc_data Greg Kroah-Hartman
                   ` (959 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Howells, Li Daming, Ren Wei,
	Marc Dionne, Jeffrey Altman, Simon Horman, linux-afs, stable,
	Jakub Kicinski

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Howells <dhowells@redhat.com>

commit a4057e58b07005d0fe0491bdbf1868c1491909ee upstream.

Fix AFS to cancel its OOB message processing (typically to respond to
security challenges).  Also move OOB message processing to afs_wq so that
it's also waited for and make the OOB handler just return if the net
namespace is no longer live.

Fixes: 5800b1cf3fd8 ("rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE")
Link: https://sashiko.dev/#/patchset/20260609140911.838677-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Li Daming <d4n.for.sec@gmail.com>
cc: Ren Wei <n05ec@lzu.edu.cn>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260624163819.3017002-6-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/afs/cm_security.c |    3 ++-
 fs/afs/rxrpc.c       |    5 ++++-
 2 files changed, 6 insertions(+), 2 deletions(-)

--- a/fs/afs/cm_security.c
+++ b/fs/afs/cm_security.c
@@ -101,7 +101,8 @@ void afs_process_oob_queue(struct work_s
 	struct sk_buff *oob;
 	enum rxrpc_oob_type type;
 
-	while ((oob = rxrpc_kernel_dequeue_oob(net->socket, &type))) {
+	while (READ_ONCE(net->live) &&
+	       (oob = rxrpc_kernel_dequeue_oob(net->socket, &type))) {
 		switch (type) {
 		case RXRPC_OOB_CHALLENGE:
 			afs_respond_to_challenge(oob);
--- a/fs/afs/rxrpc.c
+++ b/fs/afs/rxrpc.c
@@ -128,6 +128,7 @@ void afs_close_socket(struct afs_net *ne
 	_enter("");
 
 	cancel_work_sync(&net->charge_preallocation_work);
+	cancel_work_sync(&net->rx_oob_work);
 	/* Future work items should now see ->live is false. */
 
 	kernel_listen(net->socket, 0);
@@ -148,6 +149,7 @@ void afs_close_socket(struct afs_net *ne
 
 	kernel_sock_shutdown(net->socket, SHUT_RDWR);
 	flush_workqueue(afs_async_calls);
+	cancel_work_sync(&net->rx_oob_work);
 	net->socket->sk->sk_user_data = NULL;
 	sock_release(net->socket);
 	key_put(net->fs_cm_token_key);
@@ -989,5 +991,6 @@ static void afs_rx_notify_oob(struct soc
 {
 	struct afs_net *net = sk->sk_user_data;
 
-	schedule_work(&net->rx_oob_work);
+	if (READ_ONCE(net->live))
+		queue_work(afs_wq, &net->rx_oob_work);
 }



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0039/2077] fbcon: fix NULL pointer dereference for a console without vc_data
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (37 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0038/2077] afs: Fix uncancelled rxrpc OOB message handler Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0040/2077] fbcon: Use correct type for vc_resize() return value Greg Kroah-Hartman
                   ` (958 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+42525d636f430fd5d983,
	Ian Bridges, Helge Deller

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Bridges <icb@fastmail.org>

commit 5fae9a928482d4845bca169a3a098789203a1ca4 upstream.

fbcon_new_modelist() runs when a framebuffer's modelist changes. For each
console mapped to it with fb_display[i].mode set, it reads vc_cons[i].d and
passes the vc_num to fbcon_set_disp(). This assumes a console with a mode
set has a vc_data, but it can be NULL. fbcon_set_disp() sets
fb_display[i].mode before it checks vc_data, and fbcon_deinit() leaves the
mode set after the vc_data is freed. fbcon_new_modelist() then dereferences
the NULL vc_data.

Keep fb_display[i].mode set only while the console has a vc_data. Check
vc_data before setting the mode in fbcon_set_disp(), and clear the mode in
fbcon_deinit(). The existing mode check in fbcon_new_modelist() then skips
such consoles.

Reported-by: syzbot+42525d636f430fd5d983@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=42525d636f430fd5d983
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Ian Bridges <icb@fastmail.org>
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/video/fbdev/core/fbcon.c |    7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

--- a/drivers/video/fbdev/core/fbcon.c
+++ b/drivers/video/fbdev/core/fbcon.c
@@ -1274,6 +1274,7 @@ static void fbcon_deinit(struct vc_data
 	int idx;
 
 	fbcon_free_font(p);
+	p->mode = NULL;
 	idx = con2fb_map[vc->vc_num];
 
 	if (idx == -1)
@@ -1445,14 +1446,14 @@ static void fbcon_set_disp(struct fb_inf
 
 	p = &fb_display[unit];
 
-	if (var_to_display(p, var, info))
-		return;
-
 	vc = vc_cons[unit].d;
 
 	if (!vc)
 		return;
 
+	if (var_to_display(p, var, info))
+		return;
+
 	default_mode = vc->vc_display_fg;
 	svc = *default_mode;
 	t = &fb_display[svc->vc_num];



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0040/2077] fbcon: Use correct type for vc_resize() return value
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (38 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0039/2077] fbcon: fix NULL pointer dereference for a console without vc_data Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0041/2077] soc: fsl: qe_ports_ic: Add missing cleanup on device removal Greg Kroah-Hartman
                   ` (957 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jiacheng Yu, Thomas Zimmermann,
	Helge Deller

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiacheng Yu <yujiacheng3@huawei.com>

commit 84202754fb1727dc3ee87f47104e4162ecc8ba3a upstream.

The return value of vc_resize() is int, but fbcon_set_disp() stores it
in an unsigned long variable. While the !ret check happens to work
correctly by coincidence (negative values become large positive values),
the types should match. Use int instead.

Eliminates the following W=3 warning:

  drivers/video/fbdev/core/fbcon.c: In function 'fbcon_set_disp':
  drivers/video/fbdev/core/fbcon.c:1494:14: warning: implicit conversion from 'int' to 'unsigned long' [-Wconversion]

Fixes: af0db3c1f898 ("fbdev: Fix vmalloc out-of-bounds write in fast_imageblit")
Cc: stable@vger.kernel.org # v6.17+
Signed-off-by: Jiacheng Yu <yujiacheng3@huawei.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/video/fbdev/core/fbcon.c |    3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

--- a/drivers/video/fbdev/core/fbcon.c
+++ b/drivers/video/fbdev/core/fbcon.c
@@ -1441,8 +1441,7 @@ static void fbcon_set_disp(struct fb_inf
 	struct vc_data **default_mode, *vc;
 	struct vc_data *svc;
 	struct fbcon_par *par = info->fbcon_par;
-	int rows, cols;
-	unsigned long ret = 0;
+	int rows, cols, ret;
 
 	p = &fb_display[unit];
 



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0041/2077] soc: fsl: qe_ports_ic: Add missing cleanup on device removal
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (39 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0040/2077] fbcon: Use correct type for vc_resize() return value Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0042/2077] openrisc: mm: Fix section mismatch between map_page and __set_fixmap Greg Kroah-Hartman
                   ` (956 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Felix Gu,
	Christophe Leroy (CS GROUP), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit 7dad18a179741dbad9f40799e549fa9111987c0c ]

Add a devm action handler to properly clean up the irq_domain and
chained handler when the device is removed.

Fixes: f0bcd784e1b7 ("soc: fsl: qe: Add an interrupt controller for QUICC Engine Ports")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Link: https://lore.kernel.org/r/20260310-qe_ports_ic-v1-1-608293026561@gmail.com
Signed-off-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/soc/fsl/qe/qe_ports_ic.c | 21 +++++++++++++++------
 1 file changed, 15 insertions(+), 6 deletions(-)

diff --git a/drivers/soc/fsl/qe/qe_ports_ic.c b/drivers/soc/fsl/qe/qe_ports_ic.c
index 8e2107e2cde5b2..5e3fae19f31417 100644
--- a/drivers/soc/fsl/qe/qe_ports_ic.c
+++ b/drivers/soc/fsl/qe/qe_ports_ic.c
@@ -17,6 +17,7 @@
 struct qepic_data {
 	void __iomem *reg;
 	struct irq_domain *host;
+	int irq;
 };
 
 static void qepic_mask(struct irq_data *d)
@@ -92,11 +93,18 @@ static const struct irq_domain_ops qepic_host_ops = {
 	.map = qepic_host_map,
 };
 
+static void qepic_remove(void *res)
+{
+	struct qepic_data *data = res;
+
+	irq_set_chained_handler_and_data(data->irq, NULL, NULL);
+	irq_domain_remove(data->host);
+}
+
 static int qepic_probe(struct platform_device *pdev)
 {
 	struct device *dev = &pdev->dev;
 	struct qepic_data *data;
-	int irq;
 
 	data = devm_kzalloc(dev, sizeof(*data), GFP_KERNEL);
 	if (!data)
@@ -106,17 +114,18 @@ static int qepic_probe(struct platform_device *pdev)
 	if (IS_ERR(data->reg))
 		return PTR_ERR(data->reg);
 
-	irq = platform_get_irq(pdev, 0);
-	if (irq < 0)
-		return irq;
+	data->irq = platform_get_irq(pdev, 0);
+	if (data->irq < 0)
+		return data->irq;
 
 	data->host = irq_domain_add_linear(dev->of_node, 32, &qepic_host_ops, data);
 	if (!data->host)
 		return -ENODEV;
 
-	irq_set_chained_handler_and_data(irq, qepic_cascade, data);
+	irq_set_chained_handler_and_data(data->irq, qepic_cascade, data);
+
+	return devm_add_action_or_reset(dev, qepic_remove, data);
 
-	return 0;
 }
 
 static const struct of_device_id qepic_match[] = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0042/2077] openrisc: mm: Fix section mismatch between map_page and __set_fixmap
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (40 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0041/2077] soc: fsl: qe_ports_ic: Add missing cleanup on device removal Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0043/2077] clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() Greg Kroah-Hartman
                   ` (955 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, kernel test robot, Stafford Horne,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stafford Horne <shorne@gmail.com>

[ Upstream commit 431400d49cac4bac944fc2d989921003314667ae ]

This warning was reported by the kernel test robot:

  WARNING: modpost: vmlinux: section mismatch in reference: __set_fixmap+0x84 (section: .text.unlikely) -> map_page.isra.0 (section: .init.text)

With commit 4735037b5d9b ("openrisc: Add text patching API support") the
__set_fixmap function was moved out of the .init.text section.
However, the map_page helper that it uses was not moved.  This was not
noticed on gcc 15.1.0 where map_page gets inlined unlike lkp@intel.com
which uses gcc 10.5.0.

Fix this by also moving the map_page helper function out of the init
section.

Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202603211503.E8mMETO3-lkp@intel.com/
Fixes: 4735037b5d9b ("openrisc: Add text patching API support")
Signed-off-by: Stafford Horne <shorne@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/openrisc/mm/init.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/openrisc/mm/init.c b/arch/openrisc/mm/init.c
index 89d8c6df885511..db7c844faeeb62 100644
--- a/arch/openrisc/mm/init.c
+++ b/arch/openrisc/mm/init.c
@@ -193,7 +193,7 @@ void __init mem_init(void)
 	return;
 }
 
-static int __init map_page(unsigned long va, phys_addr_t pa, pgprot_t prot)
+static int map_page(unsigned long va, phys_addr_t pa, pgprot_t prot)
 {
 	p4d_t *p4d;
 	pud_t *pud;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0043/2077] clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (41 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0042/2077] openrisc: mm: Fix section mismatch between map_page and __set_fixmap Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0044/2077] accel/amdxdna: Fix leak when pinning ubuf pages Greg Kroah-Hartman
                   ` (954 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chen Ni, Daniel Lezcano,
	Chen-Yu Tsai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chen Ni <nichen@iscas.ac.cn>

[ Upstream commit fed9f727cc3f91dde8278961269419083502b40e ]

The devm_reset_control_get_optional_exclusive() function may return an
ERR_PTR in case of genuine reset control acquisition errors, not just
NULL which indicates the legitimate absence of an optional reset.

Add an IS_ERR() check after the call in sun5i_timer_probe(). On error,
return the error code to ensure proper failure handling rather than
proceeding with invalid pointers.

Fixes: 7e5bac610d2f ("clocksource/drivers/sun5i: Convert to platform device driver")
Signed-off-by: Chen Ni <nichen@iscas.ac.cn>
Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
Acked-by: Chen-Yu Tsai <wens@kernel.org>
Link: https://patch.msgid.link/20260205084037.3661261-1-nichen@iscas.ac.cn
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clocksource/timer-sun5i.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/clocksource/timer-sun5i.c b/drivers/clocksource/timer-sun5i.c
index f827d3f98f60e6..d7e012992170b7 100644
--- a/drivers/clocksource/timer-sun5i.c
+++ b/drivers/clocksource/timer-sun5i.c
@@ -286,6 +286,9 @@ static int sun5i_timer_probe(struct platform_device *pdev)
 	}
 
 	rstc = devm_reset_control_get_optional_exclusive(dev, NULL);
+	if (IS_ERR(rstc))
+		return dev_err_probe(dev, PTR_ERR(rstc),
+				     "failed to get reset\n");
 	if (rstc)
 		reset_control_deassert(rstc);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0044/2077] accel/amdxdna: Fix leak when pinning ubuf pages
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (42 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0043/2077] clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0045/2077] drm/rockchip: inno-hdmi: Switch to drmm_kzalloc() Greg Kroah-Hartman
                   ` (953 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mario Limonciello (AMD), Max Zhen,
	Lizhi Hou, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Max Zhen <max.zhen@amd.com>

[ Upstream commit d946347edc4f0a7b846325323d77e936a4c90d0f ]

When pin_user_pages_fast() returns fewer pages than requested, the pages
that were successfully pinned are not released, leading to a leak.

Fix this by unpinning any partially pinned pages before returning failure.

Fixes: bd72d4acda10 ("accel/amdxdna: Support user space allocated buffer")
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Max Zhen <max.zhen@amd.com>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260326010642.2596525-1-lizhi.hou@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/accel/amdxdna/amdxdna_ubuf.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/drivers/accel/amdxdna/amdxdna_ubuf.c b/drivers/accel/amdxdna/amdxdna_ubuf.c
index 85390e3cc9f982..0e0cd69cd1fbfc 100644
--- a/drivers/accel/amdxdna/amdxdna_ubuf.c
+++ b/drivers/accel/amdxdna/amdxdna_ubuf.c
@@ -146,13 +146,17 @@ struct dma_buf *amdxdna_get_ubuf(struct drm_device *dev,
 		ret = pin_user_pages_fast(va_ent[i].vaddr, npages,
 					  FOLL_WRITE | FOLL_LONGTERM,
 					  &ubuf->pages[start]);
-		if (ret < 0 || ret != npages) {
-			ret = -ENOMEM;
+		if (ret >= 0) {
+			start += ret;
+			if (ret != npages) {
+				XDNA_ERR(xdna, "Partially pinned pages %d/%u", ret, npages);
+				ret = -ENOMEM;
+				goto destroy_pages;
+			}
+		} else {
 			XDNA_ERR(xdna, "Failed to pin pages ret %d", ret);
 			goto destroy_pages;
 		}
-
-		start += ret;
 	}
 
 	exp_info.ops = &amdxdna_ubuf_dmabuf_ops;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0045/2077] drm/rockchip: inno-hdmi: Switch to drmm_kzalloc()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (43 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0044/2077] accel/amdxdna: Fix leak when pinning ubuf pages Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0046/2077] drm/rockchip: dw_dp: " Greg Kroah-Hartman
                   ` (952 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cristian Ciocaltea, Heiko Stuebner,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>

[ Upstream commit 3cc50e7f73fcf79f28660b9d91566b13cb62e520 ]

Driver makes use of drmm_encoder_init() to initialize the encoder and
automatically handle the cleanup by registering drm_encoder_cleanup()
with drmm_add_action().

However, the internal structure containing the encoder part gets
allocated with devm_kzalloc(), which happens while component_bind_all()
is being called from Rockchip DRM driver.  The component framework
further ensures it is deallocated as part of releasing all the resources
claimed during bind, which is triggered from component_unbind_all().

When the reference to the DRM device gets eventually dropped via
drm_dev_put() in rockchip_drm_unbind(), drmm_encoder_alloc_release()
attempts to access the now released encoder structure, leading to
use-after-free.

Ensure driver's internal structure is still reachable on encoder cleanup
by switching from a device-managed allocation to a drm-managed one.

Fixes: 969325a2597e ("drm/rockchip: inno-hdmi: Convert to drm bridge")
Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260310-drm-rk-fixes-v2-1-645ecfb43f49@collabora.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/rockchip/inno_hdmi-rockchip.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/rockchip/inno_hdmi-rockchip.c b/drivers/gpu/drm/rockchip/inno_hdmi-rockchip.c
index 97c20500f79012..28e6fb09aae735 100644
--- a/drivers/gpu/drm/rockchip/inno_hdmi-rockchip.c
+++ b/drivers/gpu/drm/rockchip/inno_hdmi-rockchip.c
@@ -14,6 +14,7 @@
 
 #include <drm/bridge/inno_hdmi.h>
 #include <drm/drm_bridge_connector.h>
+#include <drm/drm_managed.h>
 #include <drm/drm_of.h>
 
 #include "rockchip_drm_drv.h"
@@ -90,7 +91,7 @@ static int inno_hdmi_rockchip_bind(struct device *dev, struct device *master, vo
 	const struct inno_hdmi_plat_data *plat_data;
 	int ret;
 
-	hdmi = devm_kzalloc(dev, sizeof(*hdmi), GFP_KERNEL);
+	hdmi = drmm_kzalloc(drm, sizeof(*hdmi), GFP_KERNEL);
 	if (!hdmi)
 		return -ENOMEM;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0046/2077] drm/rockchip: dw_dp: Switch to drmm_kzalloc()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (44 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0045/2077] drm/rockchip: inno-hdmi: Switch to drmm_kzalloc() Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0047/2077] drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove() Greg Kroah-Hartman
                   ` (951 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cristian Ciocaltea, Heiko Stuebner,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>

[ Upstream commit ed9da8d23020352ad24c528db09b5acdd78b81fd ]

Driver makes use of drmm_encoder_init() to initialize the encoder and
automatically handle the cleanup by registering drm_encoder_cleanup()
with drmm_add_action().

However, the internal structure containing the encoder part gets
allocated with devm_kzalloc(), which happens while component_bind_all()
is being called from Rockchip DRM driver.  The component framework
further ensures it is deallocated as part of releasing all the resources
claimed during bind, which is triggered from component_unbind_all().

When the reference to the DRM device gets eventually dropped via
drm_dev_put() in rockchip_drm_unbind(), drmm_encoder_alloc_release()
attempts to access the now released encoder structure, leading to
use-after-free.

Ensure driver's internal structure is still reachable on encoder cleanup
by switching from a device-managed allocation to a drm-managed one.

Fixes: d68ba7bac955 ("drm/rockchip: Add RK3588 DPTX output support")
Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260310-drm-rk-fixes-v2-2-645ecfb43f49@collabora.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/rockchip/dw_dp-rockchip.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
index dac3d202971eda..532af476d250a5 100644
--- a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
@@ -13,6 +13,7 @@
 #include <drm/drm_atomic_helper.h>
 #include <drm/drm_bridge.h>
 #include <drm/drm_bridge_connector.h>
+#include <drm/drm_managed.h>
 #include <drm/drm_of.h>
 #include <drm/drm_print.h>
 #include <drm/drm_probe_helper.h>
@@ -82,7 +83,7 @@ static int dw_dp_rockchip_bind(struct device *dev, struct device *master, void *
 	struct drm_connector *connector;
 	int ret;
 
-	dp = devm_kzalloc(dev, sizeof(*dp), GFP_KERNEL);
+	dp = drmm_kzalloc(drm_dev, sizeof(*dp), GFP_KERNEL);
 	if (!dp)
 		return -ENOMEM;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0047/2077] drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (45 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0046/2077] drm/rockchip: dw_dp: " Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55   ` Greg Kroah-Hartman
                   ` (950 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cristian Ciocaltea, Heiko Stuebner,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>

[ Upstream commit 9456381d8b60bb7dd42f2f04afe5ee4ce6e0bc12 ]

Attempting to access driver data in the platform driver ->remove()
callback may lead to a null pointer dereference since there is no
guaranty that the component ->bind() callback invoking
platform_set_drvdata() was executed.

A common scenario is when Rockchip DRM driver didn't manage to run
component_bind_all() because of an (unrelated) error causing early
return from rockchip_drm_bind().

Drop the unnecessary call to platform_get_drvdata() and, instead,
reference the target device structure via platform_device.

Fixes: d68ba7bac955 ("drm/rockchip: Add RK3588 DPTX output support")
Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260310-drm-rk-fixes-v2-3-645ecfb43f49@collabora.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/rockchip/dw_dp-rockchip.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
index 532af476d250a5..8945a245398ca4 100644
--- a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
@@ -133,9 +133,7 @@ static int dw_dp_probe(struct platform_device *pdev)
 
 static void dw_dp_remove(struct platform_device *pdev)
 {
-	struct rockchip_dw_dp *dp = platform_get_drvdata(pdev);
-
-	component_del(dp->dev, &dw_dp_rockchip_component_ops);
+	component_del(&pdev->dev, &dw_dp_rockchip_component_ops);
 }
 
 static const struct dw_dp_plat_data rk3588_dp_plat_data = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0048/2077] drm/rockchip: Test for imported buffers with drm_gem_is_imported()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
@ 2026-07-21 14:55   ` Greg Kroah-Hartman
  2026-07-21 14:54 ` [PATCH 7.1 0002/2077] iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry Greg Kroah-Hartman
                     ` (996 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann, Sandy Huang,
	Heiko Stübner, Andy Yan, linux-rockchip, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Zimmermann <tzimmermann@suse.de>

[ Upstream commit 9fc0da81916250f343599a4dd259f097196bf0fb ]

Instead of testing import_attach for imported GEM buffers, invoke
drm_gem_is_imported() to do the test. The test itself does not change.

Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Cc: Sandy Huang <hjc@rock-chips.com>
Cc: Heiko Stübner <heiko@sntech.de>
Cc: Andy Yan <andy.yan@rock-chips.com>
Cc: linux-rockchip@lists.infradead.org
Fixes: b57aa47d39e9 ("drm/gem: Test for imported GEM buffers with helper")
Closes: https://lore.kernel.org/dri-devel/38d09d34.4354.196379aa560.Coremail.andyshrk@163.com/
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260227133113.235940-11-tzimmermann@suse.de
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/rockchip/rockchip_drm_gem.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/rockchip/rockchip_drm_gem.c b/drivers/gpu/drm/rockchip/rockchip_drm_gem.c
index 09d14a072d274e..b188539dca0b25 100644
--- a/drivers/gpu/drm/rockchip/rockchip_drm_gem.c
+++ b/drivers/gpu/drm/rockchip/rockchip_drm_gem.c
@@ -334,7 +334,7 @@ void rockchip_gem_free_object(struct drm_gem_object *obj)
 	struct rockchip_drm_private *private = drm->dev_private;
 	struct rockchip_gem_object *rk_obj = to_rockchip_obj(obj);
 
-	if (obj->import_attach) {
+	if (drm_gem_is_imported(obj)) {
 		if (private->domain) {
 			rockchip_gem_iommu_unmap(rk_obj);
 		} else {
-- 
2.53.0




_______________________________________________
Linux-rockchip mailing list
Linux-rockchip@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-rockchip

^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0048/2077] drm/rockchip: Test for imported buffers with drm_gem_is_imported()
@ 2026-07-21 14:55   ` Greg Kroah-Hartman
  0 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann, Sandy Huang,
	Heiko Stübner, Andy Yan, linux-rockchip, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Zimmermann <tzimmermann@suse.de>

[ Upstream commit 9fc0da81916250f343599a4dd259f097196bf0fb ]

Instead of testing import_attach for imported GEM buffers, invoke
drm_gem_is_imported() to do the test. The test itself does not change.

Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Cc: Sandy Huang <hjc@rock-chips.com>
Cc: Heiko Stübner <heiko@sntech.de>
Cc: Andy Yan <andy.yan@rock-chips.com>
Cc: linux-rockchip@lists.infradead.org
Fixes: b57aa47d39e9 ("drm/gem: Test for imported GEM buffers with helper")
Closes: https://lore.kernel.org/dri-devel/38d09d34.4354.196379aa560.Coremail.andyshrk@163.com/
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260227133113.235940-11-tzimmermann@suse.de
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/rockchip/rockchip_drm_gem.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/rockchip/rockchip_drm_gem.c b/drivers/gpu/drm/rockchip/rockchip_drm_gem.c
index 09d14a072d274e..b188539dca0b25 100644
--- a/drivers/gpu/drm/rockchip/rockchip_drm_gem.c
+++ b/drivers/gpu/drm/rockchip/rockchip_drm_gem.c
@@ -334,7 +334,7 @@ void rockchip_gem_free_object(struct drm_gem_object *obj)
 	struct rockchip_drm_private *private = drm->dev_private;
 	struct rockchip_gem_object *rk_obj = to_rockchip_obj(obj);
 
-	if (obj->import_attach) {
+	if (drm_gem_is_imported(obj)) {
 		if (private->domain) {
 			rockchip_gem_iommu_unmap(rk_obj);
 		} else {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0049/2077] drm/tidss: Drop extra drm_mode_config_reset() call
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (47 preceding siblings ...)
  2026-07-21 14:55   ` Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0050/2077] drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges Greg Kroah-Hartman
                   ` (948 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Maxime Ripard, Tomi Valkeinen,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tomi Valkeinen <tomi.valkeinen@ideasonboard.com>

[ Upstream commit f468fef38716f667e805e0fa2c497c6b9c325bb9 ]

We are calling drm_mode_config_reset() twice at probe time. There's no
reason for this and the second call can be removed, reducing work at
probe time slightly.

Fixes: 32a1795f57ee ("drm/tidss: New driver for TI Keystone platform Display SubSystem")
Acked-by: Maxime Ripard <mripard@kernel.org>
Link: https://patch.msgid.link/20260311-tidss-minor-fixes-v2-1-cb4479784458@ideasonboard.com
Signed-off-by: Tomi Valkeinen <tomi.valkeinen@ideasonboard.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/tidss/tidss_kms.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/drivers/gpu/drm/tidss/tidss_kms.c b/drivers/gpu/drm/tidss/tidss_kms.c
index 8bb93194e5ac68..b4779c09a1bfa5 100644
--- a/drivers/gpu/drm/tidss/tidss_kms.c
+++ b/drivers/gpu/drm/tidss/tidss_kms.c
@@ -287,8 +287,6 @@ int tidss_modeset_init(struct tidss_device *tidss)
 	if (ret)
 		return ret;
 
-	drm_mode_config_reset(ddev);
-
 	dev_dbg(tidss->dev, "%s done\n", __func__);
 
 	return 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0050/2077] drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (48 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0049/2077] drm/tidss: Drop extra drm_mode_config_reset() call Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0051/2077] accel/amdxdna: Create shared functions for AIE2 and AIE4 Greg Kroah-Hartman
                   ` (947 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Matthew Brost, Himal Prasad Ghimiray,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matthew Brost <matthew.brost@intel.com>

[ Upstream commit b82a225e57a334335a21462b75ee2223bc6efe6d ]

VMAs marked with VM_IO or VM_PFNMAP are not backed by struct page
objects, which GPUSVM requires in order to operate correctly. In
particular, get_pages() relies on hmm_range_fault() to resolve struct
pages for the target range.

Attempting to create an SVM range on such VMAs results in repeated
get_pages() failures and can lead to an infinite loop inside a driver’s
page‑fault handler. Prevent this by rejecting ranges on VM_IO or
VM_PFNMAP VMAs and returning -EIO.

Fixes: 99624bdff867 ("drm/gpusvm: Add support for GPU Shared Virtual Memory")
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Reviewed-by: Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
Link: https://patch.msgid.link/20260325231608.25581-1-matthew.brost@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/drm_gpusvm.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/gpu/drm/drm_gpusvm.c b/drivers/gpu/drm/drm_gpusvm.c
index 4b928fda5b127f..7993e85c05661f 100644
--- a/drivers/gpu/drm/drm_gpusvm.c
+++ b/drivers/gpu/drm/drm_gpusvm.c
@@ -1065,6 +1065,11 @@ drm_gpusvm_range_find_or_insert(struct drm_gpusvm *gpusvm,
 		goto err_notifier_remove;
 	}
 
+	if (vas->vm_flags & (VM_IO | VM_PFNMAP)) {
+		err = -EIO;
+		goto err_notifier_remove;
+	}
+
 	range = drm_gpusvm_range_find(notifier, fault_addr, fault_addr + 1);
 	if (range)
 		goto out_mmunlock;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0051/2077] accel/amdxdna: Create shared functions for AIE2 and AIE4
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (49 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0050/2077] drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0052/2077] accel/amdxdna: Adjust size for copy_to_user() Greg Kroah-Hartman
                   ` (946 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mario Limonciello (AMD), Lizhi Hou,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lizhi Hou <lizhi.hou@amd.com>

[ Upstream commit 5a55a5da1f01274c07359b09abec952ec9f05105 ]

The AIE4 platform uses a mailbox management channel mechanism similar to
AIE2 to communicate with the firmware.

Create aie.h and aie.c and move the functions and structures that can
be shared by both platforms from the AIE2-specific files into these
common files. This allows AIE2 and AIE4 to reuse the same implementation
and reduces code duplication.

Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260330163705.3153647-2-lizhi.hou@amd.com
Stable-dep-of: 6e87001fe19f ("accel/amdxdna: Adjust size for copy_to_user()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/accel/amdxdna/Makefile          |   1 +
 drivers/accel/amdxdna/aie.c             |  89 +++++++++++++++
 drivers/accel/amdxdna/aie.h             |  31 ++++++
 drivers/accel/amdxdna/aie2_ctx.c        |   4 +-
 drivers/accel/amdxdna/aie2_error.c      |  12 +--
 drivers/accel/amdxdna/aie2_message.c    | 138 +++++++++---------------
 drivers/accel/amdxdna/aie2_pci.c        | 107 ++++++------------
 drivers/accel/amdxdna/aie2_pci.h        |  26 +----
 drivers/accel/amdxdna/aie2_pm.c         |   6 +-
 drivers/accel/amdxdna/aie2_smu.c        |  22 ++--
 drivers/accel/amdxdna/amdxdna_pci_drv.h |   8 ++
 drivers/accel/amdxdna/npu1_regs.c       |   4 +-
 drivers/accel/amdxdna/npu4_regs.c       |   4 +-
 drivers/accel/amdxdna/npu5_regs.c       |   2 +-
 drivers/accel/amdxdna/npu6_regs.c       |   2 +-
 15 files changed, 246 insertions(+), 210 deletions(-)
 create mode 100644 drivers/accel/amdxdna/aie.c
 create mode 100644 drivers/accel/amdxdna/aie.h

diff --git a/drivers/accel/amdxdna/Makefile b/drivers/accel/amdxdna/Makefile
index cf9bf19dedb9e5..5c7911554c46ee 100644
--- a/drivers/accel/amdxdna/Makefile
+++ b/drivers/accel/amdxdna/Makefile
@@ -1,6 +1,7 @@
 # SPDX-License-Identifier: GPL-2.0-only
 
 amdxdna-y := \
+	aie.o \
 	aie2_ctx.o \
 	aie2_error.o \
 	aie2_message.o \
diff --git a/drivers/accel/amdxdna/aie.c b/drivers/accel/amdxdna/aie.c
new file mode 100644
index 00000000000000..4b3d4493128e9e
--- /dev/null
+++ b/drivers/accel/amdxdna/aie.c
@@ -0,0 +1,89 @@
+// SPDX-License-Identifier: GPL-2.0
+/*
+ * Copyright (C) 2026, Advanced Micro Devices, Inc.
+ */
+
+#include <linux/errno.h>
+
+#include "aie.h"
+#include "amdxdna_mailbox_helper.h"
+#include "amdxdna_mailbox.h"
+#include "amdxdna_pci_drv.h"
+
+void aie_dump_mgmt_chann_debug(struct aie_device *aie)
+{
+	struct amdxdna_dev *xdna = aie->xdna;
+
+	XDNA_DBG(xdna, "i2x tail    0x%x", aie->mgmt_i2x.mb_tail_ptr_reg);
+	XDNA_DBG(xdna, "i2x head    0x%x", aie->mgmt_i2x.mb_head_ptr_reg);
+	XDNA_DBG(xdna, "i2x ringbuf 0x%x", aie->mgmt_i2x.rb_start_addr);
+	XDNA_DBG(xdna, "i2x rsize   0x%x", aie->mgmt_i2x.rb_size);
+	XDNA_DBG(xdna, "x2i tail    0x%x", aie->mgmt_x2i.mb_tail_ptr_reg);
+	XDNA_DBG(xdna, "x2i head    0x%x", aie->mgmt_x2i.mb_head_ptr_reg);
+	XDNA_DBG(xdna, "x2i ringbuf 0x%x", aie->mgmt_x2i.rb_start_addr);
+	XDNA_DBG(xdna, "x2i rsize   0x%x", aie->mgmt_x2i.rb_size);
+	XDNA_DBG(xdna, "x2i chann index 0x%x", aie->mgmt_chan_idx);
+	XDNA_DBG(xdna, "mailbox protocol major 0x%x", aie->mgmt_prot_major);
+	XDNA_DBG(xdna, "mailbox protocol minor 0x%x", aie->mgmt_prot_minor);
+}
+
+void aie_destroy_chann(struct aie_device *aie, struct mailbox_channel **chann)
+{
+	struct amdxdna_dev *xdna = aie->xdna;
+
+	drm_WARN_ON(&xdna->ddev, !mutex_is_locked(&xdna->dev_lock));
+
+	if (!*chann)
+		return;
+
+	xdna_mailbox_stop_channel(*chann);
+	xdna_mailbox_free_channel(*chann);
+	*chann = NULL;
+}
+
+int aie_send_mgmt_msg_wait(struct aie_device *aie, struct xdna_mailbox_msg *msg)
+{
+	struct amdxdna_dev *xdna = aie->xdna;
+	struct xdna_notify *hdl = msg->handle;
+	int ret;
+
+	drm_WARN_ON(&xdna->ddev, !mutex_is_locked(&xdna->dev_lock));
+
+	if (!aie->mgmt_chann)
+		return -ENODEV;
+
+	ret = xdna_send_msg_wait(xdna, aie->mgmt_chann, msg);
+	if (ret == -ETIME)
+		aie_destroy_chann(aie, &aie->mgmt_chann);
+
+	if (!ret && *hdl->status) {
+		XDNA_ERR(xdna, "command opcode 0x%x failed, status 0x%x",
+			 msg->opcode, *hdl->data);
+		ret = -EINVAL;
+	}
+
+	return ret;
+}
+
+int aie_check_protocol(struct aie_device *aie, u32 fw_major, u32 fw_minor)
+{
+	const struct amdxdna_fw_feature_tbl *feature;
+	bool found = false;
+
+	for (feature = aie->xdna->dev_info->fw_feature_tbl;
+	     feature->major; feature++) {
+		if (feature->major != fw_major)
+			continue;
+		if (fw_minor < feature->min_minor)
+			continue;
+		if (feature->max_minor > 0 && fw_minor > feature->max_minor)
+			continue;
+
+		aie->feature_mask |= feature->features;
+
+		/* firmware version matches one of the driver support entry */
+		found = true;
+	}
+
+	return found ? 0 : -EOPNOTSUPP;
+}
diff --git a/drivers/accel/amdxdna/aie.h b/drivers/accel/amdxdna/aie.h
new file mode 100644
index 00000000000000..1bea14b79c7c92
--- /dev/null
+++ b/drivers/accel/amdxdna/aie.h
@@ -0,0 +1,31 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+/*
+ * Copyright (C) 2026, Advanced Micro Devices, Inc.
+ */
+#ifndef _AIE_H_
+#define _AIE_H_
+
+#include "amdxdna_pci_drv.h"
+#include "amdxdna_mailbox.h"
+
+struct aie_device {
+	struct amdxdna_dev *xdna;
+	struct mailbox_channel *mgmt_chann;
+	struct xdna_mailbox_chann_res mgmt_x2i;
+	struct xdna_mailbox_chann_res mgmt_i2x;
+	u32 mgmt_chan_idx;
+	u32 mgmt_prot_major;
+	u32 mgmt_prot_minor;
+	unsigned long feature_mask;
+};
+
+#define DECLARE_AIE_MSG(name, op) \
+	DECLARE_XDNA_MSG_COMMON(name, op, -1)
+#define AIE_FEATURE_ON(aie, feature) test_bit(feature, &(aie)->feature_mask)
+
+void aie_dump_mgmt_chann_debug(struct aie_device *aie);
+void aie_destroy_chann(struct aie_device *aie, struct mailbox_channel **chann);
+int aie_send_mgmt_msg_wait(struct aie_device *aie, struct xdna_mailbox_msg *msg);
+int aie_check_protocol(struct aie_device *aie, u32 fw_major, u32 fw_minor);
+
+#endif /* _AIE_H_ */
diff --git a/drivers/accel/amdxdna/aie2_ctx.c b/drivers/accel/amdxdna/aie2_ctx.c
index eed3d0ec541336..2dc69900ca0107 100644
--- a/drivers/accel/amdxdna/aie2_ctx.c
+++ b/drivers/accel/amdxdna/aie2_ctx.c
@@ -515,7 +515,7 @@ static int aie2_alloc_resource(struct amdxdna_hwctx *hwctx)
 	struct alloc_requests *xrs_req;
 	int ret;
 
-	if (AIE2_FEATURE_ON(xdna->dev_handle, AIE2_TEMPORAL_ONLY)) {
+	if (AIE_FEATURE_ON(&xdna->dev_handle->aie, AIE2_TEMPORAL_ONLY)) {
 		hwctx->num_unused_col = xdna->dev_handle->total_col - hwctx->num_col;
 		hwctx->num_col = xdna->dev_handle->total_col;
 		return aie2_create_context(xdna->dev_handle, hwctx);
@@ -552,7 +552,7 @@ static void aie2_release_resource(struct amdxdna_hwctx *hwctx)
 	struct amdxdna_dev *xdna = hwctx->client->xdna;
 	int ret;
 
-	if (AIE2_FEATURE_ON(xdna->dev_handle, AIE2_TEMPORAL_ONLY)) {
+	if (AIE_FEATURE_ON(&xdna->dev_handle->aie, AIE2_TEMPORAL_ONLY)) {
 		ret = aie2_destroy_context(xdna->dev_handle, hwctx);
 		if (ret && ret != -ENODEV)
 			XDNA_ERR(xdna, "Destroy temporal only context failed, ret %d", ret);
diff --git a/drivers/accel/amdxdna/aie2_error.c b/drivers/accel/amdxdna/aie2_error.c
index 58abb59b615350..9d20e956c020ec 100644
--- a/drivers/accel/amdxdna/aie2_error.c
+++ b/drivers/accel/amdxdna/aie2_error.c
@@ -249,12 +249,12 @@ static u32 aie2_error_backtrack(struct amdxdna_dev_hdl *ndev, void *err_info, u3
 		enum aie_error_category cat;
 
 		cat = aie_get_error_category(err->row, err->event_id, err->mod_type);
-		XDNA_ERR(ndev->xdna, "Row: %d, Col: %d, module %d, event ID %d, category %d",
+		XDNA_ERR(ndev->aie.xdna, "Row: %d, Col: %d, module %d, event ID %d, category %d",
 			 err->row, err->col, err->mod_type,
 			 err->event_id, cat);
 
 		if (err->col >= 32) {
-			XDNA_WARN(ndev->xdna, "Invalid column number");
+			XDNA_WARN(ndev->aie.xdna, "Invalid column number");
 			break;
 		}
 
@@ -294,7 +294,7 @@ static void aie2_error_worker(struct work_struct *err_work)
 
 	e = container_of(err_work, struct async_event, work);
 
-	xdna = e->ndev->xdna;
+	xdna = e->ndev->aie.xdna;
 
 	if (e->resp.status == MAX_AIE2_STATUS_CODE)
 		return;
@@ -329,7 +329,7 @@ static void aie2_error_worker(struct work_struct *err_work)
 
 void aie2_error_async_events_free(struct amdxdna_dev_hdl *ndev)
 {
-	struct amdxdna_dev *xdna = ndev->xdna;
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	struct async_events *events;
 
 	events = ndev->async_events;
@@ -344,7 +344,7 @@ void aie2_error_async_events_free(struct amdxdna_dev_hdl *ndev)
 
 int aie2_error_async_events_alloc(struct amdxdna_dev_hdl *ndev)
 {
-	struct amdxdna_dev *xdna = ndev->xdna;
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	u32 total_col = ndev->total_col;
 	u32 total_size = ASYNC_BUF_SIZE * total_col;
 	struct async_events *events;
@@ -402,7 +402,7 @@ int aie2_error_async_events_alloc(struct amdxdna_dev_hdl *ndev)
 
 int aie2_get_array_async_error(struct amdxdna_dev_hdl *ndev, struct amdxdna_drm_get_array *args)
 {
-	struct amdxdna_dev *xdna = ndev->xdna;
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 
 	drm_WARN_ON(&xdna->ddev, !mutex_is_locked(&xdna->dev_lock));
 
diff --git a/drivers/accel/amdxdna/aie2_message.c b/drivers/accel/amdxdna/aie2_message.c
index a1c546c3e81c34..ccf87b1aa1ccc5 100644
--- a/drivers/accel/amdxdna/aie2_message.c
+++ b/drivers/accel/amdxdna/aie2_message.c
@@ -16,6 +16,7 @@
 #include <linux/types.h>
 #include <linux/xarray.h>
 
+#include "aie.h"
 #include "aie2_msg_priv.h"
 #include "aie2_pci.h"
 #include "amdxdna_ctx.h"
@@ -24,38 +25,12 @@
 #include "amdxdna_mailbox_helper.h"
 #include "amdxdna_pci_drv.h"
 
-#define DECLARE_AIE2_MSG(name, op) \
-	DECLARE_XDNA_MSG_COMMON(name, op, MAX_AIE2_STATUS_CODE)
-
 #define EXEC_MSG_OPS(xdna)	((xdna)->dev_handle->exec_msg_ops)
 
-static int aie2_send_mgmt_msg_wait(struct amdxdna_dev_hdl *ndev,
-				   struct xdna_mailbox_msg *msg)
-{
-	struct amdxdna_dev *xdna = ndev->xdna;
-	struct xdna_notify *hdl = msg->handle;
-	int ret;
-
-	if (!ndev->mgmt_chann)
-		return -ENODEV;
-
-	ret = xdna_send_msg_wait(xdna, ndev->mgmt_chann, msg);
-	if (ret == -ETIME)
-		aie2_destroy_mgmt_chann(ndev);
-
-	if (!ret && *hdl->status != AIE2_STATUS_SUCCESS) {
-		XDNA_ERR(xdna, "command opcode 0x%x failed, status 0x%x",
-			 msg->opcode, *hdl->data);
-		ret = -EINVAL;
-	}
-
-	return ret;
-}
-
 void *aie2_alloc_msg_buffer(struct amdxdna_dev_hdl *ndev, u32 *size,
 			    dma_addr_t *dma_addr)
 {
-	struct amdxdna_dev *xdna = ndev->xdna;
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	void *vaddr;
 	int order;
 
@@ -79,7 +54,7 @@ void *aie2_alloc_msg_buffer(struct amdxdna_dev_hdl *ndev, u32 *size,
 void aie2_free_msg_buffer(struct amdxdna_dev_hdl *ndev, size_t size,
 			  void *cpu_addr, dma_addr_t dma_addr)
 {
-	struct amdxdna_dev *xdna = ndev->xdna;
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 
 	if (amdxdna_iova_on(xdna)) {
 		amdxdna_iommu_free(xdna, size, cpu_addr, dma_addr);
@@ -91,12 +66,12 @@ void aie2_free_msg_buffer(struct amdxdna_dev_hdl *ndev, size_t size,
 
 int aie2_suspend_fw(struct amdxdna_dev_hdl *ndev)
 {
-	DECLARE_AIE2_MSG(suspend, MSG_OP_SUSPEND);
+	DECLARE_AIE_MSG(suspend, MSG_OP_SUSPEND);
 	int ret;
 
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Failed to suspend fw, ret %d", ret);
+		XDNA_ERR(ndev->aie.xdna, "Failed to suspend fw, ret %d", ret);
 		return ret;
 	}
 
@@ -105,22 +80,22 @@ int aie2_suspend_fw(struct amdxdna_dev_hdl *ndev)
 
 int aie2_resume_fw(struct amdxdna_dev_hdl *ndev)
 {
-	DECLARE_AIE2_MSG(suspend, MSG_OP_RESUME);
+	DECLARE_AIE_MSG(suspend, MSG_OP_RESUME);
 
-	return aie2_send_mgmt_msg_wait(ndev, &msg);
+	return aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 }
 
 int aie2_set_runtime_cfg(struct amdxdna_dev_hdl *ndev, u32 type, u64 value)
 {
-	DECLARE_AIE2_MSG(set_runtime_cfg, MSG_OP_SET_RUNTIME_CONFIG);
+	DECLARE_AIE_MSG(set_runtime_cfg, MSG_OP_SET_RUNTIME_CONFIG);
 	int ret;
 
 	req.type = type;
 	req.value = value;
 
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Failed to set runtime config, ret %d", ret);
+		XDNA_ERR(ndev->aie.xdna, "Failed to set runtime config, ret %d", ret);
 		return ret;
 	}
 
@@ -129,13 +104,13 @@ int aie2_set_runtime_cfg(struct amdxdna_dev_hdl *ndev, u32 type, u64 value)
 
 int aie2_get_runtime_cfg(struct amdxdna_dev_hdl *ndev, u32 type, u64 *value)
 {
-	DECLARE_AIE2_MSG(get_runtime_cfg, MSG_OP_GET_RUNTIME_CONFIG);
+	DECLARE_AIE_MSG(get_runtime_cfg, MSG_OP_GET_RUNTIME_CONFIG);
 	int ret;
 
 	req.type = type;
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Failed to get runtime config, ret %d", ret);
+		XDNA_ERR(ndev->aie.xdna, "Failed to get runtime config, ret %d", ret);
 		return ret;
 	}
 
@@ -145,20 +120,20 @@ int aie2_get_runtime_cfg(struct amdxdna_dev_hdl *ndev, u32 type, u64 *value)
 
 int aie2_assign_mgmt_pasid(struct amdxdna_dev_hdl *ndev, u16 pasid)
 {
-	DECLARE_AIE2_MSG(assign_mgmt_pasid, MSG_OP_ASSIGN_MGMT_PASID);
+	DECLARE_AIE_MSG(assign_mgmt_pasid, MSG_OP_ASSIGN_MGMT_PASID);
 
 	req.pasid = pasid;
 
-	return aie2_send_mgmt_msg_wait(ndev, &msg);
+	return aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 }
 
 int aie2_query_aie_version(struct amdxdna_dev_hdl *ndev, struct aie_version *version)
 {
-	DECLARE_AIE2_MSG(aie_version_info, MSG_OP_QUERY_AIE_VERSION);
-	struct amdxdna_dev *xdna = ndev->xdna;
+	DECLARE_AIE_MSG(aie_version_info, MSG_OP_QUERY_AIE_VERSION);
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	int ret;
 
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret)
 		return ret;
 
@@ -173,10 +148,10 @@ int aie2_query_aie_version(struct amdxdna_dev_hdl *ndev, struct aie_version *ver
 
 int aie2_query_aie_metadata(struct amdxdna_dev_hdl *ndev, struct aie_metadata *metadata)
 {
-	DECLARE_AIE2_MSG(aie_tile_info, MSG_OP_QUERY_AIE_TILE_INFO);
+	DECLARE_AIE_MSG(aie_tile_info, MSG_OP_QUERY_AIE_TILE_INFO);
 	int ret;
 
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret)
 		return ret;
 
@@ -211,10 +186,10 @@ int aie2_query_aie_metadata(struct amdxdna_dev_hdl *ndev, struct aie_metadata *m
 int aie2_query_firmware_version(struct amdxdna_dev_hdl *ndev,
 				struct amdxdna_fw_ver *fw_ver)
 {
-	DECLARE_AIE2_MSG(firmware_version, MSG_OP_GET_FIRMWARE_VERSION);
+	DECLARE_AIE_MSG(firmware_version, MSG_OP_GET_FIRMWARE_VERSION);
 	int ret;
 
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret)
 		return ret;
 
@@ -228,12 +203,12 @@ int aie2_query_firmware_version(struct amdxdna_dev_hdl *ndev,
 
 static int aie2_destroy_context_req(struct amdxdna_dev_hdl *ndev, u32 id)
 {
-	DECLARE_AIE2_MSG(destroy_ctx, MSG_OP_DESTROY_CONTEXT);
-	struct amdxdna_dev *xdna = ndev->xdna;
+	DECLARE_AIE_MSG(destroy_ctx, MSG_OP_DESTROY_CONTEXT);
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	int ret;
 
 	req.context_id = id;
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret && ret != -ENODEV)
 		XDNA_WARN(xdna, "Destroy context failed, ret %d", ret);
 	else if (ret == -ENODEV)
@@ -245,7 +220,7 @@ static int aie2_destroy_context_req(struct amdxdna_dev_hdl *ndev, u32 id)
 static u32 aie2_get_context_priority(struct amdxdna_dev_hdl *ndev,
 				     struct amdxdna_hwctx *hwctx)
 {
-	if (!AIE2_FEATURE_ON(ndev, AIE2_PREEMPT))
+	if (!AIE_FEATURE_ON(&ndev->aie, AIE2_PREEMPT))
 		return PRIORITY_HIGH;
 
 	switch (hwctx->qos.priority) {
@@ -264,8 +239,8 @@ static u32 aie2_get_context_priority(struct amdxdna_dev_hdl *ndev,
 
 int aie2_create_context(struct amdxdna_dev_hdl *ndev, struct amdxdna_hwctx *hwctx)
 {
-	DECLARE_AIE2_MSG(create_ctx, MSG_OP_CREATE_CONTEXT);
-	struct amdxdna_dev *xdna = ndev->xdna;
+	DECLARE_AIE_MSG(create_ctx, MSG_OP_CREATE_CONTEXT);
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	struct xdna_mailbox_chann_res x2i;
 	struct xdna_mailbox_chann_res i2x;
 	struct cq_pair *cq_pair;
@@ -280,7 +255,7 @@ int aie2_create_context(struct amdxdna_dev_hdl *ndev, struct amdxdna_hwctx *hwct
 	req.pasid = amdxdna_pasid_on(hwctx->client) ? hwctx->client->pasid : 0;
 	req.context_priority = aie2_get_context_priority(ndev, hwctx);
 
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret)
 		return ret;
 
@@ -344,7 +319,7 @@ int aie2_create_context(struct amdxdna_dev_hdl *ndev, struct amdxdna_hwctx *hwct
 
 int aie2_destroy_context(struct amdxdna_dev_hdl *ndev, struct amdxdna_hwctx *hwctx)
 {
-	struct amdxdna_dev *xdna = ndev->xdna;
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	int ret;
 
 	if (!hwctx->priv->mbox_chann)
@@ -363,14 +338,14 @@ int aie2_destroy_context(struct amdxdna_dev_hdl *ndev, struct amdxdna_hwctx *hwc
 
 int aie2_map_host_buf(struct amdxdna_dev_hdl *ndev, u32 context_id, u64 addr, u64 size)
 {
-	DECLARE_AIE2_MSG(map_host_buffer, MSG_OP_MAP_HOST_BUFFER);
-	struct amdxdna_dev *xdna = ndev->xdna;
+	DECLARE_AIE_MSG(map_host_buffer, MSG_OP_MAP_HOST_BUFFER);
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	int ret;
 
 	req.context_id = context_id;
 	req.buf_addr = addr;
 	req.buf_size = size;
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret)
 		return ret;
 
@@ -392,8 +367,8 @@ static int amdxdna_hwctx_col_map(struct amdxdna_hwctx *hwctx, void *arg)
 int aie2_query_status(struct amdxdna_dev_hdl *ndev, char __user *buf,
 		      u32 size, u32 *cols_filled)
 {
-	DECLARE_AIE2_MSG(aie_column_info, MSG_OP_QUERY_COL_STATUS);
-	struct amdxdna_dev *xdna = ndev->xdna;
+	DECLARE_AIE_MSG(aie_column_info, MSG_OP_QUERY_COL_STATUS);
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	u32 buf_sz = size, aie_bitmap = 0;
 	struct amdxdna_client *client;
 	dma_addr_t dma_addr;
@@ -415,7 +390,7 @@ int aie2_query_status(struct amdxdna_dev_hdl *ndev, char __user *buf,
 	req.aie_bitmap = aie_bitmap;
 
 	drm_clflush_virt_range(buff_addr, size); /* device can access */
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret) {
 		XDNA_ERR(xdna, "Error during NPU query, status %d", ret);
 		goto fail;
@@ -446,8 +421,8 @@ int aie2_query_telemetry(struct amdxdna_dev_hdl *ndev,
 			 char __user *buf, u32 size,
 			 struct amdxdna_drm_query_telemetry_header *header)
 {
-	DECLARE_AIE2_MSG(get_telemetry, MSG_OP_GET_TELEMETRY);
-	struct amdxdna_dev *xdna = ndev->xdna;
+	DECLARE_AIE_MSG(get_telemetry, MSG_OP_GET_TELEMETRY);
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	dma_addr_t dma_addr;
 	u32 buf_sz = size;
 	u8 *addr;
@@ -465,7 +440,7 @@ int aie2_query_telemetry(struct amdxdna_dev_hdl *ndev,
 	req.type = header->type;
 
 	drm_clflush_virt_range(addr, size); /* device can access */
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret) {
 		XDNA_ERR(xdna, "Query telemetry failed, status %d", ret);
 		goto free_buf;
@@ -506,8 +481,8 @@ int aie2_register_asyn_event_msg(struct amdxdna_dev_hdl *ndev, dma_addr_t addr,
 	req.buf_addr = addr;
 	req.buf_size = size;
 
-	XDNA_DBG(ndev->xdna, "Register addr 0x%llx size 0x%x", addr, size);
-	return xdna_mailbox_send_msg(ndev->mgmt_chann, &msg, TX_TIMEOUT);
+	XDNA_DBG(ndev->aie.xdna, "Register addr 0x%llx size 0x%x", addr, size);
+	return xdna_mailbox_send_msg(ndev->aie.mgmt_chann, &msg, TX_TIMEOUT);
 }
 
 int aie2_config_cu(struct amdxdna_hwctx *hwctx,
@@ -866,7 +841,6 @@ static int aie2_init_exec_req(void *req, struct amdxdna_gem_obj *cmd_abo,
 	int ret;
 	u32 op;
 
-
 	op = amdxdna_cmd_get_op(cmd_abo);
 	switch (op) {
 	case ERT_START_CU:
@@ -915,12 +889,12 @@ aie2_cmdlist_fill_slot(void *slot, struct amdxdna_gem_obj *cmd_abo,
 		ret = EXEC_MSG_OPS(xdna)->fill_dpu_slot(cmd_abo, slot, size);
 		break;
 	case ERT_START_NPU_PREEMPT:
-		if (!AIE2_FEATURE_ON(xdna->dev_handle, AIE2_PREEMPT))
+		if (!AIE_FEATURE_ON(&xdna->dev_handle->aie, AIE2_PREEMPT))
 			return -EOPNOTSUPP;
 		ret = EXEC_MSG_OPS(xdna)->fill_preempt_slot(cmd_abo, slot, size);
 		break;
 	case ERT_START_NPU_PREEMPT_ELF:
-		if (!AIE2_FEATURE_ON(xdna->dev_handle, AIE2_PREEMPT))
+		if (!AIE_FEATURE_ON(&xdna->dev_handle->aie, AIE2_PREEMPT))
 			return -EOPNOTSUPP;
 		ret = EXEC_MSG_OPS(xdna)->fill_elf_slot(cmd_abo, slot, size);
 		break;
@@ -935,26 +909,12 @@ aie2_cmdlist_fill_slot(void *slot, struct amdxdna_gem_obj *cmd_abo,
 
 void aie2_msg_init(struct amdxdna_dev_hdl *ndev)
 {
-	if (AIE2_FEATURE_ON(ndev, AIE2_NPU_COMMAND))
+	if (AIE_FEATURE_ON(&ndev->aie, AIE2_NPU_COMMAND))
 		ndev->exec_msg_ops = &npu_exec_message_ops;
 	else
 		ndev->exec_msg_ops = &legacy_exec_message_ops;
 }
 
-void aie2_destroy_mgmt_chann(struct amdxdna_dev_hdl *ndev)
-{
-	struct amdxdna_dev *xdna = ndev->xdna;
-
-	drm_WARN_ON(&xdna->ddev, !mutex_is_locked(&xdna->dev_lock));
-
-	if (!ndev->mgmt_chann)
-		return;
-
-	xdna_mailbox_stop_channel(ndev->mgmt_chann);
-	xdna_mailbox_free_channel(ndev->mgmt_chann);
-	ndev->mgmt_chann = NULL;
-}
-
 static inline struct amdxdna_gem_obj *
 aie2_cmdlist_get_cmd_buf(struct amdxdna_sched_job *job)
 {
@@ -1199,14 +1159,14 @@ int aie2_config_debug_bo(struct amdxdna_hwctx *hwctx, struct amdxdna_sched_job *
 int aie2_query_app_health(struct amdxdna_dev_hdl *ndev, u32 context_id,
 			  struct app_health_report *report)
 {
-	DECLARE_AIE2_MSG(get_app_health, MSG_OP_GET_APP_HEALTH);
-	struct amdxdna_dev *xdna = ndev->xdna;
+	DECLARE_AIE_MSG(get_app_health, MSG_OP_GET_APP_HEALTH);
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	struct app_health_report *buf;
 	dma_addr_t dma_addr;
 	u32 buf_size;
 	int ret;
 
-	if (!AIE2_FEATURE_ON(ndev, AIE2_APP_HEALTH)) {
+	if (!AIE_FEATURE_ON(&ndev->aie, AIE2_APP_HEALTH)) {
 		XDNA_DBG(xdna, "App health feature not supported");
 		return -EOPNOTSUPP;
 	}
@@ -1223,7 +1183,7 @@ int aie2_query_app_health(struct amdxdna_dev_hdl *ndev, u32 context_id,
 	req.buf_size = buf_size;
 
 	drm_clflush_virt_range(buf, sizeof(*report));
-	ret = aie2_send_mgmt_msg_wait(ndev, &msg);
+	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret) {
 		XDNA_ERR(xdna, "Get app health failed, ret %d status 0x%x", ret, resp.status);
 		goto free_buf;
diff --git a/drivers/accel/amdxdna/aie2_pci.c b/drivers/accel/amdxdna/aie2_pci.c
index 4500b9ccb02e0c..ebdac0eaa365e2 100644
--- a/drivers/accel/amdxdna/aie2_pci.c
+++ b/drivers/accel/amdxdna/aie2_pci.c
@@ -60,45 +60,6 @@ struct mgmt_mbox_chann_info {
 	__u32	rsvd[4];
 };
 
-static int aie2_check_protocol(struct amdxdna_dev_hdl *ndev, u32 fw_major, u32 fw_minor)
-{
-	const struct aie2_fw_feature_tbl *feature;
-	bool found = false;
-
-	for (feature = ndev->priv->fw_feature_tbl; feature->major; feature++) {
-		if (feature->major != fw_major)
-			continue;
-		if (fw_minor < feature->min_minor)
-			continue;
-		if (feature->max_minor > 0 && fw_minor > feature->max_minor)
-			continue;
-
-		ndev->feature_mask |= feature->features;
-
-		/* firmware version matches one of the driver support entry */
-		found = true;
-	}
-
-	return found ? 0 : -EOPNOTSUPP;
-}
-
-static void aie2_dump_chann_info_debug(struct amdxdna_dev_hdl *ndev)
-{
-	struct amdxdna_dev *xdna = ndev->xdna;
-
-	XDNA_DBG(xdna, "i2x tail    0x%x", ndev->mgmt_i2x.mb_tail_ptr_reg);
-	XDNA_DBG(xdna, "i2x head    0x%x", ndev->mgmt_i2x.mb_head_ptr_reg);
-	XDNA_DBG(xdna, "i2x ringbuf 0x%x", ndev->mgmt_i2x.rb_start_addr);
-	XDNA_DBG(xdna, "i2x rsize   0x%x", ndev->mgmt_i2x.rb_size);
-	XDNA_DBG(xdna, "x2i tail    0x%x", ndev->mgmt_x2i.mb_tail_ptr_reg);
-	XDNA_DBG(xdna, "x2i head    0x%x", ndev->mgmt_x2i.mb_head_ptr_reg);
-	XDNA_DBG(xdna, "x2i ringbuf 0x%x", ndev->mgmt_x2i.rb_start_addr);
-	XDNA_DBG(xdna, "x2i rsize   0x%x", ndev->mgmt_x2i.rb_size);
-	XDNA_DBG(xdna, "x2i chann index 0x%x", ndev->mgmt_chan_idx);
-	XDNA_DBG(xdna, "mailbox protocol major 0x%x", ndev->mgmt_prot_major);
-	XDNA_DBG(xdna, "mailbox protocol minor 0x%x", ndev->mgmt_prot_minor);
-}
-
 static int aie2_get_mgmt_chann_info(struct amdxdna_dev_hdl *ndev)
 {
 	struct mgmt_mbox_chann_info info_regs;
@@ -128,13 +89,13 @@ static int aie2_get_mgmt_chann_info(struct amdxdna_dev_hdl *ndev)
 		reg[i] = readl(ndev->sram_base + off + i * sizeof(u32));
 
 	if (info_regs.magic != MGMT_MBOX_MAGIC) {
-		XDNA_ERR(ndev->xdna, "Invalid mbox magic 0x%x", info_regs.magic);
+		XDNA_ERR(ndev->aie.xdna, "Invalid mbox magic 0x%x", info_regs.magic);
 		ret = -EINVAL;
 		goto done;
 	}
 
-	i2x = &ndev->mgmt_i2x;
-	x2i = &ndev->mgmt_x2i;
+	i2x = &ndev->aie.mgmt_i2x;
+	x2i = &ndev->aie.mgmt_x2i;
 
 	i2x->mb_head_ptr_reg = AIE2_MBOX_OFF(ndev, info_regs.i2x_head);
 	i2x->mb_tail_ptr_reg = AIE2_MBOX_OFF(ndev, info_regs.i2x_tail);
@@ -146,14 +107,15 @@ static int aie2_get_mgmt_chann_info(struct amdxdna_dev_hdl *ndev)
 	x2i->rb_start_addr   = AIE2_SRAM_OFF(ndev, info_regs.x2i_buf);
 	x2i->rb_size         = info_regs.x2i_buf_sz;
 
-	ndev->mgmt_chan_idx  = info_regs.msi_id;
-	ndev->mgmt_prot_major = info_regs.prot_major;
-	ndev->mgmt_prot_minor = info_regs.prot_minor;
+	ndev->aie.mgmt_chan_idx  = info_regs.msi_id;
+	ndev->aie.mgmt_prot_major = info_regs.prot_major;
+	ndev->aie.mgmt_prot_minor = info_regs.prot_minor;
 
-	ret = aie2_check_protocol(ndev, ndev->mgmt_prot_major, ndev->mgmt_prot_minor);
+	ret = aie_check_protocol(&ndev->aie, ndev->aie.mgmt_prot_major,
+				 ndev->aie.mgmt_prot_minor);
 
 done:
-	aie2_dump_chann_info_debug(ndev);
+	aie_dump_mgmt_chann_debug(&ndev->aie);
 
 	/* Must clear address at FW_ALIVE_OFF */
 	writel(0, SRAM_GET_ADDR(ndev, FW_ALIVE_OFF));
@@ -173,13 +135,14 @@ int aie2_runtime_cfg(struct amdxdna_dev_hdl *ndev,
 			continue;
 
 		if (cfg->feature_mask &&
-		    bitmap_subset(&cfg->feature_mask, &ndev->feature_mask, AIE2_FEATURE_MAX))
+		    bitmap_subset(&cfg->feature_mask, &ndev->aie.feature_mask,
+				  AIE2_FEATURE_MAX))
 			continue;
 
 		value = val ? *val : cfg->value;
 		ret = aie2_set_runtime_cfg(ndev, cfg->type, value);
 		if (ret) {
-			XDNA_ERR(ndev->xdna, "Set type %d value %d failed",
+			XDNA_ERR(ndev->aie.xdna, "Set type %d value %d failed",
 				 cfg->type, value);
 			return ret;
 		}
@@ -194,13 +157,13 @@ static int aie2_xdna_reset(struct amdxdna_dev_hdl *ndev)
 
 	ret = aie2_suspend_fw(ndev);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Suspend firmware failed");
+		XDNA_ERR(ndev->aie.xdna, "Suspend firmware failed");
 		return ret;
 	}
 
 	ret = aie2_resume_fw(ndev);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Resume firmware failed");
+		XDNA_ERR(ndev->aie.xdna, "Resume firmware failed");
 		return ret;
 	}
 
@@ -213,19 +176,19 @@ static int aie2_mgmt_fw_init(struct amdxdna_dev_hdl *ndev)
 
 	ret = aie2_runtime_cfg(ndev, AIE2_RT_CFG_INIT, NULL);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Runtime config failed");
+		XDNA_ERR(ndev->aie.xdna, "Runtime config failed");
 		return ret;
 	}
 
 	ret = aie2_assign_mgmt_pasid(ndev, 0);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Can not assign PASID");
+		XDNA_ERR(ndev->aie.xdna, "Can not assign PASID");
 		return ret;
 	}
 
 	ret = aie2_xdna_reset(ndev);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Reset firmware failed");
+		XDNA_ERR(ndev->aie.xdna, "Reset firmware failed");
 		return ret;
 	}
 
@@ -236,21 +199,21 @@ static int aie2_mgmt_fw_query(struct amdxdna_dev_hdl *ndev)
 {
 	int ret;
 
-	ret = aie2_query_firmware_version(ndev, &ndev->xdna->fw_ver);
+	ret = aie2_query_firmware_version(ndev, &ndev->aie.xdna->fw_ver);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "query firmware version failed");
+		XDNA_ERR(ndev->aie.xdna, "query firmware version failed");
 		return ret;
 	}
 
 	ret = aie2_query_aie_version(ndev, &ndev->version);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Query AIE version failed");
+		XDNA_ERR(ndev->aie.xdna, "Query AIE version failed");
 		return ret;
 	}
 
 	ret = aie2_query_aie_metadata(ndev, &ndev->metadata);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Query AIE metadata failed");
+		XDNA_ERR(ndev->aie.xdna, "Query AIE metadata failed");
 		return ret;
 	}
 
@@ -262,8 +225,8 @@ static int aie2_mgmt_fw_query(struct amdxdna_dev_hdl *ndev)
 static void aie2_mgmt_fw_fini(struct amdxdna_dev_hdl *ndev)
 {
 	if (aie2_suspend_fw(ndev))
-		XDNA_ERR(ndev->xdna, "Suspend_fw failed");
-	XDNA_DBG(ndev->xdna, "Firmware suspended");
+		XDNA_ERR(ndev->aie.xdna, "Suspend_fw failed");
+	XDNA_DBG(ndev->aie.xdna, "Firmware suspended");
 }
 
 static int aie2_xrs_load(void *cb_arg, struct xrs_action_load *action)
@@ -331,7 +294,7 @@ static void aie2_hw_stop(struct amdxdna_dev *xdna)
 
 	aie2_runtime_cfg(ndev, AIE2_RT_CFG_CLK_GATING, NULL);
 	aie2_mgmt_fw_fini(ndev);
-	aie2_destroy_mgmt_chann(ndev);
+	aie_destroy_chann(&ndev->aie, &ndev->aie.mgmt_chann);
 	drmm_kfree(&xdna->ddev, ndev->mbox);
 	ndev->mbox = NULL;
 	aie2_psp_stop(ndev->psp_hdl);
@@ -374,8 +337,8 @@ static int aie2_hw_start(struct amdxdna_dev *xdna)
 		goto disable_dev;
 	}
 
-	ndev->mgmt_chann = xdna_mailbox_alloc_channel(ndev->mbox);
-	if (!ndev->mgmt_chann) {
+	ndev->aie.mgmt_chann = xdna_mailbox_alloc_channel(ndev->mbox);
+	if (!ndev->aie.mgmt_chann) {
 		XDNA_ERR(xdna, "failed to alloc channel");
 		ret = -ENODEV;
 		goto disable_dev;
@@ -399,17 +362,17 @@ static int aie2_hw_start(struct amdxdna_dev *xdna)
 		goto stop_psp;
 	}
 
-	mgmt_mb_irq = pci_irq_vector(pdev, ndev->mgmt_chan_idx);
+	mgmt_mb_irq = pci_irq_vector(pdev, ndev->aie.mgmt_chan_idx);
 	if (mgmt_mb_irq < 0) {
 		ret = mgmt_mb_irq;
 		XDNA_ERR(xdna, "failed to alloc irq vector, ret %d", ret);
 		goto stop_psp;
 	}
 
-	xdna_mailbox_intr_reg = ndev->mgmt_i2x.mb_head_ptr_reg + 4;
-	ret = xdna_mailbox_start_channel(ndev->mgmt_chann,
-					 &ndev->mgmt_x2i,
-					 &ndev->mgmt_i2x,
+	xdna_mailbox_intr_reg = ndev->aie.mgmt_i2x.mb_head_ptr_reg + 4;
+	ret = xdna_mailbox_start_channel(ndev->aie.mgmt_chann,
+					 &ndev->aie.mgmt_x2i,
+					 &ndev->aie.mgmt_i2x,
 					 xdna_mailbox_intr_reg,
 					 mgmt_mb_irq);
 	if (ret) {
@@ -448,14 +411,14 @@ static int aie2_hw_start(struct amdxdna_dev *xdna)
 
 stop_fw:
 	aie2_suspend_fw(ndev);
-	xdna_mailbox_stop_channel(ndev->mgmt_chann);
+	xdna_mailbox_stop_channel(ndev->aie.mgmt_chann);
 stop_psp:
 	aie2_psp_stop(ndev->psp_hdl);
 fini_smu:
 	aie2_smu_fini(ndev);
 free_channel:
-	xdna_mailbox_free_channel(ndev->mgmt_chann);
-	ndev->mgmt_chann = NULL;
+	xdna_mailbox_free_channel(ndev->aie.mgmt_chann);
+	ndev->aie.mgmt_chann = NULL;
 disable_dev:
 	pci_disable_device(pdev);
 
@@ -521,7 +484,7 @@ static int aie2_init(struct amdxdna_dev *xdna)
 		return -ENOMEM;
 
 	ndev->priv = xdna->dev_info->dev_priv;
-	ndev->xdna = xdna;
+	ndev->aie.xdna = xdna;
 
 	for (i = 0; i < ARRAY_SIZE(npu_fw); i++) {
 		fw_full_path = kasprintf(GFP_KERNEL, "%s%s", ndev->priv->fw_path, npu_fw[i]);
diff --git a/drivers/accel/amdxdna/aie2_pci.h b/drivers/accel/amdxdna/aie2_pci.h
index efcf4be035f048..90fb0aafaf406c 100644
--- a/drivers/accel/amdxdna/aie2_pci.h
+++ b/drivers/accel/amdxdna/aie2_pci.h
@@ -10,6 +10,7 @@
 #include <linux/limits.h>
 #include <linux/semaphore.h>
 
+#include "aie.h"
 #include "aie2_msg_priv.h"
 #include "amdxdna_mailbox.h"
 
@@ -20,7 +21,7 @@
 #define AIE2_DEVM_BASE	0x4000000
 #define AIE2_DEVM_SIZE	SZ_64M
 
-#define NDEV2PDEV(ndev) (to_pci_dev((ndev)->xdna->ddev.dev))
+#define NDEV2PDEV(ndev) (to_pci_dev((ndev)->aie.xdna->ddev.dev))
 
 #define AIE2_SRAM_OFF(ndev, addr) ((addr) - (ndev)->priv->sram_dev_addr)
 #define AIE2_MBOX_OFF(ndev, addr) ((addr) - (ndev)->priv->mbox_dev_addr)
@@ -45,7 +46,7 @@
 ({ \
 	typeof(ndev) _ndev = (ndev); \
 	((_ndev)->priv->mbox_size) ? (_ndev)->priv->mbox_size : \
-	pci_resource_len(NDEV2PDEV(_ndev), (_ndev)->xdna->dev_info->mbox_bar); \
+	pci_resource_len(NDEV2PDEV(_ndev), (_ndev)->aie.xdna->dev_info->mbox_bar); \
 })
 
 #if IS_ENABLED(CONFIG_AMD_PMF)
@@ -203,23 +204,16 @@ struct aie2_exec_msg_ops {
 };
 
 struct amdxdna_dev_hdl {
-	struct amdxdna_dev		*xdna;
+	struct aie_device		aie;
 	const struct amdxdna_dev_priv	*priv;
 	void			__iomem *sram_base;
 	void			__iomem *smu_base;
 	void			__iomem *mbox_base;
 	struct psp_device		*psp_hdl;
 
-	struct xdna_mailbox_chann_res	mgmt_x2i;
-	struct xdna_mailbox_chann_res	mgmt_i2x;
-	u32				mgmt_chan_idx;
-	u32				mgmt_prot_major;
-	u32				mgmt_prot_minor;
-
 	u32				total_col;
 	struct aie_version		version;
 	struct aie_metadata		metadata;
-	unsigned long			feature_mask;
 	struct aie2_exec_msg_ops	*exec_msg_ops;
 
 	/* power management and clock*/
@@ -237,7 +231,6 @@ struct amdxdna_dev_hdl {
 
 	/* Mailbox and the management channel */
 	struct mailbox			*mbox;
-	struct mailbox_channel		*mgmt_chann;
 	struct async_events		*async_events;
 
 	enum aie2_dev_status		dev_status;
@@ -266,21 +259,12 @@ enum aie2_fw_feature {
 	AIE2_FEATURE_MAX
 };
 
-struct aie2_fw_feature_tbl {
-	u64 features;
-	u32 major;
-	u32 max_minor;
-	u32 min_minor;
-};
-
 #define AIE2_ALL_FEATURES	GENMASK_ULL(AIE2_FEATURE_MAX - 1, AIE2_NPU_COMMAND)
-#define AIE2_FEATURE_ON(ndev, feature)	test_bit(feature, &(ndev)->feature_mask)
 
 struct amdxdna_dev_priv {
 	const char			*fw_path;
 	const struct rt_config		*rt_config;
 	const struct dpm_clk_freq	*dpm_clk_tbl;
-	const struct aie2_fw_feature_tbl *fw_feature_tbl;
 
 #define COL_ALIGN_NONE   0
 #define COL_ALIGN_NATURE 1
@@ -306,7 +290,7 @@ extern const struct dpm_clk_freq npu1_dpm_clk_table[];
 extern const struct dpm_clk_freq npu4_dpm_clk_table[];
 extern const struct rt_config npu1_default_rt_cfg[];
 extern const struct rt_config npu4_default_rt_cfg[];
-extern const struct aie2_fw_feature_tbl npu4_fw_feature_table[];
+extern const struct amdxdna_fw_feature_tbl npu4_fw_feature_table[];
 
 /* aie2_smu.c */
 int aie2_smu_init(struct amdxdna_dev_hdl *ndev);
diff --git a/drivers/accel/amdxdna/aie2_pm.c b/drivers/accel/amdxdna/aie2_pm.c
index 29bd4403a94d44..5ec6728d04fd5b 100644
--- a/drivers/accel/amdxdna/aie2_pm.c
+++ b/drivers/accel/amdxdna/aie2_pm.c
@@ -31,14 +31,14 @@ int aie2_pm_set_dpm(struct amdxdna_dev_hdl *ndev, u32 dpm_level)
 {
 	int ret;
 
-	ret = amdxdna_pm_resume_get_locked(ndev->xdna);
+	ret = amdxdna_pm_resume_get_locked(ndev->aie.xdna);
 	if (ret)
 		return ret;
 
 	ret = ndev->priv->hw_ops.set_dpm(ndev, dpm_level);
 	if (!ret)
 		ndev->dpm_level = dpm_level;
-	amdxdna_pm_suspend_put(ndev->xdna);
+	amdxdna_pm_suspend_put(ndev->aie.xdna);
 
 	return ret;
 }
@@ -81,7 +81,7 @@ int aie2_pm_init(struct amdxdna_dev_hdl *ndev)
 
 int aie2_pm_set_mode(struct amdxdna_dev_hdl *ndev, enum amdxdna_power_mode_type target)
 {
-	struct amdxdna_dev *xdna = ndev->xdna;
+	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	u32 clk_gating, dpm_level;
 	int ret;
 
diff --git a/drivers/accel/amdxdna/aie2_smu.c b/drivers/accel/amdxdna/aie2_smu.c
index d8c31924e501ba..727637dac3a8d0 100644
--- a/drivers/accel/amdxdna/aie2_smu.c
+++ b/drivers/accel/amdxdna/aie2_smu.c
@@ -46,7 +46,7 @@ static int aie2_smu_exec(struct amdxdna_dev_hdl *ndev, u32 reg_cmd,
 	ret = readx_poll_timeout(readl, SMU_REG(ndev, SMU_RESP_REG), resp,
 				 resp, AIE2_INTERVAL, AIE2_TIMEOUT);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "smu cmd %d timed out", reg_cmd);
+		XDNA_ERR(ndev->aie.xdna, "smu cmd %d timed out", reg_cmd);
 		return ret;
 	}
 
@@ -54,7 +54,7 @@ static int aie2_smu_exec(struct amdxdna_dev_hdl *ndev, u32 reg_cmd,
 		*out = readl(SMU_REG(ndev, SMU_OUT_REG));
 
 	if (resp != SMU_RESULT_OK) {
-		XDNA_ERR(ndev->xdna, "smu cmd %d failed, 0x%x", reg_cmd, resp);
+		XDNA_ERR(ndev->aie.xdna, "smu cmd %d failed, 0x%x", reg_cmd, resp);
 		return -EINVAL;
 	}
 
@@ -69,7 +69,7 @@ int npu1_set_dpm(struct amdxdna_dev_hdl *ndev, u32 dpm_level)
 	ret = aie2_smu_exec(ndev, AIE2_SMU_SET_MPNPUCLK_FREQ,
 			    ndev->priv->dpm_clk_tbl[dpm_level].npuclk, &freq);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Set npu clock to %d failed, ret %d\n",
+		XDNA_ERR(ndev->aie.xdna, "Set npu clock to %d failed, ret %d\n",
 			 ndev->priv->dpm_clk_tbl[dpm_level].npuclk, ret);
 		return ret;
 	}
@@ -78,7 +78,7 @@ int npu1_set_dpm(struct amdxdna_dev_hdl *ndev, u32 dpm_level)
 	ret = aie2_smu_exec(ndev, AIE2_SMU_SET_HCLK_FREQ,
 			    ndev->priv->dpm_clk_tbl[dpm_level].hclk, &freq);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Set h clock to %d failed, ret %d\n",
+		XDNA_ERR(ndev->aie.xdna, "Set h clock to %d failed, ret %d\n",
 			 ndev->priv->dpm_clk_tbl[dpm_level].hclk, ret);
 		return ret;
 	}
@@ -87,7 +87,7 @@ int npu1_set_dpm(struct amdxdna_dev_hdl *ndev, u32 dpm_level)
 	ndev->max_tops = 2 * ndev->total_col;
 	ndev->curr_tops = ndev->max_tops * freq / 1028;
 
-	XDNA_DBG(ndev->xdna, "MP-NPU clock %d, H clock %d\n",
+	XDNA_DBG(ndev->aie.xdna, "MP-NPU clock %d, H clock %d\n",
 		 ndev->npuclk_freq, ndev->hclk_freq);
 
 	return 0;
@@ -99,14 +99,14 @@ int npu4_set_dpm(struct amdxdna_dev_hdl *ndev, u32 dpm_level)
 
 	ret = aie2_smu_exec(ndev, AIE2_SMU_SET_HARD_DPMLEVEL, dpm_level, NULL);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Set hard dpm level %d failed, ret %d ",
+		XDNA_ERR(ndev->aie.xdna, "Set hard dpm level %d failed, ret %d ",
 			 dpm_level, ret);
 		return ret;
 	}
 
 	ret = aie2_smu_exec(ndev, AIE2_SMU_SET_SOFT_DPMLEVEL, dpm_level, NULL);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Set soft dpm level %d failed, ret %d",
+		XDNA_ERR(ndev->aie.xdna, "Set soft dpm level %d failed, ret %d",
 			 dpm_level, ret);
 		return ret;
 	}
@@ -116,7 +116,7 @@ int npu4_set_dpm(struct amdxdna_dev_hdl *ndev, u32 dpm_level)
 	ndev->max_tops = NPU4_DPM_TOPS(ndev, ndev->max_dpm_level);
 	ndev->curr_tops = NPU4_DPM_TOPS(ndev, dpm_level);
 
-	XDNA_DBG(ndev->xdna, "MP-NPU clock %d, H clock %d\n",
+	XDNA_DBG(ndev->aie.xdna, "MP-NPU clock %d, H clock %d\n",
 		 ndev->npuclk_freq, ndev->hclk_freq);
 
 	return 0;
@@ -132,13 +132,13 @@ int aie2_smu_init(struct amdxdna_dev_hdl *ndev)
 	 */
 	ret = aie2_smu_exec(ndev, AIE2_SMU_POWER_OFF, 0, NULL);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Access power failed, ret %d", ret);
+		XDNA_ERR(ndev->aie.xdna, "Access power failed, ret %d", ret);
 		return ret;
 	}
 
 	ret = aie2_smu_exec(ndev, AIE2_SMU_POWER_ON, 0, NULL);
 	if (ret) {
-		XDNA_ERR(ndev->xdna, "Power on failed, ret %d", ret);
+		XDNA_ERR(ndev->aie.xdna, "Power on failed, ret %d", ret);
 		return ret;
 	}
 
@@ -152,5 +152,5 @@ void aie2_smu_fini(struct amdxdna_dev_hdl *ndev)
 	ndev->priv->hw_ops.set_dpm(ndev, 0);
 	ret = aie2_smu_exec(ndev, AIE2_SMU_POWER_OFF, 0, NULL);
 	if (ret)
-		XDNA_ERR(ndev->xdna, "Power off failed, ret %d", ret);
+		XDNA_ERR(ndev->aie.xdna, "Power off failed, ret %d", ret);
 }
diff --git a/drivers/accel/amdxdna/amdxdna_pci_drv.h b/drivers/accel/amdxdna/amdxdna_pci_drv.h
index 0661749917d684..5e0bf565a1ae6b 100644
--- a/drivers/accel/amdxdna/amdxdna_pci_drv.h
+++ b/drivers/accel/amdxdna/amdxdna_pci_drv.h
@@ -66,6 +66,13 @@ struct amdxdna_dev_ops {
 	int (*get_array)(struct amdxdna_client *client, struct amdxdna_drm_get_array *args);
 };
 
+struct amdxdna_fw_feature_tbl {
+	u64 features;
+	u32 major;
+	u32 max_minor;
+	u32 min_minor;
+};
+
 /*
  * struct amdxdna_dev_info - Device hardware information
  * Record device static information, like reg, mbox, PSP, SMU bar index
@@ -83,6 +90,7 @@ struct amdxdna_dev_info {
 	size_t				dev_mem_size;
 	char				*vbnv;
 	const struct amdxdna_dev_priv	*dev_priv;
+	const struct amdxdna_fw_feature_tbl *fw_feature_tbl;
 	const struct amdxdna_dev_ops	*ops;
 };
 
diff --git a/drivers/accel/amdxdna/npu1_regs.c b/drivers/accel/amdxdna/npu1_regs.c
index 1320e924e54824..2ea7568a2e995a 100644
--- a/drivers/accel/amdxdna/npu1_regs.c
+++ b/drivers/accel/amdxdna/npu1_regs.c
@@ -65,7 +65,7 @@ const struct dpm_clk_freq npu1_dpm_clk_table[] = {
 	{ 0 }
 };
 
-static const struct aie2_fw_feature_tbl npu1_fw_feature_table[] = {
+static const struct amdxdna_fw_feature_tbl npu1_fw_feature_table[] = {
 	{ .major = 5, .min_minor = 7 },
 	{ .features = BIT_U64(AIE2_NPU_COMMAND), .major = 5, .min_minor = 8 },
 	{ 0 }
@@ -75,7 +75,6 @@ static const struct amdxdna_dev_priv npu1_dev_priv = {
 	.fw_path        = "amdnpu/1502_00/",
 	.rt_config	= npu1_default_rt_cfg,
 	.dpm_clk_tbl	= npu1_dpm_clk_table,
-	.fw_feature_tbl = npu1_fw_feature_table,
 	.col_align	= COL_ALIGN_NONE,
 	.mbox_dev_addr  = NPU1_MBOX_BAR_BASE,
 	.mbox_size      = 0, /* Use BAR size */
@@ -120,5 +119,6 @@ const struct amdxdna_dev_info dev_npu1_info = {
 	.vbnv              = "RyzenAI-npu1",
 	.device_type       = AMDXDNA_DEV_TYPE_KMQ,
 	.dev_priv          = &npu1_dev_priv,
+	.fw_feature_tbl    = npu1_fw_feature_table,
 	.ops               = &aie2_ops,
 };
diff --git a/drivers/accel/amdxdna/npu4_regs.c b/drivers/accel/amdxdna/npu4_regs.c
index 619bff042e52c6..9689c56c83beb0 100644
--- a/drivers/accel/amdxdna/npu4_regs.c
+++ b/drivers/accel/amdxdna/npu4_regs.c
@@ -88,7 +88,7 @@ const struct dpm_clk_freq npu4_dpm_clk_table[] = {
 	{ 0 }
 };
 
-const struct aie2_fw_feature_tbl npu4_fw_feature_table[] = {
+const struct amdxdna_fw_feature_tbl npu4_fw_feature_table[] = {
 	{ .major = 6, .min_minor = 12 },
 	{ .features = BIT_U64(AIE2_NPU_COMMAND), .major = 6, .min_minor = 15 },
 	{ .features = BIT_U64(AIE2_PREEMPT), .major = 6, .min_minor = 12 },
@@ -102,7 +102,6 @@ static const struct amdxdna_dev_priv npu4_dev_priv = {
 	.fw_path        = "amdnpu/17f0_10/",
 	.rt_config	= npu4_default_rt_cfg,
 	.dpm_clk_tbl	= npu4_dpm_clk_table,
-	.fw_feature_tbl = npu4_fw_feature_table,
 	.col_align	= COL_ALIGN_NATURE,
 	.mbox_dev_addr  = NPU4_MBOX_BAR_BASE,
 	.mbox_size      = 0, /* Use BAR size */
@@ -147,5 +146,6 @@ const struct amdxdna_dev_info dev_npu4_info = {
 	.vbnv              = "RyzenAI-npu4",
 	.device_type       = AMDXDNA_DEV_TYPE_KMQ,
 	.dev_priv          = &npu4_dev_priv,
+	.fw_feature_tbl    = npu4_fw_feature_table,
 	.ops               = &aie2_ops, /* NPU4 can share NPU1's callback */
 };
diff --git a/drivers/accel/amdxdna/npu5_regs.c b/drivers/accel/amdxdna/npu5_regs.c
index c0ac5daf32ee5c..98ee8780f3f5c7 100644
--- a/drivers/accel/amdxdna/npu5_regs.c
+++ b/drivers/accel/amdxdna/npu5_regs.c
@@ -66,7 +66,6 @@ static const struct amdxdna_dev_priv npu5_dev_priv = {
 	.fw_path        = "amdnpu/17f0_11/",
 	.rt_config	= npu4_default_rt_cfg,
 	.dpm_clk_tbl	= npu4_dpm_clk_table,
-	.fw_feature_tbl = npu4_fw_feature_table,
 	.col_align	= COL_ALIGN_NATURE,
 	.mbox_dev_addr  = NPU5_MBOX_BAR_BASE,
 	.mbox_size      = 0, /* Use BAR size */
@@ -111,5 +110,6 @@ const struct amdxdna_dev_info dev_npu5_info = {
 	.vbnv              = "RyzenAI-npu5",
 	.device_type       = AMDXDNA_DEV_TYPE_KMQ,
 	.dev_priv          = &npu5_dev_priv,
+	.fw_feature_tbl    = npu4_fw_feature_table,
 	.ops               = &aie2_ops,
 };
diff --git a/drivers/accel/amdxdna/npu6_regs.c b/drivers/accel/amdxdna/npu6_regs.c
index ce591ed0d4832e..31400cca5ec4c9 100644
--- a/drivers/accel/amdxdna/npu6_regs.c
+++ b/drivers/accel/amdxdna/npu6_regs.c
@@ -66,7 +66,6 @@ static const struct amdxdna_dev_priv npu6_dev_priv = {
 	.fw_path        = "amdnpu/17f0_10/",
 	.rt_config	= npu4_default_rt_cfg,
 	.dpm_clk_tbl	= npu4_dpm_clk_table,
-	.fw_feature_tbl = npu4_fw_feature_table,
 	.col_align	= COL_ALIGN_NATURE,
 	.mbox_dev_addr  = NPU6_MBOX_BAR_BASE,
 	.mbox_size      = 0, /* Use BAR size */
@@ -112,5 +111,6 @@ const struct amdxdna_dev_info dev_npu6_info = {
 	.vbnv              = "RyzenAI-npu6",
 	.device_type       = AMDXDNA_DEV_TYPE_KMQ,
 	.dev_priv          = &npu6_dev_priv,
+	.fw_feature_tbl    = npu4_fw_feature_table,
 	.ops               = &aie2_ops,
 };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0052/2077] accel/amdxdna: Adjust size for copy_to_user()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (50 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0051/2077] accel/amdxdna: Create shared functions for AIE2 and AIE4 Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0053/2077] accel/amdxdna: Handle DETACH_DEBUG_BO through config_debug_bo path Greg Kroah-Hartman
                   ` (945 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mario Limonciello (AMD), Lizhi Hou,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lizhi Hou <lizhi.hou@amd.com>

[ Upstream commit 6e87001fe19f251e2ae14373bc76554358a13df2 ]

The amount of data returned to user space should be limited by the buffer
size provided by the application. If the buffer is smaller than the data
size, return only the portion that fits instead of failing.

Fixes: 850d71f6bf4c ("accel/amdxdna: Add query functions")
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260402174148.3527757-1-lizhi.hou@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/accel/amdxdna/aie2_error.c   |  5 ++-
 drivers/accel/amdxdna/aie2_message.c | 20 ++++++----
 drivers/accel/amdxdna/aie2_pci.c     | 59 ++++++++++++++++------------
 3 files changed, 50 insertions(+), 34 deletions(-)

diff --git a/drivers/accel/amdxdna/aie2_error.c b/drivers/accel/amdxdna/aie2_error.c
index 9d20e956c020ec..70007b4363cd02 100644
--- a/drivers/accel/amdxdna/aie2_error.c
+++ b/drivers/accel/amdxdna/aie2_error.c
@@ -406,8 +406,11 @@ int aie2_get_array_async_error(struct amdxdna_dev_hdl *ndev, struct amdxdna_drm_
 
 	drm_WARN_ON(&xdna->ddev, !mutex_is_locked(&xdna->dev_lock));
 
+	if (!args->num_element)
+		return -EINVAL;
+
 	args->num_element = 1;
-	args->element_size = sizeof(ndev->last_async_err);
+	args->element_size = min(args->element_size, sizeof(ndev->last_async_err));
 	if (copy_to_user(u64_to_user_ptr(args->buffer),
 			 &ndev->last_async_err, args->element_size))
 		return -EFAULT;
diff --git a/drivers/accel/amdxdna/aie2_message.c b/drivers/accel/amdxdna/aie2_message.c
index ccf87b1aa1ccc5..0a619e55902b58 100644
--- a/drivers/accel/amdxdna/aie2_message.c
+++ b/drivers/accel/amdxdna/aie2_message.c
@@ -369,12 +369,13 @@ int aie2_query_status(struct amdxdna_dev_hdl *ndev, char __user *buf,
 {
 	DECLARE_AIE_MSG(aie_column_info, MSG_OP_QUERY_COL_STATUS);
 	struct amdxdna_dev *xdna = ndev->aie.xdna;
-	u32 buf_sz = size, aie_bitmap = 0;
+	u32 buf_sz, aie_bitmap = 0;
 	struct amdxdna_client *client;
 	dma_addr_t dma_addr;
 	u8 *buff_addr;
 	int ret;
 
+	buf_sz = ndev->metadata.cols * ndev->metadata.size;
 	buff_addr = aie2_alloc_msg_buffer(ndev, &buf_sz, &dma_addr);
 	if (IS_ERR(buff_addr))
 		return PTR_ERR(buff_addr);
@@ -398,13 +399,14 @@ int aie2_query_status(struct amdxdna_dev_hdl *ndev, char __user *buf,
 
 	XDNA_DBG(xdna, "Query NPU status completed");
 
-	if (size < resp.size) {
+	if (buf_sz < resp.size) {
 		ret = -EINVAL;
-		XDNA_ERR(xdna, "Bad buffer size. Available: %u. Needs: %u", size, resp.size);
+		XDNA_ERR(xdna, "Bad buffer size. Available: %u. Needs: %u", buf_sz, resp.size);
 		goto fail;
 	}
 
-	if (copy_to_user(buf, buff_addr, resp.size)) {
+	size = min(size, resp.size);
+	if (copy_to_user(buf, buff_addr, size)) {
 		ret = -EFAULT;
 		XDNA_ERR(xdna, "Failed to copy NPU status to user space");
 		goto fail;
@@ -424,13 +426,14 @@ int aie2_query_telemetry(struct amdxdna_dev_hdl *ndev,
 	DECLARE_AIE_MSG(get_telemetry, MSG_OP_GET_TELEMETRY);
 	struct amdxdna_dev *xdna = ndev->aie.xdna;
 	dma_addr_t dma_addr;
-	u32 buf_sz = size;
+	u32 buf_sz;
 	u8 *addr;
 	int ret;
 
 	if (header->type >= MAX_TELEMETRY_TYPE)
 		return -EINVAL;
 
+	buf_sz = min(size, SZ_4M);
 	addr = aie2_alloc_msg_buffer(ndev, &buf_sz, &dma_addr);
 	if (IS_ERR(addr))
 		return PTR_ERR(addr);
@@ -446,13 +449,14 @@ int aie2_query_telemetry(struct amdxdna_dev_hdl *ndev,
 		goto free_buf;
 	}
 
-	if (size < resp.size) {
+	if (buf_sz < resp.size) {
 		ret = -EINVAL;
-		XDNA_ERR(xdna, "Bad buffer size. Available: %u. Needs: %u", size, resp.size);
+		XDNA_ERR(xdna, "Bad buffer size. Available: %u. Needs: %u", buf_sz, resp.size);
 		goto free_buf;
 	}
 
-	if (copy_to_user(buf, addr, resp.size)) {
+	size = min(size, resp.size);
+	if (copy_to_user(buf, addr, size)) {
 		ret = -EFAULT;
 		XDNA_ERR(xdna, "Failed to copy telemetry to user space");
 		goto free_buf;
diff --git a/drivers/accel/amdxdna/aie2_pci.c b/drivers/accel/amdxdna/aie2_pci.c
index ebdac0eaa365e2..a7b923005ab7c7 100644
--- a/drivers/accel/amdxdna/aie2_pci.c
+++ b/drivers/accel/amdxdna/aie2_pci.c
@@ -607,23 +607,19 @@ static void aie2_fini(struct amdxdna_dev *xdna)
 static int aie2_get_aie_status(struct amdxdna_client *client,
 			       struct amdxdna_drm_get_info *args)
 {
-	struct amdxdna_drm_query_aie_status status;
+	struct amdxdna_drm_query_aie_status status = {};
 	struct amdxdna_dev *xdna = client->xdna;
 	struct amdxdna_dev_hdl *ndev;
+	u32 buf_sz;
 	int ret;
 
 	ndev = xdna->dev_handle;
-	if (copy_from_user(&status, u64_to_user_ptr(args->buffer), sizeof(status))) {
+	buf_sz = min(args->buffer_size, sizeof(status));
+	if (copy_from_user(&status, u64_to_user_ptr(args->buffer), buf_sz)) {
 		XDNA_ERR(xdna, "Failed to copy AIE request into kernel");
 		return -EFAULT;
 	}
 
-	if (ndev->metadata.cols * ndev->metadata.size < status.buffer_size) {
-		XDNA_ERR(xdna, "Invalid buffer size. Given Size: %u. Need Size: %u.",
-			 status.buffer_size, ndev->metadata.cols * ndev->metadata.size);
-		return -EINVAL;
-	}
-
 	ret = aie2_query_status(ndev, u64_to_user_ptr(status.buffer),
 				status.buffer_size, &status.cols_filled);
 	if (ret) {
@@ -631,7 +627,7 @@ static int aie2_get_aie_status(struct amdxdna_client *client,
 		return ret;
 	}
 
-	if (copy_to_user(u64_to_user_ptr(args->buffer), &status, sizeof(status))) {
+	if (copy_to_user(u64_to_user_ptr(args->buffer), &status, buf_sz)) {
 		XDNA_ERR(xdna, "Failed to copy AIE request info to user space");
 		return -EFAULT;
 	}
@@ -646,6 +642,7 @@ static int aie2_get_aie_metadata(struct amdxdna_client *client,
 	struct amdxdna_dev *xdna = client->xdna;
 	struct amdxdna_dev_hdl *ndev;
 	int ret = 0;
+	u32 buf_sz;
 
 	ndev = xdna->dev_handle;
 	meta = kzalloc_obj(*meta);
@@ -677,7 +674,8 @@ static int aie2_get_aie_metadata(struct amdxdna_client *client,
 	meta->shim.lock_count = ndev->metadata.shim.lock_count;
 	meta->shim.event_reg_count = ndev->metadata.shim.event_reg_count;
 
-	if (copy_to_user(u64_to_user_ptr(args->buffer), meta, sizeof(*meta)))
+	buf_sz = min(args->buffer_size, sizeof(*meta));
+	if (copy_to_user(u64_to_user_ptr(args->buffer), meta, buf_sz))
 		ret = -EFAULT;
 
 	kfree(meta);
@@ -690,12 +688,14 @@ static int aie2_get_aie_version(struct amdxdna_client *client,
 	struct amdxdna_drm_query_aie_version version;
 	struct amdxdna_dev *xdna = client->xdna;
 	struct amdxdna_dev_hdl *ndev;
+	u32 buf_sz;
 
 	ndev = xdna->dev_handle;
 	version.major = ndev->version.major;
 	version.minor = ndev->version.minor;
 
-	if (copy_to_user(u64_to_user_ptr(args->buffer), &version, sizeof(version)))
+	buf_sz = min(args->buffer_size, sizeof(version));
+	if (copy_to_user(u64_to_user_ptr(args->buffer), &version, buf_sz))
 		return -EFAULT;
 
 	return 0;
@@ -706,13 +706,15 @@ static int aie2_get_firmware_version(struct amdxdna_client *client,
 {
 	struct amdxdna_drm_query_firmware_version version;
 	struct amdxdna_dev *xdna = client->xdna;
+	u32 buf_sz;
 
 	version.major = xdna->fw_ver.major;
 	version.minor = xdna->fw_ver.minor;
 	version.patch = xdna->fw_ver.sub;
 	version.build = xdna->fw_ver.build;
 
-	if (copy_to_user(u64_to_user_ptr(args->buffer), &version, sizeof(version)))
+	buf_sz = min(args->buffer_size, sizeof(version));
+	if (copy_to_user(u64_to_user_ptr(args->buffer), &version, buf_sz))
 		return -EFAULT;
 
 	return 0;
@@ -724,11 +726,13 @@ static int aie2_get_power_mode(struct amdxdna_client *client,
 	struct amdxdna_drm_get_power_mode mode = {};
 	struct amdxdna_dev *xdna = client->xdna;
 	struct amdxdna_dev_hdl *ndev;
+	u32 buf_sz;
 
 	ndev = xdna->dev_handle;
 	mode.power_mode = ndev->pw_mode;
 
-	if (copy_to_user(u64_to_user_ptr(args->buffer), &mode, sizeof(mode)))
+	buf_sz = min(args->buffer_size, sizeof(mode));
+	if (copy_to_user(u64_to_user_ptr(args->buffer), &mode, buf_sz))
 		return -EFAULT;
 
 	return 0;
@@ -741,6 +745,7 @@ static int aie2_get_clock_metadata(struct amdxdna_client *client,
 	struct amdxdna_dev *xdna = client->xdna;
 	struct amdxdna_dev_hdl *ndev;
 	int ret = 0;
+	u32 buf_sz;
 
 	ndev = xdna->dev_handle;
 	clock = kzalloc_obj(*clock);
@@ -753,7 +758,8 @@ static int aie2_get_clock_metadata(struct amdxdna_client *client,
 	snprintf(clock->h_clock.name, sizeof(clock->h_clock.name), "H Clock");
 	clock->h_clock.freq_mhz = ndev->hclk_freq;
 
-	if (copy_to_user(u64_to_user_ptr(args->buffer), clock, sizeof(*clock)))
+	buf_sz = min(args->buffer_size, sizeof(*clock));
+	if (copy_to_user(u64_to_user_ptr(args->buffer), clock, buf_sz))
 		ret = -EFAULT;
 
 	kfree(clock);
@@ -779,12 +785,14 @@ static int aie2_get_sensors(struct amdxdna_client *client,
 	scnprintf(sensor.label, sizeof(sensor.label), "Total Power");
 	scnprintf(sensor.units, sizeof(sensor.units), "mW");
 
+	if (args->buffer_size < sizeof(sensor))
+		goto out;
+
 	if (copy_to_user(u64_to_user_ptr(args->buffer), &sensor, sizeof(sensor)))
 		return -EFAULT;
 
+	args->buffer_size -= sizeof(sensor);
 	sensors_count++;
-	if (args->buffer_size <= sensors_count * sizeof(sensor))
-		goto out;
 
 	for (i = 0; i < min_t(u32, ndev->total_col, 8); i++) {
 		memset(&sensor, 0, sizeof(sensor));
@@ -794,13 +802,15 @@ static int aie2_get_sensors(struct amdxdna_client *client,
 		scnprintf(sensor.label, sizeof(sensor.label), "Column %d Utilization", i);
 		scnprintf(sensor.units, sizeof(sensor.units), "%%");
 
+		if (args->buffer_size < sizeof(sensor))
+			goto out;
+
 		if (copy_to_user(u64_to_user_ptr(args->buffer) + sensors_count * sizeof(sensor),
 				 &sensor, sizeof(sensor)))
 			return -EFAULT;
 
+		args->buffer_size -= sizeof(sensor);
 		sensors_count++;
-		if (args->buffer_size <= sensors_count * sizeof(sensor))
-			goto out;
 	}
 
 out:
@@ -896,6 +906,7 @@ static int aie2_query_resource_info(struct amdxdna_client *client,
 	const struct amdxdna_dev_priv *priv;
 	struct amdxdna_dev_hdl *ndev;
 	struct amdxdna_dev *xdna;
+	u32 buf_sz;
 
 	xdna = client->xdna;
 	ndev = xdna->dev_handle;
@@ -907,7 +918,8 @@ static int aie2_query_resource_info(struct amdxdna_client *client,
 	res_info.npu_tops_curr = ndev->curr_tops;
 	res_info.npu_task_curr = ndev->hwctx_num;
 
-	if (copy_to_user(u64_to_user_ptr(args->buffer), &res_info, sizeof(res_info)))
+	buf_sz = min(args->buffer_size, sizeof(res_info));
+	if (copy_to_user(u64_to_user_ptr(args->buffer), &res_info, buf_sz))
 		return -EFAULT;
 
 	return 0;
@@ -943,12 +955,7 @@ static int aie2_get_telemetry(struct amdxdna_client *client,
 		XDNA_ERR(xdna, "Invalid buffer size");
 		return -EINVAL;
 	}
-
 	telemetry_data_sz = args->buffer_size - header_sz;
-	if (telemetry_data_sz > SZ_4M) {
-		XDNA_ERR(xdna, "Buffer size is too big, %d", telemetry_data_sz);
-		return -EINVAL;
-	}
 
 	header = kzalloc(header_sz, GFP_KERNEL);
 	if (!header)
@@ -989,6 +996,7 @@ static int aie2_get_preempt_state(struct amdxdna_client *client,
 	struct amdxdna_drm_attribute_state state = {};
 	struct amdxdna_dev *xdna = client->xdna;
 	struct amdxdna_dev_hdl *ndev;
+	u32 buf_sz;
 
 	ndev = xdna->dev_handle;
 	if (args->param == DRM_AMDXDNA_GET_FORCE_PREEMPT_STATE)
@@ -996,7 +1004,8 @@ static int aie2_get_preempt_state(struct amdxdna_client *client,
 	else if (args->param == DRM_AMDXDNA_GET_FRAME_BOUNDARY_PREEMPT_STATE)
 		state.state = ndev->frame_boundary_preempt;
 
-	if (copy_to_user(u64_to_user_ptr(args->buffer), &state, sizeof(state)))
+	buf_sz = min(args->buffer_size, sizeof(state));
+	if (copy_to_user(u64_to_user_ptr(args->buffer), &state, buf_sz))
 		return -EFAULT;
 
 	return 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0053/2077] accel/amdxdna: Handle DETACH_DEBUG_BO through config_debug_bo path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (51 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0052/2077] accel/amdxdna: Adjust size for copy_to_user() Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0054/2077] accel/amdxdna: Fix iommu_map_sgtable() return value handling Greg Kroah-Hartman
                   ` (944 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Max Zhen, Mario Limonciello (AMD),
	Lizhi Hou, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Max Zhen <max.zhen@amd.com>

[ Upstream commit f844177c6811fd322aa84ed5c32f0e39743446c2 ]

Route DETACH_DEBUG_BO through aie2_config_debug_bo() the same way as
ATTACH_DEBUG_BO.

The scheduler switch in aie2_sched_job_run() already handles
ATTACH_DEBUG_BO with aie2_config_debug_bo(), but DETACH_DEBUG_BO was
not included in that path. Add an explicit fallthrough so both attach
and detach operations use the same handler.

This fixes debug BO detach handling by ensuring the detach command is
processed by the expected configuration path.

Fixes: 7ea046838021 ("accel/amdxdna: Support firmware debug buffer")
Signed-off-by: Max Zhen <max.zhen@amd.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260406211403.4011988-1-lizhi.hou@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/accel/amdxdna/aie2_ctx.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/accel/amdxdna/aie2_ctx.c b/drivers/accel/amdxdna/aie2_ctx.c
index 2dc69900ca0107..d719000c453252 100644
--- a/drivers/accel/amdxdna/aie2_ctx.c
+++ b/drivers/accel/amdxdna/aie2_ctx.c
@@ -360,6 +360,7 @@ aie2_sched_job_run(struct drm_sched_job *sched_job)
 			ret = aie2_sync_bo(hwctx, job, aie2_sched_drvcmd_resp_handler);
 			break;
 		case ATTACH_DEBUG_BO:
+		case DETACH_DEBUG_BO:
 			ret = aie2_config_debug_bo(hwctx, job, aie2_sched_drvcmd_resp_handler);
 			break;
 		default:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0054/2077] accel/amdxdna: Fix iommu_map_sgtable() return value handling
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (52 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0053/2077] accel/amdxdna: Handle DETACH_DEBUG_BO through config_debug_bo path Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0055/2077] accel/amdxdna: Fix order of canceled mailbox messages Greg Kroah-Hartman
                   ` (943 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Carpenter,
	Mario Limonciello (AMD), Wendy Liang, Lizhi Hou, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lizhi Hou <lizhi.hou@amd.com>

[ Upstream commit 1bcfa4c4e88a554d1b6f98f4e3f886288581cbb4 ]

iommu_map_sgtable() returns negative error codes on failure, but the
result is stored in an unsigned variable. This prevents proper error
detection.

Change the variable type to ssize_t so negative error values can be
handled correctly.

Fixes: ece3e8980907 ("accel/amdxdna: Allow forcing IOVA-based DMA via module parameter")
Reported-by: Dan Carpenter <error27@gmail.com>
Closes: https://lore.kernel.org/all/adk7kOUBwIyYnX1M@stanley.mountain/
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Wendy Liang <wendy.liang@amd.com>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260413180238.668441-1-lizhi.hou@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/accel/amdxdna/amdxdna_iommu.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/drivers/accel/amdxdna/amdxdna_iommu.c b/drivers/accel/amdxdna/amdxdna_iommu.c
index 4626434d4180cf..2676cfcfabee0d 100644
--- a/drivers/accel/amdxdna/amdxdna_iommu.c
+++ b/drivers/accel/amdxdna/amdxdna_iommu.c
@@ -40,7 +40,7 @@ int amdxdna_iommu_map_bo(struct amdxdna_dev *xdna, struct amdxdna_gem_obj *abo)
 	struct sg_table *sgt;
 	dma_addr_t dma_addr;
 	struct iova *iova;
-	size_t size;
+	ssize_t size;
 
 	if (abo->type != AMDXDNA_BO_DEV_HEAP && abo->type != AMDXDNA_BO_SHMEM)
 		return 0;
@@ -65,7 +65,14 @@ int amdxdna_iommu_map_bo(struct amdxdna_dev *xdna, struct amdxdna_gem_obj *abo)
 
 	size = iommu_map_sgtable(xdna->domain, dma_addr, sgt,
 				 IOMMU_READ | IOMMU_WRITE);
+	if (size < 0) {
+		XDNA_ERR(xdna, "iommu_map_sgtable failed: %zd", size);
+		__free_iova(&xdna->iovad, iova);
+		return size;
+	}
+
 	if (size < abo->mem.size) {
+		iommu_unmap(xdna->domain, dma_addr, size);
 		__free_iova(&xdna->iovad, iova);
 		return -ENXIO;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0055/2077] accel/amdxdna: Fix order of canceled mailbox messages
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (53 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0054/2077] accel/amdxdna: Fix iommu_map_sgtable() return value handling Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0056/2077] dma-fence: Fix potential tracepoint null pointer dereferences Greg Kroah-Hartman
                   ` (942 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mario Limonciello (AMD), Lizhi Hou,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lizhi Hou <lizhi.hou@amd.com>

[ Upstream commit c83ad8ea6b0a53f1ed61ae0b4b9606bdfe338b33 ]

Mailbox message IDs are allocated cyclically. When destroying a mailbox
channel, pending messages are canceled starting from message ID 0. This
results in an incorrect cancellation order when the ID of the last posted
message wraps around and is smaller than the ID of the first posted
message.

Fix this by canceling pending messages starting from the next available
message ID, ensuring the correct ordering across wraparound.

Fixes: a37d78470bcc ("accel/amdxdna: Replace idr api with xarray")
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260413181843.670796-1-lizhi.hou@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/accel/amdxdna/amdxdna_mailbox.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/accel/amdxdna/amdxdna_mailbox.c b/drivers/accel/amdxdna/amdxdna_mailbox.c
index e681a090752df4..d3639a2ea23951 100644
--- a/drivers/accel/amdxdna/amdxdna_mailbox.c
+++ b/drivers/accel/amdxdna/amdxdna_mailbox.c
@@ -538,7 +538,9 @@ void xdna_mailbox_stop_channel(struct mailbox_channel *mb_chann)
 	drain_workqueue(mb_chann->work_q);
 
 	/* We can clean up and release resources */
-	xa_for_each(&mb_chann->chan_xa, msg_id, mb_msg)
+	xa_for_each_start(&mb_chann->chan_xa, msg_id, mb_msg, mb_chann->next_msgid)
+		mailbox_release_msg(mb_chann, mb_msg);
+	xa_for_each_range(&mb_chann->chan_xa, msg_id, mb_msg, 0, mb_chann->next_msgid - 1)
 		mailbox_release_msg(mb_chann, mb_msg);
 	xa_destroy(&mb_chann->chan_xa);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0056/2077] dma-fence: Fix potential tracepoint null pointer dereferences
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (54 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0055/2077] accel/amdxdna: Fix order of canceled mailbox messages Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0057/2077] accel/amdxdna: Fix fatal_error_info layout in firmware interface Greg Kroah-Hartman
                   ` (941 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tvrtko Ursulin, Christian König,
	Philipp Stanner, Boris Brezillon, linux-media, linaro-mm-sig,
	Tvrtko Ursulin, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>

[ Upstream commit e94b9f01543cc6a83538c2c2cc645a424d3015ca ]

Trace_dma_fence_signaled, trace_dma_fence_wait_end and
trace_dma_fence_destroy can all currently dereference a null fence->ops
pointer after it has been reset on fence signalling.

Lets use the safe string getters for most tracepoints to avoid this class
of a problem, while for the signal tracepoint we move it to before ops are
cleared to avoid losing the driver and timeline name information. Apart
from moving it we also need to add a new tracepoint class to bypass the
safe name getters since the signaled bit is already set.

For dma_fence_init we also need to use the new tracepoint class since the
rcu read lock is not held there, and we can do the same for the enable
signaling since there we are certain the fence cannot be signaled while
we are holding the lock and have even validated the fence->ops.

Signed-off-by: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
Fixes: 541c8f2468b9 ("dma-buf: detach fence ops on signal v3")
Cc: Christian König <christian.koenig@amd.com>
Cc: Philipp Stanner <phasta@kernel.org>
Cc: Boris Brezillon <boris.brezillon@collabora.com>
Cc: linux-media@vger.kernel.org
Cc: linaro-mm-sig@lists.linaro.org
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Tvrtko Ursulin <tursulin@ursulin.net>
Link: https://lore.kernel.org/r/20260415083207.40513-2-tvrtko.ursulin@igalia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dma-buf/dma-fence.c      |  3 ++-
 include/trace/events/dma_fence.h | 40 +++++++++++++++++++++++++++-----
 2 files changed, 36 insertions(+), 7 deletions(-)

diff --git a/drivers/dma-buf/dma-fence.c b/drivers/dma-buf/dma-fence.c
index a2aa82f4eedd49..b3bfa6943a8e13 100644
--- a/drivers/dma-buf/dma-fence.c
+++ b/drivers/dma-buf/dma-fence.c
@@ -363,6 +363,8 @@ void dma_fence_signal_timestamp_locked(struct dma_fence *fence,
 				      &fence->flags)))
 		return;
 
+	trace_dma_fence_signaled(fence);
+
 	/*
 	 * When neither a release nor a wait operation is specified set the ops
 	 * pointer to NULL to allow the fence structure to become independent
@@ -377,7 +379,6 @@ void dma_fence_signal_timestamp_locked(struct dma_fence *fence,
 
 	fence->timestamp = timestamp;
 	set_bit(DMA_FENCE_FLAG_TIMESTAMP_BIT, &fence->flags);
-	trace_dma_fence_signaled(fence);
 
 	list_for_each_entry_safe(cur, tmp, &cb_list, node) {
 		INIT_LIST_HEAD(&cur->node);
diff --git a/include/trace/events/dma_fence.h b/include/trace/events/dma_fence.h
index 3abba45c0601a4..5b10a9e06fb4ec 100644
--- a/include/trace/events/dma_fence.h
+++ b/include/trace/events/dma_fence.h
@@ -9,12 +9,40 @@
 
 struct dma_fence;
 
+DECLARE_EVENT_CLASS(dma_fence,
+
+	TP_PROTO(struct dma_fence *fence),
+
+	TP_ARGS(fence),
+
+	TP_STRUCT__entry(
+		__string(driver, dma_fence_driver_name(fence))
+		__string(timeline, dma_fence_timeline_name(fence))
+		__field(unsigned int, context)
+		__field(unsigned int, seqno)
+	),
+
+	TP_fast_assign(
+		__assign_str(driver);
+		__assign_str(timeline);
+		__entry->context = fence->context;
+		__entry->seqno = fence->seqno;
+	),
+
+	TP_printk("driver=%s timeline=%s context=%u seqno=%u",
+		  __get_str(driver), __get_str(timeline), __entry->context,
+		  __entry->seqno)
+);
+
 /*
  * Safe only for call sites which are guaranteed to not race with fence
- * signaling,holding the fence->lock and having checked for not signaled, or the
- * signaling path itself.
+ * signaling, holding the fence->lock and having checked for not signaled, or
+ * the signaling path itself.
+ *
+ * TODO: Remove the need for this event class when drivers switch to independent
+ *       fences.
  */
-DECLARE_EVENT_CLASS(dma_fence,
+DECLARE_EVENT_CLASS(dma_fence_ops,
 
 	TP_PROTO(struct dma_fence *fence),
 
@@ -46,7 +74,7 @@ DEFINE_EVENT(dma_fence, dma_fence_emit,
 	TP_ARGS(fence)
 );
 
-DEFINE_EVENT(dma_fence, dma_fence_init,
+DEFINE_EVENT(dma_fence_ops, dma_fence_init,
 
 	TP_PROTO(struct dma_fence *fence),
 
@@ -60,14 +88,14 @@ DEFINE_EVENT(dma_fence, dma_fence_destroy,
 	TP_ARGS(fence)
 );
 
-DEFINE_EVENT(dma_fence, dma_fence_enable_signal,
+DEFINE_EVENT(dma_fence_ops, dma_fence_enable_signal,
 
 	TP_PROTO(struct dma_fence *fence),
 
 	TP_ARGS(fence)
 );
 
-DEFINE_EVENT(dma_fence, dma_fence_signaled,
+DEFINE_EVENT(dma_fence_ops, dma_fence_signaled,
 
 	TP_PROTO(struct dma_fence *fence),
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0057/2077] accel/amdxdna: Fix fatal_error_info layout in firmware interface
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (55 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0056/2077] dma-fence: Fix potential tracepoint null pointer dereferences Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0058/2077] accel/amdxdna: Fix memory leak in amdxdna_iommu_alloc() Greg Kroah-Hartman
                   ` (940 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Max Zhen, Mario Limonciello (AMD),
	Lizhi Hou, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Max Zhen <max.zhen@amd.com>

[ Upstream commit 2d1e82f1224f3109481bb0ed3683e54b09b978e3 ]

Adjust struct fatal_error_info to match the expected driver/firmware
interface layout.

The structure is used to retrieve debug information from firmware when
a command becomes stuck on the device. The reserved field currently
uses 128 u32 entries, which makes the structure larger than intended
and causes the layout to no longer match the firmware definition.

Reduce the reserved array size from 128 to 127 entries so the
structure matches the expected interface format.

Fixes: 25854131c04a ("accel/amdxdna: Support retrieving hardware context debug information")
Signed-off-by: Max Zhen <max.zhen@amd.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260414165625.788853-1-lizhi.hou@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/accel/amdxdna/aie2_msg_priv.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/accel/amdxdna/aie2_msg_priv.h b/drivers/accel/amdxdna/aie2_msg_priv.h
index f18e89a39e3571..4a01d73209bbf7 100644
--- a/drivers/accel/amdxdna/aie2_msg_priv.h
+++ b/drivers/accel/amdxdna/aie2_msg_priv.h
@@ -460,7 +460,7 @@ struct fatal_error_info {
 	__u32 exception_pc;       /* Program Counter at the time of the exception */
 	__u32 app_module;         /* Error module name */
 	__u32 task_index;         /* Index of the task in which the error occurred */
-	__u32 reserved[128];
+	__u32 reserved[127];
 };
 
 struct app_health_report {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0058/2077] accel/amdxdna: Fix memory leak in amdxdna_iommu_alloc()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (56 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0057/2077] accel/amdxdna: Fix fatal_error_info layout in firmware interface Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0059/2077] drm/gpuvm: Do not prepare NULL objects Greg Kroah-Hartman
                   ` (939 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Lizhi Hou, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit 432fafdc9a3122a7bee5b2bfd23dcf2dc262a3d7 ]

In amdxdna_iommu_alloc(), if iommu_map() fails after successfully
allocating both iova and cpu_addr, the code jumps to free_iova
which only frees the iova, leaking the allocated pages.

Fixes: ece3e8980907 ("accel/amdxdna: Allow forcing IOVA-based DMA via module parameter")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Reviewed-by: Lizhi Hou <lizhi.hou@amd.com>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260416-amdxdna-v1-1-30c13008365c@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/accel/amdxdna/amdxdna_iommu.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/accel/amdxdna/amdxdna_iommu.c b/drivers/accel/amdxdna/amdxdna_iommu.c
index 2676cfcfabee0d..5a9f06183487fd 100644
--- a/drivers/accel/amdxdna/amdxdna_iommu.c
+++ b/drivers/accel/amdxdna/amdxdna_iommu.c
@@ -117,10 +117,12 @@ void *amdxdna_iommu_alloc(struct amdxdna_dev *xdna, size_t size, dma_addr_t *dma
 			iova_align(&xdna->iovad, size),
 			IOMMU_READ | IOMMU_WRITE, GFP_KERNEL);
 	if (ret)
-		goto free_iova;
+		goto free_cpu_addr;
 
 	return cpu_addr;
 
+free_cpu_addr:
+	free_pages((unsigned long)cpu_addr, get_order(size));
 free_iova:
 	__free_iova(&xdna->iovad, iova);
 	return ERR_PTR(ret);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0059/2077] drm/gpuvm: Do not prepare NULL objects
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (57 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0058/2077] accel/amdxdna: Fix memory leak in amdxdna_iommu_alloc() Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0060/2077] accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer Greg Kroah-Hartman
                   ` (938 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jonathan Cavitt, Matthew Brost,
	Thomas Hellström, Krzysztof Karas, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jonathan Cavitt <jonathan.cavitt@intel.com>

[ Upstream commit 88f059f6f6f589bd78e2ceb05a1339a8c10b8626 ]

Statis analysis issue:

drm_gpuvm_prepare_range issues an exec_object_prepare call to all
drm_gem_objects mapped between addr and addr + range.  However, it is
possible (albeit very unlikely) that the objects found through
drm_gpuvm_for_each_va_range (as connected to va->gem) are NULL, as seen
in other functions such as drm_gpuva_link and drm_gpuva_unlink_defer.

Do not prepare NULL objects.

Fixes: 50c1a36f594b ("drm/gpuvm: track/lock/validate external/evicted objects")
Signed-off-by: Jonathan Cavitt <jonathan.cavitt@intel.com>
Cc: Matthew Brost <matthew.brost@intel.com>
Cc: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Reviewed-by: Krzysztof Karas <krzysztof.karas@intel.com>
Link: https://patch.msgid.link/20260130191953.61718-2-jonathan.cavitt@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/drm_gpuvm.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/gpu/drm/drm_gpuvm.c b/drivers/gpu/drm/drm_gpuvm.c
index 44acfe4120d243..f56719e9f4350a 100644
--- a/drivers/gpu/drm/drm_gpuvm.c
+++ b/drivers/gpu/drm/drm_gpuvm.c
@@ -1322,6 +1322,9 @@ drm_gpuvm_prepare_range(struct drm_gpuvm *gpuvm, struct drm_exec *exec,
 	drm_gpuvm_for_each_va_range(va, gpuvm, addr, end) {
 		struct drm_gem_object *obj = va->gem.obj;
 
+		if (unlikely(!obj))
+			continue;
+
 		ret = exec_prepare_obj(exec, obj, num_fences);
 		if (ret)
 			return ret;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0060/2077] accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (58 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0059/2077] drm/gpuvm: Do not prepare NULL objects Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0061/2077] drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() Greg Kroah-Hartman
                   ` (937 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mario Limonciello (AMD), Max Zhen,
	Lizhi Hou, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Max Zhen <max.zhen@amd.com>

[ Upstream commit 506255d46bdb93a281cf39e72abbca124f5c7a1b ]

The management mailbox channel cleanup helpers can be called from
error handling paths when mgmt_chann has already been destroyed.

Add NULL checks to xdna_mailbox_free_channel() and
xdna_mailbox_stop_channel() so the cleanup path safely returns instead
of dereferencing a NULL mailbox channel pointer.

Fixes: b87f920b9344 ("accel/amdxdna: Support hardware mailbox")
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Max Zhen <max.zhen@amd.com>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260416201106.1046072-1-lizhi.hou@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/accel/amdxdna/amdxdna_mailbox.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/accel/amdxdna/amdxdna_mailbox.c b/drivers/accel/amdxdna/amdxdna_mailbox.c
index d3639a2ea23951..13c20bb3890c93 100644
--- a/drivers/accel/amdxdna/amdxdna_mailbox.c
+++ b/drivers/accel/amdxdna/amdxdna_mailbox.c
@@ -485,6 +485,9 @@ struct mailbox_channel *xdna_mailbox_alloc_channel(struct mailbox *mb)
 
 void xdna_mailbox_free_channel(struct mailbox_channel *mb_chann)
 {
+	if (!mb_chann)
+		return;
+
 	destroy_workqueue(mb_chann->work_q);
 	kfree(mb_chann);
 }
@@ -531,6 +534,9 @@ void xdna_mailbox_stop_channel(struct mailbox_channel *mb_chann)
 	struct mailbox_msg *mb_msg;
 	unsigned long msg_id;
 
+	if (!mb_chann)
+		return;
+
 	/* Disable an irq and wait. This might sleep. */
 	free_irq(mb_chann->msix_irq, mb_chann);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0061/2077] drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (59 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0060/2077] accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0062/2077] drm/amdkfd: fix redundant MQD iterations in GFX v12.1 Greg Kroah-Hartman
                   ` (936 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Werner Kasselman, Alex Deucher,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Werner Kasselman <werner@verivus.ai>

[ Upstream commit fc3659f178d4a65599167d5a648bbeef4b0d4446 ]

amdgpu_gem_align_pitch() is passed u32 width and cpp from dumb buffer
creation but uses signed int internally.  The round-up add and the
aligned * cpp multiplication can overflow, returning zero or a negative
pitch.  A zero pitch propagates to a zero-sized GEM object allocation
that reaches userspace via DRM_IOCTL_MODE_CREATE_DUMB.

Switch the helper to unsigned int and use check_add_overflow() /
check_mul_overflow() so wraparound returns zero.  Reject a zero pitch
or size in amdgpu_mode_dumb_create() rather than allocating a zero-
byte BO.

Fixes: 8e911ab770f7 ("drm: amdgpu: Replace drm_fb_get_bpp_depth() with drm_format_plane_cpp()")
Signed-off-by: Werner Kasselman <werner@verivus.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c | 25 +++++++++++++++++--------
 1 file changed, 17 insertions(+), 8 deletions(-)

diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c
index fe6d988e7f245c..1120f8225ac020 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c
@@ -27,6 +27,7 @@
  */
 #include <linux/ktime.h>
 #include <linux/module.h>
+#include <linux/overflow.h>
 #include <linux/pagemap.h>
 #include <linux/pci.h>
 #include <linux/dma-buf.h>
@@ -1228,13 +1229,14 @@ int amdgpu_gem_list_handles_ioctl(struct drm_device *dev, void *data,
 	return ret;
 }
 
-static int amdgpu_gem_align_pitch(struct amdgpu_device *adev,
-				  int width,
-				  int cpp,
-				  bool tiled)
+static unsigned int amdgpu_gem_align_pitch(struct amdgpu_device *adev,
+					   unsigned int width,
+					   unsigned int cpp,
+					   bool tiled)
 {
-	int aligned = width;
-	int pitch_mask = 0;
+	unsigned int aligned = width;
+	unsigned int pitch_mask = 0;
+	unsigned int pitch;
 
 	switch (cpp) {
 	case 1:
@@ -1249,9 +1251,12 @@ static int amdgpu_gem_align_pitch(struct amdgpu_device *adev,
 		break;
 	}
 
-	aligned += pitch_mask;
+	if (check_add_overflow(aligned, pitch_mask, &aligned))
+		return 0;
 	aligned &= ~pitch_mask;
-	return aligned * cpp;
+	if (check_mul_overflow(aligned, cpp, &pitch))
+		return 0;
+	return pitch;
 }
 
 int amdgpu_mode_dumb_create(struct drm_file *file_priv,
@@ -1278,8 +1283,12 @@ int amdgpu_mode_dumb_create(struct drm_file *file_priv,
 
 	args->pitch = amdgpu_gem_align_pitch(adev, args->width,
 					     DIV_ROUND_UP(args->bpp, 8), 0);
+	if (!args->pitch)
+		return -EINVAL;
 	args->size = (u64)args->pitch * args->height;
 	args->size = ALIGN(args->size, PAGE_SIZE);
+	if (!args->size)
+		return -EINVAL;
 	domain = amdgpu_bo_get_preferred_domain(adev,
 				amdgpu_display_supported_domains(adev, flags));
 	r = amdgpu_gem_object_create(adev, args->size, 0, domain, flags,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0062/2077] drm/amdkfd: fix redundant MQD iterations in GFX v12.1
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (60 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0061/2077] drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0063/2077] drm/radeon: fix integer overflow in radeon_align_pitch() Greg Kroah-Hartman
                   ` (935 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alex Sierra, Felix Kuehling,
	Alex Deucher, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alex Sierra <alex.sierra@amd.com>

[ Upstream commit 9315a1e2bdf1ba4aace856cabcb5f9f3a5c09202 ]

The init_mqd_v12_1 function and its sub-call update_mqd_v12_1 both independently
iterate over XCC-specific MQDs. This nested iteration is redundant and can cause
MQDs in different queues to be overwritten. This patch removes the duplicate
loop logic to prevent queue corruption.

Fixes: 01bbc4a4b947 ("drm/amdkfd: Add MQD manager for GFX 12.1.0")
Signed-off-by: Alex Sierra <alex.sierra@amd.com>
Reviewed-by: Felix Kuehling <felix.kuehling@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c b/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c
index c90c0d99b1e3f3..475589b924e90a 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c
@@ -32,6 +32,10 @@
 #include "amdgpu_amdkfd.h"
 #include "kfd_device_queue_manager.h"
 
+static void update_mqd(struct mqd_manager *mm, void *mqd,
+		       struct queue_properties *q,
+		       struct mqd_update_info *minfo);
+
 static inline struct v12_1_compute_mqd *get_mqd(void *mqd)
 {
 	return (struct v12_1_compute_mqd *)mqd;
@@ -215,7 +219,7 @@ static void init_mqd(struct mqd_manager *mm, void **mqd,
 	*mqd = m;
 	if (gart_addr)
 		*gart_addr = addr;
-	mm->update_mqd(mm, m, q, NULL);
+	update_mqd(mm, m, q, NULL);
 }
 
 static int load_mqd(struct mqd_manager *mm, void *mqd,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0063/2077] drm/radeon: fix integer overflow in radeon_align_pitch()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (61 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0062/2077] drm/amdkfd: fix redundant MQD iterations in GFX v12.1 Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0064/2077] drm/radeon: fix memory leak in radeon_ring_restore() on lock failure Greg Kroah-Hartman
                   ` (934 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Werner Kasselman, Alex Deucher,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Werner Kasselman <werner@verivus.ai>

[ Upstream commit ce3b24eb3ee8f82de851535f516bf21f83e82259 ]

radeon_align_pitch() has the same kind of overflow issue as the old
amdgpu helper: both the alignment round-up add and the final
'aligned * cpp' calculation can overflow signed int.

If that wraps, radeon_mode_dumb_create() can end up returning an
invalid pitch or creating a zero-sized dumb buffer.

Fix this by using check_add_overflow() for the alignment round-up and
check_mul_overflow() for the final pitch calculation, returning 0 on
overflow. Also reject zero pitch and size in
radeon_mode_dumb_create().

Found via AST-based call-graph analysis using sqry.

Fixes: ff72145badb8 ("drm: dumb scanout create/mmap for intel/radeon (v3)")
Signed-off-by: Werner Kasselman <werner@verivus.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/radeon/radeon_gem.c | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/radeon/radeon_gem.c b/drivers/gpu/drm/radeon/radeon_gem.c
index 20fc87409f2e4a..8ce180e22d1d1d 100644
--- a/drivers/gpu/drm/radeon/radeon_gem.c
+++ b/drivers/gpu/drm/radeon/radeon_gem.c
@@ -28,6 +28,7 @@
 
 #include <linux/debugfs.h>
 #include <linux/iosys-map.h>
+#include <linux/overflow.h>
 #include <linux/pci.h>
 
 #include <drm/drm_device.h>
@@ -812,6 +813,7 @@ int radeon_align_pitch(struct radeon_device *rdev, int width, int cpp, bool tile
 	int aligned = width;
 	int align_large = (ASIC_IS_AVIVO(rdev)) || tiled;
 	int pitch_mask = 0;
+	int pitch;
 
 	switch (cpp) {
 	case 1:
@@ -826,9 +828,12 @@ int radeon_align_pitch(struct radeon_device *rdev, int width, int cpp, bool tile
 		break;
 	}
 
-	aligned += pitch_mask;
+	if (check_add_overflow(aligned, pitch_mask, &aligned))
+		return 0;
 	aligned &= ~pitch_mask;
-	return aligned * cpp;
+	if (check_mul_overflow(aligned, cpp, &pitch))
+		return 0;
+	return pitch;
 }
 
 int radeon_mode_dumb_create(struct drm_file *file_priv,
@@ -842,8 +847,12 @@ int radeon_mode_dumb_create(struct drm_file *file_priv,
 
 	args->pitch = radeon_align_pitch(rdev, args->width,
 					 DIV_ROUND_UP(args->bpp, 8), 0);
+	if (!args->pitch)
+		return -EINVAL;
 	args->size = (u64)args->pitch * args->height;
 	args->size = ALIGN(args->size, PAGE_SIZE);
+	if (!args->size)
+		return -EINVAL;
 
 	r = radeon_gem_object_create(rdev, args->size, 0,
 				     RADEON_GEM_DOMAIN_VRAM, 0,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0064/2077] drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (62 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0063/2077] drm/radeon: fix integer overflow in radeon_align_pitch() Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0065/2077] libbpf: Report error when a negative kprobe offset is specified Greg Kroah-Hartman
                   ` (933 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Alex Deucher, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yuho Choi <dbgh9129@gmail.com>

[ Upstream commit 82f1d6042611d45b8b9de423bbcb4e0ced9ec62b ]

radeon_ring_restore() takes ownership of the data buffer allocated by
radeon_ring_backup(). The caller (radeon_gpu_reset()) only frees it in
the non-restore branch; in the restore branch it relies on
radeon_ring_restore() to free it.

If radeon_ring_lock() fails, the function returned early without calling
kvfree(data), leaking the ring backup buffer on every GPU reset that
fails at the lock stage. During repeated GPU resets this causes
cumulative kernel memory exhaustion.

Free data before returning the error.

Fixes: 55d7c22192be ("drm/radeon: implement ring saving on reset v4")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/radeon/radeon_ring.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/radeon/radeon_ring.c b/drivers/gpu/drm/radeon/radeon_ring.c
index 581ae20c46e4b5..a5dff072c1ac03 100644
--- a/drivers/gpu/drm/radeon/radeon_ring.c
+++ b/drivers/gpu/drm/radeon/radeon_ring.c
@@ -356,8 +356,10 @@ int radeon_ring_restore(struct radeon_device *rdev, struct radeon_ring *ring,
 
 	/* restore the saved ring content */
 	r = radeon_ring_lock(rdev, ring, size);
-	if (r)
+	if (r) {
+		kvfree(data);
 		return r;
+	}
 
 	for (i = 0; i < size; ++i) {
 		radeon_ring_write(ring, data[i]);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0065/2077] libbpf: Report error when a negative kprobe offset is specified
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (63 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0064/2077] drm/radeon: fix memory leak in radeon_ring_restore() on lock failure Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0066/2077] selftests/bpf: Fix off-by-one in bpf_cpumask_populate related selftest Greg Kroah-Hartman
                   ` (932 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Aaron Tomlin, Mykyta Yatsenko,
	Kumar Kartikeya Dwivedi, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aaron Tomlin <atomlin@atomlin.com>

[ Upstream commit ad35d8018669fd2eea76e3f74eb050fd3d2fb690 ]

In attach_kprobe(), the parsing logic uses sscanf() to extract the
target function name and offset from the section definition. Currently,
if a user specifies a negative offset (e.g., SEC("kprobe/func+-100")),
the input is not explicitly caught and reported as an error.

This commit updates the logic to explicitly notify the user when a
negative integer is provided. To facilitate this check, the offset
variable is changed from unsigned long to long so that sscanf()
can accurately capture a negative input for evaluation.

If a negative offset is detected, the loader will now print an
informative warning stating that the offset must be non-negative,
and return -EINVAL.

Additionally, free(func) is called in this new error path to prevent
a memory leak, as the function name string is dynamically allocated
by sscanf().

Fixes: e3f9bc35ea7e9 ("libbpf: Allow decimal offset for kprobes")
Signed-off-by: Aaron Tomlin <atomlin@atomlin.com>
Acked-by: Mykyta Yatsenko <yatsenko@meta.com>
Link: https://lore.kernel.org/bpf/20260419030944.1423642-1-atomlin@atomlin.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/lib/bpf/libbpf.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c
index 3a80a018fc7d50..83aae7a39d36de 100644
--- a/tools/lib/bpf/libbpf.c
+++ b/tools/lib/bpf/libbpf.c
@@ -12280,7 +12280,7 @@ bpf_program__attach_kprobe_multi_opts(const struct bpf_program *prog,
 static int attach_kprobe(const struct bpf_program *prog, long cookie, struct bpf_link **link)
 {
 	DECLARE_LIBBPF_OPTS(bpf_kprobe_opts, opts);
-	unsigned long offset = 0;
+	long offset = 0;
 	const char *func_name;
 	char *func;
 	int n;
@@ -12302,6 +12302,13 @@ static int attach_kprobe(const struct bpf_program *prog, long cookie, struct bpf
 		pr_warn("kprobe name is invalid: %s\n", func_name);
 		return -EINVAL;
 	}
+
+	if (offset < 0) {
+		free(func);
+		pr_warn("kprobe offset must be a non-negative integer: %li\n", offset);
+		return -EINVAL;
+	}
+
 	if (opts.retprobe && offset != 0) {
 		free(func);
 		pr_warn("kretprobes do not support offset specification\n");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0066/2077] selftests/bpf: Fix off-by-one in bpf_cpumask_populate related selftest
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (64 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0065/2077] libbpf: Report error when a negative kprobe offset is specified Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0067/2077] dt-bindings: timer: Remove sifive,fine-ctr-bits property Greg Kroah-Hartman
                   ` (931 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Matt Bobrowski, Paul Chaignon,
	Kumar Kartikeya Dwivedi, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matt Bobrowski <mattbobrowski@google.com>

[ Upstream commit 0aa6378695b8c67146130812f635f07c4898f171 ]

The test_populate test uses >= instead of > when checking if the
runtime nr_cpus exceeds the bit capacity of a cpumask_t.

On a system where the physical CPU core count perfectly matches the
CONFIG_NR_CPUS upper bound (e.g. nr_cpus = 512 and CONFIG_NR_CPUS =
512), the condition nr_cpus >= CPUMASK_TEST_MASKLEN * 8 evaluates to
true (512 >= 512). This incorrectly causes the test to fail with an
error value of 3.

A 512-bit cpumask_t provides enough bits (indices 0 through 511) to
represent 512 CPUs. The subsequent bpf_for(i, 0, nr_cpus) loop
iterates up to nr_cpus - 1 (511), which perfectly aligns with the
maximum valid index of the bitmask.

Change the condition to nr_cpus > CPUMASK_TEST_MASKLEN * 8 to fix the
false positive failure on these systems.

Fixes: 918ba2636d4e ("selftests: bpf: add bpf_cpumask_populate selftests")
Signed-off-by: Matt Bobrowski <mattbobrowski@google.com>
Acked-by: Paul Chaignon <paul.chaignon@gmail.com>
Link: https://lore.kernel.org/bpf/20260420093734.2400330-1-mattbobrowski@google.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/bpf/progs/cpumask_success.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/selftests/bpf/progs/cpumask_success.c b/tools/testing/selftests/bpf/progs/cpumask_success.c
index 0e04c31b91c0c0..774706e7b058b9 100644
--- a/tools/testing/selftests/bpf/progs/cpumask_success.c
+++ b/tools/testing/selftests/bpf/progs/cpumask_success.c
@@ -866,7 +866,7 @@ int BPF_PROG(test_populate, struct task_struct *task, u64 clone_flags)
 	 * access NR_CPUS, the upper bound for nr_cpus, so we infer
 	 * it from the size of cpumask_t.
 	 */
-	if (nr_cpus < 0 || nr_cpus >= CPUMASK_TEST_MASKLEN * 8) {
+	if (nr_cpus < 0 || nr_cpus > CPUMASK_TEST_MASKLEN * 8) {
 		err = 3;
 		goto out;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0067/2077] dt-bindings: timer: Remove sifive,fine-ctr-bits property
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (65 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0066/2077] selftests/bpf: Fix off-by-one in bpf_cpumask_populate related selftest Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0068/2077] wifi: ath12k: Fix invalid IRQ requests during AHB probe Greg Kroah-Hartman
                   ` (930 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Conor Dooley, Nick Hu,
	Daniel Lezcano, Conor Dooley, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nick Hu <nick.hu@sifive.com>

[ Upstream commit 1ccca10755107bc8c649937d1ba69651d1ef9da2 ]

The counter width can be inferred from the compatible string, making the
explicit "sifive,fine-ctr-bits" property redundant. Remove the property
to simplify the bindings.

Fixes: 0f920690a82c ("dt-bindings: timer: Add SiFive CLINT2")
Suggested-by: Conor Dooley <conor+dt@kernel.org>
Signed-off-by: Nick Hu <nick.hu@sifive.com>
Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
Acked-by: Conor Dooley <conor.dooley@microchip.com>
Link: https://lore.kernel.org/linux-riscv/20260330-relative-hardened-5ce35fe1ef57@spud/
Link: https://patch.msgid.link/20260419-clintv2-remove-fine-ctr-v1-1-7527f4d45850@sifive.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../devicetree/bindings/timer/sifive,clint.yaml  | 16 ----------------
 1 file changed, 16 deletions(-)

diff --git a/Documentation/devicetree/bindings/timer/sifive,clint.yaml b/Documentation/devicetree/bindings/timer/sifive,clint.yaml
index 3c16b260db040d..051edb1da0d739 100644
--- a/Documentation/devicetree/bindings/timer/sifive,clint.yaml
+++ b/Documentation/devicetree/bindings/timer/sifive,clint.yaml
@@ -72,22 +72,6 @@ properties:
     minItems: 1
     maxItems: 4095
 
-  sifive,fine-ctr-bits:
-    maximum: 15
-    description: The width in bits of the fine counter.
-
-if:
-  properties:
-    compatible:
-      contains:
-        const: sifive,clint2
-then:
-  required:
-    - sifive,fine-ctr-bits
-else:
-  properties:
-    sifive,fine-ctr-bits: false
-
 additionalProperties: false
 
 required:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0068/2077] wifi: ath12k: Fix invalid IRQ requests during AHB probe
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (66 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0067/2077] dt-bindings: timer: Remove sifive,fine-ctr-bits property Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0069/2077] libbpf: Fix deduplication of typedef with base definitions Greg Kroah-Hartman
                   ` (929 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Aaradhana Sahu, Baochen Qiang,
	Rameshkumar Sundaram, Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>

[ Upstream commit 590182b72213ef04977ab0b16b8dadfcfd25ff73 ]

ath12k_ahb_config_ext_irq() iterates over ATH12K_EXT_IRQ_NUM_MAX (16)
entries while checking TX ring masks, but the tcl_to_wbm_rbm_map array
contains only DP_TCL_NUM_RING_MAX (4) valid elements.

When the iterator (j) is greater than or equal to DP_TCL_NUM_RING_MAX,
it accesses tcl_to_wbm_rbm_map[j] out of bounds. This results in
reading uninitialized memory for wbm_ring_num, causing the driver to
evaluate incorrect BIT() conditions and request IRQs for rings that do
not have an assigned interrupt line or device tree entry.

This leads to request_irq() failures with -ENXIO or -EINVAL during
ath12k AHB probe.

Fix this by splitting the loop into two separate loops: one iterating
over DP_TCL_NUM_RING_MAX for TX ring, and another iterating over
ATH12K_EXT_IRQ_NUM_MAX for remaining IRQ entries.
Also add a bounds check for num_irq.

Tested-on: IPQ5332 hw1.0 AHB WLAN.WBE.1.6-01275-QCAHKSWPL_SILICONZ-1

Fixes: 6cee30f0da75 ("wifi: ath12k: add AHB driver support for IPQ5332")
Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Link: https://patch.msgid.link/20260414062829.2371761-1-aaradhana.sahu@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/ath12k/ahb.c | 25 +++++++++++++++----------
 1 file changed, 15 insertions(+), 10 deletions(-)

diff --git a/drivers/net/wireless/ath/ath12k/ahb.c b/drivers/net/wireless/ath/ath12k/ahb.c
index 2dcf0a52e4c15b..30733a244454e5 100644
--- a/drivers/net/wireless/ath/ath12k/ahb.c
+++ b/drivers/net/wireless/ath/ath12k/ahb.c
@@ -583,31 +583,36 @@ static int ath12k_ahb_config_ext_irq(struct ath12k_base *ab)
 		netif_napi_add(irq_grp->napi_ndev, &irq_grp->napi,
 			       ath12k_ahb_ext_grp_napi_poll);
 
-		for (j = 0; j < ATH12K_EXT_IRQ_NUM_MAX; j++) {
-			/* For TX ring, ensure that the ring mask and the
-			 * tcl_to_wbm_rbm_map point to the same ring number.
-			 */
+		for (j = 0; j < DP_TCL_NUM_RING_MAX; j++) {
 			if (ring_mask->tx[i] &
-			    BIT(ab->hal.tcl_to_wbm_rbm_map[j].wbm_ring_num)) {
+			    BIT(ab->hal.tcl_to_wbm_rbm_map[j].wbm_ring_num) &&
+			    num_irq < ATH12K_EXT_IRQ_NUM_MAX) {
 				irq_grp->irqs[num_irq++] =
 					wbm2host_tx_completions_ring1 - j;
 			}
+		}
 
-			if (ring_mask->rx[i] & BIT(j)) {
+		for (j = 0; j < ATH12K_EXT_IRQ_NUM_MAX; j++) {
+			if (ring_mask->rx[i] & BIT(j) &&
+			    num_irq < ATH12K_EXT_IRQ_NUM_MAX) {
 				irq_grp->irqs[num_irq++] =
 					reo2host_destination_ring1 - j;
 			}
 
-			if (ring_mask->rx_err[i] & BIT(j))
+			if (ring_mask->rx_err[i] & BIT(j) &&
+			    num_irq < ATH12K_EXT_IRQ_NUM_MAX)
 				irq_grp->irqs[num_irq++] = reo2host_exception;
 
-			if (ring_mask->rx_wbm_rel[i] & BIT(j))
+			if (ring_mask->rx_wbm_rel[i] & BIT(j) &&
+			    num_irq < ATH12K_EXT_IRQ_NUM_MAX)
 				irq_grp->irqs[num_irq++] = wbm2host_rx_release;
 
-			if (ring_mask->reo_status[i] & BIT(j))
+			if (ring_mask->reo_status[i] & BIT(j) &&
+			    num_irq < ATH12K_EXT_IRQ_NUM_MAX)
 				irq_grp->irqs[num_irq++] = reo2host_status;
 
-			if (ring_mask->rx_mon_dest[i] & BIT(j))
+			if (ring_mask->rx_mon_dest[i] & BIT(j) &&
+			    num_irq < ATH12K_EXT_IRQ_NUM_MAX)
 				irq_grp->irqs[num_irq++] =
 					rxdma2host_monitor_destination_mac1;
 		}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0069/2077] libbpf: Fix deduplication of typedef with base definitions
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (67 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0068/2077] wifi: ath12k: Fix invalid IRQ requests during AHB probe Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0070/2077] drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro Greg Kroah-Hartman
                   ` (928 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Antoine Tenart, Andrii Nakryiko,
	Alan Maguire, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Antoine Tenart <atenart@kernel.org>

[ Upstream commit 0831b110eb4591e4ad8c5fd0d8f0f3f9979a5ff5 ]

When deduplicating definitions for a module, typedef defined in the base
are not removed. This is because the hash used for base types differs
from the one used in the deduplication logic in btf_dedup_struct_type.

This was introduced by the referenced commit when moving the typedef
deduplication logic handling from btf_dedup_ref_type to
btf_dedup_struct_type, as this also changed the hash logic
(btf_hash_common to btf_hash_typedef).

This also impacts other types referencing those typedef (e.g. const). In
my test, the BTF section size of the openvswitch module went from 31KB
to 45KB.

Fixes: 3781413465df ("libbpf: Fix BTF dedup to support recursive typedef definitions").
Signed-off-by: Antoine Tenart <atenart@kernel.org>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Tested-by: Alan Maguire <alan.maguire@oracle.com>
Reviewed-by: Alan Maguire <alan.maguire@oracle.com>
Link: https://lore.kernel.org/bpf/20260417083319.32716-1-atenart@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/lib/bpf/btf.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/tools/lib/bpf/btf.c b/tools/lib/bpf/btf.c
index ceb57b46a8782a..771aeaa0262b29 100644
--- a/tools/lib/bpf/btf.c
+++ b/tools/lib/bpf/btf.c
@@ -4578,12 +4578,14 @@ static int btf_dedup_prep(struct btf_dedup *d)
 		case BTF_KIND_RESTRICT:
 		case BTF_KIND_PTR:
 		case BTF_KIND_FWD:
-		case BTF_KIND_TYPEDEF:
 		case BTF_KIND_FUNC:
 		case BTF_KIND_FLOAT:
 		case BTF_KIND_TYPE_TAG:
 			h = btf_hash_common(t);
 			break;
+		case BTF_KIND_TYPEDEF:
+			h = btf_hash_typedef(t);
+			break;
 		case BTF_KIND_INT:
 		case BTF_KIND_DECL_TAG:
 			h = btf_hash_int_decl_tag(t);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0070/2077] drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (68 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0069/2077] libbpf: Fix deduplication of typedef with base definitions Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0071/2077] spi: atcspi200: fix use-after-free when driver unbind Greg Kroah-Hartman
                   ` (927 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yang Wang, Alex Deucher, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yang Wang <kevinyang.wang@amd.com>

[ Upstream commit 0d892afb52d2b940d891b6b52dc9f04debef2d81 ]

macros should not include a trailing semicolon as per kernel coding
style (checkpatch.pl warning).

move the semicolon from the macro definition to the invocation sites instead.

checkpatch.pl logs:
WARNING: macros should not use a trailing semicolon
+#define AMDGPU_PM_POLICY_ATTR(_name, _id)                                  \
+       static struct amdgpu_pm_policy_attr pm_policy_attr_##_name = {     \
+               .dev_attr = __ATTR(_name, 0644, amdgpu_get_pm_policy_attr, \
+                                  amdgpu_set_pm_policy_attr),             \
+               .id = PP_PM_POLICY_##_id,                                  \
+       };

Fixes: 4d154b1ca580 ("drm/amd/pm: Add support for DPM policies")
Signed-off-by: Yang Wang <kevinyang.wang@amd.com>
Acked-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/amd/pm/amdgpu_pm.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/gpu/drm/amd/pm/amdgpu_pm.c b/drivers/gpu/drm/amd/pm/amdgpu_pm.c
index 736304e73ca4d1..024bfdb7c1571c 100644
--- a/drivers/gpu/drm/amd/pm/amdgpu_pm.c
+++ b/drivers/gpu/drm/amd/pm/amdgpu_pm.c
@@ -2505,12 +2505,12 @@ static ssize_t amdgpu_set_pm_policy_attr(struct device *dev,
 		.dev_attr = __ATTR(_name, 0644, amdgpu_get_pm_policy_attr, \
 				   amdgpu_set_pm_policy_attr),             \
 		.id = PP_PM_POLICY_##_id,                                  \
-	};
+	}
 
 #define AMDGPU_PM_POLICY_ATTR_VAR(_name) pm_policy_attr_##_name.dev_attr.attr
 
-AMDGPU_PM_POLICY_ATTR(soc_pstate, SOC_PSTATE)
-AMDGPU_PM_POLICY_ATTR(xgmi_plpd, XGMI_PLPD)
+AMDGPU_PM_POLICY_ATTR(soc_pstate, SOC_PSTATE);
+AMDGPU_PM_POLICY_ATTR(xgmi_plpd, XGMI_PLPD);
 
 static struct attribute *pm_policy_attrs[] = {
 	&AMDGPU_PM_POLICY_ATTR_VAR(soc_pstate),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0071/2077] spi: atcspi200: fix use-after-free when driver unbind
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (69 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0070/2077] drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0072/2077] selftests/bpf: Use local type for flow_offload_tuple_rhash in xdp_flowtable Greg Kroah-Hartman
                   ` (926 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit 565bdf45125a05aa8f622f58f598283f46ba43f4 ]

DMA resource is initialized after SPI controller registration. So
when driver unbind, this can trigger a use-after-free when DMA is
torn down while the controller is still alive and triggers DMA transfers.

Fixes: 34e3815ea459 ("spi: atcspi200: Add ATCSPI200 SPI controller driver")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Link: https://patch.msgid.link/20260417-atcspi-v1-1-854831667d63@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/spi/spi-atcspi200.c | 13 +++++++------
 1 file changed, 7 insertions(+), 6 deletions(-)

diff --git a/drivers/spi/spi-atcspi200.c b/drivers/spi/spi-atcspi200.c
index 3832d9db3cbf84..c5cf1aa2d67438 100644
--- a/drivers/spi/spi-atcspi200.c
+++ b/drivers/spi/spi-atcspi200.c
@@ -575,12 +575,6 @@ static int atcspi_probe(struct platform_device *pdev)
 	if (ret)
 		goto free_controller;
 
-	ret = devm_spi_register_controller(&pdev->dev, host);
-	if (ret) {
-		dev_err_probe(spi->dev, ret,
-			      "Failed to register SPI controller\n");
-		goto free_controller;
-	}
 	spi->use_dma = false;
 	if (ATCSPI_DMA_SUPPORT) {
 		ret = atcspi_configure_dma(spi);
@@ -591,6 +585,13 @@ static int atcspi_probe(struct platform_device *pdev)
 			spi->use_dma = true;
 	}
 
+	ret = devm_spi_register_controller(&pdev->dev, host);
+	if (ret) {
+		dev_err_probe(spi->dev, ret,
+			      "Failed to register SPI controller\n");
+		goto free_controller;
+	}
+
 	return 0;
 
 free_controller:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0072/2077] selftests/bpf: Use local type for flow_offload_tuple_rhash in xdp_flowtable
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (70 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0071/2077] spi: atcspi200: fix use-after-free when driver unbind Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0073/2077] selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern Greg Kroah-Hartman
                   ` (925 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Gregory Bell, Alexei Starovoitov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Gregory Bell <grbell@redhat.com>

[ Upstream commit ac985e7bf840e34a8dafe0808cc571fd85896c30 ]

Define flow_offload_tuple_rhash___local and use it in place of the
forward-declared kernel type for the bpf_xdp_flow_lookup kfunc return
type and tuplehash variable. This is consistent with how
bpf_flowtable_opts___local is already handled in the same file and
avoids relying on a forward declaration of the struct.

Fixes: eeb23b54e447 ("selftests/bpf: fix compilation failure when CONFIG_NF_FLOW_TABLE=m")
Signed-off-by: Gregory Bell <grbell@redhat.com>
Link: https://lore.kernel.org/r/20260417154122.2558890-2-grbell@redhat.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/bpf/progs/xdp_flowtable.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/tools/testing/selftests/bpf/progs/xdp_flowtable.c b/tools/testing/selftests/bpf/progs/xdp_flowtable.c
index 7fdc7b23ee7498..e67daa02749d54 100644
--- a/tools/testing/selftests/bpf/progs/xdp_flowtable.c
+++ b/tools/testing/selftests/bpf/progs/xdp_flowtable.c
@@ -15,7 +15,10 @@ struct bpf_flowtable_opts___local {
 	s32 error;
 };
 
-struct flow_offload_tuple_rhash *
+struct flow_offload_tuple_rhash___local {
+};
+
+struct flow_offload_tuple_rhash___local *
 bpf_xdp_flow_lookup(struct xdp_md *, struct bpf_fib_lookup *,
 		    struct bpf_flowtable_opts___local *, u32) __ksym;
 
@@ -67,7 +70,7 @@ int xdp_flowtable_do_lookup(struct xdp_md *ctx)
 {
 	void *data_end = (void *)(long)ctx->data_end;
 	struct bpf_flowtable_opts___local opts = {};
-	struct flow_offload_tuple_rhash *tuplehash;
+	struct flow_offload_tuple_rhash___local *tuplehash;
 	struct bpf_fib_lookup tuple = {
 		.ifindex = ctx->ingress_ifindex,
 	};
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0073/2077] selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (71 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0072/2077] selftests/bpf: Use local type for flow_offload_tuple_rhash in xdp_flowtable Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0074/2077] Documentation: proc: fix section numbering in table of contents Greg Kroah-Hartman
                   ` (924 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Gregory Bell, Alexei Starovoitov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Gregory Bell <grbell@redhat.com>

[ Upstream commit afb0450be061907a0f5d36bd8b010ca30eda3d3b ]

Replace the forward-declared struct bpf_fou_encap with the existing
bpf_fou_encap___local type in the bpf_skb_set_fou_encap and
bpf_skb_get_fou_encap declarations. This removes the need for
the forward declaration and the explicit casts at each call.

Fixes: d17f9b370df6 ("selftests/bpf: Fix compilation failure when CONFIG_NET_FOU!=y")
Signed-off-by: Gregory Bell <grbell@redhat.com>
Link: https://lore.kernel.org/r/20260417154122.2558890-3-grbell@redhat.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../testing/selftests/bpf/progs/test_tunnel_kern.c  | 13 ++++++-------
 1 file changed, 6 insertions(+), 7 deletions(-)

diff --git a/tools/testing/selftests/bpf/progs/test_tunnel_kern.c b/tools/testing/selftests/bpf/progs/test_tunnel_kern.c
index 32127f1cd6872e..30f1de458669d3 100644
--- a/tools/testing/selftests/bpf/progs/test_tunnel_kern.c
+++ b/tools/testing/selftests/bpf/progs/test_tunnel_kern.c
@@ -6,6 +6,7 @@
  * modify it under the terms of version 2 of the GNU General Public
  * License as published by the Free Software Foundation.
  */
+#define BPF_NO_KFUNC_PROTOTYPES
 #include "vmlinux.h"
 #include <bpf/bpf_core_read.h>
 #include <bpf/bpf_helpers.h>
@@ -36,12 +37,10 @@ enum bpf_fou_encap_type___local {
 	FOU_BPF_ENCAP_GUE___local,
 };
 
-struct bpf_fou_encap;
-
 int bpf_skb_set_fou_encap(struct __sk_buff *skb_ctx,
-			  struct bpf_fou_encap *encap, int type) __ksym;
+			  struct bpf_fou_encap___local *encap, int type) __ksym;
 int bpf_skb_get_fou_encap(struct __sk_buff *skb_ctx,
-			  struct bpf_fou_encap *encap) __ksym;
+			  struct bpf_fou_encap___local *encap) __ksym;
 struct xfrm_state *
 bpf_xdp_get_xfrm_state(struct xdp_md *ctx, struct bpf_xfrm_state_opts *opts,
 		       u32 opts__sz) __ksym;
@@ -781,7 +780,7 @@ int ipip_gue_set_tunnel(struct __sk_buff *skb)
 	encap.sport = 0;
 	encap.dport = bpf_htons(5555);
 
-	ret = bpf_skb_set_fou_encap(skb, (struct bpf_fou_encap *)&encap,
+	ret = bpf_skb_set_fou_encap(skb, &encap,
 				    bpf_core_enum_value(enum bpf_fou_encap_type___local,
 							FOU_BPF_ENCAP_GUE___local));
 	if (ret < 0) {
@@ -820,7 +819,7 @@ int ipip_fou_set_tunnel(struct __sk_buff *skb)
 	encap.sport = 0;
 	encap.dport = bpf_htons(5555);
 
-	ret = bpf_skb_set_fou_encap(skb, (struct bpf_fou_encap *)&encap,
+	ret = bpf_skb_set_fou_encap(skb, &encap,
 				    FOU_BPF_ENCAP_FOU___local);
 	if (ret < 0) {
 		log_err(ret);
@@ -843,7 +842,7 @@ int ipip_encap_get_tunnel(struct __sk_buff *skb)
 		return TC_ACT_SHOT;
 	}
 
-	ret = bpf_skb_get_fou_encap(skb, (struct bpf_fou_encap *)&encap);
+	ret = bpf_skb_get_fou_encap(skb, &encap);
 	if (ret < 0) {
 		log_err(ret);
 		return TC_ACT_SHOT;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0074/2077] Documentation: proc: fix section numbering in table of contents
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (72 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0073/2077] selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0075/2077] arm64: dts: rockchip: Fix vdec register blocks order on RK3576 Greg Kroah-Hartman
                   ` (923 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Baolin Liu, Randy Dunlap,
	Jonathan Corbet, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Baolin Liu <liubaolin@kylinos.cn>

[ Upstream commit 97a7bd8c2c58a6d820df563d1d0f68aafec45477 ]

Commit e24ccaaf7ec4 ("block: remove last remaining traces of IDE
documentation") removed the IDE section but left its table of
contents entry behind.
Fix the stale entry and renumber the following sections.

Fixes: e24ccaaf7ec4 ("block: remove last remaining traces of IDE documentation")
Signed-off-by: Baolin Liu <liubaolin@kylinos.cn>
Acked-by: Randy Dunlap <rdunlap@infradead.org>
Signed-off-by: Jonathan Corbet <corbet@lwn.net>
Message-ID: <20260424090654.19229-1-liubaolin12138@163.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/filesystems/proc.rst | 14 +++++++-------
 1 file changed, 7 insertions(+), 7 deletions(-)

diff --git a/Documentation/filesystems/proc.rst b/Documentation/filesystems/proc.rst
index db6167befb7b2c..3c6e4f52f3e4ef 100644
--- a/Documentation/filesystems/proc.rst
+++ b/Documentation/filesystems/proc.rst
@@ -23,13 +23,13 @@ fixes/update part 1.1  Stefani Seibold <stefani@seibold.net>    June 9 2009
   1	Collecting System Information
   1.1	Process-Specific Subdirectories
   1.2	Kernel data
-  1.3	IDE devices in /proc/ide
-  1.4	Networking info in /proc/net
-  1.5	SCSI info
-  1.6	Parallel port info in /proc/parport
-  1.7	TTY info in /proc/tty
-  1.8	Miscellaneous kernel statistics in /proc/stat
-  1.9	Ext4 file system parameters
+  1.3	Networking info in /proc/net
+  1.4	SCSI info
+  1.5	Parallel port info in /proc/parport
+  1.6	TTY info in /proc/tty
+  1.7	Miscellaneous kernel statistics in /proc/stat
+  1.8	Ext4 file system parameters
+  1.9	/proc/consoles - Shows registered system consoles
 
   2	Modifying System Parameters
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0075/2077] arm64: dts: rockchip: Fix vdec register blocks order on RK3576
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (73 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0074/2077] Documentation: proc: fix section numbering in table of contents Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0076/2077] arm64: dts: rockchip: Update vdec register blocks order on RK3588 Greg Kroah-Hartman
                   ` (922 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cristian Ciocaltea, Heiko Stuebner,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>

[ Upstream commit 63fd2f6aa402a105fa22ede6f3c35dafd64827a5 ]

When building device trees for the RK3576 based boards, DTC shows the
following complaint:

  rk3576.dtsi:1282.30-1304.5: Warning (simple_bus_reg): /soc/video-codec@27b00000: simple-bus unit address format error, expected "27b00100"

Since the video decoder support for the aforementioned SoC in mainline
driver and devicetrees hasn't been released yet (just landed in
v7.0-rc1), fix the issue by providing the register blocks using the
'link,function,cache' listing, which follows the address-based order as
shown in the vendor's datasheet and, implicitly, ensures the unit
address points to the primary register range.

Fixes: da0de806d8b4 ("arm64: dts: rockchip: Add the vdpu383 Video Decoder on rk3576")
Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Link: https://patch.msgid.link/20260304-vdec-reg-order-rk3576-v5-3-7006fad42c3a@collabora.com
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/rockchip/rk3576.dtsi | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/arch/arm64/boot/dts/rockchip/rk3576.dtsi b/arch/arm64/boot/dts/rockchip/rk3576.dtsi
index 28175d8200d57c..e12a2a0cfb8916 100644
--- a/arch/arm64/boot/dts/rockchip/rk3576.dtsi
+++ b/arch/arm64/boot/dts/rockchip/rk3576.dtsi
@@ -1281,10 +1281,10 @@ gpu: gpu@27800000 {
 
 		vdec: video-codec@27b00000 {
 			compatible = "rockchip,rk3576-vdec";
-			reg = <0x0 0x27b00100 0x0 0x500>,
-			      <0x0 0x27b00000 0x0 0x100>,
+			reg = <0x0 0x27b00000 0x0 0x100>,
+			      <0x0 0x27b00100 0x0 0x500>,
 			      <0x0 0x27b00600 0x0 0x100>;
-			reg-names = "function", "link", "cache";
+			reg-names = "link", "function", "cache";
 			interrupts = <GIC_SPI 308 IRQ_TYPE_LEVEL_HIGH>;
 			clocks = <&cru ACLK_RKVDEC_ROOT>, <&cru HCLK_RKVDEC>,
 				 <&cru ACLK_RKVDEC_ROOT_BAK>, <&cru CLK_RKVDEC_CORE>,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0076/2077] arm64: dts: rockchip: Update vdec register blocks order on RK3588
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (74 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0075/2077] arm64: dts: rockchip: Fix vdec register blocks order on RK3576 Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0077/2077] arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Cobra Greg Kroah-Hartman
                   ` (921 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cristian Ciocaltea, Heiko Stuebner,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>

[ Upstream commit b481c11cd20a114c4df35f3b1ecd28b05e622067 ]

With the introduction of the RK3588 SoC, three register blocks have been
provided for the video decoder unit instead of just one, which are
further referenced in the vendor's datasheet by 'link table', 'function'
and 'cache'.  The former is present at the top of the listing, starting
at video decoder unit base address, but the binding got this wrong
initially, i.e. the 'function' block got listed before the 'link' one.

Since the video decoder support for the aforementioned SoC in mainline
driver and devicetrees hasn't been released yet (just landed in
v7.0-rc1), address the problem by providing the register blocks for
vdec0 & vdec1 nodes using the 'link,function,cache' listing, which
ensures the unit address points to the primary register range.

This aligns with a similar fix for RK3576, where DTC also complained
about the bus address format.

Fixes: f61731bd6062 ("arm64: dts: rockchip: Add the vdpu381 Video Decoders on RK3588")
Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Link: https://patch.msgid.link/20260304-vdec-reg-order-rk3576-v5-4-7006fad42c3a@collabora.com
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/rockchip/rk3588-base.dtsi | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/arch/arm64/boot/dts/rockchip/rk3588-base.dtsi b/arch/arm64/boot/dts/rockchip/rk3588-base.dtsi
index 4fb8888c281c8c..d4dc057e31f0e3 100644
--- a/arch/arm64/boot/dts/rockchip/rk3588-base.dtsi
+++ b/arch/arm64/boot/dts/rockchip/rk3588-base.dtsi
@@ -1355,10 +1355,10 @@ vepu121_3_mmu: iommu@fdbac800 {
 
 	vdec0: video-codec@fdc38000 {
 		compatible = "rockchip,rk3588-vdec";
-		reg = <0x0 0xfdc38100 0x0 0x500>,
-		      <0x0 0xfdc38000 0x0 0x100>,
+		reg = <0x0 0xfdc38000 0x0 0x100>,
+		      <0x0 0xfdc38100 0x0 0x500>,
 		      <0x0 0xfdc38600 0x0 0x100>;
-		reg-names = "function", "link", "cache";
+		reg-names = "link", "function", "cache";
 		interrupts = <GIC_SPI 95 IRQ_TYPE_LEVEL_HIGH 0>;
 		clocks = <&cru ACLK_RKVDEC0>, <&cru HCLK_RKVDEC0>, <&cru CLK_RKVDEC0_CA>,
 			 <&cru CLK_RKVDEC0_CORE>, <&cru CLK_RKVDEC0_HEVC_CA>;
@@ -1387,10 +1387,10 @@ vdec0_mmu: iommu@fdc38700 {
 
 	vdec1: video-codec@fdc40000 {
 		compatible = "rockchip,rk3588-vdec";
-		reg = <0x0 0xfdc40100 0x0 0x500>,
-		      <0x0 0xfdc40000 0x0 0x100>,
+		reg = <0x0 0xfdc40000 0x0 0x100>,
+		      <0x0 0xfdc40100 0x0 0x500>,
 		      <0x0 0xfdc40600 0x0 0x100>;
-		reg-names = "function", "link", "cache";
+		reg-names = "link", "function", "cache";
 		interrupts = <GIC_SPI 97 IRQ_TYPE_LEVEL_HIGH 0>;
 		clocks = <&cru ACLK_RKVDEC1>, <&cru HCLK_RKVDEC1>, <&cru CLK_RKVDEC1_CA>,
 			 <&cru CLK_RKVDEC1_CORE>, <&cru CLK_RKVDEC1_HEVC_CA>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0077/2077] arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Cobra
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (75 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0076/2077] arm64: dts: rockchip: Update vdec register blocks order on RK3588 Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0078/2077] arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S Greg Kroah-Hartman
                   ` (920 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Quentin Schulz, Heiko Stuebner,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Quentin Schulz <quentin.schulz@cherry.de>

[ Upstream commit 6598ed3586a4b1cc79423666e66b9861631a6c7e ]

When not passing the PHY ID with an ethernet-phy-idX.Y compatible
property, the MDIO bus will attempt to auto-detect the PHY by reading
its registers and then probing the appropriate driver. For this to work,
the PHY needs to be in a working state.

Unfortunately, the net subsystem doesn't control the PHY reset GPIO when
attempting to auto-detect the PHY. This means the PHY needs to be in a
working state when entering the Linux kernel. This historically has been
the case for this device, but only because the bootloader was taking
care of initializing the Ethernet controller even when not using it.
We're attempting to support the removal of the network stack in the
bootloader, which means the Linux kernel will be entered with the PHY
still in reset and now Ethernet doesn't work anymore.

The devices in the field only ever had a TI DP83825, so let's simply
bypass the auto-detection mechanism entirely by passing the appropriate
PHY IDs via the compatible.

Fixes: bb510ddc9d3e ("arm64: dts: rockchip: add px30-cobra base dtsi and board variants")
Signed-off-by: Quentin Schulz <quentin.schulz@cherry.de>
Link: https://patch.msgid.link/20260421-px30-eth-phy-v2-1-68c375b120fd@cherry.de
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/rockchip/px30-cobra.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/rockchip/px30-cobra.dtsi b/arch/arm64/boot/dts/rockchip/px30-cobra.dtsi
index b7e669d8ba4d14..add917af5de783 100644
--- a/arch/arm64/boot/dts/rockchip/px30-cobra.dtsi
+++ b/arch/arm64/boot/dts/rockchip/px30-cobra.dtsi
@@ -397,7 +397,7 @@ &io_domains {
 
 &mdio {
 	dp83825: ethernet-phy@0 {
-		compatible = "ethernet-phy-ieee802.3-c22";
+		compatible = "ethernet-phy-id2000.a140";
 		reg = <0x0>;
 		pinctrl-names = "default";
 		pinctrl-0 = <&phy_rst>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0078/2077] arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (76 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0077/2077] arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Cobra Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0079/2077] ima: Fix sigv3 signature handling for EVM_IMA_XATTR_DIGSIG Greg Kroah-Hartman
                   ` (919 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Diederik de Haas, Heiko Stuebner,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Diederik de Haas <diederik@cknow-tech.com>

[ Upstream commit c83c4a09d4c01c91d6c52d6d4d77a06892a3e83b ]

According to the NanoPi R5S 2204 schematic on page 6, GPIO0_C4 is for
GMAC0_INT/PMEB_GPIO0_C4, while GPIO0_C5 is for GMAC0_RSTn_GPIO0_C5.
While the 'reset-gpios' property was set correctly, the corresponding
pinctrl didn't match that.

Next to fixing the pinctrl definition, also change the node name and
phandle to match what is used in the schematic.

Fixes: c6629b9a6738 ("arm64: dts: rockchip: Add FriendlyElec Nanopi R5S")
Signed-off-by: Diederik de Haas <diederik@cknow-tech.com>
Link: https://patch.msgid.link/20260401131551.734456-2-diederik@cknow-tech.com
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/rockchip/rk3568-nanopi-r5s.dts | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/arch/arm64/boot/dts/rockchip/rk3568-nanopi-r5s.dts b/arch/arm64/boot/dts/rockchip/rk3568-nanopi-r5s.dts
index 718d1a2da8e568..90ce6f0e1dcff7 100644
--- a/arch/arm64/boot/dts/rockchip/rk3568-nanopi-r5s.dts
+++ b/arch/arm64/boot/dts/rockchip/rk3568-nanopi-r5s.dts
@@ -98,7 +98,7 @@ &mdio0 {
 	rgmii_phy0: ethernet-phy@1 {
 		compatible = "ethernet-phy-ieee802.3-c22";
 		reg = <1>;
-		pinctrl-0 = <&eth_phy0_reset_pin>;
+		pinctrl-0 = <&gmac0_rstn_gpio0_c5_pin>;
 		pinctrl-names = "default";
 	};
 };
@@ -132,8 +132,8 @@ &pcie3x2 {
 
 &pinctrl {
 	gmac0 {
-		eth_phy0_reset_pin: eth-phy0-reset-pin {
-			rockchip,pins = <0 RK_PC4 RK_FUNC_GPIO &pcfg_pull_up>;
+		gmac0_rstn_gpio0_c5_pin: gmac0-rstn-gpio0-c5-pin {
+			rockchip,pins = <0 RK_PC5 RK_FUNC_GPIO &pcfg_pull_up>;
 		};
 	};
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0079/2077] ima: Fix sigv3 signature handling for EVM_IMA_XATTR_DIGSIG
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (77 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0078/2077] arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0080/2077] dt-bindings: net: bluetooth: qualcomm: Fix WCN6855 regulator names Greg Kroah-Hartman
                   ` (918 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kamlesh Kumar, Stefan Berger,
	Mimi Zohar, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kamlesh Kumar <kamlesh0hrs@gmail.com>

[ Upstream commit 398ee113f15c1e8e62535e54f22fb4db340c7835 ]

ima_get_hash_algo() only recognizes version 2 signatures when the xattr
type is EVM_IMA_XATTR_DIGSIG. Since sigv3 signatures also use
EVM_IMA_XATTR_DIGSIG as the xattr type, version 3 must be accepted as
well to correctly determine the hash algorithm.

Additionally, ima_validate_rule() does not include IMA_SIGV3_REQUIRED in
the allowed flags bitmask for MODULE_CHECK, KEXEC_KERNEL_CHECK, and
KEXEC_INITRAMFS_CHECK hook functions. As a result, policy rules with
"appraise_type=sigv3" are rejected for these functions.

Add version 3 to the accepted versions in ima_get_hash_algo() for
EVM_IMA_XATTR_DIGSIG, and add IMA_SIGV3_REQUIRED to the allowed flags
for MODULE_CHECK, KEXEC_KERNEL_CHECK, and KEXEC_INITRAMFS_CHECK in
ima_validate_rule().

Signed-off-by: Kamlesh Kumar <kam@juniper.net>
Tested-by: Stefan Berger <stefanb@linux.ibm.com>
Fixes: de4c44a7f559 ("ima: add support to require IMA sigv3 signatures")
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 security/integrity/ima/ima_appraise.c | 5 +++--
 security/integrity/ima/ima_policy.c   | 3 ++-
 2 files changed, 5 insertions(+), 3 deletions(-)

diff --git a/security/integrity/ima/ima_appraise.c b/security/integrity/ima/ima_appraise.c
index de963b9f363447..2dd231567710a5 100644
--- a/security/integrity/ima/ima_appraise.c
+++ b/security/integrity/ima/ima_appraise.c
@@ -195,8 +195,9 @@ enum hash_algo ima_get_hash_algo(const struct evm_ima_xattr_data *xattr_value,
 		return sig->hash_algo;
 	case EVM_IMA_XATTR_DIGSIG:
 		sig = (typeof(sig))xattr_value;
-		if (sig->version != 2 || xattr_len <= sizeof(*sig)
-		    || sig->hash_algo >= HASH_ALGO__LAST)
+		if ((sig->version != 2 && sig->version != 3) ||
+		    xattr_len <= sizeof(*sig) ||
+		    sig->hash_algo >= HASH_ALGO__LAST)
 			return ima_hash_algo;
 		return sig->hash_algo;
 	case IMA_XATTR_DIGEST_NG:
diff --git a/security/integrity/ima/ima_policy.c b/security/integrity/ima/ima_policy.c
index f7f940a7692234..b1c010e8eb1387 100644
--- a/security/integrity/ima/ima_policy.c
+++ b/security/integrity/ima/ima_policy.c
@@ -1313,7 +1313,8 @@ static bool ima_validate_rule(struct ima_rule_entry *entry)
 				     IMA_GID | IMA_EGID |
 				     IMA_FGROUP | IMA_DIGSIG_REQUIRED |
 				     IMA_PERMIT_DIRECTIO | IMA_MODSIG_ALLOWED |
-				     IMA_CHECK_BLACKLIST | IMA_VALIDATE_ALGOS))
+				     IMA_CHECK_BLACKLIST | IMA_VALIDATE_ALGOS |
+				     IMA_SIGV3_REQUIRED))
 			return false;
 
 		break;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0080/2077] dt-bindings: net: bluetooth: qualcomm: Fix WCN6855 regulator names
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (78 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0079/2077] ima: Fix sigv3 signature handling for EVM_IMA_XATTR_DIGSIG Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0081/2077] x86/bug: Add printf() validation to HAVE_ARCH_BUG_FORMAT_ARGS WARNs Greg Kroah-Hartman
                   ` (917 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Abel Vesa,
	Bartosz Golaszewski, Dmitry Baryshkov, Konrad Dybcio,
	Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>

[ Upstream commit 63b35a29d7ad2cafb0076f8b002b30fb74df053a ]

Commit 5f4f954bba12 ("dt-bindings: bluetooth: bring the HW description
closer to reality for wcn6855") changed the vddrfa1p7-supply to 1p8
for whatever reason.

The schematics footprint for this chip definitely says 7 on the input
leg and the driver still expects 1p7. Bring it back.

Fixes: 5f4f954bba12 ("dt-bindings: bluetooth: bring the HW description closer to reality for wcn6855")
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Acked-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260225-topic-wcn6855_pmu_dtbdings-v3-1-576ec5c4e631@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../devicetree/bindings/net/bluetooth/qcom,wcn6855-bt.yaml | 7 ++-----
 1 file changed, 2 insertions(+), 5 deletions(-)

diff --git a/Documentation/devicetree/bindings/net/bluetooth/qcom,wcn6855-bt.yaml b/Documentation/devicetree/bindings/net/bluetooth/qcom,wcn6855-bt.yaml
index 45630067d3c8ed..0beda26ae8bb45 100644
--- a/Documentation/devicetree/bindings/net/bluetooth/qcom,wcn6855-bt.yaml
+++ b/Documentation/devicetree/bindings/net/bluetooth/qcom,wcn6855-bt.yaml
@@ -50,9 +50,6 @@ properties:
     description: VDD_RFA_1P7 supply regulator handle
     deprecated: true
 
-  vddrfa1p8-supply:
-    description: VDD_RFA_1P8 supply regulator handle
-
   vddrfacmn-supply:
     description: VDD_RFA_CMN supply regulator handle
 
@@ -68,7 +65,7 @@ required:
   - vddbtcmx-supply
   - vddrfa0p8-supply
   - vddrfa1p2-supply
-  - vddrfa1p8-supply
+  - vddrfa1p7-supply
   - vddrfacmn-supply
   - vddwlcx-supply
   - vddwlmx-supply
@@ -91,7 +88,7 @@ examples:
             vddbtcmx-supply = <&vreg_pmu_btcmx_0p8>;
             vddrfa0p8-supply = <&vreg_pmu_rfa_0p8>;
             vddrfa1p2-supply = <&vreg_pmu_rfa_1p2>;
-            vddrfa1p8-supply = <&vreg_pmu_rfa_1p7>;
+            vddrfa1p7-supply = <&vreg_pmu_rfa_1p7>;
             vddrfacmn-supply = <&vreg_pmu_rfa_cmn_0p8>;
             vddwlcx-supply = <&vreg_pmu_wlcx_0p8>;
             vddwlmx-supply = <&vreg_pmu_wlmx_0p8>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0081/2077] x86/bug: Add printf() validation to HAVE_ARCH_BUG_FORMAT_ARGS WARNs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (79 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0080/2077] dt-bindings: net: bluetooth: qualcomm: Fix WCN6855 regulator names Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0082/2077] arm64: dts: qcom: milos: Reduce rmtfs_mem size to 2.5MiB Greg Kroah-Hartman
                   ` (916 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sean Christopherson, Dave Hansen,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

[ Upstream commit 40c4b47f41b95dff743c841536cb64014e65ef0c ]

Add explicit printf() validation for x86-64's newfangled WARN
implementation, as most (all?) compilers fail to detect basic formatting
issues without the annotation.  E.g. even goofs like printing a u64 as a
string aren't detected:

  WARN_ONCE(1, "Bad message, %s", vcpu->arch.last_guest_tsc);

32-bit x86 doesn't support HAVE_ARCH_BUG_FORMAT_ARGS and uses generic
implementations that provide printf() validation. This means there's
now a big blind spot is code that is strictly x86-64. Inconveniently,
new features are also frequently x86-64-only.

Fix the blind 64-bit blind spot.

[ dhansen: changelog tweaks to flesh out the 64-bit-only details ]

Fixes: 5b472b6e5bd9 ("x86_64/bug: Implement __WARN_printf()")
Fixes: 11bb4944f014 ("x86/bug: Implement WARN_ONCE()")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Dave Hansen <dave.hansen@linux.intel.com>
Acked-by: Dave Hansen <dave.hansen@linux.intel.com>
Link: https://lore.kernel.org/all/adc1IrD8uqWdaOKv@yzhao56-desk.sh.intel.com
Link: https://patch.msgid.link/20260423145419.459988-2-seanjc@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/x86/include/asm/bug.h | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/arch/x86/include/asm/bug.h b/arch/x86/include/asm/bug.h
index 80c1696d8d5978..bf3c802654d18a 100644
--- a/arch/x86/include/asm/bug.h
+++ b/arch/x86/include/asm/bug.h
@@ -153,6 +153,7 @@ struct arch_va_list {
 	struct sysv_va_list args;
 };
 extern void *__warn_args(struct arch_va_list *args, struct pt_regs *regs);
+static __always_inline __printf(1, 2) void __WARN_validate_printf(const char *fmt, ...) { }
 #endif /* __ASSEMBLER__ */
 
 #define __WARN_bug_entry(flags, format) ({				\
@@ -172,6 +173,7 @@ extern void *__warn_args(struct arch_va_list *args, struct pt_regs *regs);
 #define __WARN_print_arg(flags, format, arg...)				\
 do {									\
 	int __flags = (flags) | BUGFLAG_WARNING | BUGFLAG_ARGS ;	\
+	__WARN_validate_printf(format, ## arg);				\
 	static_call_mod(WARN_trap)(__WARN_bug_entry(__flags, format), ## arg); \
 	asm (""); /* inhibit tail-call optimization */			\
 } while (0)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0082/2077] arm64: dts: qcom: milos: Reduce rmtfs_mem size to 2.5MiB
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (80 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0081/2077] x86/bug: Add printf() validation to HAVE_ARCH_BUG_FORMAT_ARGS WARNs Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0083/2077] arm64: dts: qcom: sdm845-oneplus: Drop address from framebuffer node Greg Kroah-Hartman
                   ` (915 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Luca Weiss, Konrad Dybcio,
	Alexander Koskovich, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexander Koskovich <akoskovich@pm.me>

[ Upstream commit 1f820571ca7c64d3fd5bd9bf653b571cb3350703 ]

The rmtfs_mem region is currently sized at 6MiB but the default for
milos downstream is 2.5MiB. This causes remoteproc crashes on devices
that expect the smaller size:

modem_ac.c:281:Access Control Error: Could not protect the region specified:Start:e1f00000 End:e2180000, PID:1

Reduce the default to 2.5MiB to match the QCOM downstream config, and
override the size for FP6.

Fixes: d9d59d105f98 ("arm64: dts: qcom: Add initial Milos dtsi")
Reviewed-by: Luca Weiss <luca.weiss@fairphone.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Alexander Koskovich <akoskovich@pm.me>
Link: https://lore.kernel.org/r/20260323-asteroids-v2-1-1a35fa9e178a@pm.me
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/milos-fairphone-fp6.dts | 5 +++++
 arch/arm64/boot/dts/qcom/milos.dtsi              | 2 +-
 2 files changed, 6 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/milos-fairphone-fp6.dts b/arch/arm64/boot/dts/qcom/milos-fairphone-fp6.dts
index c1899db46e7141..5dc7c950e60d65 100644
--- a/arch/arm64/boot/dts/qcom/milos-fairphone-fp6.dts
+++ b/arch/arm64/boot/dts/qcom/milos-fairphone-fp6.dts
@@ -786,6 +786,11 @@ &remoteproc_wpss {
 	status = "okay";
 };
 
+&rmtfs_mem {
+	/* Increase the size from 2.5 MiB to 6 MiB */
+	reg = <0x0 0xe1f00000 0x0 0x600000>;
+};
+
 &sdhc_2 {
 	cd-gpios = <&tlmm 65 GPIO_ACTIVE_HIGH>;
 
diff --git a/arch/arm64/boot/dts/qcom/milos.dtsi b/arch/arm64/boot/dts/qcom/milos.dtsi
index a6e463f3885dc6..c4e373872e8c6f 100644
--- a/arch/arm64/boot/dts/qcom/milos.dtsi
+++ b/arch/arm64/boot/dts/qcom/milos.dtsi
@@ -642,7 +642,7 @@ cpusys_vm_mem: cpusys-vm-region@e0600000 {
 
 		rmtfs_mem: rmtfs@e1f00000 {
 			compatible = "qcom,rmtfs-mem";
-			reg = <0x0 0xe1f00000 0x0 0x600000>;
+			reg = <0x0 0xe1f00000 0x0 0x280000>;
 			no-map;
 
 			qcom,client-id = <1>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0083/2077] arm64: dts: qcom: sdm845-oneplus: Drop address from framebuffer node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (81 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0082/2077] arm64: dts: qcom: milos: Reduce rmtfs_mem size to 2.5MiB Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0084/2077] arm64: dts: qcom: glymur: Fix USB simple_bus_reg warning Greg Kroah-Hartman
                   ` (914 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, David Heidelberg,
	Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Heidelberg <david@ixit.cz>

[ Upstream commit b379bb1470d864659ae9522b72f241a15255dce6 ]

This node has no 'reg' property, so it shouldn't have a unit address
(after '@') either

Fixes: b0d5c96e860c ("arm64: dts: qcom: sdm845-oneplus: Add framebuffer")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: David Heidelberg <david@ixit.cz>
Link: https://lore.kernel.org/r/20260402-beryllium-fb-v4-2-46170004da28@ixit.cz
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sdm845-oneplus-common.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/sdm845-oneplus-common.dtsi b/arch/arm64/boot/dts/qcom/sdm845-oneplus-common.dtsi
index 6b7378cf4d493a..b0b9baf01ec292 100644
--- a/arch/arm64/boot/dts/qcom/sdm845-oneplus-common.dtsi
+++ b/arch/arm64/boot/dts/qcom/sdm845-oneplus-common.dtsi
@@ -72,7 +72,7 @@ chosen {
 
 		stdout-path = "serial0:115200n8";
 
-		framebuffer: framebuffer@9d400000 {
+		framebuffer: framebuffer {
 			compatible = "simple-framebuffer";
 			memory-region = <&cont_splash_mem>;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0084/2077] arm64: dts: qcom: glymur: Fix USB simple_bus_reg warning
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (82 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0083/2077] arm64: dts: qcom: sdm845-oneplus: Drop address from framebuffer node Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0085/2077] arm64: dts: qcom: glymur: Fix cache and SRAM simple_bus_reg warnings Greg Kroah-Hartman
                   ` (913 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov,
	Krzysztof Kozlowski, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit cd66b6d256f94e40922941e14d7f9390d35d072b ]

Correct the unit address of USB node in Qualcomm Glymur SoC DTSI to fix
W=1 DTC warning:

  glymur.dtsi:4027.23-4093.5: Warning (simple_bus_reg): /soc@0/usb@a2f8800: simple-bus unit address format error, expected "a200000"

Fixes: 4eee57dd4df9 ("arm64: dts: qcom: glymur: Add USB related nodes")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260405-dts-qcom-w-1-fixes-v2-1-1f2c7b74a93f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/glymur.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/glymur.dtsi b/arch/arm64/boot/dts/qcom/glymur.dtsi
index 82436984485d41..ab2a6b577bc9d0 100644
--- a/arch/arm64/boot/dts/qcom/glymur.dtsi
+++ b/arch/arm64/boot/dts/qcom/glymur.dtsi
@@ -4016,7 +4016,7 @@ usb_2_dwc3_ss: endpoint {
 			};
 		};
 
-		usb_hs: usb@a2f8800 {
+		usb_hs: usb@a200000 {
 			compatible = "qcom,glymur-dwc3", "qcom,snps-dwc3";
 			reg = <0x0 0x0a200000 0x0 0xfc100>;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0085/2077] arm64: dts: qcom: glymur: Fix cache and SRAM simple_bus_reg warnings
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (83 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0084/2077] arm64: dts: qcom: glymur: Fix USB simple_bus_reg warning Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:55 ` [PATCH 7.1 0086/2077] arm64: dts: qcom: ipq5424: Fix USB " Greg Kroah-Hartman
                   ` (912 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov,
	Krzysztof Kozlowski, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit 46eccc1034c3740b07b58c125190bbb99247c9de ]

Correct the unit address of cache controller and SRAM nodes in Qualcomm
Glymur SoC DTSI to fix W=1 DTC warnings:

  glymur.dtsi:5876.36-5908.5: Warning (simple_bus_reg): /soc@0/system-cache-controller@20400000: simple-bus unit address format error, expected "21800000"
  glymur.dtsi:5917.23-5934.5: Warning (simple_bus_reg): /soc@0/sram@81e08000: simple-bus unit address format error, expected "81e08600"

Fixes: 41b6e8db400c ("arm64: dts: qcom: Introduce Glymur base dtsi")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260405-dts-qcom-w-1-fixes-v2-2-1f2c7b74a93f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/glymur.dtsi | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/arm64/boot/dts/qcom/glymur.dtsi b/arch/arm64/boot/dts/qcom/glymur.dtsi
index ab2a6b577bc9d0..7283d45ca259a8 100644
--- a/arch/arm64/boot/dts/qcom/glymur.dtsi
+++ b/arch/arm64/boot/dts/qcom/glymur.dtsi
@@ -5865,7 +5865,7 @@ oobm_ss_noc: interconnect@1f300000 {
 			#interconnect-cells = <2>;
 		};
 
-		system-cache-controller@20400000 {
+		system-cache-controller@21800000 {
 			compatible = "qcom,glymur-llcc";
 			reg = <0x0 0x21800000 0x0 0x100000>,
 			      <0x0 0x21a00000 0x0 0x100000>,
@@ -5906,7 +5906,7 @@ nsp_noc: interconnect@320c0000 {
 			#interconnect-cells = <2>;
 		};
 
-		imem: sram@81e08000 {
+		imem: sram@81e08600 {
 			compatible = "mmio-sram";
 			reg = <0x0 0x81e08600 0x0 0x300>;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0086/2077] arm64: dts: qcom: ipq5424: Fix USB simple_bus_reg warnings
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (84 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0085/2077] arm64: dts: qcom: glymur: Fix cache and SRAM simple_bus_reg warnings Greg Kroah-Hartman
@ 2026-07-21 14:55 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0087/2077] arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning Greg Kroah-Hartman
                   ` (911 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:55 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov,
	Krzysztof Kozlowski, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit 864fde494aa1dd26c68254661f2ce973e9f03832 ]

Correct the unit address of USB nodes in Qualcomm IPQ5424 SoC DTSI to
fix W=1 DTC warnings:

  ipq5424.dtsi:642.22-693.5: Warning (simple_bus_reg): /soc@0/usb2@1e00000: simple-bus unit address format error, expected "1ef8800"
  ipq5424.dtsi:733.22-786.5: Warning (simple_bus_reg): /soc@0/usb3@8a00000: simple-bus unit address format error, expected "8af8800"

Fixes: 113d52bdc820 ("arm64: dts: qcom: ipq5424: Add USB controller and phy nodes")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260405-dts-qcom-w-1-fixes-v2-3-1f2c7b74a93f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/ipq5424.dtsi | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/arm64/boot/dts/qcom/ipq5424.dtsi b/arch/arm64/boot/dts/qcom/ipq5424.dtsi
index f20cda42909497..876bf6a8b8ff0c 100644
--- a/arch/arm64/boot/dts/qcom/ipq5424.dtsi
+++ b/arch/arm64/boot/dts/qcom/ipq5424.dtsi
@@ -639,7 +639,7 @@ qusb_phy_1: phy@71000 {
 			status = "disabled";
 		};
 
-		usb2: usb2@1e00000 {
+		usb2: usb2@1ef8800 {
 			compatible = "qcom,ipq5424-dwc3", "qcom,dwc3";
 			reg = <0 0x01ef8800 0 0x400>;
 			#address-cells = <2>;
@@ -730,7 +730,7 @@ ssphy_0: phy@7d000 {
 			status = "disabled";
 		};
 
-		usb3: usb3@8a00000 {
+		usb3: usb3@8af8800 {
 			compatible = "qcom,ipq5424-dwc3", "qcom,dwc3";
 			reg = <0 0x08af8800 0 0x400>;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0087/2077] arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (85 preceding siblings ...)
  2026-07-21 14:55 ` [PATCH 7.1 0086/2077] arm64: dts: qcom: ipq5424: Fix USB " Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0088/2077] arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning Greg Kroah-Hartman
                   ` (910 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov,
	Krzysztof Kozlowski, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit f319a5fc998e29699d325af0e461721b3768eeec ]

Correct the unit address of phy node in Qualcomm SC8180x SoC DTSI to fix
W=1 DTC warning:

  sc8180x.dtsi:2650.31-2695.5: Warning (simple_bus_reg): /soc@0/phy@88ee000: simple-bus unit address format error, expected "88ed000"

Fixes: 35e3a9c1afce ("arm64: dts: qcom: sc8180x: switch USB+DP QMP PHYs to new bindings")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260405-dts-qcom-w-1-fixes-v2-4-1f2c7b74a93f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sc8180x.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/sc8180x.dtsi b/arch/arm64/boot/dts/qcom/sc8180x.dtsi
index f45deb188c6c09..e87e82fa73e9c3 100644
--- a/arch/arm64/boot/dts/qcom/sc8180x.dtsi
+++ b/arch/arm64/boot/dts/qcom/sc8180x.dtsi
@@ -2647,7 +2647,7 @@ usb_mp_qmpphy1: phy@88ec000 {
 			status = "disabled";
 		};
 
-		usb_sec_qmpphy: phy@88ee000 {
+		usb_sec_qmpphy: phy@88ed000 {
 			compatible = "qcom,sc8180x-qmp-usb3-dp-phy";
 			reg = <0 0x088ed000 0 0x3000>;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0088/2077] arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (86 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0087/2077] arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0089/2077] arm64: dts: qcom: fix temp-alarm probe failure for PMH0104 on Glymur Greg Kroah-Hartman
                   ` (909 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, David Heidelberg,
	Krzysztof Kozlowski, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit f20a82aacd7f381084391a8d1f0f58defa91974c ]

Add necessary properties for ports node in SDM845 DB845c Navigation
mezzanine overlay to fix W=1 DTC warning:

sdm845-db845c-navigation-mezzanine.dtso:19.10-24.5: Warning (unit_address_vs_reg): /fragment@0/__overlay__/ports/port@0: node has a unit name, but no reg or ranges property

Fixes: 30df676a31b7 ("arm64: dts: qcom: sdm845-db845c-navigation-mezzanine: Convert mezzanine riser to dtso")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260405-dts-qcom-w-1-fixes-v2-5-1f2c7b74a93f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../boot/dts/qcom/sdm845-db845c-navigation-mezzanine.dtso    | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/arch/arm64/boot/dts/qcom/sdm845-db845c-navigation-mezzanine.dtso b/arch/arm64/boot/dts/qcom/sdm845-db845c-navigation-mezzanine.dtso
index dbe1911d8e470e..678a17c805f74c 100644
--- a/arch/arm64/boot/dts/qcom/sdm845-db845c-navigation-mezzanine.dtso
+++ b/arch/arm64/boot/dts/qcom/sdm845-db845c-navigation-mezzanine.dtso
@@ -16,7 +16,12 @@
 	status = "okay";
 
 	ports {
+		#address-cells = <1>;
+		#size-cells = <0>;
+
 		port@0 {
+			reg = <0>;
+
 			csiphy0_ep: endpoint {
 				data-lanes = <0 1 2 3>;
 				remote-endpoint = <&ov8856_ep>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0089/2077] arm64: dts: qcom: fix temp-alarm probe failure for PMH0104 on Glymur
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (87 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0088/2077] arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0090/2077] arm64: dts: qcom: sdm845-shift-axolotl: Correct touchscreen sleep state Greg Kroah-Hartman
                   ` (908 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kamal Wadhwa, Dmitry Baryshkov,
	Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kamal Wadhwa <kamal.wadhwa@oss.qualcomm.com>

[ Upstream commit e8fae9152e100b4bb30d38b25bc9c81623e8e91e ]

The temp-alarm driver probe is failing for the pmh0104 PMICs on glymur.

[    3.999713] spmi-temp-alarm c426000.spmi:pmic@8:temp-alarm@a00: error -ENODEV: failed to register sensor
[    4.015066] spmi-temp-alarm c426000.spmi:pmic@9:temp-alarm@a00: error -ENODEV: failed to register sensor
[    4.033908] spmi-temp-alarm c437000.spmi:pmic@b:temp-alarm@a00: error -ENODEV: failed to register sensor

This happens because thermal zone associated with the temp alarm was
defined under the thermal zones parent node which had a typo (used `_` in
place of `-`). Correct the typo to fix probe failure.

Fixes: 41b6e8db400c ("arm64: dts: qcom: Introduce Glymur base dtsi")
Signed-off-by: Kamal Wadhwa <kamal.wadhwa@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260406-glymur-pmh0104-temp-alarm-fix-v1-1-4441b7b01f85@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/pmh0104-glymur.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/pmh0104-glymur.dtsi b/arch/arm64/boot/dts/qcom/pmh0104-glymur.dtsi
index 7a1e5f355c1759..6b4747025b9f85 100644
--- a/arch/arm64/boot/dts/qcom/pmh0104-glymur.dtsi
+++ b/arch/arm64/boot/dts/qcom/pmh0104-glymur.dtsi
@@ -7,7 +7,7 @@
 #include <dt-bindings/spmi/spmi.h>
 
 /{
-	thermal_zones {
+	thermal-zones {
 		pmh0104_i0_thermal: pmh0104-i0-thermal {
 			polling-delay-passive = <100>;
 			thermal-sensors = <&pmh0104_i_e0_temp_alarm>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0090/2077] arm64: dts: qcom: sdm845-shift-axolotl: Correct touchscreen sleep state
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (88 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0089/2077] arm64: dts: qcom: fix temp-alarm probe failure for PMH0104 on Glymur Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0091/2077] hfsplus: Remove the duplicate attr inode dirty marking action Greg Kroah-Hartman
                   ` (907 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Heidelberg, Dmitry Baryshkov,
	Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Heidelberg <david@ixit.cz>

[ Upstream commit 0689aa70fe28ba13eb1d8b10d50e08157ade9670 ]

There is no suspend state in the mainline kernel, use the sleep state
intended for this purpose.

Fixes: 45882459159d ("arm64: dts: qcom: sdm845: add device tree for SHIFT6mq")
Signed-off-by: David Heidelberg <david@ixit.cz>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260403-oneplus-nfc-v3-3-fbdce57d63c1@ixit.cz
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sdm845-shift-axolotl.dts | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/sdm845-shift-axolotl.dts b/arch/arm64/boot/dts/qcom/sdm845-shift-axolotl.dts
index 7d81198bc499ca..b5fc93f0315fd0 100644
--- a/arch/arm64/boot/dts/qcom/sdm845-shift-axolotl.dts
+++ b/arch/arm64/boot/dts/qcom/sdm845-shift-axolotl.dts
@@ -448,7 +448,7 @@ touchscreen@38 {
 
 		pinctrl-0 = <&ts_int_active &ts_reset_active>;
 		pinctrl-1 = <&ts_int_suspend &ts_reset_suspend>;
-		pinctrl-names = "default", "suspend";
+		pinctrl-names = "default", "sleep";
 
 		touchscreen-size-x = <1080>;
 		touchscreen-size-y = <2160>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0091/2077] hfsplus: Remove the duplicate attr inode dirty marking action
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (89 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0090/2077] arm64: dts: qcom: sdm845-shift-axolotl: Correct touchscreen sleep state Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0092/2077] hfsplus: Add a sanity check for btree node size Greg Kroah-Hartman
                   ` (906 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+bc70a12e438dadba4fb4,
	Edward Adam Davis, Viacheslav Dubeyko, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Edward Adam Davis <eadavis@qq.com>

[ Upstream commit 7a41fd2b32e5908f19a68732008d581c167279dd ]

Syzbot reported a null-ptr-deref in [1].
If the attributes file is not loaded during system mount, a trigger
occurs [1] when setxattr is executed in userspace.

Remove the first mark attr inode dirty operation.

[1]
KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
Call Trace:
 hfsplus_setxattr+0x124/0x340 fs/hfsplus/xattr.c:555
 hfsplus_trusted_setxattr+0x40/0x60 fs/hfsplus/xattr_trusted.c:30
 __vfs_setxattr+0x43c/0x480 fs/xattr.c:218
 __vfs_setxattr_noperm+0x12d/0x660 fs/xattr.c:252
 vfs_setxattr+0x163/0x360 fs/xattr.c:339
 do_setxattr fs/xattr.c:654 [inline]

Reported-by: syzbot+bc70a12e438dadba4fb4@syzkaller.appspotmail.com
Fixes: ee8422d00b7c ("hfsplus: fix potential Allocation File corruption after fsync")
Closes: https://syzkaller.appspot.com/bug?extid=bc70a12e438dadba4fb4
Signed-off-by: Edward Adam Davis <eadavis@qq.com>
Reviewed-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Link: https://lore.kernel.org/r/tencent_A8D47429765566CC3C8B378496D036664A09@qq.com
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/hfsplus/xattr.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/fs/hfsplus/xattr.c b/fs/hfsplus/xattr.c
index 452a1f9becb2d1..21a1c196c71f2e 100644
--- a/fs/hfsplus/xattr.c
+++ b/fs/hfsplus/xattr.c
@@ -317,7 +317,6 @@ static int hfsplus_create_attributes_file(struct super_block *sb)
 		next_node++;
 	}
 
-	hfsplus_mark_inode_dirty(HFSPLUS_ATTR_TREE_I(sb), HFSPLUS_I_ATTR_DIRTY);
 	hfsplus_mark_inode_dirty(attr_file, HFSPLUS_I_ATTR_DIRTY);
 
 	sbi->attr_tree = hfs_btree_open(sb, HFSPLUS_ATTR_CNID);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0092/2077] hfsplus: Add a sanity check for btree node size
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (90 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0091/2077] hfsplus: Remove the duplicate attr inode dirty marking action Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0093/2077] wifi: cfg80211: fix grammar in MLO group key error message Greg Kroah-Hartman
                   ` (905 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+217eb327242d08197efb,
	Edward Adam Davis, Viacheslav Dubeyko, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Edward Adam Davis <eadavis@qq.com>

[ Upstream commit 3f95e2661574ff13f099dd13456751933c280628 ]

Syzbot reported an uninit-value bug in [1] with a corrupted HFS+ image,
during the file system mounting process, specifically while loading the
catalog, a corrupted node_size value of 1 caused the rec_off argument
passed to hfs_bnode_read_u16() (within hfs_bnode_find()) to be excessively
large. Consequently, the function failed to return a valid value to
initialize the off variable, triggering the bug [1].

Every node starts from BTree node descriptor: struct hfs_bnode_desc.
So, the size of node cannot be lesser than that. However, technical
specification declares that: "The node size (which is expressed in bytes)
must be power of two, from 512 through 32,768, inclusive." Add a check
for btree node size base on technical specification.

[1]
BUG: KMSAN: uninit-value in hfsplus_bnode_find+0x141c/0x1600 fs/hfsplus/bnode.c:584
 hfsplus_bnode_find+0x141c/0x1600 fs/hfsplus/bnode.c:584
 hfsplus_btree_open+0x169a/0x1e40 fs/hfsplus/btree.c:382
 hfsplus_fill_super+0x111f/0x2770 fs/hfsplus/super.c:553
 get_tree_bdev_flags+0x6e6/0x920 fs/super.c:1694
 get_tree_bdev+0x38/0x50 fs/super.c:1717
 hfsplus_get_tree+0x35/0x40 fs/hfsplus/super.c:709
 vfs_get_tree+0xb3/0x5d0 fs/super.c:1754
 fc_mount fs/namespace.c:1193 [inline]

Fixes: 8ad2c6a36ac4 ("hfsplus: validate b-tree node 0 bitmap at mount time")
Reported-by: syzbot+217eb327242d08197efb@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=217eb327242d08197efb
Signed-off-by: Edward Adam Davis <eadavis@qq.com>
Reviewed-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Link: https://lore.kernel.org/r/tencent_5ED373437A697F83A4A446B771577626CD05@qq.com
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/hfsplus/btree.c         | 2 ++
 include/linux/hfs_common.h | 1 +
 2 files changed, 3 insertions(+)

diff --git a/fs/hfsplus/btree.c b/fs/hfsplus/btree.c
index 761c74ccd6531e..394542a47e6009 100644
--- a/fs/hfsplus/btree.c
+++ b/fs/hfsplus/btree.c
@@ -365,6 +365,8 @@ struct hfs_btree *hfs_btree_open(struct super_block *sb, u32 id)
 	}
 
 	size = tree->node_size;
+	if (size < HFSPLUS_NODE_MINSZ || size > HFSPLUS_NODE_MXSZ)
+		goto fail_page;
 	if (!is_power_of_2(size))
 		goto fail_page;
 	if (!tree->node_count)
diff --git a/include/linux/hfs_common.h b/include/linux/hfs_common.h
index 07dfc39630ab91..45fb4c9ff9f5ee 100644
--- a/include/linux/hfs_common.h
+++ b/include/linux/hfs_common.h
@@ -513,6 +513,7 @@ struct hfs_btree_header_rec {
 /* HFS+ BTree misc info */
 #define HFSPLUS_TREE_HEAD			0
 #define HFSPLUS_NODE_MXSZ			32768
+#define HFSPLUS_NODE_MINSZ			512
 #define HFSPLUS_ATTR_TREE_NODE_SIZE		8192
 #define HFSPLUS_BTREE_HDR_NODE_RECS_COUNT	3
 #define HFSPLUS_BTREE_HDR_MAP_REC_INDEX		2	/* Map (bitmap) record in Header node */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0093/2077] wifi: cfg80211: fix grammar in MLO group key error message
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (91 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0092/2077] hfsplus: Add a sanity check for btree node size Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0094/2077] arm64: tegra: Fix Tegra234 MGBE PTP clock Greg Kroah-Hartman
                   ` (904 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Louis Kotze, Johannes Berg,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Louis Kotze <loukot@gmail.com>

[ Upstream commit 9dcc1af3bbf5441f71a1e51b8d81bdf38a249607 ]

The error message emitted by nl80211_validate_key_link_id() when a group
key install on an MLO wdev is missing the link ID reads "link ID must
for MLO group key", which is missing the words "be set". This makes the
error harder to grep and parse in userspace logs, and is reported
verbatim by wpa_supplicant via its nl80211 extack relay, e.g.:

  wpa_supplicant: nl80211: kernel reports: link ID must for MLO group key

The sibling error strings in the same helper already use grammatical
phrasing ("link ID not allowed for pairwise key", "invalid link ID for
MLO group key", "link ID not allowed for non-MLO group key"). Fix this
one to match.

No functional change.

Fixes: e7a7b84e3317 ("wifi: cfg80211: Add link_id parameter to various key operations for MLO")
Signed-off-by: Louis Kotze <loukot@gmail.com>
Link: https://patch.msgid.link/20260414122728.92234-1-loukot@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/wireless/nl80211.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index 76c537a6e8b52d..21e43e08b5d795 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -5112,7 +5112,7 @@ static int nl80211_validate_key_link_id(struct genl_info *info,
 	if (wdev->valid_links) {
 		if (link_id == -1) {
 			GENL_SET_ERR_MSG(info,
-					 "link ID must for MLO group key");
+					 "link ID must be set for MLO group key");
 			return -EINVAL;
 		}
 		if (!(wdev->valid_links & BIT(link_id))) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0094/2077] arm64: tegra: Fix Tegra234 MGBE PTP clock
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (92 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0093/2077] wifi: cfg80211: fix grammar in MLO group key error message Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0095/2077] dt-bindings: pinctrl: nvidia,tegra234: Add missing required block Greg Kroah-Hartman
                   ` (903 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jon Hunter, Krzysztof Kozlowski,
	Thierry Reding, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jon Hunter <jonathanh@nvidia.com>

[ Upstream commit 8f0cc929a4bad534c5a860a53d88912cf16d9c9c ]

The Tegra MGBE PTP clock is incorrectly named as 'ptp-ref' and not
'ptp_ref' and this causing the initialisation of the PTP clock to fail.
The device-tree binding doc for the device and the Tegra MGBE driver
have been updated to use the correct name and so update the device-tree
for Tegra234 as well.

Fixes: 610cdf3186bc ("arm64: tegra: Add MGBE nodes on Tegra234")
Signed-off-by: Jon Hunter <jonathanh@nvidia.com>
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/nvidia/tegra234.dtsi | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/arch/arm64/boot/dts/nvidia/tegra234.dtsi b/arch/arm64/boot/dts/nvidia/tegra234.dtsi
index 04a95b6658caaa..18220cdac9f9bb 100644
--- a/arch/arm64/boot/dts/nvidia/tegra234.dtsi
+++ b/arch/arm64/boot/dts/nvidia/tegra234.dtsi
@@ -3605,7 +3605,7 @@ ethernet@6800000 {
 				 <&bpmp TEGRA234_CLK_MGBE0_RX_PCS_M>,
 				 <&bpmp TEGRA234_CLK_MGBE0_RX_PCS>,
 				 <&bpmp TEGRA234_CLK_MGBE0_TX_PCS>;
-			clock-names = "mgbe", "mac", "mac-divider", "ptp-ref", "rx-input-m",
+			clock-names = "mgbe", "mac", "mac-divider", "ptp_ref", "rx-input-m",
 				      "rx-input", "tx", "eee-pcs", "rx-pcs-input", "rx-pcs-m",
 				      "rx-pcs", "tx-pcs";
 			resets = <&bpmp TEGRA234_RESET_MGBE0_MAC>,
@@ -3647,7 +3647,7 @@ ethernet@6900000 {
 				 <&bpmp TEGRA234_CLK_MGBE1_RX_PCS_M>,
 				 <&bpmp TEGRA234_CLK_MGBE1_RX_PCS>,
 				 <&bpmp TEGRA234_CLK_MGBE1_TX_PCS>;
-			clock-names = "mgbe", "mac", "mac-divider", "ptp-ref", "rx-input-m",
+			clock-names = "mgbe", "mac", "mac-divider", "ptp_ref", "rx-input-m",
 				      "rx-input", "tx", "eee-pcs", "rx-pcs-input", "rx-pcs-m",
 				      "rx-pcs", "tx-pcs";
 			resets = <&bpmp TEGRA234_RESET_MGBE1_MAC>,
@@ -3689,7 +3689,7 @@ ethernet@6a00000 {
 				 <&bpmp TEGRA234_CLK_MGBE2_RX_PCS_M>,
 				 <&bpmp TEGRA234_CLK_MGBE2_RX_PCS>,
 				 <&bpmp TEGRA234_CLK_MGBE2_TX_PCS>;
-			clock-names = "mgbe", "mac", "mac-divider", "ptp-ref", "rx-input-m",
+			clock-names = "mgbe", "mac", "mac-divider", "ptp_ref", "rx-input-m",
 				      "rx-input", "tx", "eee-pcs", "rx-pcs-input", "rx-pcs-m",
 				      "rx-pcs", "tx-pcs";
 			resets = <&bpmp TEGRA234_RESET_MGBE2_MAC>,
@@ -3731,7 +3731,7 @@ ethernet@6b00000 {
 				 <&bpmp TEGRA234_CLK_MGBE3_RX_PCS_M>,
 				 <&bpmp TEGRA234_CLK_MGBE3_RX_PCS>,
 				 <&bpmp TEGRA234_CLK_MGBE3_TX_PCS>;
-			clock-names = "mgbe", "mac", "mac-divider", "ptp-ref", "rx-input-m",
+			clock-names = "mgbe", "mac", "mac-divider", "ptp_ref", "rx-input-m",
 				      "rx-input", "tx", "eee-pcs", "rx-pcs-input", "rx-pcs-m",
 				      "rx-pcs", "tx-pcs";
 			resets = <&bpmp TEGRA234_RESET_MGBE3_MAC>,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0095/2077] dt-bindings: pinctrl: nvidia,tegra234: Add missing required block
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (93 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0094/2077] arm64: tegra: Fix Tegra234 MGBE PTP clock Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0096/2077] pinctrl: pinconf-generic: fix properties bitmap leak in parse_fw_cfg() Greg Kroah-Hartman
                   ` (902 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski,
	Rob Herring (Arm), Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit 61b5deb5a968f7a82124f9b2591a6a151ed7273a ]

Binding should require 'reg' property, because address space cannot be
missing in the hardware and is already needed by the Linux drivers.
Require also 'compatible' by convention, although it is not strictly
necessary.

Fixes: 857982138b79 ("dt-bindings: pinctrl: Document Tegra234 pin controllers")
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Acked-by: Rob Herring (Arm) <robh@kernel.org>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../bindings/pinctrl/nvidia,tegra234-pinmux-aon.yaml          | 4 ++++
 .../devicetree/bindings/pinctrl/nvidia,tegra234-pinmux.yaml   | 4 ++++
 2 files changed, 8 insertions(+)

diff --git a/Documentation/devicetree/bindings/pinctrl/nvidia,tegra234-pinmux-aon.yaml b/Documentation/devicetree/bindings/pinctrl/nvidia,tegra234-pinmux-aon.yaml
index db8224dfba2c1b..56fb9cf763ef7f 100644
--- a/Documentation/devicetree/bindings/pinctrl/nvidia,tegra234-pinmux-aon.yaml
+++ b/Documentation/devicetree/bindings/pinctrl/nvidia,tegra234-pinmux-aon.yaml
@@ -58,6 +58,10 @@ patternProperties:
                     drive_soc_gpio27_pee6, drive_ao_retention_n_pee2,
                     drive_vcomp_alert_pee1, drive_hdmi_cec_pgg0 ]
 
+required:
+  - compatible
+  - reg
+
 unevaluatedProperties: false
 
 examples:
diff --git a/Documentation/devicetree/bindings/pinctrl/nvidia,tegra234-pinmux.yaml b/Documentation/devicetree/bindings/pinctrl/nvidia,tegra234-pinmux.yaml
index f5a3a881dec4f0..bd305a34eee2b2 100644
--- a/Documentation/devicetree/bindings/pinctrl/nvidia,tegra234-pinmux.yaml
+++ b/Documentation/devicetree/bindings/pinctrl/nvidia,tegra234-pinmux.yaml
@@ -115,6 +115,10 @@ patternProperties:
                     drive_sdmmc1_dat2_pj4, drive_sdmmc1_dat1_pj3,
                     drive_sdmmc1_dat0_pj2 ]
 
+required:
+  - compatible
+  - reg
+
 unevaluatedProperties: false
 
 examples:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0096/2077] pinctrl: pinconf-generic: fix properties bitmap leak in parse_fw_cfg()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (94 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0095/2077] dt-bindings: pinctrl: nvidia,tegra234: Add missing required block Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0097/2077] drm/amdkfd: Validate CRIU-restored IDs before idr_alloc Greg Kroah-Hartman
                   ` (901 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit 352f5621b8c472bf328f452446bce85c00837223 ]

In parse_fw_cfg(), if fwnode_property_match_property_string() fails with
-ENOENT, the code returns directly and leaks the bitmap.

Use __free(bitmap) for automatic cleanup to fix the leak.

Fixes: 9c105255108b ("pinctrl: pinconf-generic: perform basic checks on pincfg properties")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/pinconf-generic.c | 5 +----
 1 file changed, 1 insertion(+), 4 deletions(-)

diff --git a/drivers/pinctrl/pinconf-generic.c b/drivers/pinctrl/pinconf-generic.c
index 64ed2830978871..07714912162809 100644
--- a/drivers/pinctrl/pinconf-generic.c
+++ b/drivers/pinctrl/pinconf-generic.c
@@ -225,10 +225,9 @@ static int parse_fw_cfg(struct fwnode_handle *fwnode,
 			unsigned int count, unsigned long *cfg,
 			unsigned int *ncfg)
 {
-	unsigned long *properties;
 	int i, test;
 
-	properties = bitmap_zalloc(count, GFP_KERNEL);
+	unsigned long *properties __free(bitmap) = bitmap_zalloc(count, GFP_KERNEL);
 
 	for (i = 0; i < count; i++) {
 		u32 val;
@@ -263,7 +262,6 @@ static int parse_fw_cfg(struct fwnode_handle *fwnode,
 			if (ret) {
 				pr_err("%pfw: conflicting setting detected for %s\n",
 				       fwnode, par->property);
-				bitmap_free(properties);
 				return -EINVAL;
 			}
 		}
@@ -295,7 +293,6 @@ static int parse_fw_cfg(struct fwnode_handle *fwnode,
 		pr_err("%pfw: cannot have multiple drive configurations\n",
 		       fwnode);
 
-	bitmap_free(properties);
 	return 0;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0097/2077] drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (95 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0096/2077] pinctrl: pinconf-generic: fix properties bitmap leak in parse_fw_cfg() Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0098/2077] driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() Greg Kroah-Hartman
                   ` (900 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Felix Kuehling,
	David Yat Sin, Rajneesh Bhardwaj, Srinivasan Shanmugam,
	Alex Deucher, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>

[ Upstream commit 85043dd49c2f51a37b22618168e3ae59ab92f0d6 ]

The KFD CRIU restore flow restores previously saved object IDs from
userspace.

For event restore:

  kfd_criu_restore_event()
      -> create_signal_event() / create_other_event()
          -> allocate_event_notification_slot()
              -> idr_alloc(..., *restore_id, *restore_id + 1, ...)

For BO restore:

  criu_restore_memory_of_gpu()
      -> idr_alloc(..., bo_priv->idr_handle, ...)

In both cases, the restored ID comes from userspace-provided CRIU data.

idr_alloc() expects the ID range values to fit within signed int
limits. If a restored ID is larger than INT_MAX, it can trigger a WARN
in the IDR layer.

A kernel WARN is undesirable because it prints a warning trace and may
cause a panic or reboot on systems with panic_on_warn enabled.

Smatch reported these paths as allowing unchecked userspace values to
reach idr_alloc().

Add INT_MAX validation before using restored IDs in:

- kfd_criu_restore_event()
- criu_restore_memory_of_gpu()

If the restored ID is invalid, return -EINVAL.

This prevents invalid restore data from reaching the IDR layer and
avoids WARN-triggering paths, while keeping valid restore behavior
unchanged.

Fixes: 40e8a766a761 ("drm/amdkfd: CRIU checkpoint and restore events")
Reported-by: Dan Carpenter <error27@gmail.com>
Cc: Felix Kuehling <Felix.Kuehling@amd.com>
Cc: David Yat Sin <david.yatsin@amd.com>
Cc: Rajneesh Bhardwaj <rajneesh.bhardwaj@amd.com>
Signed-off-by: Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>
Reviewed-by: David Yat Sin <david.yatsin@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/amd/amdkfd/kfd_chardev.c | 3 +++
 drivers/gpu/drm/amd/amdkfd/kfd_events.c  | 5 +++++
 2 files changed, 8 insertions(+)

diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
index 8785f7810157e1..78068b2c968567 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
@@ -2362,6 +2362,9 @@ static int criu_restore_memory_of_gpu(struct kfd_process_device *pdd,
 	const bool criu_resume = true;
 	u64 offset;
 
+	if (bo_priv->idr_handle > INT_MAX)
+		return -EINVAL;
+
 	if (bo_bucket->alloc_flags & KFD_IOC_ALLOC_MEM_FLAGS_DOORBELL) {
 		if (bo_bucket->size !=
 				kfd_doorbell_process_slice(pdd->dev->kfd))
diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_events.c b/drivers/gpu/drm/amd/amdkfd/kfd_events.c
index e65b323aafbf37..81900b49d9d5b5 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_events.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_events.c
@@ -483,6 +483,11 @@ int kfd_criu_restore_event(struct file *devkfd,
 	}
 	*priv_data_offset += sizeof(*ev_priv);
 
+	if (ev_priv->event_id > INT_MAX) {
+		ret = -EINVAL;
+		goto exit;
+	}
+
 	if (ev_priv->user_handle) {
 		ret = kfd_kmap_event_page(p, ev_priv->user_handle);
 		if (ret)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0098/2077] driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (96 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0097/2077] drm/amdkfd: Validate CRIU-restored IDs before idr_alloc Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0099/2077] gpu: nova-core: use correct fwsignature for GA100 Greg Kroah-Hartman
                   ` (899 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki (Intel),
	Saravana Kannan, Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Danilo Krummrich <dakr@kernel.org>

[ Upstream commit e9506871a8ea304cde48ff4a57226df2aadddae3 ]

dev_has_sync_state() reads dev->driver twice without holding
device_lock() -- once for the NULL check and once to dereference
->sync_state. Some callers only hold device_links_write_lock, which
doesn't prevent a concurrent unbind from clearing dev->driver via
device_unbind_cleanup().

Fix it by reading dev->driver exactly once with READ_ONCE(), pairing
with the WRITE_ONCE() in device_set_driver().

Link: https://lore.kernel.org/driver-core/DHW8QPU1VU1F.3P6PH69HLFBYC@kernel.org/
Fixes: ac338acf514e ("driver core: Add dev_has_sync_state()")
Reviewed-by: Rafael J. Wysocki (Intel) <rafael@kernel.org>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Reviewed-by: Saravana Kannan <saravanak@kernel.org>
Link: https://patch.msgid.link/20260418162221.1121873-1-dakr@kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/device.h | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/include/linux/device.h b/include/linux/device.h
index 9c8fde6a3d866b..79a4a6549be8e3 100644
--- a/include/linux/device.h
+++ b/include/linux/device.h
@@ -1065,9 +1065,12 @@ static inline void device_lock_assert(struct device *dev)
 
 static inline bool dev_has_sync_state(struct device *dev)
 {
+	struct device_driver *drv;
+
 	if (!dev)
 		return false;
-	if (dev->driver && dev->driver->sync_state)
+	drv = READ_ONCE(dev->driver);
+	if (drv && drv->sync_state)
 		return true;
 	if (dev->bus && dev->bus->sync_state)
 		return true;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0099/2077] gpu: nova-core: use correct fwsignature for GA100
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (97 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0098/2077] driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0100/2077] wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers Greg Kroah-Hartman
                   ` (898 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Timur Tabi, Eliot Courtney, Gary Guo,
	Alexandre Courbot, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Timur Tabi <ttabi@nvidia.com>

[ Upstream commit c1dca0cb0e761568c448a6007855fe5879ad4d37 ]

Although GA100 uses the same GSP-RM firmware as Turing, it has a different
signature specifically for it.

Fixes: 121ea04cd9f2 ("gpu: nova-core: add support for Turing/GA100 fwsignature")
Signed-off-by: Timur Tabi <ttabi@nvidia.com>
Reviewed-by: Eliot Courtney <ecourtney@nvidia.com>
Reviewed-by: Gary Guo <gary@garyguo.net>
Link: https://patch.msgid.link/20260417191359.1307434-2-ttabi@nvidia.com
Signed-off-by: Alexandre Courbot <acourbot@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/nova-core/firmware/gsp.rs | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/drivers/gpu/nova-core/firmware/gsp.rs b/drivers/gpu/nova-core/firmware/gsp.rs
index 2fcc255c3bc81b..c423191b21f018 100644
--- a/drivers/gpu/nova-core/firmware/gsp.rs
+++ b/drivers/gpu/nova-core/firmware/gsp.rs
@@ -138,8 +138,7 @@ impl GspFirmware {
                             ".fwsignature_tu11x"
                         }
                         Architecture::Turing => ".fwsignature_tu10x",
-                        // GA100 uses the same firmware as Turing
-                        Architecture::Ampere if chipset == Chipset::GA100 => ".fwsignature_tu10x",
+                        Architecture::Ampere if chipset == Chipset::GA100 => ".fwsignature_ga100",
                         Architecture::Ampere => ".fwsignature_ga10x",
                         Architecture::Ada => ".fwsignature_ad10x",
                     };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0100/2077] wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (98 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0099/2077] gpu: nova-core: use correct fwsignature for GA100 Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0101/2077] wifi: rtw88: " Greg Kroah-Hartman
                   ` (897 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christos Longros, Ping-Ke Shih,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christos Longros <chris.longros@gmail.com>

[ Upstream commit 7068c379cf9aa8afe4dce4d9d82390187aa9c4d0 ]

rtw89 stores an ieee80211_hw pointer via pci_set_drvdata() at probe
time, but io_error_detected() and io_resume() retrieve it as a
net_device pointer.  This causes netif_device_detach/attach to
operate on an ieee80211_hw struct, reading and writing at wrong
offsets.  The adjacent io_slot_reset() already does it correctly.

Use ieee80211_stop_queues/wake_queues instead, consistent with
every other queue stop/start path in the driver.

Tested on RTL8852CE by calling the handlers from a test module
before and after the fix.

Fixes: 16e3d93c6183 ("wifi: rtw89: pci: add PCI Express error handling")
Signed-off-by: Christos Longros <chris.longros@gmail.com>
Acked-by: Ping-Ke Shih <pkshih@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260329073857.113081-1-chris.longros@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/realtek/rtw89/pci.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/net/wireless/realtek/rtw89/pci.c b/drivers/net/wireless/realtek/rtw89/pci.c
index 43c61b3dc969f2..64554eb35a72cf 100644
--- a/drivers/net/wireless/realtek/rtw89/pci.c
+++ b/drivers/net/wireless/realtek/rtw89/pci.c
@@ -4624,9 +4624,9 @@ EXPORT_SYMBOL(rtw89_pm_ops);
 static pci_ers_result_t rtw89_pci_io_error_detected(struct pci_dev *pdev,
 						    pci_channel_state_t state)
 {
-	struct net_device *netdev = pci_get_drvdata(pdev);
+	struct ieee80211_hw *hw = pci_get_drvdata(pdev);
 
-	netif_device_detach(netdev);
+	ieee80211_stop_queues(hw);
 
 	return PCI_ERS_RESULT_NEED_RESET;
 }
@@ -4643,12 +4643,12 @@ static pci_ers_result_t rtw89_pci_io_slot_reset(struct pci_dev *pdev)
 
 static void rtw89_pci_io_resume(struct pci_dev *pdev)
 {
-	struct net_device *netdev = pci_get_drvdata(pdev);
+	struct ieee80211_hw *hw = pci_get_drvdata(pdev);
 
 	/* ack any pending wake events, disable PME */
 	pci_enable_wake(pdev, PCI_D0, 0);
 
-	netif_device_attach(netdev);
+	ieee80211_wake_queues(hw);
 }
 
 const struct pci_error_handlers rtw89_pci_err_handler = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0101/2077] wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (99 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0100/2077] wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0102/2077] wifi: rtw89: Correct data type for scan index to avoid infinite loop Greg Kroah-Hartman
                   ` (896 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Chin-Yen Lee, Ping-Ke Shih,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chin-Yen Lee <timlee@realtek.com>

[ Upstream commit 706183dbef4a79d120d4e928f693bea50df496f8 ]

rtw88 stores an ieee80211_hw pointer via pci_set_drvdata() at probe
time, but io_error_detected() and io_resume() retrieve it as a
net_device pointer.  This causes netif_device_detach/attach to
operate on an ieee80211_hw struct, reading and writing at wrong
offsets.

Use ieee80211_stop_queues/wake_queues instead, consistent with
every other queue stop/start path in the driver.

Fixes: cdb82c80b934 ("wifi: rtw88: pci: add PCI Express error handling")
Signed-off-by: Chin-Yen Lee <timlee@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260413065926.17027-1-pkshih@realtek.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/realtek/rtw88/pci.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/net/wireless/realtek/rtw88/pci.c b/drivers/net/wireless/realtek/rtw88/pci.c
index bba370ad510cf7..c56beacbb1b03f 100644
--- a/drivers/net/wireless/realtek/rtw88/pci.c
+++ b/drivers/net/wireless/realtek/rtw88/pci.c
@@ -1711,9 +1711,9 @@ static void rtw_pci_napi_deinit(struct rtw_dev *rtwdev)
 static pci_ers_result_t rtw_pci_io_err_detected(struct pci_dev *pdev,
 						pci_channel_state_t state)
 {
-	struct net_device *netdev = pci_get_drvdata(pdev);
+	struct ieee80211_hw *hw = pci_get_drvdata(pdev);
 
-	netif_device_detach(netdev);
+	ieee80211_stop_queues(hw);
 
 	return PCI_ERS_RESULT_NEED_RESET;
 }
@@ -1730,12 +1730,12 @@ static pci_ers_result_t rtw_pci_io_slot_reset(struct pci_dev *pdev)
 
 static void rtw_pci_io_resume(struct pci_dev *pdev)
 {
-	struct net_device *netdev = pci_get_drvdata(pdev);
+	struct ieee80211_hw *hw = pci_get_drvdata(pdev);
 
 	/* ack any pending wake events, disable PME */
 	pci_enable_wake(pdev, PCI_D0, 0);
 
-	netif_device_attach(netdev);
+	ieee80211_wake_queues(hw);
 }
 
 const struct pci_error_handlers rtw_pci_err_handler = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0102/2077] wifi: rtw89: Correct data type for scan index to avoid infinite loop
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (100 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0101/2077] wifi: rtw88: " Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0103/2077] wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer Greg Kroah-Hartman
                   ` (895 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Shin-Yi Lin, Ping-Ke Shih,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shin-Yi Lin <isaiah@realtek.com>

[ Upstream commit 08fdcb529df6df3562dd2b0035f88dd5be8b3c68 ]

A kernel soft lockup was observed during Wi-Fi scanning on the 6GHz band.
The CPU becomes stuck in rtw89_hw_scan_add_chan_ax for over 20 seconds,
leading to a system panic.

RIP points to 0f b6 c3 (movzbl %bl, %eax), which zero-extends
the low 8 bits of RBX into RAX.
RBX (the counter i) has reached a huge value: 0x137466a1.

  watchdog: BUG: soft lockup - CPU#2 stuck for 26s! [kworker/u16:4:6124]
  Workqueue: events_unbound cfg80211_wiphy_work [cfg80211]
  RIP: 0010:rtw89_hw_scan_add_chan_ax+0xb3/0x6e0 [rtw89_core]
  Code: a0 48 89 45 a8 44 89 6d 9c 44 89 75 98 eb 29 66 66 2e 0f 1f
  84 00 00 00 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 66 90 83 c3 01
  <0f> b6 c3 41 3b 44 24 74 0f 83 0b 02 00 00 0f b6 c3 48 8d 14 80 49
  RSP: 0018:ffffcb48cbaa39f8 EFLAGS: 00000202
  RAX: 0000000000000005 RBX: 00000000137466a1 RCX: 0000000000000000
  RDX: ffff89ffc9d851a8 RSI: 0000000000004f0d RDI: 0000000096af0130
  RBP: ffffcb48cbaa3a60 R08: 0000000000000000 R09: ffff8a00b7502080
  R10: ffff8a00b75ff600 R11: 0000000000000000 R12: ffff89ffc7553870
  R13: ffff8a00b7ac8f19 R14: ffff8a00b75020d8 R15: ffff89ffc3d54d80
  FS:  0000000000000000(0000) GS:ffff8a014f962000(0000)
  knlGS:0000000000000000
  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
  CR2: 00007558d7f9f4c4 CR3: 0000000178040001 CR4: 00000000001706f0
  Call Trace:
   <TASK>
   rtw89_hw_scan_prep_chan_list_ax+0x8a/0x400 [rtw89_core]
   rtw89_hw_scan_start+0x546/0x8a0 [rtw89_core]
   ? rtw89_fw_h2c_default_cmac_tbl+0x13c/0x1f0 [rtw89_core]
   rtw89_ops_hw_scan+0xae/0x120 [rtw89_core]
   drv_hw_scan+0xbb/0x180 [mac80211]
   __ieee80211_start_scan+0x2fc/0x750 [mac80211]
   ieee80211_request_scan+0xe/0x20 [mac80211]
   ieee80211_scan+0x123/0x190 [mac80211]
   rdev_scan+0x40/0x110 [cfg80211]
   cfg80211_scan_6ghz+0x5a1/0xa30 [cfg80211]

By objdump with source:

	for (i = 0; i < req->n_6ghz_params; i++) {
   5fbc0:	83 c3 01             	add    $0x1,%ebx --> i++
   5fbc3:	0f b6 c3             	movzbl %bl,%eax  --> get counter
   fbc6:	41 3b 44 24 74       	cmp    0x74(%r12),%eax

   * RBX: 00000000137466a1 -> %bl = a1 -> EAX = 000000a1 (161)

Fixes: c6aa9a9c4725 ("wifi: rtw89: add RNR support for 6 GHz scan")
Signed-off-by: Shin-Yi Lin <isaiah@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260420034051.17666-7-pkshih@realtek.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/realtek/rtw89/fw.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wireless/realtek/rtw89/fw.c b/drivers/net/wireless/realtek/rtw89/fw.c
index 17704f054727a9..089c9071b58f5b 100644
--- a/drivers/net/wireless/realtek/rtw89/fw.c
+++ b/drivers/net/wireless/realtek/rtw89/fw.c
@@ -8318,7 +8318,7 @@ static int rtw89_update_6ghz_rnr_chan_ax(struct rtw89_dev *rtwdev,
 	struct sk_buff *skb;
 	bool found;
 	int ret = 0;
-	u8 i;
+	u32 i;
 
 	if (!req->n_6ghz_params)
 		return 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0103/2077] wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (101 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0102/2077] wifi: rtw89: Correct data type for scan index to avoid infinite loop Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0104/2077] wifi: rtw89: add bounds check on firmware mac_id in link lookup Greg Kroah-Hartman
                   ` (894 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tristan Madani, Ping-Ke Shih,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tristan Madani <tristan@talencesecurity.com>

[ Upstream commit 6e76e9ed273dfb4b3333a5ebbb94958cc5752ab6 ]

In rtw_pci_rx_napi(), new_len is computed as the sum of pkt_len (14-bit
descriptor field, max 16383) and pkt_offset (drv_info_sz + shift, both
firmware-controlled). The result can exceed RTK_PCI_RX_BUF_SIZE (11478),
causing an out-of-bounds read from the pre-allocated DMA buffer when
skb_put_data copies new_len bytes. The USB transport already validates
this (rtw_usb_rx_data_put checks against RTW_USB_MAX_RECVBUF_SZ); the
PCIe path does not.

Add a check that new_len does not exceed the DMA buffer size.

Fixes: e3037485c68e ("rtw88: new Realtek 802.11ac driver")
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260421111434.3389674-1-tristmd@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/realtek/rtw88/pci.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/net/wireless/realtek/rtw88/pci.c b/drivers/net/wireless/realtek/rtw88/pci.c
index c56beacbb1b03f..c2bf44e880cf2d 100644
--- a/drivers/net/wireless/realtek/rtw88/pci.c
+++ b/drivers/net/wireless/realtek/rtw88/pci.c
@@ -1077,6 +1077,11 @@ static u32 rtw_pci_rx_napi(struct rtw_dev *rtwdev, struct rtw_pci *rtwpci,
 		 * discard the frame if none available
 		 */
 		new_len = pkt_stat.pkt_len + pkt_offset;
+		if (unlikely(new_len > RTK_PCI_RX_BUF_SIZE)) {
+			rtw_dbg(rtwdev, RTW_DBG_RX,
+				"oversized RX packet: %u\n", new_len);
+			goto next_rp;
+		}
 		new = dev_alloc_skb(new_len);
 		if (WARN_ONCE(!new, "rx routine starvation\n"))
 			goto next_rp;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0104/2077] wifi: rtw89: add bounds check on firmware mac_id in link lookup
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (102 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0103/2077] wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0105/2077] kconfig: fix potential NULL pointer dereference in conf_askvalue Greg Kroah-Hartman
                   ` (893 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tristan Madani, Ping-Ke Shih,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tristan Madani <tristan@talencesecurity.com>

[ Upstream commit 6d88244bb129755acca696f9227200f4a2d106a6 ]

The mac_id field in RX descriptors is 8 bits wide (0-255), but
assoc_link_on_macid[] has only RTW89_MAX_MAC_ID_NUM (128) entries.
While the driver currently assigns mac_id values below 128, the
descriptor value comes from firmware and is not validated before use
as an array index. Add a defensive bounds check in
rtw89_assoc_link_rcu_dereference() to guard against out-of-range
firmware values.

Fixes: 144c6cd24b35 ("wifi: rtw89: 8922a: configure AP_LINK_PS if FW supports")
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260421111442.3395411-1-tristmd@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/realtek/rtw89/core.h | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/net/wireless/realtek/rtw89/core.h b/drivers/net/wireless/realtek/rtw89/core.h
index fd29dbbb120d2f..05adf20a65be1e 100644
--- a/drivers/net/wireless/realtek/rtw89/core.h
+++ b/drivers/net/wireless/realtek/rtw89/core.h
@@ -6492,6 +6492,9 @@ static inline void rtw89_assoc_link_clr(struct rtw89_sta_link *rtwsta_link)
 static inline struct rtw89_sta_link *
 rtw89_assoc_link_rcu_dereference(struct rtw89_dev *rtwdev, u8 macid)
 {
+	if (unlikely(macid >= RTW89_MAX_MAC_ID_NUM))
+		return NULL;
+
 	return rcu_dereference(rtwdev->assoc_link_on_macid[macid]);
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0105/2077] kconfig: fix potential NULL pointer dereference in conf_askvalue
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (103 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0104/2077] wifi: rtw89: add bounds check on firmware mac_id in link lookup Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0106/2077] soc: xilinx: Fix race condition in event registration Greg Kroah-Hartman
                   ` (892 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Xingjing Deng, Nathan Chancellor,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xingjing Deng <micro6947@gmail.com>

[ Upstream commit b9d21c32dca2167a614e66c9e27999b9e1c33d55 ]

In conf_askvalue(), the 'def' argument (retrieved via sym_get_string_value)
can be NULL. While current call sites ensure that 'def' is valid,
calling printf("%s\n", def) is technically undefined behavior and could
lead to a segmentation fault on certain libc implementations if the
function were called with a NULL pointer in the future.

Improve the robustness of conf_askvalue() by providing an empty string
as a fallback.

Additionally, remove the redundant re-initialization of the 'line'
buffer inside the !sym_is_changeable(sym) block, as it is already
properly initialized at the function entry.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Xingjing Deng <micro6947@gmail.com>
Reviewed-by: Nathan Chancellor <nathan@kernel.org>
Link: https://patch.msgid.link/20260306021709.27068-1-micro6947@gmail.com
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 scripts/kconfig/conf.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

diff --git a/scripts/kconfig/conf.c b/scripts/kconfig/conf.c
index a7b44cd8ae1408..c368bec5ab6016 100644
--- a/scripts/kconfig/conf.c
+++ b/scripts/kconfig/conf.c
@@ -297,9 +297,7 @@ static int conf_askvalue(struct symbol *sym, const char *def)
 	line[1] = 0;
 
 	if (!sym_is_changeable(sym)) {
-		printf("%s\n", def);
-		line[0] = '\n';
-		line[1] = 0;
+		printf("%s\n", def ?: "");
 		return 0;
 	}
 
@@ -307,7 +305,7 @@ static int conf_askvalue(struct symbol *sym, const char *def)
 	case oldconfig:
 	case syncconfig:
 		if (sym_has_value(sym)) {
-			printf("%s\n", def);
+			printf("%s\n", def ?: "");
 			return 0;
 		}
 		/* fall through */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0106/2077] soc: xilinx: Fix race condition in event registration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (104 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0105/2077] kconfig: fix potential NULL pointer dereference in conf_askvalue Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0107/2077] soc: xilinx: Shutdown and free rx mailbox channel Greg Kroah-Hartman
                   ` (891 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Prasanna Kumar T S M, Michal Simek,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Prasanna Kumar T S M <ptsm@linux.microsoft.com>

[ Upstream commit fb445935338405110baca8f541a2df3b4cb8d712 ]

The zynqmp_power driver registers handlers for suspend and subsystem
restart events using register_event(). However, the work structures
(zynqmp_pm_init_suspend_work and zynqmp_pm_init_restart_work) used by
these handlers were allocated and initialized after the registration
call.

This created a race window where, if the firmware triggered an event
immediately after registration but before allocation, the callback
(suspend_event_callback or subsystem_restart_event_callback) would
dereference a NULL pointer in work_pending(), leading to a crash.

Fix this by allocating and initializing the work structures before
registering the events.

Fixes: fcf544ac6439 ("soc: xilinx: Add cb event for subsystem restart")
Signed-off-by: Prasanna Kumar T S M <ptsm@linux.microsoft.com>
Signed-off-by: Michal Simek <michal.simek@amd.com>
Link: https://lore.kernel.org/r/20260320060306.1540928-1-ptsm@linux.microsoft.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/soc/xilinx/zynqmp_power.c | 43 ++++++++++++-------------------
 1 file changed, 17 insertions(+), 26 deletions(-)

diff --git a/drivers/soc/xilinx/zynqmp_power.c b/drivers/soc/xilinx/zynqmp_power.c
index 9085db1b480aa3..9dd938bd01d840 100644
--- a/drivers/soc/xilinx/zynqmp_power.c
+++ b/drivers/soc/xilinx/zynqmp_power.c
@@ -303,18 +303,18 @@ static int zynqmp_pm_probe(struct platform_device *pdev)
 	 * is not available to use) or -ENODEV(Xilinx Event Manager not compiled),
 	 * then use ipi-mailbox or interrupt method.
 	 */
+	zynqmp_pm_init_suspend_work = devm_kzalloc(&pdev->dev,
+						   sizeof(struct zynqmp_pm_work_struct),
+						   GFP_KERNEL);
+	if (!zynqmp_pm_init_suspend_work)
+		return -ENOMEM;
+
+	INIT_WORK(&zynqmp_pm_init_suspend_work->callback_work,
+		  zynqmp_pm_init_suspend_work_fn);
+
 	ret = register_event(&pdev->dev, PM_INIT_SUSPEND_CB, 0, 0, false,
 			     suspend_event_callback);
 	if (!ret) {
-		zynqmp_pm_init_suspend_work = devm_kzalloc(&pdev->dev,
-							   sizeof(struct zynqmp_pm_work_struct),
-							   GFP_KERNEL);
-		if (!zynqmp_pm_init_suspend_work)
-			return -ENOMEM;
-
-		INIT_WORK(&zynqmp_pm_init_suspend_work->callback_work,
-			  zynqmp_pm_init_suspend_work_fn);
-
 		ret = zynqmp_pm_get_family_info(&pm_family_code);
 		if (ret < 0)
 			return ret;
@@ -326,14 +326,6 @@ static int zynqmp_pm_probe(struct platform_device *pdev)
 		else
 			return -ENODEV;
 
-		ret = register_event(&pdev->dev, PM_NOTIFY_CB, node_id, EVENT_SUBSYSTEM_RESTART,
-				     false, subsystem_restart_event_callback);
-		if (ret) {
-			dev_err(&pdev->dev, "Failed to Register with Xilinx Event manager %d\n",
-				ret);
-			return ret;
-		}
-
 		zynqmp_pm_init_restart_work = devm_kzalloc(&pdev->dev,
 							   sizeof(struct zynqmp_pm_work_struct),
 							   GFP_KERNEL);
@@ -342,19 +334,18 @@ static int zynqmp_pm_probe(struct platform_device *pdev)
 
 		INIT_WORK(&zynqmp_pm_init_restart_work->callback_work,
 			  zynqmp_pm_subsystem_restart_work_fn);
+
+		ret = register_event(&pdev->dev, PM_NOTIFY_CB, node_id, EVENT_SUBSYSTEM_RESTART,
+				     false, subsystem_restart_event_callback);
+		if (ret) {
+			dev_err(&pdev->dev, "Failed to Register with Xilinx Event manager %d\n",
+				ret);
+			return ret;
+		}
 	} else if (ret != -EACCES && ret != -ENODEV) {
 		dev_err(&pdev->dev, "Failed to Register with Xilinx Event manager %d\n", ret);
 		return ret;
 	} else if (of_property_present(pdev->dev.of_node, "mboxes")) {
-		zynqmp_pm_init_suspend_work =
-			devm_kzalloc(&pdev->dev,
-				     sizeof(struct zynqmp_pm_work_struct),
-				     GFP_KERNEL);
-		if (!zynqmp_pm_init_suspend_work)
-			return -ENOMEM;
-
-		INIT_WORK(&zynqmp_pm_init_suspend_work->callback_work,
-			  zynqmp_pm_init_suspend_work_fn);
 		client = devm_kzalloc(&pdev->dev, sizeof(*client), GFP_KERNEL);
 		if (!client)
 			return -ENOMEM;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0107/2077] soc: xilinx: Shutdown and free rx mailbox channel
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (105 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0106/2077] soc: xilinx: Fix race condition in event registration Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0108/2077] pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask() Greg Kroah-Hartman
                   ` (890 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Prasanna Kumar T S M, Michal Simek,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Prasanna Kumar T S M <ptsm@linux.microsoft.com>

[ Upstream commit fdee7c66c0d7b6869c36b9f9a915abf29ab5b550 ]

A mbox rx channel is requested using mbox_request_channel_byname() in
probe. In remove callback, the rx mailbox channel is cleaned up when the
rx_chan is NULL due to incorrect condition check. The mailbox channel is
not shutdown and it can receive messages even after the device removal.
This leads to use after free. Also the channel resources are not freed.
Fix this by checking the rx_chan correctly.

Fixes: ffdbae28d9d1a ("drivers: soc: xilinx: Use mailbox IPI callback")
Signed-off-by: Prasanna Kumar T S M <ptsm@linux.microsoft.com>
Signed-off-by: Michal Simek <michal.simek@amd.com>
Link: https://lore.kernel.org/r/20260320060445.1541017-1-ptsm@linux.microsoft.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/soc/xilinx/zynqmp_power.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/soc/xilinx/zynqmp_power.c b/drivers/soc/xilinx/zynqmp_power.c
index 9dd938bd01d840..370e61ac47d88f 100644
--- a/drivers/soc/xilinx/zynqmp_power.c
+++ b/drivers/soc/xilinx/zynqmp_power.c
@@ -389,8 +389,10 @@ static void zynqmp_pm_remove(struct platform_device *pdev)
 {
 	sysfs_remove_file(&pdev->dev.kobj, &dev_attr_suspend_mode.attr);
 
-	if (!rx_chan)
+	if (rx_chan) {
 		mbox_free_channel(rx_chan);
+		rx_chan = NULL;
+	}
 }
 
 static const struct of_device_id pm_of_match[] = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0108/2077] pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (106 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0107/2077] soc: xilinx: Shutdown and free rx mailbox channel Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0109/2077] wifi: ath9k: fix OOB access from firmware tx status queue ID Greg Kroah-Hartman
                   ` (889 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hao Chang, Qingliang Li,
	Chen-Yu Tsai, Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chen-Yu Tsai <wenst@chromium.org>

[ Upstream commit 3ca99eed042620d12315e9272ed3ef260ca29877 ]

When support for multiple EINT base addresses was added in commit
3ef9f710efcb ("pinctrl: mediatek: Add EINT support for multiple
addresses"), mtk_eint_chip_write_mask() was changed to write interrupt
masks for all base addresses in one call. However the "base" parameter
was left around and now causes sparse warnings:

    mtk-eint.c:428:44: warning: incorrect type in argument 2 (different address spaces)
    mtk-eint.c:428:44:    expected void [noderef] __iomem *base
    mtk-eint.c:428:44:    got void [noderef] __iomem **base
    mtk-eint.c:436:44: warning: incorrect type in argument 2 (different address spaces)
    mtk-eint.c:436:44:    expected void [noderef] __iomem *base
    mtk-eint.c:436:44:    got void [noderef] __iomem **base

Since the "base" parameter is no longer needed, just drop it.

Fixes: 3ef9f710efcb ("pinctrl: mediatek: Add EINT support for multiple addresses")
Cc: Hao Chang <ot_chhao.chang@mediatek.com>
Cc: Qingliang Li <qingliang.li@mediatek.com>
Signed-off-by: Chen-Yu Tsai <wenst@chromium.org>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/mtk-eint.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/pinctrl/mediatek/mtk-eint.c b/drivers/pinctrl/mediatek/mtk-eint.c
index 2a3c04eedc5f38..47ac92ea98c2c5 100644
--- a/drivers/pinctrl/mediatek/mtk-eint.c
+++ b/drivers/pinctrl/mediatek/mtk-eint.c
@@ -246,7 +246,7 @@ static int mtk_eint_irq_set_wake(struct irq_data *d, unsigned int on)
 }
 
 static void mtk_eint_chip_write_mask(const struct mtk_eint *eint,
-				     void __iomem *base, unsigned int **buf)
+				     unsigned int **buf)
 {
 	int inst, port, port_num;
 	void __iomem *reg;
@@ -425,7 +425,7 @@ static void mtk_eint_irq_handler(struct irq_desc *desc)
 
 int mtk_eint_do_suspend(struct mtk_eint *eint)
 {
-	mtk_eint_chip_write_mask(eint, eint->base, eint->wake_mask);
+	mtk_eint_chip_write_mask(eint, eint->wake_mask);
 
 	return 0;
 }
@@ -433,7 +433,7 @@ EXPORT_SYMBOL_GPL(mtk_eint_do_suspend);
 
 int mtk_eint_do_resume(struct mtk_eint *eint)
 {
-	mtk_eint_chip_write_mask(eint, eint->base, eint->cur_mask);
+	mtk_eint_chip_write_mask(eint, eint->cur_mask);
 
 	return 0;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0109/2077] wifi: ath9k: fix OOB access from firmware tx status queue ID
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (107 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0108/2077] pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask() Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0110/2077] wifi: ath11k: cancel SSR work items during PCI shutdown Greg Kroah-Hartman
                   ` (888 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tristan Madani,
	Toke Høiland-Jørgensen, Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tristan Madani <tristan@talencesecurity.com>

[ Upstream commit 7ce2f118a2389e8f0a64068c6fe7cc7d40639be0 ]

ath_tx_edma_tasklet() accesses sc->tx.txq[ts.qid] where ts.qid is a
4-bit hardware field (0-15), but the txq array only has
ATH9K_NUM_TX_QUEUES (10) entries. A qid >= 10 causes an OOB array
access.

Add a bounds check on ts.qid before using it as an array index.

Fixes: fce041beb03f ("ath9k: unify edma and non-edma tx code, improve tx fifo handling")
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Acked-by: Toke Høiland-Jørgensen <toke@toke.dk>
Link: https://patch.msgid.link/20260415222343.1540564-1-tristmd@gmail.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/ath9k/xmit.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/net/wireless/ath/ath9k/xmit.c b/drivers/net/wireless/ath/ath9k/xmit.c
index 0ac9212e42f75e..957646b2df4ded 100644
--- a/drivers/net/wireless/ath/ath9k/xmit.c
+++ b/drivers/net/wireless/ath/ath9k/xmit.c
@@ -2746,6 +2746,11 @@ void ath_tx_edma_tasklet(struct ath_softc *sc)
 			continue;
 		}
 
+		if (ts.qid >= ATH9K_NUM_TX_QUEUES) {
+			ath_dbg(common, XMIT, "invalid qid %d\n", ts.qid);
+			continue;
+		}
+
 		txq = &sc->tx.txq[ts.qid];
 
 		ath_txq_lock(sc, txq);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0110/2077] wifi: ath11k: cancel SSR work items during PCI shutdown
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (108 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0109/2077] wifi: ath9k: fix OOB access from firmware tx status queue ID Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0111/2077] ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint Greg Kroah-Hartman
                   ` (887 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wei Zhang, Rameshkumar Sundaram,
	Baochen Qiang, Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wei Zhang <wei.zhang@oss.qualcomm.com>

[ Upstream commit 8c79aac429b583301f387374ff37c59be671df87 ]

A reboot can crash the kernel if it overlaps with WLAN firmware crash
recovery (SSR). The crash is a NULL pointer dereference in the MHI teardown
path while freeing DMA-backed MHI contexts.

Simplified trace:
  dma_free_attrs
  mhi_deinit_dev_ctxt [mhi]
  ath11k_pci_power_down [ath11k_pci]
  ath11k_pci_shutdown [ath11k_pci]
  device_shutdown
  kernel_restart

On the host side, SSR is driven by the MHI RDDM callback, which queues
reset_work to perform device recovery. reset_work power-cycles the device
by calling ath11k_hif_power_down() followed by ath11k_hif_power_up(). The
power-down phase deinitializes MHI and frees DMA resources.

Shutdown/reboot runs fully asynchronously with this RDDM-driven SSR
recovery flow. As a result, the shutdown path
(ath11k_pci_shutdown() -> ath11k_pci_power_down()) can race with the SSR
recovery sequence.

Fix this by canceling SSR-related work items during PCI shutdown, marking
the device as unregistering, and serializing the RDDM callback path that
checks and queues reset_work. This ensures that no new SSR recovery work
can be queued once teardown has started, and that any in-flight recovery
work is fully synchronized before device power-down, preventing MHI
teardown and DMA resource freeing from running more than once.

Note: This issue only affects PCI/MHI-based devices. AHB-based ath11k
devices do not queue reset_work in normal SSR flows.

Tested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04866.5-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1

Fixes: 13da397f884d ("ath11k: add support for device recovery for QCA6390/WCN6855")
Fixes: 5edbb148bc57 ("wifi: ath11k: Add firmware coredump collection support")
Signed-off-by: Wei Zhang <wei.zhang@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260404043050.3433754-1-wei.zhang@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/ath11k/mhi.c | 4 +++-
 drivers/net/wireless/ath/ath11k/pci.c | 8 ++++++++
 2 files changed, 11 insertions(+), 1 deletion(-)

diff --git a/drivers/net/wireless/ath/ath11k/mhi.c b/drivers/net/wireless/ath/ath11k/mhi.c
index f994233df2bb94..a6c9ff112c68f4 100644
--- a/drivers/net/wireless/ath/ath11k/mhi.c
+++ b/drivers/net/wireless/ath/ath11k/mhi.c
@@ -1,7 +1,7 @@
 // SPDX-License-Identifier: BSD-3-Clause-Clear
 /*
  * Copyright (c) 2020 The Linux Foundation. All rights reserved.
- * Copyright (c) 2021-2025 Qualcomm Innovation Center, Inc. All rights reserved.
+ * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries.
  */
 
 #include <linux/msi.h>
@@ -282,8 +282,10 @@ static void ath11k_mhi_op_status_cb(struct mhi_controller *mhi_cntrl,
 			break;
 		}
 
+		spin_lock_bh(&ab->base_lock);
 		if (!(test_bit(ATH11K_FLAG_UNREGISTERING, &ab->dev_flags)))
 			queue_work(ab->workqueue_aux, &ab->reset_work);
+		spin_unlock_bh(&ab->base_lock);
 
 		break;
 	default:
diff --git a/drivers/net/wireless/ath/ath11k/pci.c b/drivers/net/wireless/ath/ath11k/pci.c
index 7114eca8810dbf..35bb9e7a63a207 100644
--- a/drivers/net/wireless/ath/ath11k/pci.c
+++ b/drivers/net/wireless/ath/ath11k/pci.c
@@ -1210,6 +1210,14 @@ static void ath11k_pci_shutdown(struct pci_dev *pdev)
 	struct ath11k_pci *ab_pci = ath11k_pci_priv(ab);
 
 	ath11k_pci_set_irq_affinity_hint(ab_pci, NULL);
+
+	spin_lock_bh(&ab->base_lock);
+	set_bit(ATH11K_FLAG_UNREGISTERING, &ab->dev_flags);
+	spin_unlock_bh(&ab->base_lock);
+
+	cancel_work_sync(&ab->reset_work);
+	cancel_work_sync(&ab->dump_work);
+
 	ath11k_pci_power_down(ab, false);
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0111/2077] ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (109 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0110/2077] wifi: ath11k: cancel SSR work items during PCI shutdown Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0112/2077] ixgbe: fix unaligned u32 access in ixgbe_update_flash_X550() Greg Kroah-Hartman
                   ` (886 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jihed Chaibi, Kevin Hilman (TI),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jihed Chaibi <jihed.chaibi.dev@gmail.com>

[ Upstream commit 2bc564f46b00dc4f4331fc337277ff3f5fac8a4e ]

The cpu_endpoint in mcasp0 specifies the TLV320AIC3106 codec as the
bitclock and frame master, but the phandles point to the codec's port
node (codec_port) rather than its endpoint node (codec_endpoint).

audio-graph-card calls simple_util_parse_daifmt() with ep_codec set to
the endpoint node (codec_endpoint). The function resolves the
bitclock-master phandle and checks whether it equals ep_codec. Since
codec_port is the parent of codec_endpoint, not the endpoint itself, the
comparison always evaluates to false. This causes the mcasp0 CPU side to
be silently configured as bitclock and frame master instead of the codec,
which is the opposite of the intended configuration.

Fix by pointing bitclock-master and frame-master to codec_endpoint.

Fixes: e5f89dbdebc5 ("ARM: dts: am335x-sl50: use audio-graph-card for sound")
Signed-off-by: Jihed Chaibi <jihed.chaibi.dev@gmail.com>
Link: https://patch.msgid.link/20260325223411.123666-1-jihed.chaibi.dev@gmail.com
Signed-off-by: Kevin Hilman (TI) <khilman@baylibre.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm/boot/dts/ti/omap/am335x-sl50.dts | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/arm/boot/dts/ti/omap/am335x-sl50.dts b/arch/arm/boot/dts/ti/omap/am335x-sl50.dts
index 1dc4e344efd63e..c5259eb7d21c7e 100644
--- a/arch/arm/boot/dts/ti/omap/am335x-sl50.dts
+++ b/arch/arm/boot/dts/ti/omap/am335x-sl50.dts
@@ -558,8 +558,8 @@ cpu_endpoint: endpoint {
 			remote-endpoint = <&codec_endpoint>;
 
 			dai-format = "dsp_b";
-			bitclock-master = <&codec_port>;
-			frame-master = <&codec_port>;
+			bitclock-master = <&codec_endpoint>;
+			frame-master = <&codec_endpoint>;
 			bitclock-inversion;
 			clocks = <&audio_mclk>;
 		};
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0112/2077] ixgbe: fix unaligned u32 access in ixgbe_update_flash_X550()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (110 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0111/2077] ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0113/2077] Documentation/rv: Replace stale website link Greg Kroah-Hartman
                   ` (885 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Aleksandr Loktionov,
	Jedrzej Jagielski, Paul Menzel, Rinitha S, Jacob Keller,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aleksandr Loktionov <aleksandr.loktionov@intel.com>

[ Upstream commit eae23ec14a9c83b6af9bd616f3b86163688e2688 ]

ixgbe_host_interface_command() treats its buffer as a u32 array. The
local buffer we pass in was a union of byte-sized fields, which gives
it 1-byte alignment on the stack. On strict-align architectures this
can cause unaligned 32-bit accesses.

Add a u32 member to union ixgbe_hic_hdr2 so the object is 4-byte
aligned, and pass the u32 member when calling
ixgbe_host_interface_command().

No functional change on x86; prevents unaligned accesses on
architectures that enforce natural alignment.

Fixes: 49425dfc7451 ("ixgbe: Add support for x550em_a 10G MAC type")
Signed-off-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Reviewed-by: Jedrzej Jagielski <jedrzej.jagielski@intel.com>
Reviewed-by: Paul Menzel <pmenzel@molgen.mpg.de>
Fixes: 6a14ee0cfb19 ("ixgbe: Add X550 support function pointers")
Tested-by: Rinitha S <sx.rinitha@intel.com>
Signed-off-by: Jacob Keller <jacob.e.keller@intel.com>
Link: https://patch.msgid.link/20260430-jk-iwl-net-next-2026-04-30-v1-9-6f27ae1cd073@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/intel/ixgbe/ixgbe_type.h | 1 +
 drivers/net/ethernet/intel/ixgbe/ixgbe_x550.c | 2 +-
 2 files changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/intel/ixgbe/ixgbe_type.h b/drivers/net/ethernet/intel/ixgbe/ixgbe_type.h
index 61f2ef67defdde..eb5bf3b6bbb522 100644
--- a/drivers/net/ethernet/intel/ixgbe/ixgbe_type.h
+++ b/drivers/net/ethernet/intel/ixgbe/ixgbe_type.h
@@ -2798,6 +2798,7 @@ struct ixgbe_hic_hdr2_rsp {
 };
 
 union ixgbe_hic_hdr2 {
+	u32 buf[1];
 	struct ixgbe_hic_hdr2_req req;
 	struct ixgbe_hic_hdr2_rsp rsp;
 };
diff --git a/drivers/net/ethernet/intel/ixgbe/ixgbe_x550.c b/drivers/net/ethernet/intel/ixgbe/ixgbe_x550.c
index 76d2fa3ef51825..4a0ccbf448a2ad 100644
--- a/drivers/net/ethernet/intel/ixgbe/ixgbe_x550.c
+++ b/drivers/net/ethernet/intel/ixgbe/ixgbe_x550.c
@@ -1228,7 +1228,7 @@ static int ixgbe_update_flash_X550(struct ixgbe_hw *hw)
 	buffer.req.buf_lenl = FW_SHADOW_RAM_DUMP_LEN;
 	buffer.req.checksum = FW_DEFAULT_CHECKSUM;
 
-	status = ixgbe_host_interface_command(hw, &buffer, sizeof(buffer),
+	status = ixgbe_host_interface_command(hw, buffer.buf, sizeof(buffer),
 					      IXGBE_HI_COMMAND_TIMEOUT, false);
 	return status;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0113/2077] Documentation/rv: Replace stale website link
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (111 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0112/2077] ixgbe: fix unaligned u32 access in ixgbe_update_flash_X550() Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0114/2077] watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH Greg Kroah-Hartman
                   ` (884 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Gabriele Monaco, Matteo Martelli,
	Randy Dunlap, Jonathan Corbet, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Gabriele Monaco <gmonaco@redhat.com>

[ Upstream commit 49cbd359e4a7501e9d6694c072031d9ae6b2d1a5 ]

The sched monitor page was linking to Daniel's website which is now
down. The main purpose of the link was to point to a source for the
models from the original author and that can be found also in his
published paper.

Replace the link with a reference to Daniel's "A thread synchronization
model for the PREEMPT_RT Linux kernel" which can be found online and
includes the models definitions as well as the work behind them (not the
original patches but since they're based on a 5.0 kernel and are mostly
included upstream, there's little value in keeping them in the docs).

Fixes: 03abeaa63c08 ("Documentation/rv: Add docs for the sched monitors")
Signed-off-by: Gabriele Monaco <gmonaco@redhat.com>
Acked-by: Matteo Martelli <matteo.martelli@codethink.co.uk>
Tested-by: Matteo Martelli <matteo.martelli@codethink.co.uk>
Tested-by: Randy Dunlap <rdunlap@infradead.org>
Acked-by: Randy Dunlap <rdunlap@infradead.org>
Signed-off-by: Jonathan Corbet <corbet@lwn.net>
Message-ID: <20260427131709.170505-2-gmonaco@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/trace/rv/monitor_sched.rst | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/Documentation/trace/rv/monitor_sched.rst b/Documentation/trace/rv/monitor_sched.rst
index 0b96d6e147c655..d3ba7edc202f6f 100644
--- a/Documentation/trace/rv/monitor_sched.rst
+++ b/Documentation/trace/rv/monitor_sched.rst
@@ -36,7 +36,7 @@ Specifications
 --------------
 
 The specifications included in sched are currently a work in progress, adapting the ones
-defined in by Daniel Bristot in [1].
+defined by Daniel Bristot in [1]_.
 
 Currently we included the following:
 
@@ -365,4 +365,7 @@ constraints when processing the events::
 References
 ----------
 
-[1] - https://bristot.me/linux-task-model
+.. [1] Daniel Bristot de Oliveira et al.:
+       `A thread synchronization model for the PREEMPT_RT Linux kernel
+       <https://www.iris.sssup.it/bitstream/11382/533630/1/Elsevier-JSA-2020.pdf>`_,
+       J. Syst. Archit., 2020.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0114/2077] watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (112 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0113/2077] Documentation/rv: Replace stale website link Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0115/2077] watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 Greg Kroah-Hartman
                   ` (883 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yingjie Gao, Guenter Roeck,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yingjie Gao <gaoyingjie@uniontech.com>

[ Upstream commit 4f675f036cd5e9cfbe6df5f24f8338158af96a4b ]

Commit 009637de1f65 ("watchdog: sp5100_tco: support Hygon FCH/SCH
(Server Controller Hub)") added Hygon vendor matching to the efch
layout selection, but newer Hygon 0x790b SMBus devices still need the
efch_mmio path.

The efch_mmio path enables EFCH_PM_DECODEEN_WDT_TMREN before probing the
watchdog MMIO block. If firmware leaves that bit clear and the driver
picks the legacy efch path instead, probe falls back to the alternate
window and fails with "Watchdog hardware is disabled".

Select efch_mmio for Hygon 0x790b devices with revision 0x51 or later,
matching the equivalent AMD behavior and allowing the watchdog to
initialize on those systems.

Fixes: 009637de1f65 ("watchdog: sp5100_tco: support Hygon FCH/SCH (Server Controller Hub)")
Signed-off-by: Yingjie Gao <gaoyingjie@uniontech.com>
Reviewed-by: Guenter Roeck <linux@roeck-us.net>
Link: https://lore.kernel.org/r/20260402071617.634563-2-gaoyingjie@uniontech.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/watchdog/sp5100_tco.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/watchdog/sp5100_tco.c b/drivers/watchdog/sp5100_tco.c
index 2bd3dc25cb0304..7e99c3b1f3676b 100644
--- a/drivers/watchdog/sp5100_tco.c
+++ b/drivers/watchdog/sp5100_tco.c
@@ -92,7 +92,8 @@ static enum tco_reg_layout tco_reg_layout(struct pci_dev *dev)
 	    dev->device == PCI_DEVICE_ID_ATI_SBX00_SMBUS &&
 	    dev->revision < 0x40) {
 		return sp5100;
-	} else if (dev->vendor == PCI_VENDOR_ID_AMD &&
+	} else if ((dev->vendor == PCI_VENDOR_ID_AMD ||
+		    dev->vendor == PCI_VENDOR_ID_HYGON) &&
 	    sp5100_tco_pci->device == PCI_DEVICE_ID_AMD_KERNCZ_SMBUS &&
 	    sp5100_tco_pci->revision >= AMD_ZEN_SMBUS_PCI_REV) {
 		return efch_mmio;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0115/2077] watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (113 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0114/2077] watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0116/2077] watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure Greg Kroah-Hartman
                   ` (882 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Andrei Simion, Balakrishnan Sambath,
	Alexandre Belloni, Guenter Roeck, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Balakrishnan Sambath <balakrishnan.s@microchip.com>

[ Upstream commit e8bc610b14a99d24b0916635102cc52ba41def9b ]

The driver hardcoded AT91_WDT_WDDIS (bit 15) in wdt_enabled and the
probe initial state readout. SAM9X60 and SAMA7G5 use bit 12
(AT91_SAM9X60_WDDIS), causing incorrect WDDIS detection.

Introduce a per-device wddis_mask field to select the correct WDDIS
bit based on the compatible string.

Fixes: 266da53c35fc ("watchdog: sama5d4: readout initial state")
Co-developed-by: Andrei Simion <andrei.simion@microchip.com>
Signed-off-by: Andrei Simion <andrei.simion@microchip.com>
Signed-off-by: Balakrishnan Sambath <balakrishnan.s@microchip.com>
Reviewed-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Link: https://lore.kernel.org/r/20260302113310.133989-2-balakrishnan.s@microchip.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/watchdog/sama5d4_wdt.c | 48 +++++++++++++++-------------------
 1 file changed, 21 insertions(+), 27 deletions(-)

diff --git a/drivers/watchdog/sama5d4_wdt.c b/drivers/watchdog/sama5d4_wdt.c
index 13e72918338a20..704b786cc2ec63 100644
--- a/drivers/watchdog/sama5d4_wdt.c
+++ b/drivers/watchdog/sama5d4_wdt.c
@@ -30,6 +30,7 @@ struct sama5d4_wdt {
 	void __iomem		*reg_base;
 	u32			mr;
 	u32			ir;
+	u32			wddis_mask;
 	unsigned long		last_ping;
 	bool			need_irq;
 	bool			sam9x60_support;
@@ -48,7 +49,10 @@ MODULE_PARM_DESC(nowayout,
 	"Watchdog cannot be stopped once started (default="
 	__MODULE_STRING(WATCHDOG_NOWAYOUT) ")");
 
-#define wdt_enabled (!(wdt->mr & AT91_WDT_WDDIS))
+static inline bool wdt_enabled(struct sama5d4_wdt *wdt)
+{
+	return !(wdt->mr & wdt->wddis_mask);
+}
 
 #define wdt_read(wdt, field) \
 	readl_relaxed((wdt)->reg_base + (field))
@@ -81,12 +85,9 @@ static int sama5d4_wdt_start(struct watchdog_device *wdd)
 {
 	struct sama5d4_wdt *wdt = watchdog_get_drvdata(wdd);
 
-	if (wdt->sam9x60_support) {
+	if (wdt->sam9x60_support)
 		writel_relaxed(wdt->ir, wdt->reg_base + AT91_SAM9X60_IER);
-		wdt->mr &= ~AT91_SAM9X60_WDDIS;
-	} else {
-		wdt->mr &= ~AT91_WDT_WDDIS;
-	}
+	wdt->mr &= ~wdt->wddis_mask;
 	wdt_write(wdt, AT91_WDT_MR, wdt->mr);
 
 	return 0;
@@ -96,12 +97,9 @@ static int sama5d4_wdt_stop(struct watchdog_device *wdd)
 {
 	struct sama5d4_wdt *wdt = watchdog_get_drvdata(wdd);
 
-	if (wdt->sam9x60_support) {
+	if (wdt->sam9x60_support)
 		writel_relaxed(wdt->ir, wdt->reg_base + AT91_SAM9X60_IDR);
-		wdt->mr |= AT91_SAM9X60_WDDIS;
-	} else {
-		wdt->mr |= AT91_WDT_WDDIS;
-	}
+	wdt->mr |= wdt->wddis_mask;
 	wdt_write(wdt, AT91_WDT_MR, wdt->mr);
 
 	return 0;
@@ -117,7 +115,7 @@ static int sama5d4_wdt_ping(struct watchdog_device *wdd)
 }
 
 static int sama5d4_wdt_set_timeout(struct watchdog_device *wdd,
-				 unsigned int timeout)
+				    unsigned int timeout)
 {
 	struct sama5d4_wdt *wdt = watchdog_get_drvdata(wdd);
 	u32 value = WDT_SEC2TICKS(timeout);
@@ -140,8 +138,8 @@ static int sama5d4_wdt_set_timeout(struct watchdog_device *wdd,
 	 * If the watchdog is enabled, then the timeout can be updated. Else,
 	 * wait that the user enables it.
 	 */
-	if (wdt_enabled)
-		wdt_write(wdt, AT91_WDT_MR, wdt->mr & ~AT91_WDT_WDDIS);
+	if (wdt_enabled(wdt))
+		wdt_write(wdt, AT91_WDT_MR, wdt->mr & ~wdt->wddis_mask);
 
 	wdd->timeout = timeout;
 
@@ -184,10 +182,7 @@ static int of_sama5d4_wdt_init(struct device_node *np, struct sama5d4_wdt *wdt)
 {
 	const char *tmp;
 
-	if (wdt->sam9x60_support)
-		wdt->mr = AT91_SAM9X60_WDDIS;
-	else
-		wdt->mr = AT91_WDT_WDDIS;
+	wdt->mr = wdt->wddis_mask;
 
 	if (!of_property_read_string(np, "atmel,watchdog-type", &tmp) &&
 	    !strcmp(tmp, "software"))
@@ -213,15 +208,11 @@ static int sama5d4_wdt_init(struct sama5d4_wdt *wdt)
 	 * If the watchdog is already running, we can safely update it.
 	 * Else, we have to disable it properly.
 	 */
-	if (!wdt_enabled) {
+	if (!wdt_enabled(wdt)) {
 		reg = wdt_read(wdt, AT91_WDT_MR);
-		if (wdt->sam9x60_support && (!(reg & AT91_SAM9X60_WDDIS)))
-			wdt_write_nosleep(wdt, AT91_WDT_MR,
-					  reg | AT91_SAM9X60_WDDIS);
-		else if (!wdt->sam9x60_support &&
-			 (!(reg & AT91_WDT_WDDIS)))
+		if (!(reg & wdt->wddis_mask))
 			wdt_write_nosleep(wdt, AT91_WDT_MR,
-					  reg | AT91_WDT_WDDIS);
+					  reg | wdt->wddis_mask);
 	}
 
 	if (wdt->sam9x60_support) {
@@ -273,6 +264,9 @@ static int sama5d4_wdt_probe(struct platform_device *pdev)
 	    of_device_is_compatible(dev->of_node, "microchip,sama7g5-wdt"))
 		wdt->sam9x60_support = true;
 
+	wdt->wddis_mask = wdt->sam9x60_support ? AT91_SAM9X60_WDDIS
+						: AT91_WDT_WDDIS;
+
 	watchdog_set_drvdata(wdd, wdt);
 
 	regs = devm_platform_ioremap_resource(pdev, 0);
@@ -306,8 +300,8 @@ static int sama5d4_wdt_probe(struct platform_device *pdev)
 	watchdog_init_timeout(wdd, wdt_timeout, dev);
 
 	reg = wdt_read(wdt, AT91_WDT_MR);
-	if (!(reg & AT91_WDT_WDDIS)) {
-		wdt->mr &= ~AT91_WDT_WDDIS;
+	if (!(reg & wdt->wddis_mask)) {
+		wdt->mr &= ~wdt->wddis_mask;
 		set_bit(WDOG_HW_RUNNING, &wdd->status);
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0116/2077] watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (114 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0115/2077] watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0117/2077] media: cedrus: Fix failure to clean up hardware on probe failure Greg Kroah-Hartman
                   ` (881 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Felix Gu, Guenter Roeck, Baolin Wang,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit 96b3cfc3b8ad0524d12fed1e08bc5df3ff345f64 ]

The driver uses devm_add_action_or_reset() to register sprd_wdt_disable()
as a managed cleanup action.

When devm_watchdog_register_device() fails, the devm core will invoke
the cleanup action automatically.

The explicit sprd_wdt_disable() call in the error path is therefore
redundant and results in adouble cleanup.

Fixes: 78d9bfad2e89 ("watchdog: sprd_wdt: Convert to use device managed functions and other improvements")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Reviewed-by: Guenter Roeck <linux@roeck-us.net>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Link: https://lore.kernel.org/r/20260223-sprd_wdt-v1-1-2e71f9a76ecb@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/watchdog/sprd_wdt.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/drivers/watchdog/sprd_wdt.c b/drivers/watchdog/sprd_wdt.c
index 4e689b6ff1418c..aacf04616fefe2 100644
--- a/drivers/watchdog/sprd_wdt.c
+++ b/drivers/watchdog/sprd_wdt.c
@@ -320,10 +320,9 @@ static int sprd_wdt_probe(struct platform_device *pdev)
 	watchdog_init_timeout(&wdt->wdd, 0, dev);
 
 	ret = devm_watchdog_register_device(dev, &wdt->wdd);
-	if (ret) {
-		sprd_wdt_disable(wdt);
+	if (ret)
 		return ret;
-	}
+
 	platform_set_drvdata(pdev, wdt);
 
 	return 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0117/2077] media: cedrus: Fix failure to clean up hardware on probe failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (115 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0116/2077] watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0118/2077] media: v4l2-common: Add YUV24 format info Greg Kroah-Hartman
                   ` (880 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Samuel Holland, Andrey Skvortsov,
	Paul Kocialkowski, Nicolas Dufresne, Hans Verkuil, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Samuel Holland <samuel@sholland.org>

[ Upstream commit f0a22f1d602ed499a192284de5e811a73421f0c7 ]

If V4L2 device fails to register, then SRAM still be claimed and as a
result driver will not be able to probe again.

 cedrus 1c0e000.video-codec: Failed to claim SRAM
 cedrus 1c0e000.video-codec: Failed to probe hardware
 cedrus 1c0e000.video-codec: probe with driver cedrus failed with error -16

cedrus_hw_remove undoes everything that was previously done by
cedrus_hw_probe, such as disabling runtime power management and
releasing the claimed SRAM and reserved memory region.

Signed-off-by: Samuel Holland <samuel@sholland.org>
Signed-off-by: Andrey Skvortsov <andrej.skvortzov@gmail.com>
Fixes: 50e761516f2b ("media: platform: Add Cedrus VPU decoder driver")
Acked-by: Paul Kocialkowski <paulk@sys-base.io>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/staging/media/sunxi/cedrus/cedrus.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/staging/media/sunxi/cedrus/cedrus.c b/drivers/staging/media/sunxi/cedrus/cedrus.c
index 6600245dff0e23..27e43af6c7bd01 100644
--- a/drivers/staging/media/sunxi/cedrus/cedrus.c
+++ b/drivers/staging/media/sunxi/cedrus/cedrus.c
@@ -476,7 +476,7 @@ static int cedrus_probe(struct platform_device *pdev)
 	ret = v4l2_device_register(&pdev->dev, &dev->v4l2_dev);
 	if (ret) {
 		dev_err(&pdev->dev, "Failed to register V4L2 device\n");
-		return ret;
+		goto err_hw;
 	}
 
 	vfd = &dev->vfd;
@@ -537,6 +537,8 @@ static int cedrus_probe(struct platform_device *pdev)
 	v4l2_m2m_release(dev->m2m_dev);
 err_v4l2:
 	v4l2_device_unregister(&dev->v4l2_dev);
+err_hw:
+	cedrus_hw_remove(dev);
 
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0118/2077] media: v4l2-common: Add YUV24 format info
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (116 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0117/2077] media: cedrus: Fix failure to clean up hardware on probe failure Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0119/2077] drm: verisilicon: call atomic helpers plane state check even if no CRTC Greg Kroah-Hartman
                   ` (879 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nas Chung, Nicolas Dufresne,
	Hans Verkuil, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nas Chung <nas.chung@chipsnmedia.com>

[ Upstream commit 968b741872914a15363af0daf24ed2e82ec355f3 ]

The YUV24 format is missing an entry in the v4l2_format_info().
The YUV24 format is the packed YUV 4:4:4 formats with 8 bits
per component.

Fixes: 0376a51fbe5e ("media: v4l: Add packed YUV444 24bpp pixel format")
Signed-off-by: Nas Chung <nas.chung@chipsnmedia.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/media/v4l2-core/v4l2-common.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/media/v4l2-core/v4l2-common.c b/drivers/media/v4l2-core/v4l2-common.c
index 554c591e111331..55bcd5975d9fcb 100644
--- a/drivers/media/v4l2-core/v4l2-common.c
+++ b/drivers/media/v4l2-core/v4l2-common.c
@@ -281,6 +281,7 @@ const struct v4l2_format_info *v4l2_format_info(u32 format)
 		{ .format = V4L2_PIX_FMT_Y212,    .pixel_enc = V4L2_PIXEL_ENC_YUV, .mem_planes = 1, .comp_planes = 1, .bpp = { 4, 0, 0, 0 }, .bpp_div = { 1, 1, 1, 1 }, .hdiv = 2, .vdiv = 1 },
 		{ .format = V4L2_PIX_FMT_Y216,    .pixel_enc = V4L2_PIXEL_ENC_YUV, .mem_planes = 1, .comp_planes = 1, .bpp = { 4, 0, 0, 0 }, .bpp_div = { 1, 1, 1, 1 }, .hdiv = 2, .vdiv = 1 },
 		{ .format = V4L2_PIX_FMT_YUV48_12, .pixel_enc = V4L2_PIXEL_ENC_YUV, .mem_planes = 1, .comp_planes = 1, .bpp = { 6, 0, 0, 0 }, .bpp_div = { 1, 1, 1, 1 }, .hdiv = 1, .vdiv = 1 },
+		{ .format = V4L2_PIX_FMT_YUV24,   .pixel_enc = V4L2_PIXEL_ENC_YUV, .mem_planes = 1, .comp_planes = 1, .bpp = { 3, 0, 0, 0 }, .bpp_div = { 1, 1, 1, 1 }, .hdiv = 1, .vdiv = 1 },
 		{ .format = V4L2_PIX_FMT_MT2110T, .pixel_enc = V4L2_PIXEL_ENC_YUV, .mem_planes = 2, .comp_planes = 2, .bpp = { 5, 10, 0, 0 }, .bpp_div = { 4, 4, 1, 1 }, .hdiv = 2, .vdiv = 2,
 		  .block_w = { 16, 8, 0, 0 }, .block_h = { 32, 16, 0, 0 }},
 		{ .format = V4L2_PIX_FMT_MT2110R, .pixel_enc = V4L2_PIXEL_ENC_YUV, .mem_planes = 2, .comp_planes = 2, .bpp = { 5, 10, 0, 0 }, .bpp_div = { 4, 4, 1, 1 }, .hdiv = 2, .vdiv = 2,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0119/2077] drm: verisilicon: call atomic helpers plane state check even if no CRTC
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (117 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0118/2077] media: v4l2-common: Add YUV24 format info Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0120/2077] memory: tegra: Wire up system sleep PM ops Greg Kroah-Hartman
                   ` (878 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Icenowy Zheng, Thomas Zimmermann,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Icenowy Zheng <zhengxingda@iscas.ac.cn>

[ Upstream commit eae3903e33797a28d0d37e693d4314d58338918e ]

The `drm_atomic_helper_check_plane_state()` helper function needs to be
called even if the plane is bound to no CRTCs.

Remove the early return in the primary plane's atomic_check, and use
NULL for crtc_state in this situation.

Fixes: dbf21777caa8 ("drm: verisilicon: add a driver for Verisilicon display controllers")
Signed-off-by: Icenowy Zheng <zhengxingda@iscas.ac.cn>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260331060126.1291966-4-zhengxingda@iscas.ac.cn
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/verisilicon/vs_primary_plane.c | 10 +++-------
 1 file changed, 3 insertions(+), 7 deletions(-)

diff --git a/drivers/gpu/drm/verisilicon/vs_primary_plane.c b/drivers/gpu/drm/verisilicon/vs_primary_plane.c
index e8fcb5958615c0..a383b70f1ea0fc 100644
--- a/drivers/gpu/drm/verisilicon/vs_primary_plane.c
+++ b/drivers/gpu/drm/verisilicon/vs_primary_plane.c
@@ -26,14 +26,10 @@ static int vs_primary_plane_atomic_check(struct drm_plane *plane,
 	struct drm_plane_state *new_plane_state = drm_atomic_get_new_plane_state(state,
 										 plane);
 	struct drm_crtc *crtc = new_plane_state->crtc;
-	struct drm_crtc_state *crtc_state;
+	struct drm_crtc_state *crtc_state = NULL;
 
-	if (!crtc)
-		return 0;
-
-	crtc_state = drm_atomic_get_new_crtc_state(state, crtc);
-	if (WARN_ON(!crtc_state))
-		return -EINVAL;
+	if (crtc)
+		crtc_state = drm_atomic_get_new_crtc_state(state, crtc);
 
 	return drm_atomic_helper_check_plane_state(new_plane_state,
 						   crtc_state,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0120/2077] memory: tegra: Wire up system sleep PM ops
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (118 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0119/2077] drm: verisilicon: call atomic helpers plane state check even if no CRTC Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0121/2077] objtool/klp: Fix is_uncorrelated_static_local() for Clang Greg Kroah-Hartman
                   ` (877 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ashish Mhetre, Jon Hunter,
	Krzysztof Kozlowski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ashish Mhetre <amhetre@nvidia.com>

[ Upstream commit 2411c8d1e3e09910e94bab0d0a2c071fbc8a9e7b ]

The tegra-mc platform driver does not register any dev_pm_ops, so the
SoC-specific ->resume() is never invoked (e.g. tegra186_mc_resume) on
system wake. On Tegra186 and later this means MC client Stream-ID
override registers are not reprogrammed, and clients behind the ARM
SMMU fault on the first DMA after resume.

Register a dev_pm_ops on the tegra-mc driver and route the system
resume callback into mc->soc->ops->resume() so the existing SID
restore path runs again on wake.

No suspend callback is needed as the resume path reprograms all MC
state from the static SoC tables, so there is nothing to save.

Fixes: fe3b082a6eb8 ("memory: tegra: Add SID override programming for MC clients")
Signed-off-by: Ashish Mhetre <amhetre@nvidia.com>
Reviewed-by: Jon Hunter <jonathanh@nvidia.com>
Link: https://patch.msgid.link/20260430095202.1167651-3-amhetre@nvidia.com
Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/memory/tegra/mc.c | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/drivers/memory/tegra/mc.c b/drivers/memory/tegra/mc.c
index d620660da3311c..64e41338cdf2d1 100644
--- a/drivers/memory/tegra/mc.c
+++ b/drivers/memory/tegra/mc.c
@@ -13,6 +13,7 @@
 #include <linux/of.h>
 #include <linux/of_platform.h>
 #include <linux/platform_device.h>
+#include <linux/pm.h>
 #include <linux/slab.h>
 #include <linux/sort.h>
 #include <linux/tegra-icc.h>
@@ -1010,10 +1011,23 @@ static void tegra_mc_sync_state(struct device *dev)
 		icc_sync_state(dev);
 }
 
+static int tegra_mc_resume(struct device *dev)
+{
+	struct tegra_mc *mc = dev_get_drvdata(dev);
+
+	if (mc->soc->ops && mc->soc->ops->resume)
+		mc->soc->ops->resume(mc);
+
+	return 0;
+}
+
+static DEFINE_SIMPLE_DEV_PM_OPS(tegra_mc_pm_ops, NULL, tegra_mc_resume);
+
 static struct platform_driver tegra_mc_driver = {
 	.driver = {
 		.name = "tegra-mc",
 		.of_match_table = tegra_mc_of_match,
+		.pm = pm_sleep_ptr(&tegra_mc_pm_ops),
 		.suppress_bind_attrs = true,
 		.sync_state = tegra_mc_sync_state,
 	},
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0121/2077] objtool/klp: Fix is_uncorrelated_static_local() for Clang
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (119 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0120/2077] memory: tegra: Wire up system sleep PM ops Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0122/2077] objtool/klp: Fix .data..once static local non-correlation Greg Kroah-Hartman
                   ` (876 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joe Lawrence, Song Liu,
	Miroslav Benes, Josh Poimboeuf, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joe Lawrence <joe.lawrence@redhat.com>

[ Upstream commit 84c304a534b844703d3437811e8f072166e3f116 ]

For naming function-local static locals, GCC uses <var>.<id>, e.g.
__already_done.15, while Clang uses <func>.<var> with optional .<id>,
e.g. create_worker.__already_done.111

The existing is_uncorrelated_static_local() check only matches the GCC
convention where the variable name is a prefix.  Handle both cases by
checking for a prefix match (GCC) and by checking after the first dot
separator (Clang).

Fixes: dd590d4d57eb ("objtool/klp: Introduce klp diff subcommand for diffing object files")
Signed-off-by: Joe Lawrence <joe.lawrence@redhat.com>
Acked-by: Song Liu <song@kernel.org>
Reviewed-by: Miroslav Benes <mbenes@suse.cz>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/objtool/klp-diff.c | 33 +++++++++++++++++++++++----------
 1 file changed, 23 insertions(+), 10 deletions(-)

diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c
index 0b0d1503851ff9..b1b068e9b4c708 100644
--- a/tools/objtool/klp-diff.c
+++ b/tools/objtool/klp-diff.c
@@ -242,16 +242,17 @@ static struct symbol *next_file_symbol(struct elf *elf, struct symbol *sym)
 static bool is_uncorrelated_static_local(struct symbol *sym)
 {
 	static const char * const vars[] = {
-		"__already_done.",
-		"__func__.",
-		"__key.",
-		"__warned.",
-		"_entry.",
-		"_entry_ptr.",
-		"_rs.",
-		"descriptor.",
-		"CSWTCH.",
+		"__already_done",
+		"__func__",
+		"__key",
+		"__warned",
+		"_entry",
+		"_entry_ptr",
+		"_rs",
+		"descriptor",
+		"CSWTCH",
 	};
+	const char *dot;
 
 	if (!is_object_sym(sym) || !is_local_sym(sym))
 		return false;
@@ -259,8 +260,20 @@ static bool is_uncorrelated_static_local(struct symbol *sym)
 	if (!strcmp(sym->sec->name, ".data.once"))
 		return true;
 
+	dot = strchr(sym->name, '.');
+	if (!dot)
+		return false;
+
 	for (int i = 0; i < ARRAY_SIZE(vars); i++) {
-		if (strstarts(sym->name, vars[i]))
+		size_t len = strlen(vars[i]);
+
+		/* GCC: <var>.<id> */
+		if (strstarts(sym->name, vars[i]) && (sym->name[len] == '.'))
+			return true;
+
+		/* Clang: <func>.<var>[.<id>] */
+		if (strstarts(dot + 1, vars[i]) &&
+		    (dot[1 + len] == '.' || dot[1 + len] == '\0'))
 			return true;
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0122/2077] objtool/klp: Fix .data..once static local non-correlation
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (120 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0121/2077] objtool/klp: Fix is_uncorrelated_static_local() for Clang Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0123/2077] objtool/klp: Fix create_fake_symbols() skipping entsize-based sections Greg Kroah-Hartman
                   ` (875 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Song Liu, Miroslav Benes,
	Josh Poimboeuf, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josh Poimboeuf <jpoimboe@kernel.org>

[ Upstream commit ff529864e738f447ff4c019956319930fc274a23 ]

While there was once a section named .data.once, it has since been
renamed to .data..once with commit dbefa1f31a91 ("Rename .data.once to
.data..once to fix resetting WARN*_ONCE").  Fix it.

Fixes: dd590d4d57eb ("objtool/klp: Introduce klp diff subcommand for diffing object files")
Acked-by: Song Liu <song@kernel.org>
Reviewed-by: Miroslav Benes <mbenes@suse.cz>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/objtool/klp-diff.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c
index b1b068e9b4c708..cb26c1c92a74a2 100644
--- a/tools/objtool/klp-diff.c
+++ b/tools/objtool/klp-diff.c
@@ -257,7 +257,8 @@ static bool is_uncorrelated_static_local(struct symbol *sym)
 	if (!is_object_sym(sym) || !is_local_sym(sym))
 		return false;
 
-	if (!strcmp(sym->sec->name, ".data.once"))
+	/* WARN_ONCE, etc */
+	if (!strcmp(sym->sec->name, ".data..once"))
 		return true;
 
 	dot = strchr(sym->name, '.');
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0123/2077] objtool/klp: Fix create_fake_symbols() skipping entsize-based sections
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (121 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0122/2077] objtool/klp: Fix .data..once static local non-correlation Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0124/2077] objtool/klp: Fix handling of zero-length .altinstr_replacement sections Greg Kroah-Hartman
                   ` (874 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joe Lawrence, Song Liu,
	Miroslav Benes, Josh Poimboeuf, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joe Lawrence <joe.lawrence@redhat.com>

[ Upstream commit 3de711fba73ad93b8b3fbe09cf681cefed5d573d ]

create_fake_symbols() has two phases: creating symbols from
ANNOTATE_DATA_SPECIAL entries, and a fallback that uses sh_entsize for
special sections like .static_call_sites.

When .discard.annotate_data is absent, the function returns early,
skipping the entsize fallback and silently allowing unsupported
module-local static call keys through.

Fix it by jumping to the entsize phase instead of returning early.

Fixes: dd590d4d57eb ("objtool/klp: Introduce klp diff subcommand for diffing object files")
Assisted-by: Claude:claude-4-opus
Signed-off-by: Joe Lawrence <joe.lawrence@redhat.com>
Acked-by: Song Liu <song@kernel.org>
Reviewed-by: Miroslav Benes <mbenes@suse.cz>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/objtool/klp-diff.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c
index cb26c1c92a74a2..18e40a7f864310 100644
--- a/tools/objtool/klp-diff.c
+++ b/tools/objtool/klp-diff.c
@@ -1348,7 +1348,7 @@ static int create_fake_symbols(struct elf *elf)
 
 	sec = find_section_by_name(elf, ".discard.annotate_data");
 	if (!sec || !sec->rsec)
-		return 0;
+		goto entsize;
 
 	for_each_reloc(sec->rsec, reloc) {
 		unsigned long offset, size;
@@ -1380,7 +1380,7 @@ static int create_fake_symbols(struct elf *elf)
 	/*
 	 * 2) Make symbols for sh_entsize, and simple arrays of pointers:
 	 */
-
+entsize:
 	for_each_sec(elf, sec) {
 		unsigned int entry_size;
 		unsigned long offset;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0124/2077] objtool/klp: Fix handling of zero-length .altinstr_replacement sections
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (122 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0123/2077] objtool/klp: Fix create_fake_symbols() skipping entsize-based sections Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0125/2077] objtool/klp: Fix cloning of zero-length section symbols Greg Kroah-Hartman
                   ` (873 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Song Liu, Miroslav Benes,
	Josh Poimboeuf, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josh Poimboeuf <jpoimboe@kernel.org>

[ Upstream commit c4c02d4450b5b7e2fbde578252f71a5697180112 ]

When a section is empty (e.g. only zero-length alternative
replacements), there are no symbols to convert a section symbol
reference to.  Skip the reloc instead of erroring out.

Fixes: dd590d4d57eb ("objtool/klp: Introduce klp diff subcommand for diffing object files")
Acked-by: Song Liu <song@kernel.org>
Reviewed-by: Miroslav Benes <mbenes@suse.cz>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/objtool/klp-diff.c | 13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)

diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c
index 18e40a7f864310..8aec5f5702c73b 100644
--- a/tools/objtool/klp-diff.c
+++ b/tools/objtool/klp-diff.c
@@ -993,6 +993,13 @@ static int convert_reloc_secsym_to_sym(struct elf *elf, struct reloc *reloc)
 	/* No dedicated section; find the symbol manually */
 	sym = find_symbol_containing(sec, arch_adjusted_addend(reloc));
 	if (!sym) {
+		/*
+		 * This is presumably an .altinstr_replacement section which is
+		 * empty due to it only having zero-length replacement(s).
+		 */
+		if (!sec_size(sec))
+			return 1;
+
 		/*
 		 * This can happen for special section references to weak code
 		 * whose symbol has been stripped by the linker.
@@ -1253,6 +1260,7 @@ static int clone_sym_relocs(struct elfs *e, struct symbol *patched_sym)
 
 	for_each_reloc(patched_rsec, patched_reloc) {
 		unsigned long offset;
+		int ret;
 
 		if (reloc_offset(patched_reloc) < start ||
 		    reloc_offset(patched_reloc) >= end)
@@ -1266,12 +1274,15 @@ static int clone_sym_relocs(struct elfs *e, struct symbol *patched_sym)
 		    !strcmp(patched_reloc->sym->sec->name, ".altinstr_aux"))
 			continue;
 
-		if (convert_reloc_sym(e->patched, patched_reloc)) {
+		ret = convert_reloc_sym(e->patched, patched_reloc);
+		if (ret < 0) {
 			ERROR_FUNC(patched_rsec->base, reloc_offset(patched_reloc),
 				   "failed to convert reloc sym '%s' to its proper format",
 				   patched_reloc->sym->name);
 			return -1;
 		}
+		if (ret > 0)
+			continue;
 
 		offset = out_sym->offset + (reloc_offset(patched_reloc) - patched_sym->offset);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0125/2077] objtool/klp: Fix cloning of zero-length section symbols
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (123 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0124/2077] objtool/klp: Fix handling of zero-length .altinstr_replacement sections Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0126/2077] objtool/klp: Fix extraction of text annotations for alternatives Greg Kroah-Hartman
                   ` (872 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Song Liu, Miroslav Benes,
	Josh Poimboeuf, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josh Poimboeuf <jpoimboe@kernel.org>

[ Upstream commit 98377f3ba7c02d6eb34e203c9f9823bc62b0d231 ]

Fix NULL dereference when cloning a symbol from an empty section.
sec->data is only populated for sections with non-zero size.

Fixes: dd590d4d57eb ("objtool/klp: Introduce klp diff subcommand for diffing object files")
Acked-by: Song Liu <song@kernel.org>
Reviewed-by: Miroslav Benes <mbenes@suse.cz>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/objtool/klp-diff.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c
index 8aec5f5702c73b..67fdc43a743373 100644
--- a/tools/objtool/klp-diff.c
+++ b/tools/objtool/klp-diff.c
@@ -669,7 +669,7 @@ static struct symbol *__clone_symbol(struct elf *elf, struct symbol *patched_sym
 			size_t size;
 
 			/* bss doesn't have data */
-			if (patched_sym->sec->data->d_buf)
+			if (patched_sym->sec->data && patched_sym->sec->data->d_buf)
 				data = patched_sym->sec->data->d_buf + patched_sym->offset;
 
 			if (is_sec_sym(patched_sym))
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0126/2077] objtool/klp: Fix extraction of text annotations for alternatives
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (124 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0125/2077] objtool/klp: Fix cloning of zero-length section symbols Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0127/2077] objtool/klp: Fix relocation conversion failures for R_X86_64_NONE Greg Kroah-Hartman
                   ` (871 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Song Liu, Miroslav Benes,
	Josh Poimboeuf, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josh Poimboeuf <jpoimboe@kernel.org>

[ Upstream commit 62a7a01fde87c99926cd7e9670b4226c4c79ebaf ]

Objtool is failing to extract text annotations which reference
.altinstr_replacement instructions:

  1) Alternative replacement fake symbols are NOTYPE rather than FUNC,
     and they don't have sym->included set, thus they aren't recognized
     by should_keep_special_sym().

  2) .discard.annotate_insn gets processed before .altinstr_replacement,
     so the referenced (fake) symbols don't have clones yet.

Fix the first issue by checking for a valid clone instead of
sym->included and by accepting NOTYPE symbols when processing
.discard.annotate_insn.

Fix the second issue by deferring text annotation processing until after
the other special sections have been cloned.

Fixes: dd590d4d57eb ("objtool/klp: Introduce klp diff subcommand for diffing object files")
Acked-by: Song Liu <song@kernel.org>
Reviewed-by: Miroslav Benes <mbenes@suse.cz>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/objtool/klp-diff.c | 33 ++++++++++++++++++++++++++++-----
 1 file changed, 28 insertions(+), 5 deletions(-)

diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c
index 67fdc43a743373..61abf5ceb650e4 100644
--- a/tools/objtool/klp-diff.c
+++ b/tools/objtool/klp-diff.c
@@ -1425,6 +1425,7 @@ static int create_fake_symbols(struct elf *elf)
 /* Keep a special section entry if it references an included function */
 static bool should_keep_special_sym(struct elf *elf, struct symbol *sym)
 {
+	bool annotate_insn = !strcmp(sym->sec->name, ".discard.annotate_insn");
 	struct reloc *reloc;
 
 	if (is_sec_sym(sym) || !sym->sec->rsec)
@@ -1434,7 +1435,16 @@ static bool should_keep_special_sym(struct elf *elf, struct symbol *sym)
 		if (convert_reloc_sym(elf, reloc))
 			continue;
 
-		if (is_func_sym(reloc->sym) && reloc->sym->included)
+		if (!reloc->sym->clone || is_undef_sym(reloc->sym->clone))
+			continue;
+
+		/*
+		 * Keep special section references to cloned functions.
+		 * In some cases annotate_insn can also reference cloned alt
+		 * replacement fake symbols; keep those references as well.
+		 */
+		if (is_func_sym(reloc->sym) ||
+		    (annotate_insn && is_notype_sym(reloc->sym)))
 			return true;
 	}
 
@@ -1578,15 +1588,28 @@ static int clone_special_section(struct elfs *e, struct section *patched_sec)
 /* Extract only the needed bits from special sections */
 static int clone_special_sections(struct elfs *e)
 {
-	struct section *patched_sec;
+	struct section *sec, *annotate_insn = NULL;
 
-	for_each_sec(e->patched, patched_sec) {
-		if (is_special_section(patched_sec)) {
-			if (clone_special_section(e, patched_sec))
+	for_each_sec(e->patched, sec) {
+		if (is_special_section(sec)) {
+			if (!strcmp(sec->name, ".discard.annotate_insn")) {
+				annotate_insn = sec;
+				continue;
+			}
+			if (clone_special_section(e, sec))
 				return -1;
 		}
 	}
 
+	/*
+	 * Do .discard.annotate_insn last, it can reference other special
+	 * sections (alt replacements) so they need to be cloned first.
+	 */
+	if (annotate_insn) {
+		if (clone_special_section(e, annotate_insn))
+			return -1;
+	}
+
 	return 0;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0127/2077] objtool/klp: Fix relocation conversion failures for R_X86_64_NONE
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (125 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0126/2077] objtool/klp: Fix extraction of text annotations for alternatives Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0128/2077] objtool: Replace iterator callback with for_each_sym_by_mangled_name() Greg Kroah-Hartman
                   ` (870 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Song Liu, Miroslav Benes,
	Josh Poimboeuf, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josh Poimboeuf <jpoimboe@kernel.org>

[ Upstream commit 3787e82a4e3a0a04aeb5543580ee90bed3a36e55 ]

Objtool has some hacks which NOP out certain calls/jumps and replace
their relocations with R_X86_64_NONE.  The klp-diff relocation
extraction code will error out when trying to copy these relocations due
to their negative addend, which would only makes sense for a PC-relative
branch instruction.  Just ignore them.

Fixes: dd590d4d57eb ("objtool/klp: Introduce klp diff subcommand for diffing object files")
Acked-by: Song Liu <song@kernel.org>
Reviewed-by: Miroslav Benes <mbenes@suse.cz>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/objtool/klp-diff.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c
index 61abf5ceb650e4..ef038f13366678 100644
--- a/tools/objtool/klp-diff.c
+++ b/tools/objtool/klp-diff.c
@@ -1020,6 +1020,9 @@ static int convert_reloc_secsym_to_sym(struct elf *elf, struct reloc *reloc)
  */
 static int convert_reloc_sym(struct elf *elf, struct reloc *reloc)
 {
+	if (reloc_type(reloc) == R_NONE)
+		return 1;
+
 	if (is_reloc_allowed(reloc))
 		return 0;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0128/2077] objtool: Replace iterator callback with for_each_sym_by_mangled_name()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (126 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0127/2077] objtool/klp: Fix relocation conversion failures for R_X86_64_NONE Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0129/2077] objtool: Fix reloc hash collision in find_reloc_by_dest_range() Greg Kroah-Hartman
                   ` (869 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Song Liu, Miroslav Benes,
	Josh Poimboeuf, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josh Poimboeuf <jpoimboe@kernel.org>

[ Upstream commit 0333b7399587ee0aaa863ed0d13a00a6c7c64068 ]

Convert the callback-based iterate_sym_by_demangled_name() with a new
for_each_sym_by_demangled_name() macro.  This eliminates the callback
struct/function and makes the code more compact and readable.

Acked-by: Song Liu <song@kernel.org>
Reviewed-by: Miroslav Benes <mbenes@suse.cz>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Stable-dep-of: a375e327b63e ("objtool: Fix reloc hash collision in find_reloc_by_dest_range()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/objtool/elf.c                 | 68 ++++++++---------------------
 tools/objtool/include/objtool/elf.h | 32 ++++++++++++--
 tools/objtool/klp-diff.c            | 42 ++++++------------
 3 files changed, 60 insertions(+), 82 deletions(-)

diff --git a/tools/objtool/elf.c b/tools/objtool/elf.c
index f3df2bde119fc4..dc39132f71c148 100644
--- a/tools/objtool/elf.c
+++ b/tools/objtool/elf.c
@@ -27,27 +27,16 @@
 
 static ssize_t demangled_name_len(const char *name);
 
-static inline u32 str_hash(const char *str)
-{
-	return jhash(str, strlen(str), 0);
-}
-
-static inline u32 str_hash_demangled(const char *str)
+u32 str_hash_demangled(const char *str)
 {
 	return jhash(str, demangled_name_len(str), 0);
 }
 
-#define __elf_table(name)	(elf->name##_hash)
-#define __elf_bits(name)	(elf->name##_bits)
-
-#define __elf_table_entry(name, key) \
-	__elf_table(name)[hash_min(key, __elf_bits(name))]
-
 #define elf_hash_add(name, node, key)					\
 ({									\
 	struct elf_hash_node *__node = node;				\
-	__node->next = __elf_table_entry(name, key);			\
-	__elf_table_entry(name, key) = __node;				\
+	__node->next = __elf_table_entry(elf, name, key);		\
+	__elf_table_entry(elf, name, key) = __node;			\
 })
 
 static inline void __elf_hash_del(struct elf_hash_node *node,
@@ -69,30 +58,20 @@ static inline void __elf_hash_del(struct elf_hash_node *node,
 }
 
 #define elf_hash_del(name, node, key) \
-	__elf_hash_del(node, &__elf_table_entry(name, key))
-
-#define elf_list_entry(ptr, type, member)				\
-({									\
-	typeof(ptr) __ptr = (ptr);					\
-	__ptr ? container_of(__ptr, type, member) : NULL;		\
-})
-
-#define elf_hash_for_each_possible(name, obj, member, key)		\
-	for (obj = elf_list_entry(__elf_table_entry(name, key), typeof(*obj), member); \
-	     obj;							\
-	     obj = elf_list_entry(obj->member.next, typeof(*(obj)), member))
+	__elf_hash_del(node, &__elf_table_entry(elf, name, key))
 
 #define elf_alloc_hash(name, size)					\
 ({									\
-	__elf_bits(name) = max(10, ilog2(size));			\
-	__elf_table(name) = mmap(NULL, sizeof(struct elf_hash_node *) << __elf_bits(name), \
+	__elf_bits(elf, name) = max(10, ilog2(size));			\
+	__elf_table(elf, name) = mmap(NULL,				\
+				 sizeof(struct elf_hash_node *) << __elf_bits(elf, name), \
 				 PROT_READ|PROT_WRITE,			\
 				 MAP_PRIVATE|MAP_ANON, -1, 0);		\
-	if (__elf_table(name) == (void *)-1L) {				\
+	if (__elf_table(elf, name) == (void *)-1L) {			\
 		ERROR_GLIBC("mmap fail " #name);			\
-		__elf_table(name) = NULL;				\
+		__elf_table(elf, name) = NULL;				\
 	}								\
-	__elf_table(name);						\
+	__elf_table(elf, name);						\
 })
 
 static inline unsigned long __sym_start(struct symbol *s)
@@ -141,7 +120,7 @@ struct section *find_section_by_name(const struct elf *elf, const char *name)
 {
 	struct section *sec;
 
-	elf_hash_for_each_possible(section_name, sec, name_hash, str_hash(name)) {
+	elf_hash_for_each_possible(elf, section_name, sec, name_hash, str_hash(name)) {
 		if (!strcmp(sec->name, name))
 			return sec;
 	}
@@ -154,7 +133,7 @@ static struct section *find_section_by_index(struct elf *elf,
 {
 	struct section *sec;
 
-	elf_hash_for_each_possible(section, sec, hash, idx) {
+	elf_hash_for_each_possible(elf, section, sec, hash, idx) {
 		if (sec->idx == idx)
 			return sec;
 	}
@@ -166,7 +145,7 @@ static struct symbol *find_symbol_by_index(struct elf *elf, unsigned int idx)
 {
 	struct symbol *sym;
 
-	elf_hash_for_each_possible(symbol, sym, hash, idx) {
+	elf_hash_for_each_possible(elf, symbol, sym, hash, idx) {
 		if (sym->idx == idx)
 			return sym;
 	}
@@ -285,7 +264,7 @@ struct symbol *find_symbol_by_name(const struct elf *elf, const char *name)
 {
 	struct symbol *sym;
 
-	elf_hash_for_each_possible(symbol_name, sym, name_hash, str_hash(name)) {
+	elf_hash_for_each_possible(elf, symbol_name, sym, name_hash, str_hash(name)) {
 		if (!strcmp(sym->name, name))
 			return sym;
 	}
@@ -300,7 +279,7 @@ static struct symbol *find_local_symbol_by_file_and_name(const struct elf *elf,
 {
 	struct symbol *sym;
 
-	elf_hash_for_each_possible(symbol_name, sym, name_hash, str_hash_demangled(name)) {
+	elf_hash_for_each_possible(elf, symbol_name, sym, name_hash, str_hash_demangled(name)) {
 		if (sym->bind == STB_LOCAL && sym->file == file &&
 		    !strcmp(sym->name, name)) {
 			return sym;
@@ -314,7 +293,7 @@ struct symbol *find_global_symbol_by_name(const struct elf *elf, const char *nam
 {
 	struct symbol *sym;
 
-	elf_hash_for_each_possible(symbol_name, sym, name_hash, str_hash_demangled(name)) {
+	elf_hash_for_each_possible(elf, symbol_name, sym, name_hash, str_hash_demangled(name)) {
 		if (!strcmp(sym->name, name) && !is_local_sym(sym))
 			return sym;
 	}
@@ -322,19 +301,6 @@ struct symbol *find_global_symbol_by_name(const struct elf *elf, const char *nam
 	return NULL;
 }
 
-void iterate_global_symbol_by_demangled_name(const struct elf *elf,
-					     const char *demangled_name,
-					     void (*process)(struct symbol *sym, void *data),
-					     void *data)
-{
-	struct symbol *sym;
-
-	elf_hash_for_each_possible(symbol_name, sym, name_hash, str_hash(demangled_name)) {
-		if (!strcmp(sym->demangled_name, demangled_name) && !is_local_sym(sym))
-			process(sym, data);
-	}
-}
-
 struct reloc *find_reloc_by_dest_range(const struct elf *elf, struct section *sec,
 				     unsigned long offset, unsigned int len)
 {
@@ -347,7 +313,7 @@ struct reloc *find_reloc_by_dest_range(const struct elf *elf, struct section *se
 		return NULL;
 
 	for_offset_range(o, offset, offset + len) {
-		elf_hash_for_each_possible(reloc, reloc, hash,
+		elf_hash_for_each_possible(elf, reloc, reloc, hash,
 					   sec_offset_hash(rsec, o)) {
 			if (reloc->sec != rsec)
 				continue;
diff --git a/tools/objtool/include/objtool/elf.h b/tools/objtool/include/objtool/elf.h
index 25573e5af76efe..b142984eb9b5a7 100644
--- a/tools/objtool/include/objtool/elf.h
+++ b/tools/objtool/include/objtool/elf.h
@@ -21,6 +21,13 @@
 #define SEC_NAME_LEN		1024
 #define SYM_NAME_LEN		512
 
+static inline u32 str_hash(const char *str)
+{
+	return jhash(str, strlen(str), 0);
+}
+
+u32 str_hash_demangled(const char *str);
+
 #define bswap_if_needed(elf, val) __bswap_if_needed(&elf->ehdr, val)
 
 #ifdef LIBELF_USE_DEPRECATED
@@ -130,6 +137,23 @@ struct elf {
 	struct symbol *symbol_data;
 };
 
+#define __elf_table(elf, name)	((elf)->name##_hash)
+#define __elf_bits(elf, name)	((elf)->name##_bits)
+
+#define __elf_table_entry(elf, name, key) \
+	__elf_table(elf, name)[hash_min(key, __elf_bits(elf, name))]
+
+#define elf_list_entry(ptr, type, member)				\
+({									\
+	typeof(ptr) __ptr = (ptr);					\
+	__ptr ? container_of(__ptr, type, member) : NULL;		\
+})
+
+#define elf_hash_for_each_possible(elf, name, obj, member, key)		\
+	for (obj = elf_list_entry(__elf_table_entry(elf, name, key), typeof(*obj), member); \
+	     obj;							\
+	     obj = elf_list_entry(obj->member.next, typeof(*(obj)), member))
+
 struct elf *elf_open_read(const char *name, int flags);
 struct elf *elf_create_file(GElf_Ehdr *ehdr, const char *name);
 
@@ -186,9 +210,6 @@ struct symbol *find_func_by_offset(struct section *sec, unsigned long offset);
 struct symbol *find_symbol_by_offset(struct section *sec, unsigned long offset);
 struct symbol *find_symbol_by_name(const struct elf *elf, const char *name);
 struct symbol *find_global_symbol_by_name(const struct elf *elf, const char *name);
-void iterate_global_symbol_by_demangled_name(const struct elf *elf, const char *demangled_name,
-					     void (*process)(struct symbol *sym, void *data),
-					     void *data);
 struct symbol *find_symbol_containing(const struct section *sec, unsigned long offset);
 int find_symbol_hole_containing(const struct section *sec, unsigned long offset);
 struct reloc *find_reloc_by_dest(const struct elf *elf, struct section *sec, unsigned long offset);
@@ -468,6 +489,11 @@ static inline void set_sym_next_reloc(struct reloc *reloc, struct reloc *next)
 #define for_each_sym_continue(elf, sym)					\
 	list_for_each_entry_continue(sym, &elf->symbols, global_list)
 
+#define for_each_sym_by_demangled_name(elf, name, sym)			\
+	elf_hash_for_each_possible(elf, symbol_name, sym, name_hash,	\
+				   str_hash(name))			\
+		if (strcmp(sym->demangled_name, name)) {} else
+
 #define rsec_next_reloc(rsec, reloc)					\
 	reloc_idx(reloc) < sec_num_entries(rsec) - 1 ? reloc + 1 : NULL
 
diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c
index ef038f13366678..d0b3d1eef05215 100644
--- a/tools/objtool/klp-diff.c
+++ b/tools/objtool/klp-diff.c
@@ -46,11 +46,6 @@ static const struct option klp_diff_options[] = {
 
 static DEFINE_HASHTABLE(exports, 15);
 
-static inline u32 str_hash(const char *str)
-{
-	return jhash(str, strlen(str), 0);
-}
-
 static char *escape_str(const char *orig)
 {
 	size_t len = 0;
@@ -370,22 +365,6 @@ static bool dont_correlate(struct symbol *sym)
 	       strstarts(sym->name, "__initcall__");
 }
 
-struct process_demangled_name_data {
-	struct symbol *ret;
-	int count;
-};
-
-static void process_demangled_name(struct symbol *sym, void *d)
-{
-	struct process_demangled_name_data *data = d;
-
-	if (sym->twin)
-		return;
-
-	data->count++;
-	data->ret = sym;
-}
-
 /*
  * When there is no full name match, try match demangled_name. This would
  * match original foo.llvm.123 to patched foo.llvm.456.
@@ -397,16 +376,23 @@ static void process_demangled_name(struct symbol *sym, void *d)
 static int find_global_symbol_by_demangled_name(struct elf *elf, struct symbol *sym,
 						struct symbol **out_sym)
 {
-	struct process_demangled_name_data data = {};
+	struct symbol *sym2, *result = NULL;
+	int count = 0;
+
+	for_each_sym_by_demangled_name(elf, sym->demangled_name, sym2) {
+		if (is_local_sym(sym2) || sym2->twin)
+			continue;
 
-	iterate_global_symbol_by_demangled_name(elf, sym->demangled_name,
-						process_demangled_name,
-						&data);
-	if (data.count > 1) {
-		ERROR("Multiple (%d) correlation candidates for %s", data.count, sym->name);
+		count++;
+		result = sym2;
+	}
+
+	if (count > 1) {
+		ERROR("Multiple (%d) correlation candidates for %s", count, sym->name);
 		return -1;
 	}
-	*out_sym = data.ret;
+
+	*out_sym = result;
 	return 0;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0129/2077] objtool: Fix reloc hash collision in find_reloc_by_dest_range()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (127 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0128/2077] objtool: Replace iterator callback with for_each_sym_by_mangled_name() Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0130/2077] klp-build: Fix hang on out-of-date .config Greg Kroah-Hartman
                   ` (868 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Peter Zijlstra (Intel), Song Liu,
	Miroslav Benes, Josh Poimboeuf, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josh Poimboeuf <jpoimboe@kernel.org>

[ Upstream commit a375e327b63e0da29b82a92b569bfdf4628fa38a ]

In find_reloc_by_dest_range(), hash collisions can cause a high-offset
relocation to appear when probing a low-offset hash bucket.

Only return early when the best match found so far genuinely belongs to
the current bucket (its offset is within the bucket's stride range).
Otherwise, continue scanning later buckets which may contain
lower-offset matches.

This ensures the first reloc in the range gets returned.

Fixes: 74b873e49d92 ("objtool: Optimize find_rela_by_dest_range()")
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: Song Liu <song@kernel.org>
Reviewed-by: Miroslav Benes <mbenes@suse.cz>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/objtool/elf.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/tools/objtool/elf.c b/tools/objtool/elf.c
index dc39132f71c148..58631d62011d67 100644
--- a/tools/objtool/elf.c
+++ b/tools/objtool/elf.c
@@ -301,8 +301,9 @@ struct symbol *find_global_symbol_by_name(const struct elf *elf, const char *nam
 	return NULL;
 }
 
+/* If there are multiple matches, return the first one in the range */
 struct reloc *find_reloc_by_dest_range(const struct elf *elf, struct section *sec,
-				     unsigned long offset, unsigned int len)
+				       unsigned long offset, unsigned int len)
 {
 	struct reloc *reloc, *r = NULL;
 	struct section *rsec;
@@ -324,11 +325,11 @@ struct reloc *find_reloc_by_dest_range(const struct elf *elf, struct section *se
 					r = reloc;
 			}
 		}
-		if (r)
+		if (r && (reloc_offset(r) & OFFSET_STRIDE_MASK) == o)
 			return r;
 	}
 
-	return NULL;
+	return r;
 }
 
 struct reloc *find_reloc_by_dest(const struct elf *elf, struct section *sec, unsigned long offset)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0130/2077] klp-build: Fix hang on out-of-date .config
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (128 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0129/2077] objtool: Fix reloc hash collision in find_reloc_by_dest_range() Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0131/2077] klp-build: Fix checksum comparison for changed offsets Greg Kroah-Hartman
                   ` (867 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Song Liu, Josh Poimboeuf,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josh Poimboeuf <jpoimboe@kernel.org>

[ Upstream commit cc39ccce7d5bc623100f07dcda070cef1bf690f6 ]

If .config is out of date with the kernel source, 'make syncconfig'
hangs while waiting for user input on new config options.  Detect the
mismatch and return an error.

Fixes: 6f93f7b06810 ("livepatch/klp-build: Fix inconsistent kernel version")
Acked-by: Song Liu <song@kernel.org>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 scripts/livepatch/klp-build | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/scripts/livepatch/klp-build b/scripts/livepatch/klp-build
index 0ad7e663131420..e19d93b78fcba0 100755
--- a/scripts/livepatch/klp-build
+++ b/scripts/livepatch/klp-build
@@ -306,7 +306,12 @@ set_kernelversion() {
 
 	stash_file "$file"
 
-	kernelrelease="$(cd "$SRC" && make syncconfig &>/dev/null && make -s kernelrelease)"
+	if [[ -n "$(make -s listnewconfig 2>/dev/null)" ]]; then
+		die ".config mismatch, check your .config or run 'make olddefconfig'"
+	fi
+	make syncconfig &>/dev/null || die "make syncconfig failed"
+
+	kernelrelease="$(make -s kernelrelease)"
 	[[ -z "$kernelrelease" ]] && die "failed to get kernel version"
 
 	sed -i "2i echo $kernelrelease; exit 0" scripts/setlocalversion
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0131/2077] klp-build: Fix checksum comparison for changed offsets
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (129 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0130/2077] klp-build: Fix hang on out-of-date .config Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0132/2077] klp-build: Fix patch cleanup on interrupt Greg Kroah-Hartman
                   ` (866 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Song Liu, Josh Poimboeuf,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josh Poimboeuf <jpoimboe@kernel.org>

[ Upstream commit ba77fe55781a2464f68b6c13b4b31d05abd2abcf ]

The klp-build -f/--show-first-changed feature uses diff to compare
checksum log lines between original and patched objects.  However, diff
compares entire lines, including the offset field.  When a function is
at a different section offset, the offset field differs even though the
instruction checksum is identical, causing the wrong instruction to be
printed.

Only compare the checksum field when looking for the first changed
instruction.  Also print both the original and patched offsets when they
differ.

Fixes: 78be9facfb5e ("livepatch/klp-build: Add --show-first-changed option to show function divergence")
Acked-by: Song Liu <song@kernel.org>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 scripts/livepatch/klp-build | 30 +++++++++++++++++++++++-------
 1 file changed, 23 insertions(+), 7 deletions(-)

diff --git a/scripts/livepatch/klp-build b/scripts/livepatch/klp-build
index e19d93b78fcba0..8f0ea56f264005 100755
--- a/scripts/livepatch/klp-build
+++ b/scripts/livepatch/klp-build
@@ -727,13 +727,29 @@ diff_checksums() {
 		)
 
 		for func in ${funcs[$file]}; do
-			diff <( grep0 -E "^DEBUG: .*checksum: $func " "$orig_log"    | sed "s|$ORIG_DIR/||")	\
-			     <( grep0 -E "^DEBUG: .*checksum: $func " "$patched_log" | sed "s|$PATCHED_DIR/||")	\
-				| gawk '/^< DEBUG: / {
-					gsub(/:/, "")
-					printf "%s: %s: %s\n", $3, $5, $6
-					exit
-			}' || true
+			local -a orig patched
+			paste <(grep0 -E "^DEBUG: .*checksum: $func " "$orig_log") \
+			      <(grep0 -E "^DEBUG: .*checksum: $func " "$patched_log") |
+			while IFS= read -r line; do
+				read -ra orig <<< "${line%%$'\t'*}"
+				read -ra patched <<< "${line#*$'\t'}"
+
+				if [[ ${#patched[@]} -eq 0 ]]; then
+					printf "%s: %s: %s (removed)\n" "${orig[1]%:}" "${orig[3]}" "${orig[-2]}"
+					break
+				elif [[ ${#orig[@]} -eq 0 ]]; then
+					printf "%s: %s: %s (added)\n" "${patched[1]%:}" "${patched[3]}" "${patched[-2]}"
+					break
+				fi
+
+				[[ "${orig[-1]}" == "${patched[-1]}" ]] && continue
+
+				printf "%s: %s: %s" "${orig[1]%:}" "${orig[3]}" "${orig[-2]}"
+				[[ "${orig[-2]}" != "${patched[-2]}" ]] && \
+					printf " (patched: %s)" "${patched[-2]}"
+				printf "\n"
+				break
+			done || true
 		done
 	done
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0132/2077] klp-build: Fix patch cleanup on interrupt
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (130 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0131/2077] klp-build: Fix checksum comparison for changed offsets Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0133/2077] crypto: qat - fix heartbeat error injection Greg Kroah-Hartman
                   ` (865 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Song Liu, Josh Poimboeuf,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josh Poimboeuf <jpoimboe@kernel.org>

[ Upstream commit f3048888ea62ac1c573db91e74e0dcabe058e89f ]

If a build error occurs and the user hits Ctrl-C while a large patch is
being reverted during cleanup, the cleanup EXIT trap gets re-triggered
and tries to re-revert the already partially-reverted patch.  That
causes 'patch -R' to repeatedly prompt

  "Unreversed patch detected!  Ignore -R? [n]"

for each already-reverted hunk, with no way to break out.

Fix it by adding '--force' to the patch revert command in
revert_patch(), which causes it to silently ignore already-reverted
hunks.  And ignore errors, as the cleanup is always best-effort.

For similar reasons, add to APPLIED_PATCHES before (rather than after)
applying the patch in apply_patch() so an interrupted apply will also
get cleaned up.

Fixes: d36a7343f4ba ("livepatch/klp-build: switch to GNU patch and recountdiff")
Acked-by: Song Liu <song@kernel.org>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 scripts/livepatch/klp-build | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/scripts/livepatch/klp-build b/scripts/livepatch/klp-build
index 8f0ea56f264005..ab5ea13c87004e 100755
--- a/scripts/livepatch/klp-build
+++ b/scripts/livepatch/klp-build
@@ -381,15 +381,15 @@ apply_patch() {
 		warn "${patch} applied with fuzz"
 	fi
 
-	patch -d "$SRC" -p1 --no-backup-if-mismatch -r /dev/null "${extra_args[@]}" --silent < "$patch"
 	APPLIED_PATCHES+=("$patch")
+	patch -d "$SRC" -p1 --no-backup-if-mismatch -r /dev/null "${extra_args[@]}" --silent < "$patch"
 }
 
 revert_patch() {
 	local patch="$1"
 	local tmp=()
 
-	patch -d "$SRC" -p1 -R --silent --no-backup-if-mismatch -r /dev/null < "$patch"
+	patch -d "$SRC" -p1 -R --force --no-backup-if-mismatch -r /dev/null &> /dev/null < "$patch" || true
 
 	for p in "${APPLIED_PATCHES[@]}"; do
 		[[ "$p" == "$patch" ]] && continue
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0133/2077] crypto: qat - fix heartbeat error injection
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (131 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0132/2077] klp-build: Fix patch cleanup on interrupt Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0134/2077] lib/vsprintf: Fix to check field_width and precision Greg Kroah-Hartman
                   ` (864 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Damian Muszynski, Ahsan Atta,
	Giovanni Cabiddu, Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Damian Muszynski <damian.muszynski@intel.com>

[ Upstream commit 2e96024632b386c86860aa78639940fc96d6fcc9 ]

The current implementation of the heartbeat error injection uses
adf_disable_arb_thd() to stop a specific accelerator engine thread
from processing requests. This does not reliably prevent the device
from generating responses.

Fix the error injection by disabling the device arbiter through
exit_arb() instead. This properly simulates a device failure by
stopping all arbitration, which results in missing responses for
sent requests.

Remove the now unused adf_disable_arb_thd() function and its
declaration.

Fixes: e2b67859ab6e ("crypto: qat - add heartbeat error simulator")
Signed-off-by: Damian Muszynski <damian.muszynski@intel.com>
Reviewed-by: Ahsan Atta <ahsan.atta@intel.com>
Reviewed-by: Giovanni Cabiddu <giovanni.cabiddu@intel.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../intel/qat/qat_common/adf_common_drv.h     |  1 -
 .../qat/qat_common/adf_heartbeat_inject.c     |  6 ++---
 .../intel/qat/qat_common/adf_hw_arbiter.c     | 25 -------------------
 3 files changed, 2 insertions(+), 30 deletions(-)

diff --git a/drivers/crypto/intel/qat/qat_common/adf_common_drv.h b/drivers/crypto/intel/qat/qat_common/adf_common_drv.h
index db26e0b31170e8..7d7d64fce61404 100644
--- a/drivers/crypto/intel/qat/qat_common/adf_common_drv.h
+++ b/drivers/crypto/intel/qat/qat_common/adf_common_drv.h
@@ -90,7 +90,6 @@ void adf_exit_aer(void);
 int adf_init_arb(struct adf_accel_dev *accel_dev);
 void adf_exit_arb(struct adf_accel_dev *accel_dev);
 void adf_update_ring_arb(struct adf_etr_ring_data *ring);
-int adf_disable_arb_thd(struct adf_accel_dev *accel_dev, u32 ae, u32 thr);
 
 int adf_dev_get(struct adf_accel_dev *accel_dev);
 void adf_dev_put(struct adf_accel_dev *accel_dev);
diff --git a/drivers/crypto/intel/qat/qat_common/adf_heartbeat_inject.c b/drivers/crypto/intel/qat/qat_common/adf_heartbeat_inject.c
index a3b474bdef6c83..023c5f1e78b075 100644
--- a/drivers/crypto/intel/qat/qat_common/adf_heartbeat_inject.c
+++ b/drivers/crypto/intel/qat/qat_common/adf_heartbeat_inject.c
@@ -64,10 +64,8 @@ int adf_heartbeat_inject_error(struct adf_accel_dev *accel_dev)
 	if (ret)
 		return ret;
 
-	/* Configure worker threads to stop processing any packet */
-	ret = adf_disable_arb_thd(accel_dev, rand_ae, rand_thr);
-	if (ret)
-		return ret;
+	/* Disable arbiter to stop processing any packet */
+	hw_device->exit_arb(accel_dev);
 
 	/* Change HB counters memory to simulate a hang */
 	adf_set_hb_counters_fail(accel_dev, rand_ae, rand_thr);
diff --git a/drivers/crypto/intel/qat/qat_common/adf_hw_arbiter.c b/drivers/crypto/intel/qat/qat_common/adf_hw_arbiter.c
index f93d9cca70cee4..dd9a31c20bc9c9 100644
--- a/drivers/crypto/intel/qat/qat_common/adf_hw_arbiter.c
+++ b/drivers/crypto/intel/qat/qat_common/adf_hw_arbiter.c
@@ -99,28 +99,3 @@ void adf_exit_arb(struct adf_accel_dev *accel_dev)
 		csr_ops->write_csr_ring_srv_arb_en(csr, i, 0);
 }
 EXPORT_SYMBOL_GPL(adf_exit_arb);
-
-int adf_disable_arb_thd(struct adf_accel_dev *accel_dev, u32 ae, u32 thr)
-{
-	void __iomem *csr = accel_dev->transport->banks[0].csr_addr;
-	struct adf_hw_device_data *hw_data = accel_dev->hw_device;
-	const u32 *thd_2_arb_cfg;
-	struct arb_info info;
-	u32 ae_thr_map;
-
-	if (ADF_AE_STRAND0_THREAD == thr || ADF_AE_STRAND1_THREAD == thr)
-		thr = ADF_AE_ADMIN_THREAD;
-
-	hw_data->get_arb_info(&info);
-	thd_2_arb_cfg = hw_data->get_arb_mapping(accel_dev);
-	if (!thd_2_arb_cfg)
-		return -EFAULT;
-
-	/* Disable scheduling for this particular AE and thread */
-	ae_thr_map = *(thd_2_arb_cfg + ae);
-	ae_thr_map &= ~(GENMASK(3, 0) << (thr * BIT(2)));
-
-	WRITE_CSR_ARB_WT2SAM(csr, info.arb_offset, info.wt2sam_offset, ae,
-			     ae_thr_map);
-	return 0;
-}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0134/2077] lib/vsprintf: Fix to check field_width and precision
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (132 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0133/2077] crypto: qat - fix heartbeat error injection Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0135/2077] dts: spacemit: set console baud rate on bpif3 Greg Kroah-Hartman
                   ` (863 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Laight,
	Masami Hiramatsu (Google), Petr Mladek, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Masami Hiramatsu (Google) <mhiramat@kernel.org>

[ Upstream commit 71876dffab295b6e25d4209f0424da8fc5020e12 ]

Check the field_width and presition correctly. Previously it depends
on the bitfield conversion from int to check out-of-range error.
However, commit 938df695e98d ("vsprintf: associate the format state
with the format pointer") changed those fields to int.
We need to check the out-of-range correctly without bitfield
conversion.

Fixes: 938df695e98d ("vsprintf: associate the format state with the format pointer")
Reported-by: David Laight <david.laight.linux@gmail.com>
Closes: https://lore.kernel.org/all/20260318151250.40fef0ab@pumpkin/
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Reviewed-by: Petr Mladek <pmladek@suse.com>
Link: https://patch.msgid.link/177452712047.197965.16376597502504928495.stgit@devnote2
Signed-off-by: Petr Mladek <pmladek@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 lib/vsprintf.c | 36 ++++++++++++++----------------------
 1 file changed, 14 insertions(+), 22 deletions(-)

diff --git a/lib/vsprintf.c b/lib/vsprintf.c
index 9f359b31c8d1c1..3c76cc5c7f9ceb 100644
--- a/lib/vsprintf.c
+++ b/lib/vsprintf.c
@@ -2640,6 +2640,18 @@ static unsigned char spec_flag(unsigned char c)
 	return (c < sizeof(spec_flag_array)) ? spec_flag_array[c] : 0;
 }
 
+static void set_field_width(struct printf_spec *spec, int width)
+{
+	spec->field_width = clamp(width, -FIELD_WIDTH_MAX, FIELD_WIDTH_MAX);
+	WARN_ONCE(spec->field_width != width, "field width %d out of range", width);
+}
+
+static void set_precision(struct printf_spec *spec, int prec)
+{
+	spec->precision = clamp(prec, 0, PRECISION_MAX);
+	WARN_ONCE(spec->precision < prec, "precision %d too large", prec);
+}
+
 /*
  * Helper function to decode printf style format.
  * Each call decode a token from the format and return the
@@ -2710,7 +2722,7 @@ struct fmt format_decode(struct fmt fmt, struct printf_spec *spec)
 	spec->field_width = -1;
 
 	if (isdigit(*fmt.str))
-		spec->field_width = skip_atoi(&fmt.str);
+		set_field_width(spec, skip_atoi(&fmt.str));
 	else if (unlikely(*fmt.str == '*')) {
 		/* it's the next argument */
 		fmt.state = FORMAT_STATE_WIDTH;
@@ -2724,9 +2736,7 @@ struct fmt format_decode(struct fmt fmt, struct printf_spec *spec)
 	if (unlikely(*fmt.str == '.')) {
 		fmt.str++;
 		if (isdigit(*fmt.str)) {
-			spec->precision = skip_atoi(&fmt.str);
-			if (spec->precision < 0)
-				spec->precision = 0;
+			set_precision(spec, skip_atoi(&fmt.str));
 		} else if (*fmt.str == '*') {
 			/* it's the next argument */
 			fmt.state = FORMAT_STATE_PRECISION;
@@ -2799,24 +2809,6 @@ struct fmt format_decode(struct fmt fmt, struct printf_spec *spec)
 	return fmt;
 }
 
-static void
-set_field_width(struct printf_spec *spec, int width)
-{
-	spec->field_width = width;
-	if (WARN_ONCE(spec->field_width != width, "field width %d too large", width)) {
-		spec->field_width = clamp(width, -FIELD_WIDTH_MAX, FIELD_WIDTH_MAX);
-	}
-}
-
-static void
-set_precision(struct printf_spec *spec, int prec)
-{
-	spec->precision = prec;
-	if (WARN_ONCE(spec->precision != prec, "precision %d too large", prec)) {
-		spec->precision = clamp(prec, 0, PRECISION_MAX);
-	}
-}
-
 /*
  * Turn a 1/2/4-byte value into a 64-bit one for printing: truncate
  * as necessary and deal with signedness.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0135/2077] dts: spacemit: set console baud rate on bpif3
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (133 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0134/2077] lib/vsprintf: Fix to check field_width and precision Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0136/2077] pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path Greg Kroah-Hartman
                   ` (862 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Vivian Wang, Conor Dooley, Yixun Lan,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Conor Dooley <conor.dooley@microchip.com>

[ Upstream commit 24c12ca43b12c104389d9a159207d0b25779d0af ]

Because the default console's baud rate is not set, defconfig kernels do
not have any serial output on this platform. Set the baud rate to
115200, matching what is used by U-Boot etc on this platform.

Suggested-by: Vivian Wang <wangruikang@iscas.ac.cn>
Fixes: d60d57ab6b2a8 ("riscv: dts: spacemit: add Banana Pi BPI-F3 board device tree")
Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
Reviewed-by: Yixun Lan <dlan@kernel.org>
Link: https://lore.kernel.org/r/20260430-reword-overstep-3be08b7eab25@spud
Signed-off-by: Yixun Lan <dlan@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/boot/dts/spacemit/k1-bananapi-f3.dts | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/riscv/boot/dts/spacemit/k1-bananapi-f3.dts b/arch/riscv/boot/dts/spacemit/k1-bananapi-f3.dts
index 5790d927b93db3..333ac8ebf3f516 100644
--- a/arch/riscv/boot/dts/spacemit/k1-bananapi-f3.dts
+++ b/arch/riscv/boot/dts/spacemit/k1-bananapi-f3.dts
@@ -19,7 +19,7 @@ aliases {
 	};
 
 	chosen {
-		stdout-path = "serial0";
+		stdout-path = "serial0:115200n8";
 	};
 
 	leds {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0136/2077] pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (134 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0135/2077] dts: spacemit: set console baud rate on bpif3 Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0137/2077] riscv: dts: microchip: gpio controllers on mpfs need 2 interrupt cells Greg Kroah-Hartman
                   ` (861 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Felix Gu, Andre Przywara,
	Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit 334f7bcbdc79dc8e5b938ac3372453a5368221cf ]

In the error path of sunxi_pmx_request(), the code calls
regulator_put(s_reg->regulator) to release the regulator. However,
s_reg->regulator is only assigned after a successful regulator_enable().
This causes a memory leak: the regulator obtained via regulator_get()
is never properly released when regulator_enable() fails.

Fixes: dc1445584177 ("pinctrl: sunxi: Fix and simplify pin bank regulator handling")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Reviewed-by: Andre Przywara <andre.przywara@arm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/sunxi/pinctrl-sunxi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pinctrl/sunxi/pinctrl-sunxi.c b/drivers/pinctrl/sunxi/pinctrl-sunxi.c
index d3042e0c9712e8..25489beeb31253 100644
--- a/drivers/pinctrl/sunxi/pinctrl-sunxi.c
+++ b/drivers/pinctrl/sunxi/pinctrl-sunxi.c
@@ -925,7 +925,7 @@ static int sunxi_pmx_request(struct pinctrl_dev *pctldev, unsigned offset)
 	return 0;
 
 out:
-	regulator_put(s_reg->regulator);
+	regulator_put(reg);
 
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0137/2077] riscv: dts: microchip: gpio controllers on mpfs need 2 interrupt cells
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (135 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0136/2077] pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0138/2077] riscv: dts: microchip: remove gpio hogs from beaglev-fire Greg Kroah-Hartman
                   ` (860 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Conor Dooley, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Conor Dooley <conor.dooley@microchip.com>

[ Upstream commit 79b731da340f1c9703e28665d49a865aa6956278 ]

The platform has variable interrupt types for GPIO interrupts, in
addition to having multiple lines per GPIO controller. Two interrupt
cells are required.

Fixes: 528a5b1f2556d ("riscv: dts: microchip: add new peripherals to icicle kit device tree")
Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/boot/dts/microchip/mpfs.dtsi | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/arch/riscv/boot/dts/microchip/mpfs.dtsi b/arch/riscv/boot/dts/microchip/mpfs.dtsi
index d535d4c72763c9..85d8df6437f23e 100644
--- a/arch/riscv/boot/dts/microchip/mpfs.dtsi
+++ b/arch/riscv/boot/dts/microchip/mpfs.dtsi
@@ -499,7 +499,7 @@ gpio0: gpio@20120000 {
 			reg = <0x0 0x20120000 0x0 0x1000>;
 			interrupt-parent = <&irqmux>;
 			interrupt-controller;
-			#interrupt-cells = <1>;
+			#interrupt-cells = <2>;
 			interrupts = <0>, <1>, <2>, <3>,
 				     <4>, <5>, <6>, <7>,
 				     <8>, <9>, <10>, <11>,
@@ -516,7 +516,7 @@ gpio1: gpio@20121000 {
 			reg = <0x0 0x20121000 0x0 0x1000>;
 			interrupt-parent = <&irqmux>;
 			interrupt-controller;
-			#interrupt-cells = <1>;
+			#interrupt-cells = <2>;
 			interrupts = <32>, <33>, <34>, <35>,
 				     <36>, <37>, <38>, <39>,
 				     <40>, <41>, <42>, <43>,
@@ -535,7 +535,7 @@ gpio2: gpio@20122000 {
 			reg = <0x0 0x20122000 0x0 0x1000>;
 			interrupt-parent = <&irqmux>;
 			interrupt-controller;
-			#interrupt-cells = <1>;
+			#interrupt-cells = <2>;
 			interrupts = <64>, <65>, <66>, <67>,
 				     <68>, <69>, <70>, <71>,
 				     <72>, <73>, <74>, <75>,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0138/2077] riscv: dts: microchip: remove gpio hogs from beaglev-fire
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (136 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0137/2077] riscv: dts: microchip: gpio controllers on mpfs need 2 interrupt cells Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0139/2077] dt-bindings: vendor-prefixes: Add Displaytech Ltd Greg Kroah-Hartman
                   ` (859 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Conor Dooley, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Conor Dooley <conor.dooley@microchip.com>

[ Upstream commit 7ab032833b2f0dd3b51d71e6756ebe7efc61eed4 ]

sd-det-hog should be cd-gpios, but when the mmc-spi-slot was added, the
"cd-" prefix was omitted and the collision with the hog was not noticed.

vio-enable-hog is just a regulator that can be modelled as such.

Fixes: 1088d49b62648 ("riscv: dts: microchip: enable qspi adc/mmc-spi-slot on BeagleV Fire")
Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../boot/dts/microchip/mpfs-beaglev-fire.dts  | 25 ++++++++-----------
 1 file changed, 10 insertions(+), 15 deletions(-)

diff --git a/arch/riscv/boot/dts/microchip/mpfs-beaglev-fire.dts b/arch/riscv/boot/dts/microchip/mpfs-beaglev-fire.dts
index 0e1b0b8d394b90..6e9653827cfe25 100644
--- a/arch/riscv/boot/dts/microchip/mpfs-beaglev-fire.dts
+++ b/arch/riscv/boot/dts/microchip/mpfs-beaglev-fire.dts
@@ -77,6 +77,15 @@ imx219_vddl: fixedregulator-2 {
 		regulator-max-microvolt = <1200000>;
 	};
 
+	regulator-1v8-syzygy {
+		compatible = "regulator-fixed";
+		gpios = <&gpio2 30 GPIO_ACTIVE_HIGH>;
+		regulator-name = "syzygy_1v8";
+		regulator-min-microvolt = <1800000>;
+		regulator-max-microvolt = <1800000>;
+		regulator-always-on;
+		enable-active-high;
+	};
 };
 
 &gpio0 {
@@ -118,20 +127,6 @@ &gpio2 {
 			  "P8_PIN27", "P8_PIN28", "P8_PIN29", "P8_PIN30", "M2_W_DISABLE1",
 			  "M2_W_DISABLE2", "VIO_ENABLE", "SD_DET";
 	status = "okay";
-
-	vio-enable-hog {
-		gpio-hog;
-		gpios = <30 30>;
-		output-high;
-		line-name = "VIO_ENABLE";
-	};
-
-	sd-det-hog {
-		gpio-hog;
-		gpios = <31 31>;
-		input;
-		line-name = "SD_DET";
-	};
 };
 
 &i2c0 {
@@ -316,7 +311,7 @@ channel@7 {
 	mmc@1 {
 		compatible = "mmc-spi-slot";
 		reg = <1>;
-		gpios = <&gpio2 31 1>;
+		cd-gpios = <&gpio2 31 GPIO_ACTIVE_LOW>;
 		voltage-ranges = <3300 3300>;
 		spi-max-frequency = <5000000>;
 		disable-wp;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0139/2077] dt-bindings: vendor-prefixes: Add Displaytech Ltd.
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (137 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0138/2077] riscv: dts: microchip: remove gpio hogs from beaglev-fire Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0140/2077] drm/gpuvm: take refcount on DRM device Greg Kroah-Hartman
                   ` (858 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Marek Vasut, Krzysztof Kozlowski,
	Neil Armstrong, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marek Vasut <marex@nabladev.com>

[ Upstream commit 42112cff8cb78ff6120983ba71bd14d52ce9dccd ]

Add "displaytech" vendor prefix for Displaytech Ltd. .

Signed-off-by: Marek Vasut <marex@nabladev.com>
Acked-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260422210806.80948-1-marex@nabladev.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/devicetree/bindings/vendor-prefixes.yaml | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/Documentation/devicetree/bindings/vendor-prefixes.yaml b/Documentation/devicetree/bindings/vendor-prefixes.yaml
index 28784d66ae7ba5..11c55b5df0e4ca 100644
--- a/Documentation/devicetree/bindings/vendor-prefixes.yaml
+++ b/Documentation/devicetree/bindings/vendor-prefixes.yaml
@@ -437,6 +437,8 @@ patternProperties:
     description: Diodes, Inc.
   "^dioo,.*":
     description: Dioo Microcircuit Co., Ltd
+  "^displaytech,.*":
+    description: Displaytech Ltd.
   "^djn,.*":
     description: Shenzhen DJN Optronics Technology Co., Ltd
   "^dlc,.*":
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0140/2077] drm/gpuvm: take refcount on DRM device
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (138 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0139/2077] dt-bindings: vendor-prefixes: Add Displaytech Ltd Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0141/2077] wifi: cfg80211: restrict LMR feedback check to TB and non-TB ranging Greg Kroah-Hartman
                   ` (857 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Danilo Krummrich, Alice Ryhl,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alice Ryhl <aliceryhl@google.com>

[ Upstream commit c2d72717e0a9dd01c6a1bac61a1462a8e04bd179 ]

Currently GPUVM relies on the owner implicitly holding a refcount to the
drm device, and it does not implicitly take a refcount on the drm
device. This design is error-prone, so take a refcount on the device.

Suggested-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Alice Ryhl <aliceryhl@google.com>
Fixes: 546ca4d35dcc ("drm/gpuvm: convert WARN() to drm_WARN() variants")
Link: https://patch.msgid.link/20260416-gpuvm-drm-dev-get-v1-1-f3bc06571e73@google.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/drm_gpuvm.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/drm_gpuvm.c b/drivers/gpu/drm/drm_gpuvm.c
index f56719e9f4350a..83020b6cf9ba15 100644
--- a/drivers/gpu/drm/drm_gpuvm.c
+++ b/drivers/gpu/drm/drm_gpuvm.c
@@ -25,6 +25,7 @@
  *
  */
 
+#include <drm/drm_drv.h>
 #include <drm/drm_gpuvm.h>
 #include <drm/drm_print.h>
 
@@ -1117,6 +1118,7 @@ drm_gpuvm_init(struct drm_gpuvm *gpuvm, const char *name,
 	gpuvm->drm = drm;
 	gpuvm->r_obj = r_obj;
 
+	drm_dev_get(drm);
 	drm_gem_object_get(r_obj);
 
 	drm_gpuvm_warn_check_overflow(gpuvm, start_offset, range);
@@ -1160,13 +1162,15 @@ static void
 drm_gpuvm_free(struct kref *kref)
 {
 	struct drm_gpuvm *gpuvm = container_of(kref, struct drm_gpuvm, kref);
+	struct drm_device *drm = gpuvm->drm;
 
 	drm_gpuvm_fini(gpuvm);
 
-	if (drm_WARN_ON(gpuvm->drm, !gpuvm->ops->vm_free))
+	if (drm_WARN_ON(drm, !gpuvm->ops->vm_free))
 		return;
 
 	gpuvm->ops->vm_free(gpuvm);
+	drm_dev_put(drm);
 }
 
 /**
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0141/2077] wifi: cfg80211: restrict LMR feedback check to TB and non-TB ranging
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (139 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0140/2077] drm/gpuvm: take refcount on DRM device Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0142/2077] drm/panel: Clean up SOFEF00 config dependencies Greg Kroah-Hartman
                   ` (856 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kavita Kavita,
	Peddolla Harshavardhan Reddy, Johannes Berg, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peddolla Harshavardhan Reddy <peddolla.reddy@oss.qualcomm.com>

[ Upstream commit bef9d5e378f07ccdf967b929897de84a9931d1e3 ]

The lmr_feedback field is only applicable to TB and non-TB ranging.
Currently, pmsr_parse_ftm() enforces lmr_feedback for all RSTA
requests, incorrectly rejecting valid EDCA-based RSTA requests.

Fix this by limiting the lmr_feedback requirement to TB and non-TB
ranging only.

Fixes: 853800c746d3 ("wifi: nl80211/cfg80211: support operating as RSTA in PMSR FTM request")
Co-developed-by: Kavita Kavita <kavita.kavita@oss.qualcomm.com>
Signed-off-by: Kavita Kavita <kavita.kavita@oss.qualcomm.com>
Signed-off-by: Peddolla Harshavardhan Reddy <peddolla.reddy@oss.qualcomm.com>
Link: https://patch.msgid.link/20260420090856.2152905-2-peddolla.reddy@oss.qualcomm.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/wireless/pmsr.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/net/wireless/pmsr.c b/net/wireless/pmsr.c
index d6cd0de64d1f84..0ca93fd7d46f8d 100644
--- a/net/wireless/pmsr.c
+++ b/net/wireless/pmsr.c
@@ -195,7 +195,9 @@ static int pmsr_parse_ftm(struct cfg80211_registered_device *rdev,
 		return -EOPNOTSUPP;
 	}
 
-	if (out->ftm.rsta && !out->ftm.lmr_feedback) {
+	if (out->ftm.rsta &&
+	    (out->ftm.non_trigger_based || out->ftm.trigger_based) &&
+	    !out->ftm.lmr_feedback) {
 		NL_SET_ERR_MSG_ATTR(info->extack,
 				    tb[NL80211_PMSR_FTM_REQ_ATTR_RSTA],
 				    "FTM: RSTA set without LMR feedback");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0142/2077] drm/panel: Clean up SOFEF00 config dependencies
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (140 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0141/2077] wifi: cfg80211: restrict LMR feedback check to TB and non-TB ranging Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0143/2077] drm/panel: Clean up S6E3FC2X01 " Greg Kroah-Hartman
                   ` (855 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Neil Armstrong, Casey Connolly,
	David Heidelberg, Marijn Suijten, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marijn Suijten <marijn.suijten@somainline.org>

[ Upstream commit e87e2357292f80d10e1a43cb910454313a5cb448 ]

As per the config name this Display IC features a DSI command-mode
interface (or the command to switch to video mode is not
known/documented) and does not use any of the video-mode helper
utilities, hence should not select VIDEOMODE_HELPERS.  In addition it
uses devm_gpiod_get() and related functions from GPIOLIB.

Fixes: 5933baa36e26 ("drm/panel/samsung-sofef00: Add panel for OnePlus 6/T devices")
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Reviewed-by: Casey Connolly <casey.connolly@linaro.org>
Reviewed-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Marijn Suijten <marijn.suijten@somainline.org>
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260505-panel-clean-up-kconfig-dep-v2-1-9cc31d6e6919@ixit.cz
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/panel/Kconfig | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/panel/Kconfig b/drivers/gpu/drm/panel/Kconfig
index d592f4f4b939a9..28802f86a538fe 100644
--- a/drivers/gpu/drm/panel/Kconfig
+++ b/drivers/gpu/drm/panel/Kconfig
@@ -982,10 +982,10 @@ config DRM_PANEL_SAMSUNG_S6E8FC0
 
 config DRM_PANEL_SAMSUNG_SOFEF00
 	tristate "Samsung SOFEF00 DSI panel controller"
+	depends on GPIOLIB
 	depends on OF
 	depends on DRM_MIPI_DSI
 	depends on BACKLIGHT_CLASS_DEVICE
-	select VIDEOMODE_HELPERS
 	help
 	  Say Y or M here if you want to enable support for the Samsung AMOLED
 	  panel SOFEF00 DDIC and connected panel.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0143/2077] drm/panel: Clean up S6E3FC2X01 config dependencies
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (141 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0142/2077] drm/panel: Clean up SOFEF00 config dependencies Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0144/2077] drm/panel: Clean up S6E3HA2 config dependencies and fill help text Greg Kroah-Hartman
                   ` (854 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Heidelberg, Neil Armstrong,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Heidelberg <david@ixit.cz>

[ Upstream commit faf497d2f1ff15756981c6e65a9c3d8bf192a969 ]

As per the config name this Display IC features a DSI command-mode
interface (or the command to switch to video mode is not
known/documented) and does not use any of the video-mode helper
utilities, hence should not select VIDEOMODE_HELPERS.  In addition it
uses devm_gpiod_get() and related functions from GPIOLIB.

Fixes: 88148c30ef26 ("drm/panel: Add Samsung S6E3FC2X01 DDIC with AMS641RW panel")
Signed-off-by: David Heidelberg <david@ixit.cz>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260505-panel-clean-up-kconfig-dep-v2-2-9cc31d6e6919@ixit.cz
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/panel/Kconfig | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/panel/Kconfig b/drivers/gpu/drm/panel/Kconfig
index 28802f86a538fe..56b4c464ec9b30 100644
--- a/drivers/gpu/drm/panel/Kconfig
+++ b/drivers/gpu/drm/panel/Kconfig
@@ -890,10 +890,10 @@ config DRM_PANEL_SAMSUNG_S6D7AA0
 
 config DRM_PANEL_SAMSUNG_S6E3FC2X01
 	tristate "Samsung S6E3FC2X01 DSI panel controller"
+	depends on GPIOLIB
 	depends on OF
 	depends on DRM_MIPI_DSI
 	depends on BACKLIGHT_CLASS_DEVICE
-	select VIDEOMODE_HELPERS
 	help
 	  Say Y or M here if you want to enable support for the
 	  Samsung S6E3FC2 DDIC and connected MIPI DSI panel.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0144/2077] drm/panel: Clean up S6E3HA2 config dependencies and fill help text
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (142 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0143/2077] drm/panel: Clean up S6E3FC2X01 " Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0145/2077] riscv: dts: microchip: update pic64gx gpio interrupts to better match the SoC Greg Kroah-Hartman
                   ` (853 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Heidelberg, Neil Armstrong,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Heidelberg <david@ixit.cz>

[ Upstream commit 632a8aa96d0717aa92cb63e3939d09b896223b4c ]

As per the config name this Display IC features a DSI command-mode
interface (or the command to switch to video mode is not
known/documented) and does not use any of the video-mode helper
utilities, hence should not select VIDEOMODE_HELPERS. In addition it
uses devm_gpiod_get() and related functions from GPIOLIB.

Fixes: 779679d3c164 ("drm/panel: Add support for S6E3HA8 panel driver")
Signed-off-by: David Heidelberg <david@ixit.cz>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260505-panel-clean-up-kconfig-dep-v2-3-9cc31d6e6919@ixit.cz
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/panel/Kconfig | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/panel/Kconfig b/drivers/gpu/drm/panel/Kconfig
index 56b4c464ec9b30..b2153e04a59af7 100644
--- a/drivers/gpu/drm/panel/Kconfig
+++ b/drivers/gpu/drm/panel/Kconfig
@@ -910,11 +910,18 @@ config DRM_PANEL_SAMSUNG_S6E3HA2
 
 config DRM_PANEL_SAMSUNG_S6E3HA8
 	tristate "Samsung S6E3HA8 DSI video mode panel"
+	depends on GPIOLIB
 	depends on OF
 	depends on DRM_MIPI_DSI
 	depends on BACKLIGHT_CLASS_DEVICE
 	select DRM_DISPLAY_DSC_HELPER
-	select VIDEOMODE_HELPERS
+	help
+	  Say Y or M here if you want to enable support for the
+	  Samsung S6E3HA8 DDIC and connected MIPI DSI panel.
+	  Currently supported panels:
+
+	    Samsung AMB577PX01 (found in the Samsung S9 smartphone)
+
 
 config DRM_PANEL_SAMSUNG_S6E63J0X03
 	tristate "Samsung S6E63J0X03 DSI command mode panel"
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0145/2077] riscv: dts: microchip: update pic64gx gpio interrupts to better match the SoC
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (143 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0144/2077] drm/panel: Clean up S6E3HA2 config dependencies and fill help text Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:56 ` [PATCH 7.1 0146/2077] riscv: dts: microchip: fix pic64gx gpio interrupt-cells Greg Kroah-Hartman
                   ` (852 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Conor Dooley, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Conor Dooley <conor.dooley@microchip.com>

[ Upstream commit 4ce4a46cdb2404bcd53ca58a18aeda673f37fbe9 ]

Just like PolarFire SoC, the same issues with GPIO interrupts exist in
the pic64gx, due to their similarity. Yoinking from the commit message
for the same change for PolarFire SoC:

There are 3 GPIO controllers on this SoC, of which:
- GPIO controller 0 has 14 GPIOs
- GPIO controller 1 has 24 GPIOs
- GPIO controller 2 has 32 GPIOs

All GPIOs are capable of generating interrupts, for a total of 70.
There are only 41 IRQs available however, so a configurable mux is used
to ensure all GPIOs can be used for interrupt generation.
38 of the 41 interrupts are in what the documentation calls "direct
mode", as they provide an exclusive connection from a GPIO to the PLIC.
The 3 remaining interrupts are used to mux the interrupts which do not
have a exclusive connection, one for each GPIO controller.

The mux was overlooked when the bindings and driver were originally
written for the GPIO controllers on Polarfire SoC, and the interrupts
property in the GPIO nodes used to try and convey what the mapping was.
Instead, the mux should be a device in its own right, and the GPIO
controllers should be connected to it, rather than to the PLIC.
Now that a binding exists for that mux, fix the inaccurate description
of the interrupt controller hierarchy.

Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
Stable-dep-of: 48c7771b3c79 ("riscv: dts: microchip: fix pic64gx gpio interrupt-cells")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../dts/microchip/pic64gx-curiosity-kit.dts   | 47 ++++++++++++-------
 arch/riscv/boot/dts/microchip/pic64gx.dtsi    | 32 +++++++++++--
 2 files changed, 58 insertions(+), 21 deletions(-)

diff --git a/arch/riscv/boot/dts/microchip/pic64gx-curiosity-kit.dts b/arch/riscv/boot/dts/microchip/pic64gx-curiosity-kit.dts
index 2f2ccd77af30ab..ed3ff03f3b11b7 100644
--- a/arch/riscv/boot/dts/microchip/pic64gx-curiosity-kit.dts
+++ b/arch/riscv/boot/dts/microchip/pic64gx-curiosity-kit.dts
@@ -63,10 +63,6 @@ hss: hss-buffer@bfc00000 {
 };
 
 &gpio0 {
-	interrupts = <13>, <14>, <15>, <16>,
-		     <17>, <18>, <19>, <20>,
-		     <21>, <22>, <23>, <24>,
-		     <25>, <26>;
 	status ="okay";
 	gpio-line-names =
 		"", "", "", "", "", "", "", "",
@@ -74,12 +70,6 @@ &gpio0 {
 };
 
 &gpio1 {
-	interrupts = <27>, <28>, <29>, <30>,
-		     <31>, <32>, <33>, <34>,
-		     <35>, <36>, <37>, <38>,
-		     <39>, <40>, <41>, <42>,
-		     <43>, <44>, <45>, <46>,
-		     <47>, <48>, <49>, <50>;
 	status ="okay";
 	gpio-line-names =
 		"", "", "LED1", "LED2", "LED3", "LED4", "LED5", "LED6",
@@ -88,14 +78,6 @@ &gpio1 {
 };
 
 &gpio2 {
-	interrupts = <53>, <53>, <53>, <53>,
-		     <53>, <53>, <53>, <53>,
-		     <53>, <53>, <53>, <53>,
-		     <53>, <53>, <53>, <53>,
-		     <53>, <53>, <53>, <53>,
-		     <53>, <53>, <53>, <53>,
-		     <53>, <53>, <53>, <53>,
-		     <53>, <53>, <53>, <53>;
 	pinctrl-names = "default";
 	pinctrl-0 = <&mdio1_gpio>, <&spi0_gpio>, <&can0_gpio>, <&pcie_gpio>,
 		    <&qspi_gpio>, <&uart3_gpio>, <&uart4_gpio>, <&can1_gpio>;
@@ -107,6 +89,35 @@ &gpio2 {
 		"DIP4", "USR_IO11", "", "", "SWITCH1", "", "", "";
 };
 
+&irqmux {
+	interrupt-map = <0 &plic 13>, <1 &plic 14>, <2 &plic 15>,
+			<3 &plic 16>, <4 &plic 17>, <5 &plic 18>,
+			<6 &plic 19>, <7 &plic 20>, <8 &plic 21>,
+			<9 &plic 22>, <10 &plic 23>, <11 &plic 24>,
+			<12 &plic 25>, <13 &plic 26>,
+
+			<32 &plic 27>, <33 &plic 28>, <34 &plic 29>,
+			<35 &plic 30>, <36 &plic 31>, <37 &plic 32>,
+			<38 &plic 33>, <39 &plic 34>, <40 &plic 35>,
+			<41 &plic 36>, <42 &plic 37>, <43 &plic 38>,
+			<44 &plic 39>, <45 &plic 40>, <46 &plic 41>,
+			<47 &plic 42>, <48 &plic 43>, <49 &plic 44>,
+			<50 &plic 45>, <51 &plic 46>, <52 &plic 47>,
+			<53 &plic 48>, <54 &plic 49>, <55 &plic 50>,
+
+			<64 &plic 53>, <65 &plic 53>, <66 &plic 53>,
+			<67 &plic 53>, <68 &plic 53>, <69 &plic 53>,
+			<70 &plic 53>, <71 &plic 53>, <72 &plic 53>,
+			<73 &plic 53>, <74 &plic 53>, <75 &plic 53>,
+			<76 &plic 53>, <77 &plic 53>, <78 &plic 53>,
+			<79 &plic 53>, <80 &plic 53>, <81 &plic 53>,
+			<82 &plic 53>, <83 &plic 53>, <84 &plic 53>,
+			<85 &plic 53>, <86 &plic 53>, <87 &plic 53>,
+			<88 &plic 53>, <89 &plic 53>, <90 &plic 53>,
+			<91 &plic 53>, <92 &plic 53>, <93 &plic 53>,
+			<94 &plic 53>, <95 &plic 53>;
+};
+
 &mac0 {
 	status = "okay";
 	phy-mode = "sgmii";
diff --git a/arch/riscv/boot/dts/microchip/pic64gx.dtsi b/arch/riscv/boot/dts/microchip/pic64gx.dtsi
index c164d7bc270a22..ed4623b29920e0 100644
--- a/arch/riscv/boot/dts/microchip/pic64gx.dtsi
+++ b/arch/riscv/boot/dts/microchip/pic64gx.dtsi
@@ -295,6 +295,14 @@ mss_top_sysreg: syscon@20002000 {
 			#size-cells = <1>;
 			#reset-cells = <1>;
 
+			irqmux: interrupt-controller@54 {
+				compatible = "microchip,pic64gx-irqmux", "microchip,mpfs-irqmux";
+				reg = <0x54 0x4>;
+				#address-cells = <0>;
+				#interrupt-cells = <1>;
+				interrupt-map-mask = <0x7f>;
+			};
+
 			iomux0: pinctrl@200 {
 				compatible = "microchip,pic64gx-pinctrl-iomux0",
 					     "microchip,mpfs-pinctrl-iomux0";
@@ -484,9 +492,13 @@ mac1: ethernet@20112000 {
 		gpio0: gpio@20120000 {
 			compatible = "microchip,pic64gx-gpio", "microchip,mpfs-gpio";
 			reg = <0x0 0x20120000 0x0 0x1000>;
-			interrupt-parent = <&plic>;
+			interrupt-parent = <&irqmux>;
 			interrupt-controller;
 			#interrupt-cells = <1>;
+			interrupts = <0>, <1>, <2>, <3>,
+				     <4>, <5>, <6>, <7>,
+				     <8>, <9>, <10>, <11>,
+				     <12>, <13>;
 			clocks = <&clkcfg CLK_GPIO0>;
 			gpio-controller;
 			#gpio-cells = <2>;
@@ -497,9 +509,15 @@ gpio0: gpio@20120000 {
 		gpio1: gpio@20121000 {
 			compatible = "microchip,pic64gx-gpio", "microchip,mpfs-gpio";
 			reg = <0x0 0x20121000 0x0 0x1000>;
-			interrupt-parent = <&plic>;
+			interrupt-parent = <&irqmux>;
 			interrupt-controller;
 			#interrupt-cells = <1>;
+			interrupts = <32>, <33>, <34>, <35>,
+				     <36>, <37>, <38>, <39>,
+				     <40>, <41>, <42>, <43>,
+				     <44>, <45>, <46>, <47>,
+				     <48>, <49>, <50>, <51>,
+				     <52>, <53>, <54>, <55>;
 			clocks = <&clkcfg CLK_GPIO1>;
 			gpio-controller;
 			#gpio-cells = <2>;
@@ -510,9 +528,17 @@ gpio1: gpio@20121000 {
 		gpio2: gpio@20122000 {
 			compatible = "microchip,pic64gx-gpio", "microchip,mpfs-gpio";
 			reg = <0x0 0x20122000 0x0 0x1000>;
-			interrupt-parent = <&plic>;
+			interrupt-parent = <&irqmux>;
 			interrupt-controller;
 			#interrupt-cells = <1>;
+			interrupts = <64>, <65>, <66>, <67>,
+				     <68>, <69>, <70>, <71>,
+				     <72>, <73>, <74>, <75>,
+				     <76>, <77>, <78>, <79>,
+				     <80>, <81>, <82>, <83>,
+				     <84>, <85>, <86>, <87>,
+				     <88>, <89>, <90>, <91>,
+				     <92>, <93>, <94>, <95>;
 			clocks = <&clkcfg CLK_GPIO2>;
 			gpio-controller;
 			#gpio-cells = <2>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0146/2077] riscv: dts: microchip: fix pic64gx gpio interrupt-cells
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (144 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0145/2077] riscv: dts: microchip: update pic64gx gpio interrupts to better match the SoC Greg Kroah-Hartman
@ 2026-07-21 14:56 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0147/2077] arm64: dts: marvell: samsung-coreprimevelte: Increase touchscreen voltage Greg Kroah-Hartman
                   ` (851 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:56 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Conor Dooley, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Conor Dooley <conor.dooley@microchip.com>

[ Upstream commit 48c7771b3c792b153872a2eff67e4cbcb77e4054 ]

As the pic64gx devicetree files got added in parallel to the
GPIO interrupt-cells being fixed for PolarFire SoC, they didn't get
changed to the correct values. Fix them now.

Fixes: 7219d20f9f421 ("riscv: dts: microchip: add pic64gx and its curiosity kit")
Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/boot/dts/microchip/pic64gx.dtsi | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/arch/riscv/boot/dts/microchip/pic64gx.dtsi b/arch/riscv/boot/dts/microchip/pic64gx.dtsi
index ed4623b29920e0..e6a24cc5715fad 100644
--- a/arch/riscv/boot/dts/microchip/pic64gx.dtsi
+++ b/arch/riscv/boot/dts/microchip/pic64gx.dtsi
@@ -494,7 +494,7 @@ gpio0: gpio@20120000 {
 			reg = <0x0 0x20120000 0x0 0x1000>;
 			interrupt-parent = <&irqmux>;
 			interrupt-controller;
-			#interrupt-cells = <1>;
+			#interrupt-cells = <2>;
 			interrupts = <0>, <1>, <2>, <3>,
 				     <4>, <5>, <6>, <7>,
 				     <8>, <9>, <10>, <11>,
@@ -511,7 +511,7 @@ gpio1: gpio@20121000 {
 			reg = <0x0 0x20121000 0x0 0x1000>;
 			interrupt-parent = <&irqmux>;
 			interrupt-controller;
-			#interrupt-cells = <1>;
+			#interrupt-cells = <2>;
 			interrupts = <32>, <33>, <34>, <35>,
 				     <36>, <37>, <38>, <39>,
 				     <40>, <41>, <42>, <43>,
@@ -530,7 +530,7 @@ gpio2: gpio@20122000 {
 			reg = <0x0 0x20122000 0x0 0x1000>;
 			interrupt-parent = <&irqmux>;
 			interrupt-controller;
-			#interrupt-cells = <1>;
+			#interrupt-cells = <2>;
 			interrupts = <64>, <65>, <66>, <67>,
 				     <68>, <69>, <70>, <71>,
 				     <72>, <73>, <74>, <75>,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0147/2077] arm64: dts: marvell: samsung-coreprimevelte: Increase touchscreen voltage
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (145 preceding siblings ...)
  2026-07-21 14:56 ` [PATCH 7.1 0146/2077] riscv: dts: microchip: fix pic64gx gpio interrupt-cells Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0148/2077] ARM: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware Greg Kroah-Hartman
                   ` (850 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Karel Balej, Duje Mihanović,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Duje Mihanović <duje@dujemihanovic.xyz>

[ Upstream commit 4da515eca1b8de56c9e8a17866626f99d9bccbc7 ]

The old 1.9V setting was found to be insufficient in certain
environments (in my case cold ones), causing the touchscreen to register
ghost touches and mostly ignore actual touches. Increase the voltage to
2.5V to correct the issue.

Fixes: ec958b5b18c8 ("arm64: dts: samsung,coreprimevelte: add touchscreen")
Acked-by: Karel Balej <balejk@matfyz.cz>
Signed-off-by: Duje Mihanović <duje@dujemihanovic.xyz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../boot/dts/marvell/mmp/pxa1908-samsung-coreprimevelte.dts     | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/marvell/mmp/pxa1908-samsung-coreprimevelte.dts b/arch/arm64/boot/dts/marvell/mmp/pxa1908-samsung-coreprimevelte.dts
index b2ce5edd9c6ac6..bb0a993996241d 100644
--- a/arch/arm64/boot/dts/marvell/mmp/pxa1908-samsung-coreprimevelte.dts
+++ b/arch/arm64/boot/dts/marvell/mmp/pxa1908-samsung-coreprimevelte.dts
@@ -460,7 +460,7 @@ pmic@30 {
 
 		regulators {
 			ldo2: ldo2 {
-				regulator-min-microvolt = <1900000>;
+				regulator-min-microvolt = <2500000>;
 				regulator-max-microvolt = <3100000>;
 			};
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0148/2077] ARM: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (146 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0147/2077] arm64: dts: marvell: samsung-coreprimevelte: Increase touchscreen voltage Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0149/2077] arm64: " Greg Kroah-Hartman
                   ` (849 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Brian Norris, Douglas Anderson,
	Heiko Stuebner, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Brian Norris <briannorris@chromium.org>

[ Upstream commit 98461edf564a35ee00a97a64f5463eaece586546 ]

Chromium/Depthcharge bootloaders may dynamically add a few device nodes
to a system's DTB under a /firmware node. A typical DT looks something
like the following:

/ {
	firmware {
		ranges;

		coreboot {
			compatible = "coreboot";
			reg = <...>;
			...;
		};
	};
};

Notably, the /firmware node has an empty 'ranges', but does not have
address/size-cells.

Commit 6e5773d52f4a ("of/address: Fix WARN when attempting translating
non-translatable addresses") started requiring #address-cells for a
device's parent if we want to use the reg resource in a device node.
This leads to errors like the following:

[    7.763870] coreboot_table firmware:coreboot: probe with driver coreboot_table failed with error -22

Add appropriate #{address,size}-cells to work around the problem.

Note that Google has also patched the Depthcharge bootloader source to
add {address,size}-cells [1], but bootloader updates are typically
delivered only via Google OS updates. Not all users install Google
software updates, and even if they do, Google may not produce updated
binaries for all/older devices.

[1] https://lore.kernel.org/all/20241209092809.GA3246424@google.com/
    https://crrev.com/c/6051580 ("coreboot: Insert #address-cells and
    #size-cells for firmware node")

Closes: https://lore.kernel.org/all/aeKlYzTiL0OB1y3g@google.com/
Fixes: 6e5773d52f4a ("of/address: Fix WARN when attempting translating non-translatable addresses")
Signed-off-by: Brian Norris <briannorris@chromium.org>
Reviewed-by: Douglas Anderson <dianders@chromium.org>
[On RK288-based Chromebooks there is no real other way than to load the
 DTB  together with its kernel when running a mainline kernel and as the
 whole line is EOL, there also won't be any updates to the bootloader that
 could fix that issue there.]
Link: https://patch.msgid.link/20260428200712.2660635-3-briannorris@chromium.org
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm/boot/dts/rockchip/rk3288-veyron.dtsi | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/arch/arm/boot/dts/rockchip/rk3288-veyron.dtsi b/arch/arm/boot/dts/rockchip/rk3288-veyron.dtsi
index 2d6cf08d00f906..ca8e8e73507819 100644
--- a/arch/arm/boot/dts/rockchip/rk3288-veyron.dtsi
+++ b/arch/arm/boot/dts/rockchip/rk3288-veyron.dtsi
@@ -18,6 +18,11 @@ chosen {
 		stdout-path = "serial2:115200n8";
 	};
 
+	firmware {
+		#address-cells = <1>;
+		#size-cells = <1>;
+	};
+
 	/*
 	 * The default coreboot on veyron devices ignores memory@0 nodes
 	 * and would instead create another memory node.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0149/2077] arm64: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (147 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0148/2077] ARM: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0150/2077] arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc Greg Kroah-Hartman
                   ` (848 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Brian Norris, Douglas Anderson,
	Chen-Yu Tsai, Heiko Stuebner, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Brian Norris <briannorris@chromium.org>

[ Upstream commit 0b74f1a037672980c477bbe6b3848fb5341eb4f1 ]

Chromium/Depthcharge bootloaders may dynamically add a few device nodes
to a system's DTB under a /firmware node. A typical DT looks something
like the following:

  ## From a RK3399 Gru/Kevin Chromebook:
  # find /sys/firmware/devicetree/base/firmware
  /sys/firmware/devicetree/base/firmware
  /sys/firmware/devicetree/base/firmware/coreboot
  /sys/firmware/devicetree/base/firmware/coreboot/ram-code
  /sys/firmware/devicetree/base/firmware/coreboot/compatible
  /sys/firmware/devicetree/base/firmware/coreboot/board-id
  /sys/firmware/devicetree/base/firmware/coreboot/reg
  /sys/firmware/devicetree/base/firmware/coreboot/name
  /sys/firmware/devicetree/base/firmware/chromeos
  /sys/firmware/devicetree/base/firmware/chromeos/readonly-firmware-version
  /sys/firmware/devicetree/base/firmware/chromeos/active-ec-firmware
  /sys/firmware/devicetree/base/firmware/chromeos/firmware-version
  /sys/firmware/devicetree/base/firmware/chromeos/nonvolatile-context-storage
  /sys/firmware/devicetree/base/firmware/chromeos/vboot-shared-data
  /sys/firmware/devicetree/base/firmware/chromeos/nonvolatile-context-size
  /sys/firmware/devicetree/base/firmware/chromeos/nonvolatile-context-offset
  /sys/firmware/devicetree/base/firmware/chromeos/hardware-id
  /sys/firmware/devicetree/base/firmware/chromeos/compatible
  /sys/firmware/devicetree/base/firmware/chromeos/firmware-type
  /sys/firmware/devicetree/base/firmware/chromeos/fmap-offset
  /sys/firmware/devicetree/base/firmware/chromeos/name
  /sys/firmware/devicetree/base/firmware/ranges
  /sys/firmware/devicetree/base/firmware/name

The /firmware node has an empty 'ranges', but does not have
address/size-cells.

Commit 6e5773d52f4a ("of/address: Fix WARN when attempting translating
non-translatable addresses") started requiring #address-cells for a
device's parent if we want to use the reg resource in a device node.
This leads to errors like the following:

[    7.763870] coreboot_table firmware:coreboot: probe with driver coreboot_table failed with error -22

Add appropriate #{address,size}-cells to work around the problem.

Note that Google has also patched the Depthcharge bootloader source to
add {address,size}-cells [1], but bootloader updates are typically
delivered only via Google OS updates. Not all users install Google
software updates, and even if they do, Google may not produce updated
binaries for all/older devices.

[1] https://lore.kernel.org/all/20241209092809.GA3246424@google.com/
    https://crrev.com/c/6051580 ("coreboot: Insert #address-cells and
    #size-cells for firmware node")

Closes: https://lore.kernel.org/all/aeKlYzTiL0OB1y3g@google.com/
Fixes: 6e5773d52f4a ("of/address: Fix WARN when attempting translating non-translatable addresses")
Signed-off-by: Brian Norris <briannorris@chromium.org>
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Reviewed-by: Chen-Yu Tsai <wenst@chromium.org>
[On RK3399-based Chromebooks there is no real other way than to load the
 DTB  together with its kernel when running a mainline kernel and as the
 whole line is EOL, there also won't be any updates to the bootloader that
 could fix that issue there.]
Link: https://patch.msgid.link/20260428200712.2660635-2-briannorris@chromium.org
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/rockchip/rk3399-gru.dtsi | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/arch/arm64/boot/dts/rockchip/rk3399-gru.dtsi b/arch/arm64/boot/dts/rockchip/rk3399-gru.dtsi
index 7eca1da78cffab..2f9e39671efc05 100644
--- a/arch/arm64/boot/dts/rockchip/rk3399-gru.dtsi
+++ b/arch/arm64/boot/dts/rockchip/rk3399-gru.dtsi
@@ -18,6 +18,11 @@ chosen {
 		stdout-path = "serial2:115200n8";
 	};
 
+	firmware {
+		#address-cells = <2>;
+		#size-cells = <2>;
+	};
+
 	/*
 	 * Power Tree
 	 *
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0150/2077] arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (148 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0149/2077] arm64: " Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0151/2077] arm64: dts: imx8x-colibri: Correct SODIMM PAD settings Greg Kroah-Hartman
                   ` (847 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Weixin Guo, Heiko Stuebner,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Weixin Guo <2298701336@qq.com>

[ Upstream commit 460bac478c5fe69054ffc60d607bba03bcaf909b ]

The RK809 PMIC interrupt pin on the Firefly ROC-RK3566-PC (Station M2)
is physically connected to GPIO0_A3 (RK_PA3) according to the board's
schematic.

Currently, the PMIC node incorrectly specifies RK_PA7 for the interrupt,
which prevents the PMIC from correctly signaling interrupts. (Note that
the pinctrl node 'pmic_int' correctly configures RK_PA3).

Fix this by updating the interrupts property to use RK_PA3.

Fixes: 30ac9b4e25d8 ("arm64: dts: rockchip: add dts for Firefly Station M2 rk3566")
Signed-off-by: Weixin Guo <2298701336@qq.com>
Link: https://patch.msgid.link/tencent_5035EEE630C845B1B51DEA4284DE23DCCE06@qq.com
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/rockchip/rk3566-roc-pc.dts | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/rockchip/rk3566-roc-pc.dts b/arch/arm64/boot/dts/rockchip/rk3566-roc-pc.dts
index 7e499064e03579..985770e3a5e2cc 100644
--- a/arch/arm64/boot/dts/rockchip/rk3566-roc-pc.dts
+++ b/arch/arm64/boot/dts/rockchip/rk3566-roc-pc.dts
@@ -245,7 +245,7 @@ rk809: pmic@20 {
 		compatible = "rockchip,rk809";
 		reg = <0x20>;
 		interrupt-parent = <&gpio0>;
-		interrupts = <RK_PA7 IRQ_TYPE_LEVEL_LOW>;
+		interrupts = <RK_PA3 IRQ_TYPE_LEVEL_LOW>;
 		clock-output-names = "rk808-clkout1", "rk808-clkout2";
 		assigned-clocks = <&cru I2S1_MCLKOUT_TX>;
 		assigned-clock-parents = <&cru CLK_I2S1_8CH_TX>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0151/2077] arm64: dts: imx8x-colibri: Correct SODIMM PAD settings
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (149 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0150/2077] arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0152/2077] arm64: dts: imx8mn-vhip4-evalboard-v1: Correct interrupt flags Greg Kroah-Hartman
                   ` (846 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Peng Fan, Daniel Baluta,
	Alexander Stein, Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peng Fan <peng.fan@nxp.com>

[ Upstream commit 0a03ee38a262cab0d9754e9947d565e089a9f7a5 ]

SION is BIT(30), not BIT(26). Correct it.

Fixes: 7ece3cbc8b1ef ("arm64: dts: colibri-imx8x: Add atmel pinctrl groups")
Signed-off-by: Peng Fan <peng.fan@nxp.com>
Reviewed-by: Daniel Baluta <daniel.baluta@nxp.com>
Reviewed-by: Alexander Stein <alexander.stein@ew.tq-group.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx8x-colibri.dtsi | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/arm64/boot/dts/freescale/imx8x-colibri.dtsi b/arch/arm64/boot/dts/freescale/imx8x-colibri.dtsi
index 47895ff8cb244e..2415487d3a5dea 100644
--- a/arch/arm64/boot/dts/freescale/imx8x-colibri.dtsi
+++ b/arch/arm64/boot/dts/freescale/imx8x-colibri.dtsi
@@ -631,12 +631,12 @@ pinctrl_adc0: adc0grp {
 	 */
 	pinctrl_atmel_adap: atmeladaptergrp {
 		fsl,pins = <IMX8QXP_UART1_RX_LSIO_GPIO0_IO22			0x21>,		/* SODIMM  30 */
-			   <IMX8QXP_UART1_TX_LSIO_GPIO0_IO21			0x4000021>;	/* SODIMM  28 */
+			   <IMX8QXP_UART1_TX_LSIO_GPIO0_IO21			0x40000021>;	/* SODIMM  28 */
 	};
 
 	/* Atmel MXT touchsceen + boards with built-in Capacitive Touch Connector */
 	pinctrl_atmel_conn: atmelconnectorgrp {
-		fsl,pins = <IMX8QXP_QSPI0B_DATA2_LSIO_GPIO3_IO20		0x4000021>,	/* SODIMM 107 */
+		fsl,pins = <IMX8QXP_QSPI0B_DATA2_LSIO_GPIO3_IO20		0x40000021>,	/* SODIMM 107 */
 			   <IMX8QXP_QSPI0B_SS1_B_LSIO_GPIO3_IO24		0x21>;		/* SODIMM 106 */
 	};
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0152/2077] arm64: dts: imx8mn-vhip4-evalboard-v1: Correct interrupt flags
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (150 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0151/2077] arm64: dts: imx8x-colibri: Correct SODIMM PAD settings Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0153/2077] arm64: dts: imx8mn-vhip4-evalboard-v2: " Greg Kroah-Hartman
                   ` (845 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Marek Vasut,
	Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit 895e7756cdc1ba6467eb37eba31c1358243f6ad9 ]

GPIO_ACTIVE_x flags are not correct in the context of interrupt flags.
These are simple defines so they could be used in DTS but they will not
have the same meaning:
1. GPIO_ACTIVE_HIGH = 0 => IRQ_TYPE_NONE
2. GPIO_ACTIVE_LOW  = 1 => IRQ_TYPE_EDGE_RISING

Correct the interrupt flags, assuming the author of the code wanted the
same logical behavior behind the name "ACTIVE_xxx", this is:
ACTIVE_LOW  => IRQ_TYPE_LEVEL_LOW

Fixes: 5eb7405db99b ("arm64: dts: imx8mn: Add ifm VHIP4 EvalBoard v1 and v2")
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Marek Vasut <marex@nabladev.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx8mn-vhip4-evalboard-v1.dts | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/freescale/imx8mn-vhip4-evalboard-v1.dts b/arch/arm64/boot/dts/freescale/imx8mn-vhip4-evalboard-v1.dts
index 5f37065bf43f38..a8f7c226a61f86 100644
--- a/arch/arm64/boot/dts/freescale/imx8mn-vhip4-evalboard-v1.dts
+++ b/arch/arm64/boot/dts/freescale/imx8mn-vhip4-evalboard-v1.dts
@@ -112,7 +112,7 @@ &i2c3 {
 
 &ifm_pmic {
 	interrupt-parent = <&gpio2>;
-	interrupts = <0 GPIO_ACTIVE_LOW>;
+	interrupts = <0 IRQ_TYPE_LEVEL_LOW>;
 };
 
 &iomuxc {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0153/2077] arm64: dts: imx8mn-vhip4-evalboard-v2: Correct interrupt flags
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (151 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0152/2077] arm64: dts: imx8mn-vhip4-evalboard-v1: Correct interrupt flags Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0154/2077] arm64: dts: imx8mp-ab2: " Greg Kroah-Hartman
                   ` (844 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Marek Vasut,
	Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit 7263f1acdd33169e1558064ee9a98758921f3bec ]

GPIO_ACTIVE_x flags are not correct in the context of interrupt flags.
These are simple defines so they could be used in DTS but they will not
have the same meaning:
1. GPIO_ACTIVE_HIGH = 0 => IRQ_TYPE_NONE
2. GPIO_ACTIVE_LOW  = 1 => IRQ_TYPE_EDGE_RISING

Correct the interrupt flags, assuming the author of the code wanted the
same logical behavior behind the name "ACTIVE_xxx", this is:
ACTIVE_LOW  => IRQ_TYPE_LEVEL_LOW

Fixes: 5eb7405db99b ("arm64: dts: imx8mn: Add ifm VHIP4 EvalBoard v1 and v2")
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Marek Vasut <marex@nabladev.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx8mn-vhip4-evalboard-v2.dts | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/freescale/imx8mn-vhip4-evalboard-v2.dts b/arch/arm64/boot/dts/freescale/imx8mn-vhip4-evalboard-v2.dts
index 4dadfb7f78de27..43fd4d0041ef30 100644
--- a/arch/arm64/boot/dts/freescale/imx8mn-vhip4-evalboard-v2.dts
+++ b/arch/arm64/boot/dts/freescale/imx8mn-vhip4-evalboard-v2.dts
@@ -99,7 +99,7 @@ &i2c3 {
 
 &ifm_pmic {
 	interrupt-parent = <&gpio5>;
-	interrupts = <17 GPIO_ACTIVE_LOW>;
+	interrupts = <17 IRQ_TYPE_LEVEL_LOW>;
 };
 
 &iomuxc {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0154/2077] arm64: dts: imx8mp-ab2: Correct interrupt flags
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (152 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0153/2077] arm64: dts: imx8mn-vhip4-evalboard-v2: " Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0155/2077] Revert "arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL signal" Greg Kroah-Hartman
                   ` (843 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Shengjiu Wang,
	Daniel Baluta, Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit eb27f9b9a4b2965f8d497a3c565cfbc2473c184b ]

GPIO_ACTIVE_x flags are not correct in the context of interrupt flags.
These are simple defines so they could be used in DTS but they will not
have the same meaning:
1. GPIO_ACTIVE_HIGH = 0 => IRQ_TYPE_NONE
2. GPIO_ACTIVE_LOW  = 1 => IRQ_TYPE_EDGE_RISING

Correct the interrupt flags, assuming the author of the code wanted the
same logical behavior behind the name "ACTIVE_xxx", this is:
ACTIVE_LOW  => IRQ_TYPE_LEVEL_LOW

Fixes: bf68c18150ef ("arm64: dts: imx8mp-ab2: add support for NXP i.MX8MP audio board (version 2)")
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Shengjiu Wang <shengjiu.wang@nxp.com>
Reviewed-by: Daniel Baluta <daniel.baluta@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx8mp-ab2.dts | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/freescale/imx8mp-ab2.dts b/arch/arm64/boot/dts/freescale/imx8mp-ab2.dts
index dbbc0df0e3d1c7..443e4fd5b9bfc1 100644
--- a/arch/arm64/boot/dts/freescale/imx8mp-ab2.dts
+++ b/arch/arm64/boot/dts/freescale/imx8mp-ab2.dts
@@ -281,7 +281,7 @@ pca9450: pmic@25 {
 		compatible = "nxp,pca9450c";
 		reg = <0x25>;
 		interrupt-parent = <&gpio1>;
-		interrupts = <3 GPIO_ACTIVE_LOW>;
+		interrupts = <3 IRQ_TYPE_LEVEL_LOW>;
 		pinctrl-0 = <&pinctrl_pmic>;
 
 		regulators {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0155/2077] Revert "arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL signal"
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (153 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0154/2077] arm64: dts: imx8mp-ab2: " Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0156/2077] Revert "arm64: dts: imx8mp-kontron: " Greg Kroah-Hartman
                   ` (842 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peng Fan, Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peng Fan <peng.fan@nxp.com>

[ Upstream commit aa907ee010e396c0c0d31d60495ace6e531ceec9 ]

This reverts commit 8472751c4d96b558d60d0f6aede6b24b64bcb3c9.

The board uses SDHC VSELECT to automatically switch between 1.8v and
3.3v. It does not use GPIO to control the PMIC SD_VSEL signal.
The original commit intends to read back SD_VSEL value from GPIO,
but it is wrong. When MUX is configured as SDHC VSELECT, it is
impossible to read back the value from GPIO controller. Setting SION
could only enable the input path for the mux function. It could not
redirect the input to GPIO.

And value "0x40000d0" is wrong, SION is BIT30, not BIT26.

Fixes: 8472751c4d96b ("arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL signal")
Signed-off-by: Peng Fan <peng.fan@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx8mm-kontron-bl.dts    | 10 +++-------
 .../arm64/boot/dts/freescale/imx8mm-kontron-osm-s.dtsi |  7 +++----
 2 files changed, 6 insertions(+), 11 deletions(-)

diff --git a/arch/arm64/boot/dts/freescale/imx8mm-kontron-bl.dts b/arch/arm64/boot/dts/freescale/imx8mm-kontron-bl.dts
index e756fe5db56b6a..dd59af0ebaae55 100644
--- a/arch/arm64/boot/dts/freescale/imx8mm-kontron-bl.dts
+++ b/arch/arm64/boot/dts/freescale/imx8mm-kontron-bl.dts
@@ -254,10 +254,6 @@ &pwm2 {
 	status = "okay";
 };
 
-&reg_nvcc_sd {
-	sd-vsel-gpios = <&gpio1 4 GPIO_ACTIVE_HIGH>;
-};
-
 &uart1 {
 	pinctrl-names = "default";
 	pinctrl-0 = <&pinctrl_uart1>;
@@ -466,7 +462,7 @@ MX8MM_IOMUXC_SD2_DATA1_USDHC2_DATA1		0x1d0
 			MX8MM_IOMUXC_SD2_DATA2_USDHC2_DATA2		0x1d0
 			MX8MM_IOMUXC_SD2_DATA3_USDHC2_DATA3		0x1d0
 			MX8MM_IOMUXC_SD2_CD_B_GPIO2_IO12		0x19
-			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0x40000d0
+			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0xd0
 		>;
 	};
 
@@ -479,7 +475,7 @@ MX8MM_IOMUXC_SD2_DATA1_USDHC2_DATA1		0x1d4
 			MX8MM_IOMUXC_SD2_DATA2_USDHC2_DATA2		0x1d4
 			MX8MM_IOMUXC_SD2_DATA3_USDHC2_DATA3		0x1d4
 			MX8MM_IOMUXC_SD2_CD_B_GPIO2_IO12		0x19
-			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0x40000d0
+			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0xd0
 		>;
 	};
 
@@ -492,7 +488,7 @@ MX8MM_IOMUXC_SD2_DATA1_USDHC2_DATA1		0x1d6
 			MX8MM_IOMUXC_SD2_DATA2_USDHC2_DATA2		0x1d6
 			MX8MM_IOMUXC_SD2_DATA3_USDHC2_DATA3		0x1d6
 			MX8MM_IOMUXC_SD2_CD_B_GPIO2_IO12		0x19
-			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0x40000d0
+			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0xd0
 		>;
 	};
 };
diff --git a/arch/arm64/boot/dts/freescale/imx8mm-kontron-osm-s.dtsi b/arch/arm64/boot/dts/freescale/imx8mm-kontron-osm-s.dtsi
index 96987910609f1b..4fb13d8ecfd45a 100644
--- a/arch/arm64/boot/dts/freescale/imx8mm-kontron-osm-s.dtsi
+++ b/arch/arm64/boot/dts/freescale/imx8mm-kontron-osm-s.dtsi
@@ -342,7 +342,6 @@ reg_nvcc_sd: LDO5 {
 				regulator-name = "NVCC_SD (LDO5)";
 				regulator-min-microvolt = <1800000>;
 				regulator-max-microvolt = <3300000>;
-				sd-vsel-gpios = <&gpio1 4 GPIO_ACTIVE_HIGH>;
 			};
 		};
 	};
@@ -795,7 +794,7 @@ MX8MM_IOMUXC_SD2_DATA1_USDHC2_DATA1		0x1d0 /* SDIO_A_D1 */
 			MX8MM_IOMUXC_SD2_DATA2_USDHC2_DATA2		0x1d0 /* SDIO_A_D2 */
 			MX8MM_IOMUXC_SD2_DATA3_USDHC2_DATA3		0x1d0 /* SDIO_A_D3 */
 			MX8MM_IOMUXC_SD2_WP_USDHC2_WP			0x400000d6 /* SDIO_A_WP */
-			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0x40000090
+			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0x90
 		>;
 	};
 
@@ -808,7 +807,7 @@ MX8MM_IOMUXC_SD2_DATA1_USDHC2_DATA1		0x1d4 /* SDIO_A_D1 */
 			MX8MM_IOMUXC_SD2_DATA2_USDHC2_DATA2		0x1d4 /* SDIO_A_D2 */
 			MX8MM_IOMUXC_SD2_DATA3_USDHC2_DATA3		0x1d4 /* SDIO_A_D3 */
 			MX8MM_IOMUXC_SD2_WP_USDHC2_WP			0x400000d6 /* SDIO_A_WP */
-			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0x40000090
+			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0x90
 		>;
 	};
 
@@ -821,7 +820,7 @@ MX8MM_IOMUXC_SD2_DATA1_USDHC2_DATA1		0x1d6 /* SDIO_A_D1 */
 			MX8MM_IOMUXC_SD2_DATA2_USDHC2_DATA2		0x1d6 /* SDIO_A_D2 */
 			MX8MM_IOMUXC_SD2_DATA3_USDHC2_DATA3		0x1d6 /* SDIO_A_D3 */
 			MX8MM_IOMUXC_SD2_WP_USDHC2_WP			0x400000d6 /* SDIO_A_WP */
-			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0x40000090
+			MX8MM_IOMUXC_GPIO1_IO04_USDHC2_VSELECT		0x90
 		>;
 	};
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0156/2077] Revert "arm64: dts: imx8mp-kontron: Add support for reading SD_VSEL signal"
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (154 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0155/2077] Revert "arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL signal" Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0157/2077] vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() Greg Kroah-Hartman
                   ` (841 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peng Fan, Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peng Fan <peng.fan@nxp.com>

[ Upstream commit 22465a195af370ed6311be3adee479fb7c683685 ]

This reverts commit 39e4189d9d63a0b6fc15458ce0136e99ecdfb1b8.

The board uses SDHC VSELECT to automatically switch between 1.8v and
3.3v. It does not use GPIO to control the PMIC SD_VSEL signal.
The original commit intends to read back SD_VSEL value from GPIO,
but it is wrong. When MUX is configured as SDHC VSELECT, it is
impossible to read back the value from GPIO controller. Setting SION
could only enable the input path for the mux function. It could not
redirect the input to GPIO.

Fixes: 39e4189d9d63a ("arm64: dts: imx8mp-kontron: Add support for reading SD_VSEL signal")
Signed-off-by: Peng Fan <peng.fan@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx8mp-kontron-osm-s.dtsi | 7 +++----
 1 file changed, 3 insertions(+), 4 deletions(-)

diff --git a/arch/arm64/boot/dts/freescale/imx8mp-kontron-osm-s.dtsi b/arch/arm64/boot/dts/freescale/imx8mp-kontron-osm-s.dtsi
index bc1a261bb000ed..ea69c639b30b8f 100644
--- a/arch/arm64/boot/dts/freescale/imx8mp-kontron-osm-s.dtsi
+++ b/arch/arm64/boot/dts/freescale/imx8mp-kontron-osm-s.dtsi
@@ -311,7 +311,6 @@ reg_nvcc_sd: LDO5 {
 				regulator-name = "NVCC_SD (LDO5)";
 				regulator-min-microvolt = <1800000>;
 				regulator-max-microvolt = <3300000>;
-				sd-vsel-gpios = <&gpio1 4 GPIO_ACTIVE_HIGH>;
 			};
 		};
 	};
@@ -815,7 +814,7 @@ MX8MP_IOMUXC_SD2_DATA0__USDHC2_DATA0		0x1d0 /* SDIO_A_D0 */
 			MX8MP_IOMUXC_SD2_DATA1__USDHC2_DATA1		0x1d0 /* SDIO_A_D1 */
 			MX8MP_IOMUXC_SD2_DATA2__USDHC2_DATA2		0x1d0 /* SDIO_A_D2 */
 			MX8MP_IOMUXC_SD2_DATA3__USDHC2_DATA3		0x1d0 /* SDIO_A_D3 */
-			MX8MP_IOMUXC_GPIO1_IO04__USDHC2_VSELECT		0x400001d0
+			MX8MP_IOMUXC_GPIO1_IO04__USDHC2_VSELECT		0x1d0
 		>;
 	};
 
@@ -827,7 +826,7 @@ MX8MP_IOMUXC_SD2_DATA0__USDHC2_DATA0		0x1d4 /* SDIO_A_D0 */
 			MX8MP_IOMUXC_SD2_DATA1__USDHC2_DATA1		0x1d4 /* SDIO_A_D1 */
 			MX8MP_IOMUXC_SD2_DATA2__USDHC2_DATA2		0x1d4 /* SDIO_A_D2 */
 			MX8MP_IOMUXC_SD2_DATA3__USDHC2_DATA3		0x1d4 /* SDIO_A_D3 */
-			MX8MP_IOMUXC_GPIO1_IO04__USDHC2_VSELECT		0x400001d0
+			MX8MP_IOMUXC_GPIO1_IO04__USDHC2_VSELECT		0x1d0
 		>;
 	};
 
@@ -839,7 +838,7 @@ MX8MP_IOMUXC_SD2_DATA0__USDHC2_DATA0		0x1d6 /* SDIO_A_D0 */
 			MX8MP_IOMUXC_SD2_DATA1__USDHC2_DATA1		0x1d6 /* SDIO_A_D1 */
 			MX8MP_IOMUXC_SD2_DATA2__USDHC2_DATA2		0x1d6 /* SDIO_A_D2 */
 			MX8MP_IOMUXC_SD2_DATA3__USDHC2_DATA3		0x1d6 /* SDIO_A_D3 */
-			MX8MP_IOMUXC_GPIO1_IO04__USDHC2_VSELECT		0x400001d0
+			MX8MP_IOMUXC_GPIO1_IO04__USDHC2_VSELECT		0x1d0
 		>;
 	};
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0157/2077] vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (155 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0156/2077] Revert "arm64: dts: imx8mp-kontron: " Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0158/2077] drm: renesas: rz-du: mipi_dsi: Fix return path on error Greg Kroah-Hartman
                   ` (840 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kuniyuki Iwashima <kuniyu@google.com>

[ Upstream commit 30a45c0bffdd62350261e2f2689fdba426a33578 ]

udp_tunnel_sock_release() could set sk->sk_user_data to NULL
while vxlan_gro_prepare_receive() is running.

Let's check if rcu_dereference_sk_user_data() is NULL after
skb_gro_remcsum_init().

Fixes: 5602c48cf875 ("vxlan: change vxlan to use UDP socket GRO")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20260502031401.3557229-7-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/vxlan/vxlan_core.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
index b5b1253ac08ba4..89397447a14d45 100644
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -657,14 +657,18 @@ static struct vxlanhdr *vxlan_gro_prepare_receive(struct sock *sk,
 						  struct sk_buff *skb,
 						  struct gro_remcsum *grc)
 {
-	struct sk_buff *p;
 	struct vxlanhdr *vh, *vh2;
 	unsigned int hlen, off_vx;
-	struct vxlan_sock *vs = rcu_dereference_sk_user_data(sk);
+	struct vxlan_sock *vs;
+	struct sk_buff *p;
 	__be32 flags;
 
 	skb_gro_remcsum_init(grc);
 
+	vs = rcu_dereference_sk_user_data(sk);
+	if (!vs)
+		return NULL;
+
 	off_vx = skb_gro_offset(skb);
 	hlen = off_vx + sizeof(*vh);
 	vh = skb_gro_header(skb, hlen, off_vx);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0158/2077] drm: renesas: rz-du: mipi_dsi: Fix return path on error
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (156 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0157/2077] vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0159/2077] alarmtimer: Remove stale return description from alarm_handle_timer() Greg Kroah-Hartman
                   ` (839 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Pavel Machek, Chris Brandt, Biju Das,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chris Brandt <chris.brandt@renesas.com>

[ Upstream commit 79e1afecfe1afbfd06f63bf7bbe854a88155b7bd ]

In case of error, we should unwind correctly.
Switching to using dmam_ instead of dma_ and moving the code earlier
fixes the issue.

Fixes: 6f392f371650 ("drm: renesas: rz-du: Implement MIPI DSI host transfers")
Suggested-by: Pavel Machek <pavel@nabladev.com>
Signed-off-by: Chris Brandt <chris.brandt@renesas.com>
Reviewed-by: Biju Das <biju.das.jz@bp.renesas.com>
Link: https://patch.msgid.link/20260501132135.196701-1-chris.brandt@renesas.com
Signed-off-by: Biju Das <biju.das.jz@bp.renesas.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/renesas/rz-du/rzg2l_mipi_dsi.c | 12 +++++-------
 1 file changed, 5 insertions(+), 7 deletions(-)

diff --git a/drivers/gpu/drm/renesas/rz-du/rzg2l_mipi_dsi.c b/drivers/gpu/drm/renesas/rz-du/rzg2l_mipi_dsi.c
index a87a301326c7aa..0d0cf10225bb56 100644
--- a/drivers/gpu/drm/renesas/rz-du/rzg2l_mipi_dsi.c
+++ b/drivers/gpu/drm/renesas/rz-du/rzg2l_mipi_dsi.c
@@ -1441,6 +1441,11 @@ static int rzg2l_mipi_dsi_probe(struct platform_device *pdev)
 		return dev_err_probe(dsi->dev, PTR_ERR(dsi->prstc),
 				     "failed to get prst\n");
 
+	dsi->dcs_buf_virt = dmam_alloc_coherent(dsi->dev, RZG2L_DCS_BUF_SIZE,
+						&dsi->dcs_buf_phys, GFP_KERNEL);
+	if (!dsi->dcs_buf_virt)
+		return -ENOMEM;
+
 	platform_set_drvdata(pdev, dsi);
 
 	pm_runtime_enable(dsi->dev);
@@ -1473,11 +1478,6 @@ static int rzg2l_mipi_dsi_probe(struct platform_device *pdev)
 	if (ret < 0)
 		goto err_pm_disable;
 
-	dsi->dcs_buf_virt = dma_alloc_coherent(dsi->host.dev, RZG2L_DCS_BUF_SIZE,
-					       &dsi->dcs_buf_phys, GFP_KERNEL);
-	if (!dsi->dcs_buf_virt)
-		return -ENOMEM;
-
 	return 0;
 
 err_phy:
@@ -1492,8 +1492,6 @@ static void rzg2l_mipi_dsi_remove(struct platform_device *pdev)
 {
 	struct rzg2l_mipi_dsi *dsi = platform_get_drvdata(pdev);
 
-	dma_free_coherent(dsi->host.dev, RZG2L_DCS_BUF_SIZE, dsi->dcs_buf_virt,
-			  dsi->dcs_buf_phys);
 	mipi_dsi_host_unregister(&dsi->host);
 	pm_runtime_disable(&pdev->dev);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0159/2077] alarmtimer: Remove stale return description from alarm_handle_timer()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (157 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0158/2077] drm: renesas: rz-du: mipi_dsi: Fix return path on error Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0160/2077] OPP: Fix race between OPP addition and lookup Greg Kroah-Hartman
                   ` (838 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhan Xusheng, Thomas Gleixner,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhan Xusheng <zhanxusheng1024@gmail.com>

[ Upstream commit ed3b3c4976686b63b28e44f9805a88abc20ff18a ]

alarm_handle_timer() was converted from returning enum alarmtimer_restart
to void, but the kernel-doc "Return:" line was not removed. Remove the
stale description.

Fixes: 2634303f8773 ("alarmtimers: Remove return value from alarm functions")
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260429080635.166790-1-zhanxusheng@xiaomi.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/time/alarmtimer.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/kernel/time/alarmtimer.c b/kernel/time/alarmtimer.c
index 6e173d70d82592..fe9c42c03523c5 100644
--- a/kernel/time/alarmtimer.c
+++ b/kernel/time/alarmtimer.c
@@ -512,8 +512,6 @@ static enum alarmtimer_type clock2alarm(clockid_t clockid)
  * @now: time at the timer expiration
  *
  * Posix timer callback for expired alarm timers.
- *
- * Return: whether the timer is to be restarted
  */
 static void alarm_handle_timer(struct alarm *alarm, ktime_t now)
 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0160/2077] OPP: Fix race between OPP addition and lookup
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (158 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0159/2077] alarmtimer: Remove stale return description from alarm_handle_timer() Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0161/2077] crypto: ccp - Reverse the cleanup order in psp_dev_destroy() Greg Kroah-Hartman
                   ` (837 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ling Xu, Di Shen, Viresh Kumar,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Di Shen <di.shen@unisoc.com>

[ Upstream commit f5e1cc9a284bff2510981643a5bca4bc4c21b81a ]

A race exists between dev_pm_opp_add_dynamic() and
dev_pm_opp_find_freq_exact():

  CPU0 (add)                          CPU1 (lookup)
  -------------------------------     ------------------------------
  _opp_add()
    mutex_lock()
    list_add(&new_opp->node, head)
    mutex_unlock()                    _opp_table_find_key()
                                        mutex_lock()
                                        dev_pm_opp_get(opp)
                                          kref_get()
                                        mutex_unlock()
    kref_init(&new_opp->kref)
                                      dev_pm_opp_put()
                                        kref_put_mutex()

The newly added OPP is inserted into the list before its kref is
initialized. A concurrent lookup can find this OPP and increment its
reference count while it is still uninitialized, leading to refcount
corruption and a potential premature free.

Fix this by initializing ->kref and ->opp_table before making the OPP
visible via list_add(). This ensures any concurrent lookup observes a
fully initialized object.

Fixes: 7034764a1e4a (PM / OPP: Add 'struct kref' to struct dev_pm_opp)
Co-developed-by: Ling Xu <ling_ling.xu@unisoc.com>
Signed-off-by: Ling Xu <ling_ling.xu@unisoc.com>
Signed-off-by: Di Shen <di.shen@unisoc.com>
[ Viresh: Updated commit log ]
Signed-off-by: Viresh Kumar <viresh.kumar@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/opp/core.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/drivers/opp/core.c b/drivers/opp/core.c
index da3f5eba434197..ab0b0a2f85a178 100644
--- a/drivers/opp/core.c
+++ b/drivers/opp/core.c
@@ -2088,11 +2088,10 @@ int _opp_add(struct device *dev, struct dev_pm_opp *new_opp,
 			return ret;
 
 		list_add(&new_opp->node, head);
+		new_opp->opp_table = opp_table;
+		kref_init(&new_opp->kref);
 	}
 
-	new_opp->opp_table = opp_table;
-	kref_init(&new_opp->kref);
-
 	opp_debug_create_one(new_opp, opp_table);
 
 	if (!_opp_supported_by_regulators(new_opp, opp_table)) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0161/2077] crypto: ccp - Reverse the cleanup order in psp_dev_destroy()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (159 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0160/2077] OPP: Fix race between OPP addition and lookup Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0162/2077] crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one Greg Kroah-Hartman
                   ` (836 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tom Lendacky, Tycho Andersen (AMD),
	Ashish Kalra, Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tycho Andersen (AMD) <tycho@kernel.org>

[ Upstream commit 4a76a164ba1617f60d1c8a2fd754466c9d9e48e9 ]

Before SNP x86 shutdown [1], all HV_FIXED pages were always leaked on
module unload. Now pages can be reclaimed if they are freed before SNP
shutdown.

The SFS driver does sfs_dev_destroy() -> snp_free_hv_fixed_pages(), marking
the command buffer as free. But this happens after sev_dev_destroy() in
psp_dev_destroy(), so the pages are always leaked.

Rearrange psp_dev_destroy() to destroy things in the reverse order from
psp_init(), so that any dependencies can be unwound accordingly. This lets
SFS free the page and the subsequent SNP shutdown release it.

This was identified with use of Chris Mason's review-prompts:
https://github.com/masoncl/review-prompts

[1]: https://lore.kernel.org/all/20260324161301.1353976-1-tycho@kernel.org/

Fixes: 648dbccc03a0 ("crypto: ccp - Add AMD Seamless Firmware Servicing (SFS) driver")
Reported-by: review-prompts
Assisted-by: Claude:claude-4.6-opus
Suggested-by: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Tycho Andersen (AMD) <tycho@kernel.org>
Reviewed-by: Ashish Kalra <ashish.kalra@amd.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/ccp/psp-dev.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/crypto/ccp/psp-dev.c b/drivers/crypto/ccp/psp-dev.c
index 5c7f7e02a7d8ab..b14ce51065d5da 100644
--- a/drivers/crypto/ccp/psp-dev.c
+++ b/drivers/crypto/ccp/psp-dev.c
@@ -316,15 +316,15 @@ void psp_dev_destroy(struct sp_device *sp)
 	if (!psp)
 		return;
 
-	sev_dev_destroy(psp);
+	dbc_dev_destroy(psp);
 
-	tee_dev_destroy(psp);
+	platform_access_dev_destroy(psp);
 
 	sfs_dev_destroy(psp);
 
-	dbc_dev_destroy(psp);
+	tee_dev_destroy(psp);
 
-	platform_access_dev_destroy(psp);
+	sev_dev_destroy(psp);
 
 	sp_free_psp_irq(sp, psp);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0162/2077] crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (160 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0161/2077] crypto: ccp - Reverse the cleanup order in psp_dev_destroy() Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0163/2077] crypto: ccp - Check for page allocation failure correctly in TIO Greg Kroah-Hartman
                   ` (835 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tycho Andersen (AMD), Herbert Xu,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tycho Andersen (AMD) <tycho@kernel.org>

[ Upstream commit 1b864b6cb213bbd7b406e9b2e98c962077f300df ]

Sashiko notes:

> regarding the bounds check in snp_filter_reserved_mem_regions()
> called via walk_iomem_res_desc(): does the check
> if ((range_list->num_elements * 16 + 8) > PAGE_SIZE)
> allow an off-by-one heap buffer overflow?
>
> If range_list->num_elements is 255, 255 * 16 + 8 = 4088, which is <= 4096.
> Writing range->base (8 bytes) fills 4088-4095, but writing range->page_count
> (4 bytes) would write to 4096-4099, overflowing the kzalloc-allocated
> PAGE_SIZE buffer.

Fix this by accounting for the entry about to be written to, in addition to
the entries that are already allocated.

Fixes: 1ca5614b84ee ("crypto: ccp: Add support to initialize the AMD-SP for SEV-SNP")
Reported-by: Sashiko
Assisted-by: Gemini:gemini-3.1-pro-preview
Link: https://sashiko.dev/#/patchset/20260324161301.1353976-1-tycho%40kernel.org
Signed-off-by: Tycho Andersen (AMD) <tycho@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/ccp/sev-dev.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/drivers/crypto/ccp/sev-dev.c b/drivers/crypto/ccp/sev-dev.c
index 7c4dd57fabb91e..b0290f8491f59a 100644
--- a/drivers/crypto/ccp/sev-dev.c
+++ b/drivers/crypto/ccp/sev-dev.c
@@ -1328,10 +1328,11 @@ static int snp_filter_reserved_mem_regions(struct resource *rs, void *arg)
 	size_t size;
 
 	/*
-	 * Ensure the list of HV_FIXED pages that will be passed to firmware
-	 * do not exceed the page-sized argument buffer.
+	 * Ensure the list of HV_FIXED pages passed to the firmware including
+	 * the one about to be written to do not exceed the page-sized argument
+	 * buffer.
 	 */
-	if ((range_list->num_elements * sizeof(struct sev_data_range) +
+	if (((range_list->num_elements + 1) * sizeof(struct sev_data_range) +
 	     sizeof(struct sev_data_range_list)) > PAGE_SIZE)
 		return -E2BIG;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0163/2077] crypto: ccp - Check for page allocation failure correctly in TIO
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (161 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0162/2077] crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0164/2077] crypto: ccp - Initialize data during __sev_snp_init_locked() Greg Kroah-Hartman
                   ` (834 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tycho Andersen (AMD), Herbert Xu,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tycho Andersen (AMD) <tycho@kernel.org>

[ Upstream commit a8d5370eef00eca132a292b1901c9914c817e385 ]

Sashiko notes:

> if __snp_alloc_firmware_pages() returns NULL under memory pressure, is it
> safe to pass it directly to page_address()?
>
> On architectures without HASHED_PAGE_VIRTUAL, page_address(NULL) might
> compute a deterministic but invalid, non-zero virtual address. The
> subsequent if (tio_status) check would then evaluate to true, and
> sev_tsm_init_locked() would dereference the invalid pointer.

Indeed, page_address(NULL) will return non-NULL garbage here. Fix this by
checking the page allocation itself for NULL, not the resulting virtual
address.

Fixes: 4be423572da1 ("crypto/ccp: Implement SEV-TIO PCIe IDE (phase1)")
Reported-by: Sashiko
Assisted-by: Gemini:gemini-3.1-pro-preview
Link: https://sashiko.dev/#/patchset/20260324161301.1353976-1-tycho%40kernel.org
Signed-off-by: Tycho Andersen (AMD) <tycho@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/ccp/sev-dev.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/drivers/crypto/ccp/sev-dev.c b/drivers/crypto/ccp/sev-dev.c
index b0290f8491f59a..3991d4b355e606 100644
--- a/drivers/crypto/ccp/sev-dev.c
+++ b/drivers/crypto/ccp/sev-dev.c
@@ -1488,6 +1488,8 @@ static int __sev_snp_init_locked(int *error, unsigned int max_snp_asid)
 				       &snp_panic_notifier);
 
 	if (data.tio_en) {
+		struct page *page;
+
 		/*
 		 * This executes with the sev_cmd_mutex held so down the stack
 		 * snp_reclaim_pages(locked=false) might be needed (which is extremely
@@ -1495,12 +1497,14 @@ static int __sev_snp_init_locked(int *error, unsigned int max_snp_asid)
 		 * Instead of exporting __snp_alloc_firmware_pages(), allocate a page
 		 * for this one call here.
 		 */
-		void *tio_status = page_address(__snp_alloc_firmware_pages(
-			GFP_KERNEL_ACCOUNT | __GFP_ZERO, 0, true));
+		page = __snp_alloc_firmware_pages(GFP_KERNEL_ACCOUNT | __GFP_ZERO,
+						  0, true);
+		if (page) {
+			void *tio_status = page_address(page);
 
-		if (tio_status) {
 			sev_tsm_init_locked(sev, tio_status);
-			__snp_free_firmware_pages(virt_to_page(tio_status), 0, true);
+
+			__snp_free_firmware_pages(page, 0, true);
 		}
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0164/2077] crypto: ccp - Initialize data during __sev_snp_init_locked()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (162 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0163/2077] crypto: ccp - Check for page allocation failure correctly in TIO Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0165/2077] crypto: atmel-sha204a - fix blocking and non-blocking rng logic Greg Kroah-Hartman
                   ` (833 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tycho Andersen (AMD), Herbert Xu,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tycho Andersen (AMD) <tycho@kernel.org>

[ Upstream commit fed613c1230277105bb512bce6e1fda8f316d178 ]

Sashiko notes:

> is the stack variable data left uninitialized when taking the else branch?
> Since data.tio_en is later evaluated unconditionally, could stack garbage
> cause it to evaluate to true, leading to erroneous attempts to allocate
> pages and initialize SEV-TIO on unsupported hardware?

If the firmware is too old to support SEV_INIT_EX, data is left
uninitialized but used in the debug logging about whether TIO is enabled or
not.

Fixes: 4be423572da1 ("crypto/ccp: Implement SEV-TIO PCIe IDE (phase1)")
Reported-by: Sashiko
Assisted-by: Gemini:gemini-3.1-pro-preview
Link: https://sashiko.dev/#/patchset/20260324161301.1353976-1-tycho%40kernel.org
Signed-off-by: Tycho Andersen (AMD) <tycho@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/ccp/sev-dev.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/drivers/crypto/ccp/sev-dev.c b/drivers/crypto/ccp/sev-dev.c
index 3991d4b355e606..14df519ae7eea7 100644
--- a/drivers/crypto/ccp/sev-dev.c
+++ b/drivers/crypto/ccp/sev-dev.c
@@ -1356,7 +1356,7 @@ static int __sev_snp_init_locked(int *error, unsigned int max_snp_asid)
 {
 	struct sev_data_range_list *snp_range_list __free(kfree) = NULL;
 	struct psp_device *psp = psp_master;
-	struct sev_data_snp_init_ex data;
+	struct sev_data_snp_init_ex data = {};
 	struct sev_device *sev;
 	void *arg = &data;
 	int cmd, rc = 0;
@@ -1420,8 +1420,6 @@ static int __sev_snp_init_locked(int *error, unsigned int max_snp_asid)
 		 */
 		snp_add_hv_fixed_pages(sev, snp_range_list);
 
-		memset(&data, 0, sizeof(data));
-
 		if (max_snp_asid) {
 			data.ciphertext_hiding_en = 1;
 			data.max_snp_asid = max_snp_asid;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0165/2077] crypto: atmel-sha204a - fix blocking and non-blocking rng logic
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (163 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0164/2077] crypto: ccp - Initialize data during __sev_snp_init_locked() Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0166/2077] crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve Greg Kroah-Hartman
                   ` (832 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ard Biesheuvel, Lothar Rubusch,
	Thorsten Blum, Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lothar Rubusch <l.rubusch@gmail.com>

[ Upstream commit 319400fc5ee15db5793aa45f854968141326effc ]

The blocking and non-blocking paths were failing to provide valid entropy
due to improper buffer management. Reading the buffer starting from byte 1,
only fetch the 32 bytes of random data from the return message.

Tested on an Atmel SHA204A device.

Before (here for blocking), tests showed repeatedly reading reduced bytes.
$ head -c 32 /dev/hwrng | hexdump -C
00000000  02 28 85 b3 47 40 f2 ee  00 00 00 00 00 00 00 00  |.(..G@..........|
00000010  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000020

After, the result will be similar to the following:
$ head -c 32 /dev/hwrng | hexdump -C
00000000  5a fc 3f 13 14 68 fe 06  68 0a bd 04 83 6e 09 69  |Z.?..h..h....n.i|
00000010  75 ff cf 87 10 84 3b c9  c1 df ae eb 45 53 4c c3  |u.....;.....ESL.|
00000020

Fixes: da001fb651b0 ("crypto: atmel-i2c - add support for SHA204A random number generator")
Suggested-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Lothar Rubusch <l.rubusch@gmail.com>
Tested-by: Thorsten Blum <thorsten.blum@linux.dev>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/atmel-sha204a.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/crypto/atmel-sha204a.c b/drivers/crypto/atmel-sha204a.c
index 987eadae2007a6..aa1db7ac2bb2a2 100644
--- a/drivers/crypto/atmel-sha204a.c
+++ b/drivers/crypto/atmel-sha204a.c
@@ -54,8 +54,8 @@ static int atmel_sha204a_rng_read_nonblocking(struct hwrng *rng, void *data,
 
 	if (rng->priv) {
 		work_data = (struct atmel_i2c_work_data *)rng->priv;
-		max = min(sizeof(work_data->cmd.data), max);
-		memcpy(data, &work_data->cmd.data, max);
+		max = min(RANDOM_RSP_SIZE - CMD_OVERHEAD_SIZE, max);
+		memcpy(data, &work_data->cmd.data[RSP_DATA_IDX], max);
 		rng->priv = 0;
 	} else {
 		work_data = kmalloc_obj(*work_data, GFP_ATOMIC);
@@ -93,8 +93,8 @@ static int atmel_sha204a_rng_read(struct hwrng *rng, void *data, size_t max,
 	if (ret)
 		return ret;
 
-	max = min(sizeof(cmd.data), max);
-	memcpy(data, cmd.data, max);
+	max = min(RANDOM_RSP_SIZE - CMD_OVERHEAD_SIZE, max);
+	memcpy(data, &cmd.data[RSP_DATA_IDX], max);
 
 	return max;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0166/2077] crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (164 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0165/2077] crypto: atmel-sha204a - fix blocking and non-blocking rng logic Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0167/2077] crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents Greg Kroah-Hartman
                   ` (831 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thorsten Blum, Lukas Wunner,
	Vitaly Chikunov, Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thorsten Blum <thorsten.blum@linux.dev>

[ Upstream commit 2d7b2cfc59998baf5e8622a24dc28f69a5212e06 ]

The ->curve_oid check in ecrdsa_param_curve() rejects the valid enum
value 0 (OID_id_dsa_with_sha1), but look_up_OID() returns OID__NR on
lookup failure. Compare ->curve_oid with OID__NR instead to ensure that
only unknown OIDs return -EINVAL.

Fixes: 0d7a78643f69 ("crypto: ecrdsa - add EC-RDSA (GOST 34.10) algorithm")
Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev>
Reviewed-by: Lukas Wunner <lukas@wunner.de>
Reviewed-by: Vitaly Chikunov <vt@altlinux.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 crypto/ecrdsa.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/crypto/ecrdsa.c b/crypto/ecrdsa.c
index 2c0602f0cd406f..0cd7eb3676041f 100644
--- a/crypto/ecrdsa.c
+++ b/crypto/ecrdsa.c
@@ -145,7 +145,7 @@ int ecrdsa_param_curve(void *context, size_t hdrlen, unsigned char tag,
 	struct ecrdsa_ctx *ctx = context;
 
 	ctx->curve_oid = look_up_OID(value, vlen);
-	if (!ctx->curve_oid)
+	if (ctx->curve_oid == OID__NR)
 		return -EINVAL;
 	ctx->curve = get_curve_by_oid(ctx->curve_oid);
 	return 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0167/2077] crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (165 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0166/2077] crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0168/2077] ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD Greg Kroah-Hartman
                   ` (830 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi, Herbert Xu,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Weiming Shi <bestswngs@gmail.com>

[ Upstream commit f7dd32c5179d7755de18e21d5674b08f9e5cb180 ]

pefile_digest_pe_contents() computes the trailing-data hash length as
pelen - (hashed_bytes + certs_size). A crafted PE can make the addition
exceed pelen, causing the unsigned subtraction to underflow to ~4 GiB.
This is passed to crypto_shash_update() which reads out of bounds and
panics on unmapped vmalloc guard pages.

 BUG: unable to handle page fault for address: ffffc900038d8000
 Oops: Oops: 0000 [#1] SMP KASAN NOPTI
 RIP: 0010:sha256_blocks_generic (lib/crypto/sha256.c:152)
 Call Trace:
  <TASK>
  __sha256_update (lib/crypto/sha256.c:208)
  crypto_sha256_update (crypto/sha256.c:142)
  verify_pefile_signature (crypto/asymmetric_keys/verify_pefile.c:436)
  kexec_kernel_verify_pe_sig (kernel/kexec_file.c:151)
  __do_sys_kexec_file_load (kernel/kexec_file.c:406)
  do_syscall_64 (arch/x86/entry/syscall_64.c:94)
  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
  </TASK>
 Kernel panic - not syncing: Fatal exception

Validate that the addition does not overflow and the result does not
exceed pelen before the subtraction. Return -ELIBBAD on failure.

Fixes: af316fc442ef ("pefile: Digest the PE binary and compare to the PKCS#7 data")
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 crypto/asymmetric_keys/verify_pefile.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/crypto/asymmetric_keys/verify_pefile.c b/crypto/asymmetric_keys/verify_pefile.c
index 1f3b227ba7f221..cec99db14129af 100644
--- a/crypto/asymmetric_keys/verify_pefile.c
+++ b/crypto/asymmetric_keys/verify_pefile.c
@@ -305,6 +305,8 @@ static int pefile_digest_pe_contents(const void *pebuf, unsigned int pelen,
 
 	if (pelen > hashed_bytes) {
 		tmp = hashed_bytes + ctx->certs_size;
+		if (tmp <= hashed_bytes || pelen < tmp)
+			return -ELIBBAD;
 		ret = crypto_shash_update(desc,
 					  pebuf + hashed_bytes,
 					  pelen - tmp);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0168/2077] ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (166 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0167/2077] crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0169/2077] accel/amdxdna: Fix clflush buffer size Greg Kroah-Hartman
                   ` (829 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Linus Walleij,
	Arnd Bergmann, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit 02802b40c31d2f2cfc94716189cfaf610930c589 ]

QCOM_RPMH and QCOM_RPMHPD can be build only as modules when
QCOM_COMMAND_DB is module itself.

Fixes: 1c25ca9bb5c5 ("ARM: multi_v7_defconfig: enable more Qualcomm drivers")
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm/configs/multi_v7_defconfig | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/arm/configs/multi_v7_defconfig b/arch/arm/configs/multi_v7_defconfig
index bcc9aabc120283..aad12026b20d28 100644
--- a/arch/arm/configs/multi_v7_defconfig
+++ b/arch/arm/configs/multi_v7_defconfig
@@ -1155,7 +1155,7 @@ CONFIG_QCOM_COMMAND_DB=m
 CONFIG_QCOM_GSBI=y
 CONFIG_QCOM_OCMEM=m
 CONFIG_QCOM_RMTFS_MEM=m
-CONFIG_QCOM_RPMH=y
+CONFIG_QCOM_RPMH=m
 CONFIG_QCOM_SMEM=y
 CONFIG_QCOM_SMD_RPM=y
 CONFIG_QCOM_SMP2P=y
@@ -1170,7 +1170,7 @@ CONFIG_KEYSTONE_NAVIGATOR_DMA=y
 CONFIG_TI_PRUSS=m
 CONFIG_RASPBERRYPI_POWER=y
 CONFIG_QCOM_CPR=y
-CONFIG_QCOM_RPMHPD=y
+CONFIG_QCOM_RPMHPD=m
 CONFIG_QCOM_RPMPD=y
 CONFIG_ROCKCHIP_PM_DOMAINS=y
 CONFIG_TI_SCI_PM_DOMAINS=y
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0169/2077] accel/amdxdna: Fix clflush buffer size
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (167 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0168/2077] ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0170/2077] dlm: fix add msg handle in send_queue ordered Greg Kroah-Hartman
                   ` (828 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mario Limonciello (AMD), Lizhi Hou,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lizhi Hou <lizhi.hou@amd.com>

[ Upstream commit ada61841caede131cc626f6cd28a60904296f248 ]

The firmware is told the buffer is req.buf_size bytes. It may read/write
the entire region. If the CPU only flushes a subset, the remaining cache
lines could contain stale data, causing the device to see garbage.

Fixes: 6e87001fe19f ("accel/amdxdna: Adjust size for copy_to_user()")
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260507040207.178111-1-lizhi.hou@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/accel/amdxdna/aie2_message.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/accel/amdxdna/aie2_message.c b/drivers/accel/amdxdna/aie2_message.c
index 0a619e55902b58..30289680660646 100644
--- a/drivers/accel/amdxdna/aie2_message.c
+++ b/drivers/accel/amdxdna/aie2_message.c
@@ -390,7 +390,7 @@ int aie2_query_status(struct amdxdna_dev_hdl *ndev, char __user *buf,
 	req.num_cols = hweight32(aie_bitmap);
 	req.aie_bitmap = aie_bitmap;
 
-	drm_clflush_virt_range(buff_addr, size); /* device can access */
+	drm_clflush_virt_range(buff_addr, req.dump_buff_size); /* device can access */
 	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret) {
 		XDNA_ERR(xdna, "Error during NPU query, status %d", ret);
@@ -442,7 +442,7 @@ int aie2_query_telemetry(struct amdxdna_dev_hdl *ndev,
 	req.buf_size = buf_sz;
 	req.type = header->type;
 
-	drm_clflush_virt_range(addr, size); /* device can access */
+	drm_clflush_virt_range(addr, req.buf_size); /* device can access */
 	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret) {
 		XDNA_ERR(xdna, "Query telemetry failed, status %d", ret);
@@ -1186,7 +1186,7 @@ int aie2_query_app_health(struct amdxdna_dev_hdl *ndev, u32 context_id,
 	req.context_id = context_id;
 	req.buf_size = buf_size;
 
-	drm_clflush_virt_range(buf, sizeof(*report));
+	drm_clflush_virt_range(buf, req.buf_size);
 	ret = aie_send_mgmt_msg_wait(&ndev->aie, &msg);
 	if (ret) {
 		XDNA_ERR(xdna, "Get app health failed, ret %d status 0x%x", ret, resp.status);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0170/2077] dlm: fix add msg handle in send_queue ordered
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (168 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0169/2077] accel/amdxdna: Fix clflush buffer size Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0171/2077] nilfs2: fix backing_dev_info reference leak Greg Kroah-Hartman
                   ` (827 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alexander Aring, David Teigland,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexander Aring <aahringo@redhat.com>

[ Upstream commit d2248cb70c070f8f04762872772e155b59016f17 ]

In a benchmark scenario triggering a lot of requests that triggers a lot
of DLM messages on the network it can be that the mh->seq is not ordered
according the oldest seq number. This ordering is required by
dlm_receive_ack as "before(mh->seq, seq)" will stop to check for older
sequence numbers that are ordered in the tail of "node->send_queue".

The side effects of not having it correct ordered regarding
"before(mh->seq, seq)" are refcounting issues and use-after free.

I only was able to reproduce this issue in a experimental DLM branch
and a user space DLM benchmark that uses io_uring. After changing this I
don't experienced any refcounting with the sending buffer issues anymore.

Fixes: 489d8e559c659 ("fs: dlm: add reliable connection if reconnect")
Signed-off-by: Alexander Aring <aahringo@redhat.com>
Signed-off-by: David Teigland <teigland@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/dlm/midcomms.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/dlm/midcomms.c b/fs/dlm/midcomms.c
index d54bdd8fc4f2ed..64826a9b79a557 100644
--- a/fs/dlm/midcomms.c
+++ b/fs/dlm/midcomms.c
@@ -968,10 +968,10 @@ static void midcomms_new_msg_cb(void *data)
 	atomic_inc(&mh->node->send_queue_cnt);
 
 	spin_lock_bh(&mh->node->send_queue_lock);
+	/* need to be locked with list_add_tail_rcu() because list is ordered */
+	mh->seq = atomic_fetch_inc(&mh->node->seq_send);
 	list_add_tail_rcu(&mh->list, &mh->node->send_queue);
 	spin_unlock_bh(&mh->node->send_queue_lock);
-
-	mh->seq = atomic_fetch_inc(&mh->node->seq_send);
 }
 
 static struct dlm_msg *dlm_midcomms_get_msg_3_2(struct dlm_mhandle *mh, int nodeid,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0171/2077] nilfs2: fix backing_dev_info reference leak
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (169 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0170/2077] dlm: fix add msg handle in send_queue ordered Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0172/2077] ntb: Store original DMA address for future release Greg Kroah-Hartman
                   ` (826 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Ryusuke Konishi,
	Viacheslav Dubeyko, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shuangpeng Bai <shuangpeng.kernel@gmail.com>

[ Upstream commit 665f192a2a11384cb7dc1be5f87d16438522a4ed ]

setup_bdev_super() already initializes sb->s_bdev and takes a
reference on the block device backing_dev_info when assigning sb->s_bdi.

nilfs_fill_super() takes another reference to the same
backing_dev_info and stores it in sb->s_bdi again. The extra
reference is not paired with a matching bdi_put(), since
generic_shutdown_super() releases sb->s_bdi only once.

Drop the redundant bdi_get() in nilfs_fill_super(). The single
reference taken by setup_bdev_super() is enough and is released
during superblock shutdown.

Fixes: c1e012ea9e83 ("nilfs2: use setup_bdev_super to de-duplicate the mount code")
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Acked-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Reviewed-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/nilfs2/super.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/fs/nilfs2/super.c b/fs/nilfs2/super.c
index 7aa5ef8606cdd4..893a504cb80c8a 100644
--- a/fs/nilfs2/super.c
+++ b/fs/nilfs2/super.c
@@ -1070,8 +1070,6 @@ nilfs_fill_super(struct super_block *sb, struct fs_context *fc)
 	sb->s_time_gran = 1;
 	sb->s_max_links = NILFS_LINK_MAX;
 
-	sb->s_bdi = bdi_get(sb->s_bdev->bd_disk->bdi);
-
 	err = load_nilfs(nilfs, sb);
 	if (err)
 		goto failed_nilfs;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0172/2077] ntb: Store original DMA address for future release
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (170 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0171/2077] nilfs2: fix backing_dev_info reference leak Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0173/2077] ntb: Use consistent DMA attributes when freeing DMA mappings Greg Kroah-Hartman
                   ` (825 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Dave Jiang,
	Marek Szyprowski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leon Romanovsky <leonro@nvidia.com>

[ Upstream commit da6d997ac556479c112554ab5d95cbd04683eb11 ]

The DMA API requires that dma_free_attrs receive the exact dma_handle
originally returned by the allocation function. Do not modify it.

Fixes: fc5d1829f9bf ("NTB: transport: Try harder to alloc an aligned MW buffer")
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Link: https://lore.kernel.org/r/20260501-dma-attrs-debug-v2-1-8dbac75cd501@nvidia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/ntb/ntb_transport.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/ntb/ntb_transport.c b/drivers/ntb/ntb_transport.c
index 7cabc82305d6b1..771eb7d9f43560 100644
--- a/drivers/ntb/ntb_transport.c
+++ b/drivers/ntb/ntb_transport.c
@@ -223,6 +223,7 @@ struct ntb_transport_mw {
 	void *alloc_addr;
 	void *virt_addr;
 	dma_addr_t dma_addr;
+	dma_addr_t original_dma_addr;
 };
 
 struct ntb_transport_client_dev {
@@ -766,7 +767,7 @@ static void ntb_free_mw(struct ntb_transport_ctx *nt, int num_mw)
 
 	ntb_mw_clear_trans(nt->ndev, PIDX, num_mw);
 	dma_free_coherent(dma_dev, mw->alloc_size,
-			  mw->alloc_addr, mw->dma_addr);
+			  mw->alloc_addr, mw->original_dma_addr);
 	mw->xlat_size = 0;
 	mw->buff_size = 0;
 	mw->alloc_size = 0;
@@ -802,6 +803,7 @@ static int ntb_alloc_mw_buffer(struct ntb_transport_mw *mw,
 		return -ENOMEM;
 	}
 	virt_addr = alloc_addr;
+	mw->original_dma_addr = dma_addr;
 
 	/*
 	 * we must ensure that the memory address allocated is BAR size
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0173/2077] ntb: Use consistent DMA attributes when freeing DMA mappings
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (171 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0172/2077] ntb: Store original DMA address for future release Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0174/2077] media: qcom: camss: vfe: fix PIX subdev naming on VFE lite Greg Kroah-Hartman
                   ` (824 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Dave Jiang,
	Marek Szyprowski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leon Romanovsky <leonro@nvidia.com>

[ Upstream commit 9d625aa2ebd445868955719e0abcf695b43f9318 ]

The counterpart of dma_alloc_attrs() is dma_free_attrs(), which must
receive the same DMA attributes used during allocation. The code
previously used dma_free_coherent(), which does not accept or apply any
DMA attributes.

Fixes: 061a785a114f ("ntb: Force physically contiguous allocation of rx ring buffers")
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Link: https://lore.kernel.org/r/20260501-dma-attrs-debug-v2-2-8dbac75cd501@nvidia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/ntb/ntb_transport.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/ntb/ntb_transport.c b/drivers/ntb/ntb_transport.c
index 771eb7d9f43560..f59f926d4bfaa9 100644
--- a/drivers/ntb/ntb_transport.c
+++ b/drivers/ntb/ntb_transport.c
@@ -766,8 +766,8 @@ static void ntb_free_mw(struct ntb_transport_ctx *nt, int num_mw)
 		return;
 
 	ntb_mw_clear_trans(nt->ndev, PIDX, num_mw);
-	dma_free_coherent(dma_dev, mw->alloc_size,
-			  mw->alloc_addr, mw->original_dma_addr);
+	dma_free_attrs(dma_dev, mw->alloc_size, mw->alloc_addr,
+		       mw->original_dma_addr, DMA_ATTR_FORCE_CONTIGUOUS);
 	mw->xlat_size = 0;
 	mw->buff_size = 0;
 	mw->alloc_size = 0;
@@ -828,8 +828,8 @@ static int ntb_alloc_mw_buffer(struct ntb_transport_mw *mw,
 	return 0;
 
 err:
-	dma_free_coherent(ntb_dev, mw->alloc_size, alloc_addr, dma_addr);
-
+	dma_free_attrs(ntb_dev, mw->alloc_size, alloc_addr, dma_addr,
+		       DMA_ATTR_FORCE_CONTIGUOUS);
 	return rc;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0174/2077] media: qcom: camss: vfe: fix PIX subdev naming on VFE lite
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (172 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0173/2077] ntb: Use consistent DMA attributes when freeing DMA mappings Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0175/2077] dts: riscv: spacemit: correct 32k clock frequency Greg Kroah-Hartman
                   ` (823 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wenmeng Liu, Bryan ODonoghue,
	Bryan ODonoghue, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wenmeng Liu <wenmeng.liu@oss.qualcomm.com>

[ Upstream commit c97e797a64cdfe4acecff831b4285418d2815893 ]

VFE lite hardware does not provide a functional PIX path, but after
the per sub-device type resource changes the PIX subdev name is still
assigned unconditionally.

Only assign the PIX subdev name on non-lite VFE variants to avoid
exposing a misleading device name.

Fixes: ae44829a4a97 ("media: qcom: camss: Add per sub-device type resources")
Signed-off-by: Wenmeng Liu <wenmeng.liu@oss.qualcomm.com>
Reviewed-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/media/platform/qcom/camss/camss-vfe.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/media/platform/qcom/camss/camss-vfe.c b/drivers/media/platform/qcom/camss/camss-vfe.c
index 5baf0e3d4bc461..2ee4f9ae0ab50e 100644
--- a/drivers/media/platform/qcom/camss/camss-vfe.c
+++ b/drivers/media/platform/qcom/camss/camss-vfe.c
@@ -2053,7 +2053,7 @@ int msm_vfe_register_entities(struct vfe_device *vfe,
 		v4l2_subdev_init(sd, &vfe_v4l2_ops);
 		sd->internal_ops = &vfe_v4l2_internal_ops;
 		sd->flags |= V4L2_SUBDEV_FL_HAS_DEVNODE;
-		if (i == VFE_LINE_PIX)
+		if (i == VFE_LINE_PIX && vfe->res->is_lite == false)
 			snprintf(sd->name, ARRAY_SIZE(sd->name), "%s%d_%s",
 				 MSM_VFE_NAME, vfe->id, "pix");
 		else
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0175/2077] dts: riscv: spacemit: correct 32k clock frequency
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (173 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0174/2077] media: qcom: camss: vfe: fix PIX subdev naming on VFE lite Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0176/2077] arm64: dts: qcom: sdm660: set cdsp compute-cbs regs properly Greg Kroah-Hartman
                   ` (822 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yixun Lan, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yixun Lan <dlan@kernel.org>

[ Upstream commit 3c350f6284d8ea5e7a9648241b2e9604f2262d42 ]

The 32k oscillator's clock frequency is actually 32768Hz, so correct it.

Fixes: 67072c8cd48c ("riscv: dts: spacemit: k3: add clock tree")
Fixes: a6fafa64b03a ("riscv: dts: spacemit: Add clock tree for SpacemiT K1")
Link: https://patch.msgid.link/20260428-06-k3-clk-osc32k-v1-1-e2378da7cb9b@kernel.org
Signed-off-by: Yixun Lan <dlan@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/boot/dts/spacemit/k1.dtsi | 2 +-
 arch/riscv/boot/dts/spacemit/k3.dtsi | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/riscv/boot/dts/spacemit/k1.dtsi b/arch/riscv/boot/dts/spacemit/k1.dtsi
index f0bad6855c970a..b0b9c19b56a091 100644
--- a/arch/riscv/boot/dts/spacemit/k1.dtsi
+++ b/arch/riscv/boot/dts/spacemit/k1.dtsi
@@ -333,7 +333,7 @@ vctcxo_3m: clock-3m {
 
 		osc_32k: clock-32k {
 			compatible = "fixed-clock";
-			clock-frequency = <32000>;
+			clock-frequency = <32768>;
 			clock-output-names = "osc_32k";
 			#clock-cells = <0>;
 		};
diff --git a/arch/riscv/boot/dts/spacemit/k3.dtsi b/arch/riscv/boot/dts/spacemit/k3.dtsi
index 815debd16409be..e6faf8d8759e1f 100644
--- a/arch/riscv/boot/dts/spacemit/k3.dtsi
+++ b/arch/riscv/boot/dts/spacemit/k3.dtsi
@@ -424,7 +424,7 @@ vctcxo_3m: clock-3m {
 
 		osc_32k: clock-32k {
 			compatible = "fixed-clock";
-			clock-frequency = <32000>;
+			clock-frequency = <32768>;
 			clock-output-names = "osc_32k";
 			#clock-cells = <0>;
 		};
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0176/2077] arm64: dts: qcom: sdm660: set cdsp compute-cbs regs properly
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (174 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0175/2077] dts: riscv: spacemit: correct 32k clock frequency Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0177/2077] arm64: dts: qcom: sdm630: set adsp " Greg Kroah-Hartman
                   ` (821 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Konrad Dybcio,
	Ekansh Gupta, Nickolay Goppen, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nickolay Goppen <setotau@mainlining.org>

[ Upstream commit 708ab9d3bc5b74eeee767c678366624d3c02a4ec ]

Changing FastRPC compute-cbs' reg values to matching iommu streams
solves SMMU translation errors when trying to use FastRPC on CDSP
so change FastRPC compute-cbs' reg values that way

Fixes: c0c32a9e3493 ("arm64: dts: qcom: sdm630/660: Add CDSP-related nodes")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Ekansh Gupta <ekansh.gupta@oss.qualcomm.com>
Signed-off-by: Nickolay Goppen <setotau@mainlining.org>
Link: https://lore.kernel.org/r/20260429-qcom-sdm660-cdsp-adsp-fastrpc-dts-fix-v5-2-16bc82e622ad@mainlining.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sdm660.dtsi | 36 ++++++++++++++--------------
 1 file changed, 18 insertions(+), 18 deletions(-)

diff --git a/arch/arm64/boot/dts/qcom/sdm660.dtsi b/arch/arm64/boot/dts/qcom/sdm660.dtsi
index 3fd6dd82a9927d..0fca9662c64a1c 100644
--- a/arch/arm64/boot/dts/qcom/sdm660.dtsi
+++ b/arch/arm64/boot/dts/qcom/sdm660.dtsi
@@ -350,57 +350,57 @@ fastrpc {
 				#address-cells = <1>;
 				#size-cells = <0>;
 
-				compute-cb@5 {
+				compute-cb@3 {
 					compatible = "qcom,fastrpc-compute-cb";
-					reg = <5>;
+					reg = <3>;
 					iommus = <&cdsp_smmu 3>;
 				};
 
-				compute-cb@6 {
+				compute-cb@4 {
 					compatible = "qcom,fastrpc-compute-cb";
-					reg = <6>;
+					reg = <4>;
 					iommus = <&cdsp_smmu 4>;
 				};
 
-				compute-cb@7 {
+				compute-cb@5 {
 					compatible = "qcom,fastrpc-compute-cb";
-					reg = <7>;
+					reg = <5>;
 					iommus = <&cdsp_smmu 5>;
 				};
 
-				compute-cb@8 {
+				compute-cb@6 {
 					compatible = "qcom,fastrpc-compute-cb";
-					reg = <8>;
+					reg = <6>;
 					iommus = <&cdsp_smmu 6>;
 				};
 
-				compute-cb@9 {
+				compute-cb@7 {
 					compatible = "qcom,fastrpc-compute-cb";
-					reg = <9>;
+					reg = <7>;
 					iommus = <&cdsp_smmu 7>;
 				};
 
-				compute-cb@10 {
+				compute-cb@8 {
 					compatible = "qcom,fastrpc-compute-cb";
-					reg = <10>;
+					reg = <8>;
 					iommus = <&cdsp_smmu 8>;
 				};
 
-				compute-cb@11 {
+				compute-cb@9 {
 					compatible = "qcom,fastrpc-compute-cb";
-					reg = <11>;
+					reg = <9>;
 					iommus = <&cdsp_smmu 9>;
 				};
 
-				compute-cb@12 {
+				compute-cb@10 {
 					compatible = "qcom,fastrpc-compute-cb";
-					reg = <12>;
+					reg = <10>;
 					iommus = <&cdsp_smmu 10>;
 				};
 
-				compute-cb@13 {
+				compute-cb@11 {
 					compatible = "qcom,fastrpc-compute-cb";
-					reg = <13>;
+					reg = <11>;
 					iommus = <&cdsp_smmu 11>;
 				};
 			};
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0177/2077] arm64: dts: qcom: sdm630: set adsp compute-cbs regs properly
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (175 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0176/2077] arm64: dts: qcom: sdm660: set cdsp compute-cbs regs properly Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0178/2077] arm64: dts: qcom: lemans: Move PCIe devices into soc node Greg Kroah-Hartman
                   ` (820 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Konrad Dybcio,
	Ekansh Gupta, Nickolay Goppen, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nickolay Goppen <setotau@mainlining.org>

[ Upstream commit e8e1fb5c703fc6962103ffdc60830df99351c139 ]

Changing FastRPC compute-cbs' reg values to matching iommu streams
solves SMMU translation errors when trying to use FastRPC on ADSP
so change FastRPC compute-cbs' reg values that way

Fixes: af2ce7296643 ("arm64: dts: qcom: sdm630: Add FastRPC nodes to ADSP")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Ekansh Gupta <ekansh.gupta@oss.qualcomm.com>
Signed-off-by: Nickolay Goppen <setotau@mainlining.org>
Link: https://lore.kernel.org/r/20260429-qcom-sdm660-cdsp-adsp-fastrpc-dts-fix-v5-3-16bc82e622ad@mainlining.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sdm630.dtsi | 16 ++++++++--------
 1 file changed, 8 insertions(+), 8 deletions(-)

diff --git a/arch/arm64/boot/dts/qcom/sdm630.dtsi b/arch/arm64/boot/dts/qcom/sdm630.dtsi
index bef3213165d668..4b47efdb57b213 100644
--- a/arch/arm64/boot/dts/qcom/sdm630.dtsi
+++ b/arch/arm64/boot/dts/qcom/sdm630.dtsi
@@ -2459,27 +2459,27 @@ fastrpc {
 					#address-cells = <1>;
 					#size-cells = <0>;
 
-					compute-cb@1 {
+					compute-cb@3 {
 						compatible = "qcom,fastrpc-compute-cb";
-						reg = <1>;
+						reg = <3>;
 						iommus = <&lpass_smmu 3>;
 					};
 
-					compute-cb@2 {
+					compute-cb@7 {
 						compatible = "qcom,fastrpc-compute-cb";
-						reg = <2>;
+						reg = <7>;
 						iommus = <&lpass_smmu 7>;
 					};
 
-					compute-cb@3 {
+					compute-cb@8 {
 						compatible = "qcom,fastrpc-compute-cb";
-						reg = <3>;
+						reg = <8>;
 						iommus = <&lpass_smmu 8>;
 					};
 
-					compute-cb@4 {
+					compute-cb@9 {
 						compatible = "qcom,fastrpc-compute-cb";
-						reg = <4>;
+						reg = <9>;
 						iommus = <&lpass_smmu 9>;
 					};
 				};
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0178/2077] arm64: dts: qcom: lemans: Move PCIe devices into soc node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (176 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0177/2077] arm64: dts: qcom: sdm630: set adsp " Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0179/2077] media: iris: scale MMCX power domain on SM8250 Greg Kroah-Hartman
                   ` (819 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shawn Guo, Konrad Dybcio,
	Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shawn Guo <shengchao.guo@oss.qualcomm.com>

[ Upstream commit 8222873cd4698627c08bffb2e40ba6f5a008fe32 ]

These PCIe devices with MMIO address should be inside soc node rather
than outside.

Fixes: 489f14be0e0a ("arm64: dts: qcom: sa8775p: Add pcie0 and pcie1 nodes")
Signed-off-by: Shawn Guo <shengchao.guo@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260331090147.18522-1-shengchao.guo@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/lemans.dtsi | 692 +++++++++++++--------------
 1 file changed, 346 insertions(+), 346 deletions(-)

diff --git a/arch/arm64/boot/dts/qcom/lemans.dtsi b/arch/arm64/boot/dts/qcom/lemans.dtsi
index fe6e7635182307..5dd271e7108d7a 100644
--- a/arch/arm64/boot/dts/qcom/lemans.dtsi
+++ b/arch/arm64/boot/dts/qcom/lemans.dtsi
@@ -2694,6 +2694,352 @@ mmss_noc: interconnect@17a0000 {
 			qcom,bcm-voters = <&apps_bcm_voter>;
 		};
 
+		pcie0: pcie@1c00000 {
+			compatible = "qcom,pcie-sa8775p";
+			reg = <0x0 0x01c00000 0x0 0x3000>,
+			      <0x0 0x40000000 0x0 0xf20>,
+			      <0x0 0x40000f20 0x0 0xa8>,
+			      <0x0 0x40001000 0x0 0x4000>,
+			      <0x0 0x40100000 0x0 0x100000>,
+			      <0x0 0x01c03000 0x0 0x1000>;
+			reg-names = "parf", "dbi", "elbi", "atu", "config", "mhi";
+			device_type = "pci";
+
+			#address-cells = <3>;
+			#size-cells = <2>;
+			ranges = <0x01000000 0x0 0x00000000 0x0 0x40200000 0x0 0x100000>,
+				 <0x02000000 0x0 0x40300000 0x0 0x40300000 0x0 0x1fd00000>;
+			bus-range = <0x00 0xff>;
+
+			dma-coherent;
+
+			linux,pci-domain = <0>;
+			num-lanes = <2>;
+
+			interrupts = <GIC_SPI 307 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 308 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 309 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 312 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 313 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 314 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 374 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 375 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 306 IRQ_TYPE_LEVEL_HIGH>;
+			interrupt-names = "msi0",
+					  "msi1",
+					  "msi2",
+					  "msi3",
+					  "msi4",
+					  "msi5",
+					  "msi6",
+					  "msi7",
+					  "global";
+			#interrupt-cells = <1>;
+			interrupt-map-mask = <0 0 0 0x7>;
+			interrupt-map = <0 0 0 1 &intc GIC_SPI 434 IRQ_TYPE_LEVEL_HIGH>,
+					<0 0 0 2 &intc GIC_SPI 435 IRQ_TYPE_LEVEL_HIGH>,
+					<0 0 0 3 &intc GIC_SPI 438 IRQ_TYPE_LEVEL_HIGH>,
+					<0 0 0 4 &intc GIC_SPI 439 IRQ_TYPE_LEVEL_HIGH>;
+
+			clocks = <&gcc GCC_PCIE_0_AUX_CLK>,
+				 <&gcc GCC_PCIE_0_CFG_AHB_CLK>,
+				 <&gcc GCC_PCIE_0_MSTR_AXI_CLK>,
+				 <&gcc GCC_PCIE_0_SLV_AXI_CLK>,
+				 <&gcc GCC_PCIE_0_SLV_Q2A_AXI_CLK>;
+
+			clock-names = "aux",
+				      "cfg",
+				      "bus_master",
+				      "bus_slave",
+				      "slave_q2a";
+
+			assigned-clocks = <&gcc GCC_PCIE_0_AUX_CLK>;
+			assigned-clock-rates = <19200000>;
+
+			interconnects = <&pcie_anoc MASTER_PCIE_0 0 &mc_virt SLAVE_EBI1 0>,
+					<&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_0 0>;
+			interconnect-names = "pcie-mem", "cpu-pcie";
+
+			iommu-map = <0x0 &pcie_smmu 0x0000 0x1>,
+				    <0x100 &pcie_smmu 0x0001 0x1>;
+
+			resets = <&gcc GCC_PCIE_0_BCR>,
+				 <&gcc GCC_PCIE_0_LINK_DOWN_BCR>;
+			reset-names = "pci",
+				      "link_down";
+
+			power-domains = <&gcc PCIE_0_GDSC>;
+
+			phys = <&pcie0_phy>;
+			phy-names = "pciephy";
+
+			eq-presets-8gts = /bits/ 16 <0x5555 0x5555>;
+			eq-presets-16gts = /bits/ 8 <0x55 0x55>;
+
+			status = "disabled";
+
+			pcieport0: pcie@0 {
+				device_type = "pci";
+				reg = <0x0 0x0 0x0 0x0 0x0>;
+				bus-range = <0x01 0xff>;
+
+				#address-cells = <3>;
+				#size-cells = <2>;
+				ranges;
+			};
+		};
+
+		pcie0_ep: pcie-ep@1c00000 {
+			compatible = "qcom,sa8775p-pcie-ep";
+			reg = <0x0 0x01c00000 0x0 0x3000>,
+			      <0x0 0x40000000 0x0 0xf20>,
+			      <0x0 0x40000f20 0x0 0xa8>,
+			      <0x0 0x40001000 0x0 0x4000>,
+			      <0x0 0x40200000 0x0 0x1fe00000>,
+			      <0x0 0x01c03000 0x0 0x1000>,
+			      <0x0 0x40005000 0x0 0x2000>;
+			reg-names = "parf", "dbi", "elbi", "atu", "addr_space",
+				    "mmio", "dma";
+
+			clocks = <&gcc GCC_PCIE_0_AUX_CLK>,
+				<&gcc GCC_PCIE_0_CFG_AHB_CLK>,
+				<&gcc GCC_PCIE_0_MSTR_AXI_CLK>,
+				<&gcc GCC_PCIE_0_SLV_AXI_CLK>,
+				<&gcc GCC_PCIE_0_SLV_Q2A_AXI_CLK>;
+
+			clock-names = "aux",
+				      "cfg",
+				      "bus_master",
+				      "bus_slave",
+				      "slave_q2a";
+
+			interrupts = <GIC_SPI 306 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 147 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 630 IRQ_TYPE_LEVEL_HIGH>;
+
+			interrupt-names = "global", "doorbell", "dma";
+
+			interconnects = <&pcie_anoc MASTER_PCIE_0 0 &mc_virt SLAVE_EBI1 0>,
+					<&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_0 0>;
+			interconnect-names = "pcie-mem", "cpu-pcie";
+
+			dma-coherent;
+			iommus = <&pcie_smmu 0x0000 0x7f>;
+			resets = <&gcc GCC_PCIE_0_BCR>;
+			reset-names = "core";
+			power-domains = <&gcc PCIE_0_GDSC>;
+			phys = <&pcie0_phy>;
+			phy-names = "pciephy";
+			num-lanes = <2>;
+			linux,pci-domain = <0>;
+
+			status = "disabled";
+		};
+
+		pcie0_phy: phy@1c04000 {
+			compatible = "qcom,sa8775p-qmp-gen4x2-pcie-phy";
+			reg = <0x0 0x1c04000 0x0 0x2000>;
+
+			clocks = <&gcc GCC_PCIE_0_PHY_AUX_CLK>,
+				 <&gcc GCC_PCIE_0_CFG_AHB_CLK>,
+				 <&gcc GCC_PCIE_CLKREF_EN>,
+				 <&gcc GCC_PCIE_0_PHY_RCHNG_CLK>,
+				 <&gcc GCC_PCIE_0_PIPE_CLK>,
+				 <&gcc GCC_PCIE_0_PIPEDIV2_CLK>;
+			clock-names = "aux",
+				      "cfg_ahb",
+				      "ref",
+				      "rchng",
+				      "pipe",
+				      "pipediv2";
+
+			assigned-clocks = <&gcc GCC_PCIE_0_PHY_RCHNG_CLK>;
+			assigned-clock-rates = <100000000>;
+
+			resets = <&gcc GCC_PCIE_0_PHY_BCR>;
+			reset-names = "phy";
+
+			#clock-cells = <0>;
+			clock-output-names = "pcie_0_pipe_clk";
+
+			#phy-cells = <0>;
+
+			status = "disabled";
+		};
+
+		pcie1: pcie@1c10000 {
+			compatible = "qcom,pcie-sa8775p";
+			reg = <0x0 0x01c10000 0x0 0x3000>,
+			      <0x0 0x60000000 0x0 0xf20>,
+			      <0x0 0x60000f20 0x0 0xa8>,
+			      <0x0 0x60001000 0x0 0x4000>,
+			      <0x0 0x60100000 0x0 0x100000>,
+			      <0x0 0x01c13000 0x0 0x1000>;
+			reg-names = "parf", "dbi", "elbi", "atu", "config", "mhi";
+			device_type = "pci";
+
+			#address-cells = <3>;
+			#size-cells = <2>;
+			ranges = <0x01000000 0x0 0x00000000 0x0 0x60200000 0x0 0x100000>,
+				 <0x02000000 0x0 0x60300000 0x0 0x60300000 0x0 0x1fd00000>;
+			bus-range = <0x00 0xff>;
+
+			dma-coherent;
+
+			linux,pci-domain = <1>;
+			num-lanes = <4>;
+
+			interrupts = <GIC_SPI 519 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 140 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 141 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 142 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 143 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 144 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 145 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 146 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 518 IRQ_TYPE_LEVEL_HIGH>;
+			interrupt-names = "msi0",
+					  "msi1",
+					  "msi2",
+					  "msi3",
+					  "msi4",
+					  "msi5",
+					  "msi6",
+					  "msi7",
+					  "global";
+			#interrupt-cells = <1>;
+			interrupt-map-mask = <0 0 0 0x7>;
+			interrupt-map = <0 0 0 1 &intc GIC_SPI 148 IRQ_TYPE_LEVEL_HIGH>,
+					<0 0 0 2 &intc GIC_SPI 149 IRQ_TYPE_LEVEL_HIGH>,
+					<0 0 0 3 &intc GIC_SPI 150 IRQ_TYPE_LEVEL_HIGH>,
+					<0 0 0 4 &intc GIC_SPI 151 IRQ_TYPE_LEVEL_HIGH>;
+
+			clocks = <&gcc GCC_PCIE_1_AUX_CLK>,
+				 <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
+				 <&gcc GCC_PCIE_1_MSTR_AXI_CLK>,
+				 <&gcc GCC_PCIE_1_SLV_AXI_CLK>,
+				 <&gcc GCC_PCIE_1_SLV_Q2A_AXI_CLK>;
+
+			clock-names = "aux",
+				      "cfg",
+				      "bus_master",
+				      "bus_slave",
+				      "slave_q2a";
+
+			assigned-clocks = <&gcc GCC_PCIE_1_AUX_CLK>;
+			assigned-clock-rates = <19200000>;
+
+			interconnects = <&pcie_anoc MASTER_PCIE_1 0 &mc_virt SLAVE_EBI1 0>,
+					<&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_1 0>;
+			interconnect-names = "pcie-mem", "cpu-pcie";
+
+			iommu-map = <0x0 &pcie_smmu 0x0080 0x1>,
+				    <0x100 &pcie_smmu 0x0081 0x1>;
+
+			resets = <&gcc GCC_PCIE_1_BCR>,
+				 <&gcc GCC_PCIE_1_LINK_DOWN_BCR>;
+			reset-names = "pci",
+				      "link_down";
+
+			power-domains = <&gcc PCIE_1_GDSC>;
+
+			phys = <&pcie1_phy>;
+			phy-names = "pciephy";
+
+			eq-presets-8gts = /bits/ 16 <0x5555 0x5555 0x5555 0x5555>;
+			eq-presets-16gts = /bits/ 8 <0x55 0x55 0x55 0x55>;
+
+			status = "disabled";
+
+			pcie@0 {
+				device_type = "pci";
+				reg = <0x0 0x0 0x0 0x0 0x0>;
+				bus-range = <0x01 0xff>;
+
+				#address-cells = <3>;
+				#size-cells = <2>;
+				ranges;
+			};
+		};
+
+		pcie1_ep: pcie-ep@1c10000 {
+			compatible = "qcom,sa8775p-pcie-ep";
+			reg = <0x0 0x01c10000 0x0 0x3000>,
+			      <0x0 0x60000000 0x0 0xf20>,
+			      <0x0 0x60000f20 0x0 0xa8>,
+			      <0x0 0x60001000 0x0 0x4000>,
+			      <0x0 0x60200000 0x0 0x1fe00000>,
+			      <0x0 0x01c13000 0x0 0x1000>,
+			      <0x0 0x60005000 0x0 0x2000>;
+			reg-names = "parf", "dbi", "elbi", "atu", "addr_space",
+				    "mmio", "dma";
+
+			clocks = <&gcc GCC_PCIE_1_AUX_CLK>,
+				 <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
+				 <&gcc GCC_PCIE_1_MSTR_AXI_CLK>,
+				 <&gcc GCC_PCIE_1_SLV_AXI_CLK>,
+				 <&gcc GCC_PCIE_1_SLV_Q2A_AXI_CLK>;
+
+			clock-names = "aux",
+				      "cfg",
+				      "bus_master",
+				      "bus_slave",
+				      "slave_q2a";
+
+			interrupts = <GIC_SPI 518 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 152 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 474 IRQ_TYPE_LEVEL_HIGH>;
+
+			interrupt-names = "global", "doorbell", "dma";
+
+			interconnects = <&pcie_anoc MASTER_PCIE_1 0 &mc_virt SLAVE_EBI1 0>,
+					<&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_1 0>;
+			interconnect-names = "pcie-mem", "cpu-pcie";
+
+			dma-coherent;
+			iommus = <&pcie_smmu 0x80 0x7f>;
+			resets = <&gcc GCC_PCIE_1_BCR>;
+			reset-names = "core";
+			power-domains = <&gcc PCIE_1_GDSC>;
+			phys = <&pcie1_phy>;
+			phy-names = "pciephy";
+			num-lanes = <4>;
+			linux,pci-domain = <1>;
+
+			status = "disabled";
+		};
+
+		pcie1_phy: phy@1c14000 {
+			compatible = "qcom,sa8775p-qmp-gen4x4-pcie-phy";
+			reg = <0x0 0x1c14000 0x0 0x4000>;
+
+			clocks = <&gcc GCC_PCIE_1_PHY_AUX_CLK>,
+				 <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
+				 <&gcc GCC_PCIE_CLKREF_EN>,
+				 <&gcc GCC_PCIE_1_PHY_RCHNG_CLK>,
+				 <&gcc GCC_PCIE_1_PIPE_CLK>,
+				 <&gcc GCC_PCIE_1_PIPEDIV2_CLK>;
+			clock-names = "aux",
+				      "cfg_ahb",
+				      "ref",
+				      "rchng",
+				      "pipe",
+				      "pipediv2";
+
+			assigned-clocks = <&gcc GCC_PCIE_1_PHY_RCHNG_CLK>;
+			assigned-clock-rates = <100000000>;
+
+			resets = <&gcc GCC_PCIE_1_PHY_BCR>;
+			reset-names = "phy";
+
+			#clock-cells = <0>;
+			clock-output-names = "pcie_1_pipe_clk";
+
+			#phy-cells = <0>;
+
+			status = "disabled";
+		};
+
 		ufs_mem_hc: ufshc@1d84000 {
 			compatible = "qcom,sa8775p-ufshc", "qcom,ufshc", "jedec,ufs-2.0";
 			reg = <0x0 0x01d84000 0x0 0x3000>;
@@ -8601,350 +8947,4 @@ turing_llm_tpdm_out: endpoint {
 			};
 		};
 	};
-
-	pcie0: pcie@1c00000 {
-		compatible = "qcom,pcie-sa8775p";
-		reg = <0x0 0x01c00000 0x0 0x3000>,
-		      <0x0 0x40000000 0x0 0xf20>,
-		      <0x0 0x40000f20 0x0 0xa8>,
-		      <0x0 0x40001000 0x0 0x4000>,
-		      <0x0 0x40100000 0x0 0x100000>,
-		      <0x0 0x01c03000 0x0 0x1000>;
-		reg-names = "parf", "dbi", "elbi", "atu", "config", "mhi";
-		device_type = "pci";
-
-		#address-cells = <3>;
-		#size-cells = <2>;
-		ranges = <0x01000000 0x0 0x00000000 0x0 0x40200000 0x0 0x100000>,
-			 <0x02000000 0x0 0x40300000 0x0 0x40300000 0x0 0x1fd00000>;
-		bus-range = <0x00 0xff>;
-
-		dma-coherent;
-
-		linux,pci-domain = <0>;
-		num-lanes = <2>;
-
-		interrupts = <GIC_SPI 307 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 308 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 309 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 312 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 313 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 314 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 374 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 375 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 306 IRQ_TYPE_LEVEL_HIGH>;
-		interrupt-names = "msi0",
-				  "msi1",
-				  "msi2",
-				  "msi3",
-				  "msi4",
-				  "msi5",
-				  "msi6",
-				  "msi7",
-				  "global";
-		#interrupt-cells = <1>;
-		interrupt-map-mask = <0 0 0 0x7>;
-		interrupt-map = <0 0 0 1 &intc GIC_SPI 434 IRQ_TYPE_LEVEL_HIGH>,
-				<0 0 0 2 &intc GIC_SPI 435 IRQ_TYPE_LEVEL_HIGH>,
-				<0 0 0 3 &intc GIC_SPI 438 IRQ_TYPE_LEVEL_HIGH>,
-				<0 0 0 4 &intc GIC_SPI 439 IRQ_TYPE_LEVEL_HIGH>;
-
-		clocks = <&gcc GCC_PCIE_0_AUX_CLK>,
-			 <&gcc GCC_PCIE_0_CFG_AHB_CLK>,
-			 <&gcc GCC_PCIE_0_MSTR_AXI_CLK>,
-			 <&gcc GCC_PCIE_0_SLV_AXI_CLK>,
-			 <&gcc GCC_PCIE_0_SLV_Q2A_AXI_CLK>;
-
-		clock-names = "aux",
-			      "cfg",
-			      "bus_master",
-			      "bus_slave",
-			      "slave_q2a";
-
-		assigned-clocks = <&gcc GCC_PCIE_0_AUX_CLK>;
-		assigned-clock-rates = <19200000>;
-
-		interconnects = <&pcie_anoc MASTER_PCIE_0 0 &mc_virt SLAVE_EBI1 0>,
-				<&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_0 0>;
-		interconnect-names = "pcie-mem", "cpu-pcie";
-
-		iommu-map = <0x0 &pcie_smmu 0x0000 0x1>,
-			    <0x100 &pcie_smmu 0x0001 0x1>;
-
-		resets = <&gcc GCC_PCIE_0_BCR>,
-			 <&gcc GCC_PCIE_0_LINK_DOWN_BCR>;
-		reset-names = "pci",
-			      "link_down";
-
-		power-domains = <&gcc PCIE_0_GDSC>;
-
-		phys = <&pcie0_phy>;
-		phy-names = "pciephy";
-
-		eq-presets-8gts = /bits/ 16 <0x5555 0x5555>;
-		eq-presets-16gts = /bits/ 8 <0x55 0x55>;
-
-		status = "disabled";
-
-		pcieport0: pcie@0 {
-			device_type = "pci";
-			reg = <0x0 0x0 0x0 0x0 0x0>;
-			bus-range = <0x01 0xff>;
-
-			#address-cells = <3>;
-			#size-cells = <2>;
-			ranges;
-		};
-	};
-
-	pcie0_ep: pcie-ep@1c00000 {
-		compatible = "qcom,sa8775p-pcie-ep";
-		reg = <0x0 0x01c00000 0x0 0x3000>,
-		      <0x0 0x40000000 0x0 0xf20>,
-		      <0x0 0x40000f20 0x0 0xa8>,
-		      <0x0 0x40001000 0x0 0x4000>,
-		      <0x0 0x40200000 0x0 0x1fe00000>,
-		      <0x0 0x01c03000 0x0 0x1000>,
-		      <0x0 0x40005000 0x0 0x2000>;
-		reg-names = "parf", "dbi", "elbi", "atu", "addr_space",
-			    "mmio", "dma";
-
-		clocks = <&gcc GCC_PCIE_0_AUX_CLK>,
-			<&gcc GCC_PCIE_0_CFG_AHB_CLK>,
-			<&gcc GCC_PCIE_0_MSTR_AXI_CLK>,
-			<&gcc GCC_PCIE_0_SLV_AXI_CLK>,
-			<&gcc GCC_PCIE_0_SLV_Q2A_AXI_CLK>;
-
-		clock-names = "aux",
-			      "cfg",
-			      "bus_master",
-			      "bus_slave",
-			      "slave_q2a";
-
-		interrupts = <GIC_SPI 306 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 147 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 630 IRQ_TYPE_LEVEL_HIGH>;
-
-		interrupt-names = "global", "doorbell", "dma";
-
-		interconnects = <&pcie_anoc MASTER_PCIE_0 0 &mc_virt SLAVE_EBI1 0>,
-				<&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_0 0>;
-		interconnect-names = "pcie-mem", "cpu-pcie";
-
-		dma-coherent;
-		iommus = <&pcie_smmu 0x0000 0x7f>;
-		resets = <&gcc GCC_PCIE_0_BCR>;
-		reset-names = "core";
-		power-domains = <&gcc PCIE_0_GDSC>;
-		phys = <&pcie0_phy>;
-		phy-names = "pciephy";
-		num-lanes = <2>;
-		linux,pci-domain = <0>;
-
-		status = "disabled";
-	};
-
-	pcie0_phy: phy@1c04000 {
-		compatible = "qcom,sa8775p-qmp-gen4x2-pcie-phy";
-		reg = <0x0 0x1c04000 0x0 0x2000>;
-
-		clocks = <&gcc GCC_PCIE_0_PHY_AUX_CLK>,
-			 <&gcc GCC_PCIE_0_CFG_AHB_CLK>,
-			 <&gcc GCC_PCIE_CLKREF_EN>,
-			 <&gcc GCC_PCIE_0_PHY_RCHNG_CLK>,
-			 <&gcc GCC_PCIE_0_PIPE_CLK>,
-			 <&gcc GCC_PCIE_0_PIPEDIV2_CLK>;
-		clock-names = "aux",
-			      "cfg_ahb",
-			      "ref",
-			      "rchng",
-			      "pipe",
-			      "pipediv2";
-
-		assigned-clocks = <&gcc GCC_PCIE_0_PHY_RCHNG_CLK>;
-		assigned-clock-rates = <100000000>;
-
-		resets = <&gcc GCC_PCIE_0_PHY_BCR>;
-		reset-names = "phy";
-
-		#clock-cells = <0>;
-		clock-output-names = "pcie_0_pipe_clk";
-
-		#phy-cells = <0>;
-
-		status = "disabled";
-	};
-
-	pcie1: pcie@1c10000 {
-		compatible = "qcom,pcie-sa8775p";
-		reg = <0x0 0x01c10000 0x0 0x3000>,
-		      <0x0 0x60000000 0x0 0xf20>,
-		      <0x0 0x60000f20 0x0 0xa8>,
-		      <0x0 0x60001000 0x0 0x4000>,
-		      <0x0 0x60100000 0x0 0x100000>,
-		      <0x0 0x01c13000 0x0 0x1000>;
-		reg-names = "parf", "dbi", "elbi", "atu", "config", "mhi";
-		device_type = "pci";
-
-		#address-cells = <3>;
-		#size-cells = <2>;
-		ranges = <0x01000000 0x0 0x00000000 0x0 0x60200000 0x0 0x100000>,
-			 <0x02000000 0x0 0x60300000 0x0 0x60300000 0x0 0x1fd00000>;
-		bus-range = <0x00 0xff>;
-
-		dma-coherent;
-
-		linux,pci-domain = <1>;
-		num-lanes = <4>;
-
-		interrupts = <GIC_SPI 519 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 140 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 141 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 142 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 143 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 144 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 145 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 146 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 518 IRQ_TYPE_LEVEL_HIGH>;
-		interrupt-names = "msi0",
-				  "msi1",
-				  "msi2",
-				  "msi3",
-				  "msi4",
-				  "msi5",
-				  "msi6",
-				  "msi7",
-				  "global";
-		#interrupt-cells = <1>;
-		interrupt-map-mask = <0 0 0 0x7>;
-		interrupt-map = <0 0 0 1 &intc GIC_SPI 148 IRQ_TYPE_LEVEL_HIGH>,
-				<0 0 0 2 &intc GIC_SPI 149 IRQ_TYPE_LEVEL_HIGH>,
-				<0 0 0 3 &intc GIC_SPI 150 IRQ_TYPE_LEVEL_HIGH>,
-				<0 0 0 4 &intc GIC_SPI 151 IRQ_TYPE_LEVEL_HIGH>;
-
-		clocks = <&gcc GCC_PCIE_1_AUX_CLK>,
-			 <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
-			 <&gcc GCC_PCIE_1_MSTR_AXI_CLK>,
-			 <&gcc GCC_PCIE_1_SLV_AXI_CLK>,
-			 <&gcc GCC_PCIE_1_SLV_Q2A_AXI_CLK>;
-
-		clock-names = "aux",
-			      "cfg",
-			      "bus_master",
-			      "bus_slave",
-			      "slave_q2a";
-
-		assigned-clocks = <&gcc GCC_PCIE_1_AUX_CLK>;
-		assigned-clock-rates = <19200000>;
-
-		interconnects = <&pcie_anoc MASTER_PCIE_1 0 &mc_virt SLAVE_EBI1 0>,
-				<&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_1 0>;
-		interconnect-names = "pcie-mem", "cpu-pcie";
-
-		iommu-map = <0x0 &pcie_smmu 0x0080 0x1>,
-			    <0x100 &pcie_smmu 0x0081 0x1>;
-
-		resets = <&gcc GCC_PCIE_1_BCR>,
-			 <&gcc GCC_PCIE_1_LINK_DOWN_BCR>;
-		reset-names = "pci",
-			      "link_down";
-
-		power-domains = <&gcc PCIE_1_GDSC>;
-
-		phys = <&pcie1_phy>;
-		phy-names = "pciephy";
-
-		eq-presets-8gts = /bits/ 16 <0x5555 0x5555 0x5555 0x5555>;
-		eq-presets-16gts = /bits/ 8 <0x55 0x55 0x55 0x55>;
-
-		status = "disabled";
-
-		pcie@0 {
-			device_type = "pci";
-			reg = <0x0 0x0 0x0 0x0 0x0>;
-			bus-range = <0x01 0xff>;
-
-			#address-cells = <3>;
-			#size-cells = <2>;
-			ranges;
-		};
-	};
-
-	pcie1_ep: pcie-ep@1c10000 {
-		compatible = "qcom,sa8775p-pcie-ep";
-		reg = <0x0 0x01c10000 0x0 0x3000>,
-		      <0x0 0x60000000 0x0 0xf20>,
-		      <0x0 0x60000f20 0x0 0xa8>,
-		      <0x0 0x60001000 0x0 0x4000>,
-		      <0x0 0x60200000 0x0 0x1fe00000>,
-		      <0x0 0x01c13000 0x0 0x1000>,
-		      <0x0 0x60005000 0x0 0x2000>;
-		reg-names = "parf", "dbi", "elbi", "atu", "addr_space",
-			    "mmio", "dma";
-
-		clocks = <&gcc GCC_PCIE_1_AUX_CLK>,
-			 <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
-			 <&gcc GCC_PCIE_1_MSTR_AXI_CLK>,
-			 <&gcc GCC_PCIE_1_SLV_AXI_CLK>,
-			 <&gcc GCC_PCIE_1_SLV_Q2A_AXI_CLK>;
-
-		clock-names = "aux",
-			      "cfg",
-			      "bus_master",
-			      "bus_slave",
-			      "slave_q2a";
-
-		interrupts = <GIC_SPI 518 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 152 IRQ_TYPE_LEVEL_HIGH>,
-			     <GIC_SPI 474 IRQ_TYPE_LEVEL_HIGH>;
-
-		interrupt-names = "global", "doorbell", "dma";
-
-		interconnects = <&pcie_anoc MASTER_PCIE_1 0 &mc_virt SLAVE_EBI1 0>,
-				<&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_1 0>;
-		interconnect-names = "pcie-mem", "cpu-pcie";
-
-		dma-coherent;
-		iommus = <&pcie_smmu 0x80 0x7f>;
-		resets = <&gcc GCC_PCIE_1_BCR>;
-		reset-names = "core";
-		power-domains = <&gcc PCIE_1_GDSC>;
-		phys = <&pcie1_phy>;
-		phy-names = "pciephy";
-		num-lanes = <4>;
-		linux,pci-domain = <1>;
-
-		status = "disabled";
-	};
-
-	pcie1_phy: phy@1c14000 {
-		compatible = "qcom,sa8775p-qmp-gen4x4-pcie-phy";
-		reg = <0x0 0x1c14000 0x0 0x4000>;
-
-		clocks = <&gcc GCC_PCIE_1_PHY_AUX_CLK>,
-			 <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
-			 <&gcc GCC_PCIE_CLKREF_EN>,
-			 <&gcc GCC_PCIE_1_PHY_RCHNG_CLK>,
-			 <&gcc GCC_PCIE_1_PIPE_CLK>,
-			 <&gcc GCC_PCIE_1_PIPEDIV2_CLK>;
-		clock-names = "aux",
-			      "cfg_ahb",
-			      "ref",
-			      "rchng",
-			      "pipe",
-			      "pipediv2";
-
-		assigned-clocks = <&gcc GCC_PCIE_1_PHY_RCHNG_CLK>;
-		assigned-clock-rates = <100000000>;
-
-		resets = <&gcc GCC_PCIE_1_PHY_BCR>;
-		reset-names = "phy";
-
-		#clock-cells = <0>;
-		clock-output-names = "pcie_1_pipe_clk";
-
-		#phy-cells = <0>;
-
-		status = "disabled";
-	};
 };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0179/2077] media: iris: scale MMCX power domain on SM8250
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (177 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0178/2077] arm64: dts: qcom: lemans: Move PCIe devices into soc node Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0180/2077] media: venus: " Greg Kroah-Hartman
                   ` (818 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dikshita Agarwal, Dmitry Baryshkov,
	Bryan ODonoghue, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>

[ Upstream commit 4170e2f25ce40b69f3827fcdabf395380095e136 ]

On SM8250 most of the video clocks are powered by the MMCX domain, while
the PLL is powered on by the MX domain. Extend the driver to support
scaling both power domains, while keeping compatibility with the
existing DTs, which define only the MX domain.

Fixes: 79865252acb6 ("media: iris: enable video driver probe of SM8250 SoC")
Reviewed-by: Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/media/platform/qcom/iris/iris_platform_gen1.c | 2 +-
 drivers/media/platform/qcom/iris/iris_probe.c         | 7 +++++++
 2 files changed, 8 insertions(+), 1 deletion(-)

diff --git a/drivers/media/platform/qcom/iris/iris_platform_gen1.c b/drivers/media/platform/qcom/iris/iris_platform_gen1.c
index df8e6bf9430ed2..aa71f7f53ee344 100644
--- a/drivers/media/platform/qcom/iris/iris_platform_gen1.c
+++ b/drivers/media/platform/qcom/iris/iris_platform_gen1.c
@@ -281,7 +281,7 @@ static const struct bw_info sm8250_bw_table_dec[] = {
 
 static const char * const sm8250_pmdomain_table[] = { "venus", "vcodec0" };
 
-static const char * const sm8250_opp_pd_table[] = { "mx" };
+static const char * const sm8250_opp_pd_table[] = { "mx", "mmcx" };
 
 static const struct platform_clk_data sm8250_clk_table[] = {
 	{IRIS_AXI_CLK,  "iface"        },
diff --git a/drivers/media/platform/qcom/iris/iris_probe.c b/drivers/media/platform/qcom/iris/iris_probe.c
index ddaacda523ecb9..487eb0917c0e2d 100644
--- a/drivers/media/platform/qcom/iris/iris_probe.c
+++ b/drivers/media/platform/qcom/iris/iris_probe.c
@@ -64,6 +64,13 @@ static int iris_init_power_domains(struct iris_core *core)
 		return ret;
 
 	ret =  devm_pm_domain_attach_list(core->dev, &iris_opp_pd_data, &core->opp_pmdomain_tbl);
+	/* backwards compatibility for incomplete ABI SM8250 */
+	if (ret == -ENODEV &&
+	    of_device_is_compatible(core->dev->of_node, "qcom,sm8250-venus")) {
+		iris_opp_pd_data.num_pd_names--;
+		ret = devm_pm_domain_attach_list(core->dev, &iris_opp_pd_data,
+						 &core->opp_pmdomain_tbl);
+	}
 	if (ret < 0)
 		return ret;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0180/2077] media: venus: scale MMCX power domain on SM8250
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (178 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0179/2077] media: iris: scale MMCX power domain on SM8250 Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0181/2077] iommu/amd: Fix a stale comment about which legacy mode is user visible Greg Kroah-Hartman
                   ` (817 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bryan ODonoghue, Dikshita Agarwal,
	Dmitry Baryshkov, Bryan ODonoghue, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>

[ Upstream commit f45fd3dbb5f6d60a8b31d5cc4affaf1ef40163b3 ]

On SM8250 most of the video clocks are powered by the MMCX domain, while
the PLL is powered on by the MX domain. Extend the driver to support
scaling both power domains, while keeping compatibility with the
existing DTs, which define only the MX domain.

Fixes: 0aeabfa29a9c ("media: venus: core: add sm8250 DT compatible and resource data")
Reviewed-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
Reviewed-by: Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/media/platform/qcom/venus/core.c       | 7 ++++++-
 drivers/media/platform/qcom/venus/core.h       | 1 +
 drivers/media/platform/qcom/venus/pm_helpers.c | 8 +++++++-
 3 files changed, 14 insertions(+), 2 deletions(-)

diff --git a/drivers/media/platform/qcom/venus/core.c b/drivers/media/platform/qcom/venus/core.c
index 7e639760c41d95..00fb6806c12988 100644
--- a/drivers/media/platform/qcom/venus/core.c
+++ b/drivers/media/platform/qcom/venus/core.c
@@ -882,6 +882,7 @@ static const struct venus_resources sdm845_res_v2 = {
 	.vcodec_pmdomains = (const char *[]) { "venus", "vcodec0", "vcodec1" },
 	.vcodec_pmdomains_num = 3,
 	.opp_pmdomain = (const char *[]) { "cx" },
+	.opp_pmdomain_num = 1,
 	.vcodec_num = 2,
 	.max_load = 3110400,	/* 4096x2160@90 */
 	.hfi_version = HFI_VERSION_4XX,
@@ -933,6 +934,7 @@ static const struct venus_resources sc7180_res = {
 	.vcodec_pmdomains = (const char *[]) { "venus", "vcodec0" },
 	.vcodec_pmdomains_num = 2,
 	.opp_pmdomain = (const char *[]) { "cx" },
+	.opp_pmdomain_num = 1,
 	.vcodec_num = 1,
 	.hfi_version = HFI_VERSION_4XX,
 	.vpu_version = VPU_VERSION_AR50,
@@ -991,7 +993,8 @@ static const struct venus_resources sm8250_res = {
 	.vcodec_clks_num = 1,
 	.vcodec_pmdomains = (const char *[]) { "venus", "vcodec0" },
 	.vcodec_pmdomains_num = 2,
-	.opp_pmdomain = (const char *[]) { "mx" },
+	.opp_pmdomain = (const char *[]) { "mx", "mmcx" },
+	.opp_pmdomain_num = 2,
 	.vcodec_num = 1,
 	.max_load = 7833600,
 	.hfi_version = HFI_VERSION_6XX,
@@ -1053,6 +1056,7 @@ static const struct venus_resources sc7280_res = {
 	.vcodec_pmdomains = (const char *[]) { "venus", "vcodec0" },
 	.vcodec_pmdomains_num = 2,
 	.opp_pmdomain = (const char *[]) { "cx" },
+	.opp_pmdomain_num = 1,
 	.vcodec_num = 1,
 	.hfi_version = HFI_VERSION_6XX,
 	.vpu_version = VPU_VERSION_IRIS2_1,
@@ -1100,6 +1104,7 @@ static const struct venus_resources qcm2290_res = {
 	.vcodec_pmdomains = (const char *[]) { "venus", "vcodec0" },
 	.vcodec_pmdomains_num = 2,
 	.opp_pmdomain = (const char *[]) { "cx" },
+	.opp_pmdomain_num = 1,
 	.vcodec_num = 1,
 	.hfi_version = HFI_VERSION_4XX,
 	.vpu_version = VPU_VERSION_AR50_LITE,
diff --git a/drivers/media/platform/qcom/venus/core.h b/drivers/media/platform/qcom/venus/core.h
index 7506f5d0f609ac..70e7b40affa938 100644
--- a/drivers/media/platform/qcom/venus/core.h
+++ b/drivers/media/platform/qcom/venus/core.h
@@ -83,6 +83,7 @@ struct venus_resources {
 	const char **vcodec_pmdomains;
 	unsigned int vcodec_pmdomains_num;
 	const char **opp_pmdomain;
+	unsigned int opp_pmdomain_num;
 	unsigned int vcodec_num;
 	const char * const resets[VIDC_RESETS_NUM_MAX];
 	unsigned int resets_num;
diff --git a/drivers/media/platform/qcom/venus/pm_helpers.c b/drivers/media/platform/qcom/venus/pm_helpers.c
index f0269524ac70eb..14a4e8311a6431 100644
--- a/drivers/media/platform/qcom/venus/pm_helpers.c
+++ b/drivers/media/platform/qcom/venus/pm_helpers.c
@@ -887,7 +887,7 @@ static int vcodec_domains_get(struct venus_core *core)
 	};
 	struct dev_pm_domain_attach_data opp_pd_data = {
 		.pd_names = res->opp_pmdomain,
-		.num_pd_names = 1,
+		.num_pd_names = res->opp_pmdomain_num,
 		.pd_flags = PD_FLAG_DEV_LINK_ON | PD_FLAG_REQUIRED_OPP,
 	};
 
@@ -904,6 +904,12 @@ static int vcodec_domains_get(struct venus_core *core)
 
 	/* Attach the power domain for setting performance state */
 	ret = devm_pm_domain_attach_list(dev, &opp_pd_data, &core->opp_pmdomain);
+	/* backwards compatibility for incomplete ABI SM8250 */
+	if (ret == -ENODEV &&
+	    of_device_is_compatible(dev->of_node, "qcom,sm8250-venus")) {
+		opp_pd_data.num_pd_names--;
+		ret = devm_pm_domain_attach_list(dev, &opp_pd_data, &core->opp_pmdomain);
+	}
 	if (ret < 0)
 		return ret;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0181/2077] iommu/amd: Fix a stale comment about which legacy mode is user visible
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (179 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0180/2077] media: venus: " Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0182/2077] soc: mediatek: mtk-mmsys: Restore MT8167 routing masks lost during merge Greg Kroah-Hartman
                   ` (816 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sean Christopherson, Vasant Hegde,
	Wei Wang, Joerg Roedel, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

[ Upstream commit 4bf53c2d0c08bbdaa32f2114281f1ddab61902bf ]

Update a stale comment about which of the legacy modes is visible to the
user, i.e. can be forced via amd_iommu_intr=legacy.

Fixes: b74aa02d7a30 ("iommu/amd: Fix legacy interrupt remapping for x2APIC-enabled system")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Reviewed-by: Vasant Hegde <vasant.hegde@amd.com>
Reviewed-by: Wei Wang <wei.w.wang@hotmail.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iommu/amd/amd_iommu_types.h | 11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

diff --git a/drivers/iommu/amd/amd_iommu_types.h b/drivers/iommu/amd/amd_iommu_types.h
index f9f71808789303..c726d115939a6b 100644
--- a/drivers/iommu/amd/amd_iommu_types.h
+++ b/drivers/iommu/amd/amd_iommu_types.h
@@ -948,12 +948,13 @@ static inline int get_hpet_devid(int id)
 }
 
 enum amd_iommu_intr_mode_type {
-	AMD_IOMMU_GUEST_IR_LEGACY,
-
-	/* This mode is not visible to users. It is used when
-	 * we cannot fully enable vAPIC and fallback to only support
-	 * legacy interrupt remapping via 128-bit IRTE.
+	/*
+	 * The legacy format mode is not visible to users to prevent the user
+	 * from crashing x2APIC systems, which for all intents and purposes
+	 * require 128-bit IRTEs.   The legacy format will be forced as needed
+	 * when hardware doesn't support 128-bit IRTEs.
 	 */
+	AMD_IOMMU_GUEST_IR_LEGACY,
 	AMD_IOMMU_GUEST_IR_LEGACY_GA,
 	AMD_IOMMU_GUEST_IR_VAPIC,
 };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0182/2077] soc: mediatek: mtk-mmsys: Restore MT8167 routing masks lost during merge
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (180 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0181/2077] iommu/amd: Fix a stale comment about which legacy mode is user visible Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0183/2077] bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries Greg Kroah-Hartman
                   ` (815 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Luca Leonardo Scorcia,
	AngeloGioacchino Del Regno, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Luca Leonardo Scorcia <l.scorcia@gmail.com>

[ Upstream commit 7d462de9f65b002b439b1b168bf3b5579b0de48b ]

The original patch that was sent to the mailing lists included the values
for the route masks, but they got lost during merge: add back the full
register masks where missing.

Fixes: 060f7875bd23 ("soc: mediatek: mmsys: Add support for MT8167 SoC")
Signed-off-by: Luca Leonardo Scorcia <l.scorcia@gmail.com>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/soc/mediatek/mt8167-mmsys.h | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

diff --git a/drivers/soc/mediatek/mt8167-mmsys.h b/drivers/soc/mediatek/mt8167-mmsys.h
index c468926561b475..eef14083c47b5a 100644
--- a/drivers/soc/mediatek/mt8167-mmsys.h
+++ b/drivers/soc/mediatek/mt8167-mmsys.h
@@ -10,24 +10,29 @@
 #define MT8167_DISP_REG_CONFIG_DISP_RDMA0_SOUT_SEL_IN	0x06c
 
 #define MT8167_DITHER_MOUT_EN_RDMA0			0x1
+#define MT8167_DITHER_MOUT_EN_MASK			0x7
+
 #define MT8167_RDMA0_SOUT_DSI0				0x2
+#define MT8167_RDMA0_SOUT_MASK				0x3
+
 #define MT8167_DSI0_SEL_IN_RDMA0			0x1
+#define MT8167_DSI0_SEL_IN_MASK				0x3
 
 static const struct mtk_mmsys_routes mt8167_mmsys_routing_table[] = {
 	MMSYS_ROUTE(OVL0, COLOR0,
 		    MT8167_DISP_REG_CONFIG_DISP_OVL0_MOUT_EN, OVL0_MOUT_EN_COLOR0,
 		    OVL0_MOUT_EN_COLOR0),
 	MMSYS_ROUTE(DITHER0, RDMA0,
-		    MT8167_DISP_REG_CONFIG_DISP_DITHER_MOUT_EN, MT8167_DITHER_MOUT_EN_RDMA0,
+		    MT8167_DISP_REG_CONFIG_DISP_DITHER_MOUT_EN, MT8167_DITHER_MOUT_EN_MASK,
 		    MT8167_DITHER_MOUT_EN_RDMA0),
 	MMSYS_ROUTE(OVL0, COLOR0,
 		    MT8167_DISP_REG_CONFIG_DISP_COLOR0_SEL_IN, COLOR0_SEL_IN_OVL0,
 		    COLOR0_SEL_IN_OVL0),
 	MMSYS_ROUTE(RDMA0, DSI0,
-		    MT8167_DISP_REG_CONFIG_DISP_DSI0_SEL_IN, MT8167_DSI0_SEL_IN_RDMA0,
+		    MT8167_DISP_REG_CONFIG_DISP_DSI0_SEL_IN, MT8167_DSI0_SEL_IN_MASK,
 		    MT8167_DSI0_SEL_IN_RDMA0),
 	MMSYS_ROUTE(RDMA0, DSI0,
-		    MT8167_DISP_REG_CONFIG_DISP_RDMA0_SOUT_SEL_IN, MT8167_RDMA0_SOUT_DSI0,
+		    MT8167_DISP_REG_CONFIG_DISP_RDMA0_SOUT_SEL_IN, MT8167_RDMA0_SOUT_MASK,
 		    MT8167_RDMA0_SOUT_DSI0),
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0183/2077] bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (181 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0182/2077] soc: mediatek: mtk-mmsys: Restore MT8167 routing masks lost during merge Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0184/2077] uaccess: fix ignored_trailing logic in copy_struct_to_user() Greg Kroah-Hartman
                   ` (814 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Quan Sun, Matt Bobrowski,
	Christian Brauner, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matt Bobrowski <mattbobrowski@google.com>

[ Upstream commit 07410646f6ff1d23222f105ccab778957d401bbe ]

bpf_set_dentry_xattr and bpf_remove_dentry_xattr BPF kfuncs attempt to
lock the inode of the supplied dentry without checking if it is
NULL. If a negative dentry is passed (e.g. from
security_inode_create), d_inode(dentry) returns NULL, and
inode_lock(inode) will cause a NULL pointer dereference.

Trivially fix this by adding a NULL check for inode before attempting
to lock it, returning -EINVAL if it is NULL.

Additionally, drop WARN_ON(!inode) in bpf_xattr_read_permission() and
bpf_xattr_write_permission(). These warnings could be triggered by
passing a negative dentry to bpf_get_dentry_xattr() or the _locked
variants of the xattr kfuncs, potentially causing a Denial of Service
on systems with panic_on_warn enabled. Instead, simply return -EINVAL.

Reported-by: Quan Sun <2022090917019@std.uestc.edu.cn>
Closes: https://lore.kernel.org/bpf/1587cbf4-1293-4e25-ad24-c970836a1686@std.uestc.edu.cn/
Fixes: 56467292794b ("bpf: fs/xattr: Add BPF kfuncs to set and remove xattrs")
Signed-off-by: Matt Bobrowski <mattbobrowski@google.com>
Link: https://patch.msgid.link/20260430073836.2894001-1-mattbobrowski@google.com
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/bpf_fs_kfuncs.c | 10 ++++++++--
 1 file changed, 8 insertions(+), 2 deletions(-)

diff --git a/fs/bpf_fs_kfuncs.c b/fs/bpf_fs_kfuncs.c
index e4e51a1d0de281..606319dd69e803 100644
--- a/fs/bpf_fs_kfuncs.c
+++ b/fs/bpf_fs_kfuncs.c
@@ -100,7 +100,7 @@ static bool match_security_bpf_prefix(const char *name__str)
 
 static int bpf_xattr_read_permission(const char *name, struct inode *inode)
 {
-	if (WARN_ON(!inode))
+	if (!inode)
 		return -EINVAL;
 
 	/* Allow reading xattr with user. and security.bpf. prefix */
@@ -170,7 +170,7 @@ __bpf_kfunc_end_defs();
 
 static int bpf_xattr_write_permission(const char *name, struct inode *inode)
 {
-	if (WARN_ON(!inode))
+	if (!inode)
 		return -EINVAL;
 
 	/* Only allow setting and removing security.bpf. xattrs */
@@ -289,6 +289,9 @@ __bpf_kfunc int bpf_set_dentry_xattr(struct dentry *dentry, const char *name__st
 	struct inode *inode = d_inode(dentry);
 	int ret;
 
+	if (!inode)
+		return -EINVAL;
+
 	inode_lock(inode);
 	ret = bpf_set_dentry_xattr_locked(dentry, name__str, value_p, flags);
 	inode_unlock(inode);
@@ -314,6 +317,9 @@ __bpf_kfunc int bpf_remove_dentry_xattr(struct dentry *dentry, const char *name_
 	struct inode *inode = d_inode(dentry);
 	int ret;
 
+	if (!inode)
+		return -EINVAL;
+
 	inode_lock(inode);
 	ret = bpf_remove_dentry_xattr_locked(dentry, name__str);
 	inode_unlock(inode);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0184/2077] uaccess: fix ignored_trailing logic in copy_struct_to_user()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (182 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0183/2077] bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0185/2077] sockptr: fix usize check in copy_struct_from_sockptr() for user pointers Greg Kroah-Hartman
                   ` (813 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Safonov, Dmitry Safonov,
	Francesco Ruggeri, Salam Noureddine, David Ahern, David S. Miller,
	Michal Luczaj, David Wei, Luiz Augusto von Dentz,
	Luiz Augusto von Dentz, Marcel Holtmann, Xin Long, Eric Dumazet,
	Kuniyuki Iwashima, Paolo Abeni, Willem de Bruijn, Neal Cardwell,
	Jakub Kicinski, Simon Horman, Aleksa Sarai, Christian Brauner,
	Kees Cook, netdev, linux-bluetooth, linux-kernel,
	Stefan Metzmacher, Aleksa Sarai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stefan Metzmacher <metze@samba.org>

[ Upstream commit 4911de3145a797389577abfdf9a5185d36cc18d7 ]

Currently all callers pass ignored_trailing=NULL, but I have
code that will make use of.

Now it actually behaves like documented:

* If @usize < @ksize, then the kernel is trying to pass userspace a newer
  struct than it supports. Thus we only copy the interoperable portions
  (@usize) and ignore the rest (but @ignored_trailing is set to %true if
  any of the trailing (@ksize - @usize) bytes are non-zero).

Fixes: 424a55a4a908 ("uaccess: add copy_struct_to_user helper")
Cc: Dmitry Safonov <0x7f454c46@gmail.com>
Cc: Dmitry Safonov <dima@arista.com>
Cc: Francesco Ruggeri <fruggeri@arista.com>
Cc: Salam Noureddine <noureddine@arista.com>
Cc: David Ahern <dsahern@kernel.org>
Cc: David S. Miller <davem@davemloft.net>
Cc: Michal Luczaj <mhal@rbox.co>
Cc: David Wei <dw@davidwei.uk>
Cc: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Cc: Luiz Augusto von Dentz <luiz.dentz@gmail.com>
Cc: Marcel Holtmann <marcel@holtmann.org>
Cc: Xin Long <lucien.xin@gmail.com>
Cc: Eric Dumazet <edumazet@google.com>
Cc: Kuniyuki Iwashima <kuniyu@google.com>
Cc: Paolo Abeni <pabeni@redhat.com>
Cc: Willem de Bruijn <willemb@google.com>
Cc: Neal Cardwell <ncardwell@google.com>
Cc: Jakub Kicinski <kuba@kernel.org>
Cc: Simon Horman <horms@kernel.org>
Cc: Aleksa Sarai <cyphar@cyphar.com>
Cc: Christian Brauner <brauner@kernel.org>
CC: Kees Cook <keescook@chromium.org>
Cc: netdev@vger.kernel.org
Cc: linux-bluetooth@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Signed-off-by: Stefan Metzmacher <metze@samba.org>
Link: https://patch.msgid.link/71f69442410c1186ed8ce6d5b4b9d4a5a70edbad.1775576651.git.metze@samba.org
Reviewed-by: Aleksa Sarai <aleksa@amutable.com>
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/uaccess.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/linux/uaccess.h b/include/linux/uaccess.h
index 56328601218c5a..09a09cc4aac274 100644
--- a/include/linux/uaccess.h
+++ b/include/linux/uaccess.h
@@ -510,7 +510,7 @@ copy_struct_to_user(void __user *dst, size_t usize, const void *src,
 			return -EFAULT;
 	}
 	if (ignored_trailing)
-		*ignored_trailing = ksize < usize &&
+		*ignored_trailing = usize < ksize &&
 			memchr_inv(src + size, 0, rest) != NULL;
 	/* Copy the interoperable parts of the struct. */
 	if (copy_to_user(dst, src, size))
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0185/2077] sockptr: fix usize check in copy_struct_from_sockptr() for user pointers
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (183 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0184/2077] uaccess: fix ignored_trailing logic in copy_struct_to_user() Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0186/2077] arm64: dts: mediatek: mt7988a-bpi-r4pro: rework pcie gpio-hog handling Greg Kroah-Hartman
                   ` (812 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Safonov, Dmitry Safonov,
	Francesco Ruggeri, Salam Noureddine, David Ahern, David S. Miller,
	Michal Luczaj, David Wei, Luiz Augusto von Dentz,
	Luiz Augusto von Dentz, Marcel Holtmann, Xin Long, Eric Dumazet,
	Kuniyuki Iwashima, Paolo Abeni, Willem de Bruijn, Neal Cardwell,
	Jakub Kicinski, Simon Horman, Aleksa Sarai, Christian Brauner,
	Kees Cook, netdev, linux-bluetooth, linux-kernel,
	Stefan Metzmacher, Aleksa Sarai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stefan Metzmacher <metze@samba.org>

[ Upstream commit db0493512931fe1e5a71612e6a358df1aa22d80c ]

copy_struct_from_user will never hit the check_zeroed_user() call
and will never return -E2BIG if new userspace passed new bits in a
larger structure than the current kernel structure.

As far as I can there are no critical/related uapi changes in

- include/net/bluetooth/bluetooth.h and net/bluetooth/sco.c
  after the use of copy_struct_from_sockptr in v6.13-rc3
- include/uapi/linux/tcp.h and net/ipv4/tcp_ao.c
  after the use of copy_struct_from_sockptr in v6.6-rc1

So that new callers will get the correct behavior from the start.

Fixes: 4954f17ddefc ("net/tcp: Introduce TCP_AO setsockopt()s")
Fixes: ef84703a911f ("net/tcp: Add TCP-AO getsockopt()s")
Fixes: faadfaba5e01 ("net/tcp: Add TCP_AO_REPAIR")
Fixes: 3e643e4efa1e ("Bluetooth: Improve setsockopt() handling of malformed user input")
Cc: Dmitry Safonov <0x7f454c46@gmail.com>
Cc: Dmitry Safonov <dima@arista.com>
Cc: Francesco Ruggeri <fruggeri@arista.com>
Cc: Salam Noureddine <noureddine@arista.com>
Cc: David Ahern <dsahern@kernel.org>
Cc: David S. Miller <davem@davemloft.net>
Cc: Michal Luczaj <mhal@rbox.co>
Cc: David Wei <dw@davidwei.uk>
Cc: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Cc: Luiz Augusto von Dentz <luiz.dentz@gmail.com>
Cc: Marcel Holtmann <marcel@holtmann.org>
Cc: Xin Long <lucien.xin@gmail.com>
Cc: Eric Dumazet <edumazet@google.com>
Cc: Kuniyuki Iwashima <kuniyu@google.com>
Cc: Paolo Abeni <pabeni@redhat.com>
Cc: Willem de Bruijn <willemb@google.com>
Cc: Neal Cardwell <ncardwell@google.com>
Cc: Jakub Kicinski <kuba@kernel.org>
Cc: Simon Horman <horms@kernel.org>
Cc: Aleksa Sarai <cyphar@cyphar.com>
Cc: Christian Brauner <brauner@kernel.org>
CC: Kees Cook <keescook@chromium.org>
Cc: netdev@vger.kernel.org
Cc: linux-bluetooth@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Signed-off-by: Stefan Metzmacher <metze@samba.org>
Link: https://patch.msgid.link/cfaedbc33ae9d36adaabf04fa79424f30ff1efdd.1775576651.git.metze@samba.org
Reviewed-by: Aleksa Sarai <aleksa@amutable.com>
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/sockptr.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/linux/sockptr.h b/include/linux/sockptr.h
index 3e6c8e9d67aef6..ba88f4d78c1b16 100644
--- a/include/linux/sockptr.h
+++ b/include/linux/sockptr.h
@@ -91,7 +91,7 @@ static inline int copy_struct_from_sockptr(void *dst, size_t ksize,
 	size_t rest = max(ksize, usize) - size;
 
 	if (!sockptr_is_kernel(src))
-		return copy_struct_from_user(dst, ksize, src.user, size);
+		return copy_struct_from_user(dst, ksize, src.user, usize);
 
 	if (usize < ksize) {
 		memset(dst + size, 0, rest);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0186/2077] arm64: dts: mediatek: mt7988a-bpi-r4pro: rework pcie gpio-hog handling
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (184 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0185/2077] sockptr: fix usize check in copy_struct_from_sockptr() for user pointers Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0187/2077] arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host Greg Kroah-Hartman
                   ` (811 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Frank Wunderlich,
	AngeloGioacchino Del Regno, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Frank Wunderlich <frank-w@public-files.de>

[ Upstream commit e309fa232d12b969afac43a4b7d83dee025cfe63 ]

The active-high property in base-dt cannot be overwritten and must be
set in separate overlay.

Fixes: f397471a6a8c ("arm64: dts: mediatek: mt7988: Add devicetree for BananaPi R4 Pro")
Signed-off-by: Frank Wunderlich <frank-w@public-files.de>
Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/mediatek/Makefile         |  8 ++++++++
 .../mt7988a-bananapi-bpi-r4-pro-cn13.dtso     | 20 +++++++++++++++++++
 .../mt7988a-bananapi-bpi-r4-pro-cn14.dtso     | 20 +++++++++++++++++++
 .../mediatek/mt7988a-bananapi-bpi-r4-pro.dtsi |  2 --
 4 files changed, 48 insertions(+), 2 deletions(-)
 create mode 100644 arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro-cn13.dtso
 create mode 100644 arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro-cn14.dtso

diff --git a/arch/arm64/boot/dts/mediatek/Makefile b/arch/arm64/boot/dts/mediatek/Makefile
index 387faa9c2a09b5..a86fb313b1a9db 100644
--- a/arch/arm64/boot/dts/mediatek/Makefile
+++ b/arch/arm64/boot/dts/mediatek/Makefile
@@ -47,6 +47,8 @@ dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-2g5.dtb
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-emmc.dtbo
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-pro-4e.dtb
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-pro-8x.dtb
+dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-pro-cn13.dtbo
+dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-pro-cn14.dtbo
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-pro-cn15.dtbo
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-pro-cn18.dtbo
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-pro-emmc.dtbo
@@ -70,18 +72,24 @@ mt7988a-bananapi-bpi-r4-2g5-sd-dtbs := \
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-2g5-sd.dtb
 mt7988a-bananapi-bpi-r4-pro-8x-emmc-dtbs := \
 	mt7988a-bananapi-bpi-r4-pro-8x.dtb \
+	mt7988a-bananapi-bpi-r4-pro-cn13.dtbo \
+	mt7988a-bananapi-bpi-r4-pro-cn14.dtbo \
 	mt7988a-bananapi-bpi-r4-pro-emmc.dtbo
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-pro-8x-emmc.dtb
 mt7988a-bananapi-bpi-r4-pro-8x-sd-dtbs := \
 	mt7988a-bananapi-bpi-r4-pro-8x.dtb \
+	mt7988a-bananapi-bpi-r4-pro-cn13.dtbo \
+	mt7988a-bananapi-bpi-r4-pro-cn14.dtbo \
 	mt7988a-bananapi-bpi-r4-pro-sd.dtbo
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-pro-8x-sd.dtb
 mt7988a-bananapi-bpi-r4-pro-8x-sd-cn15-dtbs := \
 	mt7988a-bananapi-bpi-r4-pro-8x-sd.dtb \
+	mt7988a-bananapi-bpi-r4-pro-cn14.dtbo \
 	mt7988a-bananapi-bpi-r4-pro-cn15.dtbo
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-pro-8x-sd-cn15.dtb
 mt7988a-bananapi-bpi-r4-pro-8x-sd-cn18-dtbs := \
 	mt7988a-bananapi-bpi-r4-pro-8x-sd.dtb \
+	mt7988a-bananapi-bpi-r4-pro-cn13.dtbo \
 	mt7988a-bananapi-bpi-r4-pro-cn18.dtbo
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt7988a-bananapi-bpi-r4-pro-8x-sd-cn18.dtb
 dtb-$(CONFIG_ARCH_MEDIATEK) += mt8167-pumpkin.dtb
diff --git a/arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro-cn13.dtso b/arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro-cn13.dtso
new file mode 100644
index 00000000000000..973b76ba0cbfba
--- /dev/null
+++ b/arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro-cn13.dtso
@@ -0,0 +1,20 @@
+// SPDX-License-Identifier: (GPL-2.0 OR MIT)
+/*
+ * Copyright (C) 2025 MediaTek Inc.
+ * Author: Frank Wunderlich <frank-w@public-files.de>
+ */
+
+/* This enables key-m slot CN13 on pcie2(11280000 1L0) on BPI-R4-Pro */
+
+/dts-v1/;
+/plugin/;
+
+#include <dt-bindings/gpio/gpio.h>
+
+/ {
+	compatible = "bananapi,bpi-r4-pro", "mediatek,mt7988a";
+};
+
+&{/soc/pinctrl@1001f000/pcie-2-hog} {
+	output-high;
+};
diff --git a/arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro-cn14.dtso b/arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro-cn14.dtso
new file mode 100644
index 00000000000000..90b2a64459c316
--- /dev/null
+++ b/arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro-cn14.dtso
@@ -0,0 +1,20 @@
+// SPDX-License-Identifier: (GPL-2.0 OR MIT)
+/*
+ * Copyright (C) 2025 MediaTek Inc.
+ * Author: Frank Wunderlich <frank-w@public-files.de>
+ */
+
+/* This enables key-m slot CN14 on pcie3(11290000 1L1) on BPI-R4-Pro */
+
+/dts-v1/;
+/plugin/;
+
+#include <dt-bindings/gpio/gpio.h>
+
+/ {
+	compatible = "bananapi,bpi-r4-pro", "mediatek,mt7988a";
+};
+
+&{/soc/pinctrl@1001f000/pcie-3-hog} {
+	output-high;
+};
diff --git a/arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro.dtsi b/arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro.dtsi
index a48132f0941143..ff778e8305d5be 100644
--- a/arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro.dtsi
+++ b/arch/arm64/boot/dts/mediatek/mt7988a-bananapi-bpi-r4-pro.dtsi
@@ -437,14 +437,12 @@ mux {
 	pcie-2-hog {
 		gpio-hog;
 		gpios = <79 GPIO_ACTIVE_HIGH>;
-		output-high;
 	};
 
 	/* 1L1 0=key-b (CN18), 1=key-m (CN14) */
 	pcie-3-hog {
 		gpio-hog;
 		gpios = <63 GPIO_ACTIVE_HIGH>;
-		output-high;
 	};
 
 	pwm0_pins: pwm0-pins {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0187/2077] arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (185 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0186/2077] arm64: dts: mediatek: mt7988a-bpi-r4pro: rework pcie gpio-hog handling Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0188/2077] workqueue: forbid TEST_WORKQUEUE from being built-in Greg Kroah-Hartman
                   ` (810 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chen-Yu Tsai,
	AngeloGioacchino Del Regno, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chen-Yu Tsai <wenst@chromium.org>

[ Upstream commit 533275a4b5240a2bf2c592bd4536560388306d26 ]

The DMA bounce buffer is attached to the PCIe host controller, i.e. all
PCIe DMA transfers should use it.

Move it from the PCIe (WiFi) device node down to the PCIe host
controller node.

Fixes: 0dca9f0b3e63 ("arm64: dts: mediatek: asurada: Enable PCIe and add WiFi")
Signed-off-by: Chen-Yu Tsai <wenst@chromium.org>
Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/mediatek/mt8192-asurada.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/mediatek/mt8192-asurada.dtsi b/arch/arm64/boot/dts/mediatek/mt8192-asurada.dtsi
index eadf1b2d156f29..95d4db2b797941 100644
--- a/arch/arm64/boot/dts/mediatek/mt8192-asurada.dtsi
+++ b/arch/arm64/boot/dts/mediatek/mt8192-asurada.dtsi
@@ -525,6 +525,7 @@ flash@0 {
 &pcie {
 	pinctrl-names = "default";
 	pinctrl-0 = <&pcie_pins>;
+	memory-region = <&wifi_restricted_dma_region>;
 
 	pcie0: pcie@0,0 {
 		device_type = "pci";
@@ -539,7 +540,6 @@ pcie0: pcie@0,0 {
 		wifi: wifi@0,0 {
 			reg = <0x10000 0 0 0 0x100000>,
 			      <0x10000 0 0x100000 0 0x100000>;
-			memory-region = <&wifi_restricted_dma_region>;
 		};
 	};
 };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0188/2077] workqueue: forbid TEST_WORKQUEUE from being built-in
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (186 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0187/2077] arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0189/2077] drm/amdgpu: fix error return code in mes_v12_1_map_test_bo Greg Kroah-Hartman
                   ` (809 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Breno Leitao, Tejun Heo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Breno Leitao <leitao@debian.org>

[ Upstream commit 1503043fd75e29ad49c7d506232e272f6951d07d ]

The benchmark drives the workqueue's affinity_scope through sysfs by
filp_open()'ing /sys/bus/workqueue/devices/bench_wq/affinity_scope. When
CONFIG_TEST_WORKQUEUE=y, the module_init runs during kernel init before
userspace has mounted sysfs, so every open returns -ENOENT and the
benchmark loop spins emitting:

  test_workqueue: open /sys/bus/workqueue/devices/bench_wq/affinity_scope failed: -2

Mirror the TEST_BPF pattern and add "depends on m" so Kconfig will not
let this be built into the kernel image, and document the reason in the
help text.

Fixes: 24b2e73f9700 ("workqueue: add test_workqueue benchmark module")
Signed-off-by: Breno Leitao <leitao@debian.org>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 lib/Kconfig.debug | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/lib/Kconfig.debug b/lib/Kconfig.debug
index 8ff5adcfe1e0a2..040f4e077435b5 100644
--- a/lib/Kconfig.debug
+++ b/lib/Kconfig.debug
@@ -2649,12 +2649,17 @@ config TEST_VMALLOC
 
 config TEST_WORKQUEUE
 	tristate "Test module for stress/performance analysis of workqueue"
+	depends on m
 	default n
 	help
 	  This builds the "test_workqueue" module for benchmarking
 	  workqueue throughput under contention. Useful for evaluating
 	  affinity scope changes (e.g., cache_shard vs cache).
 
+	  The test drives sysfs to switch affinity scopes, so it must be
+	  loaded after userspace has mounted sysfs; building it in (=y)
+	  would run module_init before /sys is available.
+
 	  If unsure, say N.
 
 config TEST_BPF
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0189/2077] drm/amdgpu: fix error return code in mes_v12_1_map_test_bo
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (187 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0188/2077] workqueue: forbid TEST_WORKQUEUE from being built-in Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0190/2077] arm64: dts: qcom: glymur-crd: Drop forced host mode for USB SS0 and SS1 Greg Kroah-Hartman
                   ` (808 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yang Wang, Asad Kamal, Alex Deucher,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yang Wang <kevinyang.wang@amd.com>

[ Upstream commit 5da1e1dfd15727918aab2c1a79c019f179991e80 ]

The function mes_v12_1_map_test_bo incorrectly returned 0 unconditionallyon error path,
which would hide the real error code and mislead upperlayers about the failure status.
Fix it by returning the correct error code 'r' instead of 0.

Fixes: 44e5195fa3d4 ("drm/amdgpu/mes_v12_1: add mes self test");
Signed-off-by: Yang Wang <kevinyang.wang@amd.com>
Reviewed-by: Asad Kamal <asad.kamal@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/amd/amdgpu/mes_v12_1.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/amd/amdgpu/mes_v12_1.c b/drivers/gpu/drm/amd/amdgpu/mes_v12_1.c
index cec80127812652..be86802fef33b9 100644
--- a/drivers/gpu/drm/amd/amdgpu/mes_v12_1.c
+++ b/drivers/gpu/drm/amd/amdgpu/mes_v12_1.c
@@ -2016,7 +2016,7 @@ static int mes_v12_1_map_test_bo(struct amdgpu_device *adev,
 
 error:
 	amdgpu_sync_free(&sync);
-	return 0;
+	return r;
 }
 
 static int mes_v12_1_test_ring(struct amdgpu_device *adev, int xcc_id,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0190/2077] arm64: dts: qcom: glymur-crd: Drop forced host mode for USB SS0 and SS1
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (188 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0189/2077] drm/amdgpu: fix error return code in mes_v12_1_map_test_bo Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0191/2077] arm64: dts: qcom: glymur: Mark USB SS1 and SS2 as role-switch capable Greg Kroah-Hartman
                   ` (807 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Abel Vesa, Bjorn Andersson,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Abel Vesa <abel.vesa@oss.qualcomm.com>

[ Upstream commit d9dc254945756b44fa6f61b9cbd4adf0413c6a6f ]

The two USB Type-C ports on Glymur CRD are dual-role capable.

Do not force their controllers into host mode. Drop the explicit
'dr_mode = "host"' properties so they can use their default OTG mode
instead.

Fixes: c8b63029455b ("arm64: dts: qcom: glymur-crd: Enable USB support")
Signed-off-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260415-dts-qcom-glymur-usb-role-switch-fix-v1-2-409e1a257f1f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/glymur-crd.dts | 4 ----
 1 file changed, 4 deletions(-)

diff --git a/arch/arm64/boot/dts/qcom/glymur-crd.dts b/arch/arm64/boot/dts/qcom/glymur-crd.dts
index 35aaf09e4e2b47..c98dfb3941fa36 100644
--- a/arch/arm64/boot/dts/qcom/glymur-crd.dts
+++ b/arch/arm64/boot/dts/qcom/glymur-crd.dts
@@ -322,8 +322,6 @@ reset-n-pins {
 };
 
 &usb_0 {
-	dr_mode = "host";
-
 	status = "okay";
 };
 
@@ -353,8 +351,6 @@ &usb_0_qmpphy_out {
 };
 
 &usb_1 {
-	dr_mode = "host";
-
 	status = "okay";
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0191/2077] arm64: dts: qcom: glymur: Mark USB SS1 and SS2 as role-switch capable
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (189 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0190/2077] arm64: dts: qcom: glymur-crd: Drop forced host mode for USB SS0 and SS1 Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0192/2077] rhashtable: give each instance its own lockdep class Greg Kroah-Hartman
                   ` (806 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Abel Vesa, Bjorn Andersson,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Abel Vesa <abel.vesa@oss.qualcomm.com>

[ Upstream commit 347fa2fa64e1cef0c7897522896c0c66e734c82b ]

Like USB SS0, the USB SS1 and SS2 controllers on Glymur also support
USB role switching.

Describe this by adding the 'usb-role-switch' property to both controllers.

Fixes: 4eee57dd4df9 ("arm64: dts: qcom: glymur: Add USB related nodes")
Signed-off-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260415-dts-qcom-glymur-usb-role-switch-fix-v1-1-409e1a257f1f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/glymur.dtsi | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/arch/arm64/boot/dts/qcom/glymur.dtsi b/arch/arm64/boot/dts/qcom/glymur.dtsi
index 7283d45ca259a8..780708a9d8d45f 100644
--- a/arch/arm64/boot/dts/qcom/glymur.dtsi
+++ b/arch/arm64/boot/dts/qcom/glymur.dtsi
@@ -3920,6 +3920,8 @@ usb_1: usb@a800000 {
 			snps,dis_u2_susphy_quirk;
 			snps,dis_enblslpm_quirk;
 
+			usb-role-switch;
+
 			status = "disabled";
 
 			ports {
@@ -3993,6 +3995,8 @@ usb_2: usb@a000000 {
 			snps,dis_u2_susphy_quirk;
 			snps,dis_enblslpm_quirk;
 
+			usb-role-switch;
+
 			status = "disabled";
 
 			ports {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0192/2077] rhashtable: give each instance its own lockdep class
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (190 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0191/2077] arm64: dts: qcom: glymur: Mark USB SS1 and SS2 as role-switch capable Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0193/2077] rust: alloc: fix `Vec::extend_with` SAFETY comment Greg Kroah-Hartman
                   ` (805 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michal Hocko,
	syzbot+5af806780f38a5fe691f, Christian Brauner, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Brauner <brauner@kernel.org>

[ Upstream commit 060d4e94b8d400b62453890821bd7feecd4cde2c ]

syzbot reported a possible circular locking dependency between
&ht->mutex and fs_reclaim:

  CPU0 (kswapd0)                    CPU1 (kworker)
  --------------                    --------------
  fs_reclaim                        ht->mutex
    shmem_evict_inode                 rhashtable_rehash_alloc
      simple_xattrs_free                bucket_table_alloc(GFP_KERNEL)
        rhashtable_free_and_destroy       __kvmalloc_node
          mutex_lock(&ht->mutex)            might_alloc -> fs_reclaim

The two halves of the splat refer to two different events on
&ht->mutex.

The kswapd0 path is unambiguous: shmem_evict_inode at mm/shmem.c:1429
calls simple_xattrs_free(), which calls rhashtable_free_and_destroy()
on the per-inode simple_xattrs rhashtable being torn down with the
inode.

The previously-recorded ht->mutex -> fs_reclaim edge comes from
rht_deferred_worker -> rhashtable_rehash_alloc ->
bucket_table_alloc(GFP_KERNEL) -> __kvmalloc_node ->
might_alloc -> fs_reclaim. That stack stops at generic library code:
there is no subsystem-specific frame above rht_deferred_worker, so
the splat does not identify which rhashtable's worker recorded the
edge -- only that some rhashtable in the system did.

Whether or not that recording happened on the same simple_xattrs ht
that is now being destroyed, the predicted deadlock cannot occur:
rhashtable_free_and_destroy() does cancel_work_sync(&ht->run_work)
before taking ht->mutex, so the deferred worker cannot be running on
the instance being torn down. If the recording was on a different
rhashtable instance, the two ht->mutex acquisitions are on distinct
mutex objects and cannot deadlock either.

Lockdep flags a cycle regardless because mutex_init(&ht->mutex) lives
on a single source line in rhashtable_init_noprof(), so every
ht->mutex in the kernel shares one static lockdep class. Lockdep
matches by class, not by instance, and collapses all of these into
one node.

Lift the lockdep key out of rhashtable_init_noprof() and into the
caller. The user-visible rhashtable_init_noprof() /
rhltable_init_noprof() identifiers become macros that declare a
per-call-site static lock_class_key.

Link: https://patch.msgid.link/20260427-work-rhashtable-lockdep-v1-1-f69e8bd91cb2@kernel.org
Fixes: c6307674ed82 ("mm: kvmalloc: add non-blocking support for vmalloc")
Acked-by: Michal Hocko <mhocko@suse.com>
Reported-by: syzbot+5af806780f38a5fe691f@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/69e798fe.050a0220.24bfd3.0032.GAE@google.com
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/rhashtable-types.h | 22 ++++++++++++++++++----
 lib/rhashtable.c                 | 17 ++++++++++-------
 2 files changed, 28 insertions(+), 11 deletions(-)

diff --git a/include/linux/rhashtable-types.h b/include/linux/rhashtable-types.h
index fc2f596a6df1bf..57c11ec9dc645c 100644
--- a/include/linux/rhashtable-types.h
+++ b/include/linux/rhashtable-types.h
@@ -136,12 +136,26 @@ struct rhashtable_iter {
 	bool end_of_table;
 };
 
-int rhashtable_init_noprof(struct rhashtable *ht,
-		    const struct rhashtable_params *params);
+int __rhashtable_init_noprof(struct rhashtable *ht,
+		    const struct rhashtable_params *params,
+		    struct lock_class_key *key);
+#define rhashtable_init_noprof(ht, params)				\
+({									\
+	static struct lock_class_key __key;				\
+									\
+	__rhashtable_init_noprof(ht, params, &__key);			\
+})
 #define rhashtable_init(...)	alloc_hooks(rhashtable_init_noprof(__VA_ARGS__))
 
-int rhltable_init_noprof(struct rhltable *hlt,
-		  const struct rhashtable_params *params);
+int __rhltable_init_noprof(struct rhltable *hlt,
+		  const struct rhashtable_params *params,
+		  struct lock_class_key *key);
+#define rhltable_init_noprof(hlt, params)				\
+({									\
+	static struct lock_class_key __key;				\
+									\
+	__rhltable_init_noprof(hlt, params, &__key);			\
+})
 #define rhltable_init(...)	alloc_hooks(rhltable_init_noprof(__VA_ARGS__))
 
 #endif /* _LINUX_RHASHTABLE_TYPES_H */
diff --git a/lib/rhashtable.c b/lib/rhashtable.c
index 04b3a808fca9f2..c0ba34eadb3978 100644
--- a/lib/rhashtable.c
+++ b/lib/rhashtable.c
@@ -1057,8 +1057,9 @@ static u32 rhashtable_jhash2(const void *key, u32 length, u32 seed)
  *	.obj_hashfn = my_hash_fn,
  * };
  */
-int rhashtable_init_noprof(struct rhashtable *ht,
-		    const struct rhashtable_params *params)
+int __rhashtable_init_noprof(struct rhashtable *ht,
+		    const struct rhashtable_params *params,
+		    struct lock_class_key *key)
 {
 	struct bucket_table *tbl;
 	size_t size;
@@ -1068,7 +1069,7 @@ int rhashtable_init_noprof(struct rhashtable *ht,
 		return -EINVAL;
 
 	memset(ht, 0, sizeof(*ht));
-	mutex_init(&ht->mutex);
+	mutex_init_with_key(&ht->mutex, key);
 	spin_lock_init(&ht->lock);
 	memcpy(&ht->p, params, sizeof(*params));
 
@@ -1120,7 +1121,7 @@ int rhashtable_init_noprof(struct rhashtable *ht,
 
 	return 0;
 }
-EXPORT_SYMBOL_GPL(rhashtable_init_noprof);
+EXPORT_SYMBOL_GPL(__rhashtable_init_noprof);
 
 /**
  * rhltable_init - initialize a new hash list table
@@ -1131,15 +1132,17 @@ EXPORT_SYMBOL_GPL(rhashtable_init_noprof);
  *
  * See documentation for rhashtable_init.
  */
-int rhltable_init_noprof(struct rhltable *hlt, const struct rhashtable_params *params)
+int __rhltable_init_noprof(struct rhltable *hlt,
+			   const struct rhashtable_params *params,
+			   struct lock_class_key *key)
 {
 	int err;
 
-	err = rhashtable_init_noprof(&hlt->ht, params);
+	err = __rhashtable_init_noprof(&hlt->ht, params, key);
 	hlt->ht.rhlist = true;
 	return err;
 }
-EXPORT_SYMBOL_GPL(rhltable_init_noprof);
+EXPORT_SYMBOL_GPL(__rhltable_init_noprof);
 
 static void rhashtable_free_one(struct rhashtable *ht, struct rhash_head *obj,
 				void (*free_fn)(void *ptr, void *arg),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0193/2077] rust: alloc: fix `Vec::extend_with` SAFETY comment
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (191 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0192/2077] rhashtable: give each instance its own lockdep class Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0194/2077] clk: scmi: Fix clock rate rounding Greg Kroah-Hartman
                   ` (804 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hsiu Che Yu, Alexandre Courbot,
	Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hsiu Che Yu <yu.whisper.personal@gmail.com>

[ Upstream commit f497aae6ded43f91b1dbf29a35d7062823635640 ]

Fix an incorrect operator in the SAFETY comment, changing `<` to `<=`,
since `Vec::reserve` guarantees capacity for exactly n additional elements,
so the equal case should be included.

Signed-off-by: Hsiu Che Yu <yu.whisper.personal@gmail.com>
Reviewed-by: Alexandre Courbot <acourbot@nvidia.com>
Fixes: 2aac4cd7dae3d ("rust: alloc: implement kernel `Vec` type")
Link: https://patch.msgid.link/18fc8eee2f057a6bfbcadae156d1d0b7c40d0077.1777111268.git.yu.whisper.personal@gmail.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 rust/kernel/alloc/kvec.rs | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/rust/kernel/alloc/kvec.rs b/rust/kernel/alloc/kvec.rs
index 6438385e4322e5..5c24fcf05bdfe6 100644
--- a/rust/kernel/alloc/kvec.rs
+++ b/rust/kernel/alloc/kvec.rs
@@ -866,7 +866,7 @@ impl<T: Clone, A: Allocator> Vec<T, A> {
         spare[n - 1].write(value);
 
         // SAFETY:
-        // - `self.len() + n < self.capacity()` due to the call to reserve above,
+        // - `self.len() + n <= self.capacity()` due to the call to reserve above,
         // - the loop and the line above initialized the next `n` elements.
         unsafe { self.inc_len(n) };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0194/2077] clk: scmi: Fix clock rate rounding
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (192 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0193/2077] rust: alloc: fix `Vec::extend_with` SAFETY comment Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0195/2077] arm64: dts: qcom: sm8750: Fix DSI1 phy reference clock rate Greg Kroah-Hartman
                   ` (803 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Turquette, Stephen Boyd,
	linux-clk, Cristian Marussi, Florian Fainelli, Geert Uytterhoeven,
	Brian Masney, Sudeep Holla, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cristian Marussi <cristian.marussi@arm.com>

[ Upstream commit d0c81a38d06d446d341532700b3a4a43d3b00eb1 ]

While the do_div() helper used for rounding expects its divisor argument
to be a 32bits quantity, the currently provided divisor parameter is a
64bit value that, as a consequence, is silently truncated and a possible
source of bugs.

Fix by using the proper div64_ul helper.

Cc: Michael Turquette <mturquette@baylibre.com>
Cc: Stephen Boyd <sboyd@kernel.org>
Cc: linux-clk@vger.kernel.org
Fixes: 7a8655e19bdb ("clk: scmi: Fix the rounding of clock rate")
Signed-off-by: Cristian Marussi <cristian.marussi@arm.com>
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260508153300.2224715-2-cristian.marussi@arm.com
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clk/clk-scmi.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/clk/clk-scmi.c b/drivers/clk/clk-scmi.c
index 6b286ea6f1218c..b6a12f3bc123c9 100644
--- a/drivers/clk/clk-scmi.c
+++ b/drivers/clk/clk-scmi.c
@@ -10,9 +10,9 @@
 #include <linux/device.h>
 #include <linux/err.h>
 #include <linux/of.h>
+#include <linux/math64.h>
 #include <linux/module.h>
 #include <linux/scmi_protocol.h>
-#include <asm/div64.h>
 
 #define NOT_ATOMIC	false
 #define ATOMIC		true
@@ -83,7 +83,7 @@ static int scmi_clk_determine_rate(struct clk_hw *hw,
 
 	ftmp = req->rate - fmin;
 	ftmp += clk->info->range.step_size - 1; /* to round up */
-	do_div(ftmp, clk->info->range.step_size);
+	ftmp = div64_ul(ftmp, clk->info->range.step_size);
 
 	req->rate = ftmp * clk->info->range.step_size + fmin;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0195/2077] arm64: dts: qcom: sm8750: Fix DSI1 phy reference clock rate
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (193 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0194/2077] clk: scmi: Fix clock rate rounding Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0196/2077] arm64: dts: qcom: kodiak: Fix ICE reg size Greg Kroah-Hartman
                   ` (802 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski,
	Dmitry Baryshkov, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit f4d7c5875a215cd3989b59d13a9c30cec9f0a33b ]

The DSI PHY CXO clock input is the SoC CXO divided by two.  DSI0 already
uses correct one, but DSI1 got copy-paste from SM8650.  Wrong clock
parent will cause incorrect DSI1 PHY PLL frequencies to be used making
the DSI panel non-working, although there is no upstream user of DSI1.

Fixes: 818ae2b389bc ("arm64: dts: qcom: sm8750: Add display (MDSS) with Display CC")
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260331165645.233965-2-krzysztof.kozlowski@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sm8750.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/sm8750.dtsi b/arch/arm64/boot/dts/qcom/sm8750.dtsi
index 18fb52c14acd75..320aec62e462d2 100644
--- a/arch/arm64/boot/dts/qcom/sm8750.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8750.dtsi
@@ -3313,7 +3313,7 @@ mdss_dsi1_phy: phy@ae97000 {
 					    "dsi_pll";
 
 				clocks = <&dispcc DISP_CC_MDSS_AHB_CLK>,
-					 <&rpmhcc RPMH_CXO_CLK>;
+					 <&bi_tcxo_div2>;
 				clock-names = "iface",
 					      "ref";
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0196/2077] arm64: dts: qcom: kodiak: Fix ICE reg size
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (194 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0195/2077] arm64: dts: qcom: sm8750: Fix DSI1 phy reference clock rate Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0197/2077] arm64: dts: qcom: sm8450: " Greg Kroah-Hartman
                   ` (801 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kuldeep Singh, Harshal Dev,
	Konrad Dybcio, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>

[ Upstream commit fa9c7403af64d3e56a6c20dedc60e0a55b527509 ]

The ICE register region on Kodiak is currently defined as 0x8000 bytes.
According to the hardware specification, the correct register size is
0x18000.

Update the ICE node reg property to match the hardware.

Fixes: dfd5ee7b34bb ("arm64: dts: qcom: sc7280: Add inline crypto engine")
Signed-off-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Reviewed-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260402-ice_dt_reg_fix-v1-1-74e4c2129238@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/kodiak.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/kodiak.dtsi b/arch/arm64/boot/dts/qcom/kodiak.dtsi
index 988ca5f7c8a0ec..fdde9f065199ee 100644
--- a/arch/arm64/boot/dts/qcom/kodiak.dtsi
+++ b/arch/arm64/boot/dts/qcom/kodiak.dtsi
@@ -2578,7 +2578,7 @@ ufs_mem_phy: phy@1d87000 {
 		ice: crypto@1d88000 {
 			compatible = "qcom,sc7280-inline-crypto-engine",
 				     "qcom,inline-crypto-engine";
-			reg = <0 0x01d88000 0 0x8000>;
+			reg = <0 0x01d88000 0 0x18000>;
 			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>;
 		};
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0197/2077] arm64: dts: qcom: sm8450: Fix ICE reg size
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (195 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0196/2077] arm64: dts: qcom: kodiak: Fix ICE reg size Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0198/2077] platform/chrome: chromeos_privacy_screen: Check ACPI_COMPANION() Greg Kroah-Hartman
                   ` (800 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kuldeep Singh, Harshal Dev,
	Konrad Dybcio, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>

[ Upstream commit 7fb3d0512dacc0d09217eb45057357f00298203d ]

The ICE register region size was originally described incorrectly when
the ICE hardware was first introduced. The same value was later carried
over unchanged when the ICE node was split out from the UFS node into
its own DT entry.

Correct the register size to match the hardware specification.

Fixes: 276ee34a40c1 ("arm64: dts: qcom: sm8450: add Inline Crypto Engine registers and clock")
Signed-off-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Reviewed-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260402-ice_dt_reg_fix-v1-2-74e4c2129238@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sm8450.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/sm8450.dtsi b/arch/arm64/boot/dts/qcom/sm8450.dtsi
index 03bf30b53f289e..e0c37ce3042a22 100644
--- a/arch/arm64/boot/dts/qcom/sm8450.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8450.dtsi
@@ -5373,7 +5373,7 @@ ufs_mem_phy: phy@1d87000 {
 		ice: crypto@1d88000 {
 			compatible = "qcom,sm8450-inline-crypto-engine",
 				     "qcom,inline-crypto-engine";
-			reg = <0 0x01d88000 0 0x8000>;
+			reg = <0 0x01d88000 0 0x18000>;
 			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>;
 		};
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0198/2077] platform/chrome: chromeos_privacy_screen: Check ACPI_COMPANION()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (196 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0197/2077] arm64: dts: qcom: sm8450: " Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0199/2077] platform/chrome: chromeos_tbmc: " Greg Kroah-Hartman
                   ` (799 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Tzung-Bi Shih,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit 8a4a217f617b1ac2f8c095f33efd67d947ddb2cf ]

Every platform driver can be forced to match a device that doesn't match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device's ACPI companion
object need to verify its presence.

Accordingly, add a requisite ACPI_COMPANION() check against NULL to the
chromeos_privacy_screen driver.

Fixes: d3c2872ae323 ("platform/chrome: Convert ChromeOS privacy-screen driver to platform")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://lore.kernel.org/r/3357444.5fSG56mABF@rafael.j.wysocki
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/platform/chrome/chromeos_privacy_screen.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/platform/chrome/chromeos_privacy_screen.c b/drivers/platform/chrome/chromeos_privacy_screen.c
index abc5d189a38944..407b04207de2fd 100644
--- a/drivers/platform/chrome/chromeos_privacy_screen.c
+++ b/drivers/platform/chrome/chromeos_privacy_screen.c
@@ -104,6 +104,9 @@ static const struct drm_privacy_screen_ops chromeos_privacy_screen_ops = {
 
 static int chromeos_privacy_screen_probe(struct platform_device *pdev)
 {
+	if (!ACPI_COMPANION(&pdev->dev))
+		return -ENODEV;
+
 	struct drm_privacy_screen *drm_privacy_screen =
 		drm_privacy_screen_register(&pdev->dev,
 					    &chromeos_privacy_screen_ops,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0199/2077] platform/chrome: chromeos_tbmc: Check ACPI_COMPANION()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (197 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0198/2077] platform/chrome: chromeos_privacy_screen: Check ACPI_COMPANION() Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0200/2077] platform/chrome: wilco_ec: event: " Greg Kroah-Hartman
                   ` (798 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Tzung-Bi Shih,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit c15dbae7c856fb53cc6ffb86c6c64ebb816d07c8 ]

Every platform driver can be forced to match a device that doesn't match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device's ACPI companion
object need to verify its presence.

Accordingly, add a requisite ACPI_COMPANION() check against NULL to the
chromeos_tbmc driver.

Fixes: a2676ead257f ("platform/chrome: chromeos_tbmc: Convert to a platform driver")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://lore.kernel.org/r/1875121.VLH7GnMWUR@rafael.j.wysocki
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/platform/chrome/chromeos_tbmc.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/platform/chrome/chromeos_tbmc.c b/drivers/platform/chrome/chromeos_tbmc.c
index 5133806b2d9587..fd756761a481f4 100644
--- a/drivers/platform/chrome/chromeos_tbmc.c
+++ b/drivers/platform/chrome/chromeos_tbmc.c
@@ -69,9 +69,13 @@ static int chromeos_tbmc_probe(struct platform_device *pdev)
 {
 	struct input_dev *idev;
 	struct device *dev = &pdev->dev;
-	struct acpi_device *adev = ACPI_COMPANION(dev);
+	struct acpi_device *adev;
 	int ret;
 
+	adev = ACPI_COMPANION(dev);
+	if (!adev)
+		return -ENODEV;
+
 	idev = devm_input_allocate_device(dev);
 	if (!idev)
 		return -ENOMEM;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0200/2077] platform/chrome: wilco_ec: event: Check ACPI_COMPANION()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (198 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0199/2077] platform/chrome: chromeos_tbmc: " Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0201/2077] drm/hisilicon/hibmc: add updating link cap in DP detect() Greg Kroah-Hartman
                   ` (797 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Tzung-Bi Shih,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit 51dcff9796fd486d7abf01081ca62e4072789e9d ]

Every platform driver can be forced to match a device that doesn't match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device's ACPI companion
object need to verify its presence.

Accordingly, add a requisite ACPI_COMPANION() check against NULL to the
wilco_ec event driver.

Fixes: 27d58498f690 ("platform/chrome: wilco_ec: event: Convert to a platform driver")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://lore.kernel.org/r/2076666.usQuhbGJ8B@rafael.j.wysocki
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/platform/chrome/wilco_ec/event.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/drivers/platform/chrome/wilco_ec/event.c b/drivers/platform/chrome/wilco_ec/event.c
index b6e935badc0e94..1b5cb89839e084 100644
--- a/drivers/platform/chrome/wilco_ec/event.c
+++ b/drivers/platform/chrome/wilco_ec/event.c
@@ -452,8 +452,13 @@ static void hangup_device(struct event_device_data *dev_data)
 static int event_device_probe(struct platform_device *pdev)
 {
 	struct event_device_data *dev_data;
+	struct acpi_device *adev;
 	int error, minor;
 
+	adev = ACPI_COMPANION(&pdev->dev);
+	if (!adev)
+		return -ENODEV;
+
 	minor = ida_alloc_max(&event_ida, EVENT_MAX_DEV-1, GFP_KERNEL);
 	if (minor < 0) {
 		error = minor;
@@ -494,8 +499,7 @@ static int event_device_probe(struct platform_device *pdev)
 		goto free_dev_data;
 
 	/* Install an ACPI notify handler. */
-	error = acpi_dev_install_notify_handler(ACPI_COMPANION(&pdev->dev),
-						ACPI_DEVICE_NOTIFY,
+	error = acpi_dev_install_notify_handler(adev, ACPI_DEVICE_NOTIFY,
 						event_device_notify, &pdev->dev);
 	if (error)
 		goto free_cdev;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0201/2077] drm/hisilicon/hibmc: add updating link cap in DP detect()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (199 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0200/2077] platform/chrome: wilco_ec: event: " Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0202/2077] drm/hisilicon/hibmc: fix no showing when no connectors connected Greg Kroah-Hartman
                   ` (796 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lin He, Yongbang Shi,
	Thomas Zimmermann, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lin He <helin52@huawei.com>

[ Upstream commit 7d380ef98dd469747b6df43fb0243301b0caaacf ]

In the past, the link cap is updated in link training at encoder enable
stage, but the hibmc_dp_mode_valid() is called before it, which will use
DP link's rate and lanes. So add the hibmc_dp_update_caps() in
hibmc_dp_update_caps() to avoid some potential risks.

Fixes: 607805abfb74 ("drm/hisilicon/hibmc: add dp mode valid check")
Signed-off-by: Lin He <helin52@huawei.com>
Signed-off-by: Yongbang Shi <shiyongbang@huawei.com>
Acked-by: Thomas Zimmermann <tzimmermann@suse.de>
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260509032302.2057227-2-shiyongbang@huawei.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/hisilicon/hibmc/dp/dp_comm.h   | 1 +
 drivers/gpu/drm/hisilicon/hibmc/dp/dp_link.c   | 2 +-
 drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_dp.c | 2 ++
 3 files changed, 4 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/hisilicon/hibmc/dp/dp_comm.h b/drivers/gpu/drm/hisilicon/hibmc/dp/dp_comm.h
index f9ee7ebfec55c3..f53dac256ee0be 100644
--- a/drivers/gpu/drm/hisilicon/hibmc/dp/dp_comm.h
+++ b/drivers/gpu/drm/hisilicon/hibmc/dp/dp_comm.h
@@ -69,5 +69,6 @@ int hibmc_dp_link_training(struct hibmc_dp_dev *dp);
 int hibmc_dp_serdes_init(struct hibmc_dp_dev *dp);
 int hibmc_dp_serdes_rate_switch(u8 rate, struct hibmc_dp_dev *dp);
 int hibmc_dp_serdes_set_tx_cfg(struct hibmc_dp_dev *dp, u8 train_set[HIBMC_DP_LANE_NUM_MAX]);
+void hibmc_dp_update_caps(struct hibmc_dp_dev *dp);
 
 #endif
diff --git a/drivers/gpu/drm/hisilicon/hibmc/dp/dp_link.c b/drivers/gpu/drm/hisilicon/hibmc/dp/dp_link.c
index 0726cb5b736e60..8c53f16db5160f 100644
--- a/drivers/gpu/drm/hisilicon/hibmc/dp/dp_link.c
+++ b/drivers/gpu/drm/hisilicon/hibmc/dp/dp_link.c
@@ -325,7 +325,7 @@ static int hibmc_dp_link_downgrade_training_eq(struct hibmc_dp_dev *dp)
 	return hibmc_dp_link_reduce_rate(dp);
 }
 
-static void hibmc_dp_update_caps(struct hibmc_dp_dev *dp)
+void hibmc_dp_update_caps(struct hibmc_dp_dev *dp)
 {
 	dp->link.cap.link_rate = dp->dpcd[DP_MAX_LINK_RATE];
 	if (dp->link.cap.link_rate > DP_LINK_BW_8_1 || !dp->link.cap.link_rate)
diff --git a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_dp.c b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_dp.c
index 616821e3c933bc..35dff7bfbf76f3 100644
--- a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_dp.c
+++ b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_dp.c
@@ -41,6 +41,8 @@ static bool hibmc_dp_get_dpcd(struct hibmc_dp_dev *dp_dev)
 	if (ret)
 		return false;
 
+	hibmc_dp_update_caps(dp_dev);
+
 	dp_dev->is_branch = drm_dp_is_branch(dp_dev->dpcd);
 
 	ret = drm_dp_read_desc(dp_dev->aux, &dp_dev->desc, dp_dev->is_branch);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0202/2077] drm/hisilicon/hibmc: fix no showing when no connectors connected
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (200 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0201/2077] drm/hisilicon/hibmc: add updating link cap in DP detect() Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0203/2077] drm/hisilicon/hibmc: move display contrl config to hibmc_probe() Greg Kroah-Hartman
                   ` (795 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann, Lin He,
	Yongbang Shi, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lin He <helin52@huawei.com>

[ Upstream commit 4110e29a7c384f1ff21d6b187b6a1772f6e17b23 ]

Our chip support KVM over IP feature, so hibmc driver need to support
displaying without any connectors plugged in. If no connectors are
connected, the vdac connector status should be set to 'connected' to
ensure proper KVM display functionality. Additionally, for
previous-generation products that may lack hardware link support and
thus cannot detect the monitor, the same approach should be applied
to ensure VGA display functionality.

* Add phys_state in the struct of dp and vdac to check physical outputs.

* The 'epoch_counter' of the vdac connector is incremented when the
physical status changes.

For get_modes: using BMC modes for connector if no display is attached to
phys VGA cable, otherwise use EDID modes by drm_connector_helper_get_modes,
because KVM doesn't provide EDID reads.

The polling mechanism for the KMS helper is enabled.

Fixes: 4c962bc929f1 ("drm/hisilicon/hibmc: Add vga connector detect functions")
Reported-by: Thomas Zimmermann <tzimmermann@suse.de>
Closes: https://lore.kernel.org/all/0eb5c509-2724-4c57-87ad-74e4270d5a5a@suse.de/
Signed-off-by: Lin He <helin52@huawei.com>
Signed-off-by: Yongbang Shi <shiyongbang@huawei.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Tested-by: Thomas Zimmermann <tzimmermann@suse.de>
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260509032302.2057227-3-shiyongbang@huawei.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/hisilicon/hibmc/dp/dp_hw.h    |  1 +
 .../gpu/drm/hisilicon/hibmc/hibmc_drm_dp.c    | 33 ++++++++----
 .../gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c   |  3 ++
 .../gpu/drm/hisilicon/hibmc/hibmc_drm_drv.h   |  1 +
 .../gpu/drm/hisilicon/hibmc/hibmc_drm_vdac.c  | 53 +++++++++++++------
 5 files changed, 64 insertions(+), 27 deletions(-)

diff --git a/drivers/gpu/drm/hisilicon/hibmc/dp/dp_hw.h b/drivers/gpu/drm/hisilicon/hibmc/dp/dp_hw.h
index 31316fe1ea8dbf..0f3662d8737e99 100644
--- a/drivers/gpu/drm/hisilicon/hibmc/dp/dp_hw.h
+++ b/drivers/gpu/drm/hisilicon/hibmc/dp/dp_hw.h
@@ -55,6 +55,7 @@ struct hibmc_dp {
 	struct drm_dp_aux aux;
 	struct hibmc_dp_cbar_cfg cfg;
 	u32 irq_status;
+	int phys_status;
 };
 
 int hibmc_dp_hw_init(struct hibmc_dp *dp);
diff --git a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_dp.c b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_dp.c
index 35dff7bfbf76f3..596c5bfe32d8e7 100644
--- a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_dp.c
+++ b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_dp.c
@@ -61,27 +61,38 @@ static int hibmc_dp_detect(struct drm_connector *connector,
 {
 	struct hibmc_dp *dp = to_hibmc_dp(connector);
 	struct hibmc_dp_dev *dp_dev = dp->dp_dev;
-	int ret;
+	int ret = connector_status_disconnected;
 
 	if (dp->irq_status) {
-		if (dp_dev->hpd_status != HIBMC_HPD_IN)
-			return connector_status_disconnected;
+		if (dp_dev->hpd_status != HIBMC_HPD_IN) {
+			ret = connector_status_disconnected;
+			goto exit;
+		}
 	}
 
-	if (!hibmc_dp_get_dpcd(dp_dev))
-		return connector_status_disconnected;
+	if (!hibmc_dp_get_dpcd(dp_dev)) {
+		ret = connector_status_disconnected;
+		goto exit;
+	}
 
-	if (!dp_dev->is_branch)
-		return connector_status_connected;
+	if (!dp_dev->is_branch) {
+		ret = connector_status_connected;
+		goto exit;
+	}
 
 	if (drm_dp_read_sink_count_cap(connector, dp_dev->dpcd, &dp_dev->desc) &&
 	    dp_dev->downstream_ports[0] & DP_DS_PORT_HPD) {
 		ret = drm_dp_read_sink_count(dp_dev->aux);
-		if (ret > 0)
-			return connector_status_connected;
+		if (ret > 0) {
+			ret = connector_status_connected;
+			goto exit;
+		}
 	}
 
-	return connector_status_disconnected;
+exit:
+	dp->phys_status = ret;
+
+	return ret;
 }
 
 static int hibmc_dp_mode_valid(struct drm_connector *connector,
@@ -243,5 +254,7 @@ int hibmc_dp_init(struct hibmc_drm_private *priv)
 
 	connector->polled = DRM_CONNECTOR_POLL_HPD;
 
+	dp->phys_status = connector_status_disconnected;
+
 	return 0;
 }
diff --git a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c
index 289304500ab097..481e5e62c30bf1 100644
--- a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c
+++ b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c
@@ -24,6 +24,7 @@
 #include <drm/drm_managed.h>
 #include <drm/drm_module.h>
 #include <drm/drm_vblank.h>
+#include <drm/drm_probe_helper.h>
 
 #include "hibmc_drm_drv.h"
 #include "hibmc_drm_regs.h"
@@ -355,6 +356,8 @@ static int hibmc_load(struct drm_device *dev)
 	/* reset all the states of crtc/plane/encoder/connector */
 	drm_mode_config_reset(dev);
 
+	drmm_kms_helper_poll_init(dev);
+
 	return 0;
 
 err:
diff --git a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.h b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.h
index ca8502e2760c12..cd3a3fca1fe60a 100644
--- a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.h
+++ b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.h
@@ -31,6 +31,7 @@ struct hibmc_vdac {
 	struct drm_connector connector;
 	struct i2c_adapter adapter;
 	struct i2c_algo_bit_data bit_data;
+	int phys_status;
 };
 
 struct hibmc_drm_private {
diff --git a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_vdac.c b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_vdac.c
index 841e81f47b6862..2fcfa3246fd124 100644
--- a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_vdac.c
+++ b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_vdac.c
@@ -24,28 +24,21 @@
 
 static int hibmc_connector_get_modes(struct drm_connector *connector)
 {
+	struct drm_mode_config *mode_config = &connector->dev->mode_config;
 	struct hibmc_vdac *vdac = to_hibmc_vdac(connector);
-	const struct drm_edid *drm_edid;
 	int count;
 
-	drm_edid = drm_edid_read_ddc(connector, &vdac->adapter);
-
-	drm_edid_connector_update(connector, drm_edid);
-
-	if (drm_edid) {
-		count = drm_edid_connector_add_modes(connector);
+	if (vdac->phys_status == connector_status_connected) {
+		count = drm_connector_helper_get_modes(connector);
+	} else {
+		drm_edid_connector_update(connector, NULL);
+		count = drm_add_modes_noedid(connector,
+					     mode_config->max_width,
+					     mode_config->max_height);
 		if (count)
-			goto out;
+			drm_set_preferred_mode(connector, 1024, 768);
 	}
 
-	count = drm_add_modes_noedid(connector,
-				     connector->dev->mode_config.max_width,
-				     connector->dev->mode_config.max_height);
-	drm_set_preferred_mode(connector, 1024, 768);
-
-out:
-	drm_edid_free(drm_edid);
-
 	return count;
 }
 
@@ -57,10 +50,34 @@ static void hibmc_connector_destroy(struct drm_connector *connector)
 	drm_connector_cleanup(connector);
 }
 
+static int hibmc_vdac_detect(struct drm_connector *connector,
+			     struct drm_modeset_acquire_ctx *ctx,
+			     bool force)
+{
+	struct hibmc_drm_private *priv = to_hibmc_drm_private(connector->dev);
+	int status = drm_connector_helper_detect_from_ddc(connector, ctx,
+							 force);
+	struct hibmc_vdac *vdac = to_hibmc_vdac(connector);
+
+	if (priv->dp.phys_status == connector_status_connected) {
+		vdac->phys_status = status;
+		return status;
+	}
+
+	if (status != vdac->phys_status)
+		++connector->epoch_counter;
+	vdac->phys_status = status;
+
+	/* When both the DP and VDAC physical status are disconnected,
+	 * the "connected" status is returned to support KVM display.
+	 */
+	return connector_status_connected;
+}
+
 static const struct drm_connector_helper_funcs
 	hibmc_connector_helper_funcs = {
 	.get_modes = hibmc_connector_get_modes,
-	.detect_ctx = drm_connector_helper_detect_from_ddc,
+	.detect_ctx = hibmc_vdac_detect,
 };
 
 static const struct drm_connector_funcs hibmc_connector_funcs = {
@@ -130,6 +147,8 @@ int hibmc_vdac_init(struct hibmc_drm_private *priv)
 
 	connector->polled = DRM_CONNECTOR_POLL_CONNECT | DRM_CONNECTOR_POLL_DISCONNECT;
 
+	vdac->phys_status = connector_status_disconnected;
+
 	return 0;
 
 err:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0203/2077] drm/hisilicon/hibmc: move display contrl config to hibmc_probe()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (201 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0202/2077] drm/hisilicon/hibmc: fix no showing when no connectors connected Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0204/2077] drm/hisilicon/hibmc: use clock to look up the PLL value Greg Kroah-Hartman
                   ` (794 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lin He, Yongbang Shi,
	Thomas Zimmermann, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lin He <helin52@huawei.com>

[ Upstream commit de2a56c71f9b223922ea8fe0192d3c1fa2954608 ]

If there's no VGA output, this encoder modeset won't be called, which
will cause displaying data from GPU being cut off. It's actually a
common display config for DP and VGA, so move the vdac encoder modeset
to driver load stage.

Removed invalid bit configurations from `hibmc_display_ctrl`

Fixes: 5294967f4ae4 ("drm/hisilicon/hibmc: Add support for VDAC")
Signed-off-by: Lin He <helin52@huawei.com>
Signed-off-by: Yongbang Shi <shiyongbang@huawei.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260509032302.2057227-4-shiyongbang@huawei.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c   | 11 ++++++++++
 .../gpu/drm/hisilicon/hibmc/hibmc_drm_vdac.c  | 22 -------------------
 2 files changed, 11 insertions(+), 22 deletions(-)

diff --git a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c
index 481e5e62c30bf1..99b36de1fe1370 100644
--- a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c
+++ b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c
@@ -215,6 +215,15 @@ void hibmc_set_current_gate(struct hibmc_drm_private *priv, unsigned int gate)
 	writel(gate, mmio + gate_reg);
 }
 
+static void hibmc_display_ctrl(struct hibmc_drm_private *priv)
+{
+	u32 reg;
+
+	reg = readl(priv->mmio + HIBMC_DISPLAY_CONTROL_HISILE);
+	reg |= HIBMC_DISPLAY_CONTROL_PANELDATE(1);
+	writel(reg, priv->mmio + HIBMC_DISPLAY_CONTROL_HISILE);
+}
+
 static void hibmc_hw_config(struct hibmc_drm_private *priv)
 {
 	u32 reg;
@@ -246,6 +255,8 @@ static void hibmc_hw_config(struct hibmc_drm_private *priv)
 	reg |= HIBMC_MSCCTL_LOCALMEM_RESET(1);
 
 	writel(reg, priv->mmio + HIBMC_MISC_CTRL);
+
+	hibmc_display_ctrl(priv);
 }
 
 static int hibmc_hw_map(struct hibmc_drm_private *priv)
diff --git a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_vdac.c b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_vdac.c
index 2fcfa3246fd124..b9bd6d33fb0f7b 100644
--- a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_vdac.c
+++ b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_vdac.c
@@ -88,26 +88,6 @@ static const struct drm_connector_funcs hibmc_connector_funcs = {
 	.atomic_destroy_state = drm_atomic_helper_connector_destroy_state,
 };
 
-static void hibmc_encoder_mode_set(struct drm_encoder *encoder,
-				   struct drm_display_mode *mode,
-				   struct drm_display_mode *adj_mode)
-{
-	u32 reg;
-	struct drm_device *dev = encoder->dev;
-	struct hibmc_drm_private *priv = to_hibmc_drm_private(dev);
-
-	reg = readl(priv->mmio + HIBMC_DISPLAY_CONTROL_HISILE);
-	reg |= HIBMC_DISPLAY_CONTROL_FPVDDEN(1);
-	reg |= HIBMC_DISPLAY_CONTROL_PANELDATE(1);
-	reg |= HIBMC_DISPLAY_CONTROL_FPEN(1);
-	reg |= HIBMC_DISPLAY_CONTROL_VBIASEN(1);
-	writel(reg, priv->mmio + HIBMC_DISPLAY_CONTROL_HISILE);
-}
-
-static const struct drm_encoder_helper_funcs hibmc_encoder_helper_funcs = {
-	.mode_set = hibmc_encoder_mode_set,
-};
-
 int hibmc_vdac_init(struct hibmc_drm_private *priv)
 {
 	struct drm_device *dev = &priv->dev;
@@ -130,8 +110,6 @@ int hibmc_vdac_init(struct hibmc_drm_private *priv)
 		goto err;
 	}
 
-	drm_encoder_helper_add(encoder, &hibmc_encoder_helper_funcs);
-
 	ret = drm_connector_init_with_ddc(dev, connector,
 					  &hibmc_connector_funcs,
 					  DRM_MODE_CONNECTOR_VGA,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0204/2077] drm/hisilicon/hibmc: use clock to look up the PLL value
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (202 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0203/2077] drm/hisilicon/hibmc: move display contrl config to hibmc_probe() Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0205/2077] evm: terminate and bound the evm_xattrs read buffer Greg Kroah-Hartman
                   ` (793 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lin He, Yongbang Shi,
	Thomas Zimmermann, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lin He <helin52@huawei.com>

[ Upstream commit 99ef3a4f1c1813cabd50bb3e8522e85e00838bb2 ]

In the past, we use width and height to look up our PLL value.
But actually the actual clock check is also necessnary. There are
some resolutions that width and height same, but its clock different.
Add the clock check when using pll_table to determine the PLL value.

Fixes: da52605eea8f ("drm/hisilicon/hibmc: Add support for display engine")
Signed-off-by: Lin He <helin52@huawei.com>
Signed-off-by: Yongbang Shi <shiyongbang@huawei.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260509032302.2057227-5-shiyongbang@huawei.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../gpu/drm/hisilicon/hibmc/hibmc_drm_de.c    | 80 +++++++++++--------
 1 file changed, 45 insertions(+), 35 deletions(-)

diff --git a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c
index 89bed78f14666a..db7fce4e8cc344 100644
--- a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c
+++ b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c
@@ -32,26 +32,43 @@ struct hibmc_display_panel_pll {
 struct hibmc_dislay_pll_config {
 	u64 hdisplay;
 	u64 vdisplay;
+	int clock;
 	u32 pll1_config_value;
 	u32 pll2_config_value;
 };
 
 static const struct hibmc_dislay_pll_config hibmc_pll_table[] = {
-	{640, 480, CRT_PLL1_HS_25MHZ, CRT_PLL2_HS_25MHZ},
-	{800, 600, CRT_PLL1_HS_40MHZ, CRT_PLL2_HS_40MHZ},
-	{1024, 768, CRT_PLL1_HS_65MHZ, CRT_PLL2_HS_65MHZ},
-	{1152, 864, CRT_PLL1_HS_80MHZ_1152, CRT_PLL2_HS_80MHZ},
-	{1280, 768, CRT_PLL1_HS_80MHZ, CRT_PLL2_HS_80MHZ},
-	{1280, 720, CRT_PLL1_HS_74MHZ, CRT_PLL2_HS_74MHZ},
-	{1280, 960, CRT_PLL1_HS_108MHZ, CRT_PLL2_HS_108MHZ},
-	{1280, 1024, CRT_PLL1_HS_108MHZ, CRT_PLL2_HS_108MHZ},
-	{1440, 900, CRT_PLL1_HS_106MHZ, CRT_PLL2_HS_106MHZ},
-	{1600, 900, CRT_PLL1_HS_108MHZ, CRT_PLL2_HS_108MHZ},
-	{1600, 1200, CRT_PLL1_HS_162MHZ, CRT_PLL2_HS_162MHZ},
-	{1920, 1080, CRT_PLL1_HS_148MHZ, CRT_PLL2_HS_148MHZ},
-	{1920, 1200, CRT_PLL1_HS_193MHZ, CRT_PLL2_HS_193MHZ},
+	{640, 480, 25000, CRT_PLL1_HS_25MHZ, CRT_PLL2_HS_25MHZ},
+	{800, 600, 40000, CRT_PLL1_HS_40MHZ, CRT_PLL2_HS_40MHZ},
+	{1024, 768, 65000, CRT_PLL1_HS_65MHZ, CRT_PLL2_HS_65MHZ},
+	{1152, 864, 78750, CRT_PLL1_HS_80MHZ_1152, CRT_PLL2_HS_80MHZ},
+	{1280, 768, 80000, CRT_PLL1_HS_80MHZ, CRT_PLL2_HS_80MHZ},
+	{1280, 720, 74375, CRT_PLL1_HS_74MHZ, CRT_PLL2_HS_74MHZ},
+	{1280, 960, 108000, CRT_PLL1_HS_108MHZ, CRT_PLL2_HS_108MHZ},
+	{1280, 1024, 108000, CRT_PLL1_HS_108MHZ, CRT_PLL2_HS_108MHZ},
+	{1440, 900, 105952, CRT_PLL1_HS_106MHZ, CRT_PLL2_HS_106MHZ},
+	{1600, 900, 108000, CRT_PLL1_HS_108MHZ, CRT_PLL2_HS_108MHZ},
+	{1600, 1200, 162500, CRT_PLL1_HS_162MHZ, CRT_PLL2_HS_162MHZ},
+	{1920, 1080, 148750, CRT_PLL1_HS_148MHZ, CRT_PLL2_HS_148MHZ},
+	{1920, 1200, 193750, CRT_PLL1_HS_193MHZ, CRT_PLL2_HS_193MHZ},
 };
 
+static int hibmc_get_best_clock_idx(const struct drm_display_mode *mode)
+{
+	int i, diff;
+
+	for (i = 0; i < ARRAY_SIZE(hibmc_pll_table); i++) {
+		if (hibmc_pll_table[i].hdisplay == mode->hdisplay &&
+		    hibmc_pll_table[i].vdisplay == mode->vdisplay) {
+			diff = abs(mode->clock - hibmc_pll_table[i].clock);
+			if (diff < mode->clock / 100) /* tolerance 1/100 */
+				return i;
+		}
+	}
+
+	return -MODE_CLOCK_RANGE;
+}
+
 static int hibmc_plane_atomic_check(struct drm_plane *plane,
 				    struct drm_atomic_state *state)
 {
@@ -214,19 +231,15 @@ static enum drm_mode_status
 hibmc_crtc_mode_valid(struct drm_crtc *crtc,
 		      const struct drm_display_mode *mode)
 {
-	size_t i = 0;
 	int vrefresh = drm_mode_vrefresh(mode);
 
 	if (vrefresh < 59 || vrefresh > 61)
 		return MODE_NOCLOCK;
 
-	for (i = 0; i < ARRAY_SIZE(hibmc_pll_table); i++) {
-		if (hibmc_pll_table[i].hdisplay == mode->hdisplay &&
-		    hibmc_pll_table[i].vdisplay == mode->vdisplay)
-			return MODE_OK;
-	}
+	if (hibmc_get_best_clock_idx(mode) >= 0)
+		return MODE_OK;
 
-	return MODE_BAD;
+	return MODE_CLOCK_RANGE;
 }
 
 static u32 format_pll_reg(void)
@@ -281,23 +294,20 @@ static void set_vclock_hisilicon(struct drm_device *dev, u64 pll)
 	writel(val, priv->mmio + CRT_PLL1_HS);
 }
 
-static void get_pll_config(u64 x, u64 y, u32 *pll1, u32 *pll2)
+static void get_pll_config(struct drm_display_mode *mode, u32 *pll1, u32 *pll2)
 {
-	size_t i;
-	size_t count = ARRAY_SIZE(hibmc_pll_table);
-
-	for (i = 0; i < count; i++) {
-		if (hibmc_pll_table[i].hdisplay == x &&
-		    hibmc_pll_table[i].vdisplay == y) {
-			*pll1 = hibmc_pll_table[i].pll1_config_value;
-			*pll2 = hibmc_pll_table[i].pll2_config_value;
-			return;
-		}
+	int idx;
+
+	idx = hibmc_get_best_clock_idx(mode);
+	if (idx < 0) {
+		/* if found none, we use default value */
+		*pll1 = CRT_PLL1_HS_25MHZ;
+		*pll2 = CRT_PLL2_HS_25MHZ;
+		return;
 	}
 
-	/* if found none, we use default value */
-	*pll1 = CRT_PLL1_HS_25MHZ;
-	*pll2 = CRT_PLL2_HS_25MHZ;
+	*pll1 = hibmc_pll_table[idx].pll1_config_value;
+	*pll2 = hibmc_pll_table[idx].pll2_config_value;
 }
 
 /*
@@ -319,7 +329,7 @@ static u32 display_ctrl_adjust(struct drm_device *dev,
 	x = mode->hdisplay;
 	y = mode->vdisplay;
 
-	get_pll_config(x, y, &pll1, &pll2);
+	get_pll_config(mode, &pll1, &pll2);
 	writel(pll2, priv->mmio + CRT_PLL2_HS);
 	set_vclock_hisilicon(dev, pll1);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0205/2077] evm: terminate and bound the evm_xattrs read buffer
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (203 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0204/2077] drm/hisilicon/hibmc: use clock to look up the PLL value Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:57 ` [PATCH 7.1 0206/2077] thermal: hwmon: Fix critical temperature attribute removal Greg Kroah-Hartman
                   ` (792 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Roberto Sassu,
	Mimi Zohar, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pengpeng Hou <pengpeng@iscas.ac.cn>

[ Upstream commit 11143a19f5b8dc8f414deab87571134f9f447313 ]

evm_read_xattrs() allocates size + 1 bytes, fills them from the list of
enabled xattrs, and then passes strlen(temp) to
simple_read_from_buffer(). When no configured xattrs are enabled, the
fill loop stores nothing and temp[0] remains uninitialized, so strlen()
reads beyond initialized memory.

Explicitly terminate the buffer after allocation, use snprintf() for
each formatted line, and pass the accumulated length, without risk of
truncation, to simple_read_from_buffer().

Fixes: fa516b66a1bf ("EVM: Allow runtime modification of the set of verified xattrs")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Reviewed-by: Roberto Sassu <roberto.sassu@huawei.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 security/integrity/evm/evm_secfs.c | 16 +++++++++++-----
 1 file changed, 11 insertions(+), 5 deletions(-)

diff --git a/security/integrity/evm/evm_secfs.c b/security/integrity/evm/evm_secfs.c
index acd840461902f8..4baf5e23bc97e9 100644
--- a/security/integrity/evm/evm_secfs.c
+++ b/security/integrity/evm/evm_secfs.c
@@ -127,8 +127,8 @@ static ssize_t evm_read_xattrs(struct file *filp, char __user *buf,
 			       size_t count, loff_t *ppos)
 {
 	char *temp;
-	int offset = 0;
-	ssize_t rc, size = 0;
+	size_t offset = 0, size = 0;
+	ssize_t rc;
 	struct xattr_list *xattr;
 
 	if (*ppos != 0)
@@ -151,16 +151,22 @@ static ssize_t evm_read_xattrs(struct file *filp, char __user *buf,
 		return -ENOMEM;
 	}
 
+	temp[size] = '\0';
+
+	/*
+	 * No truncation possible: size is computed over the same enabled
+	 * xattrs under xattr_list_mutex, so offset never exceeds size.
+	 */
 	list_for_each_entry(xattr, &evm_config_xattrnames, list) {
 		if (!xattr->enabled)
 			continue;
 
-		sprintf(temp + offset, "%s\n", xattr->name);
-		offset += strlen(xattr->name) + 1;
+		offset += snprintf(temp + offset, size + 1 - offset, "%s\n",
+				   xattr->name);
 	}
 
 	mutex_unlock(&xattr_list_mutex);
-	rc = simple_read_from_buffer(buf, count, ppos, temp, strlen(temp));
+	rc = simple_read_from_buffer(buf, count, ppos, temp, offset);
 
 	kfree(temp);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0206/2077] thermal: hwmon: Fix critical temperature attribute removal
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (204 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0205/2077] evm: terminate and bound the evm_xattrs read buffer Greg Kroah-Hartman
@ 2026-07-21 14:57 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0207/2077] thermal: hwmon: Register a hwmon device for each thermal zone Greg Kroah-Hartman
                   ` (791 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:57 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit c2114dbda05354dbcf4dfbb30a2c623e8611c43a ]

Since the return value of thermal_zone_crit_temp_valid() depends on
the behavior of the thermal zone .get_crit_temp() callback which
may change over time in theory, thermal_remove_hwmon_sysfs() may
attempt to remove a critical temperature attribute that has not
been created, passing a pointer to an uninitialized attribute
structure to device_remove_file().

To avoid that, set a flag in struct thermal_hwmon_temp after creating
a critical temperature attribute and use the value of that flag to
decide whether or not the attribute needs to be removed.

Fixes: e8db5d6736a7 ("thermal: hwmon: Make the check for critical temp valid consistent")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/2437056.ElGaqSPkdT@rafael.j.wysocki
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/thermal/thermal_hwmon.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/drivers/thermal/thermal_hwmon.c b/drivers/thermal/thermal_hwmon.c
index b624892bc6d669..597c33c8a55508 100644
--- a/drivers/thermal/thermal_hwmon.c
+++ b/drivers/thermal/thermal_hwmon.c
@@ -40,6 +40,7 @@ struct thermal_hwmon_temp {
 	struct thermal_zone_device *tz;
 	struct thermal_hwmon_attr temp_input;	/* hwmon sys attr */
 	struct thermal_hwmon_attr temp_crit;	/* hwmon sys attr */
+	bool temp_crit_present;
 };
 
 static LIST_HEAD(thermal_hwmon_list);
@@ -191,6 +192,8 @@ int thermal_add_hwmon_sysfs(struct thermal_zone_device *tz)
 					    &temp->temp_crit.attr);
 		if (result)
 			goto unregister_input;
+
+		temp->temp_crit_present = true;
 	}
 
 	mutex_lock(&thermal_hwmon_list_lock);
@@ -235,7 +238,7 @@ void thermal_remove_hwmon_sysfs(struct thermal_zone_device *tz)
 	}
 
 	device_remove_file(hwmon->device, &temp->temp_input.attr);
-	if (thermal_zone_crit_temp_valid(tz))
+	if (temp->temp_crit_present)
 		device_remove_file(hwmon->device, &temp->temp_crit.attr);
 
 	mutex_lock(&thermal_hwmon_list_lock);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0207/2077] thermal: hwmon: Register a hwmon device for each thermal zone
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (205 preceding siblings ...)
  2026-07-21 14:57 ` [PATCH 7.1 0206/2077] thermal: hwmon: Fix critical temperature attribute removal Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0208/2077] clk: scpi: Unregister child clock providers on remove Greg Kroah-Hartman
                   ` (790 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit d6323469bcfbda91f0aa89b7b39ad45fe822ca5d ]

The current code creates one hwmon device per thermal zone type and that
device is registered under the first thermal zone of the given type.

That turns out to be problematic when the thermal zone holding the
hwmon device is removed.

For example, say that there are two ACPI thermal zones on a system

/sys/devices/virtual/thermal/thermal_zone0/
/sys/devices/virtual/thermal/thermal_zone1/

The current code registers a hwmon class device for thermal_zone0 only:

/sys/devices/virtual/thermal/thermal_zone0/hwmon0/

because the type is "acpitz" for both of them, but it adds a sysfs
attribute that belongs to thermal_zone1 under it:

/sys/devices/virtual/thermal/thermal_zone0/hwmon0/temp2_input

There is also

/sys/devices/virtual/thermal/thermal_zone0/hwmon0/temp1_input

which belongs to thermal_zone0.

When thermal_zone0 is removed, say because the ACPI thermal driver is
unbound from the underlying platform device, the removal code skips the
removal of hwmon0 because of the temp2_input attribute belonging to
thermal_zone1 which effectively prevents thermal_zone0 removal from
making progress.

To address this problem, rework the thermal hwmon code to register one
hwmon device for each thermal zone, but since user space utilities
produce confusing output in some cases when there are multiple hwmon
devices with the same name attribute value present under thermal zones
of the same type, append the thermal zone ID preceded by an underline
character to the name of the hwmon device registered for that thermal
zone.

Link: https://lore.kernel.org/linux-pm/20260402021828.16556-1-liujia6264@gmail.com/
Fixes: f6b6b52ef7a5 ("thermal_hwmon: Pass the originating device down to hwmon_device_register_with_info")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/3070412.e9J7NaK4W3@rafael.j.wysocki
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/thermal/thermal_hwmon.c | 151 ++++++++++----------------------
 1 file changed, 47 insertions(+), 104 deletions(-)

diff --git a/drivers/thermal/thermal_hwmon.c b/drivers/thermal/thermal_hwmon.c
index 597c33c8a55508..223ae1571655bd 100644
--- a/drivers/thermal/thermal_hwmon.c
+++ b/drivers/thermal/thermal_hwmon.c
@@ -19,30 +19,33 @@
 #include "thermal_hwmon.h"
 #include "thermal_core.h"
 
-/* hwmon sys I/F */
-/* thermal zone devices with the same type share one hwmon device */
-struct thermal_hwmon_device {
-	char type[THERMAL_NAME_LENGTH];
-	struct device *device;
-	int count;
-	struct list_head tz_list;
-	struct list_head node;
-};
+/*
+ * Needs to be large enough to hold a thermal zone type string followed by an
+ * underline character and a 32-bit integer in decimal representation.
+ */
+#define THERMAL_HWMON_NAME_LENGTH (THERMAL_NAME_LENGTH + 11)
 
 struct thermal_hwmon_attr {
 	struct device_attribute attr;
-	char name[16];
 };
 
 /* one temperature input for each thermal zone */
 struct thermal_hwmon_temp {
-	struct list_head hwmon_node;
 	struct thermal_zone_device *tz;
 	struct thermal_hwmon_attr temp_input;	/* hwmon sys attr */
 	struct thermal_hwmon_attr temp_crit;	/* hwmon sys attr */
 	bool temp_crit_present;
 };
 
+/* hwmon sys I/F */
+/* thermal zone devices with the same type share one hwmon device */
+struct thermal_hwmon_device {
+	char name[THERMAL_HWMON_NAME_LENGTH];
+	struct device *device;
+	struct list_head node;
+	struct thermal_hwmon_temp tz_temp;
+};
+
 static LIST_HEAD(thermal_hwmon_list);
 
 static DEFINE_MUTEX(thermal_hwmon_list_lock);
@@ -88,45 +91,6 @@ temp_crit_show(struct device *dev, struct device_attribute *attr, char *buf)
 	return sysfs_emit(buf, "%d\n", temperature);
 }
 
-
-static struct thermal_hwmon_device *
-thermal_hwmon_lookup_by_type(const struct thermal_zone_device *tz)
-{
-	struct thermal_hwmon_device *hwmon;
-	char type[THERMAL_NAME_LENGTH];
-
-	mutex_lock(&thermal_hwmon_list_lock);
-	list_for_each_entry(hwmon, &thermal_hwmon_list, node) {
-		strscpy(type, tz->type);
-		strreplace(type, '-', '_');
-		if (!strcmp(hwmon->type, type)) {
-			mutex_unlock(&thermal_hwmon_list_lock);
-			return hwmon;
-		}
-	}
-	mutex_unlock(&thermal_hwmon_list_lock);
-
-	return NULL;
-}
-
-/* Find the temperature input matching a given thermal zone */
-static struct thermal_hwmon_temp *
-thermal_hwmon_lookup_temp(const struct thermal_hwmon_device *hwmon,
-			  const struct thermal_zone_device *tz)
-{
-	struct thermal_hwmon_temp *temp;
-
-	mutex_lock(&thermal_hwmon_list_lock);
-	list_for_each_entry(temp, &hwmon->tz_list, hwmon_node)
-		if (temp->tz == tz) {
-			mutex_unlock(&thermal_hwmon_list_lock);
-			return temp;
-		}
-	mutex_unlock(&thermal_hwmon_list_lock);
-
-	return NULL;
-}
-
 static bool thermal_zone_crit_temp_valid(struct thermal_zone_device *tz)
 {
 	int temp;
@@ -137,54 +101,39 @@ int thermal_add_hwmon_sysfs(struct thermal_zone_device *tz)
 {
 	struct thermal_hwmon_device *hwmon;
 	struct thermal_hwmon_temp *temp;
-	int new_hwmon_device = 1;
 	int result;
 
-	hwmon = thermal_hwmon_lookup_by_type(tz);
-	if (hwmon) {
-		new_hwmon_device = 0;
-		goto register_sys_interface;
-	}
-
 	hwmon = kzalloc_obj(*hwmon);
 	if (!hwmon)
 		return -ENOMEM;
 
-	INIT_LIST_HEAD(&hwmon->tz_list);
-	strscpy(hwmon->type, tz->type, THERMAL_NAME_LENGTH);
-	strreplace(hwmon->type, '-', '_');
+	/*
+	 * Append the thermal zone ID preceded by an underline character to the
+	 * type to disambiguate the sensors command output.
+	 */
+	scnprintf(hwmon->name, THERMAL_HWMON_NAME_LENGTH, "%s_%d", tz->type, tz->id);
+	strreplace(hwmon->name, '-', '_');
 	hwmon->device = hwmon_device_register_for_thermal(&tz->device,
-							  hwmon->type, hwmon);
+							  hwmon->name, hwmon);
 	if (IS_ERR(hwmon->device)) {
 		result = PTR_ERR(hwmon->device);
 		goto free_mem;
 	}
 
- register_sys_interface:
-	temp = kzalloc_obj(*temp);
-	if (!temp) {
-		result = -ENOMEM;
-		goto unregister_name;
-	}
+	temp = &hwmon->tz_temp;
 
 	temp->tz = tz;
-	hwmon->count++;
 
-	snprintf(temp->temp_input.name, sizeof(temp->temp_input.name),
-		 "temp%d_input", hwmon->count);
-	temp->temp_input.attr.attr.name = temp->temp_input.name;
+	temp->temp_input.attr.attr.name = "temp1_input";
 	temp->temp_input.attr.attr.mode = 0444;
 	temp->temp_input.attr.show = temp_input_show;
 	sysfs_attr_init(&temp->temp_input.attr.attr);
 	result = device_create_file(hwmon->device, &temp->temp_input.attr);
 	if (result)
-		goto free_temp_mem;
+		goto unregister_name;
 
 	if (thermal_zone_crit_temp_valid(tz)) {
-		snprintf(temp->temp_crit.name,
-				sizeof(temp->temp_crit.name),
-				"temp%d_crit", hwmon->count);
-		temp->temp_crit.attr.attr.name = temp->temp_crit.name;
+		temp->temp_crit.attr.attr.name = "temp1_crit";
 		temp->temp_crit.attr.attr.mode = 0444;
 		temp->temp_crit.attr.show = temp_crit_show;
 		sysfs_attr_init(&temp->temp_crit.attr.attr);
@@ -196,21 +145,17 @@ int thermal_add_hwmon_sysfs(struct thermal_zone_device *tz)
 		temp->temp_crit_present = true;
 	}
 
+	/* The list is needed for hwmon lookup during removal. */
 	mutex_lock(&thermal_hwmon_list_lock);
-	if (new_hwmon_device)
-		list_add_tail(&hwmon->node, &thermal_hwmon_list);
-	list_add_tail(&temp->hwmon_node, &hwmon->tz_list);
+	list_add_tail(&hwmon->node, &thermal_hwmon_list);
 	mutex_unlock(&thermal_hwmon_list_lock);
 
 	return 0;
 
  unregister_input:
 	device_remove_file(hwmon->device, &temp->temp_input.attr);
- free_temp_mem:
-	kfree(temp);
  unregister_name:
-	if (new_hwmon_device)
-		hwmon_device_unregister(hwmon->device);
+	hwmon_device_unregister(hwmon->device);
  free_mem:
 	kfree(hwmon);
 
@@ -218,39 +163,37 @@ int thermal_add_hwmon_sysfs(struct thermal_zone_device *tz)
 }
 EXPORT_SYMBOL_GPL(thermal_add_hwmon_sysfs);
 
+static struct thermal_hwmon_device *
+thermal_hwmon_lookup(const struct thermal_zone_device *tz)
+{
+	struct thermal_hwmon_device *hwmon;
+
+	list_for_each_entry(hwmon, &thermal_hwmon_list, node) {
+		if (hwmon->tz_temp.tz == tz)
+			return hwmon;
+	}
+	return NULL;
+}
+
 void thermal_remove_hwmon_sysfs(struct thermal_zone_device *tz)
 {
 	struct thermal_hwmon_device *hwmon;
 	struct thermal_hwmon_temp *temp;
 
-	hwmon = thermal_hwmon_lookup_by_type(tz);
-	if (unlikely(!hwmon)) {
-		/* Should never happen... */
-		dev_dbg(&tz->device, "hwmon device lookup failed!\n");
-		return;
-	}
+	scoped_guard(mutex, &thermal_hwmon_list_lock) {
+		hwmon = thermal_hwmon_lookup(tz);
+		if (!hwmon)
+			return;
 
-	temp = thermal_hwmon_lookup_temp(hwmon, tz);
-	if (unlikely(!temp)) {
-		/* Should never happen... */
-		dev_dbg(&tz->device, "temperature input lookup failed!\n");
-		return;
+		list_del(&hwmon->node);
 	}
 
+	temp = &hwmon->tz_temp;
+
 	device_remove_file(hwmon->device, &temp->temp_input.attr);
 	if (temp->temp_crit_present)
 		device_remove_file(hwmon->device, &temp->temp_crit.attr);
 
-	mutex_lock(&thermal_hwmon_list_lock);
-	list_del(&temp->hwmon_node);
-	kfree(temp);
-	if (!list_empty(&hwmon->tz_list)) {
-		mutex_unlock(&thermal_hwmon_list_lock);
-		return;
-	}
-	list_del(&hwmon->node);
-	mutex_unlock(&thermal_hwmon_list_lock);
-
 	hwmon_device_unregister(hwmon->device);
 	kfree(hwmon);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0208/2077] clk: scpi: Unregister child clock providers on remove
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (206 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0207/2077] thermal: hwmon: Register a hwmon device for each thermal zone Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0209/2077] net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() Greg Kroah-Hartman
                   ` (789 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Stepan Ionichev, Sudeep Holla,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stepan Ionichev <sozdayvek@gmail.com>

[ Upstream commit b79d9b5747d961516c35ef4d5e91efa579fd3e9a ]

SCPI clock providers are registered for each child node in
scpi_clk_add(), but scpi_clocks_remove() unregisters the parent node on
each iteration.

of_clk_del_provider() matches providers by the node used at registration
time, so passing the parent node leaves the child providers registered.
This leaks the provider allocations and the node references held by the
clock provider core.

Pass the child node to of_clk_del_provider() so the remove path matches
the probe path.

Fixes: cd52c2a4b5c4 ("clk: add support for clocks provided by SCP(System Control Processor)")
Signed-off-by: Stepan Ionichev <sozdayvek@gmail.com>
Link: https://patch.msgid.link/20260513090900.5323-1-sozdayvek@gmail.com
(sudeep.holla: Updated commit title and message a bit)
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clk/clk-scpi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/clk/clk-scpi.c b/drivers/clk/clk-scpi.c
index 7806569cd0d5c4..24cee7c9fda6c5 100644
--- a/drivers/clk/clk-scpi.c
+++ b/drivers/clk/clk-scpi.c
@@ -258,7 +258,7 @@ static void scpi_clocks_remove(struct platform_device *pdev)
 	}
 
 	for_each_available_child_of_node(np, child)
-		of_clk_del_provider(np);
+		of_clk_del_provider(child);
 }
 
 static int scpi_clocks_probe(struct platform_device *pdev)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0209/2077] net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (207 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0208/2077] clk: scpi: Unregister child clock providers on remove Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0210/2077] scsi: hisi_sas: Add slave_destroy interface for v3 hw Greg Kroah-Hartman
                   ` (788 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eric Dumazet,
	Toke Høiland-Jørgensen, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit e300c7d470ad2726d6abf7d11b31b5d9912d9cf0 ]

hfsc_dump_class_stats() runs without qdisc spinlock being held.

Add READ_ONCE()/WRITE_ONCE() annotations around:

- cl->level
- cl->cl_vtperiod
- cl->cl_total
- cl->cl_cumul

Fixes: edb09eb17ed8 ("net: sched: do not acquire qdisc spinlock in qdisc/class stats dump")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Toke Høiland-Jørgensen <toke@toke.dk>
Link: https://patch.msgid.link/20260513080853.1383975-4-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/sch_hfsc.c | 22 +++++++++++-----------
 1 file changed, 11 insertions(+), 11 deletions(-)

diff --git a/net/sched/sch_hfsc.c b/net/sched/sch_hfsc.c
index 83b2ca2e37fc82..55258aac6b93c7 100644
--- a/net/sched/sch_hfsc.c
+++ b/net/sched/sch_hfsc.c
@@ -715,7 +715,7 @@ init_vf(struct hfsc_class *cl, unsigned int len)
 			rtsc_min(&cl->cl_virtual, &cl->cl_fsc, cl->cl_vt, cl->cl_total);
 			cl->cl_vtadj = 0;
 
-			cl->cl_vtperiod++;  /* increment vt period */
+			WRITE_ONCE(cl->cl_vtperiod, cl->cl_vtperiod + 1);  /* increment vt period */
 			cl->cl_parentperiod = cl->cl_parent->cl_vtperiod;
 			if (cl->cl_parent->cl_nactive == 0)
 				cl->cl_parentperiod++;
@@ -757,7 +757,7 @@ update_vf(struct hfsc_class *cl, unsigned int len, u64 cur_time)
 		go_passive = 1;
 
 	for (; cl->cl_parent != NULL; cl = cl->cl_parent) {
-		cl->cl_total += len;
+		WRITE_ONCE(cl->cl_total, cl->cl_total + len);
 
 		if (!(cl->cl_flags & HFSC_FSC) || cl->cl_nactive == 0)
 			continue;
@@ -847,7 +847,7 @@ hfsc_adjust_levels(struct hfsc_class *cl)
 			if (p->level >= level)
 				level = p->level + 1;
 		}
-		cl->level = level;
+		WRITE_ONCE(cl->level, level);
 	} while ((cl = cl->cl_parent) != NULL);
 }
 
@@ -1338,10 +1338,10 @@ hfsc_dump_class_stats(struct Qdisc *sch, unsigned long arg,
 	__u32 qlen;
 
 	qdisc_qstats_qlen_backlog(cl->qdisc, &qlen, &cl->qstats.backlog);
-	xstats.level   = cl->level;
-	xstats.period  = cl->cl_vtperiod;
-	xstats.work    = cl->cl_total;
-	xstats.rtwork  = cl->cl_cumul;
+	xstats.level   = READ_ONCE(cl->level);
+	xstats.period  = READ_ONCE(cl->cl_vtperiod);
+	xstats.work    = READ_ONCE(cl->cl_total);
+	xstats.rtwork  = READ_ONCE(cl->cl_cumul);
 
 	if (gnet_stats_copy_basic(d, NULL, &cl->bstats, true) < 0 ||
 	    gnet_stats_copy_rate_est(d, &cl->rate_est) < 0 ||
@@ -1452,15 +1452,15 @@ hfsc_change_qdisc(struct Qdisc *sch, struct nlattr *opt,
 static void
 hfsc_reset_class(struct hfsc_class *cl)
 {
-	cl->cl_total        = 0;
-	cl->cl_cumul        = 0;
+	WRITE_ONCE(cl->cl_total, 0);
+	WRITE_ONCE(cl->cl_cumul, 0);
 	cl->cl_d            = 0;
 	cl->cl_e            = 0;
 	cl->cl_vt           = 0;
 	cl->cl_vtadj        = 0;
 	cl->cl_cvtmin       = 0;
 	cl->cl_cvtoff       = 0;
-	cl->cl_vtperiod     = 0;
+	WRITE_ONCE(cl->cl_vtperiod, 0);
 	cl->cl_parentperiod = 0;
 	cl->cl_f            = 0;
 	cl->cl_myf          = 0;
@@ -1626,7 +1626,7 @@ hfsc_dequeue(struct Qdisc *sch)
 	bstats_update(&cl->bstats, skb);
 	update_vf(cl, qdisc_pkt_len(skb), cur_time);
 	if (realtime)
-		cl->cl_cumul += qdisc_pkt_len(skb);
+		WRITE_ONCE(cl->cl_cumul, cl->cl_cumul + qdisc_pkt_len(skb));
 
 	if (cl->cl_flags & HFSC_RSC) {
 		if (cl->qdisc->q.qlen != 0) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0210/2077] scsi: hisi_sas: Add slave_destroy interface for v3 hw
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (208 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0209/2077] net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0211/2077] crypto: ccp - Treat zero-length cert chain as query for blob lengths Greg Kroah-Hartman
                   ` (787 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yihang Li, Martin K. Petersen,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yihang Li <liyihang9@huawei.com>

[ Upstream commit 67b85a88265df19f049241d8c00571a5408f4eeb ]

WARNING is triggered when executing link reset of remote PHY and rmmod
SAS driver simultaneously. Following is the WARNING log:

WARNING: CPU: 61 PID: 21818 at drivers/base/core.c:1347 __device_links_no_driver+0xb4/0xc0
 Call trace:
  __device_links_no_driver+0xb4/0xc0
  device_links_driver_cleanup+0xb0/0xfc
  __device_release_driver+0x198/0x23c
  device_release_driver+0x38/0x50
  bus_remove_device+0x130/0x140
  device_del+0x184/0x434
  __scsi_remove_device+0x118/0x150
  scsi_remove_target+0x1bc/0x240
  sas_rphy_remove+0x90/0x94
  sas_rphy_delete+0x24/0x3c
  sas_destruct_devices+0x64/0xa0 [libsas]
  sas_revalidate_domain+0xe4/0x150 [libsas]
  process_one_work+0x1e0/0x46c
  worker_thread+0x15c/0x464
  kthread+0x160/0x170
  ret_from_fork+0x10/0x20
 ---[ end trace 71e059eb58f85d4a ]---

During SAS phy up, link->status is set to DL_STATE_AVAILABLE in
device_links_driver_bound, then this setting influences
__device_links_no_driver() before driver rmmod and caused WARNING.

Add the slave_destroy interface to make sure link is removed after flush
workque.

Fixes: 16fd4a7c5917 ("scsi: hisi_sas: Add device link between SCSI devices and hisi_hba")
Signed-off-by: Yihang Li <liyihang9@huawei.com>
Link: https://patch.msgid.link/20260425082056.2749910-1-liyihang9@huawei.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/scsi/hisi_sas/hisi_sas_v3_hw.c | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c b/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
index 14d563e82d2085..213d5b5dea94fa 100644
--- a/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
+++ b/drivers/scsi/hisi_sas/hisi_sas_v3_hw.c
@@ -2977,7 +2977,7 @@ static int sdev_configure_v3_hw(struct scsi_device *sdev,
 		return 0;
 
 	if (!device_link_add(&sdev->sdev_gendev, dev,
-			     DL_FLAG_PM_RUNTIME | DL_FLAG_RPM_ACTIVE)) {
+			     DL_FLAG_STATELESS | DL_FLAG_PM_RUNTIME | DL_FLAG_RPM_ACTIVE)) {
 		if (pm_runtime_enabled(dev)) {
 			dev_info(dev, "add device link failed, disable runtime PM for the host\n");
 			pm_runtime_disable(dev);
@@ -2987,6 +2987,15 @@ static int sdev_configure_v3_hw(struct scsi_device *sdev,
 	return 0;
 }
 
+static void hisi_sas_sdev_destroy(struct scsi_device *sdev)
+{
+	struct Scsi_Host *shost = dev_to_shost(&sdev->sdev_gendev);
+	struct hisi_hba *hisi_hba = shost_priv(shost);
+	struct device *dev = hisi_hba->dev;
+
+	device_link_remove(&sdev->sdev_gendev, dev);
+}
+
 static struct attribute *host_v3_hw_attrs[] = {
 	&dev_attr_phy_event_threshold.attr,
 	&dev_attr_intr_conv_v3_hw.attr,
@@ -3401,6 +3410,7 @@ static const struct scsi_host_template sht_v3_hw = {
 	.sg_tablesize		= HISI_SAS_SGE_PAGE_CNT,
 	.sg_prot_tablesize	= HISI_SAS_SGE_PAGE_CNT,
 	.sdev_init		= hisi_sas_sdev_init,
+	.sdev_destroy		= hisi_sas_sdev_destroy,
 	.shost_groups		= host_v3_hw_groups,
 	.sdev_groups		= sdev_groups_v3_hw,
 	.tag_alloc_policy_rr	= true,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0211/2077] crypto: ccp - Treat zero-length cert chain as query for blob lengths
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (209 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0210/2077] scsi: hisi_sas: Add slave_destroy interface for v3 hw Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0212/2077] crypto: af_alg - Cap AEAD AD length to 0x80000000 Greg Kroah-Hartman
                   ` (786 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sean Christopherson, Tom Lendacky,
	Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

[ Upstream commit ef8c9dacda2871accd64e3eda951fef6b788b1ea ]

When handling a PDH export, treat a zero-length userspace cert chain buffer
as a request to query the length of the relevant blobs.  Failure to account
for the zero-length buffer trips a BUG_ON() when running with
CONFIG_DEBUG_VIRTUAL=y due to trying to get the physical address of the
ZERO_SIZE_PTR (returned by kzalloc() on the bogus allocation).

   kernel BUG at arch/x86/mm/physaddr.c:28 !
  Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
  CPU: 30 UID: 0 PID: 28580 Comm: syz.2.18 Kdump: loaded
  Tainted: G        W           6.18.16-smp-DEV #1 NONE
  Tainted: [W]=WARN
  Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.62.0-0 11/19/2025
   RIP: 0010:__phys_addr+0x16a/0x180 arch/x86/mm/physaddr.c:28
  RSP: 0018:ffffc9008329fc80 EFLAGS: 00010293
  RAX: ffffffff8179110a RBX: 0000778000000010 RCX: ffff8884e6992600
  RDX: 0000000000000000 RSI: 0000000080000010 RDI: 0000778000000010
  RBP: ffffc9008329fdf0 R08: 0000000000000dc0 R09: 00000000ffffffff
  R10: dffffc0000000000 R11: fffffbfff126d297 R12: dffffc0000000000
  R13: 1ffff92010653fc8 R14: 0000000080000010 R15: dffffc0000000000
  FS:  0000555556bec9c0(0000) GS:ffff88aa4ce1c000(0000) knlGS:0000000000000000
  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
  CR2: 00007fd3159e7000 CR3: 00000004fbc44000 CR4: 0000000000350ef0
  Call Trace:
   <TASK>
    [<ffffffff853d3869>] sev_ioctl_do_pdh_export+0x559/0x7a0 drivers/crypto/ccp/sev-dev.c:2308
    [<ffffffff853d1fdd>] sev_ioctl+0x2cd/0x480 drivers/crypto/ccp/sev-dev.c:2556
    [<ffffffff82549ebc>] vfs_ioctl fs/ioctl.c:52 [inline]
    [<ffffffff82549ebc>] __do_sys_ioctl fs/ioctl.c:598 [inline]
    [<ffffffff82549ebc>] __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:584
    [<ffffffff8630115f>] do_syscall_x64 arch/x86/entry/syscall_64.c:64 [inline]
    [<ffffffff8630115f>] do_syscall_64+0x9f/0xf40 arch/x86/entry/syscall_64.c:98
   [<ffffffff81000136>] entry_SYSCALL_64_after_hwframe+0x76/0x7e
  RIP: 0033:0x7fd3158eac39
   </TASK>

Thankfully, the bug is benign outside of CONFIG_DEBUG_VIRTUAL=y as getting
the physical address is just arithmetic, and the PSP errors out before
trying to write to the garbage address (which it must, otherwise querying
the blob lengths would clobber memory at pfn=0).

Fixes: 76a2b524a4b1 ("crypto: ccp: Implement SEV_PDH_CERT_EXPORT ioctl command")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/ccp/sev-dev.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/crypto/ccp/sev-dev.c b/drivers/crypto/ccp/sev-dev.c
index 14df519ae7eea7..068b901034cbc9 100644
--- a/drivers/crypto/ccp/sev-dev.c
+++ b/drivers/crypto/ccp/sev-dev.c
@@ -2286,7 +2286,8 @@ static int sev_ioctl_do_pdh_export(struct sev_issue_cmd *argp, bool writable)
 	/* Userspace wants to query the certificate length. */
 	if (!input.pdh_cert_address ||
 	    !input.pdh_cert_len ||
-	    !input.cert_chain_address)
+	    !input.cert_chain_address ||
+	    !input.cert_chain_len)
 		goto cmd;
 
 	/* Allocate a physically contiguous buffer to store the PDH blob. */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0212/2077] crypto: af_alg - Cap AEAD AD length to 0x80000000
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (210 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0211/2077] crypto: ccp - Treat zero-length cert chain as query for blob lengths Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0213/2077] crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL Greg Kroah-Hartman
                   ` (785 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yiming Qian, Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

[ Upstream commit e4c06479d7059888adf2f22bc1ebcf053bf691a2 ]

In order to prevent arithmetic overflows when checking the TX
buffer size, cap the associated data length to 0x80000000.

Reported-by: Yiming Qian <yimingqian591@gmail.com>
Fixes: 400c40cf78da ("crypto: algif - add AEAD support")
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 crypto/af_alg.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/crypto/af_alg.c b/crypto/af_alg.c
index fce0b87c2b6521..48c53f488e0fd3 100644
--- a/crypto/af_alg.c
+++ b/crypto/af_alg.c
@@ -584,6 +584,8 @@ static int af_alg_cmsg_send(struct msghdr *msg, struct af_alg_control *con)
 			if (cmsg->cmsg_len < CMSG_LEN(sizeof(u32)))
 				return -EINVAL;
 			con->aead_assoclen = *(u32 *)CMSG_DATA(cmsg);
+			if (con->aead_assoclen >= 0x80000000u)
+				return -EINVAL;
 			break;
 
 		default:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0213/2077] crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (211 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0212/2077] crypto: af_alg - Cap AEAD AD length to 0x80000000 Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0214/2077] crypto: safexcel - Fix potential memory leak in safexcel_pci_probe() Greg Kroah-Hartman
                   ` (784 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Stepan Ionichev, Herbert Xu,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stepan Ionichev <sozdayvek@gmail.com>

[ Upstream commit 930d9d36ea618a775985446a125aedeb401db522 ]

dsm_create() initially checks pdev->bus when computing segment_id:

	u8 segment_id = pdev->bus ? pci_domain_nr(pdev->bus) : 0;

But the next two lines unconditionally dereference pdev->bus via
pcie_find_root_port() and especially pci_dev_id(pdev), which expands
to PCI_DEVID(dev->bus->number, dev->devfn). If pdev->bus is in fact
NULL, segment_id is initialised to 0 but the very next statement
crashes the kernel.

smatch flags this:

  drivers/crypto/ccp/sev-dev-tsm.c:253 dsm_create() error: we
    previously assumed 'pdev->bus' could be null (see line 251)

Make the NULL handling consistent: if pdev->bus is NULL the device
has no PCI context to work with and SEV TIO setup cannot proceed,
so return -ENODEV before any of the bus-dependent lookups. The
remaining initialisation now runs only on the path where pdev->bus
is known to be valid.

No change for callers where pdev->bus is non-NULL, which is the
only case where dsm_create() did meaningful work before this change.

Fixes: 4be423572da1 ("crypto/ccp: Implement SEV-TIO PCIe IDE (phase1)")
Signed-off-by: Stepan Ionichev <sozdayvek@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/ccp/sev-dev-tsm.c | 13 ++++++++++---
 1 file changed, 10 insertions(+), 3 deletions(-)

diff --git a/drivers/crypto/ccp/sev-dev-tsm.c b/drivers/crypto/ccp/sev-dev-tsm.c
index b07ae529b5910e..f303d8f55991b5 100644
--- a/drivers/crypto/ccp/sev-dev-tsm.c
+++ b/drivers/crypto/ccp/sev-dev-tsm.c
@@ -248,12 +248,19 @@ static void dsm_remove(struct pci_tsm *tsm)
 static int dsm_create(struct tio_dsm *dsm)
 {
 	struct pci_dev *pdev = dsm->tsm.base_tsm.pdev;
-	u8 segment_id = pdev->bus ? pci_domain_nr(pdev->bus) : 0;
-	struct pci_dev *rootport = pcie_find_root_port(pdev);
-	u16 device_id = pci_dev_id(pdev);
+	struct pci_dev *rootport;
+	u8 segment_id;
+	u16 device_id;
 	u16 root_port_id;
 	u32 lnkcap = 0;
 
+	if (!pdev->bus)
+		return -ENODEV;
+
+	segment_id = pci_domain_nr(pdev->bus);
+	rootport = pcie_find_root_port(pdev);
+	device_id = pci_dev_id(pdev);
+
 	if (pci_read_config_dword(rootport, pci_pcie_cap(rootport) + PCI_EXP_LNKCAP,
 				  &lnkcap))
 		return -ENODEV;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0214/2077] crypto: safexcel - Fix potential memory leak in safexcel_pci_probe()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (212 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0213/2077] crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0215/2077] spi: hisi-kunpeng: Use dev_err_probe() for host registration failure Greg Kroah-Hartman
                   ` (783 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Abdun Nihaal, Antoine Tenart,
	Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Abdun Nihaal <nihaal@cse.iitm.ac.in>

[ Upstream commit c36faca103a685590281412e47df74b550f71886 ]

The memory allocated for priv in safexcel_pci_probe() is not freed in the
error paths, as well as in the PCI remove function. Fix this by using
device managed allocation.

Fixes: 625f269a5a7a ("crypto: inside-secure - add support for PCI based FPGA development board")
Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in>
Reviewed-by: Antoine Tenart <atenart@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/inside-secure/safexcel.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/crypto/inside-secure/safexcel.c b/drivers/crypto/inside-secure/safexcel.c
index fb4936e7afa2dd..2bd8641a07b366 100644
--- a/drivers/crypto/inside-secure/safexcel.c
+++ b/drivers/crypto/inside-secure/safexcel.c
@@ -1893,7 +1893,7 @@ static int safexcel_pci_probe(struct pci_dev *pdev,
 		ent->vendor, ent->device, ent->subvendor,
 		ent->subdevice, ent->driver_data);
 
-	priv = kzalloc_obj(*priv);
+	priv = devm_kzalloc(dev, sizeof(*priv), GFP_KERNEL);
 	if (!priv)
 		return -ENOMEM;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0215/2077] spi: hisi-kunpeng: Use dev_err_probe() for host registration failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (213 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0214/2077] crypto: safexcel - Fix potential memory leak in safexcel_pci_probe() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0216/2077] net/sched: add qdisc_qlen_inc() and qdisc_qlen_dec() Greg Kroah-Hartman
                   ` (782 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Qiang Ma, Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Qiang Ma <maqianga@uniontech.com>

[ Upstream commit 59b991990a04b1d1ce95373983b7c8b65bdf7acc ]

When the SPI core registers the Kunpeng controller it may need to acquire
chip-select GPIO descriptors. If the GPIO provider has not probed yet,
spi_register_controller() returns -EPROBE_DEFER.

On a Kunpeng system this currently prints an alarming error even though the
next deferred-probe retry succeeds:

  hisi-kunpeng-spi HISI03E1:00: failed to register spi host, ret=-517
  hisi-kunpeng-spi HISI03E1:00: hw version:0x30 max-freq:12500 kHz

Use dev_err_probe() so that -EPROBE_DEFER is reported through the deferred
probe mechanism instead of as a hard error, while preserving normal error
reporting for real registration failures.

Fixes: c770d8631e18 ("spi: Add HiSilicon SPI Controller Driver for Kunpeng SoCs")

Signed-off-by: Qiang Ma <maqianga@uniontech.com>
Link: https://patch.msgid.link/20260515102620.1926930-1-maqianga@uniontech.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/spi/spi-hisi-kunpeng.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

diff --git a/drivers/spi/spi-hisi-kunpeng.c b/drivers/spi/spi-hisi-kunpeng.c
index 046bd894040b10..395214b81179ec 100644
--- a/drivers/spi/spi-hisi-kunpeng.c
+++ b/drivers/spi/spi-hisi-kunpeng.c
@@ -520,10 +520,8 @@ static int hisi_spi_probe(struct platform_device *pdev)
 	}
 
 	ret = spi_register_controller(host);
-	if (ret) {
-		dev_err(dev, "failed to register spi host, ret=%d\n", ret);
-		return ret;
-	}
+	if (ret)
+		return dev_err_probe(dev, ret, "failed to register spi host\n");
 
 	if (hisi_spi_debugfs_init(hs))
 		dev_info(dev, "failed to create debugfs dir\n");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0216/2077] net/sched: add qdisc_qlen_inc() and qdisc_qlen_dec()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (214 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0215/2077] spi: hisi-kunpeng: Use dev_err_probe() for host registration failure Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0217/2077] net/sched: sch_dualpi2: annotate data-races in dualpi2_dump_stats() Greg Kroah-Hartman
                   ` (781 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eric Dumazet,
	Toke Høiland-Jørgensen, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 863cd78652018576c60f1b73477a15bdb0ea7551 ]

Helpers to increment or decrement sch->q.qlen, with appropriate
WRITE_ONCE() to prevent store tearing.

Add other WRITE_ONCE() when sch->q.qlen is changed.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Toke Høiland-Jørgensen <toke@toke.dk>
Link: https://patch.msgid.link/20260510091455.4039245-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 5658bddaca41 ("net/sched: sch_dualpi2: annotate data-races in dualpi2_dump_stats()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/net/sch_generic.h | 32 +++++++++++++++++++++-----------
 net/sched/sch_api.c       |  2 +-
 net/sched/sch_cake.c      |  8 ++++----
 net/sched/sch_cbs.c       |  4 ++--
 net/sched/sch_choke.c     |  8 ++++----
 net/sched/sch_drr.c       |  4 ++--
 net/sched/sch_dualpi2.c   |  6 +++---
 net/sched/sch_etf.c       |  8 ++++----
 net/sched/sch_ets.c       |  4 ++--
 net/sched/sch_fq.c        |  6 +++---
 net/sched/sch_fq_codel.c  |  7 ++++---
 net/sched/sch_fq_pie.c    |  4 ++--
 net/sched/sch_generic.c   | 10 +++++-----
 net/sched/sch_hfsc.c      |  4 ++--
 net/sched/sch_hhf.c       |  7 ++++---
 net/sched/sch_htb.c       |  4 ++--
 net/sched/sch_mq.c        |  5 +++--
 net/sched/sch_mqprio.c    | 18 ++++++++++--------
 net/sched/sch_multiq.c    |  4 ++--
 net/sched/sch_netem.c     | 10 +++++-----
 net/sched/sch_prio.c      |  4 ++--
 net/sched/sch_qfq.c       |  6 +++---
 net/sched/sch_red.c       |  4 ++--
 net/sched/sch_sfb.c       |  4 ++--
 net/sched/sch_sfq.c       |  9 +++++----
 net/sched/sch_skbprio.c   |  4 ++--
 net/sched/sch_taprio.c    |  4 ++--
 net/sched/sch_tbf.c       |  6 +++---
 net/sched/sch_teql.c      |  2 +-
 29 files changed, 107 insertions(+), 91 deletions(-)

diff --git a/include/net/sch_generic.h b/include/net/sch_generic.h
index 11159a50d6a145..195e22a8356622 100644
--- a/include/net/sch_generic.h
+++ b/include/net/sch_generic.h
@@ -542,6 +542,16 @@ static inline int qdisc_qlen(const struct Qdisc *q)
 	return q->q.qlen;
 }
 
+static inline void qdisc_qlen_inc(struct Qdisc *q)
+{
+	WRITE_ONCE(q->q.qlen, q->q.qlen + 1);
+}
+
+static inline void qdisc_qlen_dec(struct Qdisc *q)
+{
+	WRITE_ONCE(q->q.qlen, q->q.qlen - 1);
+}
+
 static inline int qdisc_qlen_sum(const struct Qdisc *q)
 {
 	__u32 qlen = q->qstats.qlen;
@@ -549,9 +559,9 @@ static inline int qdisc_qlen_sum(const struct Qdisc *q)
 
 	if (qdisc_is_percpu_stats(q)) {
 		for_each_possible_cpu(i)
-			qlen += per_cpu_ptr(q->cpu_qstats, i)->qlen;
+			qlen += READ_ONCE(per_cpu_ptr(q->cpu_qstats, i)->qlen);
 	} else {
-		qlen += q->q.qlen;
+		qlen += READ_ONCE(q->q.qlen);
 	}
 
 	return qlen;
@@ -1063,7 +1073,7 @@ static inline void __qdisc_enqueue_tail(struct sk_buff *skb,
 		qh->tail = skb;
 		qh->head = skb;
 	}
-	qh->qlen++;
+	WRITE_ONCE(qh->qlen, qh->qlen + 1);
 }
 
 static inline int qdisc_enqueue_tail(struct sk_buff *skb, struct Qdisc *sch)
@@ -1081,7 +1091,7 @@ static inline void __qdisc_enqueue_head(struct sk_buff *skb,
 	if (!qh->head)
 		qh->tail = skb;
 	qh->head = skb;
-	qh->qlen++;
+	WRITE_ONCE(qh->qlen, qh->qlen + 1);
 }
 
 static inline struct sk_buff *__qdisc_dequeue_head(struct qdisc_skb_head *qh)
@@ -1090,7 +1100,7 @@ static inline struct sk_buff *__qdisc_dequeue_head(struct qdisc_skb_head *qh)
 
 	if (likely(skb != NULL)) {
 		qh->head = skb->next;
-		qh->qlen--;
+		WRITE_ONCE(qh->qlen, qh->qlen - 1);
 		if (qh->head == NULL)
 			qh->tail = NULL;
 		skb->next = NULL;
@@ -1105,7 +1115,7 @@ static inline struct sk_buff *qdisc_dequeue_internal(struct Qdisc *sch, bool dir
 
 	skb = __skb_dequeue(&sch->gso_skb);
 	if (skb) {
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 		qdisc_qstats_backlog_dec(sch, skb);
 		return skb;
 	}
@@ -1261,7 +1271,7 @@ static inline struct sk_buff *qdisc_peek_dequeued(struct Qdisc *sch)
 			__skb_queue_head(&sch->gso_skb, skb);
 			/* it's still part of the queue */
 			qdisc_qstats_backlog_inc(sch, skb);
-			sch->q.qlen++;
+			qdisc_qlen_inc(sch);
 		}
 	}
 
@@ -1278,7 +1288,7 @@ static inline void qdisc_update_stats_at_dequeue(struct Qdisc *sch,
 	} else {
 		qdisc_qstats_backlog_dec(sch, skb);
 		qdisc_bstats_update(sch, skb);
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 	}
 }
 
@@ -1290,7 +1300,7 @@ static inline void qdisc_update_stats_at_enqueue(struct Qdisc *sch,
 		this_cpu_add(sch->cpu_qstats->backlog, pkt_len);
 	} else {
 		sch->qstats.backlog += pkt_len;
-		sch->q.qlen++;
+		qdisc_qlen_inc(sch);
 	}
 }
 
@@ -1306,7 +1316,7 @@ static inline struct sk_buff *qdisc_dequeue_peeked(struct Qdisc *sch)
 			qdisc_qstats_cpu_qlen_dec(sch);
 		} else {
 			qdisc_qstats_backlog_dec(sch, skb);
-			sch->q.qlen--;
+			qdisc_qlen_dec(sch);
 		}
 	} else {
 		skb = sch->dequeue(sch);
@@ -1327,7 +1337,7 @@ static inline void __qdisc_reset_queue(struct qdisc_skb_head *qh)
 
 		qh->head = NULL;
 		qh->tail = NULL;
-		qh->qlen = 0;
+		WRITE_ONCE(qh->qlen, 0);
 	}
 }
 
diff --git a/net/sched/sch_api.c b/net/sched/sch_api.c
index ed869a5ffc7377..0dd3efd8639387 100644
--- a/net/sched/sch_api.c
+++ b/net/sched/sch_api.c
@@ -805,7 +805,7 @@ void qdisc_tree_reduce_backlog(struct Qdisc *sch, int n, int len)
 			cl = cops->find(sch, parentid);
 			cops->qlen_notify(sch, cl);
 		}
-		sch->q.qlen -= n;
+		WRITE_ONCE(sch->q.qlen, sch->q.qlen - n);
 		sch->qstats.backlog -= len;
 		__qdisc_qstats_drop(sch, drops);
 	}
diff --git a/net/sched/sch_cake.c b/net/sched/sch_cake.c
index 5862933be8d746..c4915073d9d1a4 100644
--- a/net/sched/sch_cake.c
+++ b/net/sched/sch_cake.c
@@ -1612,7 +1612,7 @@ static unsigned int cake_drop(struct Qdisc *sch, struct sk_buff **to_free)
 		cake_advance_shaper(q, b, skb, now, true);
 
 	qdisc_drop_reason(skb, sch, to_free, QDISC_DROP_OVERLIMIT);
-	sch->q.qlen--;
+	qdisc_qlen_dec(sch);
 
 	cake_heapify(q, 0);
 
@@ -1822,7 +1822,7 @@ static s32 cake_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 									  segs);
 			flow_queue_add(flow, segs);
 
-			sch->q.qlen++;
+			qdisc_qlen_inc(sch);
 			numsegs++;
 			slen += segs->len;
 			q->buffer_used += segs->truesize;
@@ -1861,7 +1861,7 @@ static s32 cake_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 			qdisc_tree_reduce_backlog(sch, 1, ack_pkt_len);
 			consume_skb(ack);
 		} else {
-			sch->q.qlen++;
+			qdisc_qlen_inc(sch);
 			q->buffer_used      += skb->truesize;
 		}
 
@@ -1987,7 +1987,7 @@ static struct sk_buff *cake_dequeue_one(struct Qdisc *sch)
 		WRITE_ONCE(b->tin_backlog, b->tin_backlog - len);
 		sch->qstats.backlog      -= len;
 		q->buffer_used		 -= skb->truesize;
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 
 		if (q->overflow_timeout)
 			cake_heapify(q, b->overflow_idx[q->cur_flow]);
diff --git a/net/sched/sch_cbs.c b/net/sched/sch_cbs.c
index 0f953bd46b5814..0994da70816ecf 100644
--- a/net/sched/sch_cbs.c
+++ b/net/sched/sch_cbs.c
@@ -97,7 +97,7 @@ static int cbs_child_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 		return err;
 
 	sch->qstats.backlog += len;
-	sch->q.qlen++;
+	qdisc_qlen_inc(sch);
 
 	return NET_XMIT_SUCCESS;
 }
@@ -168,7 +168,7 @@ static struct sk_buff *cbs_child_dequeue(struct Qdisc *sch, struct Qdisc *child)
 
 	qdisc_qstats_backlog_dec(sch, skb);
 	qdisc_bstats_update(sch, skb);
-	sch->q.qlen--;
+	qdisc_qlen_dec(sch);
 
 	return skb;
 }
diff --git a/net/sched/sch_choke.c b/net/sched/sch_choke.c
index 2875bcdb18a413..73d3e673dc7b16 100644
--- a/net/sched/sch_choke.c
+++ b/net/sched/sch_choke.c
@@ -123,7 +123,7 @@ static void choke_drop_by_idx(struct Qdisc *sch, unsigned int idx,
 	if (idx == q->tail)
 		choke_zap_tail_holes(q);
 
-	--sch->q.qlen;
+	qdisc_qlen_dec(sch);
 	qdisc_qstats_backlog_dec(sch, skb);
 	qdisc_tree_reduce_backlog(sch, 1, qdisc_pkt_len(skb));
 	qdisc_drop(skb, sch, to_free);
@@ -271,7 +271,7 @@ static int choke_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 	if (sch->q.qlen < q->limit) {
 		q->tab[q->tail] = skb;
 		q->tail = (q->tail + 1) & q->tab_mask;
-		++sch->q.qlen;
+		qdisc_qlen_inc(sch);
 		qdisc_qstats_backlog_inc(sch, skb);
 		return NET_XMIT_SUCCESS;
 	}
@@ -298,7 +298,7 @@ static struct sk_buff *choke_dequeue(struct Qdisc *sch)
 	skb = q->tab[q->head];
 	q->tab[q->head] = NULL;
 	choke_zap_head_holes(q);
-	--sch->q.qlen;
+	qdisc_qlen_dec(sch);
 	qdisc_qstats_backlog_dec(sch, skb);
 	qdisc_bstats_update(sch, skb);
 
@@ -396,7 +396,7 @@ static int choke_change(struct Qdisc *sch, struct nlattr *opt,
 				}
 				dropped += qdisc_pkt_len(skb);
 				qdisc_qstats_backlog_dec(sch, skb);
-				--sch->q.qlen;
+				qdisc_qlen_dec(sch);
 				rtnl_qdisc_drop(skb, sch);
 			}
 			qdisc_tree_reduce_backlog(sch, oqlen - sch->q.qlen, dropped);
diff --git a/net/sched/sch_drr.c b/net/sched/sch_drr.c
index 01335a49e09144..925fa0cfd730ce 100644
--- a/net/sched/sch_drr.c
+++ b/net/sched/sch_drr.c
@@ -366,7 +366,7 @@ static int drr_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 	}
 
 	sch->qstats.backlog += len;
-	sch->q.qlen++;
+	qdisc_qlen_inc(sch);
 	return err;
 }
 
@@ -399,7 +399,7 @@ static struct sk_buff *drr_dequeue(struct Qdisc *sch)
 			bstats_update(&cl->bstats, skb);
 			qdisc_bstats_update(sch, skb);
 			qdisc_qstats_backlog_dec(sch, skb);
-			sch->q.qlen--;
+			qdisc_qlen_dec(sch);
 			return skb;
 		}
 
diff --git a/net/sched/sch_dualpi2.c b/net/sched/sch_dualpi2.c
index 1ca4d2c03e61d5..9a6020238427c2 100644
--- a/net/sched/sch_dualpi2.c
+++ b/net/sched/sch_dualpi2.c
@@ -415,7 +415,7 @@ static int dualpi2_enqueue_skb(struct sk_buff *skb, struct Qdisc *sch,
 		dualpi2_skb_cb(skb)->apply_step = skb_apply_step(skb, q);
 
 		/* Keep the overall qdisc stats consistent */
-		++sch->q.qlen;
+		qdisc_qlen_inc(sch);
 		qdisc_qstats_backlog_inc(sch, skb);
 		++q->packets_in_l;
 		if (!q->l_head_ts)
@@ -529,7 +529,7 @@ static struct sk_buff *dequeue_packet(struct Qdisc *sch,
 		qdisc_qstats_backlog_dec(q->l_queue, skb);
 
 		/* Keep the global queue size consistent */
-		--sch->q.qlen;
+		qdisc_qlen_dec(sch);
 		q->memory_used -= skb->truesize;
 	} else if (c_len) {
 		skb = __qdisc_dequeue_head(&sch->q);
@@ -887,7 +887,7 @@ static int dualpi2_change(struct Qdisc *sch, struct nlattr *opt,
 			 * l_queue on enqueue; qdisc_dequeue_internal()
 			 * handled l_queue, so we further account for sch.
 			 */
-			--sch->q.qlen;
+			qdisc_qlen_dec(sch);
 			qdisc_qstats_backlog_dec(sch, skb);
 			q->memory_used -= skb->truesize;
 			rtnl_qdisc_drop(skb, q->l_queue);
diff --git a/net/sched/sch_etf.c b/net/sched/sch_etf.c
index c74d778c32a1ed..ada87a81da6ac4 100644
--- a/net/sched/sch_etf.c
+++ b/net/sched/sch_etf.c
@@ -189,7 +189,7 @@ static int etf_enqueue_timesortedlist(struct sk_buff *nskb, struct Qdisc *sch,
 	rb_insert_color_cached(&nskb->rbnode, &q->head, leftmost);
 
 	qdisc_qstats_backlog_inc(sch, nskb);
-	sch->q.qlen++;
+	qdisc_qlen_inc(sch);
 
 	/* Now we may need to re-arm the qdisc watchdog for the next packet. */
 	reset_watchdog(sch);
@@ -222,7 +222,7 @@ static void timesortedlist_drop(struct Qdisc *sch, struct sk_buff *skb,
 		qdisc_qstats_backlog_dec(sch, skb);
 		qdisc_drop(skb, sch, &to_free);
 		qdisc_qstats_overlimit(sch);
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 	}
 
 	kfree_skb_list(to_free);
@@ -247,7 +247,7 @@ static void timesortedlist_remove(struct Qdisc *sch, struct sk_buff *skb)
 
 	q->last = skb->tstamp;
 
-	sch->q.qlen--;
+	qdisc_qlen_dec(sch);
 }
 
 static struct sk_buff *etf_dequeue_timesortedlist(struct Qdisc *sch)
@@ -426,7 +426,7 @@ static void timesortedlist_clear(struct Qdisc *sch)
 
 		rb_erase_cached(&skb->rbnode, &q->head);
 		rtnl_kfree_skbs(skb, skb);
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 	}
 }
 
diff --git a/net/sched/sch_ets.c b/net/sched/sch_ets.c
index a4b07b661b7756..c817e0a6c14653 100644
--- a/net/sched/sch_ets.c
+++ b/net/sched/sch_ets.c
@@ -449,7 +449,7 @@ static int ets_qdisc_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 	}
 
 	sch->qstats.backlog += len;
-	sch->q.qlen++;
+	qdisc_qlen_inc(sch);
 	return err;
 }
 
@@ -458,7 +458,7 @@ ets_qdisc_dequeue_skb(struct Qdisc *sch, struct sk_buff *skb)
 {
 	qdisc_bstats_update(sch, skb);
 	qdisc_qstats_backlog_dec(sch, skb);
-	sch->q.qlen--;
+	qdisc_qlen_dec(sch);
 	return skb;
 }
 
diff --git a/net/sched/sch_fq.c b/net/sched/sch_fq.c
index f2edcf872981fd..1e34ac136b15cf 100644
--- a/net/sched/sch_fq.c
+++ b/net/sched/sch_fq.c
@@ -497,7 +497,7 @@ static void fq_dequeue_skb(struct Qdisc *sch, struct fq_flow *flow,
 	fq_erase_head(sch, flow, skb);
 	skb_mark_not_on_list(skb);
 	qdisc_qstats_backlog_dec(sch, skb);
-	sch->q.qlen--;
+	qdisc_qlen_dec(sch);
 	qdisc_bstats_update(sch, skb);
 }
 
@@ -597,7 +597,7 @@ static int fq_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 	flow_queue_add(f, skb);
 
 	qdisc_qstats_backlog_inc(sch, skb);
-	sch->q.qlen++;
+	qdisc_qlen_inc(sch);
 
 	return NET_XMIT_SUCCESS;
 }
@@ -801,7 +801,7 @@ static void fq_reset(struct Qdisc *sch)
 	struct fq_flow *f;
 	unsigned int idx;
 
-	sch->q.qlen = 0;
+	WRITE_ONCE(sch->q.qlen, 0);
 	sch->qstats.backlog = 0;
 
 	fq_flow_purge(&q->internal);
diff --git a/net/sched/sch_fq_codel.c b/net/sched/sch_fq_codel.c
index 24db54684e8a59..5302d50f4bef6c 100644
--- a/net/sched/sch_fq_codel.c
+++ b/net/sched/sch_fq_codel.c
@@ -178,7 +178,7 @@ static unsigned int fq_codel_drop(struct Qdisc *sch, unsigned int max_packets,
 	q->memory_usage -= mem;
 	sch->qstats.drops += i;
 	sch->qstats.backlog -= len;
-	sch->q.qlen -= i;
+	WRITE_ONCE(sch->q.qlen, sch->q.qlen - i);
 	return idx;
 }
 
@@ -215,7 +215,8 @@ static int fq_codel_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 	get_codel_cb(skb)->mem_usage = skb->truesize;
 	q->memory_usage += get_codel_cb(skb)->mem_usage;
 	memory_limited = q->memory_usage > q->memory_limit;
-	if (++sch->q.qlen <= sch->limit && !memory_limited)
+	qdisc_qlen_inc(sch);
+	if (sch->q.qlen <= sch->limit && !memory_limited)
 		return NET_XMIT_SUCCESS;
 
 	prev_backlog = sch->qstats.backlog;
@@ -266,7 +267,7 @@ static struct sk_buff *dequeue_func(struct codel_vars *vars, void *ctx)
 		WRITE_ONCE(q->backlogs[flow - q->flows],
 			   q->backlogs[flow - q->flows] - qdisc_pkt_len(skb));
 		q->memory_usage -= get_codel_cb(skb)->mem_usage;
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 		sch->qstats.backlog -= qdisc_pkt_len(skb);
 	}
 	return skb;
diff --git a/net/sched/sch_fq_pie.c b/net/sched/sch_fq_pie.c
index 7becbf5362b316..0a4eca4ab086eb 100644
--- a/net/sched/sch_fq_pie.c
+++ b/net/sched/sch_fq_pie.c
@@ -185,7 +185,7 @@ static int fq_pie_qdisc_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 		q->stats.packets_in++;
 		q->memory_usage += skb->truesize;
 		sch->qstats.backlog += pkt_len;
-		sch->q.qlen++;
+		qdisc_qlen_inc(sch);
 		flow_queue_add(sel_flow, skb);
 		if (list_empty(&sel_flow->flowchain)) {
 			list_add_tail(&sel_flow->flowchain, &q->new_flows);
@@ -263,7 +263,7 @@ static struct sk_buff *fq_pie_qdisc_dequeue(struct Qdisc *sch)
 		skb = dequeue_head(flow);
 		pkt_len = qdisc_pkt_len(skb);
 		sch->qstats.backlog -= pkt_len;
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 		qdisc_bstats_update(sch, skb);
 	}
 
diff --git a/net/sched/sch_generic.c b/net/sched/sch_generic.c
index a93321db8fd75d..e35d9c58850fa9 100644
--- a/net/sched/sch_generic.c
+++ b/net/sched/sch_generic.c
@@ -118,7 +118,7 @@ static inline struct sk_buff *__skb_dequeue_bad_txq(struct Qdisc *q)
 				qdisc_qstats_cpu_qlen_dec(q);
 			} else {
 				qdisc_qstats_backlog_dec(q, skb);
-				q->q.qlen--;
+				qdisc_qlen_dec(q);
 			}
 		} else {
 			skb = SKB_XOFF_MAGIC;
@@ -159,7 +159,7 @@ static inline void qdisc_enqueue_skb_bad_txq(struct Qdisc *q,
 		qdisc_qstats_cpu_qlen_inc(q);
 	} else {
 		qdisc_qstats_backlog_inc(q, skb);
-		q->q.qlen++;
+		qdisc_qlen_inc(q);
 	}
 
 	if (lock)
@@ -188,7 +188,7 @@ static inline void dev_requeue_skb(struct sk_buff *skb, struct Qdisc *q)
 		} else {
 			q->qstats.requeues++;
 			qdisc_qstats_backlog_inc(q, skb);
-			q->q.qlen++;
+			qdisc_qlen_inc(q);
 		}
 
 		skb = next;
@@ -294,7 +294,7 @@ static struct sk_buff *dequeue_skb(struct Qdisc *q, bool *validate,
 				qdisc_qstats_cpu_qlen_dec(q);
 			} else {
 				qdisc_qstats_backlog_dec(q, skb);
-				q->q.qlen--;
+				qdisc_qlen_dec(q);
 			}
 		} else {
 			skb = NULL;
@@ -1059,7 +1059,7 @@ void qdisc_reset(struct Qdisc *qdisc)
 	__skb_queue_purge(&qdisc->gso_skb);
 	__skb_queue_purge(&qdisc->skb_bad_txq);
 
-	qdisc->q.qlen = 0;
+	WRITE_ONCE(qdisc->q.qlen, 0);
 	qdisc->qstats.backlog = 0;
 }
 EXPORT_SYMBOL(qdisc_reset);
diff --git a/net/sched/sch_hfsc.c b/net/sched/sch_hfsc.c
index 55258aac6b93c7..e3dd6de8f1b6e5 100644
--- a/net/sched/sch_hfsc.c
+++ b/net/sched/sch_hfsc.c
@@ -1561,7 +1561,7 @@ hfsc_enqueue(struct sk_buff *skb, struct Qdisc *sch, struct sk_buff **to_free)
 	}
 
 	sch->qstats.backlog += len;
-	sch->q.qlen++;
+	qdisc_qlen_inc(sch);
 
 	if (first && !cl_in_el_or_vttree(cl)) {
 		if (cl->cl_flags & HFSC_RSC)
@@ -1650,7 +1650,7 @@ hfsc_dequeue(struct Qdisc *sch)
 
 	qdisc_bstats_update(sch, skb);
 	qdisc_qstats_backlog_dec(sch, skb);
-	sch->q.qlen--;
+	qdisc_qlen_dec(sch);
 
 	return skb;
 }
diff --git a/net/sched/sch_hhf.c b/net/sched/sch_hhf.c
index 96021f52d835b5..1e25b75daae2e5 100644
--- a/net/sched/sch_hhf.c
+++ b/net/sched/sch_hhf.c
@@ -360,7 +360,7 @@ static unsigned int hhf_drop(struct Qdisc *sch, struct sk_buff **to_free)
 	if (bucket->head) {
 		struct sk_buff *skb = dequeue_head(bucket);
 
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 		qdisc_qstats_backlog_dec(sch, skb);
 		qdisc_drop(skb, sch, to_free);
 	}
@@ -400,7 +400,8 @@ static int hhf_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 		}
 		bucket->deficit = weight * q->quantum;
 	}
-	if (++sch->q.qlen <= sch->limit)
+	qdisc_qlen_inc(sch);
+	if (sch->q.qlen <= sch->limit)
 		return NET_XMIT_SUCCESS;
 
 	prev_backlog = sch->qstats.backlog;
@@ -443,7 +444,7 @@ static struct sk_buff *hhf_dequeue(struct Qdisc *sch)
 
 	if (bucket->head) {
 		skb = dequeue_head(bucket);
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 		qdisc_qstats_backlog_dec(sch, skb);
 	}
 
diff --git a/net/sched/sch_htb.c b/net/sched/sch_htb.c
index eb12381795ce1b..c22ccd8eae8c73 100644
--- a/net/sched/sch_htb.c
+++ b/net/sched/sch_htb.c
@@ -651,7 +651,7 @@ static int htb_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 	}
 
 	sch->qstats.backlog += len;
-	sch->q.qlen++;
+	qdisc_qlen_inc(sch);
 	return NET_XMIT_SUCCESS;
 }
 
@@ -951,7 +951,7 @@ static struct sk_buff *htb_dequeue(struct Qdisc *sch)
 ok:
 		qdisc_bstats_update(sch, skb);
 		qdisc_qstats_backlog_dec(sch, skb);
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 		return skb;
 	}
 
diff --git a/net/sched/sch_mq.c b/net/sched/sch_mq.c
index a0133a7b9d3b09..ec8c91d3fde04e 100644
--- a/net/sched/sch_mq.c
+++ b/net/sched/sch_mq.c
@@ -143,10 +143,10 @@ EXPORT_SYMBOL_NS_GPL(mq_attach, "NET_SCHED_INTERNAL");
 void mq_dump_common(struct Qdisc *sch, struct sk_buff *skb)
 {
 	struct net_device *dev = qdisc_dev(sch);
+	unsigned int qlen = 0;
 	struct Qdisc *qdisc;
 	unsigned int ntx;
 
-	sch->q.qlen = 0;
 	gnet_stats_basic_sync_init(&sch->bstats);
 	memset(&sch->qstats, 0, sizeof(sch->qstats));
 
@@ -163,10 +163,11 @@ void mq_dump_common(struct Qdisc *sch, struct sk_buff *skb)
 				     &qdisc->bstats, false);
 		gnet_stats_add_queue(&sch->qstats, qdisc->cpu_qstats,
 				     &qdisc->qstats);
-		sch->q.qlen += qdisc_qlen(qdisc);
+		qlen += qdisc_qlen(qdisc);
 
 		spin_unlock_bh(qdisc_lock(qdisc));
 	}
+	WRITE_ONCE(sch->q.qlen, qlen);
 }
 EXPORT_SYMBOL_NS_GPL(mq_dump_common, "NET_SCHED_INTERNAL");
 
diff --git a/net/sched/sch_mqprio.c b/net/sched/sch_mqprio.c
index 002add5ce9e0ab..91a92992cd24ab 100644
--- a/net/sched/sch_mqprio.c
+++ b/net/sched/sch_mqprio.c
@@ -555,10 +555,11 @@ static int mqprio_dump(struct Qdisc *sch, struct sk_buff *skb)
 	struct mqprio_sched *priv = qdisc_priv(sch);
 	struct nlattr *nla = (struct nlattr *)skb_tail_pointer(skb);
 	struct tc_mqprio_qopt opt = { 0 };
+	unsigned int qlen = 0;
 	struct Qdisc *qdisc;
 	unsigned int ntx;
 
-	sch->q.qlen = 0;
+	qlen = 0;
 	gnet_stats_basic_sync_init(&sch->bstats);
 	memset(&sch->qstats, 0, sizeof(sch->qstats));
 
@@ -575,10 +576,11 @@ static int mqprio_dump(struct Qdisc *sch, struct sk_buff *skb)
 				     &qdisc->bstats, false);
 		gnet_stats_add_queue(&sch->qstats, qdisc->cpu_qstats,
 				     &qdisc->qstats);
-		sch->q.qlen += qdisc_qlen(qdisc);
+		qlen += qdisc_qlen(qdisc);
 
 		spin_unlock_bh(qdisc_lock(qdisc));
 	}
+	WRITE_ONCE(sch->q.qlen, qlen);
 
 	mqprio_qopt_reconstruct(dev, &opt);
 	opt.hw = priv->hw_offload;
@@ -663,12 +665,12 @@ static int mqprio_dump_class_stats(struct Qdisc *sch, unsigned long cl,
 	__acquires(d->lock)
 {
 	if (cl >= TC_H_MIN_PRIORITY) {
-		int i;
-		__u32 qlen;
-		struct gnet_stats_queue qstats = {0};
-		struct gnet_stats_basic_sync bstats;
 		struct net_device *dev = qdisc_dev(sch);
 		struct netdev_tc_txq tc = dev->tc_to_txq[cl & TC_BITMASK];
+		struct gnet_stats_queue qstats = {0};
+		struct gnet_stats_basic_sync bstats;
+		u32 qlen = 0;
+		int i;
 
 		gnet_stats_basic_sync_init(&bstats);
 		/* Drop lock here it will be reclaimed before touching
@@ -689,11 +691,11 @@ static int mqprio_dump_class_stats(struct Qdisc *sch, unsigned long cl,
 					     &qdisc->bstats, false);
 			gnet_stats_add_queue(&qstats, qdisc->cpu_qstats,
 					     &qdisc->qstats);
-			sch->q.qlen += qdisc_qlen(qdisc);
+			qlen += qdisc_qlen(qdisc);
 
 			spin_unlock_bh(qdisc_lock(qdisc));
 		}
-		qlen = qdisc_qlen(sch) + qstats.qlen;
+		qlen = qlen + qstats.qlen;
 
 		/* Reclaim root sleeping lock before completing stats */
 		if (d->lock)
diff --git a/net/sched/sch_multiq.c b/net/sched/sch_multiq.c
index 9f822fee113df6..4e465d11e3d75e 100644
--- a/net/sched/sch_multiq.c
+++ b/net/sched/sch_multiq.c
@@ -76,7 +76,7 @@ multiq_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 
 	ret = qdisc_enqueue(skb, qdisc, to_free);
 	if (ret == NET_XMIT_SUCCESS) {
-		sch->q.qlen++;
+		qdisc_qlen_inc(sch);
 		return NET_XMIT_SUCCESS;
 	}
 	if (net_xmit_drop_count(ret))
@@ -106,7 +106,7 @@ static struct sk_buff *multiq_dequeue(struct Qdisc *sch)
 			skb = qdisc->dequeue(qdisc);
 			if (skb) {
 				qdisc_bstats_update(sch, skb);
-				sch->q.qlen--;
+				qdisc_qlen_dec(sch);
 				return skb;
 			}
 		}
diff --git a/net/sched/sch_netem.c b/net/sched/sch_netem.c
index 17a79fe2f0911d..db44cdb47dcef2 100644
--- a/net/sched/sch_netem.c
+++ b/net/sched/sch_netem.c
@@ -416,7 +416,7 @@ static void tfifo_enqueue(struct sk_buff *nskb, struct Qdisc *sch)
 		rb_insert_color(&nskb->rbnode, &q->t_root);
 	}
 	q->t_len++;
-	sch->q.qlen++;
+	qdisc_qlen_inc(sch);
 }
 
 /* netem can't properly corrupt a megapacket (like we get from GSO), so instead
@@ -750,19 +750,19 @@ static struct sk_buff *netem_dequeue(struct Qdisc *sch)
 					if (net_xmit_drop_count(err))
 						qdisc_qstats_drop(sch);
 					sch->qstats.backlog -= pkt_len;
-					sch->q.qlen--;
+					qdisc_qlen_dec(sch);
 					qdisc_tree_reduce_backlog(sch, 1, pkt_len);
 				}
 				goto tfifo_dequeue;
 			}
-			sch->q.qlen--;
+			qdisc_qlen_dec(sch);
 			goto deliver;
 		}
 
 		if (q->qdisc) {
 			skb = q->qdisc->ops->dequeue(q->qdisc);
 			if (skb) {
-				sch->q.qlen--;
+				qdisc_qlen_dec(sch);
 				goto deliver;
 			}
 		}
@@ -775,7 +775,7 @@ static struct sk_buff *netem_dequeue(struct Qdisc *sch)
 	if (q->qdisc) {
 		skb = q->qdisc->ops->dequeue(q->qdisc);
 		if (skb) {
-			sch->q.qlen--;
+			qdisc_qlen_dec(sch);
 			goto deliver;
 		}
 	}
diff --git a/net/sched/sch_prio.c b/net/sched/sch_prio.c
index 9e2b9a490db23d..fe42ae3d6b696b 100644
--- a/net/sched/sch_prio.c
+++ b/net/sched/sch_prio.c
@@ -86,7 +86,7 @@ prio_enqueue(struct sk_buff *skb, struct Qdisc *sch, struct sk_buff **to_free)
 	ret = qdisc_enqueue(skb, qdisc, to_free);
 	if (ret == NET_XMIT_SUCCESS) {
 		sch->qstats.backlog += len;
-		sch->q.qlen++;
+		qdisc_qlen_inc(sch);
 		return NET_XMIT_SUCCESS;
 	}
 	if (net_xmit_drop_count(ret))
@@ -119,7 +119,7 @@ static struct sk_buff *prio_dequeue(struct Qdisc *sch)
 		if (skb) {
 			qdisc_bstats_update(sch, skb);
 			qdisc_qstats_backlog_dec(sch, skb);
-			sch->q.qlen--;
+			qdisc_qlen_dec(sch);
 			return skb;
 		}
 	}
diff --git a/net/sched/sch_qfq.c b/net/sched/sch_qfq.c
index 699e45873f8614..195c434aae5f7e 100644
--- a/net/sched/sch_qfq.c
+++ b/net/sched/sch_qfq.c
@@ -1152,12 +1152,12 @@ static struct sk_buff *qfq_dequeue(struct Qdisc *sch)
 	if (!skb)
 		return NULL;
 
-	sch->q.qlen--;
+	qdisc_qlen_dec(sch);
 
 	skb = agg_dequeue(in_serv_agg, cl, len);
 
 	if (!skb) {
-		sch->q.qlen++;
+		qdisc_qlen_inc(sch);
 		return NULL;
 	}
 
@@ -1265,7 +1265,7 @@ static int qfq_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 
 	_bstats_update(&cl->bstats, len, gso_segs);
 	sch->qstats.backlog += len;
-	++sch->q.qlen;
+	qdisc_qlen_inc(sch);
 
 	agg = cl->agg;
 	/* if the class is active, then done here */
diff --git a/net/sched/sch_red.c b/net/sched/sch_red.c
index 4d0e44a2e7c664..0719590dfd73b6 100644
--- a/net/sched/sch_red.c
+++ b/net/sched/sch_red.c
@@ -139,7 +139,7 @@ static int red_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 	ret = qdisc_enqueue(skb, child, to_free);
 	if (likely(ret == NET_XMIT_SUCCESS)) {
 		sch->qstats.backlog += len;
-		sch->q.qlen++;
+		qdisc_qlen_inc(sch);
 	} else if (net_xmit_drop_count(ret)) {
 		WRITE_ONCE(q->stats.pdrop,
 			   q->stats.pdrop + 1);
@@ -166,7 +166,7 @@ static struct sk_buff *red_dequeue(struct Qdisc *sch)
 	if (skb) {
 		qdisc_bstats_update(sch, skb);
 		qdisc_qstats_backlog_dec(sch, skb);
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 	} else {
 		if (!red_is_idling(&q->vars))
 			red_start_of_idle_period(&q->vars);
diff --git a/net/sched/sch_sfb.c b/net/sched/sch_sfb.c
index d3ee8e5479b35e..efd9251c3add31 100644
--- a/net/sched/sch_sfb.c
+++ b/net/sched/sch_sfb.c
@@ -416,7 +416,7 @@ static int sfb_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 	ret = qdisc_enqueue(skb, child, to_free);
 	if (likely(ret == NET_XMIT_SUCCESS)) {
 		sch->qstats.backlog += len;
-		sch->q.qlen++;
+		qdisc_qlen_inc(sch);
 		increment_qlen(&cb, q);
 	} else if (net_xmit_drop_count(ret)) {
 		WRITE_ONCE(q->stats.childdrop,
@@ -446,7 +446,7 @@ static struct sk_buff *sfb_dequeue(struct Qdisc *sch)
 	if (skb) {
 		qdisc_bstats_update(sch, skb);
 		qdisc_qstats_backlog_dec(sch, skb);
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 		decrement_qlen(skb, q);
 	}
 
diff --git a/net/sched/sch_sfq.c b/net/sched/sch_sfq.c
index f39822babf88be..f9807ee2cf6c72 100644
--- a/net/sched/sch_sfq.c
+++ b/net/sched/sch_sfq.c
@@ -302,7 +302,7 @@ static unsigned int sfq_drop(struct Qdisc *sch, struct sk_buff **to_free)
 		len = qdisc_pkt_len(skb);
 		WRITE_ONCE(slot->backlog, slot->backlog - len);
 		sfq_dec(q, x);
-		sch->q.qlen--;
+		qdisc_qlen_dec(sch);
 		qdisc_qstats_backlog_dec(sch, skb);
 		qdisc_drop_reason(skb, sch, to_free, QDISC_DROP_OVERLIMIT);
 		return len;
@@ -456,7 +456,8 @@ sfq_enqueue(struct sk_buff *skb, struct Qdisc *sch, struct sk_buff **to_free)
 		/* We could use a bigger initial quantum for new flows */
 		WRITE_ONCE(slot->allot, q->quantum);
 	}
-	if (++sch->q.qlen <= q->limit)
+	qdisc_qlen_inc(sch);
+	if (sch->q.qlen <= q->limit)
 		return NET_XMIT_SUCCESS;
 
 	qlen = slot->qlen;
@@ -497,7 +498,7 @@ sfq_dequeue(struct Qdisc *sch)
 	skb = slot_dequeue_head(slot);
 	sfq_dec(q, a);
 	qdisc_bstats_update(sch, skb);
-	sch->q.qlen--;
+	qdisc_qlen_dec(sch);
 	qdisc_qstats_backlog_dec(sch, skb);
 	WRITE_ONCE(slot->backlog, slot->backlog - qdisc_pkt_len(skb));
 	/* Is the slot empty? */
@@ -596,7 +597,7 @@ static void sfq_rehash(struct Qdisc *sch)
 			WRITE_ONCE(slot->allot, q->quantum);
 		}
 	}
-	sch->q.qlen -= dropped;
+	WRITE_ONCE(sch->q.qlen, sch->q.qlen - dropped);
 	qdisc_tree_reduce_backlog(sch, dropped, drop_len);
 }
 
diff --git a/net/sched/sch_skbprio.c b/net/sched/sch_skbprio.c
index f485f62ab721ab..52abfb4015a364 100644
--- a/net/sched/sch_skbprio.c
+++ b/net/sched/sch_skbprio.c
@@ -93,7 +93,7 @@ static int skbprio_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 		if (prio < q->lowest_prio)
 			q->lowest_prio = prio;
 
-		sch->q.qlen++;
+		qdisc_qlen_inc(sch);
 		return NET_XMIT_SUCCESS;
 	}
 
@@ -145,7 +145,7 @@ static struct sk_buff *skbprio_dequeue(struct Qdisc *sch)
 	if (unlikely(!skb))
 		return NULL;
 
-	sch->q.qlen--;
+	qdisc_qlen_dec(sch);
 	qdisc_qstats_backlog_dec(sch, skb);
 	qdisc_bstats_update(sch, skb);
 
diff --git a/net/sched/sch_taprio.c b/net/sched/sch_taprio.c
index 45245157e00a69..06d93d92691870 100644
--- a/net/sched/sch_taprio.c
+++ b/net/sched/sch_taprio.c
@@ -574,7 +574,7 @@ static int taprio_enqueue_one(struct sk_buff *skb, struct Qdisc *sch,
 	}
 
 	qdisc_qstats_backlog_inc(sch, skb);
-	sch->q.qlen++;
+	qdisc_qlen_inc(sch);
 
 	return qdisc_enqueue(skb, child, to_free);
 }
@@ -755,7 +755,7 @@ static struct sk_buff *taprio_dequeue_from_txq(struct Qdisc *sch, int txq,
 
 	qdisc_bstats_update(sch, skb);
 	qdisc_qstats_backlog_dec(sch, skb);
-	sch->q.qlen--;
+	qdisc_qlen_dec(sch);
 
 	return skb;
 }
diff --git a/net/sched/sch_tbf.c b/net/sched/sch_tbf.c
index f2340164f579a2..25edf11a7d671f 100644
--- a/net/sched/sch_tbf.c
+++ b/net/sched/sch_tbf.c
@@ -231,7 +231,7 @@ static int tbf_segment(struct sk_buff *skb, struct Qdisc *sch,
 			len += seg_len;
 		}
 	}
-	sch->q.qlen += nb;
+	WRITE_ONCE(sch->q.qlen, sch->q.qlen + nb);
 	sch->qstats.backlog += len;
 	if (nb > 0) {
 		qdisc_tree_reduce_backlog(sch, 1 - nb, prev_len - len);
@@ -264,7 +264,7 @@ static int tbf_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 	}
 
 	sch->qstats.backlog += len;
-	sch->q.qlen++;
+	qdisc_qlen_inc(sch);
 	return NET_XMIT_SUCCESS;
 }
 
@@ -309,7 +309,7 @@ static struct sk_buff *tbf_dequeue(struct Qdisc *sch)
 			q->tokens = toks;
 			q->ptokens = ptoks;
 			qdisc_qstats_backlog_dec(sch, skb);
-			sch->q.qlen--;
+			qdisc_qlen_dec(sch);
 			qdisc_bstats_update(sch, skb);
 			return skb;
 		}
diff --git a/net/sched/sch_teql.c b/net/sched/sch_teql.c
index ec4039a201a2c2..e7bbc9e5174d0e 100644
--- a/net/sched/sch_teql.c
+++ b/net/sched/sch_teql.c
@@ -107,7 +107,7 @@ teql_dequeue(struct Qdisc *sch)
 	} else {
 		qdisc_bstats_update(sch, skb);
 	}
-	sch->q.qlen = dat->q.qlen + q->q.qlen;
+	WRITE_ONCE(sch->q.qlen, dat->q.qlen + READ_ONCE(q->q.qlen));
 	return skb;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0217/2077] net/sched: sch_dualpi2: annotate data-races in dualpi2_dump_stats()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (215 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0216/2077] net/sched: add qdisc_qlen_inc() and qdisc_qlen_dec() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0218/2077] net/sched: sch_htb: do not change sch->flags in htb_dump() Greg Kroah-Hartman
                   ` (780 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Vineet Agarwal,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 5658bddaca41417331d2ac4b24a9b159a839ab87 ]

dualpi2_dump_stats() runs without qdisc lock held.

Add missing READ_ONCE()/WRITE_ONCE() annotations.

Fixes: d4de8bffbef4 ("sched: Dump configuration and statistics of dualpi2 qdisc")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Vineet Agarwal <agarwal.vineet2006@gmail.com>
Link: https://patch.msgid.link/20260514114713.4134674-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/sch_dualpi2.c | 68 ++++++++++++++++++++---------------------
 1 file changed, 34 insertions(+), 34 deletions(-)

diff --git a/net/sched/sch_dualpi2.c b/net/sched/sch_dualpi2.c
index 9a6020238427c2..b81a922f5e4684 100644
--- a/net/sched/sch_dualpi2.c
+++ b/net/sched/sch_dualpi2.c
@@ -190,7 +190,7 @@ static bool skb_apply_step(struct sk_buff *skb, struct dualpi2_sched_data *q)
 static bool dualpi2_mark(struct dualpi2_sched_data *q, struct sk_buff *skb)
 {
 	if (INET_ECN_set_ce(skb)) {
-		q->ecn_mark++;
+		WRITE_ONCE(q->ecn_mark, q->ecn_mark + 1);
 		return true;
 	}
 	return false;
@@ -198,7 +198,7 @@ static bool dualpi2_mark(struct dualpi2_sched_data *q, struct sk_buff *skb)
 
 static void dualpi2_reset_c_protection(struct dualpi2_sched_data *q)
 {
-	q->c_protection_credit = q->c_protection_init;
+	WRITE_ONCE(q->c_protection_credit, q->c_protection_init);
 }
 
 /* This computes the initial credit value and WRR weight for the L queue (wl)
@@ -403,12 +403,12 @@ static int dualpi2_enqueue_skb(struct sk_buff *skb, struct Qdisc *sch,
 
 	cb = dualpi2_skb_cb(skb);
 	cb->ts = ktime_get_ns();
-	q->memory_used += skb->truesize;
+	WRITE_ONCE(q->memory_used, q->memory_used + skb->truesize);
 	if (q->memory_used > q->max_memory_used)
-		q->max_memory_used = q->memory_used;
+		WRITE_ONCE(q->max_memory_used, q->memory_used);
 
 	if (qdisc_qlen(sch) > q->maxq)
-		q->maxq = qdisc_qlen(sch);
+		WRITE_ONCE(q->maxq, qdisc_qlen(sch));
 
 	if (skb_in_l_queue(skb)) {
 		/* Apply step thresh if skb is L4S && L-queue len >= min_qlen */
@@ -417,14 +417,14 @@ static int dualpi2_enqueue_skb(struct sk_buff *skb, struct Qdisc *sch,
 		/* Keep the overall qdisc stats consistent */
 		qdisc_qlen_inc(sch);
 		qdisc_qstats_backlog_inc(sch, skb);
-		++q->packets_in_l;
+		WRITE_ONCE(q->packets_in_l, q->packets_in_l + 1);
 		if (!q->l_head_ts)
-			q->l_head_ts = cb->ts;
+			WRITE_ONCE(q->l_head_ts, cb->ts);
 		return qdisc_enqueue_tail(skb, q->l_queue);
 	}
-	++q->packets_in_c;
+	WRITE_ONCE(q->packets_in_c, q->packets_in_c + 1);
 	if (!q->c_head_ts)
-		q->c_head_ts = cb->ts;
+		WRITE_ONCE(q->c_head_ts, cb->ts);
 	return qdisc_enqueue_tail(skb, sch);
 }
 
@@ -530,17 +530,16 @@ static struct sk_buff *dequeue_packet(struct Qdisc *sch,
 
 		/* Keep the global queue size consistent */
 		qdisc_qlen_dec(sch);
-		q->memory_used -= skb->truesize;
 	} else if (c_len) {
 		skb = __qdisc_dequeue_head(&sch->q);
 		WRITE_ONCE(q->c_head_ts, head_enqueue_time(sch));
 		if (qdisc_qlen(q->l_queue))
 			*credit_change = ~((s32)q->c_protection_wl) + 1;
-		q->memory_used -= skb->truesize;
 	} else {
 		dualpi2_reset_c_protection(q);
 		return NULL;
 	}
+	WRITE_ONCE(q->memory_used, q->memory_used - skb->truesize);
 	*credit_change *= qdisc_pkt_len(skb);
 	qdisc_qstats_backlog_dec(sch, skb);
 	return skb;
@@ -563,7 +562,7 @@ static int do_step_aqm(struct dualpi2_sched_data *q, struct sk_buff *skb,
 		}
 
 		if (dualpi2_mark(q, skb))
-			++q->step_marks;
+			WRITE_ONCE(q->step_marks, q->step_marks + 1);
 	}
 	qdisc_bstats_update(q->l_queue, skb);
 	return 0;
@@ -599,7 +598,8 @@ static struct sk_buff *dualpi2_qdisc_dequeue(struct Qdisc *sch)
 			continue;
 		}
 
-		q->c_protection_credit += credit_change;
+		WRITE_ONCE(q->c_protection_credit,
+			   q->c_protection_credit + credit_change);
 		qdisc_bstats_update(sch, skb);
 		break;
 	}
@@ -875,7 +875,7 @@ static int dualpi2_change(struct Qdisc *sch, struct nlattr *opt,
 				WARN_ON_ONCE(1);
 				break;
 			}
-			q->memory_used -= skb->truesize;
+			WRITE_ONCE(q->memory_used, q->memory_used - skb->truesize);
 			rtnl_qdisc_drop(skb, sch);
 		} else if (qdisc_qlen(q->l_queue)) {
 			skb = qdisc_dequeue_internal(q->l_queue, true);
@@ -889,7 +889,7 @@ static int dualpi2_change(struct Qdisc *sch, struct nlattr *opt,
 			 */
 			qdisc_qlen_dec(sch);
 			qdisc_qstats_backlog_dec(sch, skb);
-			q->memory_used -= skb->truesize;
+			WRITE_ONCE(q->memory_used, q->memory_used - skb->truesize);
 			rtnl_qdisc_drop(skb, q->l_queue);
 			qdisc_qstats_drop(sch);
 		} else {
@@ -1045,15 +1045,15 @@ static int dualpi2_dump_stats(struct Qdisc *sch, struct gnet_dump *d)
 	struct dualpi2_sched_data *q = qdisc_priv(sch);
 	struct tc_dualpi2_xstats st = {
 		.prob			= READ_ONCE(q->pi2_prob),
-		.packets_in_c		= q->packets_in_c,
-		.packets_in_l		= q->packets_in_l,
-		.maxq			= q->maxq,
-		.ecn_mark		= q->ecn_mark,
-		.credit			= q->c_protection_credit,
-		.step_marks		= q->step_marks,
-		.memory_used		= q->memory_used,
-		.max_memory_used	= q->max_memory_used,
-		.memory_limit		= q->memory_limit,
+		.packets_in_c		= READ_ONCE(q->packets_in_c),
+		.packets_in_l		= READ_ONCE(q->packets_in_l),
+		.maxq			= READ_ONCE(q->maxq),
+		.ecn_mark		= READ_ONCE(q->ecn_mark),
+		.credit			= READ_ONCE(q->c_protection_credit),
+		.step_marks		= READ_ONCE(q->step_marks),
+		.memory_used		= READ_ONCE(q->memory_used),
+		.max_memory_used	= READ_ONCE(q->max_memory_used),
+		.memory_limit		= READ_ONCE(q->memory_limit),
 	};
 	u64 qc, ql;
 
@@ -1073,16 +1073,16 @@ static void dualpi2_reset(struct Qdisc *sch)
 
 	qdisc_reset_queue(sch);
 	qdisc_reset_queue(q->l_queue);
-	q->c_head_ts = 0;
-	q->l_head_ts = 0;
-	q->pi2_prob = 0;
-	q->packets_in_c = 0;
-	q->packets_in_l = 0;
-	q->maxq = 0;
-	q->ecn_mark = 0;
-	q->step_marks = 0;
-	q->memory_used = 0;
-	q->max_memory_used = 0;
+	WRITE_ONCE(q->c_head_ts, 0);
+	WRITE_ONCE(q->l_head_ts, 0);
+	WRITE_ONCE(q->pi2_prob, 0);
+	WRITE_ONCE(q->packets_in_c, 0);
+	WRITE_ONCE(q->packets_in_l, 0);
+	WRITE_ONCE(q->maxq, 0);
+	WRITE_ONCE(q->ecn_mark, 0);
+	WRITE_ONCE(q->step_marks, 0);
+	WRITE_ONCE(q->memory_used, 0);
+	WRITE_ONCE(q->max_memory_used, 0);
 	dualpi2_reset_c_protection(q);
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0218/2077] net/sched: sch_htb: do not change sch->flags in htb_dump()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (216 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0217/2077] net/sched: sch_dualpi2: annotate data-races in dualpi2_dump_stats() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0219/2077] net/sched: sch_htb: annotate data-races (I) Greg Kroah-Hartman
                   ` (779 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 9b949fa69129e4b694ed11ee3be6d6edd4a9b8f4 ]

htb_dump() runs without holding qdisc spinlock.

It is illegal to touch sch->flags with non locked RMW,
as concurrent readers might see intermediate wrong values.

Set TCQ_F_OFFLOADED in control path (htb_init()) instead.

Fixes: d03b195b5aa0 ("sch_htb: Hierarchical QoS hardware offload")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260514095935.3926276-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/sch_htb.c | 6 +-----
 1 file changed, 1 insertion(+), 5 deletions(-)

diff --git a/net/sched/sch_htb.c b/net/sched/sch_htb.c
index c22ccd8eae8c73..f94a44fad4e9d9 100644
--- a/net/sched/sch_htb.c
+++ b/net/sched/sch_htb.c
@@ -1147,6 +1147,7 @@ static int htb_init(struct Qdisc *sch, struct nlattr *opt,
 	 * parts (especially calling ndo_setup_tc) on errors.
 	 */
 	q->offload = true;
+	sch->flags |= TCQ_F_OFFLOADED;
 
 	return 0;
 }
@@ -1207,11 +1208,6 @@ static int htb_dump(struct Qdisc *sch, struct sk_buff *skb)
 	struct nlattr *nest;
 	struct tc_htb_glob gopt;
 
-	if (q->offload)
-		sch->flags |= TCQ_F_OFFLOADED;
-	else
-		sch->flags &= ~TCQ_F_OFFLOADED;
-
 	sch->qstats.overlimits = q->overlimits;
 	/* Its safe to not acquire qdisc lock. As we hold RTNL,
 	 * no change can happen on the qdisc parameters.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0219/2077] net/sched: sch_htb: annotate data-races (I)
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (217 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0218/2077] net/sched: sch_htb: do not change sch->flags in htb_dump() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0220/2077] ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD Greg Kroah-Hartman
                   ` (778 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit e54c33503bf7cebb1c1790251ce90f1252678081 ]

htb_dump() runs without holding qdisc spinlock.

Add missing READ_ONCE()/WRITE_ONCE() annotations around
q->overlimits and q->direct_pkts.

Fixes: edb09eb17ed8 ("net: sched: do not acquire qdisc spinlock in qdisc/class stats dump")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260514095935.3926276-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/sch_htb.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/net/sched/sch_htb.c b/net/sched/sch_htb.c
index f94a44fad4e9d9..ccabafed3fe44a 100644
--- a/net/sched/sch_htb.c
+++ b/net/sched/sch_htb.c
@@ -568,7 +568,7 @@ htb_change_class_mode(struct htb_sched *q, struct htb_class *cl, s64 *diff)
 
 	if (new_mode == HTB_CANT_SEND) {
 		cl->overlimits++;
-		q->overlimits++;
+		WRITE_ONCE(q->overlimits, q->overlimits + 1);
 	}
 
 	if (cl->prio_activity) {	/* not necessary: speed optimization */
@@ -628,7 +628,7 @@ static int htb_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 		/* enqueue to helper queue */
 		if (q->direct_queue.qlen < q->direct_qlen) {
 			__qdisc_enqueue_tail(skb, &q->direct_queue);
-			q->direct_pkts++;
+			WRITE_ONCE(q->direct_pkts, q->direct_pkts + 1);
 		} else {
 			return qdisc_drop(skb, sch, to_free);
 		}
@@ -1208,12 +1208,12 @@ static int htb_dump(struct Qdisc *sch, struct sk_buff *skb)
 	struct nlattr *nest;
 	struct tc_htb_glob gopt;
 
-	sch->qstats.overlimits = q->overlimits;
+	sch->qstats.overlimits = READ_ONCE(q->overlimits);
 	/* Its safe to not acquire qdisc lock. As we hold RTNL,
 	 * no change can happen on the qdisc parameters.
 	 */
 
-	gopt.direct_pkts = q->direct_pkts;
+	gopt.direct_pkts = READ_ONCE(q->direct_pkts);
 	gopt.version = HTB_VER;
 	gopt.rate2quantum = q->rate2quantum;
 	gopt.defcls = q->defcls;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0220/2077] ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (218 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0219/2077] net/sched: sch_htb: annotate data-races (I) Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0221/2077] IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier Greg Kroah-Hartman
                   ` (777 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Linmao Li, Ido Schimmel,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Linmao Li <lilinmao@kylinos.cn>

[ Upstream commit 627ac78f2741e2ebd2225e2e953b6964a8a9182f ]

addrconf_dad_failure() transitions ifp->state from DAD to POSTDAD
via addrconf_dad_end(), which drops ifp->lock on return.  The lock
is re-acquired after net_info_ratelimited().  A concurrent
ipv6_del_addr() can take the lock in that window, set ifp->state
to DEAD and run list_del_rcu(&ifp->if_list).

addrconf_dad_failure() then overwrites DEAD with ERRDAD at errdad:
and schedules a new dad_work.  The work calls ipv6_del_addr()
again, hitting the already-poisoned list entry:

  general protection fault: 0000 [#1] SMP NOPTI
  CPU: 4 PID: 217 Comm: kworker/4:1
  Workqueue: ipv6_addrconf addrconf_dad_work
  RIP: 0010:ipv6_del_addr+0xe9/0x280
  RAX: dead000000000122
  Call Trace:
   addrconf_dad_stop+0x113/0x140
   addrconf_dad_work+0x28c/0x430
   process_one_work+0x1eb/0x3b0
   worker_thread+0x4d/0x400
   kthread+0x104/0x140
   ret_from_fork+0x35/0x40

Fold the addrconf_dad_end() logic into addrconf_dad_failure() under
a single ifp->lock critical section.  The STABLE_PRIVACY branch
temporarily drops ifp->lock around address regeneration, so at
lock_errdad: verify the state is still POSTDAD before transitioning
to ERRDAD; bail out otherwise to avoid overwriting a state set by
another path while the lock was released.

Fixes: c15b1ccadb32 ("ipv6: move DAD and addrconf_verify processing to workqueue")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260513025509.3776405-1-lilinmao@kylinos.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/ipv6/addrconf.c | 13 ++++++++++---
 1 file changed, 10 insertions(+), 3 deletions(-)

diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
index c9e5d3e48ab984..7953f5653451b5 100644
--- a/net/ipv6/addrconf.c
+++ b/net/ipv6/addrconf.c
@@ -2168,16 +2168,18 @@ void addrconf_dad_failure(struct sk_buff *skb, struct inet6_ifaddr *ifp)
 	struct net *net = dev_net(idev->dev);
 	int max_addresses;
 
-	if (addrconf_dad_end(ifp)) {
+	spin_lock_bh(&ifp->lock);
+
+	if (ifp->state != INET6_IFADDR_STATE_DAD) {
+		spin_unlock_bh(&ifp->lock);
 		in6_ifa_put(ifp);
 		return;
 	}
+	ifp->state = INET6_IFADDR_STATE_POSTDAD;
 
 	net_info_ratelimited("%s: IPv6 duplicate address %pI6c used by %pM detected!\n",
 			     ifp->idev->dev->name, &ifp->addr, eth_hdr(skb)->h_source);
 
-	spin_lock_bh(&ifp->lock);
-
 	if (ifp->flags & IFA_F_STABLE_PRIVACY) {
 		struct in6_addr new_addr;
 		struct inet6_ifaddr *ifp2;
@@ -2225,6 +2227,11 @@ void addrconf_dad_failure(struct sk_buff *skb, struct inet6_ifaddr *ifp)
 		in6_ifa_put(ifp2);
 lock_errdad:
 		spin_lock_bh(&ifp->lock);
+		if (ifp->state != INET6_IFADDR_STATE_POSTDAD) {
+			spin_unlock_bh(&ifp->lock);
+			in6_ifa_put(ifp);
+			return;
+		}
 	}
 
 errdad:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0221/2077] IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (219 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0220/2077] ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0222/2077] RDMA/hns: Fix arithmetic overflow in calc_hem_config() Greg Kroah-Hartman
                   ` (776 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Prathamesh Deshpande,
	Leon Romanovsky, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Prathamesh Deshpande <prathameshdeshpande7@gmail.com>

[ Upstream commit e79389115b9d27287ff6230a9750675106ed7668 ]

mlx5_ib_alloc_transport_domain() allocates a transport domain and then
may fail in mlx5_ib_enable_lb(). In that case, the allocated TD is leaked.

Fix this by deallocating the TD when mlx5_ib_enable_lb() returns an
error. Also return 0 explicitly in the no-loopback-capability success
branch, and move dev->lb.mutex initialization to mlx5_ib_stage_init_init().

Fixes: 146d2f1af324 ("IB/mlx5: Allocate a Transport Domain for each ucontext")
Signed-off-by: Prathamesh Deshpande <prathameshdeshpande7@gmail.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/main.c | 15 ++++++++-------
 1 file changed, 8 insertions(+), 7 deletions(-)

diff --git a/drivers/infiniband/hw/mlx5/main.c b/drivers/infiniband/hw/mlx5/main.c
index 61078281953d6c..aa2eb64ecf15e6 100644
--- a/drivers/infiniband/hw/mlx5/main.c
+++ b/drivers/infiniband/hw/mlx5/main.c
@@ -2069,9 +2069,13 @@ static int mlx5_ib_alloc_transport_domain(struct mlx5_ib_dev *dev, u32 *tdn,
 	if ((MLX5_CAP_GEN(dev->mdev, port_type) != MLX5_CAP_PORT_TYPE_ETH) ||
 	    (!MLX5_CAP_GEN(dev->mdev, disable_local_lb_uc) &&
 	     !MLX5_CAP_GEN(dev->mdev, disable_local_lb_mc)))
-		return err;
+		return 0;
+
+	err = mlx5_ib_enable_lb(dev, true, false);
+	if (err)
+		mlx5_cmd_dealloc_transport_domain(dev->mdev, *tdn, uid);
 
-	return mlx5_ib_enable_lb(dev, true, false);
+	return err;
 }
 
 static void mlx5_ib_dealloc_transport_domain(struct mlx5_ib_dev *dev, u32 tdn,
@@ -4488,6 +4492,8 @@ static int mlx5_ib_stage_init_init(struct mlx5_ib_dev *dev)
 		dev->port[i].roce.last_port_state = IB_PORT_DOWN;
 	}
 
+	mutex_init(&dev->lb.mutex);
+
 	err = mlx5r_cmd_query_special_mkeys(dev);
 	if (err)
 		return err;
@@ -4788,11 +4794,6 @@ static int mlx5_ib_stage_caps_init(struct mlx5_ib_dev *dev)
 	if (err)
 		return err;
 
-	if ((MLX5_CAP_GEN(dev->mdev, port_type) == MLX5_CAP_PORT_TYPE_ETH) &&
-	    (MLX5_CAP_GEN(dev->mdev, disable_local_lb_uc) ||
-	     MLX5_CAP_GEN(dev->mdev, disable_local_lb_mc)))
-		mutex_init(&dev->lb.mutex);
-
 	if (MLX5_CAP_GEN_64(dev->mdev, general_obj_types) &
 			MLX5_GENERAL_OBJ_TYPES_CAP_VIRTIO_NET_Q) {
 		err = mlx5_ib_init_var_region(dev);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0222/2077] RDMA/hns: Fix arithmetic overflow in calc_hem_config()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (220 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0221/2077] IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0223/2077] RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure Greg Kroah-Hartman
                   ` (775 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alexander Chesnokov, Leon Romanovsky,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>

[ Upstream commit a38e4410af9ad8b7ad2217254da06cd4dc21f0ed ]

If bt_num is 3 or 2, then the expressions like
l0_idx * chunk_ba_num + l1_idx are computed in 32-bit
arithmetic before being assigned to a u64 index field,
which can lead to overflow.

Cast the first operand to u64 to ensure the arithmetic
is performed in 64-bit.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: 2f49de21f3e9 ("RDMA/hns: Optimize mhop get flow for multi-hop addressing")
Signed-off-by: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
Link: https://patch.msgid.link/20260413091527.39990-1-Alexander.Chesnokov@kaspersky.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/hns/hns_roce_hem.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/infiniband/hw/hns/hns_roce_hem.c b/drivers/infiniband/hw/hns/hns_roce_hem.c
index e7c9e30ad2d8b4..ccb40f8a48b726 100644
--- a/drivers/infiniband/hw/hns/hns_roce_hem.c
+++ b/drivers/infiniband/hw/hns/hns_roce_hem.c
@@ -314,14 +314,14 @@ static int calc_hem_config(struct hns_roce_dev *hr_dev,
 	bt_num = hns_roce_get_bt_num(table->type, mhop->hop_num);
 	switch (bt_num) {
 	case 3:
-		index->l1 = l0_idx * chunk_ba_num + l1_idx;
+		index->l1 = (u64)l0_idx * chunk_ba_num + l1_idx;
 		index->l0 = l0_idx;
-		index->buf = l0_idx * chunk_ba_num * chunk_ba_num +
-			     l1_idx * chunk_ba_num + l2_idx;
+		index->buf = (u64)l0_idx * chunk_ba_num * chunk_ba_num +
+					 (u64)l1_idx * chunk_ba_num + l2_idx;
 		break;
 	case 2:
 		index->l0 = l0_idx;
-		index->buf = l0_idx * chunk_ba_num + l1_idx;
+		index->buf = (u64)l0_idx * chunk_ba_num + l1_idx;
 		break;
 	case 1:
 		index->buf = l0_idx;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0223/2077] RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (221 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0222/2077] RDMA/hns: Fix arithmetic overflow in calc_hem_config() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0224/2077] RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference Greg Kroah-Hartman
                   ` (774 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Prathamesh Deshpande,
	Leon Romanovsky, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Prathamesh Deshpande <prathameshdeshpande7@gmail.com>

[ Upstream commit 1eae35b37923cb71b0cb5136d00671440d488b9f ]

mlx5r_umr_update_xlt() allocates and DMA maps an XLT buffer with
mlx5r_umr_create_xlt(). The buffer is released by the common cleanup path
through mlx5r_umr_unmap_free_xlt().

After mlx5_odp_populate_xlt() became fallible, its error path returned
directly and skipped that cleanup. This leaks the XLT DMA mapping and
buffer. If the emergency XLT page was used, it also leaves
xlt_emergency_page_mutex locked.

Break out of the loop so execution falls through the existing cleanup path.

Fixes: 1efe8c0670d6 ("RDMA/core: Convert UMEM ODP DMA mapping to caching IOVA and page linkage")
Signed-off-by: Prathamesh Deshpande <prathameshdeshpande7@gmail.com>
Link: https://patch.msgid.link/20260426132356.22264-1-prathameshdeshpande7@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/umr.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/mlx5/umr.c b/drivers/infiniband/hw/mlx5/umr.c
index f2139474be3751..688d5246f284e8 100644
--- a/drivers/infiniband/hw/mlx5/umr.c
+++ b/drivers/infiniband/hw/mlx5/umr.c
@@ -915,7 +915,7 @@ int mlx5r_umr_update_xlt(struct mlx5_ib_mr *mr, u64 idx, int npages,
 		 */
 		err = mlx5_odp_populate_xlt(xlt, idx, npages, mr, flags);
 		if (err)
-			return err;
+			break;
 		dma_sync_single_for_device(ddev, sg.addr, sg.length,
 					   DMA_TO_DEVICE);
 		sg.length = ALIGN(size_to_map, MLX5_UMR_FLEX_ALIGNMENT);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0224/2077] RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (222 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0223/2077] RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0225/2077] RDMA/srpt: fix integer overflow in immediate data length check Greg Kroah-Hartman
                   ` (773 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Prathamesh Deshpande, Yishai Hadas,
	Leon Romanovsky, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Prathamesh Deshpande <prathameshdeshpande7@gmail.com>

[ Upstream commit 43f8f7946814c8e5f464518246fdbc69b6e32326 ]

MLX5_IB_METHOD_DEVX_SUBSCRIBE_EVENT() links event_sub into sub_list
before initializing the fields used by the shared error path.

If eventfd_ctx_fdget() then fails, the unwind path dereferences
event_sub->ev_file in uverbs_uobject_put() and calls
subscribe_event_xa_dealloc() with an unset xa_key_level1.

subscribe_event_xa_alloc() creates the XA entry exactly once for a given
key_level1, on the first occurrence of that key. The unwind path must
therefore call subscribe_event_xa_dealloc() exactly once for it as well.

Enforce that by adding devx_key_in_sub_list() and calling
subscribe_event_xa_dealloc() only when the last matching pending entry is
being cleaned up.

Fixes: 759738537142 ("IB/mlx5: Enable subscription for device events over DEVX")
Signed-off-by: Prathamesh Deshpande <prathameshdeshpande7@gmail.com>
Link: https://patch.msgid.link/20260428224319.37682-1-prathameshdeshpande7@gmail.com
Reviewed-by: Yishai Hadas <yishaih@nvidia.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/devx.c | 30 +++++++++++++++++++++++-------
 1 file changed, 23 insertions(+), 7 deletions(-)

diff --git a/drivers/infiniband/hw/mlx5/devx.c b/drivers/infiniband/hw/mlx5/devx.c
index 645ebcc0832d7f..c2ae5a14047115 100644
--- a/drivers/infiniband/hw/mlx5/devx.c
+++ b/drivers/infiniband/hw/mlx5/devx.c
@@ -1913,6 +1913,17 @@ static int UVERBS_HANDLER(MLX5_IB_METHOD_DEVX_OBJ_ASYNC_QUERY)(
 	return err;
 }
 
+static bool devx_key_in_sub_list(struct list_head *list, u32 key_level1)
+{
+	struct devx_event_subscription *s;
+
+	list_for_each_entry(s, list, event_list)
+		if (s->xa_key_level1 == key_level1)
+			return true;
+
+	return false;
+}
+
 static void
 subscribe_event_xa_dealloc(struct mlx5_devx_event_table *devx_event_table,
 			   u32 key_level1,
@@ -2160,10 +2171,17 @@ static int UVERBS_HANDLER(MLX5_IB_METHOD_DEVX_SUBSCRIBE_EVENT)(
 
 		event_sub = kzalloc_obj(*event_sub);
 		if (!event_sub) {
+			if (!devx_key_in_sub_list(&sub_list, key_level1))
+				subscribe_event_xa_dealloc(devx_event_table,
+							   key_level1,
+							   obj,
+							   obj_id);
 			err = -ENOMEM;
 			goto err;
 		}
 
+		event_sub->ev_file = ev_file;
+		event_sub->xa_key_level1 = key_level1;
 		list_add_tail(&event_sub->event_list, &sub_list);
 		uverbs_uobject_get(&ev_file->uobj);
 		if (use_eventfd) {
@@ -2178,9 +2196,6 @@ static int UVERBS_HANDLER(MLX5_IB_METHOD_DEVX_SUBSCRIBE_EVENT)(
 		}
 
 		event_sub->cookie = cookie;
-		event_sub->ev_file = ev_file;
-		/* May be needed upon cleanup the devx object/subscription */
-		event_sub->xa_key_level1 = key_level1;
 		event_sub->xa_key_level2 = obj_id;
 		INIT_LIST_HEAD(&event_sub->obj_list);
 	}
@@ -2225,10 +2240,11 @@ static int UVERBS_HANDLER(MLX5_IB_METHOD_DEVX_SUBSCRIBE_EVENT)(
 	list_for_each_entry_safe(event_sub, tmp_sub, &sub_list, event_list) {
 		list_del(&event_sub->event_list);
 
-		subscribe_event_xa_dealloc(devx_event_table,
-					   event_sub->xa_key_level1,
-					   obj,
-					   obj_id);
+		if (!devx_key_in_sub_list(&sub_list, event_sub->xa_key_level1))
+			subscribe_event_xa_dealloc(devx_event_table,
+						   event_sub->xa_key_level1,
+						   obj,
+						   obj_id);
 
 		if (event_sub->eventfd)
 			eventfd_ctx_put(event_sub->eventfd);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0225/2077] RDMA/srpt: fix integer overflow in immediate data length check
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (223 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0224/2077] RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0226/2077] RDMA/hns: Initialize seqfile before creating file Greg Kroah-Hartman
                   ` (772 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Carlos Bilbao (Lambda),
	Sara Venkatesh, Bart Van Assche, Leon Romanovsky, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sara Venkatesh <sarajvenkatesh@gmail.com>

[ Upstream commit eb4ecdf631fe00e8020bf461503cb9b7017ed796 ]

imm_buf->len is a user-controlled uint32_t received from the network.
Adding it to imm_data_offset without overflow checking allows a
malicious initiator to send len=0xFFFFFFFF, causing req_size to wrap
around to a small value, bypassing the bounds check, and subsequently
passing a ~4GB length to sg_init_one().

Use check_add_overflow() to detect wrapping before the comparison.

Fixes: 5dabcd0456d7 ("RDMA/srpt: Add support for immediate data")
Reported-by: Carlos Bilbao (Lambda) <carlos.bilbao@kernel.org>
Signed-off-by: Sara Venkatesh <sarajvenkatesh@gmail.com>
Link: https://patch.msgid.link/20260504080036.3482415-1-sarajvenkatesh@gmail.com
Reviewed-by: Carlos Bilbao (Lambda) <carlos.bilbao@kernel.org>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/ulp/srpt/ib_srpt.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/infiniband/ulp/srpt/ib_srpt.c b/drivers/infiniband/ulp/srpt/ib_srpt.c
index 9aec5d80117f1f..f66cfd70c2636a 100644
--- a/drivers/infiniband/ulp/srpt/ib_srpt.c
+++ b/drivers/infiniband/ulp/srpt/ib_srpt.c
@@ -1129,9 +1129,10 @@ static int srpt_get_desc_tbl(struct srpt_recv_ioctx *recv_ioctx,
 		struct srp_imm_buf *imm_buf = srpt_get_desc_buf(srp_cmd);
 		void *data = (void *)srp_cmd + imm_data_offset;
 		uint32_t len = be32_to_cpu(imm_buf->len);
-		uint32_t req_size = imm_data_offset + len;
+		uint32_t req_size;
 
-		if (req_size > srp_max_req_size) {
+		if (check_add_overflow((uint32_t)imm_data_offset, len, &req_size) ||
+		    req_size > srp_max_req_size) {
 			pr_err("Immediate data (length %d + %d) exceeds request size %d\n",
 			       imm_data_offset, len, srp_max_req_size);
 			return -EINVAL;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0226/2077] RDMA/hns: Initialize seqfile before creating file
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (224 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0225/2077] RDMA/srpt: fix integer overflow in immediate data length check Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0227/2077] tools/rtla: Fix --dump-tasks usage in timerlat Greg Kroah-Hartman
                   ` (771 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Junxian Huang, Leon Romanovsky,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Junxian Huang <huangjunxian6@hisilicon.com>

[ Upstream commit b4070770506ff516e21b4923afdaf7eb5da0e150 ]

The debugfs file was created before seq->read and seq->data were set,
leaving a small window where userspace could access an uninitialized
seqfile.

Move debugfs_create_file() after the assignments to avoid this issue.
Also, inline the original init_debugfs_seqfile() since it is not a
really necessary helper.

Fixes: ca7ad04cd5d2 ("RDMA/hns: Add debugfs to hns RoCE")
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
Link: https://patch.msgid.link/20260507012148.1079712-2-huangjunxian6@hisilicon.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/hns/hns_roce_debugfs.c | 19 +++++--------------
 1 file changed, 5 insertions(+), 14 deletions(-)

diff --git a/drivers/infiniband/hw/hns/hns_roce_debugfs.c b/drivers/infiniband/hw/hns/hns_roce_debugfs.c
index b869cdc5411893..db32c5897640fb 100644
--- a/drivers/infiniband/hw/hns/hns_roce_debugfs.c
+++ b/drivers/infiniband/hw/hns/hns_roce_debugfs.c
@@ -26,17 +26,6 @@ static const struct file_operations hns_debugfs_seqfile_fops = {
 	.llseek = seq_lseek
 };
 
-static void init_debugfs_seqfile(struct hns_debugfs_seqfile *seq,
-				 const char *name, struct dentry *parent,
-				 int (*read_fn)(struct seq_file *, void *),
-				 void *data)
-{
-	debugfs_create_file(name, 0400, parent, seq, &hns_debugfs_seqfile_fops);
-
-	seq->read = read_fn;
-	seq->data = data;
-}
-
 static const char * const sw_stat_info[] = {
 	[HNS_ROCE_DFX_AEQE_CNT] = "aeqe",
 	[HNS_ROCE_DFX_CEQE_CNT] = "ceqe",
@@ -76,10 +65,12 @@ static void create_sw_stat_debugfs(struct hns_roce_dev *hr_dev,
 {
 	struct hns_sw_stat_debugfs *dbgfs = &hr_dev->dbgfs.sw_stat_root;
 
-	dbgfs->root = debugfs_create_dir("sw_stat", parent);
+	dbgfs->sw_stat.read = sw_stat_debugfs_show;
+	dbgfs->sw_stat.data = hr_dev;
 
-	init_debugfs_seqfile(&dbgfs->sw_stat, "sw_stat", dbgfs->root,
-			     sw_stat_debugfs_show, hr_dev);
+	dbgfs->root = debugfs_create_dir("sw_stat", parent);
+	debugfs_create_file("sw_stat", 0400, dbgfs->root, &dbgfs->sw_stat,
+			    &hns_debugfs_seqfile_fops);
 }
 
 /* debugfs for device */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0227/2077] tools/rtla: Fix --dump-tasks usage in timerlat
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (225 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0226/2077] RDMA/hns: Initialize seqfile before creating file Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0228/2077] rtla: Stop the record trace on interrupt Greg Kroah-Hartman
                   ` (770 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Costa Shulyupin, Tomas Glozar,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Costa Shulyupin <costa.shul@redhat.com>

[ Upstream commit 704fe8f3d97bba842f5f357e317116f1b88169e8 ]

Fix --dump-task to --dump-tasks in timerlat_hist usage string
and getopt_long table for consistency with timerlat_top.

Add missing --dump-tasks to timerlat_top usage synopsis.

Assisted-by: Claude:claude-opus-4-6
Signed-off-by: Costa Shulyupin <costa.shul@redhat.com>
Fixes: 2091336b9a8b ("rtla/timerlat_hist: Add auto-analysis support")
Link: https://lore.kernel.org/r/20260414185223.65353-1-costa.shul@redhat.com
Signed-off-by: Tomas Glozar <tglozar@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/tracing/rtla/src/timerlat_hist.c | 4 ++--
 tools/tracing/rtla/src/timerlat_top.c  | 3 ++-
 2 files changed, 4 insertions(+), 3 deletions(-)

diff --git a/tools/tracing/rtla/src/timerlat_hist.c b/tools/tracing/rtla/src/timerlat_hist.c
index 4b6708e333b8f4..d52fd59195cd1f 100644
--- a/tools/tracing/rtla/src/timerlat_hist.c
+++ b/tools/tracing/rtla/src/timerlat_hist.c
@@ -694,7 +694,7 @@ static void timerlat_hist_usage(void)
 		"[-d s] [-D] [-n] [-a us] [-p us] [-i us] [-T us] [-s us] \\",
 		"         [-t [file]] [-e sys[:event]] [--filter <filter>] [--trigger <trigger>] [-c cpu-list] [-H cpu-list]\\",
 		"	  [-P priority] [-E N] [-b N] [--no-irq] [--no-thread] [--no-header] [--no-summary] \\",
-		"	  [--no-index] [--with-zeros] [--dma-latency us] [-C [cgroup_name]] [--no-aa] [--dump-task] [-u|-k]",
+		"	  [--no-index] [--with-zeros] [--dma-latency us] [-C [cgroup_name]] [--no-aa] [--dump-tasks] [-u|-k]",
 		"	  [--warm-up s] [--deepest-idle-state n]",
 		NULL,
 	};
@@ -809,7 +809,7 @@ static struct common_params
 			{"filter",		required_argument,	0, '7'},
 			{"dma-latency",		required_argument,	0, '8'},
 			{"no-aa",		no_argument,		0, '9'},
-			{"dump-task",		no_argument,		0, '\1'},
+			{"dump-tasks",		no_argument,		0, '\1'},
 			{"warm-up",		required_argument,	0, '\2'},
 			{"trace-buffer-size",	required_argument,	0, '\3'},
 			{"deepest-idle-state",	required_argument,	0, '\4'},
diff --git a/tools/tracing/rtla/src/timerlat_top.c b/tools/tracing/rtla/src/timerlat_top.c
index 91f88bbebad9eb..035abf01dbe631 100644
--- a/tools/tracing/rtla/src/timerlat_top.c
+++ b/tools/tracing/rtla/src/timerlat_top.c
@@ -467,7 +467,8 @@ static void timerlat_top_usage(void)
 	static const char *const msg_start[] = {
 		"[-q] [-a us] [-d s] [-D] [-n] [-p us] [-i us] [-T us] [-s us] \\",
 		"	  [[-t [file]] [-e sys[:event]] [--filter <filter>] [--trigger <trigger>] [-c cpu-list] [-H cpu-list]\\",
-		"	  [-P priority] [--dma-latency us] [--aa-only us] [-C [cgroup_name]] [-u|-k] [--warm-up s] [--deepest-idle-state n]",
+		"	  [-P priority] [--dma-latency us] [--aa-only us] [-C [cgroup_name]] [--dump-tasks] [-u|-k] [--warm-up s]\\",
+		"	  [--deepest-idle-state n]",
 		NULL,
 	};
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0228/2077] rtla: Stop the record trace on interrupt
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (226 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0227/2077] tools/rtla: Fix --dump-tasks usage in timerlat Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0229/2077] drm/syncobj: Fix memory leak in drm_syncobj_find_fence() Greg Kroah-Hartman
                   ` (769 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Crystal Wood, Tomas Glozar,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Crystal Wood <crwood@redhat.com>

[ Upstream commit f03a59f949176ce4312cb466245d1243aaf40389 ]

Before, when rtla got a signal, it stopped the main trace but not the
record trace.  With "--on-end trace", this can lead to
save_trace_to_file() failing to keep up, especially on a debug kernel.
Plus, it adds post-stoppage noise to the trace file.

Signed-off-by: Crystal Wood <crwood@redhat.com>
Fixes: c73cab9dbed0 ("rtla/timerlat_hist: Stop timerlat tracer on signal")
Fixes: a4dfce7559d7 ("rtla/timerlat_top: Stop timerlat tracer on signal")
Fixes: 3aadb65db5d6 ("rtla/timerlat: Add action on end feature")
Link: https://lore.kernel.org/r/20260512173731.2151841-1-crwood@redhat.com
Signed-off-by: Tomas Glozar <tglozar@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/tracing/rtla/src/common.c   | 19 +++++++++++--------
 tools/tracing/rtla/src/common.h   |  1 -
 tools/tracing/rtla/src/timerlat.c |  2 +-
 3 files changed, 12 insertions(+), 10 deletions(-)

diff --git a/tools/tracing/rtla/src/common.c b/tools/tracing/rtla/src/common.c
index bc9d01ddd10295..bfeccc6222e5bc 100644
--- a/tools/tracing/rtla/src/common.c
+++ b/tools/tracing/rtla/src/common.c
@@ -10,7 +10,7 @@
 
 #include "common.h"
 
-struct trace_instance *trace_inst;
+struct osnoise_tool *trace_tool;
 volatile int stop_tracing;
 int nr_cpus;
 
@@ -21,12 +21,16 @@ static void stop_trace(int sig)
 		 * Stop requested twice in a row; abort event processing and
 		 * exit immediately
 		 */
-		tracefs_iterate_stop(trace_inst->inst);
+		if (trace_tool)
+			tracefs_iterate_stop(trace_tool->trace.inst);
 		return;
 	}
 	stop_tracing = 1;
-	if (trace_inst)
-		trace_instance_stop(trace_inst);
+	if (trace_tool) {
+		trace_instance_stop(&trace_tool->trace);
+		if (trace_tool->record)
+			trace_instance_stop(&trace_tool->record->trace);
+	}
 }
 
 /*
@@ -255,11 +259,10 @@ int run_tool(struct tool_ops *ops, int argc, char *argv[])
 	tool->params = params;
 
 	/*
-	 * Save trace instance into global variable so that SIGINT can stop
-	 * the timerlat tracer.
+	 * Expose the tool to signal handlers so they can stop the trace.
 	 * Otherwise, rtla could loop indefinitely when overloaded.
 	 */
-	trace_inst = &tool->trace;
+	trace_tool = tool;
 
 	retval = ops->apply_config(tool);
 	if (retval) {
@@ -267,7 +270,7 @@ int run_tool(struct tool_ops *ops, int argc, char *argv[])
 		goto out_free;
 	}
 
-	retval = enable_tracer_by_name(trace_inst->inst, ops->tracer);
+	retval = enable_tracer_by_name(tool->trace.inst, ops->tracer);
 	if (retval) {
 		err_msg("Failed to enable %s tracer\n", ops->tracer);
 		goto out_free;
diff --git a/tools/tracing/rtla/src/common.h b/tools/tracing/rtla/src/common.h
index 8921807bda988c..505babf386373b 100644
--- a/tools/tracing/rtla/src/common.h
+++ b/tools/tracing/rtla/src/common.h
@@ -54,7 +54,6 @@ struct osnoise_context {
 	int			opt_workload;
 };
 
-extern struct trace_instance *trace_inst;
 extern volatile int stop_tracing;
 
 struct hist_params {
diff --git a/tools/tracing/rtla/src/timerlat.c b/tools/tracing/rtla/src/timerlat.c
index f8c057518d2237..637f68d684f5f5 100644
--- a/tools/tracing/rtla/src/timerlat.c
+++ b/tools/tracing/rtla/src/timerlat.c
@@ -202,7 +202,7 @@ void timerlat_analyze(struct osnoise_tool *tool, bool stopped)
 		 * If the trace did not stop with --aa-only, at least print
 		 * the max known latency.
 		 */
-		max_lat = tracefs_instance_file_read(trace_inst->inst, "tracing_max_latency", NULL);
+		max_lat = tracefs_instance_file_read(tool->trace.inst, "tracing_max_latency", NULL);
 		if (max_lat) {
 			printf("  Max latency was %s\n", max_lat);
 			free(max_lat);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0229/2077] drm/syncobj: Fix memory leak in drm_syncobj_find_fence()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (227 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0228/2077] rtla: Stop the record trace on interrupt Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0230/2077] dm: limit target bio polling to one shot Greg Kroah-Hartman
                   ` (768 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Liviu Dudau, Erik Kurzinger,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Liviu Dudau <liviu.dudau@arm.com>

[ Upstream commit e5b93bd6fdb92aa5e4689715d7e8487d9ce66a38 ]

Commit 18226ba52159 ("drm/syncobj: reject invalid flags in
drm_syncobj_find_fence") forgot to take into account the fact that
drm_syncobj_find() takes a reference to syncobj and returns early
without dropping the reference, leading to memory leaks.

Fixes: 18226ba52159 ("drm/syncobj: reject invalid flags in drm_syncobj_find_fence")
Reported by: Sam Spencer <sam.spencer@arm.com>
Signed-off-by: Liviu Dudau <liviu.dudau@arm.com>
Acked-by: Erik Kurzinger <ekurzinger@gmail.com>
Signed-off-by: Liviu Dudau <liviu.dudau@arm.com>
Link: https://lore.kernel.org/all/20260507144425.2488057-1-liviu.dudau@arm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/drm_syncobj.c | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/drivers/gpu/drm/drm_syncobj.c b/drivers/gpu/drm/drm_syncobj.c
index 8d9fd1917c6e64..c9dbf64c0c9f2c 100644
--- a/drivers/gpu/drm/drm_syncobj.c
+++ b/drivers/gpu/drm/drm_syncobj.c
@@ -442,13 +442,15 @@ int drm_syncobj_find_fence(struct drm_file *file_private,
 	u64 timeout = nsecs_to_jiffies64(DRM_SYNCOBJ_WAIT_FOR_SUBMIT_TIMEOUT);
 	int ret;
 
-	if (flags & ~DRM_SYNCOBJ_WAIT_FLAGS_WAIT_FOR_SUBMIT)
-		return -EINVAL;
-
 	if (!syncobj)
 		return -ENOENT;
 
-	/* Waiting for userspace with locks help is illegal cause that can
+	if (flags & ~DRM_SYNCOBJ_WAIT_FLAGS_WAIT_FOR_SUBMIT) {
+		ret = -EINVAL;
+		goto out;
+	}
+
+	/* Waiting for userspace with locks held is illegal cause that can
 	 * trivial deadlock with page faults for example. Make lockdep complain
 	 * about it early on.
 	 */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0230/2077] dm: limit target bio polling to one shot
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (228 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0229/2077] drm/syncobj: Fix memory leak in drm_syncobj_find_fence() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0231/2077] selftests/bpf: Override EXTRA_LDFLAGS for static builds Greg Kroah-Hartman
                   ` (767 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Fengnan Chang, Mikulas Patocka,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fengnan Chang <changfengnan@bytedance.com>

[ Upstream commit 5aa0f9231cbacade065cedd8e9b5ebd067231171 ]

dm_poll_bio() is the ->poll_bio() callback for a stacked dm device.
The caller only knows about the dm queue, so it may decide to do a
spinning poll if it thinks a single queue is being polled. Passing those
flags unchanged to the mapped clone lets blk_mq_poll() spin on a target
queue from inside dm_poll_bio().

With io_uring IOPOLL on a dm-stripe target this can keep a task in

  dm_poll_bio() -> bio_poll() -> blk_mq_poll()

long enough to trigger an RCU CPU stall, before io_uring gets back to
io_iopoll_check() and its need_resched() check.

Keep dm's ->poll_bio() bounded by forcing one-shot polling for target
bios. The caller can invoke dm_poll_bio() again if it wants to keep
polling, and it also gets a chance to reap completions or reschedule
between passes.

Fixes: f22ecf9c14c1 ("blk-mq: delete task running check in blk_hctx_poll()")
Signed-off-by: Fengnan Chang <changfengnan@bytedance.com>
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/md/dm.c | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/drivers/md/dm.c b/drivers/md/dm.c
index e178fe19973ea3..8f44fbbcf3da27 100644
--- a/drivers/md/dm.c
+++ b/drivers/md/dm.c
@@ -2098,8 +2098,17 @@ static bool dm_poll_dm_io(struct dm_io *io, struct io_comp_batch *iob,
 	WARN_ON_ONCE(!dm_tio_is_normal(&io->tio));
 
 	/* don't poll if the mapped io is done */
-	if (atomic_read(&io->io_count) > 1)
-		bio_poll(&io->tio.clone, iob, flags);
+	if (atomic_read(&io->io_count) > 1) {
+		/*
+		 * DM hides the target queues from the upper poller, which may
+		 * decide it is safe to spin on a single stacked queue.  Do not
+		 * pass that spinning policy down to a target queue: one slow
+		 * clone could keep the task inside dm_poll_bio() for a long
+		 * time.  Poll target bios once and let the caller decide
+		 * whether to keep polling, reap completions or reschedule.
+		 */
+		bio_poll(&io->tio.clone, iob, flags | BLK_POLL_ONESHOT);
+	}
 
 	/* bio_poll holds the last reference */
 	return atomic_read(&io->io_count) == 1;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0231/2077] selftests/bpf: Override EXTRA_LDFLAGS for static builds
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (229 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0230/2077] dm: limit target bio polling to one shot Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0232/2077] selftests/bpf: Reject unsupported -k option in vmtest.sh Greg Kroah-Hartman
                   ` (766 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Paul Chaignon, Jakub Sitnicki,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Paul Chaignon <paul.chaignon@gmail.com>

[ Upstream commit 879daba303f7d7c3057f4d218921621e751f1912 ]

When running vmtest.sh with static linking, the bpftool_map_access
selftests fail. These selftests are calling the bpftool binary in
tools/sbin/ directly, which results in the following error:

    error while loading shared libraries: libLLVM.so.21.1:
      cannot open shared object file: No such file or directory

To fix this, we need to also build bpftool statically. That can be done
by setting EXTRA_LDFLAGS=-static.

Fixes: 2d96bbdfd3b5 ("selftests/bpf: convert test_bpftool_map_access.sh into test_progs framework")
Signed-off-by: Paul Chaignon <paul.chaignon@gmail.com>
Reviewed-by: Jakub Sitnicki <jakub@cloudflare.com>
Link: https://lore.kernel.org/r/714556da329c812988010ffe53173d9152570a78.1778669303.git.paul.chaignon@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/bpf/README.rst | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/selftests/bpf/README.rst b/tools/testing/selftests/bpf/README.rst
index 776fbe3cb8f9bd..37164322a1023f 100644
--- a/tools/testing/selftests/bpf/README.rst
+++ b/tools/testing/selftests/bpf/README.rst
@@ -77,7 +77,7 @@ In case of linker errors when running selftests, try using static linking:
 
 .. code-block:: console
 
-  $ LDLIBS=-static PKG_CONFIG='pkg-config --static' vmtest.sh
+  $ LDLIBS=-static EXTRA_LDFLAGS=-static PKG_CONFIG='pkg-config --static' vmtest.sh
 
 .. note:: Some distros may not support static linking.
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0232/2077] selftests/bpf: Reject unsupported -k option in vmtest.sh
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (230 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0231/2077] selftests/bpf: Override EXTRA_LDFLAGS for static builds Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0233/2077] selftests/bpf: Fix test for refinement of single-value tnum Greg Kroah-Hartman
                   ` (765 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Roman Kvasnytskyi, Paul Chaignon,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Roman Kvasnytskyi <roman@kvasnytskyi.net>

[ Upstream commit 6df582112aa9ac9d190169abdb0e42e496659ec9 ]

vmtest.sh does not document a -k option and does not handle it in the
getopts case statement. However, the getopts optstring includes k, which
causes the script to accept -k silently instead of reporting it as an
invalid option.

Remove k from the optstring so unsupported options are rejected through
the existing invalid-option path.

Fixes: c9709f52386d ("bpf: Helper script for running BPF presubmit tests")
Signed-off-by: Roman Kvasnytskyi <roman@kvasnytskyi.net>
Acked-by: Paul Chaignon <paul.chaignon@gmail.com>
Link: https://lore.kernel.org/r/20260516120625.80839-1-roman@kvasnytskyi.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/bpf/vmtest.sh | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/selftests/bpf/vmtest.sh b/tools/testing/selftests/bpf/vmtest.sh
index 2f869daf8a06b7..9ca8022853933a 100755
--- a/tools/testing/selftests/bpf/vmtest.sh
+++ b/tools/testing/selftests/bpf/vmtest.sh
@@ -382,7 +382,7 @@ main()
 	local exit_command="poweroff -f"
 	local debug_shell="no"
 
-	while getopts ':hskl:id:j:' opt; do
+	while getopts ':hsl:id:j:' opt; do
 		case ${opt} in
 		l)
 			LOCAL_ROOTFS_IMAGE="$OPTARG"
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0233/2077] selftests/bpf: Fix test for refinement of single-value tnum
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (231 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0232/2077] selftests/bpf: Reject unsupported -k option in vmtest.sh Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0234/2077] iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match table Greg Kroah-Hartman
                   ` (764 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Paul Chaignon, Alexei Starovoitov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Paul Chaignon <paul.chaignon@gmail.com>

[ Upstream commit 523d2f42b406f5be2989f436b03eacebf3679835 ]

This patch fixes the "bounds refinement with single-value tnum on umin"
verifier selftest. This selftest was introduced in commit e6ad477d1bf8
("selftests/bpf: Test refinement of single-value tnum") to cover the
logic from __update_reg64_bounds(), introduced in commit efc11a667878
("bpf: Improve bounds when tnum has a single possible value"). However,
the test still passes if that last commit is reverted.

The test is supposed to cover the case when the tnum and u64 range (or
cnum64 now) overlap in a single value. __update_reg64_bounds() detects
that case and refines the bounds to a known constant. However, the
constants for the test were poorly chosen and the bounds get refined to
a known constant even without __update_reg64_bounds(). The code is as
follows:

  0: call bpf_get_prandom_u32#7  ; R0=scalar()
  1: r0 |= 224                   ; R0=scalar(umin=umin32=224,var_off=(0xe0; 0xffffffffffffff1f))
  2: r0 &= 240                   ; R0=scalar(smin=umin=smin32=umin32=224,smax=umax=smax32=umax32=240,var_off=(0xe0; 0x10))
  3: if r0 == 0xf0 goto pc+2     ; R0=224

After instruction 3, we have u64=[0xe0; 0xef] and tnum=(0xe0; 0x10).
__reg_bound_offset() is able to deduce a new tnum from the u64,
tnum=(0xe0; 0x0f), which combined with the existing tnum gives us a
constant: 0xe0 or 224.

We can easily fix this by choosing different starting bounds. If we make
it u64=[0xe1; 0xf0], then __reg_bound_offset() doesn't have any impact.

Fixes: e6ad477d1bf8 ("selftests/bpf: Test refinement of single-value tnum")
Signed-off-by: Paul Chaignon <paul.chaignon@gmail.com>
Link: https://lore.kernel.org/r/be2dc2c3d85120286e60b3029b3338fff339f942.1779121582.git.paul.chaignon@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../testing/selftests/bpf/progs/verifier_bounds.c  | 14 +++++++-------
 1 file changed, 7 insertions(+), 7 deletions(-)

diff --git a/tools/testing/selftests/bpf/progs/verifier_bounds.c b/tools/testing/selftests/bpf/progs/verifier_bounds.c
index c1ae013dee29ce..bc431f46aafdbb 100644
--- a/tools/testing/selftests/bpf/progs/verifier_bounds.c
+++ b/tools/testing/selftests/bpf/progs/verifier_bounds.c
@@ -1890,25 +1890,25 @@ __naked void bounds_refinement_tnum_umax(void *ctx)
 /* This test covers the bounds deduction when the u64 range and the tnum
  * overlap only at umin. After instruction 3, the ranges look as follows:
  *
- * 0    umin=0xe00     umax=0xeff                              U64_MAX
+ * 0    umin=0xe1      umax=0xf0                               U64_MAX
  * |    [xxxxxxxxxxxxxx]                                       |
  * |----------------------------|------------------------------|
  * |    x               x                                      | tnum values
  *
- * The verifier can therefore deduce that the R0=0xe0=224.
+ * The verifier can therefore deduce that the R0=0xe1=225.
  */
 SEC("socket")
 __description("bounds refinement with single-value tnum on umin")
-__msg("3: (15) if r0 == 0xf0 {{.*}} R0=224")
+__msg("3: (15) if r0 == 0xf1 {{.*}} R0=225")
 __success __log_level(2)
 __naked void bounds_refinement_tnum_umin(void *ctx)
 {
 	asm volatile("			\
 	call %[bpf_get_prandom_u32];	\
-	r0 |= 0xe0;			\
-	r0 &= 0xf0;			\
-	if r0 == 0xf0 goto +2;		\
-	if r0 == 0xe0 goto +1;		\
+	r0 |= 0xe1;			\
+	r0 &= 0xf1;			\
+	if r0 == 0xf1 goto +2;		\
+	if r0 == 0xe1 goto +1;		\
 	r10 = 0;			\
 	exit;				\
 "	:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0234/2077] iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match table
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (232 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0233/2077] selftests/bpf: Fix test for refinement of single-value tnum Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0235/2077] sched/fair: Update util_est after updating util_avg during dequeue Greg Kroah-Hartman
                   ` (763 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Shawn Guo,
	Bibek Kumar Patro, Will Deacon, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bibek Kumar Patro <bibek.patro@oss.qualcomm.com>

[ Upstream commit a6e1618a65d453d4e739e5898c662ccb1e3de6c0 ]

The qcom_smmu_actlr_client_of_match table contained "qcom,fastrpc" as
the compatible string for applying ACTLR prefetch settings to FastRPC
devices. However, "qcom,fastrpc" is the compatible string for the parent
rpmsg channel node, which is not an IOMMU client — it carries no
"iommus" property in the device tree and is never attached to an SMMU
context bank.

The actual IOMMU clients are the compute context bank (CB) child nodes,
which use the compatible string "qcom,fastrpc-compute-cb". These nodes
carry the "iommus" property and are probed by fastrpc_cb_driver via
fastrpc_cb_probe(), which sets up the DMA mask and IOMMU mappings for
each FastRPC session. The device tree structure is:

  fastrpc {
      compatible = "qcom,fastrpc";        /* rpmsg channel, no iommus */
      ...
      compute-cb@3 {
          compatible = "qcom,fastrpc-compute-cb";
          iommus = <&apps_smmu 0x1823 0x0>;  /* actual IOMMU client */
      };
  };

Since qcom_smmu_set_actlr_dev() calls of_match_device() against the
device being attached to the SMMU context bank, the "qcom,fastrpc"
entry was never matching any device. As a result, the ACTLR prefetch
settings (PREFETCH_DEEP | CPRE | CMTLB) were silently never applied
for FastRPC compute context banks.

Fix this by replacing "qcom,fastrpc" with "qcom,fastrpc-compute-cb"
in the match table so that the ACTLR settings are correctly applied
to the compute CB devices that are the true IOMMU clients.

Assisted-by: Claude:claude-sonnet-4-6
Fixes: 3e35c3e725de ("iommu/arm-smmu: Add ACTLR data and support for qcom_smmu_500")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Shawn Guo <shengchao.guo@oss.qualcomm.com>
Signed-off-by: Bibek Kumar Patro <bibek.patro@oss.qualcomm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iommu/arm/arm-smmu/arm-smmu-qcom.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/iommu/arm/arm-smmu/arm-smmu-qcom.c b/drivers/iommu/arm/arm-smmu/arm-smmu-qcom.c
index edd41b5a3b6ac2..2d006049dd6109 100644
--- a/drivers/iommu/arm/arm-smmu/arm-smmu-qcom.c
+++ b/drivers/iommu/arm/arm-smmu/arm-smmu-qcom.c
@@ -39,7 +39,7 @@ static const struct of_device_id qcom_smmu_actlr_client_of_match[] = {
 			.data = (const void *) (PREFETCH_DEEP | CPRE | CMTLB) },
 	{ .compatible = "qcom,adreno-smmu",
 			.data = (const void *) (PREFETCH_DEEP | CPRE | CMTLB) },
-	{ .compatible = "qcom,fastrpc",
+	{ .compatible = "qcom,fastrpc-compute-cb",
 			.data = (const void *) (PREFETCH_DEEP | CPRE | CMTLB) },
 	{ .compatible = "qcom,qcm2290-mdss",
 			.data = (const void *) (PREFETCH_SHALLOW | CPRE | CMTLB) },
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0235/2077] sched/fair: Update util_est after updating util_avg during dequeue
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (233 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0234/2077] iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match table Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0236/2077] selftests/mm: Fix resv_sz when parsing arm64 signal frame Greg Kroah-Hartman
                   ` (762 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Qais Yousef, Vincent Guittot,
	Peter Zijlstra (Intel), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vincent Guittot <vincent.guittot@linaro.org>

[ Upstream commit 6d2051403d6c93832d3058a1b275c6aef2c97f44 ]

util_est_update() must be called after updating util_avg during the dequeue
of a task and only when the task is not delayed dequeue.

Move util_est_update() in update_load_avg().

Fixes: b55945c500c5 ("sched: Fix pick_next_task_fair() vs try_to_wake_up() race")
Closes: https://lore.kernel.org/all/20260512124653.305275-1-qyousef@layalina.io/
Reported-by: Qais Yousef <qyousef@layalina.io>
Reviewed-and-tested-by: Qais Yousef <qyousef@layalina.io>
Signed-off-by: Vincent Guittot <vincent.guittot@linaro.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/20260518102345.268452-1-vincent.guittot@linaro.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/sched/fair.c | 188 ++++++++++++++++++++++----------------------
 1 file changed, 92 insertions(+), 96 deletions(-)

diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c
index 3ebec186f98236..bcc984e462272d 100644
--- a/kernel/sched/fair.c
+++ b/kernel/sched/fair.c
@@ -4959,13 +4959,86 @@ static void detach_entity_load_avg(struct cfs_rq *cfs_rq, struct sched_entity *s
 	trace_pelt_cfs_tp(cfs_rq);
 }
 
+#define UTIL_EST_MARGIN (SCHED_CAPACITY_SCALE / 100)
+
+static inline void util_est_update(struct sched_entity *se)
+{
+	unsigned int ewma, dequeued, last_ewma_diff;
+
+	if (!sched_feat(UTIL_EST))
+		return;
+
+	/* Get current estimate of utilization */
+	ewma = READ_ONCE(se->avg.util_est);
+
+	/*
+	 * If the PELT values haven't changed since enqueue time,
+	 * skip the util_est update.
+	 */
+	if (ewma & UTIL_AVG_UNCHANGED)
+		return;
+
+	/* Get utilization at dequeue */
+	dequeued = READ_ONCE(se->avg.util_avg);
+
+	/*
+	 * Reset EWMA on utilization increases, the moving average is used only
+	 * to smooth utilization decreases.
+	 */
+	if (ewma <= dequeued) {
+		ewma = dequeued;
+		goto done;
+	}
+
+	/*
+	 * Skip update of task's estimated utilization when its members are
+	 * already ~1% close to its last activation value.
+	 */
+	last_ewma_diff = ewma - dequeued;
+	if (last_ewma_diff < UTIL_EST_MARGIN)
+		goto done;
+
+	/*
+	 * To avoid underestimate of task utilization, skip updates of EWMA if
+	 * we cannot grant that thread got all CPU time it wanted.
+	 */
+	if ((dequeued + UTIL_EST_MARGIN) < READ_ONCE(se->avg.runnable_avg))
+		goto done;
+
+	/*
+	 * Update Task's estimated utilization
+	 *
+	 * When *p completes an activation we can consolidate another sample
+	 * of the task size. This is done by using this value to update the
+	 * Exponential Weighted Moving Average (EWMA):
+	 *
+	 *  ewma(t) = w *  task_util(p) + (1-w) * ewma(t-1)
+	 *          = w *  task_util(p) +         ewma(t-1)  - w * ewma(t-1)
+	 *          = w * (task_util(p) -         ewma(t-1)) +     ewma(t-1)
+	 *          = w * (      -last_ewma_diff           ) +     ewma(t-1)
+	 *          = w * (-last_ewma_diff +  ewma(t-1) / w)
+	 *
+	 * Where 'w' is the weight of new samples, which is configured to be
+	 * 0.25, thus making w=1/4 ( >>= UTIL_EST_WEIGHT_SHIFT)
+	 */
+	ewma <<= UTIL_EST_WEIGHT_SHIFT;
+	ewma  -= last_ewma_diff;
+	ewma >>= UTIL_EST_WEIGHT_SHIFT;
+done:
+	ewma |= UTIL_AVG_UNCHANGED;
+	WRITE_ONCE(se->avg.util_est, ewma);
+
+	trace_sched_util_est_se_tp(se);
+}
+
 /*
  * Optional action to be done while updating the load average
  */
-#define UPDATE_TG	0x1
-#define SKIP_AGE_LOAD	0x2
-#define DO_ATTACH	0x4
-#define DO_DETACH	0x8
+#define UPDATE_TG	0x01
+#define SKIP_AGE_LOAD	0x02
+#define DO_ATTACH	0x04
+#define DO_DETACH	0x08
+#define UPDATE_UTIL_EST	0x10
 
 /* Update task and its cfs_rq load average */
 static inline void update_load_avg(struct cfs_rq *cfs_rq, struct sched_entity *se, int flags)
@@ -5008,6 +5081,9 @@ static inline void update_load_avg(struct cfs_rq *cfs_rq, struct sched_entity *s
 		if (flags & UPDATE_TG)
 			update_tg_load_avg(cfs_rq);
 	}
+
+	if (flags & UPDATE_UTIL_EST)
+		util_est_update(se);
 }
 
 /*
@@ -5066,11 +5142,6 @@ static inline unsigned long task_util(struct task_struct *p)
 	return READ_ONCE(p->se.avg.util_avg);
 }
 
-static inline unsigned long task_runnable(struct task_struct *p)
-{
-	return READ_ONCE(p->se.avg.runnable_avg);
-}
-
 static inline unsigned long _task_util_est(struct task_struct *p)
 {
 	return READ_ONCE(p->se.avg.util_est) & ~UTIL_AVG_UNCHANGED;
@@ -5113,88 +5184,6 @@ static inline void util_est_dequeue(struct cfs_rq *cfs_rq,
 	trace_sched_util_est_cfs_tp(cfs_rq);
 }
 
-#define UTIL_EST_MARGIN (SCHED_CAPACITY_SCALE / 100)
-
-static inline void util_est_update(struct cfs_rq *cfs_rq,
-				   struct task_struct *p,
-				   bool task_sleep)
-{
-	unsigned int ewma, dequeued, last_ewma_diff;
-
-	if (!sched_feat(UTIL_EST))
-		return;
-
-	/*
-	 * Skip update of task's estimated utilization when the task has not
-	 * yet completed an activation, e.g. being migrated.
-	 */
-	if (!task_sleep)
-		return;
-
-	/* Get current estimate of utilization */
-	ewma = READ_ONCE(p->se.avg.util_est);
-
-	/*
-	 * If the PELT values haven't changed since enqueue time,
-	 * skip the util_est update.
-	 */
-	if (ewma & UTIL_AVG_UNCHANGED)
-		return;
-
-	/* Get utilization at dequeue */
-	dequeued = task_util(p);
-
-	/*
-	 * Reset EWMA on utilization increases, the moving average is used only
-	 * to smooth utilization decreases.
-	 */
-	if (ewma <= dequeued) {
-		ewma = dequeued;
-		goto done;
-	}
-
-	/*
-	 * Skip update of task's estimated utilization when its members are
-	 * already ~1% close to its last activation value.
-	 */
-	last_ewma_diff = ewma - dequeued;
-	if (last_ewma_diff < UTIL_EST_MARGIN)
-		goto done;
-
-	/*
-	 * To avoid underestimate of task utilization, skip updates of EWMA if
-	 * we cannot grant that thread got all CPU time it wanted.
-	 */
-	if ((dequeued + UTIL_EST_MARGIN) < task_runnable(p))
-		goto done;
-
-
-	/*
-	 * Update Task's estimated utilization
-	 *
-	 * When *p completes an activation we can consolidate another sample
-	 * of the task size. This is done by using this value to update the
-	 * Exponential Weighted Moving Average (EWMA):
-	 *
-	 *  ewma(t) = w *  task_util(p) + (1-w) * ewma(t-1)
-	 *          = w *  task_util(p) +         ewma(t-1)  - w * ewma(t-1)
-	 *          = w * (task_util(p) -         ewma(t-1)) +     ewma(t-1)
-	 *          = w * (      -last_ewma_diff           ) +     ewma(t-1)
-	 *          = w * (-last_ewma_diff +  ewma(t-1) / w)
-	 *
-	 * Where 'w' is the weight of new samples, which is configured to be
-	 * 0.25, thus making w=1/4 ( >>= UTIL_EST_WEIGHT_SHIFT)
-	 */
-	ewma <<= UTIL_EST_WEIGHT_SHIFT;
-	ewma  -= last_ewma_diff;
-	ewma >>= UTIL_EST_WEIGHT_SHIFT;
-done:
-	ewma |= UTIL_AVG_UNCHANGED;
-	WRITE_ONCE(p->se.avg.util_est, ewma);
-
-	trace_sched_util_est_se_tp(&p->se);
-}
-
 static inline unsigned long get_actual_cpu_capacity(int cpu)
 {
 	unsigned long capacity = arch_scale_cpu_capacity(cpu);
@@ -5647,7 +5636,7 @@ static bool
 dequeue_entity(struct cfs_rq *cfs_rq, struct sched_entity *se, int flags)
 {
 	bool sleep = flags & DEQUEUE_SLEEP;
-	int action = UPDATE_TG;
+	int action = 0;
 
 	update_curr(cfs_rq);
 	clear_buddies(cfs_rq, se);
@@ -5667,15 +5656,23 @@ dequeue_entity(struct cfs_rq *cfs_rq, struct sched_entity *se, int flags)
 
 		if (sched_feat(DELAY_DEQUEUE) && delay &&
 		    !entity_eligible(cfs_rq, se)) {
-			update_load_avg(cfs_rq, se, 0);
+			if (entity_is_task(se))
+				action |= UPDATE_UTIL_EST;
+			update_load_avg(cfs_rq, se, action);
 			update_entity_lag(cfs_rq, se);
 			set_delayed(se);
 			return false;
 		}
 	}
 
-	if (entity_is_task(se) && task_on_rq_migrating(task_of(se)))
-		action |= DO_DETACH;
+	action = UPDATE_TG;
+	if (entity_is_task(se)) {
+		if (task_on_rq_migrating(task_of(se)))
+			action |= DO_DETACH;
+
+		if (sleep && !(flags & DEQUEUE_DELAYED))
+			action |= UPDATE_UTIL_EST;
+	}
 
 	/*
 	 * When dequeuing a sched_entity, we must:
@@ -7438,7 +7435,6 @@ static bool dequeue_task_fair(struct rq *rq, struct task_struct *p, int flags)
 	if (!p->se.sched_delayed)
 		util_est_dequeue(&rq->cfs, p);
 
-	util_est_update(&rq->cfs, p, flags & DEQUEUE_SLEEP);
 	if (dequeue_entities(rq, &p->se, flags) < 0)
 		return false;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0236/2077] selftests/mm: Fix resv_sz when parsing arm64 signal frame
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (234 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0235/2077] sched/fair: Update util_est after updating util_avg during dequeue Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0237/2077] firmware: arm_ffa: Honor partition info descriptor size Greg Kroah-Hartman
                   ` (761 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kevin Brodsky, Mark Brown,
	Will Deacon, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kevin Brodsky <kevin.brodsky@arm.com>

[ Upstream commit c364aa56d6738c8759e88941d7a45a1d6b4c52d0 ]

get_header() wants the size of the reserved area in struct
sigcontext, but instead we pass it the size of the entire struct.
This could in theory result in an out-of-bounds read (if the signal
frame is malformed).

Fix this using one of the existing macros from
tools/testing/selftests/arm64/signal/testcases/testcases.h.

This issue was reported by Sashiko on a patch that copied this
portion of the code.

Link: https://sashiko.dev/#/patchset/20260421144252.1440365-1-kevin.brodsky%40arm.com
Fixes: f5b5ea51f78f ("selftests: mm: make protection_keys test work on arm64")
Signed-off-by: Kevin Brodsky <kevin.brodsky@arm.com>
Reviewed-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/mm/pkey-arm64.h | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/tools/testing/selftests/mm/pkey-arm64.h b/tools/testing/selftests/mm/pkey-arm64.h
index 8e9685e03c441a..c5a78a2f211d52 100644
--- a/tools/testing/selftests/mm/pkey-arm64.h
+++ b/tools/testing/selftests/mm/pkey-arm64.h
@@ -130,9 +130,10 @@ static inline u64 get_pkey_bits(u64 reg, int pkey)
 static inline void aarch64_write_signal_pkey(ucontext_t *uctxt, u64 pkey)
 {
 	struct _aarch64_ctx *ctx = GET_UC_RESV_HEAD(uctxt);
+	size_t resv_size = GET_UCP_RESV_SIZE(uctxt);
 	struct poe_context *poe_ctx =
 		(struct poe_context *) get_header(ctx, POE_MAGIC,
-						sizeof(uctxt->uc_mcontext), NULL);
+						  resv_size, NULL);
 	if (poe_ctx)
 		poe_ctx->por_el0 = pkey;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0237/2077] firmware: arm_ffa: Honor partition info descriptor size
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (235 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0236/2077] selftests/mm: Fix resv_sz when parsing arm64 signal frame Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0238/2077] arm64: dts: freescale: imx95-verdin-ivy: fix RS485 RTS polarity Greg Kroah-Hartman
                   ` (760 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sudeep Holla, Jamie Nguyen,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jamie Nguyen <jamien@nvidia.com>

[ Upstream commit 01b9cae706161a39452a2cce0f281d4369344c51 ]

FFA_PARTITION_INFO_GET_REGS reports the size of each partition
information descriptor in x2[63:48]. However, __ffa_partition_info_get_regs()
walks the returned register payload with a hardcoded 24-byte stride
(regs += 3), even though the size is already read into buf_sz.

That works for the FF-A v1.1/v1.2 24-byte descriptor layout, where each
descriptor consumes three registers. Newer FF-A revisions can extend the
descriptor while keeping the existing fields at the front. For example, a
48-byte descriptor consumes six registers, so advancing by only three
registers desynchronises the parser and can make it read subsequent entries
from the middle of a descriptor.

Use the advertised descriptor size to derive the register stride. Validate
that the size is register-aligned, large enough for the fields parsed by the
driver, and that the requested number of descriptors fits in the returned
x3..x17 register window. The driver still copies only the fields it
understands, but now skips over any trailing descriptor fields correctly.

Fixes: ba85c644ac8d ("firmware: arm_ffa: Add support for FFA_PARTITION_INFO_GET_REGS")
Suggested-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Jamie Nguyen <jamien@nvidia.com>
Link: https://patch.msgid.link/20260518203116.42624-1-jamien@nvidia.com
(sudeep.holla: Minor rewordng of the commit message and subject)
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/firmware/arm_ffa/driver.c | 27 ++++++++++++++++-----------
 1 file changed, 16 insertions(+), 11 deletions(-)

diff --git a/drivers/firmware/arm_ffa/driver.c b/drivers/firmware/arm_ffa/driver.c
index b9f17fda724327..cab32cfdac4236 100644
--- a/drivers/firmware/arm_ffa/driver.c
+++ b/drivers/firmware/arm_ffa/driver.c
@@ -324,11 +324,9 @@ __ffa_partition_info_get(u32 uuid0, u32 uuid1, u32 uuid2, u32 uuid3,
 #define PART_INFO_EXEC_CXT_MASK	GENMASK(31, 16)
 #define PART_INFO_PROPS_MASK	GENMASK(63, 32)
 #define FFA_PART_INFO_GET_REGS_FIRST_REG	3
-#define FFA_PART_INFO_GET_REGS_REGS_PER_DESC	3
-#define FFA_PART_INFO_GET_REGS_MAX_DESC \
-	(((sizeof(ffa_value_t) / sizeof_field(ffa_value_t, a0)) - \
-	  FFA_PART_INFO_GET_REGS_FIRST_REG) / \
-	 FFA_PART_INFO_GET_REGS_REGS_PER_DESC)
+#define FFA_PART_INFO_GET_REGS_MIN_REGS_PER_DESC	3
+#define FFA_PART_INFO_GET_REGS_NUM_REGS \
+	(sizeof(ffa_value_t) / sizeof_field(ffa_value_t, a0))
 #define PART_INFO_ID(x)		((u16)(FIELD_GET(PART_INFO_ID_MASK, (x))))
 #define PART_INFO_EXEC_CXT(x)	((u16)(FIELD_GET(PART_INFO_EXEC_CXT_MASK, (x))))
 #define PART_INFO_PROPERTIES(x)	((u32)(FIELD_GET(PART_INFO_PROPS_MASK, (x))))
@@ -342,7 +340,7 @@ __ffa_partition_info_get_regs(u32 uuid0, u32 uuid1, u32 uuid2, u32 uuid3,
 
 	do {
 		__le64 *regs;
-		int idx, nr_desc, buf_idx;
+		int idx, nr_desc, buf_idx, regs_per_desc, max_desc;
 
 		invoke_ffa_fn((ffa_value_t){
 			      .a0 = FFA_PARTITION_INFO_GET_REGS,
@@ -365,8 +363,18 @@ __ffa_partition_info_get_regs(u32 uuid0, u32 uuid1, u32 uuid2, u32 uuid3,
 		if (cur_idx < start_idx || cur_idx >= count)
 			return -EINVAL;
 
+		buf_sz = PARTITION_INFO_SZ(partition_info.a2);
+		if (buf_sz % sizeof(*regs))
+			return -EINVAL;
+
+		regs_per_desc = buf_sz / sizeof(*regs);
+		if (regs_per_desc < FFA_PART_INFO_GET_REGS_MIN_REGS_PER_DESC)
+			return -EINVAL;
+
 		nr_desc = cur_idx - start_idx + 1;
-		if (nr_desc > FFA_PART_INFO_GET_REGS_MAX_DESC)
+		max_desc = (FFA_PART_INFO_GET_REGS_NUM_REGS -
+			    FFA_PART_INFO_GET_REGS_FIRST_REG) / regs_per_desc;
+		if (nr_desc > max_desc)
 			return -EINVAL;
 
 		buf_idx = buf - buffer;
@@ -374,9 +382,6 @@ __ffa_partition_info_get_regs(u32 uuid0, u32 uuid1, u32 uuid2, u32 uuid3,
 			return -EINVAL;
 
 		tag = UUID_INFO_TAG(partition_info.a2);
-		buf_sz = PARTITION_INFO_SZ(partition_info.a2);
-		if (buf_sz > sizeof(*buffer))
-			buf_sz = sizeof(*buffer);
 
 		regs = (void *)&partition_info.a3;
 		for (idx = 0; idx < nr_desc; idx++, buf++) {
@@ -395,7 +400,7 @@ __ffa_partition_info_get_regs(u32 uuid0, u32 uuid1, u32 uuid2, u32 uuid3,
 			buf->exec_ctxt = PART_INFO_EXEC_CXT(val);
 			buf->properties = PART_INFO_PROPERTIES(val);
 			uuid_copy(&buf->uuid, &uuid_regs.uuid);
-			regs += 3;
+			regs += regs_per_desc;
 		}
 		start_idx = cur_idx + 1;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0238/2077] arm64: dts: freescale: imx95-verdin-ivy: fix RS485 RTS polarity
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (236 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0237/2077] firmware: arm_ffa: Honor partition info descriptor size Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0239/2077] arm64: dts: imx8dxl-evk: Remove unnecessary PCIe EP properties Greg Kroah-Hartman
                   ` (759 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Francesco Dolcini, Frank Li,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Francesco Dolcini <francesco.dolcini@toradex.com>

[ Upstream commit 9f004f2afded2870838c0ae4906c2fa9307286bb ]

Fix the RS485 functionality, the RS485 RTS signal is active high on Ivy.

Fixes: f33a1f9a942c ("arm64: dts: freescale: imx95-verdin: Add Ivy carrier board")
Signed-off-by: Francesco Dolcini <francesco.dolcini@toradex.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx95-verdin-ivy.dtsi | 1 -
 1 file changed, 1 deletion(-)

diff --git a/arch/arm64/boot/dts/freescale/imx95-verdin-ivy.dtsi b/arch/arm64/boot/dts/freescale/imx95-verdin-ivy.dtsi
index 8337c8b25f050a..ff31f7c48cfb42 100644
--- a/arch/arm64/boot/dts/freescale/imx95-verdin-ivy.dtsi
+++ b/arch/arm64/boot/dts/freescale/imx95-verdin-ivy.dtsi
@@ -452,7 +452,6 @@ &lpuart7 {
 
 /* Verdin UART_2, through RS485 transceiver */
 &lpuart8 {
-	rs485-rts-active-low;
 	rs485-rx-during-tx;
 	linux,rs485-enabled-at-boot-time;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0239/2077] arm64: dts: imx8dxl-evk: Remove unnecessary PCIe EP properties
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (237 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0238/2077] arm64: dts: freescale: imx95-verdin-ivy: fix RS485 RTS polarity Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0240/2077] arm64: dts: imx8qxp-mek: Remove unnecessary PCIe EP vpcie-supply Greg Kroah-Hartman
                   ` (758 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sherry Sun, Richard Zhu, Frank Li,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sherry Sun <sherry.sun@nxp.com>

[ Upstream commit 538525f34158deb21b782164bde23ec07a353e4a ]

For PCIe endpoint mode, only M.2 power supply needs to be ensured.
On imx8dxl-evk, the M.2 power is always on and cannot be controlled,
while reg_pcieb only controls the M.2 W_DISABLE1# signal. Remove the
unnecessary vpcie-supply property from pcie0_ep node.

Also remove reset-gpio as PCIe endpoint mode doesn't require reset
control.

Fixes: c1c4820b60d7 ("arm64: dts: imx8dxl-evk: Add pcie0-ep node and use unified pcie0 label")
Signed-off-by: Sherry Sun <sherry.sun@nxp.com>
Reviewed-by: Richard Zhu <hongxing.zhu@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx8dxl-evk.dts | 2 --
 1 file changed, 2 deletions(-)

diff --git a/arch/arm64/boot/dts/freescale/imx8dxl-evk.dts b/arch/arm64/boot/dts/freescale/imx8dxl-evk.dts
index bc62ae5ca812dd..441e0090302994 100644
--- a/arch/arm64/boot/dts/freescale/imx8dxl-evk.dts
+++ b/arch/arm64/boot/dts/freescale/imx8dxl-evk.dts
@@ -686,8 +686,6 @@ &pcie0_ep {
 	phy-names = "pcie-phy";
 	pinctrl-0 = <&pinctrl_pcieb>;
 	pinctrl-names = "default";
-	reset-gpio = <&lsio_gpio4 0 GPIO_ACTIVE_LOW>;
-	vpcie-supply = <&reg_pcieb>;
 	status = "disabled";
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0240/2077] arm64: dts: imx8qxp-mek: Remove unnecessary PCIe EP vpcie-supply
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (238 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0239/2077] arm64: dts: imx8dxl-evk: Remove unnecessary PCIe EP properties Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0241/2077] arm64: dts: imx95-19x19-evk: Fix " Greg Kroah-Hartman
                   ` (757 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sherry Sun, Richard Zhu, Frank Li,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sherry Sun <sherry.sun@nxp.com>

[ Upstream commit b5ba136d535f1060322af31c0cf74d85ea19892d ]

For PCIe endpoint mode, only M.2 power supply needs to be ensured.
On imx8qxp-mek, the M.2 power is always on and cannot be controlled,
while reg_pcieb only controls the M.2 W_DISABLE1# signal. Remove the
unnecessary vpcie-supply property from pcie0_ep node.

Fixes: 1c9b0c6044c2 ("arm64: dts: imx8: use common imx-pcie0-ep.dtso to enable PCI ep function")
Signed-off-by: Sherry Sun <sherry.sun@nxp.com>
Reviewed-by: Richard Zhu <hongxing.zhu@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx8qxp-mek.dts | 1 -
 1 file changed, 1 deletion(-)

diff --git a/arch/arm64/boot/dts/freescale/imx8qxp-mek.dts b/arch/arm64/boot/dts/freescale/imx8qxp-mek.dts
index 623169f7ddb5fa..c07138055229c7 100644
--- a/arch/arm64/boot/dts/freescale/imx8qxp-mek.dts
+++ b/arch/arm64/boot/dts/freescale/imx8qxp-mek.dts
@@ -742,7 +742,6 @@ &pcie0_ep {
 	phy-names = "pcie-phy";
 	pinctrl-0 = <&pinctrl_pcieb>;
 	pinctrl-names = "default";
-	vpcie-supply = <&reg_pcieb>;
 	status = "disabled";
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0241/2077] arm64: dts: imx95-19x19-evk: Fix PCIe EP vpcie-supply
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (239 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0240/2077] arm64: dts: imx8qxp-mek: Remove unnecessary PCIe EP vpcie-supply Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0242/2077] hfs: fix incorrect inode ID assignment in hfs_new_inode() Greg Kroah-Hartman
                   ` (756 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sherry Sun, Richard Zhu, Frank Li,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sherry Sun <sherry.sun@nxp.com>

[ Upstream commit 596d0f9f4fefffbf783ab26cfa90cf50f5dd6bb0 ]

The vpcie-supply property should reference the regulator that controls
the actual M.2 power supply, not the W_DISABLE1# signal.
On imx95-19x19-evk:
- reg_pcie0 controls M.2 W_DISABLE1# signal
- reg_m2_pwr controls the actual M.2 power supply

Fix the vpcie-supply to use reg_m2_pwr for proper power control in
PCIe endpoint mode.

Fixes: 58bea81052d0 ("arm64: dts: imx95: add pcie1 ep overlay file and create pcie-ep dtb files")
Signed-off-by: Sherry Sun <sherry.sun@nxp.com>
Reviewed-by: Richard Zhu <hongxing.zhu@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx95-19x19-evk.dts | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/freescale/imx95-19x19-evk.dts b/arch/arm64/boot/dts/freescale/imx95-19x19-evk.dts
index 041fd838fabba8..49400bc9ba919b 100644
--- a/arch/arm64/boot/dts/freescale/imx95-19x19-evk.dts
+++ b/arch/arm64/boot/dts/freescale/imx95-19x19-evk.dts
@@ -550,7 +550,7 @@ &pcie0 {
 &pcie0_ep {
 	pinctrl-0 = <&pinctrl_pcie0>;
 	pinctrl-names = "default";
-	vpcie-supply = <&reg_pcie0>;
+	vpcie-supply = <&reg_m2_pwr>;
 	status = "disabled";
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0242/2077] hfs: fix incorrect inode ID assignment in hfs_new_inode()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (240 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0241/2077] arm64: dts: imx95-19x19-evk: Fix " Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0243/2077] media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() Greg Kroah-Hartman
                   ` (755 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, John Paul Adrian Glaubitz,
	Yangtao Li, linux-fsdevel, Viacheslav Dubeyko, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Viacheslav Dubeyko <slava@dubeyko.com>

[ Upstream commit 6592287869bffee91f59363e51de5f971ec2bd9d ]

The xfstests' test-case generic/003 reveals the HFS volume
corruption:

sudo ./check generic/003
FSTYP -- hfs
PLATFORM -- Linux/x86_64 hfsplus-testing-0001 7.0.0-rc1+ #18 SMP PREEMPT_DYNAMIC Fri Mar 13 17:54:19 PDT 2026
MKFS_OPTIONS -- /dev/loop51
MOUNT_OPTIONS -- /dev/loop51 /mnt/scratch

generic/003 51s ... _check_generic_filesystem: filesystem on /dev/loop51 is inconsistent

sudo fsck.hfs -d /dev/loop51
** /dev/loop51
Using cacheBlockSize=32K cacheTotalBlock=1024 cacheSize=32768K.
Executing fsck_hfs (version 540.1-Linux).
** Checking HFS volume.
The volume name is untitled
** Checking extents overflow file.
** Checking catalog file.
** Checking catalog hierarchy.
** Checking volume bitmap.
** Checking volume information.
invalid MDB drNxtCNID
Master Directory Block needs minor repair
(1, 0)
Verify Status: VIStat = 0x8000, ABTStat = 0x0000 EBTStat = 0x0000
CBTStat = 0x0000 CatStat = 0x00000000
** Repairing volume.
** Rechecking volume.
** Checking HFS volume.
The volume name is untitled
** Checking extents overflow file.
** Checking catalog file.
** Checking catalog hierarchy.
** Checking volume bitmap.
** Checking volume information.
** The volume untitled was repaired successfully.

The reason of corruption is incorrect value of drNxtCNID (next
CNID) in the MDB or superblock. The generic/003 test-case
creates several new inodes:

kernel: run fstests generic/003
hfs: hfs_mdb_get():179 next_id 16
hfs: hfs_mdb_get():179 next_id 16
hfs: hfs_new_inode():208 next_id 17
hfs: hfs_new_inode():208 next_id 18
hfs: hfs_mdb_commit():307 next_id 18
hfs: hfs_mdb_get():179 next_id 18
hfs: hfs_new_inode():208 next_id 19
hfs: hfs_new_inode():208 next_id 20
hfs_mdb_commit():307 next_id 20
hfs: hfs_mdb_get():179 next_id 20
hfs: hfs_new_inode():208 next_id 21
hfs: hfs_mdb_commit():307 next_id 21
hfs: hfs_mdb_get():179 next_id 21

The final assigned CNID was 21 but fsck correct it on 22.
It is possible to see that the reason of the issue is
incrementing the next_id value at first and assigning
already incremented value to the inode->i_ino:

struct inode *hfs_new_inode(...)
{
<skipped>

    next_id = atomic64_inc_return(&HFS_SB(sb)->next_id);
<skipped>
    inode->i_ino = (u32)next_id;

<skipped>
}

This patch fixes the issue by assigning the decremented
value to inode->i_ino.

Fixes: a06ec283e125 ("hfs: add logic of correcting a next unused CNID")
cc: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
cc: Yangtao Li <frank.li@vivo.com>
cc: linux-fsdevel@vger.kernel.org
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Link: https://lore.kernel.org/r/20260514195518.354108-2-slava@dubeyko.com
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/hfs/inode.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/hfs/inode.c b/fs/hfs/inode.c
index 89b33a9d46d5c0..1cbba734503896 100644
--- a/fs/hfs/inode.c
+++ b/fs/hfs/inode.c
@@ -204,7 +204,7 @@ struct inode *hfs_new_inode(struct inode *dir, const struct qstr *name, umode_t
 		pr_err("cannot create new inode: next CNID exceeds limit\n");
 		goto out_discard;
 	}
-	inode->i_ino = (u32)next_id;
+	inode->i_ino = (u32)next_id - 1;
 	inode->i_mode = mode;
 	inode->i_uid = current_fsuid();
 	inode->i_gid = current_fsgid();
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0243/2077] media: atomisp: Fix memory leak in atomisp_fixed_pattern_table()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (241 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0242/2077] hfs: fix incorrect inode ID assignment in hfs_new_inode() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0244/2077] media: atomisp: gc2235: fix UAF and memory leak Greg Kroah-Hartman
                   ` (754 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zilin Guan, Andy Shevchenko,
	Sakari Ailus, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zilin Guan <zilin@seu.edu.cn>

[ Upstream commit 4e8156bd9517fa18c3613ea39c222c7035f0221e ]

atomisp_v4l2_framebuffer_to_css_frame() allocates memory for
temporary variable raw_black_frame, which must be released via
ia_css_frame_free() before the function returns. However, if
sh_css_set_black_frame() fails, the function returns immediately without
performing this cleanup, leading to a memory leak.

Fix this by assigning the return value of sh_css_set_black_frame() to
ret. This ensures that the error code is propagated while allowing the
execution to fall through to the ia_css_frame_free() cleanup call.

The bug was originally detected on v6.13-rc1 using an experimental
static analysis tool we are developing, and we have verified that the
issue persists in the latest mainline kernel. The tool is based on the
LLVM framework and is specifically designed to detect memory management
issues. It is currently under active development and not yet publicly
available.

We performed build testing on x86_64 with allyesconfig. Since triggering
this error path in atomisp requires specific Intel Atom ISP hardware and
firmware, we were unable to perform runtime testing and instead verified
the fix according to the code logic.

Fixes: 85b606e02ad7 ("media: atomisp: get rid of a bunch of other wrappers")
Signed-off-by: Zilin Guan <zilin@seu.edu.cn>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/staging/media/atomisp/pci/atomisp_cmd.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

diff --git a/drivers/staging/media/atomisp/pci/atomisp_cmd.c b/drivers/staging/media/atomisp/pci/atomisp_cmd.c
index fec369575d883b..d58aa4d5945774 100644
--- a/drivers/staging/media/atomisp/pci/atomisp_cmd.c
+++ b/drivers/staging/media/atomisp/pci/atomisp_cmd.c
@@ -3364,10 +3364,8 @@ int atomisp_fixed_pattern_table(struct atomisp_sub_device *asd,
 	if (ret)
 		return ret;
 
-	if (sh_css_set_black_frame(asd->stream_env[ATOMISP_INPUT_STREAM_GENERAL].stream,
-				   raw_black_frame) != 0)
-		return -ENOMEM;
-
+	ret = sh_css_set_black_frame(asd->stream_env[ATOMISP_INPUT_STREAM_GENERAL].stream,
+				     raw_black_frame);
 	ia_css_frame_free(raw_black_frame);
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0244/2077] media: atomisp: gc2235: fix UAF and memory leak
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (242 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0243/2077] media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0245/2077] staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() Greg Kroah-Hartman
                   ` (753 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuho Choi, Dan Carpenter,
	Sakari Ailus, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yuho Choi <dbgh9129@gmail.com>

[ Upstream commit 628f763aee0047ff44974388d6f70f75a763026b ]

gc2235_probe() handles its error paths incorrectly.

If media_entity_pads_init() fails, gc2235_remove() is called, which
tears down the subdev and frees dev, but then still falls through to
atomisp_register_i2c_module(). This results in use-after-free.

If atomisp_register_i2c_module() fails, the media entity and control
handler are left initialized and dev is leaked.

gc2235_remove() unconditionally calls media_entity_cleanup() and
v4l2_ctrl_handler_free(), but these are not initialized at every
error path in gc2235_probe().

Replace gc2235_remove() calls in the probe error paths with explicit
unwind labels that free only the resources initialized at each point
of failure, in reverse order of initialization.

Fixes: a49d25364dfb ("staging/atomisp: Add support for the Intel IPU v2")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Reviewed-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../media/atomisp/i2c/atomisp-gc2235.c        | 29 ++++++++++++-------
 1 file changed, 18 insertions(+), 11 deletions(-)

diff --git a/drivers/staging/media/atomisp/i2c/atomisp-gc2235.c b/drivers/staging/media/atomisp/i2c/atomisp-gc2235.c
index d3414312e1de27..998c9f46bd0684 100644
--- a/drivers/staging/media/atomisp/i2c/atomisp-gc2235.c
+++ b/drivers/staging/media/atomisp/i2c/atomisp-gc2235.c
@@ -809,7 +809,7 @@ static int gc2235_probe(struct i2c_client *client)
 
 	ret = gc2235_s_config(&dev->sd, client->irq, gcpdev);
 	if (ret)
-		goto out_free;
+		goto err_unregister_subdev;
 
 	dev->sd.flags |= V4L2_SUBDEV_FL_HAS_DEVNODE;
 	dev->pad.flags = MEDIA_PAD_FL_SOURCE;
@@ -818,18 +818,16 @@ static int gc2235_probe(struct i2c_client *client)
 	ret =
 	    v4l2_ctrl_handler_init(&dev->ctrl_handler,
 				   ARRAY_SIZE(gc2235_controls));
-	if (ret) {
-		gc2235_remove(client);
-		return ret;
-	}
+	if (ret)
+		goto err_csi_cfg;
 
 	for (i = 0; i < ARRAY_SIZE(gc2235_controls); i++)
 		v4l2_ctrl_new_custom(&dev->ctrl_handler, &gc2235_controls[i],
 				     NULL);
 
 	if (dev->ctrl_handler.error) {
-		gc2235_remove(client);
-		return dev->ctrl_handler.error;
+		ret = dev->ctrl_handler.error;
+		goto err_ctrl_handler;
 	}
 
 	/* Use same lock for controls as for everything else. */
@@ -838,14 +836,23 @@ static int gc2235_probe(struct i2c_client *client)
 
 	ret = media_entity_pads_init(&dev->sd.entity, 1, &dev->pad);
 	if (ret)
-		gc2235_remove(client);
+		goto err_ctrl_handler;
+
+	ret = atomisp_register_i2c_module(&dev->sd, gcpdev);
+	if (ret)
+		goto err_media_cleanup;
 
-	return atomisp_register_i2c_module(&dev->sd, gcpdev);
+	return 0;
 
-out_free:
+err_media_cleanup:
+	media_entity_cleanup(&dev->sd.entity);
+err_ctrl_handler:
+	v4l2_ctrl_handler_free(&dev->ctrl_handler);
+err_csi_cfg:
+	dev->platform_data->csi_cfg(&dev->sd, 0);
+err_unregister_subdev:
 	v4l2_device_unregister_subdev(&dev->sd);
 	kfree(dev);
-
 	return ret;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0245/2077] staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (243 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0244/2077] media: atomisp: gc2235: fix UAF and memory leak Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0246/2077] riscv: dts: spacemit: set console baud rate on Milk-V Jupiter Greg Kroah-Hartman
                   ` (752 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jose A. Perez de Azpillaga,
	Dan Carpenter, Sakari Ailus, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jose A. Perez de Azpillaga <azpijr@gmail.com>

[ Upstream commit 9087395a383212ab1beaefcbe3b57ed131c7823d ]

The nested loop inside the IS_ISP2401 block incorrectly uses the same
variable 'i' as the outer loop. This shadows the outer loop variable
and causes premature termination or skipped array elements.

Change the inner loop to use a new variable 'j' to prevent this.

Fixes: 113401c67386 ("media: atomisp: sh_css: Removed #ifdef ISP2401 to make code generic")
Signed-off-by: Jose A. Perez de Azpillaga <azpijr@gmail.com>
Reviewed-by: Dan Carpenter <dan.carpenter@linaro.org>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/staging/media/atomisp/pci/sh_css.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/staging/media/atomisp/pci/sh_css.c b/drivers/staging/media/atomisp/pci/sh_css.c
index 584751516b6969..3d1903a9880486 100644
--- a/drivers/staging/media/atomisp/pci/sh_css.c
+++ b/drivers/staging/media/atomisp/pci/sh_css.c
@@ -8192,7 +8192,7 @@ ia_css_stream_create(const struct ia_css_stream_config *stream_config,
 int
 ia_css_stream_destroy(struct ia_css_stream *stream)
 {
-	int i;
+	int i, j;
 	int err = 0;
 
 	IA_CSS_ENTER_PRIVATE("stream = %p", stream);
@@ -8223,10 +8223,10 @@ ia_css_stream_destroy(struct ia_css_stream *stream)
 					sp_pipeline_input_terminal =
 						&sh_css_sp_group.pipe_io[sp_thread_id].input;
 
-					for (i = 0; i < IA_CSS_STREAM_MAX_ISYS_STREAM_PER_CH; i++) {
+					for (j = 0; j < IA_CSS_STREAM_MAX_ISYS_STREAM_PER_CH; j++) {
 						ia_css_isys_stream_h isys_stream =
-							&sp_pipeline_input_terminal->context.virtual_input_system_stream[i];
-						if (stream->config.isys_config[i].valid && isys_stream->valid)
+							&sp_pipeline_input_terminal->context.virtual_input_system_stream[j];
+						if (stream->config.isys_config[j].valid && isys_stream->valid)
 							ia_css_isys_stream_destroy(isys_stream);
 					}
 				}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0246/2077] riscv: dts: spacemit: set console baud rate on Milk-V Jupiter
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (244 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0245/2077] staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0247/2077] riscv: dts: spacemit: fix uboot partition offset " Greg Kroah-Hartman
                   ` (751 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Aurelien Jarno, Yixun Lan,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aurelien Jarno <aurelien@aurel32.net>

[ Upstream commit 4f97acb4f744f516bbe976da8282c0fe213216ff ]

Because the default console's baud rate is not set, defconfig kernels do
not have any serial output on this platform. Set the baud rate to
115200, matching what is used by U-Boot etc on this platform.

See-also: 24c12ca43b12c ("dts: spacemit: set console baud rate on bpif3")
Fixes: 5b90a3d6092d9 ("riscv: dts: spacemit: Add Milk-V Jupiter board device tree")
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Reviewed-by: Yixun Lan <dlan@kernel.org>
Link: https://patch.msgid.link/20260519041458.3287843-2-aurelien@aurel32.net
Signed-off-by: Yixun Lan <dlan@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts b/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts
index afaad59e6bce22..db98dbfadf00ff 100644
--- a/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts
+++ b/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts
@@ -20,7 +20,7 @@ aliases {
 	};
 
 	chosen {
-		stdout-path = "serial0";
+		stdout-path = "serial0:115200n8";
 	};
 
 	leds {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0247/2077] riscv: dts: spacemit: fix uboot partition offset on Milk-V Jupiter
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (245 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0246/2077] riscv: dts: spacemit: set console baud rate on Milk-V Jupiter Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0248/2077] firmware: smccc: Fix Arm SMCCC SOC_ID name call Greg Kroah-Hartman
                   ` (750 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Aurelien Jarno, Yixun Lan,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aurelien Jarno <aurelien@aurel32.net>

[ Upstream commit 6edd9a0d32e1ef81133b8cb5b3bb3157a44da4d1 ]

Correct the uboot partition node name to match its actual offset.

Fixes: 2829823956f0 ("riscv: dts: spacemit: enable QSPI and add SPI NOR on Milk-V Jupiter")
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Reviewed-by: Yixun Lan <dlan@kernel.org>
Link: https://patch.msgid.link/20260519041458.3287843-6-aurelien@aurel32.net
Signed-off-by: Yixun Lan <dlan@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts b/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts
index db98dbfadf00ff..c47bfb1597306d 100644
--- a/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts
+++ b/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts
@@ -367,7 +367,7 @@ env@60000 {
 			opensbi@70000 {
 				reg = <0x70000 0x30000>;
 			};
-			uboot@a00000 {
+			uboot@a0000 {
 				reg = <0xa0000 0x760000>;
 			};
 		};
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0248/2077] firmware: smccc: Fix Arm SMCCC SOC_ID name call
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (246 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0247/2077] riscv: dts: spacemit: fix uboot partition offset " Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0249/2077] firmware: arm_scmi: Read sensor config as 32-bit value Greg Kroah-Hartman
                   ` (749 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Andre Przywara, Sudeep Holla,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Andre Przywara <andre.przywara@arm.com>

[ Upstream commit 70492cfce2a4d41e87bf46989028a90f4bc6b38f ]

Commit 5f9c23abc477 ("firmware: smccc: Support optional Arm SMCCC SOC_ID
name") introduced the SOC_ID name string call, which reports a human
readable string describing the SoC, as returned by firmware.

The SMCCC spec v1.6 describes this feature as AArch64 only, since we rely
on 8 characters to be transmitted per register. Consequently the SMCCC
call must use the AArch64 calling convention, which requires bit 30 of
the FID to be set. The spec is a bit confusing here, since it mentions
that in the parameter description ("2: SoC name (optionally implemented for
SMC64 calls, ..."), but still prints the FID explicitly as 0x80000002.

But as this FID is using the SMC32 calling convention (correct for the
other two calls), it will not match what any SMCCC conformant firmware is
expecting, so any call would return NOT_SUPPORTED.

Add a 64-bit version of the ARCH_SOC_ID FID macro, and use that for the
SoC name version of the call to fix the issue.

Fixes: 5f9c23abc477 ("firmware: smccc: Support optional Arm SMCCC SOC_ID name")
Signed-off-by: Andre Przywara <andre.przywara@arm.com>
Link: https://patch.msgid.link/20250902172053.304911-1-andre.przywara@arm.com
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/firmware/smccc/soc_id.c | 2 +-
 include/linux/arm-smccc.h       | 5 +++++
 2 files changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/firmware/smccc/soc_id.c b/drivers/firmware/smccc/soc_id.c
index 2f7475e66b3ca9..a909d5e6dee509 100644
--- a/drivers/firmware/smccc/soc_id.c
+++ b/drivers/firmware/smccc/soc_id.c
@@ -60,7 +60,7 @@ static char __init *smccc_soc_name_init(void)
 	 * to the ARM_SMCCC_ARCH_SOC_ID function.  Fetch it if
 	 * available.
 	 */
-	args.a0 = ARM_SMCCC_ARCH_SOC_ID;
+	args.a0 = ARM_SMCCC_ARCH_SOC_ID64;
 	args.a1 = 2;    /* SOC_ID name */
 	arm_smccc_1_2_invoke(&args, &res);
 
diff --git a/include/linux/arm-smccc.h b/include/linux/arm-smccc.h
index e7195750d21bb4..4de81848fe2eec 100644
--- a/include/linux/arm-smccc.h
+++ b/include/linux/arm-smccc.h
@@ -90,6 +90,11 @@
 			   ARM_SMCCC_SMC_32,				\
 			   0, 2)
 
+#define ARM_SMCCC_ARCH_SOC_ID64						\
+	ARM_SMCCC_CALL_VAL(ARM_SMCCC_FAST_CALL,				\
+			   ARM_SMCCC_SMC_64,				\
+			   0, 2)
+
 #define ARM_SMCCC_ARCH_WORKAROUND_1					\
 	ARM_SMCCC_CALL_VAL(ARM_SMCCC_FAST_CALL,				\
 			   ARM_SMCCC_SMC_32,				\
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0249/2077] firmware: arm_scmi: Read sensor config as 32-bit value
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (247 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0248/2077] firmware: smccc: Fix Arm SMCCC SOC_ID name call Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0250/2077] media: synopsys: Fix IPI using hardcoded datatype Greg Kroah-Hartman
                   ` (748 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cristian Marussi, Sudeep Holla,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sudeep Holla <sudeep.holla@kernel.org>

[ Upstream commit f6fe7c3c007df18afd289ff2d98c692fae9ab085 ]

The SENSOR_CONFIG_GET response contains a 32-bit sensor_config field,
and the xfer is initialized with a 4-byte RX buffer. Reading it with
get_unaligned_le64() can consume bytes past the returned payload.

Use get_unaligned_le32() to match the protocol layout and the allocated
response size.

Fixes: 7b83c5f41088 ("firmware: arm_scmi: Add SCMI v3.0 sensor configuration support")
Link: https://patch.msgid.link/20260517-scmi_fixes-v1-1-d86daec4defd@kernel.org
Reviewed-by: Cristian Marussi <cristian.marussi@arm.com>
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/firmware/arm_scmi/sensors.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/firmware/arm_scmi/sensors.c b/drivers/firmware/arm_scmi/sensors.c
index 882d55f987d227..836c294a9f42ae 100644
--- a/drivers/firmware/arm_scmi/sensors.c
+++ b/drivers/firmware/arm_scmi/sensors.c
@@ -793,7 +793,7 @@ static int scmi_sensor_config_get(const struct scmi_protocol_handle *ph,
 	if (!ret) {
 		struct scmi_sensor_info *s = si->sensors + sensor_id;
 
-		*sensor_config = get_unaligned_le64(t->rx.buf);
+		*sensor_config = get_unaligned_le32(t->rx.buf);
 		s->sensor_config = *sensor_config;
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0250/2077] media: synopsys: Fix IPI using hardcoded datatype
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (248 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0249/2077] firmware: arm_scmi: Read sensor config as 32-bit value Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0251/2077] sysfs: clamp show() return value in sysfs_kf_read() Greg Kroah-Hartman
                   ` (747 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Frank Li, Guoniu Zhou, Sakari Ailus,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guoniu Zhou <guoniu.zhou@oss.nxp.com>

[ Upstream commit 8ba166ff7c921da610376156d7c0a5fc985fa983 ]

The imx93_csi2rx_dphy_ipi_enable() function configures the IPI datatype
using csi2->formats->csi_dt, which is initialized during probe but never
updated in set_fmt(). This causes the IPI to always use the probe-time
default datatype, ignoring the actual media bus format negotiated at
runtime. When userspace requests a different format, the IPI hardware is
configured with the wrong datatype, resulting in incorrect image output.

Fix by updating csi2->formats in the set_fmt callback to reflect the
currently negotiated format, ensuring the IPI configuration matches the
runtime datatype.

Fixes: ec40b431f0ab ("media: synopsys: csi2rx: add i.MX93 support")
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Guoniu Zhou <guoniu.zhou@oss.nxp.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/media/platform/synopsys/dw-mipi-csi2rx.c | 15 +++++++++++++--
 1 file changed, 13 insertions(+), 2 deletions(-)

diff --git a/drivers/media/platform/synopsys/dw-mipi-csi2rx.c b/drivers/media/platform/synopsys/dw-mipi-csi2rx.c
index 02eb4a6cafadea..0b80e84983f9e2 100644
--- a/drivers/media/platform/synopsys/dw-mipi-csi2rx.c
+++ b/drivers/media/platform/synopsys/dw-mipi-csi2rx.c
@@ -311,7 +311,7 @@ dw_mipi_csi2rx_find_format(struct dw_mipi_csi2rx_device *csi2, u32 mbus_code)
 	WARN_ON(csi2->formats_num == 0);
 
 	for (unsigned int i = 0; i < csi2->formats_num; i++) {
-		const struct dw_mipi_csi2rx_format *format = &csi2->formats[i];
+		const struct dw_mipi_csi2rx_format *format = &formats[i];
 
 		if (format->code == mbus_code)
 			return format;
@@ -433,7 +433,7 @@ dw_mipi_csi2rx_enum_mbus_code(struct v4l2_subdev *sd,
 		if (code->index >= csi2->formats_num)
 			return -EINVAL;
 
-		code->code = csi2->formats[code->index].code;
+		code->code = formats[code->index].code;
 		return 0;
 	default:
 		return -EINVAL;
@@ -470,6 +470,17 @@ static int dw_mipi_csi2rx_set_fmt(struct v4l2_subdev *sd,
 
 	*src = *sink;
 
+	/* Store the CSIS format descriptor for active formats. */
+	if (format->which == V4L2_SUBDEV_FORMAT_ACTIVE) {
+		csi2->formats = fmt ? :
+			dw_mipi_csi2rx_find_format(csi2, default_format.code);
+
+		if (!csi2->formats) {
+			dev_err(csi2->dev, "Failed to find valid format\n");
+			return -EINVAL;
+		}
+	}
+
 	return 0;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0251/2077] sysfs: clamp show() return value in sysfs_kf_read()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (249 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0250/2077] media: synopsys: Fix IPI using hardcoded datatype Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0252/2077] bitops: use common function parameter names Greg Kroah-Hartman
                   ` (746 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, NeilBrown, Tejun Heo,
	Rafael J. Wysocki (Intel), Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

[ Upstream commit 454257f6d124a92342dcbb7710c03dd6ef96c731 ]

sysfs_kf_seq_show() defends against buggy show() callbacks that return
larger than PAGE_SIZE by clamping the value and printing a warning.
sysfs_kf_read(), the prealloc variant, has no such defense.

The only current in-tree user of __ATTR_PREALLOC is drivers/md/md.c,
whose show() callbacks are well-behaved, so this is hardening against
future drivers doing foolish things and out-of-tree code doing even more
foolish things.

Cc: NeilBrown <neil@brown.name>
Cc: Tejun Heo <tj@kernel.org>
Fixes: 2b75869bba67 ("sysfs/kernfs: allow attributes to request write buffer be pre-allocated.")
Assisted-by: gregkh_clanker_t1000
Reviewed-by: Rafael J. Wysocki (Intel) <rafael@kernel.org>
Reviewed-by: Danilo Krummrich <dakr@kernel.org>
Link: https://patch.msgid.link/2026052000-drove-unicycle-d61b@gregkh
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/sysfs/file.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/fs/sysfs/file.c b/fs/sysfs/file.c
index 5709cede1d7568..25b44fe171a329 100644
--- a/fs/sysfs/file.c
+++ b/fs/sysfs/file.c
@@ -120,6 +120,10 @@ static ssize_t sysfs_kf_read(struct kernfs_open_file *of, char *buf,
 	len = ops->show(kobj, of->kn->priv, buf);
 	if (len < 0)
 		return len;
+	if (len >= (ssize_t)PAGE_SIZE) {
+		printk("fill_read_buffer: %pS returned bad count\n", ops->show);
+		len = PAGE_SIZE - 1;
+	}
 	if (pos) {
 		if (len <= pos)
 			return 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0252/2077] bitops: use common function parameter names
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (250 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0251/2077] sysfs: clamp show() return value in sysfs_kf_read() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0253/2077] regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions Greg Kroah-Hartman
                   ` (745 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Randy Dunlap, Yury Norov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Randy Dunlap <rdunlap@infradead.org>

[ Upstream commit 8a51b2e874f47a6094353b59ecae421f0968fe3a ]

Fix the function prototypes to use the common parameter name 'addr'
instead of 'p' (common to arch-specific implementations of these
functions).
This avoids the kernel-doc warnings:

Warning: include/asm-generic/bitops/lock.h:19 function parameter 'p'
 not described in 'arch_test_and_set_bit_lock'
Warning: include/asm-generic/bitops/lock.h:41 function parameter 'p'
 not described in 'arch_clear_bit_unlock'
Warning: include/asm-generic/bitops/lock.h:59 function parameter 'p'
 not described in 'arch___clear_bit_unlock'

Fixes: 84c6591103db ("locking/atomics, asm-generic/bitops/lock.h: Rewrite using atomic_fetch_*()")
Signed-off-by: Randy Dunlap <rdunlap@infradead.org>
Signed-off-by: Yury Norov <yury.norov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/asm-generic/bitops/lock.h | 22 +++++++++++-----------
 1 file changed, 11 insertions(+), 11 deletions(-)

diff --git a/include/asm-generic/bitops/lock.h b/include/asm-generic/bitops/lock.h
index 14d4ec8c5152d6..ffb73b6129e736 100644
--- a/include/asm-generic/bitops/lock.h
+++ b/include/asm-generic/bitops/lock.h
@@ -16,16 +16,16 @@
  * It can be used to implement bit locks.
  */
 static __always_inline int
-arch_test_and_set_bit_lock(unsigned int nr, volatile unsigned long *p)
+arch_test_and_set_bit_lock(unsigned int nr, volatile unsigned long *addr)
 {
 	long old;
 	unsigned long mask = BIT_MASK(nr);
 
-	p += BIT_WORD(nr);
-	if (READ_ONCE(*p) & mask)
+	addr += BIT_WORD(nr);
+	if (READ_ONCE(*addr) & mask)
 		return 1;
 
-	old = raw_atomic_long_fetch_or_acquire(mask, (atomic_long_t *)p);
+	old = raw_atomic_long_fetch_or_acquire(mask, (atomic_long_t *)addr);
 	return !!(old & mask);
 }
 
@@ -38,10 +38,10 @@ arch_test_and_set_bit_lock(unsigned int nr, volatile unsigned long *p)
  * This operation is atomic and provides release barrier semantics.
  */
 static __always_inline void
-arch_clear_bit_unlock(unsigned int nr, volatile unsigned long *p)
+arch_clear_bit_unlock(unsigned int nr, volatile unsigned long *addr)
 {
-	p += BIT_WORD(nr);
-	raw_atomic_long_fetch_andnot_release(BIT_MASK(nr), (atomic_long_t *)p);
+	addr += BIT_WORD(nr);
+	raw_atomic_long_fetch_andnot_release(BIT_MASK(nr), (atomic_long_t *)addr);
 }
 
 /**
@@ -56,14 +56,14 @@ arch_clear_bit_unlock(unsigned int nr, volatile unsigned long *p)
  * See for example x86's implementation.
  */
 static inline void
-arch___clear_bit_unlock(unsigned int nr, volatile unsigned long *p)
+arch___clear_bit_unlock(unsigned int nr, volatile unsigned long *addr)
 {
 	unsigned long old;
 
-	p += BIT_WORD(nr);
-	old = READ_ONCE(*p);
+	addr += BIT_WORD(nr);
+	old = READ_ONCE(*addr);
 	old &= ~BIT_MASK(nr);
-	raw_atomic_long_set_release((atomic_long_t *)p, old);
+	raw_atomic_long_set_release((atomic_long_t *)addr, old);
 }
 
 #ifndef arch_xor_unlock_is_negative_byte
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0253/2077] regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (251 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0252/2077] bitops: use common function parameter names Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0254/2077] tools/nolibc: getopt: Fix potential out of bounds access Greg Kroah-Hartman
                   ` (744 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Chen-Yu Tsai,
	Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chen-Yu Tsai <wenst@chromium.org>

[ Upstream commit cdc517688ffa2c30a64a20b558a9ecbf046c70f1 ]

The name of the regulator should match what the board design specifies
for the power rail. There should be no limitations on what the name can
be, and they definitely don't always follow the PMIC's own names.

Drop the restrictions on regulator-name.

Fixes: 8771456635d5 ("dt-bindings: regulator: Add document for MT6359 regulator")
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Chen-Yu Tsai <wenst@chromium.org>
Link: https://patch.msgid.link/20260514091520.2718987-3-wenst@chromium.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../bindings/regulator/mt6359-regulator.yaml  | 43 -------------------
 1 file changed, 43 deletions(-)

diff --git a/Documentation/devicetree/bindings/regulator/mt6359-regulator.yaml b/Documentation/devicetree/bindings/regulator/mt6359-regulator.yaml
index fe4ac9350ba035..ac925334ae833c 100644
--- a/Documentation/devicetree/bindings/regulator/mt6359-regulator.yaml
+++ b/Documentation/devicetree/bindings/regulator/mt6359-regulator.yaml
@@ -18,84 +18,41 @@ patternProperties:
   "^buck_v(s1|gpu11|modem|pu|core|s2|pa|proc2|proc1|core_sshub)$":
     type: object
     $ref: regulator.yaml#
-
-    properties:
-      regulator-name:
-        pattern: "^v(s1|gpu11|modem|pu|core|s2|pa|proc2|proc1|core_sshub)$"
-
     unevaluatedProperties: false
 
   "^ldo_v(ibr|rf12|usb|camio|efuse|xo22)$":
     type: object
     $ref: regulator.yaml#
-
-    properties:
-      regulator-name:
-        pattern: "^v(ibr|rf12|usb|camio|efuse|xo22)$"
-
     unevaluatedProperties: false
 
   "^ldo_v(rfck|emc|a12|a09|ufs|bbck)$":
     type: object
     $ref: regulator.yaml#
-
-    properties:
-      regulator-name:
-        pattern: "^v(rfck|emc|a12|a09|ufs|bbck)$"
-
     unevaluatedProperties: false
 
   "^ldo_vcn(18|13|33_1_bt|13_1_wifi|33_2_bt|33_2_wifi)$":
     type: object
     $ref: regulator.yaml#
-
-    properties:
-      regulator-name:
-        pattern: "^vcn(18|13|33_1_bt|13_1_wifi|33_2_bt|33_2_wifi)$"
-
     unevaluatedProperties: false
 
   "^ldo_vsram_(proc2|others|md|proc1|others_sshub)$":
     type: object
     $ref: regulator.yaml#
-
-    properties:
-      regulator-name:
-        pattern: "^vsram_(proc2|others|md|proc1|others_sshub)$"
-
     unevaluatedProperties: false
 
   "^ldo_v(fe|bif|io)28$":
     type: object
     $ref: regulator.yaml#
-
-    properties:
-      regulator-name:
-        pattern: "^v(fe|bif|io)28$"
-
     unevaluatedProperties: false
 
   "^ldo_v(aud|io|aux|rf|m)18$":
     type: object
     $ref: regulator.yaml#
-
-    properties:
-      regulator-name:
-        pattern: "^v(aud|io|aux|rf|m)18$"
-
     unevaluatedProperties: false
 
   "^ldo_vsim[12]$":
     type: object
     $ref: regulator.yaml#
-
-    properties:
-      regulator-name:
-        pattern: "^vsim[12]$"
-
-    required:
-      - regulator-name
-
     unevaluatedProperties: false
 
 additionalProperties: false
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0254/2077] tools/nolibc: getopt: Fix potential out of bounds access
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (252 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0253/2077] regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0255/2077] vfio: selftests: Fix out-of-tree build with make O= Greg Kroah-Hartman
                   ` (743 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Daniel Palmer, Thomas Weißschuh,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Palmer <daniel@thingy.jp>

[ Upstream commit 136ca91411b0b637e862eb7b1cce2a56853edd17 ]

Running clang-tidy on a program that uses getopt() from nolibc
this warning appears:

getopt.h:80:6: warning: Out of bound access to memory after the end of the string literal [clang-analyzer-security.ArrayBound]
80 |         if (optstring[i] == ':') {

This looks like a very unlikely case that an argument
inside of argv is being changed between getopt() calls.

Adding a check for d becoming 0 in the guard after the loop
stops getopt() getting far enough to access beyond the end
of the array and seems to correct the issue.

Fixes: bae3cd708e8a ("tools/nolibc: add getopt()")
Assisted-by: Claude:claude-4.6-sonnet # reproducer
Signed-off-by: Daniel Palmer <daniel@thingy.jp>
Link: https://patch.msgid.link/20260520111931.1027758-1-daniel@thingy.jp
[Thomas: clean up commit message a bit]
Signed-off-by: Thomas Weißschuh <linux@weissschuh.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/include/nolibc/getopt.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/include/nolibc/getopt.h b/tools/include/nolibc/getopt.h
index 87565e3b6a339f..3ad140f692dfe7 100644
--- a/tools/include/nolibc/getopt.h
+++ b/tools/include/nolibc/getopt.h
@@ -71,7 +71,7 @@ int getopt(int argc, char * const argv[], const char *optstring)
 		d = optstring[i++];
 	} while (d && d != c);
 
-	if (d != c || c == ':') {
+	if (!d || d != c || c == ':') {
 		optopt = c;
 		if (optstring[0] != ':' && opterr)
 			fprintf(stderr, "%s: unrecognized option: %c\n", argv[0], *optchar);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0255/2077] vfio: selftests: Fix out-of-tree build with make O=
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (253 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0254/2077] tools/nolibc: getopt: Fix potential out of bounds access Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0256/2077] vfio: selftests: Allow builds when ARCH=x86 Greg Kroah-Hartman
                   ` (742 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Matlack, Jason Gunthorpe,
	Alex Williamson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jason Gunthorpe <jgg@nvidia.com>

[ Upstream commit a21b864bd951e452922dbd66747da24daca2b04f ]

The test programs are compiled via a static pattern rule that requires
intermediate .o files:

  $(TEST_GEN_PROGS): %: %.o $(LIBVFIO_O)

After lib.mk prefixes TEST_GEN_PROGS with $(OUTPUT), this creates
dependencies on .o files in the output directory (e.g.
$(OUTPUT)/vfio_dma_mapping_test.o). However, there is no rule to compile
these .o files from the source directory .c files when OUTPUT differs
from the source directory.

Add an explicit chain of pattern rules:
  $(OUTPUT)/% -> $(OUTPUT)/%.o -> %.c

Following the same pattern already used in libvfio.mk for the library
objects.

Fixes: 19faf6fd969c ("vfio: selftests: Add a helper library for VFIO selftests")
Reviewed-by: David Matlack <dmatlack@google.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Link: https://lore.kernel.org/r/0-v2-4ccc247e6aff+1d93-vfio_st_make_o_jgg@nvidia.com
Signed-off-by: Alex Williamson <alex@shazbot.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/vfio/Makefile | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/tools/testing/selftests/vfio/Makefile b/tools/testing/selftests/vfio/Makefile
index 0684932d91bfcb..a19b75742342ad 100644
--- a/tools/testing/selftests/vfio/Makefile
+++ b/tools/testing/selftests/vfio/Makefile
@@ -27,10 +27,13 @@ CFLAGS += $(EXTRA_CFLAGS)
 
 LDFLAGS += -pthread
 
-$(TEST_GEN_PROGS): %: %.o $(LIBVFIO_O)
+$(TEST_GEN_PROGS): $(OUTPUT)/%: $(OUTPUT)/%.o $(LIBVFIO_O)
 	$(CC) $(CFLAGS) $(CPPFLAGS) $(LDFLAGS) $< $(LIBVFIO_O) $(LDLIBS) -o $@
 
 TEST_GEN_PROGS_O = $(patsubst %, %.o, $(TEST_GEN_PROGS))
+$(TEST_GEN_PROGS_O): $(OUTPUT)/%.o: %.c
+	$(CC) $(CFLAGS) $(CPPFLAGS) $(TARGET_ARCH) -c $< -o $@
+
 TEST_DEP_FILES = $(patsubst %.o, %.d, $(TEST_GEN_PROGS_O) $(LIBVFIO_O))
 -include $(TEST_DEP_FILES)
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0256/2077] vfio: selftests: Allow builds when ARCH=x86
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (254 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0255/2077] vfio: selftests: Fix out-of-tree build with make O= Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0257/2077] nilfs2: Fix return in nilfs_mkdir Greg Kroah-Hartman
                   ` (741 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, David Matlack,
	Alex Williamson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Matlack <dmatlack@google.com>

[ Upstream commit 75182529687e204b2bd046a3f7b1c2acb5031032 ]

Allow builds when ARCH=x86 since the top-level Makefile can set ARCH=x86
even for 64-bit x86 builds.

Note that ARCH=x86 could also indicate a native build on a 32-bit x86
host. However, it doesn't seem like anyone is building selftests
natively on 32-bit x86 hosts these days since KVM selftests allow
ARCH=x86 and fail to compile on 32-bit x86.

If someone reports an issue on 32-bit native builds we can harden the
KVM and VFIO selftests to explicitly check 64-bit (see the discussion in
the Closes link below).

Fixes: a55d4bbbe644 ("vfio: selftests: only build tests on arm64 and x86_64")
Reported-by: Jason Gunthorpe <jgg@nvidia.com>
Closes: https://lore.kernel.org/kvm/20260427231217.GA1670652@nvidia.com/
Signed-off-by: David Matlack <dmatlack@google.com>
Reviewed-by: Jason Gunthorpe <jgg@nvidia.com>
Link: https://lore.kernel.org/r/20260428232707.2139059-1-dmatlack@google.com
Signed-off-by: Alex Williamson <alex@shazbot.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/vfio/Makefile | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/selftests/vfio/Makefile b/tools/testing/selftests/vfio/Makefile
index a19b75742342ad..0a4cfd1a6c7ed6 100644
--- a/tools/testing/selftests/vfio/Makefile
+++ b/tools/testing/selftests/vfio/Makefile
@@ -1,6 +1,6 @@
 ARCH ?= $(shell uname -m)
 
-ifeq (,$(filter $(ARCH),aarch64 arm64 x86_64))
+ifeq (,$(filter $(ARCH),aarch64 arm64 x86 x86_64))
 # Do nothing on unsupported architectures
 include ../lib.mk
 else
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0257/2077] nilfs2: Fix return in nilfs_mkdir
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (255 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0256/2077] vfio: selftests: Allow builds when ARCH=x86 Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0258/2077] vfio/xe: avoid duplicate reset in xe_vfio_pci_reset_done Greg Kroah-Hartman
                   ` (740 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hongling Zeng, Ryusuke Konishi,
	Viacheslav Dubeyko, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hongling Zeng <zenghongling@kylinos.cn>

[ Upstream commit e5925f33e4fa9ee313d481557607adce8e30ed2e ]

Return NULL instead of passing zero to ERR_PTR.
  Fixes smatch warning:
     - fs/nilfs2/namei.c:261 nilfs_mkdir() warn: passing zero to 'ERR_PTR'

Fixes: 88d5baf69082 ("Change inode_operations.mkdir to return struct dentry *")
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/nilfs2/namei.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/nilfs2/namei.c b/fs/nilfs2/namei.c
index 40ac679ec56e40..e2fe95de3d71ca 100644
--- a/fs/nilfs2/namei.c
+++ b/fs/nilfs2/namei.c
@@ -258,7 +258,7 @@ static struct dentry *nilfs_mkdir(struct mnt_idmap *idmap, struct inode *dir,
 	else
 		nilfs_transaction_abort(dir->i_sb);
 
-	return ERR_PTR(err);
+	return err ? ERR_PTR(err) : NULL;
 
 out_fail:
 	drop_nlink(inode);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0258/2077] vfio/xe: avoid duplicate reset in xe_vfio_pci_reset_done
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (256 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0257/2077] nilfs2: Fix return in nilfs_mkdir Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0259/2077] net/sched: sch_drr: annotate data-races around cl->deficit Greg Kroah-Hartman
                   ` (739 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, GuoHan Zhao, Kevin Tian,
	Michał Winiarski, Alex Williamson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: GuoHan Zhao <zhaoguohan@kylinos.cn>

[ Upstream commit b9285405c5f6144f4444f97bf3048d865e11cc1d ]

xe_vfio_pci_reset_done() sets deferred_reset and, when it manages to
acquire state_mutex itself, hands the cleanup off to
xe_vfio_pci_state_mutex_unlock().

That helper already clears deferred_reset and runs xe_vfio_pci_reset()
before dropping the mutex. Calling xe_vfio_pci_reset() again right
afterwards repeats the reset handling unnecessarily.

Fixes: 1f5556ec8b9e ("vfio/xe: Add device specific vfio_pci driver variant for Intel graphics")
Signed-off-by: GuoHan Zhao <zhaoguohan@kylinos.cn>
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Acked-by: Michał Winiarski <michal.winiarski@intel.com>
Link: https://lore.kernel.org/r/20260427012128.117051-1-zhaoguohan@kylinos.cn
Signed-off-by: Alex Williamson <alex@shazbot.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/vfio/pci/xe/main.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/drivers/vfio/pci/xe/main.c b/drivers/vfio/pci/xe/main.c
index 4ecadbbfd86ec7..cbff5af385ef53 100644
--- a/drivers/vfio/pci/xe/main.c
+++ b/drivers/vfio/pci/xe/main.c
@@ -135,8 +135,6 @@ static void xe_vfio_pci_reset_done(struct pci_dev *pdev)
 	}
 	spin_unlock(&xe_vdev->reset_lock);
 	xe_vfio_pci_state_mutex_unlock(xe_vdev);
-
-	xe_vfio_pci_reset(xe_vdev);
 }
 
 static const struct pci_error_handlers xe_vfio_pci_err_handlers = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0259/2077] net/sched: sch_drr: annotate data-races around cl->deficit
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (257 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0258/2077] vfio/xe: avoid duplicate reset in xe_vfio_pci_reset_done Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0260/2077] regmap-i2c: fix sparse warning in regmap_smbus_word_write_reg16 Greg Kroah-Hartman
                   ` (738 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit c67b104fd7982162885c5e43057ca761006748e2 ]

drr_dump_class_stats() runs without qdisc spinlock held.

Add missing READ_ONCE()/WRITE_ONCE() annotations around cl->deficit.

Fixes: edb09eb17ed8 ("net: sched: do not acquire qdisc spinlock in qdisc/class stats dump")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260519094618.2632073-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/sch_drr.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/net/sched/sch_drr.c b/net/sched/sch_drr.c
index 925fa0cfd730ce..2eedd3a4322ad5 100644
--- a/net/sched/sch_drr.c
+++ b/net/sched/sch_drr.c
@@ -270,7 +270,7 @@ static int drr_dump_class_stats(struct Qdisc *sch, unsigned long arg,
 
 	memset(&xstats, 0, sizeof(xstats));
 	if (qlen)
-		xstats.deficit = cl->deficit;
+		xstats.deficit = READ_ONCE(cl->deficit);
 
 	if (gnet_stats_copy_basic(d, NULL, &cl->bstats, true) < 0 ||
 	    gnet_stats_copy_rate_est(d, &cl->rate_est) < 0 ||
@@ -362,7 +362,7 @@ static int drr_enqueue(struct sk_buff *skb, struct Qdisc *sch,
 
 	if (!cl_is_active(cl)) {
 		list_add_tail(&cl->alist, &q->active);
-		cl->deficit = cl->quantum;
+		WRITE_ONCE(cl->deficit, cl->quantum);
 	}
 
 	sch->qstats.backlog += len;
@@ -389,7 +389,7 @@ static struct sk_buff *drr_dequeue(struct Qdisc *sch)
 
 		len = qdisc_pkt_len(skb);
 		if (len <= cl->deficit) {
-			cl->deficit -= len;
+			WRITE_ONCE(cl->deficit, cl->deficit - len);
 			skb = qdisc_dequeue_peeked(cl->qdisc);
 			if (unlikely(skb == NULL))
 				goto out;
@@ -403,7 +403,7 @@ static struct sk_buff *drr_dequeue(struct Qdisc *sch)
 			return skb;
 		}
 
-		cl->deficit += cl->quantum;
+		WRITE_ONCE(cl->deficit, cl->deficit + cl->quantum);
 		list_move_tail(&cl->alist, &q->active);
 	}
 out:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0260/2077] regmap-i2c: fix sparse warning in regmap_smbus_word_write_reg16
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (258 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0259/2077] net/sched: sch_drr: annotate data-races around cl->deficit Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0261/2077] media: rockchip: rga: fix too small buffer size Greg Kroah-Hartman
                   ` (737 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, kernel test robot,
	Nishanth Sampath Kumar, Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nishanth Sampath Kumar <nissampa@cisco.com>

[ Upstream commit 34808ac8ddafc3e2c2a59e84eaab0a410e7a0fdc ]

i2c_smbus_write_word_data() expects a plain u16, but cpu_to_le16()
returns __le16 (a sparse-restricted endian type), causing:

  drivers/base/regmap/regmap-i2c.c:340: sparse: incorrect type in
  argument 3 (different base types)
    expected unsigned short [usertype] value
    got restricted __le16 [usertype]

SMBus already defines byte ordering internally, so cpu_to_le16() is
wrong here. Replace it with a plain (u16) cast.

Fixes: bad4bd28abf4 ("regmap-i2c: add SMBus byte/word reg16 bus for adapters lacking I2C_FUNC_I2C")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202605161621.mY5zFh4D-lkp@intel.com/
Signed-off-by: Nishanth Sampath Kumar <nissampa@cisco.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/base/regmap/regmap-i2c.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/base/regmap/regmap-i2c.c b/drivers/base/regmap/regmap-i2c.c
index 31e30dfced192f..51a04961faf7be 100644
--- a/drivers/base/regmap/regmap-i2c.c
+++ b/drivers/base/regmap/regmap-i2c.c
@@ -337,7 +337,7 @@ static int regmap_smbus_word_write_reg16(void *context, const void *data,
 	val = ((u8 *)data)[2];
 
 	return i2c_smbus_write_word_data(i2c, addr_hi,
-					 cpu_to_le16(((u16)val << 8) | addr_lo));
+					 ((u16)val << 8) | addr_lo);
 }
 
 static const struct regmap_bus regmap_smbus_byte_word_reg16 = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0261/2077] media: rockchip: rga: fix too small buffer size
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (259 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0260/2077] regmap-i2c: fix sparse warning in regmap_smbus_word_write_reg16 Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0262/2077] firmware: arm_scmi: Fix OOB in scmi_power_name_get() Greg Kroah-Hartman
                   ` (736 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nicolas Dufresne, Sven Püschel,
	Hans Verkuil, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sven Püschel <s.pueschel@pengutronix.de>

[ Upstream commit 65017e26c065d1240b0512c15867ef1128034fd8 ]

Fix the command buffer size being only a quarter of the actual size.
The RGA_CMDBUF_SIZE macro was potentially intended to specify the length
of the cmdbuf u32 array pointer. But as it's used to specify the size of
the allocation, which is counted in bytes. Therefore adjust the macro
size to bytes as it better matches the variable name and adjust it's
users accordingly.

As the command buffer is relatively small, it probably didn't caused
an issue due to being smaller than a single page.

Fixes: f7e7b48e6d79 ("[media] rockchip/rga: v4l2 m2m support")
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Sven Püschel <s.pueschel@pengutronix.de>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/media/platform/rockchip/rga/rga-hw.c | 2 +-
 drivers/media/platform/rockchip/rga/rga-hw.h | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/media/platform/rockchip/rga/rga-hw.c b/drivers/media/platform/rockchip/rga/rga-hw.c
index 43ed742a164929..d1618bb2475013 100644
--- a/drivers/media/platform/rockchip/rga/rga-hw.c
+++ b/drivers/media/platform/rockchip/rga/rga-hw.c
@@ -414,7 +414,7 @@ static void rga_cmd_set(struct rga_ctx *ctx,
 {
 	struct rockchip_rga *rga = ctx->rga;
 
-	memset(rga->cmdbuf_virt, 0, RGA_CMDBUF_SIZE * 4);
+	memset(rga->cmdbuf_virt, 0, RGA_CMDBUF_SIZE);
 
 	rga_cmd_set_src_addr(ctx, src->dma_desc_pa);
 	/*
diff --git a/drivers/media/platform/rockchip/rga/rga-hw.h b/drivers/media/platform/rockchip/rga/rga-hw.h
index cc6bd7f5b03003..2b8537a5fd0d7a 100644
--- a/drivers/media/platform/rockchip/rga/rga-hw.h
+++ b/drivers/media/platform/rockchip/rga/rga-hw.h
@@ -6,7 +6,7 @@
 #ifndef __RGA_HW_H__
 #define __RGA_HW_H__
 
-#define RGA_CMDBUF_SIZE 0x20
+#define RGA_CMDBUF_SIZE 0x80
 
 /* Hardware limits */
 #define MAX_WIDTH 8192
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0262/2077] firmware: arm_scmi: Fix OOB in scmi_power_name_get()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (260 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0261/2077] media: rockchip: rga: fix too small buffer size Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0263/2077] arm64: dts: qcom: eliza-mtp: Fix the debug UART index Greg Kroah-Hartman
                   ` (735 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Geert Uytterhoeven, Cristian Marussi,
	Sudeep Holla, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Geert Uytterhoeven <geert+renesas@glider.be>

[ Upstream commit f9ef3f66f4b18078e464b7606f9497e4dbeb9905 ]

scmi_power_name_get() does not validate the domain number passed by the
external caller, which may lead to an out-of-bounds access.

Fix this by returning "unknown" for invalid domains, like
scmi_reset_name_get() does.

Fixes: 76a6550990e296a7 ("firmware: arm_scmi: add initial support for power protocol")
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Cristian Marussi <cristian.marussi@arm.com>
Link: https://patch.msgid.link/75caae28bdffb55199a0bc6cac5df112a966c608.1778838987.git.geert+renesas@glider.be
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/firmware/arm_scmi/power.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/firmware/arm_scmi/power.c b/drivers/firmware/arm_scmi/power.c
index bb5062ab8280e0..28ef63a4ecc2e1 100644
--- a/drivers/firmware/arm_scmi/power.c
+++ b/drivers/firmware/arm_scmi/power.c
@@ -204,8 +204,12 @@ scmi_power_name_get(const struct scmi_protocol_handle *ph,
 		    u32 domain)
 {
 	struct scmi_power_info *pi = ph->get_priv(ph);
-	struct power_dom_info *dom = pi->dom_info + domain;
+	struct power_dom_info *dom;
+
+	if (domain >= pi->num_domains)
+		return "unknown";
 
+	dom = pi->dom_info + domain;
 	return dom->name;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0263/2077] arm64: dts: qcom: eliza-mtp: Fix the debug UART index
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (261 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0262/2077] firmware: arm_scmi: Fix OOB in scmi_power_name_get() Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0264/2077] arm64: dts: qcom: kaanapali: Add power-domain and iface clk for ice node Greg Kroah-Hartman
                   ` (734 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Abel Vesa,
	Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Abel Vesa <abel.vesa@oss.qualcomm.com>

[ Upstream commit 179d11c1c0cfaddcfc984edc3c1863ab600f679f ]

The Eliza MTP debug UART is QUPv3 WRAP2 SE5. The existing DTS labels it
as uart14, but the serial-engine index for this block is actually 13.

Rename the SoC UART label and pinctrl state to uart13 and update the MTP
alias and node reference accordingly.

Fixes: af20af39fc09 ("arm64: dts: qcom: Introduce Eliza Soc base dtsi")
Fixes: 2a5d4fc6f3f7 ("arm64: dts: qcom: eliza: Enable Eliza MTP board support")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260515-eliza-dts-fix-debug-uart-and-more-support-v2-1-5ad3da81b9d3@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/eliza-mtp.dts | 4 ++--
 arch/arm64/boot/dts/qcom/eliza.dtsi    | 6 +++---
 2 files changed, 5 insertions(+), 5 deletions(-)

diff --git a/arch/arm64/boot/dts/qcom/eliza-mtp.dts b/arch/arm64/boot/dts/qcom/eliza-mtp.dts
index 90f629800cb02f..4708df8eb4a409 100644
--- a/arch/arm64/boot/dts/qcom/eliza-mtp.dts
+++ b/arch/arm64/boot/dts/qcom/eliza-mtp.dts
@@ -15,7 +15,7 @@ / {
 	chassis-type = "handset";
 
 	aliases {
-		serial0 = &uart14;
+		serial0 = &uart13;
 	};
 
 	chosen {
@@ -382,7 +382,7 @@ &tlmm {
 			       <118 1>;  /* NFC Secure I/O */
 };
 
-&uart14 {
+&uart13 {
 	compatible = "qcom,geni-debug-uart";
 
 	status = "okay";
diff --git a/arch/arm64/boot/dts/qcom/eliza.dtsi b/arch/arm64/boot/dts/qcom/eliza.dtsi
index 7e97361a5dc58c..9edfee5e1dde53 100644
--- a/arch/arm64/boot/dts/qcom/eliza.dtsi
+++ b/arch/arm64/boot/dts/qcom/eliza.dtsi
@@ -639,7 +639,7 @@ qupv3_2: geniqup@8c0000 {
 			#size-cells = <2>;
 			ranges;
 
-			uart14: serial@894000 {
+			uart13: serial@894000 {
 				compatible = "qcom,geni-uart";
 				reg = <0x0 0x00894000 0x0 0x4000>;
 
@@ -655,7 +655,7 @@ &clk_virt SLAVE_QUP_CORE_2 QCOM_ICC_TAG_ALWAYS>,
 				interconnect-names = "qup-core",
 						     "qup-config";
 
-				pinctrl-0 = <&qup_uart14_default>;
+				pinctrl-0 = <&qup_uart13_default>;
 				pinctrl-names = "default";
 
 				status = "disabled";
@@ -1338,7 +1338,7 @@ tlmm: pinctrl@f100000 {
 			gpio-ranges = <&tlmm 0 0 184>;
 			wakeup-parent = <&pdc>;
 
-			qup_uart14_default: qup-uart14-default-state {
+			qup_uart13_default: qup-uart13-default-state {
 				/* TX, RX */
 				pins = "gpio18", "gpio19";
 				function = "qup2_se5";
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0264/2077] arm64: dts: qcom: kaanapali: Add power-domain and iface clk for ice node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (262 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0263/2077] arm64: dts: qcom: eliza-mtp: Fix the debug UART index Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0265/2077] arm64: dts: qcom: lemans: " Greg Kroah-Hartman
                   ` (733 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Kuldeep Singh,
	Harshal Dev, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Harshal Dev <harshal.dev@oss.qualcomm.com>

[ Upstream commit 11b48f6d5ed505ced9cd3645d6615279198a7a54 ]

Qualcomm in-line crypto engine (ICE) platform driver specifies and votes
for its own resources. Before accessing ICE hardware during probe, to
avoid potential unclocked register access issues (when clk_ignore_unused
is not passed on the kernel command line), in addition to the 'core' clock
the 'iface' clock should also be turned on by the driver. This can only be
done if the GCC_UFS_PHY_GDSC power domain is enabled. Specify both the
GCC_UFS_PHY_GDSC power domain and the 'iface' clock in the ICE node for
kaanapali.

Fixes: 2eeb5767d53f4 ("arm64: dts: qcom: Introduce Kaanapali SoC")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Signed-off-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260416-qcom_ice_power_and_clk_vote-v5-3-5ccf5d7e2846@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/kaanapali.dtsi | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/kaanapali.dtsi b/arch/arm64/boot/dts/qcom/kaanapali.dtsi
index 7cc326aa1a1aab..14e362a4899b61 100644
--- a/arch/arm64/boot/dts/qcom/kaanapali.dtsi
+++ b/arch/arm64/boot/dts/qcom/kaanapali.dtsi
@@ -2538,7 +2538,11 @@ ice: crypto@1d88000 {
 				     "qcom,inline-crypto-engine";
 			reg = <0x0 0x01d88000 0x0 0x18000>;
 
-			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>;
+			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>,
+				 <&gcc GCC_UFS_PHY_AHB_CLK>;
+			clock-names = "core",
+				      "iface";
+			power-domains = <&gcc GCC_UFS_PHY_GDSC>;
 		};
 
 		tcsr_mutex: hwlock@1f40000 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0265/2077] arm64: dts: qcom: lemans: Add power-domain and iface clk for ice node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (263 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0264/2077] arm64: dts: qcom: kaanapali: Add power-domain and iface clk for ice node Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:58 ` [PATCH 7.1 0266/2077] arm64: dts: qcom: monaco: " Greg Kroah-Hartman
                   ` (732 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Kuldeep Singh,
	Harshal Dev, Bartosz Golaszewski, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Harshal Dev <harshal.dev@oss.qualcomm.com>

[ Upstream commit 04566e287b35fde9fd129db5fdf6a96e336af55c ]

Qualcomm in-line crypto engine (ICE) platform driver specifies and votes
for its own resources. Before accessing ICE hardware during probe, to
avoid potential unclocked register access issues (when clk_ignore_unused
is not passed on the kernel command line), in addition to the 'core' clock
the 'iface' clock should also be turned on by the driver. This can only be
done if the UFS_PHY_GDSC power domain is enabled. Specify both the
UFS_PHY_GDSC power domain and the 'iface' clock in the ICE node for lemans.

Fixes: 96272ba7103d4 ("arm64: dts: qcom: sa8775p: enable the inline crypto engine")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Signed-off-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260416-qcom_ice_power_and_clk_vote-v5-4-5ccf5d7e2846@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/lemans.dtsi | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/lemans.dtsi b/arch/arm64/boot/dts/qcom/lemans.dtsi
index 5dd271e7108d7a..bf3b13be3af0a8 100644
--- a/arch/arm64/boot/dts/qcom/lemans.dtsi
+++ b/arch/arm64/boot/dts/qcom/lemans.dtsi
@@ -3104,7 +3104,11 @@ ice: crypto@1d88000 {
 			compatible = "qcom,sa8775p-inline-crypto-engine",
 				     "qcom,inline-crypto-engine";
 			reg = <0x0 0x01d88000 0x0 0x18000>;
-			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>;
+			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>,
+				 <&gcc GCC_UFS_PHY_AHB_CLK>;
+			clock-names = "core",
+				      "iface";
+			power-domains = <&gcc UFS_PHY_GDSC>;
 		};
 
 		cryptobam: dma-controller@1dc4000 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0266/2077] arm64: dts: qcom: monaco: Add power-domain and iface clk for ice node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (264 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0265/2077] arm64: dts: qcom: lemans: " Greg Kroah-Hartman
@ 2026-07-21 14:58 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0267/2077] arm64: dts: qcom: sc7180: " Greg Kroah-Hartman
                   ` (731 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:58 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Kuldeep Singh,
	Harshal Dev, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Harshal Dev <harshal.dev@oss.qualcomm.com>

[ Upstream commit 68d5d9701a7ab1b1f9c76feaa3a24ca716f03f0b ]

Qualcomm in-line crypto engine (ICE) platform driver specifies and votes
for its own resources. Before accessing ICE hardware during probe, to
avoid potential unclocked register access issues (when clk_ignore_unused
is not passed on the kernel command line), in addition to the 'core' clock
the 'iface' clock should also be turned on by the driver. This can only be
done if the GCC_UFS_PHY_GDSC power domain is enabled. Specify both the
GCC_UFS_PHY_GDSC power domain and the 'iface' clock in the ICE node for
monaco.

Fixes: cc9d29aad876d ("arm64: dts: qcom: qcs8300: enable the inline crypto engine")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Signed-off-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260416-qcom_ice_power_and_clk_vote-v5-5-5ccf5d7e2846@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/monaco.dtsi | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/monaco.dtsi b/arch/arm64/boot/dts/qcom/monaco.dtsi
index 7b1d57460f1e69..fa13210fc539a6 100644
--- a/arch/arm64/boot/dts/qcom/monaco.dtsi
+++ b/arch/arm64/boot/dts/qcom/monaco.dtsi
@@ -2737,7 +2737,11 @@ ice: crypto@1d88000 {
 			compatible = "qcom,qcs8300-inline-crypto-engine",
 				     "qcom,inline-crypto-engine";
 			reg = <0x0 0x01d88000 0x0 0x18000>;
-			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>;
+			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>,
+				 <&gcc GCC_UFS_PHY_AHB_CLK>;
+			clock-names = "core",
+				      "iface";
+			power-domains = <&gcc GCC_UFS_PHY_GDSC>;
 		};
 
 		crypto: crypto@1dfa000 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0267/2077] arm64: dts: qcom: sc7180: Add power-domain and iface clk for ice node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (265 preceding siblings ...)
  2026-07-21 14:58 ` [PATCH 7.1 0266/2077] arm64: dts: qcom: monaco: " Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0268/2077] arm64: dts: qcom: kodiak: " Greg Kroah-Hartman
                   ` (730 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Kuldeep Singh,
	Harshal Dev, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Harshal Dev <harshal.dev@oss.qualcomm.com>

[ Upstream commit 7cd7271ac525e4eadd22734f418219f247638f43 ]

Qualcomm in-line crypto engine (ICE) platform driver specifies and votes
for its own resources. Before accessing ICE hardware during probe, to
avoid potential unclocked register access issues (when clk_ignore_unused
is not passed on the kernel command line), in addition to the 'core' clock
the 'iface' clock should also be turned on by the driver. This can only be
done if the UFS_PHY_GDSC power domain is enabled. Specify both the
UFS_PHY_GDSC power domain and the 'iface' clock in the ICE node for sc7180.

Fixes: 858536d9dc946 ("arm64: dts: qcom: sc7180: Add UFS nodes")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Signed-off-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260416-qcom_ice_power_and_clk_vote-v5-6-5ccf5d7e2846@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sc7180.dtsi | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/sc7180.dtsi b/arch/arm64/boot/dts/qcom/sc7180.dtsi
index a4b17564469eed..94a699cc26889e 100644
--- a/arch/arm64/boot/dts/qcom/sc7180.dtsi
+++ b/arch/arm64/boot/dts/qcom/sc7180.dtsi
@@ -1605,7 +1605,11 @@ ice: crypto@1d90000 {
 			compatible = "qcom,sc7180-inline-crypto-engine",
 				     "qcom,inline-crypto-engine";
 			reg = <0 0x01d90000 0 0x8000>;
-			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>;
+			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>,
+				 <&gcc GCC_UFS_PHY_AHB_CLK>;
+			clock-names = "core",
+				      "iface";
+			power-domains = <&gcc UFS_PHY_GDSC>;
 		};
 
 		ipa: ipa@1e40000 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0268/2077] arm64: dts: qcom: kodiak: Add power-domain and iface clk for ice node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (266 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0267/2077] arm64: dts: qcom: sc7180: " Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0269/2077] arm64: dts: qcom: sm8450: " Greg Kroah-Hartman
                   ` (729 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Kuldeep Singh,
	Harshal Dev, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Harshal Dev <harshal.dev@oss.qualcomm.com>

[ Upstream commit cca53c338ad87edc4b46d2d82730fd8ca01a164f ]

Qualcomm in-line crypto engine (ICE) platform driver specifies and votes
for its own resources. Before accessing ICE hardware during probe, to
avoid potential unclocked register access issues (when clk_ignore_unused
is not passed on the kernel command line), in addition to the 'core' clock
the 'iface' clock should also be turned on by the driver. This can only be
done if the GCC_UFS_PHY_GDSC power domain is enabled. Specify both the
GCC_UFS_PHY_GDSC power domain and the 'iface' clock in the ICE node for
kodiak.

Fixes: dfd5ee7b34bb7 ("arm64: dts: qcom: sc7280: Add inline crypto engine")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Tested-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Signed-off-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260416-qcom_ice_power_and_clk_vote-v5-7-5ccf5d7e2846@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/kodiak.dtsi | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/kodiak.dtsi b/arch/arm64/boot/dts/qcom/kodiak.dtsi
index fdde9f065199ee..522b2b61ce7d20 100644
--- a/arch/arm64/boot/dts/qcom/kodiak.dtsi
+++ b/arch/arm64/boot/dts/qcom/kodiak.dtsi
@@ -2579,7 +2579,11 @@ ice: crypto@1d88000 {
 			compatible = "qcom,sc7280-inline-crypto-engine",
 				     "qcom,inline-crypto-engine";
 			reg = <0 0x01d88000 0 0x18000>;
-			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>;
+			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>,
+				 <&gcc GCC_UFS_PHY_AHB_CLK>;
+			clock-names = "core",
+				      "iface";
+			power-domains = <&gcc GCC_UFS_PHY_GDSC>;
 		};
 
 		cryptobam: dma-controller@1dc4000 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0269/2077] arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (267 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0268/2077] arm64: dts: qcom: kodiak: " Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0270/2077] arm64: dts: qcom: sm8550: " Greg Kroah-Hartman
                   ` (728 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Kuldeep Singh,
	Harshal Dev, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Harshal Dev <harshal.dev@oss.qualcomm.com>

[ Upstream commit 3a5cb1ccbfb3141862b28f24cd5050083233aae7 ]

Qualcomm in-line crypto engine (ICE) platform driver specifies and votes
for its own resources. Before accessing ICE hardware during probe, to
avoid potential unclocked register access issues (when clk_ignore_unused
is not passed on the kernel command line), in addition to the 'core' clock
the 'iface' clock should also be turned on by the driver. This can only be
done if the UFS_PHY_GDSC power domain is enabled. Specify both the
UFS_PHY_GDSC power domain and the 'iface' clock in the ICE node for sm8450.

Fixes: 86b0aef435851 ("arm64: dts: qcom: sm8450: Use standalone ICE node for UFS")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Signed-off-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260416-qcom_ice_power_and_clk_vote-v5-8-5ccf5d7e2846@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sm8450.dtsi | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/sm8450.dtsi b/arch/arm64/boot/dts/qcom/sm8450.dtsi
index e0c37ce3042a22..47b028259d9101 100644
--- a/arch/arm64/boot/dts/qcom/sm8450.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8450.dtsi
@@ -5374,7 +5374,11 @@ ice: crypto@1d88000 {
 			compatible = "qcom,sm8450-inline-crypto-engine",
 				     "qcom,inline-crypto-engine";
 			reg = <0 0x01d88000 0 0x18000>;
-			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>;
+			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>,
+				 <&gcc GCC_UFS_PHY_AHB_CLK>;
+			clock-names = "core",
+				      "iface";
+			power-domains = <&gcc UFS_PHY_GDSC>;
 		};
 
 		cryptobam: dma-controller@1dc4000 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0270/2077] arm64: dts: qcom: sm8550: Add power-domain and iface clk for ice node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (268 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0269/2077] arm64: dts: qcom: sm8450: " Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0271/2077] arm64: dts: qcom: sm8650: " Greg Kroah-Hartman
                   ` (727 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Kuldeep Singh,
	Harshal Dev, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Harshal Dev <harshal.dev@oss.qualcomm.com>

[ Upstream commit 52696dbbe7bbe0c8fc8c17133ffb5133b8cf37a6 ]

Qualcomm in-line crypto engine (ICE) platform driver specifies and votes
for its own resources. Before accessing ICE hardware during probe, to
avoid potential unclocked register access issues (when clk_ignore_unused
is not passed on the kernel command line), in addition to the 'core' clock
the 'iface' clock should also be turned on by the driver. This can only be
done if the UFS_PHY_GDSC power domain is enabled. Specify both the
UFS_PHY_GDSC power domain and the 'iface' clock in the ICE node for sm8550.

Fixes: b8630c48b43fc ("arm64: dts: qcom: sm8550: Add the Inline Crypto Engine node")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Signed-off-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260416-qcom_ice_power_and_clk_vote-v5-9-5ccf5d7e2846@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sm8550.dtsi | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/sm8550.dtsi b/arch/arm64/boot/dts/qcom/sm8550.dtsi
index 912525e9bca6f5..fe46a5d41fe072 100644
--- a/arch/arm64/boot/dts/qcom/sm8550.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8550.dtsi
@@ -2465,7 +2465,11 @@ ice: crypto@1d88000 {
 				     "qcom,inline-crypto-engine";
 			reg = <0 0x01d88000 0 0x18000>;
 
-			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>;
+			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>,
+				 <&gcc GCC_UFS_PHY_AHB_CLK>;
+			clock-names = "core",
+				      "iface";
+			power-domains = <&gcc UFS_PHY_GDSC>;
 		};
 
 		tcsr_mutex: hwlock@1f40000 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0271/2077] arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (269 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0270/2077] arm64: dts: qcom: sm8550: " Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0272/2077] arm64: dts: qcom: sm8750: " Greg Kroah-Hartman
                   ` (726 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Kuldeep Singh,
	Harshal Dev, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Harshal Dev <harshal.dev@oss.qualcomm.com>

[ Upstream commit c62b084d5d1564f808408a2f7d4c514e57cd4106 ]

Qualcomm in-line crypto engine (ICE) platform driver specifies and votes
for its own resources. Before accessing ICE hardware during probe, to
avoid potential unclocked register access issues (when clk_ignore_unused
is not passed on the kernel command line), in addition to the 'core' clock
the 'iface' clock should also be turned on by the driver. This can only be
done if the UFS_PHY_GDSC power domain is enabled. Specify both the
UFS_PHY_GDSC power domain and the 'iface' clock in the ICE node for sm8650.

Fixes: 10e0246712951 ("arm64: dts: qcom: sm8650: add interconnect dependent device nodes")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Signed-off-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260416-qcom_ice_power_and_clk_vote-v5-10-5ccf5d7e2846@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sm8650.dtsi | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/sm8650.dtsi b/arch/arm64/boot/dts/qcom/sm8650.dtsi
index 1604bc8cff3735..e2d98cf6adca8f 100644
--- a/arch/arm64/boot/dts/qcom/sm8650.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8650.dtsi
@@ -4081,7 +4081,11 @@ ice: crypto@1d88000 {
 				     "qcom,inline-crypto-engine";
 			reg = <0 0x01d88000 0 0x18000>;
 
-			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>;
+			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>,
+				 <&gcc GCC_UFS_PHY_AHB_CLK>;
+			clock-names = "core",
+				      "iface";
+			power-domains = <&gcc UFS_PHY_GDSC>;
 		};
 
 		cryptobam: dma-controller@1dc4000 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0272/2077] arm64: dts: qcom: sm8750: Add power-domain and iface clk for ice node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (270 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0271/2077] arm64: dts: qcom: sm8650: " Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0273/2077] tracing: Bound synthetic-field strings with seq_buf Greg Kroah-Hartman
                   ` (725 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Kuldeep Singh,
	Harshal Dev, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Harshal Dev <harshal.dev@oss.qualcomm.com>

[ Upstream commit 081ac792f0ea6d27a4b130c70cfd7544efee8137 ]

Qualcomm in-line crypto engine (ICE) platform driver specifies and votes
for its own resources. Before accessing ICE hardware during probe, to
avoid potential unclocked register access issues (when clk_ignore_unused
is not passed on the kernel command line), in addition to the 'core' clock
the 'iface' clock should also be turned on by the driver. This can only be
done if the GCC_UFS_PHY_GDSC power domain is enabled. Specify both the
GCC_UFS_PHY_GDSC power domain and the 'iface' clock in the ICE node for
sm8750.

Fixes: b1dac789c650a ("arm64: dts: qcom: sm8750: Add ICE nodes")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Signed-off-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260416-qcom_ice_power_and_clk_vote-v5-11-5ccf5d7e2846@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sm8750.dtsi | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/sm8750.dtsi b/arch/arm64/boot/dts/qcom/sm8750.dtsi
index 320aec62e462d2..2d2f029c2d6fe8 100644
--- a/arch/arm64/boot/dts/qcom/sm8750.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8750.dtsi
@@ -2086,7 +2086,11 @@ ice: crypto@1d88000 {
 				     "qcom,inline-crypto-engine";
 			reg = <0x0 0x01d88000 0x0 0x18000>;
 
-			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>;
+			clocks = <&gcc GCC_UFS_PHY_ICE_CORE_CLK>,
+				 <&gcc GCC_UFS_PHY_AHB_CLK>;
+			clock-names = "core",
+				      "iface";
+			power-domains = <&gcc GCC_UFS_PHY_GDSC>;
 		};
 
 		cryptobam: dma-controller@1dc4000 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0273/2077] tracing: Bound synthetic-field strings with seq_buf
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (271 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0272/2077] arm64: dts: qcom: sm8750: " Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0274/2077] arm64: dts: qcom: lemans: Add eDP ref clock for eDP PHYs Greg Kroah-Hartman
                   ` (724 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mathieu Desnoyers, Tom Zanussi,
	Masami Hiramatsu (Google), Tom Zanussi, Pengpeng Hou,
	Steven Rostedt, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pengpeng Hou <pengpeng@iscas.ac.cn>

[ Upstream commit f07883450eb14d1cf020b55d9f3a7ec5683bcd26 ]

The synthetic field helpers build a prefixed synthetic variable name and
a generated hist command in fixed MAX_FILTER_STR_VAL buffers. The
current code appends those strings with raw strcat(), so long key lists,
field names, or saved filters can run past the end of the staging
buffers.

Build both strings with seq_buf and propagate -E2BIG if either the
synthetic variable name or the generated command exceeds
MAX_FILTER_STR_VAL. This keeps the existing tracing-side limit while
using the helper intended for bounded command construction.

Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Cc: Tom Zanussi <tom.zanussi@linux.intel.com>
Link: https://patch.msgid.link/20260430043350.57928-1-pengpeng@iscas.ac.cn
Fixes: 02205a6752f2 ("tracing: Add support for 'field variables'")
Acked-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Reviewed-by: Tom Zanussi <zanussi@kernel.org>
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ sdr: Moved struct seq_buf *s for upside-down x-mas tree formatting ]
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/trace/trace_events_hist.c | 41 ++++++++++++++++++++++----------
 1 file changed, 29 insertions(+), 12 deletions(-)

diff --git a/kernel/trace/trace_events_hist.c b/kernel/trace/trace_events_hist.c
index eb2c2bc8bc3d52..9701650c89b2f2 100644
--- a/kernel/trace/trace_events_hist.c
+++ b/kernel/trace/trace_events_hist.c
@@ -8,6 +8,7 @@
 #include <linux/module.h>
 #include <linux/kallsyms.h>
 #include <linux/security.h>
+#include <linux/seq_buf.h>
 #include <linux/mutex.h>
 #include <linux/slab.h>
 #include <linux/stacktrace.h>
@@ -2967,13 +2968,22 @@ find_synthetic_field_var(struct hist_trigger_data *target_hist_data,
 {
 	struct hist_field *event_var;
 	char *synthetic_name;
+	struct seq_buf s;
 
 	synthetic_name = kzalloc(MAX_FILTER_STR_VAL, GFP_KERNEL);
 	if (!synthetic_name)
 		return ERR_PTR(-ENOMEM);
 
-	strcpy(synthetic_name, "synthetic_");
-	strcat(synthetic_name, field_name);
+	seq_buf_init(&s, synthetic_name, MAX_FILTER_STR_VAL);
+	seq_buf_printf(&s, "synthetic_%s", field_name);
+
+	/* Terminate synthetic_name with a NUL. */
+	seq_buf_str(&s);
+
+	if (seq_buf_has_overflowed(&s)) {
+		kfree(synthetic_name);
+		return ERR_PTR(-E2BIG);
+	}
 
 	event_var = find_event_var(target_hist_data, system, event_name, synthetic_name);
 
@@ -3019,6 +3029,7 @@ create_field_var_hist(struct hist_trigger_data *target_hist_data,
 	struct hist_field *key_field;
 	struct hist_field *event_var;
 	char *saved_filter;
+	struct seq_buf s;
 	char *cmd;
 	int ret;
 
@@ -3063,28 +3074,34 @@ create_field_var_hist(struct hist_trigger_data *target_hist_data,
 		return ERR_PTR(-ENOMEM);
 	}
 
+	seq_buf_init(&s, cmd, MAX_FILTER_STR_VAL);
+
 	/* Use the same keys as the compatible histogram */
-	strcat(cmd, "keys=");
+	seq_buf_puts(&s, "keys=");
 
 	for_each_hist_key_field(i, hist_data) {
 		key_field = hist_data->fields[i];
 		if (!first)
-			strcat(cmd, ",");
-		strcat(cmd, key_field->field->name);
+			seq_buf_putc(&s, ',');
+		seq_buf_puts(&s, key_field->field->name);
 		first = false;
 	}
 
 	/* Create the synthetic field variable specification */
-	strcat(cmd, ":synthetic_");
-	strcat(cmd, field_name);
-	strcat(cmd, "=");
-	strcat(cmd, field_name);
+	seq_buf_printf(&s, ":synthetic_%s=%s", field_name, field_name);
 
 	/* Use the same filter as the compatible histogram */
 	saved_filter = find_trigger_filter(hist_data, file);
-	if (saved_filter) {
-		strcat(cmd, " if ");
-		strcat(cmd, saved_filter);
+	if (saved_filter)
+		seq_buf_printf(&s, " if %s", saved_filter);
+
+	/* Terminate cmd with a NUL. */
+	seq_buf_str(&s);
+
+	if (seq_buf_has_overflowed(&s)) {
+		kfree(cmd);
+		kfree(var_hist);
+		return ERR_PTR(-E2BIG);
 	}
 
 	var_hist->cmd = kstrdup(cmd, GFP_KERNEL);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0274/2077] arm64: dts: qcom: lemans: Add eDP ref clock for eDP PHYs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (272 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0273/2077] tracing: Bound synthetic-field strings with seq_buf Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0275/2077] arm64: dts: qcom: glymur: Fix wrong interrupt number for i2c19 Greg Kroah-Hartman
                   ` (723 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ritesh Kumar, Konrad Dybcio,
	Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ritesh Kumar <quic_riteshk@quicinc.com>

[ Upstream commit 4bd073e00fd79c0aead74ad64ade48c904221245 ]

The eDP PHY nodes on lemans were missing the reference clock voting.
This initially went unnoticed because the clock was implicitly enabled
by the UFS PHY driver, and the eDP PHY happened to rely on that.

After commit 77d2fa54a945 ("scsi: ufs: qcom : Refactor phy_power_on/off
calls"), the UFS driver no longer keeps the reference clock enabled.
As a result, the eDP PHY fails to power on.

To fix this, add eDP reference clock for eDP PHYs on lemans chipset
ensuring reference clock is enabled.

Fixes: e1e3e5673f8d7 ("arm64: dts: qcom: sa8775p: add DisplayPort device nodes")
Signed-off-by: Ritesh Kumar <quic_riteshk@quicinc.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260128114853.2543416-3-quic_riteshk@quicinc.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/lemans.dtsi | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/arch/arm64/boot/dts/qcom/lemans.dtsi b/arch/arm64/boot/dts/qcom/lemans.dtsi
index bf3b13be3af0a8..3cd8d68cc4f910 100644
--- a/arch/arm64/boot/dts/qcom/lemans.dtsi
+++ b/arch/arm64/boot/dts/qcom/lemans.dtsi
@@ -5658,9 +5658,11 @@ mdss0_dp0_phy: phy@aec2a00 {
 				      <0x0 0x0aec2000 0x0 0x1c8>;
 
 				clocks = <&dispcc0 MDSS_DISP_CC_MDSS_DPTX0_AUX_CLK>,
-					 <&dispcc0 MDSS_DISP_CC_MDSS_AHB_CLK>;
+					 <&dispcc0 MDSS_DISP_CC_MDSS_AHB_CLK>,
+					 <&gcc GCC_EDP_REF_CLKREF_EN>;
 				clock-names = "aux",
-					      "cfg_ahb";
+					      "cfg_ahb",
+					      "ref";
 
 				#clock-cells = <1>;
 				#phy-cells = <0>;
@@ -5677,9 +5679,11 @@ mdss0_dp1_phy: phy@aec5a00 {
 				      <0x0 0x0aec5000 0x0 0x1c8>;
 
 				clocks = <&dispcc0 MDSS_DISP_CC_MDSS_DPTX1_AUX_CLK>,
-					 <&dispcc0 MDSS_DISP_CC_MDSS_AHB_CLK>;
+					 <&dispcc0 MDSS_DISP_CC_MDSS_AHB_CLK>,
+					 <&gcc GCC_EDP_REF_CLKREF_EN>;
 				clock-names = "aux",
-					      "cfg_ahb";
+					      "cfg_ahb",
+					      "ref";
 
 				#clock-cells = <1>;
 				#phy-cells = <0>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0275/2077] arm64: dts: qcom: glymur: Fix wrong interrupt number for i2c19
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (273 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0274/2077] arm64: dts: qcom: lemans: Add eDP ref clock for eDP PHYs Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0276/2077] arm64: dts: qcom: sdm845-xiaomi-beryllium: Correct IPA FW path Greg Kroah-Hartman
                   ` (722 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Gopikrishna Garmidi, Abel Vesa,
	Konrad Dybcio, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Gopikrishna Garmidi <gopikrishna.garmidi@oss.qualcomm.com>

[ Upstream commit ecabfe832b817bd1c1fdb8841d7bc706bf621ef1 ]

The i2c19 node at 0x88c000 uses GIC SPI 584, but that interrupt
belongs to the neighboring i2c18/spi18 node at 0x888000. The correct
interrupt for i2c19 is GIC SPI 585, as used by its sibling nodes
spi19 and uart19 which share the same register base and clock.

Fixes: 41b6e8db400c ("arm64: dts: qcom: Introduce Glymur base dtsi")
Signed-off-by: Gopikrishna Garmidi <gopikrishna.garmidi@oss.qualcomm.com>
Reviewed-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260518-glymur-fix-i2c19-irq-v1-1-7d5968bd9b2b@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/glymur.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/glymur.dtsi b/arch/arm64/boot/dts/qcom/glymur.dtsi
index 780708a9d8d45f..63df60b7e010e2 100644
--- a/arch/arm64/boot/dts/qcom/glymur.dtsi
+++ b/arch/arm64/boot/dts/qcom/glymur.dtsi
@@ -968,7 +968,7 @@ &config_noc SLAVE_QUP_2 QCOM_ICC_TAG_ALWAYS>,
 			i2c19: i2c@88c000 {
 				compatible = "qcom,geni-i2c";
 				reg = <0x0 0x0088c000 0x0 0x4000>;
-				interrupts = <GIC_SPI 584 IRQ_TYPE_LEVEL_HIGH>;
+				interrupts = <GIC_SPI 585 IRQ_TYPE_LEVEL_HIGH>;
 				clocks = <&gcc GCC_QUPV3_WRAP2_S3_CLK>;
 				clock-names = "se";
 				interconnects = <&clk_virt MASTER_QUP_CORE_2 QCOM_ICC_TAG_ALWAYS
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0276/2077] arm64: dts: qcom: sdm845-xiaomi-beryllium: Correct IPA FW path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (274 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0275/2077] arm64: dts: qcom: glymur: Fix wrong interrupt number for i2c19 Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0277/2077] writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount() Greg Kroah-Hartman
                   ` (721 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joel Selvaraj, David Heidelberg,
	Konrad Dybcio, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joel Selvaraj <foss@joelselvaraj.com>

[ Upstream commit f3cd85f60c5eb2d817af6c62465018dd941ce4f3 ]

The path was accidentally reverted back to old while refactoring of the
device-tree.

Fixes: 5bde31dc7b17 ("arm64: dts: qcom: sdm845-xiaomi-beryllium: Add placeholders and sort")
Signed-off-by: Joel Selvaraj <foss@joelselvaraj.com>
Signed-off-by: David Heidelberg <david@ixit.cz>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260429-beryllium-ipa-fix-v1-1-816326ba9047@ixit.cz
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/qcom/sdm845-xiaomi-beryllium-common.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/qcom/sdm845-xiaomi-beryllium-common.dtsi b/arch/arm64/boot/dts/qcom/sdm845-xiaomi-beryllium-common.dtsi
index 1298485c42142a..22354968aeaa30 100644
--- a/arch/arm64/boot/dts/qcom/sdm845-xiaomi-beryllium-common.dtsi
+++ b/arch/arm64/boot/dts/qcom/sdm845-xiaomi-beryllium-common.dtsi
@@ -271,7 +271,7 @@ &ibb {
 &ipa {
 	qcom,gsi-loader = "self";
 	memory-region = <&ipa_fw_mem>;
-	firmware-name = "qcom/sdm845/beryllium/ipa_fws.mbn";
+	firmware-name = "qcom/sdm845/Xiaomi/beryllium/ipa_fws.mbn";
 
 	status = "okay";
 };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0277/2077] writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (275 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0276/2077] arm64: dts: qcom: sdm845-xiaomi-beryllium: Correct IPA FW path Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0278/2077] kernfs: fix suspicious RCU usage in kernfs_put() Greg Kroah-Hartman
                   ` (720 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jan Kara, Baokun Li, Tejun Heo,
	Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Baokun Li <libaokun@linux.alibaba.com>

[ Upstream commit e90a6d668e26e00a72df2d09c173b563468f09c9 ]

Commit e1b849cfa6b6 ("writeback: Avoid contention on wb->list_lock when
switching inodes") replaced the queue_rcu_work() based scheduling of
inode wb switches with a plain queue_work().  Since then no switcher
goes through call_rcu(), so rcu_barrier() in cgroup_writeback_umount()
has no callbacks of its own to wait for.  It still drains unrelated
call_rcu() callbacks from other subsystems on busy systems, which
incidentally slows umount down; drop it.

Fixes: e1b849cfa6b6 ("writeback: Avoid contention on wb->list_lock when switching inodes")
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Baokun Li <libaokun@linux.alibaba.com>
Link: https://patch.msgid.link/20260521095016.2791354-3-libaokun@linux.alibaba.com
Acked-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/fs-writeback.c | 5 -----
 1 file changed, 5 deletions(-)

diff --git a/fs/fs-writeback.c b/fs/fs-writeback.c
index 6766de9f9d75b3..325a30cc35bfb8 100644
--- a/fs/fs-writeback.c
+++ b/fs/fs-writeback.c
@@ -1248,11 +1248,6 @@ void cgroup_writeback_umount(struct super_block *sb)
 		 * will then drain it.
 		 */
 		synchronize_rcu();
-		/*
-		 * Use rcu_barrier() to wait for all pending callbacks to
-		 * ensure that all in-flight wb switches are in the workqueue.
-		 */
-		rcu_barrier();
 		flush_workqueue(isw_wq);
 	}
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0278/2077] kernfs: fix suspicious RCU usage in kernfs_put()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (276 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0277/2077] writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount() Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0279/2077] device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() Greg Kroah-Hartman
                   ` (719 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+0dfe499ea713e0a15bec,
	Conor Kotwasinski, Tejun Heo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Conor Kotwasinski <conorkotwasinski2024@u.northwestern.edu>

[ Upstream commit 0fdde3f2aeadcf8d090ee3edee0aad73fb91f690 ]

Commit 741c10b096bc ("kernfs: Use RCU to access kernfs_node::name.")
converted the WARN_ONCE() in kernfs_put() to read kn->name and
parent->name via rcu_dereference(), but kernfs_put() has callers that
hold neither kernfs_rwsem nor the RCU read lock. The inode eviction
path driven by memory reclaim is one such case:

  kernfs_put+0x53/0x60 fs/kernfs/dir.c:602
  evict+0x3c2/0xad0 fs/inode.c:846
  iput_final fs/inode.c:1966 [inline]
  iput.part.0+0x605/0xf50 fs/inode.c:2015
  iput+0x35/0x40 fs/inode.c:1981
  dentry_unlink_inode+0x2a1/0x490 fs/dcache.c:467
  __dentry_kill+0x1d0/0x600 fs/dcache.c:670
  shrink_dentry_list+0x180/0x5e0 fs/dcache.c:1174
  prune_dcache_sb+0xea/0x150 fs/dcache.c:1256
  super_cache_scan+0x328/0x550 fs/super.c:223
  ...
  kswapd+0x556/0xba0 mm/vmscan.c:7343

lockdep complains with "suspicious RCU usage" whenever the WARN
fires from such a context.

Wrap the rcu_dereference() calls in an RCU read-side critical section.
Gate on the active-ref check so the lock is only taken when the WARN
is about to fire.

Note that this does not address the underlying imbalance in
kn->active that triggers the WARN.

Fixes: 741c10b096bc ("kernfs: Use RCU to access kernfs_node::name.")
Reported-by: syzbot+0dfe499ea713e0a15bec@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0dfe499ea713e0a15bec
Signed-off-by: Conor Kotwasinski <conorkotwasinski2024@u.northwestern.edu>
Acked-by: Tejun Heo <tj@kernel.org>
Link: https://patch.msgid.link/20260416134315.1474726-1-conorkotwasinski2024@u.northwestern.edu
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/kernfs/dir.c | 11 +++++++----
 1 file changed, 7 insertions(+), 4 deletions(-)

diff --git a/fs/kernfs/dir.c b/fs/kernfs/dir.c
index 4f9ade82b08abd..e88b71607f1e51 100644
--- a/fs/kernfs/dir.c
+++ b/fs/kernfs/dir.c
@@ -597,10 +597,13 @@ void kernfs_put(struct kernfs_node *kn)
 	 */
 	parent = kernfs_parent(kn);
 
-	WARN_ONCE(atomic_read(&kn->active) != KN_DEACTIVATED_BIAS,
-		  "kernfs_put: %s/%s: released with incorrect active_ref %d\n",
-		  parent ? rcu_dereference(parent->name) : "",
-		  rcu_dereference(kn->name), atomic_read(&kn->active));
+	if (atomic_read(&kn->active) != KN_DEACTIVATED_BIAS) {
+		guard(rcu)();
+		WARN_ONCE(1,
+			  "kernfs_put: %s/%s: released with incorrect active_ref %d\n",
+			  parent ? rcu_dereference(parent->name) : "",
+			  rcu_dereference(kn->name), atomic_read(&kn->active));
+	}
 
 	if (kernfs_type(kn) == KERNFS_LINK)
 		kernfs_put(kn->symlink.target_kn);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0279/2077] device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (277 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0278/2077] kernfs: fix suspicious RCU usage in kernfs_put() Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0280/2077] driver core: Use mod_delayed_work to prevent lost deferred probe work Greg Kroah-Hartman
                   ` (718 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Stepan Ionichev, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stepan Ionichev <sozdayvek@gmail.com>

[ Upstream commit 9582485a65eacfd7245ec7f0a9d7e2c34749d669 ]

When called with FWNODE_GRAPH_ENDPOINT_NEXT, the function walks every
endpoint under the requested port and, for any endpoint whose ID is
greater than or equal to the requested one, may store a fwnode
reference in best_ep via fwnode_handle_get(). If a later iteration
finds an exact-ID match, the function returns that endpoint directly
without dropping the reference held by best_ep, leaking it.

Drop the saved candidate before returning the exact-match endpoint.

This affects callers that use FWNODE_GRAPH_ENDPOINT_NEXT to ask for
the next endpoint with ID >= the requested one (used by a number of
media drivers, e.g. imx7/8, sun6i CSI, omap3isp, xilinx-csi2,
stm32-csi). Each leak retains a fwnode reference until reboot/unbind.

Fixes: 0fcc2bdc8aff ("device property: Add fwnode_graph_get_endpoint_by_id()")
Signed-off-by: Stepan Ionichev <sozdayvek@gmail.com>
Link: https://patch.msgid.link/20260514171455.27271-1-sozdayvek@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/base/property.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/base/property.c b/drivers/base/property.c
index 8e0148a37fffb4..e08eadd66f4f9f 100644
--- a/drivers/base/property.c
+++ b/drivers/base/property.c
@@ -1277,8 +1277,10 @@ fwnode_graph_get_endpoint_by_id(const struct fwnode_handle *fwnode,
 		if (fwnode_ep.port != port)
 			continue;
 
-		if (fwnode_ep.id == endpoint)
+		if (fwnode_ep.id == endpoint) {
+			fwnode_handle_put(best_ep);
 			return ep;
+		}
 
 		if (!endpoint_next)
 			continue;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0280/2077] driver core: Use mod_delayed_work to prevent lost deferred probe work
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (278 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0279/2077] device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0281/2077] Revert "treewide: Fix probing of devices in DT overlays" Greg Kroah-Hartman
                   ` (717 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Zhang Yuwei, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhang Yuwei <zhangyuwei20@huawei.com>

[ Upstream commit 1137838865bfc9a7cd5869c1dc5c22aa45ec12c8 ]

The deferred_probe_timeout_work may be permanently and unexpectedly
canceled when deferred_probe_extend_timeout() executes concurrently.
Starting with deferred_probe_timeout_work pending, the problem can
occur after the following sequence:

  CPU0                                 CPU1
deferred_probe_extend_timeout
  -> cancel_delayed_work() => true
                                   deferred_probe_extend_timeout
                                     -> cancel_delayed_work()
                                       -> __cancel_work()
                                         -> try_grab_pending()
  -> schedule_delayed_work()
    -> queue_delayed_work_on()
(Since the pending bit is grabbed,
 it just returns without queuing)
                                         -> set_work_pool_and_clear_pending()
                                  (This __cancel_work() returns false and
                                     the work will never be queued again)

The root cause is that the WORK_STRUCT_PENDING_BIT of the work_struct
is set temporarily in __cancel_work() (via try_grab_pending()). This
transient state prevents the work_struct from being successfully queued
by another CPU.

To fix this, replace the original non-atomic cancel and schedule
mechanism with mod_delayed_work(). This ensures the modification is
handled atomically and guarantees that the work is not lost.

Fixes: 2b28a1a84a0e ("driver core: Extend deferred probe timeout on driver registration")
Signed-off-by: Zhang Yuwei <zhangyuwei20@huawei.com>
Link: https://patch.msgid.link/20260410024448.387231-1-zhangyuwei20@huawei.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/base/dd.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

diff --git a/drivers/base/dd.c b/drivers/base/dd.c
index 1dc1e3528043c3..3523a5d8ec5030 100644
--- a/drivers/base/dd.c
+++ b/drivers/base/dd.c
@@ -323,12 +323,10 @@ void deferred_probe_extend_timeout(void)
 	 * If the work hasn't been queued yet or if the work expired, don't
 	 * start a new one.
 	 */
-	if (cancel_delayed_work(&deferred_probe_timeout_work)) {
-		schedule_delayed_work(&deferred_probe_timeout_work,
-				driver_deferred_probe_timeout * HZ);
+	if (mod_delayed_work(system_wq, &deferred_probe_timeout_work,
+						 driver_deferred_probe_timeout))
 		pr_debug("Extended deferred probe timeout by %d secs\n",
 					driver_deferred_probe_timeout);
-	}
 }
 
 /**
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0281/2077] Revert "treewide: Fix probing of devices in DT overlays"
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (279 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0280/2077] driver core: Use mod_delayed_work to prevent lost deferred probe work Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0282/2077] of: dynamic: Fix overlayed devices not probing because of fw_devlink Greg Kroah-Hartman
                   ` (716 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Herve Codina, Saravana Kannan,
	Mark Brown, Rob Herring (Arm), Sasha Levin, Wolfram Sang

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Saravana Kannan <saravanak@google.com>

[ Upstream commit aaf08c52df9a19148731d4a3cfd85d98455db901 ]

This reverts commit 1a50d9403fb90cbe4dea0ec9fd0351d2ecbd8924.

While the commit fixed fw_devlink overlay handling for one case, it
broke it for another case. So revert it and redo the fix in a separate
patch.

Fixes: 1a50d9403fb9 ("treewide: Fix probing of devices in DT overlays")
Reported-by: Herve Codina <herve.codina@bootlin.com>
Closes: https://lore.kernel.org/lkml/CAMuHMdXEnSD4rRJ-o90x4OprUacN_rJgyo8x6=9F9rZ+-KzjOg@mail.gmail.com/
Closes: https://lore.kernel.org/all/20240221095137.616d2aaa@bootlin.com/
Closes: https://lore.kernel.org/lkml/20240312151835.29ef62a0@bootlin.com/
Signed-off-by: Saravana Kannan <saravanak@google.com>
Link: https://lore.kernel.org/lkml/20240411235623.1260061-2-saravanak@google.com/

[Herve: Fix conflicts due to f72e77c33e4b ("device property: Make
modifications of fwnode "flags" thread safe")]

Signed-off-by: Herve Codina <herve.codina@bootlin.com>
Acked-by: Mark Brown <broonie@kernel.org>
Acked-by: Rob Herring (Arm) <robh@kernel.org>
Acked-by: Wolfram Sang <wsa+renesas@sang-engineering.com> # for I2C
Link: https://patch.msgid.link/20260511155755.34428-2-herve.codina@bootlin.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/bus/imx-weim.c    | 6 ------
 drivers/i2c/i2c-core-of.c | 5 -----
 drivers/of/dynamic.c      | 1 -
 drivers/of/platform.c     | 5 -----
 drivers/spi/spi.c         | 5 -----
 5 files changed, 22 deletions(-)

diff --git a/drivers/bus/imx-weim.c b/drivers/bus/imx-weim.c
index f735e0462c55ee..87070155b05724 100644
--- a/drivers/bus/imx-weim.c
+++ b/drivers/bus/imx-weim.c
@@ -327,12 +327,6 @@ static int of_weim_notify(struct notifier_block *nb, unsigned long action,
 				 "Failed to setup timing for '%pOF'\n", rd->dn);
 
 		if (!of_node_check_flag(rd->dn, OF_POPULATED)) {
-			/*
-			 * Clear the flag before adding the device so that
-			 * fw_devlink doesn't skip adding consumers to this
-			 * device.
-			 */
-			fwnode_clear_flag(&rd->dn->fwnode, FWNODE_FLAG_NOT_DEVICE);
 			if (!of_platform_device_create(rd->dn, NULL, &pdev->dev)) {
 				dev_err(&pdev->dev,
 					"Failed to create child device '%pOF'\n",
diff --git a/drivers/i2c/i2c-core-of.c b/drivers/i2c/i2c-core-of.c
index 354a88d0599e3e..30b48a428c0be6 100644
--- a/drivers/i2c/i2c-core-of.c
+++ b/drivers/i2c/i2c-core-of.c
@@ -176,11 +176,6 @@ static int of_i2c_notify(struct notifier_block *nb, unsigned long action,
 			return NOTIFY_OK;
 		}
 
-		/*
-		 * Clear the flag before adding the device so that fw_devlink
-		 * doesn't skip adding consumers to this device.
-		 */
-		fwnode_clear_flag(&rd->dn->fwnode, FWNODE_FLAG_NOT_DEVICE);
 		client = of_i2c_register_device(adap, rd->dn);
 		if (IS_ERR(client)) {
 			dev_err(&adap->dev, "failed to create client for '%pOF'\n",
diff --git a/drivers/of/dynamic.c b/drivers/of/dynamic.c
index ade288372101bb..aa450425ec1e6a 100644
--- a/drivers/of/dynamic.c
+++ b/drivers/of/dynamic.c
@@ -225,7 +225,6 @@ static void __of_attach_node(struct device_node *np)
 	np->sibling = np->parent->child;
 	np->parent->child = np;
 	of_node_clear_flag(np, OF_DETACHED);
-	fwnode_set_flag(&np->fwnode, FWNODE_FLAG_NOT_DEVICE);
 
 	raw_spin_unlock_irqrestore(&devtree_lock, flags);
 
diff --git a/drivers/of/platform.c b/drivers/of/platform.c
index a42224f9d1a888..53bca8c6f7810c 100644
--- a/drivers/of/platform.c
+++ b/drivers/of/platform.c
@@ -744,11 +744,6 @@ static int of_platform_notify(struct notifier_block *nb,
 		if (of_node_check_flag(rd->dn, OF_POPULATED))
 			return NOTIFY_OK;
 
-		/*
-		 * Clear the flag before adding the device so that fw_devlink
-		 * doesn't skip adding consumers to this device.
-		 */
-		fwnode_clear_flag(&rd->dn->fwnode, FWNODE_FLAG_NOT_DEVICE);
 		/* pdev_parent may be NULL when no bus platform device */
 		pdev_parent = of_find_device_by_node(parent);
 		pdev = of_platform_device_create(rd->dn, NULL,
diff --git a/drivers/spi/spi.c b/drivers/spi/spi.c
index 104279858f567b..889e1eecc75737 100644
--- a/drivers/spi/spi.c
+++ b/drivers/spi/spi.c
@@ -5003,11 +5003,6 @@ static int of_spi_notify(struct notifier_block *nb, unsigned long action,
 			return NOTIFY_OK;
 		}
 
-		/*
-		 * Clear the flag before adding the device so that fw_devlink
-		 * doesn't skip adding consumers to this device.
-		 */
-		fwnode_clear_flag(&rd->dn->fwnode, FWNODE_FLAG_NOT_DEVICE);
 		spi = of_register_spi_device(ctlr, rd->dn);
 		put_device(&ctlr->dev);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0282/2077] of: dynamic: Fix overlayed devices not probing because of fw_devlink
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (280 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0281/2077] Revert "treewide: Fix probing of devices in DT overlays" Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0283/2077] crypto: eip93 - fix reset ring register definition Greg Kroah-Hartman
                   ` (715 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Herve Codina, Saravana Kannan,
	Kalle Niemi, Geert Uytterhoeven, Rob Herring (Arm), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Saravana Kannan <saravanak@google.com>

[ Upstream commit 81e7c6befa36cecdcbf7244393bd67e8f8c59bf5 ]

When an overlay is applied, if the target device has already probed
successfully and bound to a device, then some of the fw_devlink logic
that ran when the device was probed needs to be rerun. This allows newly
created dangling consumers of the overlayed device tree nodes to be
moved to become consumers of the target device.

[Herve: Add the call to driver_deferred_probe_trigger()]
[Herve: Use fwnode_test_flag() to test fwnode flags value]

Fixes: 1a50d9403fb9 ("treewide: Fix probing of devices in DT overlays")
Reported-by: Herve Codina <herve.codina@bootlin.com>
Closes: https://lore.kernel.org/lkml/CAMuHMdXEnSD4rRJ-o90x4OprUacN_rJgyo8x6=9F9rZ+-KzjOg@mail.gmail.com/
Closes: https://lore.kernel.org/all/20240221095137.616d2aaa@bootlin.com/
Closes: https://lore.kernel.org/lkml/20240312151835.29ef62a0@bootlin.com/
Signed-off-by: Saravana Kannan <saravanak@google.com>
Link: https://lore.kernel.org/lkml/20240411235623.1260061-3-saravanak@google.com/
[Herve: Rebase on top of recent kernel]
Signed-off-by: Herve Codina <herve.codina@bootlin.com>
Tested-by: Kalle Niemi <kaleposti@gmail.com>
Tested-by: Geert Uytterhoeven <geert+renesas@glider.be>
Acked-by: Rob Herring (Arm) <robh@kernel.org>
Link: https://patch.msgid.link/20260511155755.34428-3-herve.codina@bootlin.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/base/core.c    | 83 +++++++++++++++++++++++++++++++++++++-----
 drivers/of/overlay.c   | 15 ++++++++
 include/linux/fwnode.h |  1 +
 3 files changed, 90 insertions(+), 9 deletions(-)

diff --git a/drivers/base/core.c b/drivers/base/core.c
index bd2ddf2aab505f..478aa3fbf1e83f 100644
--- a/drivers/base/core.c
+++ b/drivers/base/core.c
@@ -235,6 +235,79 @@ static void __fw_devlink_pickup_dangling_consumers(struct fwnode_handle *fwnode,
 		__fw_devlink_pickup_dangling_consumers(child, new_sup);
 }
 
+static void fw_devlink_pickup_dangling_consumers(struct device *dev)
+{
+	struct fwnode_handle *child;
+
+	guard(mutex)(&fwnode_link_lock);
+
+	fwnode_for_each_available_child_node(dev->fwnode, child)
+		__fw_devlink_pickup_dangling_consumers(child, dev->fwnode);
+	__fw_devlink_link_to_consumers(dev);
+}
+
+/**
+ * fw_devlink_refresh_fwnode - Recheck the tree under this firmware node
+ * @fwnode: The fwnode under which the fwnode tree has changed
+ *
+ * This function is mainly meant to adjust the supplier/consumer dependencies
+ * after a fwnode tree overlay has occurred.
+ */
+void fw_devlink_refresh_fwnode(struct fwnode_handle *fwnode)
+{
+	struct device *dev;
+
+	/*
+	 * Find the closest ancestor fwnode that has been converted to a device
+	 * that can bind to a driver (bus device).
+	 */
+	fwnode_handle_get(fwnode);
+	do {
+		if (fwnode_test_flag(fwnode, FWNODE_FLAG_NOT_DEVICE))
+			continue;
+
+		dev = get_dev_from_fwnode(fwnode);
+		if (!dev)
+			continue;
+
+		if (dev->bus)
+			break;
+
+		put_device(dev);
+	} while ((fwnode = fwnode_get_next_parent(fwnode)));
+
+	/*
+	 * If none of the ancestor fwnodes have (yet) been converted to a device
+	 * that can bind to a driver, there's nothing to fix up.
+	 */
+	if (!fwnode)
+		return;
+
+	WARN(device_is_bound(dev) && dev->links.status != DL_DEV_DRIVER_BOUND,
+	     "Don't multithread overlaying and probing the same device!\n");
+
+	/*
+	 * If the device has already bound to a driver, then we need to redo
+	 * some of the work that was done after the device was bound to a
+	 * driver. If the device hasn't bound to a driver, running things too
+	 * soon would incorrectly pick up consumers that it shouldn't.
+	 */
+	if (dev->links.status == DL_DEV_DRIVER_BOUND) {
+		fw_devlink_pickup_dangling_consumers(dev);
+		/*
+		 * Some of dangling consumers could have been put previously in
+		 * the deferred probe list due to the unavailability of their
+		 * suppliers. Those consumers have been picked up and some of
+		 * their suppliers links have been updated. Time to re-try their
+		 * probe sequence.
+		 */
+		driver_deferred_probe_trigger();
+	}
+
+	put_device(dev);
+	fwnode_handle_put(fwnode);
+}
+
 static DEFINE_MUTEX(device_links_lock);
 DEFINE_STATIC_SRCU(device_links_srcu);
 
@@ -1312,16 +1385,8 @@ void device_links_driver_bound(struct device *dev)
 	 * child firmware node.
 	 */
 	if (dev->fwnode && dev->fwnode->dev == dev) {
-		struct fwnode_handle *child;
-
 		fwnode_links_purge_suppliers(dev->fwnode);
-
-		guard(mutex)(&fwnode_link_lock);
-
-		fwnode_for_each_available_child_node(dev->fwnode, child)
-			__fw_devlink_pickup_dangling_consumers(child,
-							       dev->fwnode);
-		__fw_devlink_link_to_consumers(dev);
+		fw_devlink_pickup_dangling_consumers(dev);
 	}
 	device_remove_file(dev, &dev_attr_waiting_for_supplier);
 
diff --git a/drivers/of/overlay.c b/drivers/of/overlay.c
index c1c5686fc7b19e..4e45f3414c2c1c 100644
--- a/drivers/of/overlay.c
+++ b/drivers/of/overlay.c
@@ -185,6 +185,15 @@ static int overlay_notify(struct overlay_changeset *ovcs,
 	return 0;
 }
 
+static void overlay_fw_devlink_refresh(struct overlay_changeset *ovcs)
+{
+	for (int i = 0; i < ovcs->count; i++) {
+		struct device_node *np = ovcs->fragments[i].target;
+
+		fw_devlink_refresh_fwnode(of_fwnode_handle(np));
+	}
+}
+
 /*
  * The values of properties in the "/__symbols__" node are paths in
  * the ovcs->overlay_root.  When duplicating the properties, the paths
@@ -951,6 +960,12 @@ static int of_overlay_apply(struct overlay_changeset *ovcs,
 		pr_err("overlay apply changeset entry notify error %d\n", ret);
 	/* notify failure is not fatal, continue */
 
+	/*
+	 * Needs to happen after changeset notify to give the listeners a chance
+	 * to finish creating all the devices they need to create.
+	 */
+	overlay_fw_devlink_refresh(ovcs);
+
 	ret_tmp = overlay_notify(ovcs, OF_OVERLAY_POST_APPLY);
 	if (ret_tmp)
 		if (!ret)
diff --git a/include/linux/fwnode.h b/include/linux/fwnode.h
index 31df7608737e70..5e9cef1e4d448e 100644
--- a/include/linux/fwnode.h
+++ b/include/linux/fwnode.h
@@ -251,6 +251,7 @@ int fwnode_link_add(struct fwnode_handle *con, struct fwnode_handle *sup,
 		    u8 flags);
 void fwnode_links_purge(struct fwnode_handle *fwnode);
 void fw_devlink_purge_absent_suppliers(struct fwnode_handle *fwnode);
+void fw_devlink_refresh_fwnode(struct fwnode_handle *fwnode);
 bool fw_devlink_is_strict(void);
 
 #endif
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0283/2077] crypto: eip93 - fix reset ring register definition
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (281 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0282/2077] of: dynamic: Fix overlayed devices not probing because of fw_devlink Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0284/2077] ASoC: mediatek: mt8189: Fix probe resource cleanup Greg Kroah-Hartman
                   ` (714 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Benjamin Larsson,
	Aleksander Jan Bajkowski, Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aleksander Jan Bajkowski <olek2@wp.pl>

[ Upstream commit 09e6b79b8ce388993aec9ac91b1cb2c181c27bd9 ]

This patch fixes a descriptor ring reset. This causes a hang in the
driver's unload/load sequence.

Fixes: 9739f5f93b78 ("crypto: eip93 - Add Inside Secure SafeXcel EIP-93 crypto engine support")
Suggested-by: Benjamin Larsson <benjamin.larsson@genexis.eu>
Signed-off-by: Aleksander Jan Bajkowski <olek2@wp.pl>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/inside-secure/eip93/eip93-regs.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/crypto/inside-secure/eip93/eip93-regs.h b/drivers/crypto/inside-secure/eip93/eip93-regs.h
index 96285ca6fbbe89..96d28c6651bdb7 100644
--- a/drivers/crypto/inside-secure/eip93/eip93-regs.h
+++ b/drivers/crypto/inside-secure/eip93/eip93-regs.h
@@ -103,7 +103,7 @@
 #define   EIP93_PE_TARGET_COMMAND_NO_RDR_MODE	FIELD_PREP(EIP93_PE_CONFIG_PE_MODE, 0x2)
 #define   EIP93_PE_TARGET_COMMAND_WITH_RDR_MODE	FIELD_PREP(EIP93_PE_CONFIG_PE_MODE, 0x1)
 #define   EIP93_PE_DIRECT_HOST_MODE		FIELD_PREP(EIP93_PE_CONFIG_PE_MODE, 0x0)
-#define   EIP93_PE_CONFIG_RST_RING		BIT(2)
+#define   EIP93_PE_CONFIG_RST_RING		BIT(1)
 #define   EIP93_PE_CONFIG_RST_PE		BIT(0)
 #define EIP93_REG_PE_STATUS			0x104
 #define EIP93_REG_PE_BUF_THRESH			0x10c
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0284/2077] ASoC: mediatek: mt8189: Fix probe resource cleanup
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (282 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0283/2077] crypto: eip93 - fix reset ring register definition Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0285/2077] drm/msm/mdss: correct UBWC programming sequences Greg Kroah-Hartman
                   ` (713 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cássio Gabriel <cassiogabrielcontato@gmail.com>

[ Upstream commit 5404599c3292a12dfc6a3b604cebb5d51064f553 ]

The MT8189 AFE probe assigns reserved memory with
of_reserved_mem_device_init(), but only releases that assignment from
.remove().  If probe fails after the reserved memory has been assigned,
the assignment record is left behind.

The probe path also uses pm_runtime_get_sync() without checking its
return value.  If runtime resume fails, pm_runtime_get_sync() leaves the
usage count incremented and the driver continues initialization without
the device being resumed.  Use pm_runtime_resume_and_get() so resume
errors abort probe without leaking a PM usage count.

Finally, component registration failure currently jumps to a label that
drops a runtime PM reference even though the temporary probe reference
was already released.  Return the component registration error directly,
and do not drop an unmatched PM reference from .remove().

Fixes: 7eb153585598 ("ASoC: mediatek: mt8189: add platform driver")
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260514-asoc-mt8189-probe-cleanup-v1-1-ded733363281@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/mediatek/mt8189/mt8189-afe-pcm.c | 38 ++++++++++++++++------
 1 file changed, 28 insertions(+), 10 deletions(-)

diff --git a/sound/soc/mediatek/mt8189/mt8189-afe-pcm.c b/sound/soc/mediatek/mt8189/mt8189-afe-pcm.c
index 24b0c78815f61f..77cf2b604f6ce8 100644
--- a/sound/soc/mediatek/mt8189/mt8189-afe-pcm.c
+++ b/sound/soc/mediatek/mt8189/mt8189-afe-pcm.c
@@ -2351,9 +2351,13 @@ static int mt8189_afe_runtime_resume(struct device *dev)
 static int mt8189_afe_component_probe(struct snd_soc_component *component)
 {
 	struct mtk_base_afe *afe = snd_soc_component_get_drvdata(component);
+	int ret;
 
 	/* enable clock for regcache get default value from hw */
-	pm_runtime_get_sync(afe->dev);
+	ret = pm_runtime_resume_and_get(afe->dev);
+	if (ret)
+		return dev_err_probe(afe->dev, ret, "failed to resume device\n");
+
 	mtk_afe_add_sub_dai_control(component);
 	pm_runtime_put_sync(afe->dev);
 
@@ -2417,6 +2421,11 @@ static const struct reg_sequence mt8189_cg_patch[] = {
 	{ AUDIO_TOP_CON4, 0x361c },
 };
 
+static void mt8189_afe_release_reserved_mem(void *data)
+{
+	of_reserved_mem_device_release(data);
+}
+
 static int mt8189_afe_pcm_dev_probe(struct platform_device *pdev)
 {
 	int ret, i;
@@ -2431,8 +2440,15 @@ static int mt8189_afe_pcm_dev_probe(struct platform_device *pdev)
 		return ret;
 
 	ret = of_reserved_mem_device_init(dev);
-	if (ret)
+	if (ret) {
 		dev_warn(dev, "failed to assign memory region: %d\n", ret);
+	} else {
+		ret = devm_add_action_or_reset(dev,
+					       mt8189_afe_release_reserved_mem,
+					       dev);
+		if (ret)
+			return ret;
+	}
 
 	afe = devm_kzalloc(dev, sizeof(*afe), GFP_KERNEL);
 	if (!afe)
@@ -2533,18 +2549,22 @@ static int mt8189_afe_pcm_dev_probe(struct platform_device *pdev)
 	dev_pm_syscore_device(dev, true);
 
 	/* enable clock for regcache get default value from hw */
-	pm_runtime_get_sync(dev);
+	ret = pm_runtime_resume_and_get(dev);
+	if (ret)
+		return dev_err_probe(dev, ret, "failed to resume device\n");
 
 	afe->regmap = devm_regmap_init_mmio(dev, afe->base_addr,
 					    &mt8189_afe_regmap_config);
-	if (IS_ERR(afe->regmap))
-		return PTR_ERR(afe->regmap);
+	if (IS_ERR(afe->regmap)) {
+		ret = PTR_ERR(afe->regmap);
+		goto err_pm_put;
+	}
 
 	ret = regmap_register_patch(afe->regmap, mt8189_cg_patch,
 				    ARRAY_SIZE(mt8189_cg_patch));
 	if (ret < 0) {
 		dev_err(dev, "Failed to apply cg patch\n");
-		goto err_pm_disable;
+		goto err_pm_put;
 	}
 
 	regmap_read(afe->regmap, AFE_IRQ_MCU_EN, &tmp_reg);
@@ -2563,12 +2583,12 @@ static int mt8189_afe_pcm_dev_probe(struct platform_device *pdev)
 					      afe->num_dai_drivers);
 	if (ret) {
 		dev_err(dev, "afe component err: %d\n", ret);
-		goto err_pm_disable;
+		return ret;
 	}
 
 	return 0;
 
-err_pm_disable:
+err_pm_put:
 	pm_runtime_put_sync(dev);
 	return ret;
 }
@@ -2578,14 +2598,12 @@ static void mt8189_afe_pcm_dev_remove(struct platform_device *pdev)
 	struct mtk_base_afe *afe = platform_get_drvdata(pdev);
 	struct device *dev = &pdev->dev;
 
-	pm_runtime_put_sync(dev);
 	if (!pm_runtime_status_suspended(dev))
 		mt8189_afe_runtime_suspend(dev);
 
 	mt8189_afe_disable_main_clock(afe);
 	/* disable afe clock */
 	mt8189_afe_disable_reg_rw_clk(afe);
-	of_reserved_mem_device_release(dev);
 }
 
 static const struct of_device_id mt8189_afe_pcm_dt_match[] = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0285/2077] drm/msm/mdss: correct UBWC programming sequences
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (283 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0284/2077] ASoC: mediatek: mt8189: Fix probe resource cleanup Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0286/2077] cpufreq: Documentation: fix sampling_down_factor range Greg Kroah-Hartman
                   ` (712 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Dmitry Baryshkov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>

[ Upstream commit 78de481c75c34623f450abf0f4604344f9396593 ]

The UBWC registers in the MDSS region are not dependent on the UBWC
version (it is an invalid assumption we inherited from the vendor SDE
driver). Instead they are dependent only on the MDSS core revision.

Rework UBWC programming to follow MDSS revision and to use required (aka
encoder) UBWC version instead of the ubwc_dec_version.

Fixes: d68db6069a8e ("drm/msm/mdss: convert UBWC setup to use match data")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/723384/
Link: https://lore.kernel.org/r/20260507-ubwc-rework-v4-1-c19593d20c1d@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/msm/msm_mdss.c | 115 ++++++++++++---------------------
 1 file changed, 41 insertions(+), 74 deletions(-)

diff --git a/drivers/gpu/drm/msm/msm_mdss.c b/drivers/gpu/drm/msm/msm_mdss.c
index 90c3fa0681a06b..4a6acd468bc84c 100644
--- a/drivers/gpu/drm/msm/msm_mdss.c
+++ b/drivers/gpu/drm/msm/msm_mdss.c
@@ -166,22 +166,19 @@ static int _msm_mdss_irq_domain_add(struct msm_mdss *msm_mdss)
 	return 0;
 }
 
-static void msm_mdss_setup_ubwc_dec_20(struct msm_mdss *msm_mdss)
+static void msm_mdss_4x_setup_ubwc(struct msm_mdss *msm_mdss)
 {
 	const struct qcom_ubwc_cfg_data *data = msm_mdss->mdss_data;
-	u32 value = MDSS_UBWC_STATIC_UBWC_SWIZZLE(data->ubwc_swizzle) |
+	u32 value = MDSS_UBWC_STATIC_UBWC_SWIZZLE(data->ubwc_swizzle & 0x1) |
 		    MDSS_UBWC_STATIC_HIGHEST_BANK_BIT(data->highest_bank_bit - 13);
 
-	if (data->ubwc_bank_spread)
-		value |= MDSS_UBWC_STATIC_UBWC_BANK_SPREAD;
-
 	if (data->ubwc_enc_version == UBWC_1_0)
 		value |= MDSS_UBWC_STATIC_UBWC_MIN_ACC_LEN(1);
 
 	writel_relaxed(value, msm_mdss->mmio + REG_MDSS_UBWC_STATIC);
 }
 
-static void msm_mdss_setup_ubwc_dec_30(struct msm_mdss *msm_mdss)
+static void msm_mdss_5x_setup_ubwc(struct msm_mdss *msm_mdss)
 {
 	const struct qcom_ubwc_cfg_data *data = msm_mdss->mdss_data;
 	u32 value = MDSS_UBWC_STATIC_UBWC_SWIZZLE(data->ubwc_swizzle & 0x1) |
@@ -199,11 +196,12 @@ static void msm_mdss_setup_ubwc_dec_30(struct msm_mdss *msm_mdss)
 	writel_relaxed(value, msm_mdss->mmio + REG_MDSS_UBWC_STATIC);
 }
 
-static void msm_mdss_setup_ubwc_dec_40(struct msm_mdss *msm_mdss)
+static void msm_mdss_6x_setup_ubwc(struct msm_mdss *msm_mdss)
 {
 	const struct qcom_ubwc_cfg_data *data = msm_mdss->mdss_data;
 	u32 value = MDSS_UBWC_STATIC_UBWC_SWIZZLE(data->ubwc_swizzle) |
 		    MDSS_UBWC_STATIC_HIGHEST_BANK_BIT(data->highest_bank_bit - 13);
+	u32 ver, prediction_mode;
 
 	if (data->ubwc_bank_spread)
 		value |= MDSS_UBWC_STATIC_UBWC_BANK_SPREAD;
@@ -211,45 +209,42 @@ static void msm_mdss_setup_ubwc_dec_40(struct msm_mdss *msm_mdss)
 	if (data->macrotile_mode)
 		value |= MDSS_UBWC_STATIC_MACROTILE_MODE;
 
-	writel_relaxed(value, msm_mdss->mmio + REG_MDSS_UBWC_STATIC);
-
-	if (data->ubwc_enc_version == UBWC_3_0) {
-		writel_relaxed(1, msm_mdss->mmio + REG_MDSS_UBWC_CTRL_2);
-		writel_relaxed(0, msm_mdss->mmio + REG_MDSS_UBWC_PREDICTION_MODE);
-	} else {
-		if (data->ubwc_dec_version == UBWC_4_3)
-			writel_relaxed(3, msm_mdss->mmio + REG_MDSS_UBWC_CTRL_2);
-		else
-			writel_relaxed(2, msm_mdss->mmio + REG_MDSS_UBWC_CTRL_2);
-		writel_relaxed(1, msm_mdss->mmio + REG_MDSS_UBWC_PREDICTION_MODE);
-	}
-}
-
-static void msm_mdss_setup_ubwc_dec_50(struct msm_mdss *msm_mdss)
-{
-	const struct qcom_ubwc_cfg_data *data = msm_mdss->mdss_data;
-	u32 value = MDSS_UBWC_STATIC_UBWC_SWIZZLE(data->ubwc_swizzle) |
-		    MDSS_UBWC_STATIC_HIGHEST_BANK_BIT(data->highest_bank_bit - 13);
-
-	if (data->ubwc_bank_spread)
-		value |= MDSS_UBWC_STATIC_UBWC_BANK_SPREAD;
-
-	if (data->macrotile_mode)
-		value |= MDSS_UBWC_STATIC_MACROTILE_MODE;
+	if (data->ubwc_enc_version == UBWC_1_0)
+		value |= MDSS_UBWC_STATIC_UBWC_MIN_ACC_LEN(1);
 
 	writel_relaxed(value, msm_mdss->mmio + REG_MDSS_UBWC_STATIC);
 
-	if (data->ubwc_dec_version == UBWC_6_0)
-		writel_relaxed(5, msm_mdss->mmio + REG_MDSS_UBWC_CTRL_2);
+	if (data->ubwc_enc_version < UBWC_4_0)
+		prediction_mode = 0;
 	else
-		writel_relaxed(4, msm_mdss->mmio + REG_MDSS_UBWC_CTRL_2);
-
-	writel_relaxed(1, msm_mdss->mmio + REG_MDSS_UBWC_PREDICTION_MODE);
+		prediction_mode = 1;
+
+	if (data->ubwc_enc_version >= UBWC_6_0)
+		ver = 5;
+	else if (data->ubwc_enc_version >= UBWC_5_0)
+		ver = 4;
+	else if (data->ubwc_enc_version >= UBWC_4_3)
+		ver = 3;
+	else if (data->ubwc_enc_version >= UBWC_4_0)
+		ver = 2;
+	else if (data->ubwc_enc_version >= UBWC_3_0)
+		ver = 1;
+	else /* UBWC 1.0 and 2.0 */
+		ver = 0;
+
+	writel_relaxed(ver, msm_mdss->mmio + REG_MDSS_UBWC_CTRL_2);
+	writel_relaxed(prediction_mode, msm_mdss->mmio + REG_MDSS_UBWC_PREDICTION_MODE);
 }
 
+#define MDSS_HW_VER(major, minor, step)	\
+	((((major) & 0xf) << 28) |	\
+	 (((minor) & 0xfff) << 16) |	\
+	 ((step) & 0xffff))
+
 static int msm_mdss_enable(struct msm_mdss *msm_mdss)
 {
 	int ret, i;
+	u32 hw_rev;
 
 	/*
 	 * Several components have AXI clocks that can only be turned on if
@@ -283,43 +278,15 @@ static int msm_mdss_enable(struct msm_mdss *msm_mdss)
 	if (msm_mdss->is_mdp5 || !msm_mdss->mdss_data)
 		return 0;
 
-	/*
-	 * ubwc config is part of the "mdss" region which is not accessible
-	 * from the rest of the driver. hardcode known configurations here
-	 *
-	 * Decoder version can be read from the UBWC_DEC_HW_VERSION reg,
-	 * UBWC_n and the rest of params comes from hw data.
-	 */
-	switch (msm_mdss->mdss_data->ubwc_dec_version) {
-	case 0: /* no UBWC */
-	case UBWC_1_0:
-		/* do nothing */
-		break;
-	case UBWC_2_0:
-		msm_mdss_setup_ubwc_dec_20(msm_mdss);
-		break;
-	case UBWC_3_0:
-		msm_mdss_setup_ubwc_dec_30(msm_mdss);
-		break;
-	case UBWC_4_0:
-	case UBWC_4_3:
-		msm_mdss_setup_ubwc_dec_40(msm_mdss);
-		break;
-	case UBWC_5_0:
-		msm_mdss_setup_ubwc_dec_50(msm_mdss);
-		break;
-	case UBWC_6_0:
-		msm_mdss_setup_ubwc_dec_50(msm_mdss);
-		break;
-	default:
-		dev_err(msm_mdss->dev, "Unsupported UBWC decoder version %x\n",
-			msm_mdss->mdss_data->ubwc_dec_version);
-		dev_err(msm_mdss->dev, "HW_REV: 0x%x\n",
-			readl_relaxed(msm_mdss->mmio + REG_MDSS_HW_VERSION));
-		dev_err(msm_mdss->dev, "UBWC_DEC_HW_VERSION: 0x%x\n",
-			readl_relaxed(msm_mdss->mmio + REG_MDSS_UBWC_DEC_HW_VERSION));
-		break;
-	}
+	hw_rev = readl_relaxed(msm_mdss->mmio + REG_MDSS_HW_VERSION);
+
+	if (hw_rev >= MDSS_HW_VER(6, 0, 0))
+		msm_mdss_6x_setup_ubwc(msm_mdss);
+	else if (hw_rev >= MDSS_HW_VER(5, 0, 0))
+		msm_mdss_5x_setup_ubwc(msm_mdss);
+	else if (hw_rev >= MDSS_HW_VER(4, 0, 0))
+		msm_mdss_4x_setup_ubwc(msm_mdss);
+	/* else UBWC 1.0 or none, no params to program */
 
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0286/2077] cpufreq: Documentation: fix sampling_down_factor range
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (284 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0285/2077] drm/msm/mdss: correct UBWC programming sequences Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0287/2077] cpufreq: conservative: Simplify frequency limit handling Greg Kroah-Hartman
                   ` (711 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhongqiu Han, Pengjie Zhang,
	Rafael J. Wysocki, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pengjie Zhang <zhangpengjie2@huawei.com>

[ Upstream commit 85524e651d20944399322d46fb97960337831d43 ]

The ondemand governor implementation accepts sampling_down_factor values
from 1 to 100000 via MAX_SAMPLING_DOWN_FACTOR, but the documentation in
admin-guide/pm/cpufreq.rst still says the valid range is 1 to 100.

Update the documentation to match the actual code.

Fixes: 2a0e49279850 ("cpufreq: User/admin documentation update and consolidation")
Reviewed-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
Signed-off-by: Pengjie Zhang <zhangpengjie2@huawei.com>
Link: https://patch.msgid.link/20260518133457.2408463-1-zhangpengjie2@huawei.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/admin-guide/pm/cpufreq.rst | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/Documentation/admin-guide/pm/cpufreq.rst b/Documentation/admin-guide/pm/cpufreq.rst
index dbe6d23a5d671d..fdca59c955dcc9 100644
--- a/Documentation/admin-guide/pm/cpufreq.rst
+++ b/Documentation/admin-guide/pm/cpufreq.rst
@@ -516,7 +516,7 @@ This governor exposes the following tunables:
 	of those tasks above 0 and set this attribute to 1.
 
 ``sampling_down_factor``
-	Temporary multiplier, between 1 (default) and 100 inclusive, to apply to
+	Temporary multiplier, between 1 (default) and 100000 inclusive, to apply to
 	the ``sampling_rate`` value if the CPU load goes above ``up_threshold``.
 
 	This causes the next execution of the governor's worker routine (after
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0287/2077] cpufreq: conservative: Simplify frequency limit handling
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (285 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0286/2077] cpufreq: Documentation: fix sampling_down_factor range Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0288/2077] pwm: imx27: Fix variable truncation in .apply() Greg Kroah-Hartman
                   ` (710 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lifeng Zheng, Viresh Kumar,
	Zhongqiu Han, Rafael J. Wysocki, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lifeng Zheng <zhenglifeng1@huawei.com>

[ Upstream commit 3494dff89779b73a6c70481c982e0e96d336454a ]

cs_dbs_update() performs explicit checks against policy->min/max
before updating the target frequency. These checks are redundant as
__cpufreq_driver_target() already clamps the requested frequency to
the valid policy limits.

Remove the unnecessary boundary checks and simplify the update logic.

This also fixes an issue introduced by commit 00bfe05889e9 ("cpufreq:
conservative: Decrease frequency faster for deferred updates"), where
stale target comparisons could cause frequency updates to be skipped
entirely after deferred adjustments.

Closes: https://lore.kernel.org/all/20260421123545.1745998-1-zhenglifeng1@huawei.com/
Fixes: 00bfe05889e9 ("cpufreq: conservative: Decrease frequency faster for deferred updates")
Signed-off-by: Lifeng Zheng <zhenglifeng1@huawei.com>
Co-developed-by: Viresh Kumar <viresh.kumar@linaro.org>
Signed-off-by: Viresh Kumar <viresh.kumar@linaro.org>
Reviewed-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
Link: https://patch.msgid.link/292e6d937890f135e30ec0d2107eaad47cb9a976.1779423281.git.viresh.kumar@linaro.org
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cpufreq/cpufreq_conservative.c | 12 +-----------
 1 file changed, 1 insertion(+), 11 deletions(-)

diff --git a/drivers/cpufreq/cpufreq_conservative.c b/drivers/cpufreq/cpufreq_conservative.c
index df01d33993d824..0b32ae28ec857f 100644
--- a/drivers/cpufreq/cpufreq_conservative.c
+++ b/drivers/cpufreq/cpufreq_conservative.c
@@ -103,10 +103,6 @@ static unsigned int cs_dbs_update(struct cpufreq_policy *policy)
 	if (load > dbs_data->up_threshold) {
 		dbs_info->down_skip = 0;
 
-		/* if we are already at full speed then break out early */
-		if (requested_freq == policy->max)
-			goto out;
-
 		requested_freq += freq_step;
 		if (requested_freq > policy->max)
 			requested_freq = policy->max;
@@ -124,13 +120,7 @@ static unsigned int cs_dbs_update(struct cpufreq_policy *policy)
 
 	/* Check for frequency decrease */
 	if (load < cs_tuners->down_threshold) {
-		/*
-		 * if we cannot reduce the frequency anymore, break out early
-		 */
-		if (requested_freq == policy->min)
-			goto out;
-
-		if (requested_freq > freq_step)
+		if (requested_freq > policy->min + freq_step)
 			requested_freq -= freq_step;
 		else
 			requested_freq = policy->min;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0288/2077] pwm: imx27: Fix variable truncation in .apply()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (286 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0287/2077] cpufreq: conservative: Simplify frequency limit handling Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0289/2077] RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed Greg Kroah-Hartman
                   ` (709 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ronaldo Nunez, Frank Li,
	Uwe Kleine-König, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ronaldo Nunez <rnunez@baylibre.com>

[ Upstream commit dc9e08fdbcc3eb08a1d2b868b535081c44425e27 ]

Fix a variable truncation when calculating period in microseconds as
part of the solution for the ERR051198 in .apply() callback.

Example scenario:
 - Period of 3us (PWMPR = 196 and prescaler = 1)
 - Expected value in tmp: 198000000000 (NSEC_PER_SEC * (196 + 2) * 1)
 - Actual value is 431504384 (truncation to u32)

Signed-off-by: Ronaldo Nunez <rnunez@baylibre.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260522191348.6227-1-rnunez@baylibre.com
Fixes: a25351e4c774 ("pwm: imx27: Workaround of the pwm output bug when decrease the duty cycle")
Signed-off-by: Uwe Kleine-König <ukleinek@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pwm/pwm-imx27.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/drivers/pwm/pwm-imx27.c b/drivers/pwm/pwm-imx27.c
index 3d34cdc4a3a51b..c8b801fcb5251f 100644
--- a/drivers/pwm/pwm-imx27.c
+++ b/drivers/pwm/pwm-imx27.c
@@ -200,7 +200,7 @@ static void pwm_imx27_wait_fifo_slot(struct pwm_chip *chip,
 static int pwm_imx27_apply(struct pwm_chip *chip, struct pwm_device *pwm,
 			   const struct pwm_state *state)
 {
-	unsigned long period_cycles, duty_cycles, prescale, period_us, tmp;
+	unsigned long period_cycles, duty_cycles, prescale, period_us;
 	struct pwm_imx27_chip *imx = to_pwm_imx27_chip(chip);
 	unsigned long long c;
 	unsigned long long clkrate;
@@ -208,6 +208,7 @@ static int pwm_imx27_apply(struct pwm_chip *chip, struct pwm_device *pwm,
 	int val;
 	int ret;
 	u32 cr;
+	u64 tmp;
 
 	clkrate = clk_get_rate(imx->clks[PWM_IMX27_PER].clk);
 	c = clkrate * state->period;
@@ -249,6 +250,11 @@ static int pwm_imx27_apply(struct pwm_chip *chip, struct pwm_device *pwm,
 	val = readl(imx->mmio_base + MX3_PWMPR);
 	val = val >= MX3_PWMPR_MAX ? MX3_PWMPR_MAX : val;
 	cr = readl(imx->mmio_base + MX3_PWMCR);
+
+	/*
+	 * tmp stores period in nanoseconds. Result fits in u64 since
+	 * val <= 0xfffe and prescaler in [1, 0x1000].
+	 */
 	tmp = NSEC_PER_SEC * (u64)(val + 2) * MX3_PWMCR_PRESCALER_GET(cr);
 	tmp = DIV_ROUND_UP_ULL(tmp, clkrate);
 	period_us = DIV_ROUND_UP_ULL(tmp, 1000);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0289/2077] RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (287 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0288/2077] pwm: imx27: Fix variable truncation in .apply() Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0290/2077] tools/nolibc: stackprotector: Avoid stalling program startup if crng is not init yet Greg Kroah-Hartman
                   ` (708 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shiraz Saleem, Konstantin Taranov,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shiraz Saleem <shirazsaleem@microsoft.com>

[ Upstream commit d28654518c8db5d06d27bd3211c0e9a70c18f7c2 ]

Replace hardcoded IB_WIDTH_4X/IB_SPEED_EDR with ib_get_eth_speed()
to report the actual link speed in mana_ib_query_port().

Fixes: 4bda1d5332ec ("RDMA/mana_ib: Implement port parameters")
Link: https://patch.msgid.link/r/20260512094056.264827-1-kotaranov@linux.microsoft.com
Signed-off-by: Shiraz Saleem <shirazsaleem@microsoft.com>
Signed-off-by: Konstantin Taranov <kotaranov@microsoft.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mana/main.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/drivers/infiniband/hw/mana/main.c b/drivers/infiniband/hw/mana/main.c
index afc2fc124fee30..307ae01bf26f34 100644
--- a/drivers/infiniband/hw/mana/main.c
+++ b/drivers/infiniband/hw/mana/main.c
@@ -600,8 +600,7 @@ int mana_ib_query_port(struct ib_device *ibdev, u32 port,
 		props->phys_state = IB_PORT_PHYS_STATE_DISABLED;
 	}
 
-	props->active_width = IB_WIDTH_4X;
-	props->active_speed = IB_SPEED_EDR;
+	ib_get_eth_speed(ibdev, port, &props->active_speed, &props->active_width);
 	props->pkey_tbl_len = 1;
 	if (mana_ib_is_rnic(dev)) {
 		props->gid_tbl_len = 16;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0290/2077] tools/nolibc: stackprotector: Avoid stalling program startup if crng is not init yet
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (288 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0289/2077] RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0291/2077] bus: sunxi-rsb: Always check register address validity Greg Kroah-Hartman
                   ` (707 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Daniel Palmer, Willy Tarreau,
	Thomas Weißschuh, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Palmer <daniel@thingy.jp>

[ Upstream commit b882d807fa443b529ae8bf917d7b640a8d555437 ]

We are using the getrandom syscall to get a random seed for the
stack protector canary but we are calling it with no flags which means
it'll block until there is some real randomness to return.

This means that if the crng is not ready yet program startup will
block and if you are unlucky that could be for a long time and
look like the program has crashed.

Even if the call to getrandom does not yield any random data,
we will still initialize the canary.

Fixes: 7188d4637e95 ("tools/nolibc: add support for stack protector")
Signed-off-by: Daniel Palmer <daniel@thingy.jp>
Acked-by: Willy Tarreau <w@1wt.eu>
Link: https://patch.msgid.link/20260522090726.726985-1-daniel@thingy.jp
Signed-off-by: Thomas Weißschuh <linux@weissschuh.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/include/nolibc/stackprotector.h | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/tools/include/nolibc/stackprotector.h b/tools/include/nolibc/stackprotector.h
index ae8b1d3a374dcd..4d1aa5371c77c2 100644
--- a/tools/include/nolibc/stackprotector.h
+++ b/tools/include/nolibc/stackprotector.h
@@ -42,7 +42,8 @@ uintptr_t __stack_chk_guard;
 
 static __no_stack_protector void __stack_chk_init(void)
 {
-	__nolibc_syscall3(__NR_getrandom, &__stack_chk_guard, sizeof(__stack_chk_guard), 0);
+	__nolibc_syscall3(__NR_getrandom, &__stack_chk_guard, sizeof(__stack_chk_guard),
+			  GRND_INSECURE | GRND_NONBLOCK);
 	/* a bit more randomness in case getrandom() fails, ensure the guard is never 0 */
 	if (__stack_chk_guard != (uintptr_t) &__stack_chk_guard)
 		__stack_chk_guard ^= (uintptr_t) &__stack_chk_guard;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0291/2077] bus: sunxi-rsb: Always check register address validity
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (289 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0290/2077] tools/nolibc: stackprotector: Avoid stalling program startup if crng is not init yet Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0292/2077] pinctrl: spacemit: fix NULL check in spacemit_pin_set_config Greg Kroah-Hartman
                   ` (706 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Samuel Holland, Andrey Skvortsov,
	Chen-Yu Tsai, Jernej Skrabec, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Samuel Holland <samuel@sholland.org>

[ Upstream commit 61192938a5870ac36edae81e4775b680dcf02c61 ]

The register address was already validated for read operations in
regmap_sunxi_rsb_reg_read before being truncated to a u8. Write operations
have the same set of possible addresses, and the address is being truncated
from u32 to u8 here as well, so the same check is needed.

Signed-off-by: Samuel Holland <samuel@sholland.org>
Signed-off-by: Andrey Skvortsov <andrej.skvortzov@gmail.com>
Fixes: d787dcdb9c8f ("bus: sunxi-rsb: Add driver for Allwinner Reduced Serial Bus")
Reviewed-by: Chen-Yu Tsai <wens@kernel.org>
Reviewed-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Link: https://patch.msgid.link/20260301144939.1832806-1-andrej.skvortzov@gmail.com
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/bus/sunxi-rsb.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/bus/sunxi-rsb.c b/drivers/bus/sunxi-rsb.c
index b4f2c64ac1810f..daf0ea563e4773 100644
--- a/drivers/bus/sunxi-rsb.c
+++ b/drivers/bus/sunxi-rsb.c
@@ -445,6 +445,9 @@ static int regmap_sunxi_rsb_reg_write(void *context, unsigned int reg,
 	struct sunxi_rsb_ctx *ctx = context;
 	struct sunxi_rsb_device *rdev = ctx->rdev;
 
+	if (reg > 0xff)
+		return -EINVAL;
+
 	return sunxi_rsb_write(rdev->rsb, rdev->rtaddr, reg, &val, ctx->size);
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0292/2077] pinctrl: spacemit: fix NULL check in spacemit_pin_set_config
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (290 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0291/2077] bus: sunxi-rsb: Always check register address validity Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0293/2077] ASoC: dapm: Fix widget lookup with prefixed names across DAPM contexts Greg Kroah-Hartman
                   ` (705 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Han Gao, Troy Mitchell, Yixun Lan,
	Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Han Gao <gaohan@iscas.ac.cn>

[ Upstream commit 09c816e5c4d3a8d6d6e4b7537433e5e98505d934 ]

spacemit_pin_set_config() looks up the per-pin descriptor with
spacemit_get_pin() then checks the wrong variable for failure:

	const struct spacemit_pin *spin = spacemit_get_pin(pctrl, pin);
	...
	if (!pin)
		return -EINVAL;

	reg = spacemit_pin_to_reg(pctrl, spin->pin);

pin is an unsigned int pin id, where 0 (GPIO_0 / gmac0_rxdv on K3) is a
valid pin, so rejecting it here drops the PAD config write for the first
pin of every group. On K3 Pico-ITX the GMAC RGMII group lists pin 0 as
its first entry, so its drive-strength / bias configuration was silently
ignored.

The intended guard is against spacemit_get_pin() returning NULL when the
pin id isn't in the SoC's pin table. Check spin instead, which both
restores PAD setup for pin 0 and prevents a NULL deref on spin->pin.

Fixes: a83c29e1d145 ("pinctrl: spacemit: add support for SpacemiT K1 SoC")
Signed-off-by: Han Gao <gaohan@iscas.ac.cn>
Reviewed-by: Troy Mitchell <troy.mitchell@linux.spacemit.com>
Reviewed-by: Yixun Lan <dlan@kernel.org>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/spacemit/pinctrl-k1.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pinctrl/spacemit/pinctrl-k1.c b/drivers/pinctrl/spacemit/pinctrl-k1.c
index b0be62b1c8161d..95024e2bb5a587 100644
--- a/drivers/pinctrl/spacemit/pinctrl-k1.c
+++ b/drivers/pinctrl/spacemit/pinctrl-k1.c
@@ -795,7 +795,7 @@ static int spacemit_pin_set_config(struct spacemit_pinctrl *pctrl,
 	void __iomem *reg;
 	unsigned int mux;
 
-	if (!pin)
+	if (!spin)
 		return -EINVAL;
 
 	reg = spacemit_pin_to_reg(pctrl, spin->pin);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0293/2077] ASoC: dapm: Fix widget lookup with prefixed names across DAPM contexts
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (291 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0292/2077] pinctrl: spacemit: fix NULL check in spacemit_pin_set_config Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0294/2077] RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs Greg Kroah-Hartman
                   ` (704 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Chancel Liu, Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chancel Liu <chancel.liu@nxp.com>

[ Upstream commit 8468c8aafe8b5807e5acba2f8aa96d0b3ce0c248 ]

Currently dapm_find_widget() manually constructs a prefixed widget name
based on the provided DAPM context and compares it using strcmp(). This
happens to work in most cases because callers usually know which DAPM
context the target widget belongs to and pass in the matching DAPM
context.

However, this assumption breaks when search_other_contexts is enabled.
In such cases, callers may intentionally pass a different DAPM context,
while searching for a widget that actually belongs to another DAPM
context.

For example, when searching for a "DAC" widget, the widget belongs to
the codec DAPM and be registered with a codec prefix, while the caller
passes card->dapm and intends to search across all DAPM contexts. The
current implementation incorrectly applies the caller card DAPM causing
the lookup to fail even though the widget exists on the card.

Improve the matching strategy to support both use cases:
1. When the caller provides a fully qualified name with prefix, perform
   exact string matching. This preserves the ability to use prefixes for
   disambiguation.
2. When the caller provides a bare widget name without prefix, try exact
   matching first, then fall back to prefix-stripped comparison using
   snd_soc_dapm_widget_name_cmp().

To determine whether the pin name includes a prefix, a new helper
function snd_soc_dapm_pin_has_prefix() is introduced. It checks if the
pin name starts with any known component prefix on the card.

This fixes widget lookup failures when searching across different DAPM
contexts while maintaining backward compatibility for explicitly
prefixed lookups.

Fixes: ae4fc532244b ("ASoC: dapm: use component prefix when checking widget names")
Signed-off-by: Chancel Liu <chancel.liu@nxp.com>
Assisted-by: Cody:Claude-4.5-Sonnet
Link: https://patch.msgid.link/20260507013654.2945915-2-chancel.liu@nxp.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/sound/soc-dapm.h |  1 +
 sound/soc/soc-dapm.c     | 49 ++++++++++++++++++++++++++++++----------
 2 files changed, 38 insertions(+), 12 deletions(-)

diff --git a/include/sound/soc-dapm.h b/include/sound/soc-dapm.h
index 4f8fb7622a139d..c1e4f467efda73 100644
--- a/include/sound/soc-dapm.h
+++ b/include/sound/soc-dapm.h
@@ -685,6 +685,7 @@ int snd_soc_dapm_sync_unlocked(struct snd_soc_dapm_context *dapm);
 int snd_soc_dapm_force_enable_pin(struct snd_soc_dapm_context *dapm, const char *pin);
 int snd_soc_dapm_force_enable_pin_unlocked(struct snd_soc_dapm_context *dapm, const char *pin);
 int snd_soc_dapm_ignore_suspend(struct snd_soc_dapm_context *dapm, const char *pin);
+bool snd_soc_dapm_pin_has_prefix(struct snd_soc_card *card, const char *pin);
 void snd_soc_dapm_mark_endpoints_dirty(struct snd_soc_card *card);
 
 /* dapm path query */
diff --git a/sound/soc/soc-dapm.c b/sound/soc/soc-dapm.c
index d6192204e613da..a26771c8e6ee69 100644
--- a/sound/soc/soc-dapm.c
+++ b/sound/soc/soc-dapm.c
@@ -2906,20 +2906,18 @@ static struct snd_soc_dapm_widget *dapm_find_widget(
 {
 	struct snd_soc_dapm_widget *w;
 	struct snd_soc_dapm_widget *fallback = NULL;
-	char prefixed_pin[80];
-	const char *pin_name;
-	const char *prefix = dapm_prefix(dapm);
-
-	if (prefix) {
-		snprintf(prefixed_pin, sizeof(prefixed_pin), "%s %s",
-			 prefix, pin);
-		pin_name = prefixed_pin;
-	} else {
-		pin_name = pin;
-	}
+	bool pin_has_prefix = snd_soc_dapm_pin_has_prefix(dapm->card, pin);
+	bool match;
 
 	for_each_card_widgets(dapm->card, w) {
-		if (!strcmp(w->name, pin_name)) {
+		match = false;
+
+		if (!strcmp(pin, w->name))
+			match = true;
+		else if (!pin_has_prefix && !snd_soc_dapm_widget_name_cmp(w, pin))
+			match = true;
+
+		if (match) {
 			if (w->dapm == dapm)
 				return w;
 			else
@@ -4872,6 +4870,33 @@ int snd_soc_dapm_ignore_suspend(struct snd_soc_dapm_context *dapm,
 }
 EXPORT_SYMBOL_GPL(snd_soc_dapm_ignore_suspend);
 
+/**
+ * snd_soc_dapm_pin_has_prefix - check if given pin has a known prefix
+ * @card: card to be checked
+ * @pin: pin name
+ *
+ * Returns true if given pin has a known prefix
+ */
+bool snd_soc_dapm_pin_has_prefix(struct snd_soc_card *card, const char *pin)
+{
+	struct snd_soc_component *component;
+	const char *prefix;
+	size_t prefix_len;
+
+	for_each_card_components(card, component) {
+		prefix = component->name_prefix;
+		if (!prefix)
+			continue;
+
+		prefix_len = strlen(prefix);
+		if (!strncmp(pin, prefix, prefix_len) && pin[prefix_len] == ' ')
+			return true;
+	}
+
+	return false;
+}
+EXPORT_SYMBOL_GPL(snd_soc_dapm_pin_has_prefix);
+
 /**
  * snd_soc_dapm_free - free dapm resources
  * @dapm: DAPM context
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0294/2077] RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (292 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0293/2077] ASoC: dapm: Fix widget lookup with prefixed names across DAPM contexts Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0295/2077] RDMA/rxe: Fix a use-after-free problem in rxe_mmap Greg Kroah-Hartman
                   ` (703 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jacob Moroni <jmoroni@google.com>

[ Upstream commit 5ebb3ed757be3e04cf803026004aa0beaeb13e9b ]

The irdma_copy_user_pgaddrs function loops through all of the umem DMA
blocks to populate the PBLEs and will stop when either the last DMA
block is reached or palloc->total_cnt is reached. The issue is that
the logic for checking palloc->total_cnt would only work for non-zero
values.

When irdma_setup_pbles is called with lvl==0, it
calls irdma_copy_user_pgaddrs with palloc->total_cnt==0, which means
the only way to break out of the loop is to reach the last umem DMA
block, which means it could end up going beyond the fixed size of 4
iwmr->pgaddrmem array that is used in the lvl==0 case.

In the case of QP/CQ/SRQ rings, the value of lvl is determined by a
separate input (for example, req.cq_pages in the case of a CQ). So,
we must perform explicit checking to ensure we don't overflow the
pgaddrmem array if the user provides a umem that consists of more
blocks than their provided req.cq_pages.

Fixes: b48c24c2d710 ("RDMA/irdma: Implement device supported verb APIs")
Link: https://patch.msgid.link/r/20260512183852.614045-1-jmoroni@google.com
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/irdma/verbs.c | 14 ++++++++++----
 1 file changed, 10 insertions(+), 4 deletions(-)

diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
index 8cd4275328052e..661f2e0299ef7d 100644
--- a/drivers/infiniband/hw/irdma/verbs.c
+++ b/drivers/infiniband/hw/irdma/verbs.c
@@ -2781,10 +2781,11 @@ static inline u64 *irdma_next_pbl_addr(u64 *pbl, struct irdma_pble_info **pinfo,
  * irdma_copy_user_pgaddrs - copy user page address to pble's os locally
  * @iwmr: iwmr for IB's user page addresses
  * @pbl: ple pointer to save 1 level or 0 level pble
+ * @pbl_len: Max number of PBL entries to populate
  * @level: indicated level 0, 1 or 2
  */
 static void irdma_copy_user_pgaddrs(struct irdma_mr *iwmr, u64 *pbl,
-				    enum irdma_pble_level level)
+				    u32 pbl_len, enum irdma_pble_level level)
 {
 	struct ib_umem *region = iwmr->region;
 	struct irdma_pbl *iwpbl = &iwmr->iwpbl;
@@ -2792,7 +2793,9 @@ static void irdma_copy_user_pgaddrs(struct irdma_mr *iwmr, u64 *pbl,
 	struct irdma_pble_info *pinfo;
 	struct ib_block_iter biter;
 	u32 idx = 0;
-	u32 pbl_cnt = 0;
+
+	if (!pbl_len)
+		return;
 
 	pinfo = (level == PBLE_LEVEL_1) ? NULL : palloc->level2.leaf;
 
@@ -2801,7 +2804,7 @@ static void irdma_copy_user_pgaddrs(struct irdma_mr *iwmr, u64 *pbl,
 
 	rdma_umem_for_each_dma_block(region, &biter, iwmr->page_size) {
 		*pbl = rdma_block_iter_dma_address(&biter);
-		if (++pbl_cnt == palloc->total_cnt)
+		if (!--pbl_len)
 			break;
 		pbl = irdma_next_pbl_addr(pbl, &pinfo, &idx);
 	}
@@ -2877,6 +2880,7 @@ static int irdma_setup_pbles(struct irdma_pci_f *rf, struct irdma_mr *iwmr,
 	u64 *pbl;
 	int status;
 	enum irdma_pble_level level = PBLE_LEVEL_1;
+	u32 pbl_len;
 
 	if (lvl) {
 		status = irdma_get_pble(rf->pble_rsrc, palloc, iwmr->page_cnt,
@@ -2884,16 +2888,18 @@ static int irdma_setup_pbles(struct irdma_pci_f *rf, struct irdma_mr *iwmr,
 		if (status)
 			return status;
 
+		pbl_len = palloc->total_cnt;
 		iwpbl->pbl_allocated = true;
 		level = palloc->level;
 		pinfo = (level == PBLE_LEVEL_1) ? &palloc->level1 :
 						  palloc->level2.leaf;
 		pbl = pinfo->addr;
 	} else {
+		pbl_len = IRDMA_MAX_SAVED_PHY_PGADDR;
 		pbl = iwmr->pgaddrmem;
 	}
 
-	irdma_copy_user_pgaddrs(iwmr, pbl, level);
+	irdma_copy_user_pgaddrs(iwmr, pbl, pbl_len, level);
 
 	if (lvl)
 		iwmr->pgaddrmem[0] = *pbl;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0295/2077] RDMA/rxe: Fix a use-after-free problem in rxe_mmap
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (293 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0294/2077] RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0296/2077] IB/mlx4: Fix refcount leak in add_port() error path Greg Kroah-Hartman
                   ` (702 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, nasm, Zhu Yanjun, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhu Yanjun <yanjun.zhu@linux.dev>

[ Upstream commit 35744ab3d03c5fca8c1752f53fc8fc674e14c561 ]

rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list
and releases pending_lock while the struct's kref is still at 1:

   list_del_init(&ip->pending_mmaps);
   spin_unlock_bh(&rxe->pending_lock);   /* ref == 1, no lock held */
   ret = remap_vmalloc_range(vma, ip->obj, 0);  /* walks PTEs */
   [...]
   rxe_vma_open(vma);                    /* kref_get, ref → 2 */
   remap_vmalloc_range_partial() walks PTEs without any lock.

A concurrent DESTROY_CQ ioctl on another CPU calls:

    kref_put(&q->ip->ref, rxe_mmap_release)   /* ref 1→0 */
    vfree(ip->obj)   /* clears vmalloc PTEs mid-walk */
    kfree(ip)        /* frees rxe_mmap_info */

This yields:

   1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the
   per-PTE race -> vm_insert_page(NULL) → GPF in validate_page_before_insert

   2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears
   it. User VMA holds a PTE to a free'd page which might eventually get
   reallocated later by vmalloc which allows the attacker to get a clean
   page-level UAF.

   It is worth noting that even though a page-level UAF is possible given
   the strong primitive, it is statistically very difficult to achieve
   given the very short time window (after the last insert_page and before
   the kref_get).

The call trace are as below:

  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI
  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
  CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy)
  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
  RIP: 0010:validate_page_before_insert+0x32/0x300
  Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5
  RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202
  RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000
  RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008
  RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000
  R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00
  R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20
  FS:  00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000
  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
  CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0
  Call Trace:
   <TASK>
   insert_page+0x8f/0x190
   ? __pfx_insert_page+0x10/0x10
   ? kasan_save_alloc_info+0x38/0x60
   vm_insert_page+0x2e7/0x400
   remap_vmalloc_range_partial+0x212/0x3e0
   remap_vmalloc_range+0x6e/0xb0
   ? __kasan_check_write+0x14/0x30
   rxe_mmap+0x2e9/0x5d0
   ib_uverbs_mmap+0x1ad/0x2c0
   __mmap_region+0x12c2/0x2ad0
   ? __pfx___mmap_region+0x10/0x10
   ? __sanitizer_cov_trace_switch+0x58/0xb0
   ? mas_prev_slot+0x360/0x39c0
   ? __sanitizer_cov_trace_switch+0x58/0xb0
   ? mas_next_slot+0x1e5b/0x2f40
   ? __sanitizer_cov_trace_cmp8+0x18/0x30
   ? unmapped_area_topdown+0x4dd/0x610
   ? kfree+0x1b1/0x440
   ? free_cpumask_var+0x16/0x30
   ? __kasan_slab_free+0x7d/0xa0
   ? __sanitizer_cov_trace_cmp8+0x18/0x30
   mmap_region+0x2e6/0x3c0
   do_mmap+0xa3e/0x12a0
   ? __pfx_do_mmap+0x10/0x10
   ? __kasan_check_write+0x14/0x30
   ? down_write_killable+0xba/0x160
   ? __pfx_down_write_killable+0x10/0x10
   ? __sanitizer_cov_trace_cmp4+0x16/0x30
   vm_mmap_pgoff+0x2d4/0x4a0
   ? __pfx_vm_mmap_pgoff+0x10/0x10
   ? fget+0x1bf/0x270
   ksys_mmap_pgoff+0x40c/0x690
   ? __sanitizer_cov_trace_const_cmp4+0x16/0x30
   ? __pfx_ksys_mmap_pgoff+0x10/0x10
   ? __kasan_check_write+0x14/0x30
   ? _raw_spin_trylock+0xbb/0x130
   ? __pfx__raw_spin_trylock+0x10/0x10
   __x64_sys_mmap+0x135/0x1e0
   x64_sys_call+0x1c14/0x2790
   do_syscall_64+0xd2/0x1050
   ? rcu_core+0x352/0x7d0
   ? rcu_core_si+0xe/0x20
   ? handle_softirqs+0x1aa/0x650
   ? __sanitizer_cov_trace_cmp4+0x16/0x30
   ? fpregs_assert_state_consistent+0xe1/0x160
   ? irqentry_exit+0xb1/0x670
   entry_SYSCALL_64_after_hwframe+0x76/0x7e

Link: https://patch.msgid.link/r/20260515002537.6209-1-yanjun.zhu@linux.dev
Reported-and-tested-by: nasm <n4sm@protonmail.com>
Suggested-by: nasm <n4sm@protonmail.com>
Fixes: 8700e3e7c485 ("Soft RoCE driver")
Signed-off-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/sw/rxe/rxe_mmap.c | 19 ++++++++++++++++---
 1 file changed, 16 insertions(+), 3 deletions(-)

diff --git a/drivers/infiniband/sw/rxe/rxe_mmap.c b/drivers/infiniband/sw/rxe/rxe_mmap.c
index db380302149e51..7f723a2f370059 100644
--- a/drivers/infiniband/sw/rxe/rxe_mmap.c
+++ b/drivers/infiniband/sw/rxe/rxe_mmap.c
@@ -93,18 +93,31 @@ int rxe_mmap(struct ib_ucontext *context, struct vm_area_struct *vma)
 	goto done;
 
 found_it:
+	/*
+	 * Increment refcount and check whether it is being freed atm while
+	 * holding lock to prevent UAF
+	 */
+	if (!kref_get_unless_zero(&ip->ref)) {
+		spin_unlock_bh(&rxe->pending_lock);
+		ret = -ENXIO;
+		goto done;
+	}
+
 	list_del_init(&ip->pending_mmaps);
 	spin_unlock_bh(&rxe->pending_lock);
 
+	vma->vm_ops = &rxe_vm_ops;
+	vma->vm_private_data = ip;
+
 	ret = remap_vmalloc_range(vma, ip->obj, 0);
 	if (ret) {
+		vma->vm_private_data = NULL;
+		vma->vm_ops = NULL;
+		kref_put(&ip->ref, rxe_mmap_release);
 		rxe_dbg_dev(rxe, "err %d from remap_vmalloc_range\n", ret);
 		goto done;
 	}
 
-	vma->vm_ops = &rxe_vm_ops;
-	vma->vm_private_data = ip;
-	rxe_vma_open(vma);
 done:
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0296/2077] IB/mlx4: Fix refcount leak in add_port() error path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (294 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0295/2077] RDMA/rxe: Fix a use-after-free problem in rxe_mmap Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0297/2077] gpu: nova-core: vbios: stop scanning at BIOS_MAX_SCAN_LEN Greg Kroah-Hartman
                   ` (701 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guangshuo Li <lgs201920130244@gmail.com>

[ Upstream commit 9a8826fdfbcd7ed2ccf745f5d54208358d939def ]

After kobject_init_and_add(), the lifetime of the embedded struct
kobject is expected to be managed through the kobject core reference
counting.

In add_port(), failure paths after kobject_init_and_add() must not free
struct mlx4_port directly, because the embedded kobject is then managed
by the kobject core. Freeing it directly leaves the kobject reference
counting unbalanced and can lead to incorrect lifetime handling.

Allocate the pkey and gid attribute arrays before kobject_init_and_add(),
so failures before kobject initialization can be handled by directly
freeing the allocated memory. Once kobject_init_and_add() has been
called, unwind later failures by removing any successfully created sysfs
groups, calling kobject_del(), and then releasing the embedded kobject
with kobject_put().

Fixes: c1e7e466120b ("IB/mlx4: Add iov directory in sysfs under the ib device")
Link: https://patch.msgid.link/r/20260518021910.972900-1-lgs201920130244@gmail.com
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx4/sysfs.c | 45 ++++++++++++++++++------------
 1 file changed, 27 insertions(+), 18 deletions(-)

diff --git a/drivers/infiniband/hw/mlx4/sysfs.c b/drivers/infiniband/hw/mlx4/sysfs.c
index b8fa4ecfc96106..e688ad66a895fe 100644
--- a/drivers/infiniband/hw/mlx4/sysfs.c
+++ b/drivers/infiniband/hw/mlx4/sysfs.c
@@ -636,12 +636,6 @@ static int add_port(struct mlx4_ib_dev *dev, int port_num, int slave)
 	p->port_num = port_num;
 	p->slave = slave;
 
-	ret = kobject_init_and_add(&p->kobj, &port_type,
-				   kobject_get(dev->dev_ports_parent[slave]),
-				   "%d", port_num);
-	if (ret)
-		goto err_alloc;
-
 	p->pkey_group.name  = "pkey_idx";
 	p->pkey_group.attrs =
 		alloc_group_attrs(show_port_pkey,
@@ -649,13 +643,9 @@ static int add_port(struct mlx4_ib_dev *dev, int port_num, int slave)
 				  dev->dev->caps.pkey_table_len[port_num]);
 	if (!p->pkey_group.attrs) {
 		ret = -ENOMEM;
-		goto err_alloc;
+		goto err_free_port;
 	}
 
-	ret = sysfs_create_group(&p->kobj, &p->pkey_group);
-	if (ret)
-		goto err_free_pkey;
-
 	p->gid_group.name  = "gid_idx";
 	p->gid_group.attrs = alloc_group_attrs(show_port_gid_idx, NULL, 1);
 	if (!p->gid_group.attrs) {
@@ -663,28 +653,47 @@ static int add_port(struct mlx4_ib_dev *dev, int port_num, int slave)
 		goto err_free_pkey;
 	}
 
+	ret = kobject_init_and_add(&p->kobj, &port_type,
+				   kobject_get(dev->dev_ports_parent[slave]),
+				   "%d", port_num);
+	if (ret)
+		goto err_put;
+
+	ret = sysfs_create_group(&p->kobj, &p->pkey_group);
+	if (ret)
+		goto err_del;
+
 	ret = sysfs_create_group(&p->kobj, &p->gid_group);
 	if (ret)
-		goto err_free_gid;
+		goto err_remove_pkey;
 
 	ret = add_vf_smi_entries(p);
 	if (ret)
-		goto err_free_gid;
+		goto err_remove_gid;
 
 	list_add_tail(&p->kobj.entry, &dev->pkeys.pkey_port_list[slave]);
 	return 0;
 
-err_free_gid:
-	kfree(p->gid_group.attrs[0]);
-	kfree(p->gid_group.attrs);
+err_remove_gid:
+	sysfs_remove_group(&p->kobj, &p->gid_group);
+
+err_remove_pkey:
+	sysfs_remove_group(&p->kobj, &p->pkey_group);
+
+err_del:
+	kobject_del(&p->kobj);
+
+err_put:
+	kobject_put(dev->dev_ports_parent[slave]);
+	kobject_put(&p->kobj);
+	return ret;
 
 err_free_pkey:
 	for (i = 0; i < dev->dev->caps.pkey_table_len[port_num]; ++i)
 		kfree(p->pkey_group.attrs[i]);
 	kfree(p->pkey_group.attrs);
 
-err_alloc:
-	kobject_put(dev->dev_ports_parent[slave]);
+err_free_port:
 	kfree(p);
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0297/2077] gpu: nova-core: vbios: stop scanning at BIOS_MAX_SCAN_LEN
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (295 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0296/2077] IB/mlx4: Fix refcount leak in add_port() error path Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0298/2077] gpu: nova-core: vbios: use checked arithmetic for bios image range end Greg Kroah-Hartman
                   ` (700 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joel Fernandes, John Hubbard,
	Eliot Courtney, Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eliot Courtney <ecourtney@nvidia.com>

[ Upstream commit fc7c1054b6f983ae2f3e100a24cc87908ae9f4b7 ]

Current code lets `current_offset` go to `BIOS_MAX_SCAN_LEN` which is
one byte too far.

Fixes: 6fda04e7f0cd ("gpu: nova-core: vbios: Add base support for VBIOS construction and iteration")
Reviewed-by: Joel Fernandes <joelagnelf@nvidia.com>
Reviewed-by: John Hubbard <jhubbard@nvidia.com>
Signed-off-by: Eliot Courtney <ecourtney@nvidia.com>
Link: https://patch.msgid.link/20260525-fix-vbios-v5-1-e5e455251537@nvidia.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/nova-core/vbios.rs | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/nova-core/vbios.rs b/drivers/gpu/nova-core/vbios.rs
index ebda28e596c5f0..871c1163f90a3d 100644
--- a/drivers/gpu/nova-core/vbios.rs
+++ b/drivers/gpu/nova-core/vbios.rs
@@ -189,7 +189,7 @@ impl<'a> Iterator for VbiosIterator<'a> {
             return None;
         }
 
-        if self.current_offset > BIOS_MAX_SCAN_LEN {
+        if self.current_offset >= BIOS_MAX_SCAN_LEN {
             dev_err!(self.dev, "Error: exceeded BIOS scan limit, stopping scan\n");
             return None;
         }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0298/2077] gpu: nova-core: vbios: use checked arithmetic for bios image range end
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (296 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0297/2077] gpu: nova-core: vbios: stop scanning at BIOS_MAX_SCAN_LEN Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0299/2077] gpu: nova-core: vbios: avoid reading too far in read_more_at_offset Greg Kroah-Hartman
                   ` (699 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joel Fernandes, John Hubbard,
	Eliot Courtney, Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eliot Courtney <ecourtney@nvidia.com>

[ Upstream commit 7a1d09e477b6496f13f92b84ed9b2eab191b3366 ]

`read_bios_image_at_offset` is called with a length from the VBIOS
header, so we should be more defensive here and use checked arithmetic.

Fixes: 6fda04e7f0cd ("gpu: nova-core: vbios: Add base support for VBIOS construction and iteration")
Reviewed-by: Joel Fernandes <joelagnelf@nvidia.com>
Reviewed-by: John Hubbard <jhubbard@nvidia.com>
Signed-off-by: Eliot Courtney <ecourtney@nvidia.com>
Link: https://patch.msgid.link/20260525-fix-vbios-v5-2-e5e455251537@nvidia.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/nova-core/vbios.rs | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/gpu/nova-core/vbios.rs b/drivers/gpu/nova-core/vbios.rs
index 871c1163f90a3d..d25f9a11228009 100644
--- a/drivers/gpu/nova-core/vbios.rs
+++ b/drivers/gpu/nova-core/vbios.rs
@@ -155,8 +155,8 @@ impl<'a> VbiosIterator<'a> {
         len: usize,
         context: &str,
     ) -> Result<BiosImage> {
-        let data_len = self.data.len();
-        if offset + len > data_len {
+        let end = offset.checked_add(len).ok_or(EINVAL)?;
+        if end > self.data.len() {
             self.read_more_at_offset(offset, len).inspect_err(|e| {
                 dev_err!(
                     self.dev,
@@ -167,7 +167,7 @@ impl<'a> VbiosIterator<'a> {
             })?;
         }
 
-        BiosImage::new(self.dev, &self.data[offset..offset + len]).inspect_err(|err| {
+        BiosImage::new(self.dev, &self.data[offset..end]).inspect_err(|err| {
             dev_err!(
                 self.dev,
                 "Failed to {} at offset {:#x}: {:?}\n",
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0299/2077] gpu: nova-core: vbios: avoid reading too far in read_more_at_offset
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (297 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0298/2077] gpu: nova-core: vbios: use checked arithmetic for bios image range end Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0300/2077] gpu: nova-core: vbios: read BitToken using FromBytes Greg Kroah-Hartman
                   ` (698 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, John Hubbard, Eliot Courtney,
	Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eliot Courtney <ecourtney@nvidia.com>

[ Upstream commit 33f1402bcfa6cfd85fa265ce6fa5c6bb7d981c6d ]

Fix bug where `read_more_at_offset` would unnecessarily read more data.
This happens when the window to read has some part cached and some part
not. It would read `len` bytes instead of just the uncached portion,
which could read past `BIOS_MAX_SCAN_LEN`.

Fixes: 6fda04e7f0cd ("gpu: nova-core: vbios: Add base support for VBIOS construction and iteration")
Reviewed-by: John Hubbard <jhubbard@nvidia.com>
Signed-off-by: Eliot Courtney <ecourtney@nvidia.com>
Link: https://patch.msgid.link/20260525-fix-vbios-v5-3-e5e455251537@nvidia.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/nova-core/vbios.rs | 25 +++++++++++--------------
 1 file changed, 11 insertions(+), 14 deletions(-)

diff --git a/drivers/gpu/nova-core/vbios.rs b/drivers/gpu/nova-core/vbios.rs
index d25f9a11228009..10473279ebeaf7 100644
--- a/drivers/gpu/nova-core/vbios.rs
+++ b/drivers/gpu/nova-core/vbios.rs
@@ -102,8 +102,13 @@ impl<'a> VbiosIterator<'a> {
 
     /// Read bytes from the ROM at the current end of the data vector.
     fn read_more(&mut self, len: usize) -> Result {
-        let current_len = self.data.len();
-        let start = ROM_OFFSET + current_len;
+        let start = self.data.len();
+        let end = start + len;
+
+        if end > BIOS_MAX_SCAN_LEN {
+            dev_err!(self.dev, "Error: exceeded BIOS scan limit.\n");
+            return Err(EINVAL);
+        }
 
         // Ensure length is a multiple of 4 for 32-bit reads
         if len % core::mem::size_of::<u32>() != 0 {
@@ -117,9 +122,9 @@ impl<'a> VbiosIterator<'a> {
 
         self.data.reserve(len, GFP_KERNEL)?;
         // Read ROM data bytes and push directly to `data`.
-        for addr in (start..start + len).step_by(core::mem::size_of::<u32>()) {
+        for addr in (start..end).step_by(core::mem::size_of::<u32>()) {
             // Read 32-bit word from the VBIOS ROM
-            let word = self.bar0.try_read32(addr)?;
+            let word = self.bar0.try_read32(ROM_OFFSET + addr)?;
 
             // Convert the `u32` to a 4 byte array and push each byte.
             word.to_ne_bytes()
@@ -132,17 +137,9 @@ impl<'a> VbiosIterator<'a> {
 
     /// Read bytes at a specific offset, filling any gap.
     fn read_more_at_offset(&mut self, offset: usize, len: usize) -> Result {
-        if offset > BIOS_MAX_SCAN_LEN {
-            dev_err!(self.dev, "Error: exceeded BIOS scan limit.\n");
-            return Err(EINVAL);
-        }
-
-        // If `offset` is beyond current data size, fill the gap first.
-        let current_len = self.data.len();
-        let gap_bytes = offset.saturating_sub(current_len);
+        let end = offset.checked_add(len).ok_or(EINVAL)?;
 
-        // Now read the requested bytes at the offset.
-        self.read_more(gap_bytes + len)
+        self.read_more(end.saturating_sub(self.data.len()))
     }
 
     /// Read a BIOS image at a specific offset and create a [`BiosImage`] from it.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0300/2077] gpu: nova-core: vbios: read BitToken using FromBytes
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (298 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0299/2077] gpu: nova-core: vbios: avoid reading too far in read_more_at_offset Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0301/2077] gpu: nova-core: vbios: use checked ops and accesses in `FwSecBiosImage::ucode` Greg Kroah-Hartman
                   ` (697 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, John Hubbard, Eliot Courtney,
	Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eliot Courtney <ecourtney@nvidia.com>

[ Upstream commit 237c252be0db616c93e4984369db7e74bb797564 ]

If `header.token_size` is smaller than `BitToken`, then we currently can
read past the end of `image.base.data`. Use checked arithmetic for
computing offsets and simplify reading it in using `FromBytes`.

Fixes: dc70c6ae2441 ("gpu: nova-core: vbios: Add support to look up PMU table in FWSEC")
Reviewed-by: John Hubbard <jhubbard@nvidia.com>
Signed-off-by: Eliot Courtney <ecourtney@nvidia.com>
Link: https://patch.msgid.link/20260525-fix-vbios-v5-4-e5e455251537@nvidia.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/nova-core/vbios.rs | 39 +++++++++++++++++-----------------
 1 file changed, 19 insertions(+), 20 deletions(-)

diff --git a/drivers/gpu/nova-core/vbios.rs b/drivers/gpu/nova-core/vbios.rs
index 10473279ebeaf7..517d113e14137a 100644
--- a/drivers/gpu/nova-core/vbios.rs
+++ b/drivers/gpu/nova-core/vbios.rs
@@ -403,7 +403,7 @@ impl BitHeader {
 
 /// BIT Token Entry: Records in the BIT table followed by the BIT header.
 #[derive(Debug, Clone, Copy)]
-#[expect(dead_code)]
+#[repr(C)]
 struct BitToken {
     /// 00h: Token identifier
     id: u8,
@@ -415,6 +415,9 @@ struct BitToken {
     data_offset: u16,
 }
 
+// SAFETY: all bit patterns are valid for `BitToken`.
+unsafe impl FromBytes for BitToken {}
+
 // Define the token ID for the Falcon data
 const BIT_TOKEN_ID_FALCON_DATA: u8 = 0x70;
 
@@ -422,32 +425,28 @@ impl BitToken {
     /// Find a BIT token entry by BIT ID in a PciAtBiosImage
     fn from_id(image: &PciAtBiosImage, token_id: u8) -> Result<Self> {
         let header = &image.bit_header;
+        let entry_size = usize::from(header.token_size);
 
         // Offset to the first token entry
         let tokens_start = image.bit_offset + usize::from(header.header_size);
 
         for i in 0..usize::from(header.token_entries) {
-            let entry_offset = tokens_start + (i * usize::from(header.token_size));
-
-            // Make sure we don't go out of bounds
-            if entry_offset + usize::from(header.token_size) > image.base.data.len() {
-                return Err(EINVAL);
-            }
+            let entry_offset = i
+                .checked_mul(entry_size)
+                .and_then(|offset| tokens_start.checked_add(offset))
+                .ok_or(EINVAL)?;
+            let entry = image
+                .base
+                .data
+                .get(entry_offset..)
+                .and_then(|data| data.get(..entry_size))
+                .ok_or(EINVAL)?;
+
+            let (token, _) = BitToken::from_bytes_copy_prefix(entry).ok_or(EINVAL)?;
 
             // Check if this token has the requested ID
-            if image.base.data[entry_offset] == token_id {
-                return Ok(BitToken {
-                    id: image.base.data[entry_offset],
-                    data_version: image.base.data[entry_offset + 1],
-                    data_size: u16::from_le_bytes([
-                        image.base.data[entry_offset + 2],
-                        image.base.data[entry_offset + 3],
-                    ]),
-                    data_offset: u16::from_le_bytes([
-                        image.base.data[entry_offset + 4],
-                        image.base.data[entry_offset + 5],
-                    ]),
-                });
+            if token.id == token_id {
+                return Ok(token);
             }
         }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0301/2077] gpu: nova-core: vbios: use checked ops and accesses in `FwSecBiosImage::ucode`
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (299 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0300/2077] gpu: nova-core: vbios: read BitToken using FromBytes Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0302/2077] gpu: nova-core: vbios: use checked access in `FwSecBiosImage::header` Greg Kroah-Hartman
                   ` (696 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joel Fernandes, John Hubbard,
	Eliot Courtney, Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eliot Courtney <ecourtney@nvidia.com>

[ Upstream commit 7c62d0b006527efc5fb4609b555c65674c819603 ]

Use checked arithmetic and access for extracting the microcode since the
offsets are firmware derived.

Fixes: 47c4846e4319 ("gpu: nova-core: vbios: Add support for FWSEC ucode extraction")
Reviewed-by: Joel Fernandes <joelagnelf@nvidia.com>
Reviewed-by: John Hubbard <jhubbard@nvidia.com>
Signed-off-by: Eliot Courtney <ecourtney@nvidia.com>
Link: https://patch.msgid.link/20260525-fix-vbios-v5-5-e5e455251537@nvidia.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/nova-core/vbios.rs | 14 ++++++++------
 1 file changed, 8 insertions(+), 6 deletions(-)

diff --git a/drivers/gpu/nova-core/vbios.rs b/drivers/gpu/nova-core/vbios.rs
index 517d113e14137a..10f812714e4dcd 100644
--- a/drivers/gpu/nova-core/vbios.rs
+++ b/drivers/gpu/nova-core/vbios.rs
@@ -1027,16 +1027,18 @@ impl FwSecBiosImage {
 
     /// Get the ucode data as a byte slice
     pub(crate) fn ucode(&self, desc: &FalconUCodeDesc) -> Result<&[u8]> {
-        let falcon_ucode_offset = self.falcon_ucode_offset;
+        let size = usize::from_safe_cast(
+            desc.imem_load_size()
+                .checked_add(desc.dmem_load_size())
+                .ok_or(ERANGE)?,
+        );
 
         // The ucode data follows the descriptor.
-        let ucode_data_offset = falcon_ucode_offset + desc.size();
-        let size = usize::from_safe_cast(desc.imem_load_size() + desc.dmem_load_size());
-
-        // Get the data slice, checking bounds in a single operation.
         self.base
             .data
-            .get(ucode_data_offset..ucode_data_offset + size)
+            .get(self.falcon_ucode_offset..)
+            .and_then(|data| data.get(desc.size()..))
+            .and_then(|data| data.get(..size))
             .ok_or(ERANGE)
             .inspect_err(|_| {
                 dev_err!(
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0302/2077] gpu: nova-core: vbios: use checked access in `FwSecBiosImage::header`
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (300 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0301/2077] gpu: nova-core: vbios: use checked ops and accesses in `FwSecBiosImage::ucode` Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0303/2077] gpu: nova-core: vbios: use checked accesses in `setup_falcon_data` Greg Kroah-Hartman
                   ` (695 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joel Fernandes, John Hubbard,
	Eliot Courtney, Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eliot Courtney <ecourtney@nvidia.com>

[ Upstream commit 25ad950b4ee37f7b42e006f508a793b7c38fcc12 ]

Use checked access in `FwSecBiosImage::header` for getting the header
version since the value is firmware derived.

Fixes: 47c4846e4319 ("gpu: nova-core: vbios: Add support for FWSEC ucode extraction")
Reviewed-by: Joel Fernandes <joelagnelf@nvidia.com>
Reviewed-by: John Hubbard <jhubbard@nvidia.com>
Signed-off-by: Eliot Courtney <ecourtney@nvidia.com>
Link: https://patch.msgid.link/20260525-fix-vbios-v5-6-e5e455251537@nvidia.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/nova-core/vbios.rs | 17 +++++++----------
 1 file changed, 7 insertions(+), 10 deletions(-)

diff --git a/drivers/gpu/nova-core/vbios.rs b/drivers/gpu/nova-core/vbios.rs
index 10f812714e4dcd..394877d5b2eae1 100644
--- a/drivers/gpu/nova-core/vbios.rs
+++ b/drivers/gpu/nova-core/vbios.rs
@@ -994,17 +994,14 @@ impl FwSecBiosBuilder {
 impl FwSecBiosImage {
     /// Get the FwSec header ([`FalconUCodeDesc`]).
     pub(crate) fn header(&self) -> Result<FalconUCodeDesc> {
-        // Get the falcon ucode offset that was found in setup_falcon_data.
-        let falcon_ucode_offset = self.falcon_ucode_offset;
-
-        // Read the first 4 bytes to get the version.
-        let hdr_bytes: [u8; 4] = self.base.data[falcon_ucode_offset..falcon_ucode_offset + 4]
-            .try_into()
-            .map_err(|_| EINVAL)?;
-        let hdr = u32::from_le_bytes(hdr_bytes);
-        let ver = (hdr & 0xff00) >> 8;
+        let data = self
+            .base
+            .data
+            .get(self.falcon_ucode_offset..)
+            .ok_or(EINVAL)?;
 
-        let data = self.base.data.get(falcon_ucode_offset..).ok_or(EINVAL)?;
+        // Read the version byte from the header.
+        let ver = data.get(1).copied().ok_or(EINVAL)?;
         match ver {
             2 => {
                 let v2 = FalconUCodeDescV2::from_bytes_copy_prefix(data)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0303/2077] gpu: nova-core: vbios: use checked accesses in `setup_falcon_data`
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (301 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0302/2077] gpu: nova-core: vbios: use checked access in `FwSecBiosImage::header` Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0304/2077] RDMA/hns: Fix warning in poll cq direct mode Greg Kroah-Hartman
                   ` (694 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joel Fernandes, John Hubbard,
	Eliot Courtney, Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eliot Courtney <ecourtney@nvidia.com>

[ Upstream commit 051ae1b21ff7a3cc27522b0b3b56e277b62c1207 ]

Use checked arithmetic for `ucode_offset` in `setup_falcon_data`. This
prevents a malformed firmware from causing a panic.

Fixes: dc70c6ae2441 ("gpu: nova-core: vbios: Add support to look up PMU table in FWSEC")
Reviewed-by: Joel Fernandes <joelagnelf@nvidia.com>
Reviewed-by: John Hubbard <jhubbard@nvidia.com>
Signed-off-by: Eliot Courtney <ecourtney@nvidia.com>
Link: https://patch.msgid.link/20260525-fix-vbios-v5-7-e5e455251537@nvidia.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/nova-core/vbios.rs | 17 +++++++++--------
 1 file changed, 9 insertions(+), 8 deletions(-)

diff --git a/drivers/gpu/nova-core/vbios.rs b/drivers/gpu/nova-core/vbios.rs
index 394877d5b2eae1..19361104a4cd3d 100644
--- a/drivers/gpu/nova-core/vbios.rs
+++ b/drivers/gpu/nova-core/vbios.rs
@@ -953,14 +953,15 @@ impl FwSecBiosBuilder {
             .find_entry_by_type(FALCON_UCODE_ENTRY_APPID_FWSEC_PROD)
         {
             Ok(entry) => {
-                let mut ucode_offset = usize::from_safe_cast(entry.data);
-                ucode_offset -= pci_at_image.base.data.len();
-                if ucode_offset < first_fwsec.base.data.len() {
-                    dev_err!(self.base.dev, "Falcon Ucode offset not in second Fwsec.\n");
-                    return Err(EINVAL);
-                }
-                ucode_offset -= first_fwsec.base.data.len();
-                self.falcon_ucode_offset = Some(ucode_offset);
+                self.falcon_ucode_offset = Some(
+                    usize::from_safe_cast(entry.data)
+                        .checked_sub(pci_at_image.base.data.len())
+                        .and_then(|o| o.checked_sub(first_fwsec.base.data.len()))
+                        .ok_or(EINVAL)
+                        .inspect_err(|_| {
+                            dev_err!(self.base.dev, "Falcon Ucode offset not in second Fwsec.\n");
+                        })?,
+                );
             }
             Err(e) => {
                 dev_err!(
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0304/2077] RDMA/hns: Fix warning in poll cq direct mode
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (302 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0303/2077] gpu: nova-core: vbios: use checked accesses in `setup_falcon_data` Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0305/2077] RDMA/hns: Fix log flood after cmd_mbox failure Greg Kroah-Hartman
                   ` (693 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lianfa Weng, Junxian Huang,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lianfa Weng <wenglianfa@huawei.com>

[ Upstream commit 3f19c2a3852e6ba75f3e92dd5edc4e07f3d07f4a ]

CQs allocated by ib_alloc_cq() always have a comp_handler. Though
in direct mode this handler is never expected to be called, it
is still called when the driver is reset, triggering the following
WARN_ONCE():

Call trace:
ib_cq_completion_direct+0x38/0x60
hns_roce_cq_completion+0x54/0x90 (hns_roce_hw_v2]
hns_roce_handle_device_err+Ox1c8/0x340 [hns_roce_hw_v2]
hns_roce_hw_v2_uninit_instance.constprop.0+0x34/0x70 [hns_roce_hw_v2]
hns_roce_hw_v2_reset_notify+0xc4/0xe0 [hns_roce_hw_v2]
hclge_notify_roce_client+0x60/0xbc [hclge]
hclge_reset_rebuild+0x48/0x34c [hclge]
hclge_reset_subtask+0xcc/0xec [hclge]
hclge_reset_service_task+0x80/0x160 [hclge]
hclge_service_task+0x50/0x80 (hclge]
process_one_work+0x1cc/0x4d0
worker_thread+0x154/0x414
kthread+0x104/0x144
ret_from_fork+0x10/0x18

Fixes: f295e4cece5c ("RDMA/hns: Delete unnecessary callback functions for cq")
Link: https://patch.msgid.link/r/20260520055759.2354037-3-huangjunxian6@hisilicon.com
Signed-off-by: Lianfa Weng <wenglianfa@huawei.com>
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/hns/hns_roce_main.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/hns/hns_roce_main.c b/drivers/infiniband/hw/hns/hns_roce_main.c
index 0dbe99aab6ad21..1e54710354542e 100644
--- a/drivers/infiniband/hw/hns/hns_roce_main.c
+++ b/drivers/infiniband/hw/hns/hns_roce_main.c
@@ -1113,7 +1113,7 @@ static void check_and_get_armed_cq(struct list_head *cq_list, struct ib_cq *cq)
 	unsigned long flags;
 
 	spin_lock_irqsave(&hr_cq->lock, flags);
-	if (cq->comp_handler) {
+	if (cq->comp_handler && hr_cq->ib_cq.poll_ctx != IB_POLL_DIRECT) {
 		if (!hr_cq->is_armed) {
 			hr_cq->is_armed = 1;
 			list_add_tail(&hr_cq->node, cq_list);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0305/2077] RDMA/hns: Fix log flood after cmd_mbox failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (303 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0304/2077] RDMA/hns: Fix warning in poll cq direct mode Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0306/2077] ACPI: PAD: Fix teardown ordering in acpi_pad_remove() Greg Kroah-Hartman
                   ` (692 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lianfa Weng, Junxian Huang,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lianfa Weng <wenglianfa@huawei.com>

[ Upstream commit bbd97d71e53e551890e4115ad9de46b5f2ac0858 ]

hns_roce_cmd_mbox() is the command interface between driver and
hardware. When hardware is abnormal, the unlimited error printings
after hns_roce_cmd_mbox() failure will cause log flood and even
system crash.

Replace ibdev_err() and ibdev_warn() with their ratelimited versions
in the error handling path after hns_roce_cmd_mbox() (and its wrappers
hns_roce_create_hw_ctx/hns_roce_destroy_hw_ctx) fails.

Fixes: 9a4435375cd1 ("IB/hns: Add driver files for hns RoCE driver")
Link: https://patch.msgid.link/r/20260520055759.2354037-4-huangjunxian6@hisilicon.com
Signed-off-by: Lianfa Weng <wenglianfa@huawei.com>
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/hns/hns_roce_cq.c    |  6 +++---
 drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 18 +++++++++---------
 drivers/infiniband/hw/hns/hns_roce_mr.c    |  6 +++---
 drivers/infiniband/hw/hns/hns_roce_srq.c   |  2 +-
 4 files changed, 16 insertions(+), 16 deletions(-)

diff --git a/drivers/infiniband/hw/hns/hns_roce_cq.c b/drivers/infiniband/hw/hns/hns_roce_cq.c
index 621568e114054b..f7e220ab421981 100644
--- a/drivers/infiniband/hw/hns/hns_roce_cq.c
+++ b/drivers/infiniband/hw/hns/hns_roce_cq.c
@@ -174,9 +174,9 @@ static int hns_roce_create_cqc(struct hns_roce_dev *hr_dev,
 	ret = hns_roce_create_hw_ctx(hr_dev, mailbox, HNS_ROCE_CMD_CREATE_CQC,
 				     hr_cq->cqn);
 	if (ret)
-		ibdev_err(ibdev,
-			  "failed to send create cmd for CQ(0x%lx), ret = %d.\n",
-			  hr_cq->cqn, ret);
+		ibdev_err_ratelimited(ibdev,
+				      "failed to send create cmd for CQ(0x%lx), ret = %d.\n",
+				      hr_cq->cqn, ret);
 
 	hns_roce_free_cmd_mailbox(hr_dev, mailbox);
 
diff --git a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
index fa36700d0db2b6..8810fa0b659731 100644
--- a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
+++ b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
@@ -6192,9 +6192,9 @@ static int hns_roce_v2_modify_srq(struct ib_srq *ibsrq,
 					HNS_ROCE_CMD_MODIFY_SRQC, srq->srqn);
 		hns_roce_free_cmd_mailbox(hr_dev, mailbox);
 		if (ret)
-			ibdev_err(&hr_dev->ib_dev,
-				  "failed to handle cmd of modifying SRQ, ret = %d.\n",
-				  ret);
+			ibdev_err_ratelimited(&hr_dev->ib_dev,
+					      "failed to handle cmd of modifying SRQ, ret = %d.\n",
+					      ret);
 	}
 
 out:
@@ -6220,9 +6220,9 @@ static int hns_roce_v2_query_srq(struct ib_srq *ibsrq, struct ib_srq_attr *attr)
 	ret = hns_roce_cmd_mbox(hr_dev, 0, mailbox->dma,
 				HNS_ROCE_CMD_QUERY_SRQC, srq->srqn);
 	if (ret) {
-		ibdev_err(&hr_dev->ib_dev,
-			  "failed to process cmd of querying SRQ, ret = %d.\n",
-			  ret);
+		ibdev_err_ratelimited(&hr_dev->ib_dev,
+				      "failed to process cmd of querying SRQ, ret = %d.\n",
+				      ret);
 		goto out;
 	}
 
@@ -6328,9 +6328,9 @@ static int hns_roce_v2_query_mpt(struct hns_roce_dev *hr_dev, u32 key,
 	ret = hns_roce_cmd_mbox(hr_dev, 0, mailbox->dma, HNS_ROCE_CMD_QUERY_MPT,
 				key_to_hw_index(key));
 	if (ret) {
-		ibdev_err(&hr_dev->ib_dev,
-			  "failed to process cmd when querying MPT, ret = %d.\n",
-			  ret);
+		ibdev_err_ratelimited(&hr_dev->ib_dev,
+				      "failed to process cmd when querying MPT, ret = %d.\n",
+				      ret);
 		goto err_mailbox;
 	}
 
diff --git a/drivers/infiniband/hw/hns/hns_roce_mr.c b/drivers/infiniband/hw/hns/hns_roce_mr.c
index 25bfd3970f5b6e..c13d29cd0897bf 100644
--- a/drivers/infiniband/hw/hns/hns_roce_mr.c
+++ b/drivers/infiniband/hw/hns/hns_roce_mr.c
@@ -173,7 +173,7 @@ static int hns_roce_mr_enable(struct hns_roce_dev *hr_dev,
 	ret = hns_roce_create_hw_ctx(hr_dev, mailbox, HNS_ROCE_CMD_CREATE_MPT,
 				     mtpt_idx & (hr_dev->caps.num_mtpts - 1));
 	if (ret) {
-		dev_err(dev, "failed to create mpt, ret = %d.\n", ret);
+		dev_err_ratelimited(dev, "failed to create mpt, ret = %d.\n", ret);
 		goto err_page;
 	}
 
@@ -319,7 +319,7 @@ struct ib_mr *hns_roce_rereg_user_mr(struct ib_mr *ibmr, int flags, u64 start,
 	ret = hns_roce_destroy_hw_ctx(hr_dev, HNS_ROCE_CMD_DESTROY_MPT,
 				      mtpt_idx);
 	if (ret)
-		ibdev_warn(ib_dev, "failed to destroy MPT, ret = %d.\n", ret);
+		ibdev_warn_ratelimited(ib_dev, "failed to destroy MPT, ret = %d.\n", ret);
 
 	mr->enabled = 0;
 	mr->iova = virt_addr;
@@ -350,7 +350,7 @@ struct ib_mr *hns_roce_rereg_user_mr(struct ib_mr *ibmr, int flags, u64 start,
 	ret = hns_roce_create_hw_ctx(hr_dev, mailbox, HNS_ROCE_CMD_CREATE_MPT,
 				     mtpt_idx);
 	if (ret) {
-		ibdev_err(ib_dev, "failed to create MPT, ret = %d.\n", ret);
+		ibdev_err_ratelimited(ib_dev, "failed to create MPT, ret = %d.\n", ret);
 		goto free_cmd_mbox;
 	}
 
diff --git a/drivers/infiniband/hw/hns/hns_roce_srq.c b/drivers/infiniband/hw/hns/hns_roce_srq.c
index 8b94cbdfa54dfa..8feb5851067d82 100644
--- a/drivers/infiniband/hw/hns/hns_roce_srq.c
+++ b/drivers/infiniband/hw/hns/hns_roce_srq.c
@@ -103,7 +103,7 @@ static int hns_roce_create_srqc(struct hns_roce_dev *hr_dev,
 	ret = hns_roce_create_hw_ctx(hr_dev, mailbox, HNS_ROCE_CMD_CREATE_SRQ,
 				     srq->srqn);
 	if (ret)
-		ibdev_err(ibdev, "failed to config SRQC, ret = %d.\n", ret);
+		ibdev_err_ratelimited(ibdev, "failed to config SRQC, ret = %d.\n", ret);
 
 err_mbox:
 	hns_roce_free_cmd_mailbox(hr_dev, mailbox);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0306/2077] ACPI: PAD: Fix teardown ordering in acpi_pad_remove()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (304 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0305/2077] RDMA/hns: Fix log flood after cmd_mbox failure Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0307/2077] RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup Greg Kroah-Hartman
                   ` (691 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit 5776575d9a7e50e77c45e0ab0271c000496f341d ]

The ACPI notify handler installed by acpi_pad_probe() needs to be
removed before calling acpi_pad_idle_cpus() in acpi_pad_remove()
so it doesn't schedule idle time injection on some CPUs again.

Fixes: 8e0af5141ab9 ("ACPI: create Processor Aggregator Device driver")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/2064153.usQuhbGJ8B@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/acpi/acpi_pad.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/acpi/acpi_pad.c b/drivers/acpi/acpi_pad.c
index ec94b09bb74716..bff702835cfebb 100644
--- a/drivers/acpi/acpi_pad.c
+++ b/drivers/acpi/acpi_pad.c
@@ -435,12 +435,12 @@ static int acpi_pad_probe(struct platform_device *pdev)
 
 static void acpi_pad_remove(struct platform_device *pdev)
 {
+	acpi_dev_remove_notify_handler(ACPI_COMPANION(&pdev->dev),
+				       ACPI_DEVICE_NOTIFY, acpi_pad_notify);
+
 	mutex_lock(&isolated_cpus_lock);
 	acpi_pad_idle_cpus(0);
 	mutex_unlock(&isolated_cpus_lock);
-
-	acpi_dev_remove_notify_handler(ACPI_COMPANION(&pdev->dev),
-				       ACPI_DEVICE_NOTIFY, acpi_pad_notify);
 }
 
 static const struct acpi_device_id pad_device_ids[] = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0307/2077] RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (305 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0306/2077] ACPI: PAD: Fix teardown ordering in acpi_pad_remove() Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0308/2077] pinctrl: meson: amlogic-a4: fix gpio output glitch Greg Kroah-Hartman
                   ` (690 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Tao Cui, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tao Cui <cuitao@kylinos.cn>

[ Upstream commit b86fd95805a7bd4c5b9465c9e7f75e45bbe7eb6f ]

The error cleanup loop in rdma_counter_init() iterates with variable
'i' but accesses dev->port_data[port] instead of dev->port_data[i].
This causes the failed port's hstats to be freed multiple times while
leaking hstats of previously initialized ports.

Fixes: 56594ae1d250 ("RDMA/core: Annotate destroy of mutex to ensure that it is released as unlocked")
Link: https://patch.msgid.link/r/20260520104546.1776253-3-cuitao@kylinos.cn
Signed-off-by: Tao Cui <cuitao@kylinos.cn>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/core/counters.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/core/counters.c b/drivers/infiniband/core/counters.c
index c3aa6d7fc66b6e..5dad5d77ce2747 100644
--- a/drivers/infiniband/core/counters.c
+++ b/drivers/infiniband/core/counters.c
@@ -661,7 +661,7 @@ void rdma_counter_init(struct ib_device *dev)
 
 fail:
 	for (i = port; i >= rdma_start_port(dev); i--) {
-		port_counter = &dev->port_data[port].port_counter;
+		port_counter = &dev->port_data[i].port_counter;
 		rdma_free_hw_stats_struct(port_counter->hstats);
 		port_counter->hstats = NULL;
 		mutex_destroy(&port_counter->lock);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0308/2077] pinctrl: meson: amlogic-a4: fix gpio output glitch
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (306 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0307/2077] RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0309/2077] PM: sleep: Use complete() in device_pm_sleep_init() Greg Kroah-Hartman
                   ` (689 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Xianwei Zhao, Neil Armstrong,
	Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xianwei Zhao <xianwei.zhao@amlogic.com>

[ Upstream commit 45ad4de324cb1bba88e568b5bef633a79d926aed ]

When the system transitions from bootloader to kernel, the GPIO is
expected to keep driving high.

However, the Linux kernel first configures the pin direction and then
sets the output value. This may cause a brief low-level glitch on the
GPIO line, which can be problematic for regulator control.

By configuring the output value before switching the pin direction to
output, the glitch can be avoided.

This commit fixes the issue by swapping the configuration order.

Fixes: 6e9be3abb78c ("pinctrl: Add driver support for Amlogic SoCs")
Signed-off-by: Xianwei Zhao <xianwei.zhao@amlogic.com>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/meson/pinctrl-amlogic-a4.c | 15 +++++++--------
 1 file changed, 7 insertions(+), 8 deletions(-)

diff --git a/drivers/pinctrl/meson/pinctrl-amlogic-a4.c b/drivers/pinctrl/meson/pinctrl-amlogic-a4.c
index 35d27626a336b7..1bd58fbbd26ac6 100644
--- a/drivers/pinctrl/meson/pinctrl-amlogic-a4.c
+++ b/drivers/pinctrl/meson/pinctrl-amlogic-a4.c
@@ -548,11 +548,11 @@ static int aml_pinconf_set_output_drive(struct aml_pinctrl *info,
 {
 	int ret;
 
-	ret = aml_pinconf_set_output(info, pin, true);
+	ret = aml_pinconf_set_drive(info, pin, high);
 	if (ret)
 		return ret;
 
-	return aml_pinconf_set_drive(info, pin, high);
+	return aml_pinconf_set_output(info, pin, true);
 }
 
 static int aml_pinconf_set(struct pinctrl_dev *pcdev, unsigned int pin,
@@ -921,15 +921,14 @@ static int aml_gpio_direction_output(struct gpio_chip *chip, unsigned int gpio,
 	unsigned int bit, reg;
 	int ret;
 
-	aml_gpio_calc_reg_and_bit(bank, AML_REG_DIR, gpio, &reg, &bit);
-	ret = regmap_update_bits(bank->reg_gpio, reg, BIT(bit), 0);
+	aml_gpio_calc_reg_and_bit(bank, AML_REG_OUT, gpio, &reg, &bit);
+	ret = regmap_update_bits(bank->reg_gpio, reg, BIT(bit),
+				 value ? BIT(bit) : 0);
 	if (ret < 0)
 		return ret;
 
-	aml_gpio_calc_reg_and_bit(bank, AML_REG_OUT, gpio, &reg, &bit);
-
-	return regmap_update_bits(bank->reg_gpio, reg, BIT(bit),
-				  value ? BIT(bit) : 0);
+	aml_gpio_calc_reg_and_bit(bank, AML_REG_DIR, gpio, &reg, &bit);
+	return regmap_update_bits(bank->reg_gpio, reg, BIT(bit), 0);
 }
 
 static int aml_gpio_set(struct gpio_chip *chip, unsigned int gpio, int value)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0309/2077] PM: sleep: Use complete() in device_pm_sleep_init()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (307 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0308/2077] pinctrl: meson: amlogic-a4: fix gpio output glitch Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0310/2077] MIPS: Fix big-endian stack argument fetching in o32 wrapper Greg Kroah-Hartman
                   ` (688 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jiakai Xu, Rafael J. Wysocki,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiakai Xu <xujiakai24@mails.ucas.ac.cn>

[ Upstream commit 3855941f1e4069182c895d5093c5fa589f5b38bd ]

Replace complete_all() with complete() in device_pm_sleep_init() to allow
it to be called in atomic contexts without triggering a false-positive
WARNING from lockdep_assert_RT_in_threaded_ctx() when
CONFIG_PROVE_RAW_LOCK_NESTING is enabled.

device_pm_sleep_init() may be called during device initialization while
holding a raw_spinlock (e.g., from within device_initialize()), and
complete_all() is unsafe in atomic contexts on PREEMPT_RT kernels.
complete(), which is safe to call from any context, is sufficient here.

complete_all() sets the completion count to UINT_MAX/2 (permanently
signaled), while complete() increments it by 1. Since no threads can be
waiting during device initialization, both are functionally equivalent.
The completion is always reinitialized via reinit_completion() in
dpm_clear_async_state() before each suspend/resume cycle.

However, changing to complete() introduces a potential deadlock for
devices with no PM support (dev->power.no_pm = true). Such devices are
never added to the dpm_list and never go through dpm_clear_async_state(),
so their completion is never reinitialized. A parent device waiting on a
no_pm child across multiple suspend phases would consume the single-use
token in the first phase and block forever in the second.

Fix this by adding an early return in dpm_wait() when dev->power.no_pm is
set, since no_pm devices do not participate in system suspend/resume.

Fixes: 152e1d592071 ("PM: Prevent waiting forever on asynchronous resume after failing suspend")
Signed-off-by: Jiakai Xu <xujiakai24@mails.ucas.ac.cn>
[ rjw: Subject adjustment ]
Link: https://patch.msgid.link/20260523022314.2657232-1-xujiakai24@mails.ucas.ac.cn
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/base/power/main.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/base/power/main.c b/drivers/base/power/main.c
index e1b550664babbf..ed48c292f57576 100644
--- a/drivers/base/power/main.c
+++ b/drivers/base/power/main.c
@@ -115,7 +115,7 @@ void device_pm_sleep_init(struct device *dev)
 	dev->power.is_noirq_suspended = false;
 	dev->power.is_late_suspended = false;
 	init_completion(&dev->power.completion);
-	complete_all(&dev->power.completion);
+	complete(&dev->power.completion);
 	dev->power.wakeup = NULL;
 	INIT_LIST_HEAD(&dev->power.entry);
 }
@@ -252,6 +252,10 @@ static void dpm_wait(struct device *dev, bool async)
 	if (!dev)
 		return;
 
+	/* Devices with no PM support don't use the completion. */
+	if (dev->power.no_pm)
+		return;
+
 	if (async || (pm_async_enabled && dev->power.async_suspend))
 		wait_for_completion(&dev->power.completion);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0310/2077] MIPS: Fix big-endian stack argument fetching in o32 wrapper
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (308 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0309/2077] PM: sleep: Use complete() in device_pm_sleep_init() Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0311/2077] MIPS: DEC: Remove do_IRQ() call indirection Greg Kroah-Hartman
                   ` (687 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Maciej W. Rozycki,
	Thomas Bogendoerfer, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Maciej W. Rozycki <macro@orcam.me.uk>

[ Upstream commit 8e0780d30b1b51248e42895b7acc7a20f147b40b ]

Fix an issue in call_o32() where the upper 32-bit half of incoming n64
stack arguments is fetched and used for outgoing o32 stack arguments on
big-endian platforms.

This code was adapted from arch/mips/dec/prom/call_o32.S which was meant
for a little-endian platform only and therefore using 32-bit loads from
64-bit stack slot locations holding incoming stack arguments resulted in
correct values being retrieved for data that is expected to be 32-bit.

This works on little-endian platforms where the lower 32-bit half of the
64-bit value is located at every 64-bit stack slot location.  However on
big-endian platforms the lower 32-bit half is instead located at offset
4 from every 64-bit stack slot location.

So to fix the issue the offset of 4 would have to be used on big-endian
platforms only, or alternatively a 64-bit load from the 64-bit stack
slot location can be used across the board, as the subsequent 32-bit
store to the corresponding outgoing stack argument slot will correctly
truncate the value and cause no unpredictable result.  We already take
advantage of this architectural feature for the incoming arguments held
in $a6 and $a7 registers, since the o32 wrapper does not know how many
incoming arguments there are and consequently propagates incoming data
which may not be 32-bit.

Since this code is generally supposed to be used with the stack located
in cached memory there is no extra overhead expected for 64-bit loads as
opposed to 32-bit ones, so pick this variant for code simplicity.

Fixes: 231a35d37293 ("[MIPS] RM: Collected changes")
Signed-off-by: Maciej W. Rozycki <macro@orcam.me.uk>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/mips/fw/lib/call_o32.S | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/mips/fw/lib/call_o32.S b/arch/mips/fw/lib/call_o32.S
index ee856709e0b600..77533cfbdfc10b 100644
--- a/arch/mips/fw/lib/call_o32.S
+++ b/arch/mips/fw/lib/call_o32.S
@@ -74,7 +74,7 @@ NESTED(call_o32, O32_FRAMESZ, ra)
 		PTR_LA		t1,6*O32_SZREG(fp)
 		li		t2,O32_ARGC-6
 1:
-		lw		t3,(t0)
+		ld		t3,(t0)
 		REG_ADDU	t0,SZREG
 		sw		t3,(t1)
 		REG_SUBU	t2,1
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0311/2077] MIPS: DEC: Remove do_IRQ() call indirection
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (309 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0310/2077] MIPS: Fix big-endian stack argument fetching in o32 wrapper Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0312/2077] mips: ralink: mt7621: add missing __iomem Greg Kroah-Hartman
                   ` (686 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Maciej W. Rozycki,
	Thomas Bogendoerfer, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Maciej W. Rozycki <macro@orcam.me.uk>

[ Upstream commit 35554eadc1b127bb5294504a4ac8f3a5dd9e299d ]

As from commit 8f99a1626535 ("MIPS: Tracing: Add IRQENTRY_EXIT section
for MIPS") do_IRQ() is not a macro anymore and can be invoked directly
from assembly code, as a tail call.  Remove the dec_irq_dispatch() stub
then and the indirection previously introduced with commit 187933f23679
("[MIPS] do_IRQ cleanup"), improving performance by reducing the number
of control flow changes and the overall instruction count, while fixing
a compiler's complaint about a missing prototype for said stub:

arch/mips/dec/setup.c:780:25: warning: no previous prototype for 'dec_irq_dispatch' [-Wmissing-prototypes]
  780 | asmlinkage unsigned int dec_irq_dispatch(unsigned int irq)
      |                         ^~~~~~~~~~~~~~~~

(which gets promoted to a compilation error with CONFIG_WERROR).

Fixes: 8f99a1626535 ("MIPS: Tracing: Add IRQENTRY_EXIT section for MIPS")
Signed-off-by: Maciej W. Rozycki <macro@orcam.me.uk>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/mips/dec/int-handler.S | 2 +-
 arch/mips/dec/setup.c       | 6 ------
 2 files changed, 1 insertion(+), 7 deletions(-)

diff --git a/arch/mips/dec/int-handler.S b/arch/mips/dec/int-handler.S
index 011d1d678840aa..a0b439c90488fc 100644
--- a/arch/mips/dec/int-handler.S
+++ b/arch/mips/dec/int-handler.S
@@ -277,7 +277,7 @@
 		 srlv	t3,t1,t2
 
 handle_it:
-		j	dec_irq_dispatch
+		j	do_IRQ
 		 nop
 
 #if defined(CONFIG_32BIT) && defined(CONFIG_MIPS_FP_SUPPORT)
diff --git a/arch/mips/dec/setup.c b/arch/mips/dec/setup.c
index 87f0a1436bf9cc..abe42616498db9 100644
--- a/arch/mips/dec/setup.c
+++ b/arch/mips/dec/setup.c
@@ -776,9 +776,3 @@ void __init arch_init_irq(void)
 			pr_err("Failed to register halt interrupt\n");
 	}
 }
-
-asmlinkage unsigned int dec_irq_dispatch(unsigned int irq)
-{
-	do_IRQ(irq);
-	return 0;
-}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0312/2077] mips: ralink: mt7621: add missing __iomem
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (310 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0311/2077] MIPS: DEC: Remove do_IRQ() call indirection Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0313/2077] mips: n64: add __iomem for writel call Greg Kroah-Hartman
                   ` (685 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, kernel test robot, Rosen Penev,
	Sergio Paracuellos, Thomas Bogendoerfer, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rosen Penev <rosenp@gmail.com>

[ Upstream commit 4ddaf88aadd3bd09c2eb3734c53d2864af6b144e ]

raw_readl and writel calls expect pointers annotated with __iomem.

Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild/202211060456.cnV6IK6G-lkp@intel.com/
Fixes: cc19db8b312a ("MIPS: ralink: mt7621: do memory detection on KSEG1")
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Reviewed-by: Sergio Paracuellos <sergio.paracuellos@gmail.com>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/mips/ralink/mt7621.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/mips/ralink/mt7621.c b/arch/mips/ralink/mt7621.c
index a4bdda8541c074..ae7b8cfedd5f7f 100644
--- a/arch/mips/ralink/mt7621.c
+++ b/arch/mips/ralink/mt7621.c
@@ -63,7 +63,7 @@ phys_addr_t mips_cpc_default_phys_base(void)
 
 static bool __init mt7621_addr_wraparound_test(phys_addr_t size)
 {
-	void *dm = (void *)KSEG1ADDR(&detect_magic);
+	void __iomem *dm = (void __iomem *)KSEG1ADDR(&detect_magic);
 
 	if (CPHYSADDR(dm + size) >= MT7621_LOWMEM_MAX_SIZE)
 		return true;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0313/2077] mips: n64: add __iomem for writel call
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (311 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0312/2077] mips: ralink: mt7621: add missing __iomem Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0314/2077] driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() Greg Kroah-Hartman
                   ` (684 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, kernel test robot, Rosen Penev,
	Thomas Bogendoerfer, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rosen Penev <rosenp@gmail.com>

[ Upstream commit 579f5329d5df2dbcf4bb5ef398701c2501d24892 ]

sparse: incorrect type in argument 2 (different address spaces) @@
expected void volatile [noderef] __iomem *mem @@
got unsigned int [usertype] *

Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202105261445.AcvPd2EE-lkp@intel.com/
Fixes: baec970aa5ba ("mips: Add N64 machine type")
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/mips/n64/init.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/mips/n64/init.c b/arch/mips/n64/init.c
index dfbd864f466700..66ec28ab41f321 100644
--- a/arch/mips/n64/init.c
+++ b/arch/mips/n64/init.c
@@ -50,7 +50,7 @@ void __init prom_init(void)
 
 #define W 320
 #define H 240
-#define REG_BASE ((u32 *) CKSEG1ADDR(0x4400000))
+#define REG_BASE ((u32 __iomem *) CKSEG1ADDR(0x4400000))
 
 static void __init n64rdp_write_reg(const u8 reg, const u32 value)
 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0314/2077] driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (312 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0313/2077] mips: n64: add __iomem for writel call Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0315/2077] driver core: Guard deferred probe timeout extension with delayed_work_pending() Greg Kroah-Hartman
                   ` (683 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Biju Das, Geert Uytterhoeven,
	Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Danilo Krummrich <dakr@kernel.org>

[ Upstream commit f9e6da99fe49277979798a1c3b9790ae10aaa18a ]

mod_delayed_work() takes jiffies, not seconds. Thus, restore the dropped
conversion.

While at it, fix incorrect indentation.

Fixes: 1137838865bf ("driver core: Use mod_delayed_work to prevent lost deferred probe work")
Tested-by: Biju Das <biju.das.jz@bp.renesas.com>
Tested-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Link: https://patch.msgid.link/20260525012340.3860581-1-dakr@kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/base/dd.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/base/dd.c b/drivers/base/dd.c
index 3523a5d8ec5030..6ced7272b97e3c 100644
--- a/drivers/base/dd.c
+++ b/drivers/base/dd.c
@@ -324,7 +324,7 @@ void deferred_probe_extend_timeout(void)
 	 * start a new one.
 	 */
 	if (mod_delayed_work(system_wq, &deferred_probe_timeout_work,
-						 driver_deferred_probe_timeout))
+			     secs_to_jiffies(driver_deferred_probe_timeout)))
 		pr_debug("Extended deferred probe timeout by %d secs\n",
 					driver_deferred_probe_timeout);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0315/2077] driver core: Guard deferred probe timeout extension with delayed_work_pending()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (313 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0314/2077] driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0316/2077] arm64: tegra: Fix address of Tegra264 main GPIO controller Greg Kroah-Hartman
                   ` (682 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Geert Uytterhoeven, Danilo Krummrich,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Danilo Krummrich <dakr@kernel.org>

[ Upstream commit 557495bc879013c3d5e21d667e987e7ce3a514de ]

mod_delayed_work() unconditionally queues the work even when it wasn't
previously pending, which can fire the timeout prematurely or restart it
after it already fired. Add a delayed_work_pending() guard to restore
the originally intended semantics.

Premature firing calls fw_devlink_drivers_done() before all built-in
drivers have registered, causing fw_devlink to prematurely relax device
links for suppliers whose drivers haven't loaded yet.

Fixes: 1137838865bf ("driver core: Use mod_delayed_work to prevent lost deferred probe work")
Tested-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Link: https://patch.msgid.link/20260525012340.3860581-2-dakr@kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/base/dd.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/base/dd.c b/drivers/base/dd.c
index 6ced7272b97e3c..f64175afefc915 100644
--- a/drivers/base/dd.c
+++ b/drivers/base/dd.c
@@ -323,7 +323,8 @@ void deferred_probe_extend_timeout(void)
 	 * If the work hasn't been queued yet or if the work expired, don't
 	 * start a new one.
 	 */
-	if (mod_delayed_work(system_wq, &deferred_probe_timeout_work,
+	if (delayed_work_pending(&deferred_probe_timeout_work) &&
+	    mod_delayed_work(system_wq, &deferred_probe_timeout_work,
 			     secs_to_jiffies(driver_deferred_probe_timeout)))
 		pr_debug("Extended deferred probe timeout by %d secs\n",
 					driver_deferred_probe_timeout);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0316/2077] arm64: tegra: Fix address of Tegra264 main GPIO controller
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (314 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0315/2077] driver core: Guard deferred probe timeout extension with delayed_work_pending() Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0317/2077] mtd: spi-nor: debugfs: Fix the flags list Greg Kroah-Hartman
                   ` (681 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jon Hunter, Thierry Reding,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jon Hunter <jonathanh@nvidia.com>

[ Upstream commit 7f2eeae12690aaee6195f85ed129a29c17f156d1 ]

The 64-bit address of the main GPIO controller on Tegra264 is
0x810c300000. The main GPIO controller was incorrectly added under the
bus@0 node instead of the bus@8100000000 node breaking the boot on
Tegra264. Fix this by moving to main GPIO controller node under
bus@8100000000.

Fixes: c70e6bc11d20 ("arm64: tegra: Add Tegra264 GPIO controllers")
Signed-off-by: Jon Hunter <jonathanh@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/nvidia/tegra264.dtsi | 88 ++++++++++++------------
 1 file changed, 44 insertions(+), 44 deletions(-)

diff --git a/arch/arm64/boot/dts/nvidia/tegra264.dtsi b/arch/arm64/boot/dts/nvidia/tegra264.dtsi
index 06d8357bdf527d..2d8e7e37830ff2 100644
--- a/arch/arm64/boot/dts/nvidia/tegra264.dtsi
+++ b/arch/arm64/boot/dts/nvidia/tegra264.dtsi
@@ -3277,50 +3277,6 @@ rtc: rtc@c2c0000 {
 			status = "disabled";
 		};
 
-		gpio_main: gpio@c300000 {
-			compatible = "nvidia,tegra264-gpio";
-			reg = <0x00 0x0c300000 0x0 0x4000>,
-			      <0x00 0x0c310000 0x0 0x4000>;
-			reg-names = "security", "gpio";
-			wakeup-parent = <&pmc>;
-			interrupts =  <GIC_SPI 99 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 100 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 101 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 102 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 103 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 104 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 105 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 106 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 107 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 108 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 109 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 110 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 111 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 112 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 113 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 114 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 115 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 116 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 117 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 118 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 119 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 120 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 121 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 122 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 91 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 92 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 93 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 94 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 95 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 96 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 97 IRQ_TYPE_LEVEL_HIGH>,
-				      <GIC_SPI 98 IRQ_TYPE_LEVEL_HIGH>;
-			gpio-controller;
-			#gpio-cells = <2>;
-			interrupt-controller;
-			#interrupt-cells = <2>;
-		};
-
 		serial@c4e0000 {
 			compatible = "nvidia,tegra264-utc";
 			reg = <0x0 0x0c4e0000 0x0 0x8000>,
@@ -3586,6 +3542,50 @@ pci@c000000 {
 			status = "disabled";
 		};
 
+		gpio_main: gpio@c300000 {
+			compatible = "nvidia,tegra264-gpio";
+			reg = <0x00 0x0c300000 0x0 0x4000>,
+			      <0x00 0x0c310000 0x0 0x4000>;
+			reg-names = "security", "gpio";
+			wakeup-parent = <&pmc>;
+			interrupts =  <GIC_SPI 99 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 100 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 101 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 102 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 103 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 104 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 105 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 106 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 107 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 108 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 109 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 110 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 111 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 112 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 113 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 114 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 115 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 116 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 117 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 118 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 119 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 120 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 121 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 122 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 91 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 92 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 93 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 94 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 95 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 96 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 97 IRQ_TYPE_LEVEL_HIGH>,
+				      <GIC_SPI 98 IRQ_TYPE_LEVEL_HIGH>;
+			gpio-controller;
+			#gpio-cells = <2>;
+			interrupt-controller;
+			#interrupt-cells = <2>;
+		};
+
 		i2c14: i2c@c410000 {
 			compatible = "nvidia,tegra264-i2c";
 			reg = <0x00 0x0c410000 0x0 0x10000>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0317/2077] mtd: spi-nor: debugfs: Fix the flags list
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (315 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0316/2077] arm64: tegra: Fix address of Tegra264 main GPIO controller Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0318/2077] mtd: spi-nor: Drop duplicate Kconfig dependency Greg Kroah-Hartman
                   ` (680 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Walle, Miquel Raynal,
	Pratyush Yadav, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Miquel Raynal <miquel.raynal@bootlin.com>

[ Upstream commit 829dff83597615208aedf0f5abb3878b47f2314d ]

As mentioned above the spi_nor_option_flags enumeration in core.h, this
list should be kept in sync with the one in the core.

Add the missing flag.

Fixes: 6a42bc97ccda ("mtd: spi-nor: core: Allow specifying the byte order in Octal DTR mode")
Reviewed-by: Michael Walle <mwalle@kernel.org>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Pratyush Yadav <pratyush@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/mtd/spi-nor/debugfs.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/mtd/spi-nor/debugfs.c b/drivers/mtd/spi-nor/debugfs.c
index 14ba1680c31547..c0bd8f1149a51d 100644
--- a/drivers/mtd/spi-nor/debugfs.c
+++ b/drivers/mtd/spi-nor/debugfs.c
@@ -29,6 +29,7 @@ static const char *const snor_f_names[] = {
 	SNOR_F_NAME(RWW),
 	SNOR_F_NAME(ECC),
 	SNOR_F_NAME(NO_WP),
+	SNOR_F_NAME(SWAP16),
 };
 #undef SNOR_F_NAME
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0318/2077] mtd: spi-nor: Drop duplicate Kconfig dependency
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (316 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0317/2077] mtd: spi-nor: debugfs: Fix the flags list Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0319/2077] wifi: ath12k: fix error unwind on arch_init() failure in PCI probe Greg Kroah-Hartman
                   ` (679 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Miquel Raynal, Michael Walle,
	Pratyush Yadav, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Miquel Raynal <miquel.raynal@bootlin.com>

[ Upstream commit a6470e2162e9c3779a4bd6ff3bed1b81d796e46e ]

I do not think the MTD dependency is needed twice. This is likely a
duplicate coming from a former rebase when the spi-nor core got cleaned
up a while ago. Remove the extra line.

Fixes: b35b9a10362d ("mtd: spi-nor: Move m25p80 code in spi-nor.c")
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Reviewed-by: Michael Walle <mwalle@kernel.org>
Signed-off-by: Pratyush Yadav <pratyush@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/mtd/spi-nor/Kconfig | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/mtd/spi-nor/Kconfig b/drivers/mtd/spi-nor/Kconfig
index 24cd25de2b8b71..fd05a24d64a96f 100644
--- a/drivers/mtd/spi-nor/Kconfig
+++ b/drivers/mtd/spi-nor/Kconfig
@@ -1,7 +1,6 @@
 # SPDX-License-Identifier: GPL-2.0-only
 menuconfig MTD_SPI_NOR
 	tristate "SPI NOR device support"
-	depends on MTD
 	depends on MTD && SPI_MASTER
 	select SPI_MEM
 	help
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0319/2077] wifi: ath12k: fix error unwind on arch_init() failure in PCI probe
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (317 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0318/2077] mtd: spi-nor: Drop duplicate Kconfig dependency Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0320/2077] cpufreq: governor: Fix data races on per-CPU idle/nice baselines Greg Kroah-Hartman
                   ` (678 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ripan Deuri, Rameshkumar Sundaram,
	Baochen Qiang, Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ripan Deuri <ripan.deuri@oss.qualcomm.com>

[ Upstream commit d5c336161088c588f85da64f48ba6deead194afd ]

When arch_init() fails in ath12k_pci_probe(), the code jumps to
err_pci_msi_free, leaking resources in teardown.

Redirect the failure path to err_free_irq so teardown matches the setup order.

Compile-tested only.

Fixes: 614c23e24ee8 ("wifi: ath12k: Support arch-specific DP device allocation")
Signed-off-by: Ripan Deuri <ripan.deuri@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260519192815.3911324-1-ripan.deuri@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/ath12k/pci.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wireless/ath/ath12k/pci.c b/drivers/net/wireless/ath/ath12k/pci.c
index 375277ca2b8921..d9a22d6afbb020 100644
--- a/drivers/net/wireless/ath/ath12k/pci.c
+++ b/drivers/net/wireless/ath/ath12k/pci.c
@@ -1639,7 +1639,7 @@ static int ath12k_pci_probe(struct pci_dev *pdev,
 	ret = ab_pci->device_family_ops->arch_init(ab);
 	if (ret) {
 		ath12k_err(ab, "PCI arch_init failed %d\n", ret);
-		goto err_pci_msi_free;
+		goto err_free_irq;
 	}
 
 	ret = ath12k_core_init(ab);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0320/2077] cpufreq: governor: Fix data races on per-CPU idle/nice baselines
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (318 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0319/2077] wifi: ath12k: fix error unwind on arch_init() failure in PCI probe Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0321/2077] cpufreq: governor: Fix stale prev_cpu_nice spike when enabling ignore_nice_load Greg Kroah-Hartman
                   ` (677 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhongqiu Han, Rafael J. Wysocki,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>

[ Upstream commit 91f5d698478f3d07230cf9ca4dfaf67e0316a53d ]

gov_update_cpu_data() resets per-CPU prev_cpu_idle for every CPU in the
governed domain, and conditionally resets prev_cpu_nice when
ignore_nice_load is set. It is called from sysfs store callbacks
(e.g. ignore_nice_load_store) which run under attr_set->update_lock,
held by the surrounding governor_store().

Concurrently, dbs_work_handler() calls gov->gov_dbs_update() (which calls
dbs_update()) under policy_dbs->update_mutex. dbs_update() both reads and
writes the same prev_cpu_idle / prev_cpu_nice fields. The potential race
path is:

Path A (sysfs write, holds attr_set->update_lock only):

  governor_store()
    mutex_lock(&attr_set->update_lock)
    ignore_nice_load_store()
      dbs_data->ignore_nice_load = input
      gov_update_cpu_data(dbs_data)
        list_for_each_entry(policy_dbs, ...)
          for_each_cpu(j, ...)
            j_cdbs->prev_cpu_idle = get_cpu_idle_time(...)  /* write */
            j_cdbs->prev_cpu_nice = kcpustat_field(...)     /* write */
    mutex_unlock(&attr_set->update_lock)

Path B (work queue, holds policy_dbs->update_mutex only):

  dbs_work_handler()
    mutex_lock(&policy_dbs->update_mutex)
    gov->gov_dbs_update(policy)
      dbs_update()
        for_each_cpu(j, policy->cpus)
          idle_time = cur - j_cdbs->prev_cpu_idle           /* read  */
          j_cdbs->prev_cpu_idle = cur_idle_time             /* write */
          idle_time += cur_nice - j_cdbs->prev_cpu_nice     /* read  */
          j_cdbs->prev_cpu_nice = cur_nice                  /* write */
    mutex_unlock(&policy_dbs->update_mutex)

Because attr_set->update_lock and policy_dbs->update_mutex are two
completely independent locks, the two paths are not mutually exclusive.
This results in a data race on cpu_dbs_info.prev_cpu_idle and
cpu_dbs_info.prev_cpu_nice.

Fix this by also acquiring policy_dbs->update_mutex in
gov_update_cpu_data() for each policy, so that path A participates in
the mutual exclusion already established by dbs_work_handler(). Also
update the function comment to accurately reflect the two-level locking
contract.

Additionally, cpufreq_dbs_governor_start() initializes prev_cpu_idle
using io_busy read from dbs_data->io_is_busy without holding
policy_dbs->update_mutex.  A concurrent io_is_busy_store() can update
io_is_busy and call gov_update_cpu_data(), which writes prev_cpu_idle
with the new value under the mutex.  cpufreq_dbs_governor_start() then
overwrites prev_cpu_idle with the stale io_busy value, leaving the
baseline inconsistent with the tunable.  Fix this by reading io_busy
inside the mutex.

The root of this race dates back to the original ondemand/conservative
governors. Before commit ee88415caf73 ("[CPUFREQ] Cleanup locking in
conservative governor") and commit 5a75c82828e7 ("[CPUFREQ] Cleanup
locking in ondemand governor"), all accesses to prev_cpu_idle and
prev_cpu_nice in cpufreq_governor_dbs() (path X), store_ignore_nice_load()
/io_is_busy_store() (path Y), and do_dbs_timer() (path Z) were serialised
by the same dbs_mutex, so no race existed. Those two commits switched
do_dbs_timer() from dbs_mutex to a per-policy/per-cpu timer_mutex to
reduce lock contention, but left path Y (store) still holding dbs_mutex.
As a result, path Y (store) and path Z (do_dbs_timer) no longer shared a
common lock, introducing a potential race on prev_cpu_idle/prev_cpu_nice
between path Y (store) and dbs_check_cpu().

Commit 326c86deaed54a ("[CPUFREQ] Remove unneeded locks") then removed
dbs_mutex from store_ignore_nice_load()/io_is_busy_store() entirely,
introducing an additional potential race between path Y (now lockless)
and cpufreq_governor_dbs() (path X, still holding dbs_mutex), while the
race between path Y and path Z remained.

Fixes: ee88415caf736b ("[CPUFREQ] Cleanup locking in conservative governor")
Fixes: 5a75c82828e7c0 ("[CPUFREQ] Cleanup locking in ondemand governor")
Fixes: 326c86deaed54a ("[CPUFREQ] Remove unneeded locks")
Signed-off-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
Link: https://patch.msgid.link/20260419132655.3800673-2-zhongqiu.han@oss.qualcomm.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cpufreq/cpufreq_governor.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/cpufreq/cpufreq_governor.c b/drivers/cpufreq/cpufreq_governor.c
index 86f35e45191423..fc6f705c5a9c70 100644
--- a/drivers/cpufreq/cpufreq_governor.c
+++ b/drivers/cpufreq/cpufreq_governor.c
@@ -90,7 +90,8 @@ EXPORT_SYMBOL_GPL(sampling_rate_store);
  * (that may be a single policy or a bunch of them if governor tunables are
  * system-wide).
  *
- * Call under the @dbs_data mutex.
+ * Call under the @dbs_data->attr_set.update_lock. The per-policy
+ * update_mutex is acquired and released internally for each policy.
  */
 void gov_update_cpu_data(struct dbs_data *dbs_data)
 {
@@ -99,6 +100,7 @@ void gov_update_cpu_data(struct dbs_data *dbs_data)
 	list_for_each_entry(policy_dbs, &dbs_data->attr_set.policy_list, list) {
 		unsigned int j;
 
+		mutex_lock(&policy_dbs->update_mutex);
 		for_each_cpu(j, policy_dbs->policy->cpus) {
 			struct cpu_dbs_info *j_cdbs = &per_cpu(cpu_dbs, j);
 
@@ -107,6 +109,7 @@ void gov_update_cpu_data(struct dbs_data *dbs_data)
 			if (dbs_data->ignore_nice_load)
 				j_cdbs->prev_cpu_nice = kcpustat_field(&kcpustat_cpu(j), CPUTIME_NICE, j);
 		}
+		mutex_unlock(&policy_dbs->update_mutex);
 	}
 }
 EXPORT_SYMBOL_GPL(gov_update_cpu_data);
@@ -527,8 +530,9 @@ int cpufreq_dbs_governor_start(struct cpufreq_policy *policy)
 
 	sampling_rate = dbs_data->sampling_rate;
 	ignore_nice = dbs_data->ignore_nice_load;
-	io_busy = dbs_data->io_is_busy;
 
+	mutex_lock(&policy_dbs->update_mutex);
+	io_busy = dbs_data->io_is_busy;
 	for_each_cpu(j, policy->cpus) {
 		struct cpu_dbs_info *j_cdbs = &per_cpu(cpu_dbs, j);
 
@@ -541,6 +545,7 @@ int cpufreq_dbs_governor_start(struct cpufreq_policy *policy)
 		if (ignore_nice)
 			j_cdbs->prev_cpu_nice = kcpustat_field(&kcpustat_cpu(j), CPUTIME_NICE, j);
 	}
+	mutex_unlock(&policy_dbs->update_mutex);
 
 	gov->start(policy);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0321/2077] cpufreq: governor: Fix stale prev_cpu_nice spike when enabling ignore_nice_load
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (319 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0320/2077] cpufreq: governor: Fix data races on per-CPU idle/nice baselines Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0322/2077] ALSA: xen-front: Reset event channel state on stream clear Greg Kroah-Hartman
                   ` (676 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhongqiu Han, Rafael J. Wysocki,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>

[ Upstream commit 24fc5870808dea4290e9563746cb5f2146043c6c ]

When ignore_nice_load is toggled from 0 to 1 via sysfs, dbs_update() may
run concurrently and observe the new tunable value while prev_cpu_nice
still holds a stale baseline, producing a spurious massive idle_time that
results in an incorrect CPU load value.

The race can be illustrated with two concurrent paths:

Path A (sysfs write, holds attr_set->update_lock):

governor_store()
  mutex_lock(&attr_set->update_lock)
  ignore_nice_load_store()
    dbs_data->ignore_nice_load = 1              /* (A1) */
    gov_update_cpu_data(dbs_data)
      mutex_lock(&policy_dbs->update_mutex)     /* (A2) */
        j_cdbs->prev_cpu_nice = kcpustat_field(...)
      mutex_unlock(&policy_dbs->update_mutex)
  mutex_unlock(&attr_set->update_lock)

Path B (work queue, wins the race between A1 and A2):

dbs_work_handler()
  mutex_lock(&policy_dbs->update_mutex)         /* acquired before A2 */
  dbs_update()
    ignore_nice = dbs_data->ignore_nice_load    /* sees new value: 1 */
    cur_nice = kcpustat_field(...)
    idle_time += div_u64(cur_nice - j_cdbs->prev_cpu_nice, ..) /* stale */
    j_cdbs->prev_cpu_nice = cur_nice
  mutex_unlock(&policy_dbs->update_mutex)

Fix this by unconditionally sampling cur_nice and advancing prev_cpu_nice
in dbs_update() on every call, regardless of ignore_nice. With
prev_cpu_nice always reflecting the most recent sample, enabling
ignore_nice_load can never produce a stale-baseline spike: the delta will
always be the nice time accumulated in the last sampling interval, not
since boot. The additional kcpustat_field() call per CPU per sample is
negligible given that the sampling path already reads idle and load
accounting.

To keep prev_cpu_nice handling consistent with the always-tracking
semantics introduced above:

  - gov_update_cpu_data() unconditionally resets prev_cpu_nice alongside
    prev_cpu_idle, so both baselines share the same timestamp when
    io_is_busy changes.  This prevents an interval mismatch between
    idle_time and nice_delta on the next dbs_update() when
    ignore_nice_load is enabled.
  - cpufreq_dbs_governor_start() unconditionally initializes prev_cpu_nice
    so the baseline is always valid from the first dbs_update() call;
    remove the ignore_nice guard and the now-unused ignore_nice variable.

Fixes: ee88415caf736b ("[CPUFREQ] Cleanup locking in conservative governor")
Fixes: 5a75c82828e7c0 ("[CPUFREQ] Cleanup locking in ondemand governor")
Fixes: 326c86deaed54a ("[CPUFREQ] Remove unneeded locks")
Signed-off-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
Link: https://patch.msgid.link/20260419132655.3800673-3-zhongqiu.han@oss.qualcomm.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cpufreq/cpufreq_governor.c | 33 +++++++++++++++++++-----------
 1 file changed, 21 insertions(+), 12 deletions(-)

diff --git a/drivers/cpufreq/cpufreq_governor.c b/drivers/cpufreq/cpufreq_governor.c
index fc6f705c5a9c70..8a85bd32defe7a 100644
--- a/drivers/cpufreq/cpufreq_governor.c
+++ b/drivers/cpufreq/cpufreq_governor.c
@@ -92,6 +92,12 @@ EXPORT_SYMBOL_GPL(sampling_rate_store);
  *
  * Call under the @dbs_data->attr_set.update_lock. The per-policy
  * update_mutex is acquired and released internally for each policy.
+ *
+ * Note: prev_cpu_nice is reset here unconditionally alongside prev_cpu_idle.
+ * When io_is_busy changes, both baselines must be advanced to the same
+ * timestamp so that the next dbs_update() computes idle_time and nice_delta
+ * over the same interval, preventing an artificially inflated idle_time when
+ * ignore_nice_load is enabled.
  */
 void gov_update_cpu_data(struct dbs_data *dbs_data)
 {
@@ -106,8 +112,7 @@ void gov_update_cpu_data(struct dbs_data *dbs_data)
 
 			j_cdbs->prev_cpu_idle = get_cpu_idle_time(j, &j_cdbs->prev_update_time,
 								  dbs_data->io_is_busy);
-			if (dbs_data->ignore_nice_load)
-				j_cdbs->prev_cpu_nice = kcpustat_field(&kcpustat_cpu(j), CPUTIME_NICE, j);
+			j_cdbs->prev_cpu_nice = kcpustat_field(&kcpustat_cpu(j), CPUTIME_NICE, j);
 		}
 		mutex_unlock(&policy_dbs->update_mutex);
 	}
@@ -121,6 +126,7 @@ unsigned int dbs_update(struct cpufreq_policy *policy)
 	unsigned int ignore_nice = dbs_data->ignore_nice_load;
 	unsigned int max_load = 0, idle_periods = UINT_MAX;
 	unsigned int sampling_rate, io_busy, j;
+	u64 cur_nice;
 
 	/*
 	 * Sometimes governors may use an additional multiplier to increase
@@ -167,12 +173,18 @@ unsigned int dbs_update(struct cpufreq_policy *policy)
 
 		j_cdbs->prev_cpu_idle = cur_idle_time;
 
-		if (ignore_nice) {
-			u64 cur_nice = kcpustat_field(&kcpustat_cpu(j), CPUTIME_NICE, j);
-
+		/*
+		 * Always sample cur_nice and advance prev_cpu_nice, regardless
+		 * of ignore_nice.  This keeps prev_cpu_nice current so that
+		 * enabling ignore_nice_load via sysfs never produces a
+		 * stale-baseline spike (the delta will be at most one sampling
+		 * interval of accumulated nice time, not since boot).
+		 */
+		cur_nice = kcpustat_field(&kcpustat_cpu(j), CPUTIME_NICE, j);
+		if (ignore_nice)
 			idle_time += div_u64(cur_nice - j_cdbs->prev_cpu_nice, NSEC_PER_USEC);
-			j_cdbs->prev_cpu_nice = cur_nice;
-		}
+
+		j_cdbs->prev_cpu_nice = cur_nice;
 
 		if (unlikely(!time_elapsed)) {
 			/*
@@ -519,7 +531,7 @@ int cpufreq_dbs_governor_start(struct cpufreq_policy *policy)
 	struct dbs_governor *gov = dbs_governor_of(policy);
 	struct policy_dbs_info *policy_dbs = policy->governor_data;
 	struct dbs_data *dbs_data = policy_dbs->dbs_data;
-	unsigned int sampling_rate, ignore_nice, j;
+	unsigned int sampling_rate, j;
 	unsigned int io_busy;
 
 	if (!policy->cur)
@@ -529,7 +541,6 @@ int cpufreq_dbs_governor_start(struct cpufreq_policy *policy)
 	policy_dbs->rate_mult = 1;
 
 	sampling_rate = dbs_data->sampling_rate;
-	ignore_nice = dbs_data->ignore_nice_load;
 
 	mutex_lock(&policy_dbs->update_mutex);
 	io_busy = dbs_data->io_is_busy;
@@ -541,9 +552,7 @@ int cpufreq_dbs_governor_start(struct cpufreq_policy *policy)
 		 * Make the first invocation of dbs_update() compute the load.
 		 */
 		j_cdbs->prev_load = 0;
-
-		if (ignore_nice)
-			j_cdbs->prev_cpu_nice = kcpustat_field(&kcpustat_cpu(j), CPUTIME_NICE, j);
+		j_cdbs->prev_cpu_nice = kcpustat_field(&kcpustat_cpu(j), CPUTIME_NICE, j);
 	}
 	mutex_unlock(&policy_dbs->update_mutex);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0322/2077] ALSA: xen-front: Reset event channel state on stream clear
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (320 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0321/2077] cpufreq: governor: Fix stale prev_cpu_nice spike when enabling ignore_nice_load Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0323/2077] ALSA: xen-front: Connect event channel after stream prepare Greg Kroah-Hartman
                   ` (675 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Takashi Iwai,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cássio Gabriel <cassiogabrielcontato@gmail.com>

[ Upstream commit 9cd81152373c560b8aa8299b0705c4db82b103b7 ]

xen_snd_front_evtchnl_pair_clear() resets evt_next_id for both
channels. That is correct for the request channel, where evt_next_id is
used to allocate the next request id. It is wrong for the event channel:
incoming events are validated against evt_id, and evt_id is incremented
by evtchnl_interrupt_evt().

This leaves the expected event id from the previous stream instance. A
backend that restarts event ids for a reopened stream can then have valid
current-position events dropped until the stale frontend id catches up.

Reset evt_id for the event channel. Also advance the event-page consumer
to the current producer while clearing the stream, so obsolete events
queued for the previous stream instance are not delivered to the next
ALSA runtime.

Fixes: 1cee559351a7 ("ALSA: xen-front: Implement ALSA virtual sound driver")
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260526-alsa-xen-event-channel-fixes-v1-1-91d3a6a50778@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/xen/xen_snd_front_evtchnl.c | 8 ++++++--
 sound/xen/xen_snd_front_evtchnl.h | 4 ++--
 2 files changed, 8 insertions(+), 4 deletions(-)

diff --git a/sound/xen/xen_snd_front_evtchnl.c b/sound/xen/xen_snd_front_evtchnl.c
index bc03f71bf16e33..09e4c1d0563632 100644
--- a/sound/xen/xen_snd_front_evtchnl.c
+++ b/sound/xen/xen_snd_front_evtchnl.c
@@ -456,7 +456,11 @@ void xen_snd_front_evtchnl_pair_clear(struct xen_snd_front_evtchnl_pair *evt_pai
 	}
 
 	scoped_guard(mutex, &evt_pair->evt.ring_io_lock) {
-		evt_pair->evt.evt_next_id = 0;
+		evt_pair->evt.evt_id = 0;
+		/* Drop obsolete events queued for the previous stream instance. */
+		evt_pair->evt.u.evt.page->in_cons =
+			evt_pair->evt.u.evt.page->in_prod;
+		/* Ensure the consumer index is visible before stream reuse. */
+		virt_wmb();
 	}
 }
-
diff --git a/sound/xen/xen_snd_front_evtchnl.h b/sound/xen/xen_snd_front_evtchnl.h
index 3675fba705647d..8400261ac46601 100644
--- a/sound/xen/xen_snd_front_evtchnl.h
+++ b/sound/xen/xen_snd_front_evtchnl.h
@@ -37,9 +37,9 @@ struct xen_snd_front_evtchnl {
 	/* State of the event channel. */
 	enum xen_snd_front_evtchnl_state state;
 	enum xen_snd_front_evtchnl_type type;
-	/* Either response id or incoming event id. */
+	/* Current response id or next expected incoming event id. */
 	u16 evt_id;
-	/* Next request id or next expected event id. */
+	/* Next request id. */
 	u16 evt_next_id;
 	/* Shared ring access lock. */
 	struct mutex ring_io_lock;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0323/2077] ALSA: xen-front: Connect event channel after stream prepare
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (321 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0322/2077] ALSA: xen-front: Reset event channel state on stream clear Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0324/2077] ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data Greg Kroah-Hartman
                   ` (674 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Takashi Iwai,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cássio Gabriel <cassiogabrielcontato@gmail.com>

[ Upstream commit 3624f0bd4af15a820b1bd88b489980fa9fd61b7a ]

The request channel must be connected from ALSA .open(), because hw-rule
queries and the stream open request use it. The event channel is
different: XENSND_EVT_CUR_POS handling uses ALSA runtime buffer and
period geometry, and the corresponding Xen stream parameters are not
submitted to the backend until .prepare() sends XENSND_OP_OPEN.

Currently .open() connects both channels. A backend current-position
event, or a stale event queued for an earlier stream instance, can
therefore reach xen_snd_front_alsa_handle_cur_pos() before
runtime->buffer_size and runtime->period_size are valid.

Add a per-channel connection helper, connect only the request channel in
.open(), connect the event channel after a successful stream prepare,
and disconnect it before stream close/free. Re-check the event-channel
state after taking ring_io_lock so disconnecting the event channel
synchronizes against a threaded IRQ that passed the initial lockless
state test. Keep defensive runtime geometry checks in the position
handler.

Fixes: 1cee559351a7 ("ALSA: xen-front: Implement ALSA virtual sound driver")
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260526-alsa-xen-event-channel-fixes-v1-2-91d3a6a50778@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/xen/xen_snd_front_alsa.c    | 17 ++++++++++++-----
 sound/xen/xen_snd_front_evtchnl.c | 20 +++++++++++++-------
 sound/xen/xen_snd_front_evtchnl.h |  2 ++
 3 files changed, 27 insertions(+), 12 deletions(-)

diff --git a/sound/xen/xen_snd_front_alsa.c b/sound/xen/xen_snd_front_alsa.c
index dc626480123acd..a6dd196f73d662 100644
--- a/sound/xen/xen_snd_front_alsa.c
+++ b/sound/xen/xen_snd_front_alsa.c
@@ -378,7 +378,7 @@ static int alsa_open(struct snd_pcm_substream *substream)
 
 	stream_clear(stream);
 
-	xen_snd_front_evtchnl_pair_set_connected(stream->evt_pair, true);
+	xen_snd_front_evtchnl_set_connected(&stream->evt_pair->req, true);
 
 	ret = snd_pcm_hw_rule_add(runtime, 0, SNDRV_PCM_HW_PARAM_FORMAT,
 				  alsa_hw_rule, stream,
@@ -498,6 +498,8 @@ static int alsa_hw_free(struct snd_pcm_substream *substream)
 	struct xen_snd_front_pcm_stream_info *stream = stream_get(substream);
 	int ret;
 
+	xen_snd_front_evtchnl_set_connected(&stream->evt_pair->evt, false);
+
 	ret = xen_snd_front_stream_close(&stream->evt_pair->req);
 	stream_free(stream);
 	return ret;
@@ -532,6 +534,7 @@ static int alsa_prepare(struct snd_pcm_substream *substream)
 			return ret;
 
 		stream->is_open = true;
+		xen_snd_front_evtchnl_set_connected(&stream->evt_pair->evt, true);
 	}
 
 	return 0;
@@ -571,20 +574,24 @@ void xen_snd_front_alsa_handle_cur_pos(struct xen_snd_front_evtchnl *evtchnl,
 {
 	struct snd_pcm_substream *substream = evtchnl->u.evt.substream;
 	struct xen_snd_front_pcm_stream_info *stream = stream_get(substream);
+	struct snd_pcm_runtime *runtime = substream->runtime;
 	snd_pcm_uframes_t delta, new_hw_ptr, cur_frame;
 
-	cur_frame = bytes_to_frames(substream->runtime, pos_bytes);
+	if (!runtime->buffer_size || !runtime->period_size)
+		return;
+
+	cur_frame = bytes_to_frames(runtime, pos_bytes);
 
 	delta = cur_frame - stream->be_cur_frame;
 	stream->be_cur_frame = cur_frame;
 
 	new_hw_ptr = (snd_pcm_uframes_t)atomic_read(&stream->hw_ptr);
-	new_hw_ptr = (new_hw_ptr + delta) % substream->runtime->buffer_size;
+	new_hw_ptr = (new_hw_ptr + delta) % runtime->buffer_size;
 	atomic_set(&stream->hw_ptr, (int)new_hw_ptr);
 
 	stream->out_frames += delta;
-	if (stream->out_frames > substream->runtime->period_size) {
-		stream->out_frames %= substream->runtime->period_size;
+	if (stream->out_frames > runtime->period_size) {
+		stream->out_frames %= runtime->period_size;
 		snd_pcm_period_elapsed(substream);
 	}
 }
diff --git a/sound/xen/xen_snd_front_evtchnl.c b/sound/xen/xen_snd_front_evtchnl.c
index 09e4c1d0563632..17a30452c0cca3 100644
--- a/sound/xen/xen_snd_front_evtchnl.c
+++ b/sound/xen/xen_snd_front_evtchnl.c
@@ -94,6 +94,9 @@ static irqreturn_t evtchnl_interrupt_evt(int irq, void *dev_id)
 
 	guard(mutex)(&channel->ring_io_lock);
 
+	if (unlikely(channel->state != EVTCHNL_STATE_CONNECTED))
+		return IRQ_HANDLED;
+
 	prod = page->in_prod;
 	/* Ensure we see ring contents up to prod. */
 	virt_rmb();
@@ -430,8 +433,8 @@ int xen_snd_front_evtchnl_publish_all(struct xen_snd_front_info *front_info)
 	return ret;
 }
 
-void xen_snd_front_evtchnl_pair_set_connected(struct xen_snd_front_evtchnl_pair *evt_pair,
-					      bool is_connected)
+void xen_snd_front_evtchnl_set_connected(struct xen_snd_front_evtchnl *channel,
+					 bool is_connected)
 {
 	enum xen_snd_front_evtchnl_state state;
 
@@ -440,13 +443,16 @@ void xen_snd_front_evtchnl_pair_set_connected(struct xen_snd_front_evtchnl_pair
 	else
 		state = EVTCHNL_STATE_DISCONNECTED;
 
-	scoped_guard(mutex, &evt_pair->req.ring_io_lock) {
-		evt_pair->req.state = state;
+	scoped_guard(mutex, &channel->ring_io_lock) {
+		channel->state = state;
 	}
+}
 
-	scoped_guard(mutex, &evt_pair->evt.ring_io_lock) {
-		evt_pair->evt.state = state;
-	}
+void xen_snd_front_evtchnl_pair_set_connected(struct xen_snd_front_evtchnl_pair *evt_pair,
+					      bool is_connected)
+{
+	xen_snd_front_evtchnl_set_connected(&evt_pair->req, is_connected);
+	xen_snd_front_evtchnl_set_connected(&evt_pair->evt, is_connected);
 }
 
 void xen_snd_front_evtchnl_pair_clear(struct xen_snd_front_evtchnl_pair *evt_pair)
diff --git a/sound/xen/xen_snd_front_evtchnl.h b/sound/xen/xen_snd_front_evtchnl.h
index 8400261ac46601..f6ebdb09c0298c 100644
--- a/sound/xen/xen_snd_front_evtchnl.h
+++ b/sound/xen/xen_snd_front_evtchnl.h
@@ -77,6 +77,8 @@ void xen_snd_front_evtchnl_free_all(struct xen_snd_front_info *front_info);
 int xen_snd_front_evtchnl_publish_all(struct xen_snd_front_info *front_info);
 
 void xen_snd_front_evtchnl_flush(struct xen_snd_front_evtchnl *evtchnl);
+void xen_snd_front_evtchnl_set_connected(struct xen_snd_front_evtchnl *channel,
+					 bool is_connected);
 
 void xen_snd_front_evtchnl_pair_set_connected(struct xen_snd_front_evtchnl_pair *evt_pair,
 					      bool is_connected);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0324/2077] ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (322 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0323/2077] ALSA: xen-front: Connect event channel after stream prepare Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0325/2077] ALSA: seq: midi: Serialize output teardown with event_input Greg Kroah-Hartman
                   ` (673 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin, Zhang Cen

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Takashi Iwai <tiwai@suse.de>

[ Upstream commit 7c349b4f2a603202fb8c363bd2774a22ac2fddf3 ]

The OSS sequencer processes the input MIDI bytes into a sequencer
event to be dispatched later (in snd_seq_oss_midi_putc() called from
snd_seq_oss_process_event()).  When it's a SysEx data, the event
record contains data.ext.ptr pointer to the original SysEx bytes, and
the referred data is copied into the pool afterwards at dispatching.
The problem is that, if the sequencer port gets closed concurrently
before the dispatch, the OSS sequencer core also releases the
resources (in snd_seq_oss_midi_check_exit_port()), while the pending
event may hold a stale pointer, eventually leading to a UAF at a later
dispatch.

Fortunately, there is already a refcounting mechanism (snd_use_lock_t)
for the OSS MIDI device access, and for addressing the issue above, we
just need to extend the refcount until the event gets dispatched.

This patch extends snd_seq_oss_process_event() to give back the
refcount object, which is in turn released after calling the sequencer
dispatcher with the given event in the caller side.

According to the original report, KASAN report as below:

KASAN slab-use-after-free in snd_seq_event_dup+0x40c/0x470
RIP: 0033:0x7f2cb66a6340
Read of size 6
Call trace:
  dump_stack_lvl+0x73/0xb0 (?:?)
  print_report+0xd1/0x650 (?:?)
  srso_alias_return_thunk+0x5/0xfbef5 (?:?)
  __virt_addr_valid+0x1a7/0x340 (?:?)
  kasan_complete_mode_report_info+0x64/0x200 (?:?)
  kasan_report+0xf7/0x130 (?:?)
  snd_seq_event_dup+0x40c/0x470 (?:?)
  kasan_check_range+0x10c/0x1c0 (?:?)
  __asan_memcpy+0x27/0x70 (?:?)
  snd_seq_event_dup+0x9/0x470 (?:?)
  snd_seq_client_enqueue_event+0x139/0x240 (?:?)
  _raw_spin_unlock_irqrestore+0x4b/0x60 (?:?)
  snd_seq_kernel_client_enqueue+0x102/0x120 (?:?)
  snd_seq_oss_write+0x416/0x4e0 (?:?)
  apparmor_file_permission+0x20/0x30 (?:?)
  odev_write+0x3b/0x60 (?:?)
  vfs_write+0x1ce/0x850 (?:?)
  lock_release+0xc8/0x2a0 (?:?)
  __kasan_check_write+0x18/0x20 (?:?)
  __mutex_unlock_slowpath+0x129/0x510 (?:?)
  ksys_write+0xe1/0x180 (?:?)
  mutex_unlock+0x16/0x20 (?:?)
  odev_ioctl+0x65/0xc0 (?:?)
  __x64_sys_write+0x46/0x60 (?:?)
  x64_sys_call+0x7d/0x20d0 (?:?)
  do_syscall_64+0xc1/0x360 (arch/x86/entry/syscall_64.c:87)
  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-and-tested-by: Zhang Cen <rollkingzzc@gmail.com>
Closes: https://lore.kernel.org/20260521233900.478153-1-rollkingzzc@gmail.com
Link: https://patch.msgid.link/20260526152843.617503-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/core/seq/oss/seq_oss_event.c | 6 ++++--
 sound/core/seq/oss/seq_oss_event.h | 3 ++-
 sound/core/seq/oss/seq_oss_ioctl.c | 5 ++++-
 sound/core/seq/oss/seq_oss_midi.c  | 6 +++++-
 sound/core/seq/oss/seq_oss_midi.h  | 2 +-
 sound/core/seq/oss/seq_oss_rw.c    | 5 ++++-
 6 files changed, 20 insertions(+), 7 deletions(-)

diff --git a/sound/core/seq/oss/seq_oss_event.c b/sound/core/seq/oss/seq_oss_event.c
index 76fb81077eef79..122735862044dc 100644
--- a/sound/core/seq/oss/seq_oss_event.c
+++ b/sound/core/seq/oss/seq_oss_event.c
@@ -39,8 +39,10 @@ static int set_echo_event(struct seq_oss_devinfo *dp, union evrec *rec, struct s
  */
 
 int
-snd_seq_oss_process_event(struct seq_oss_devinfo *dp, union evrec *q, struct snd_seq_event *ev)
+snd_seq_oss_process_event(struct seq_oss_devinfo *dp, union evrec *q,
+			  struct snd_seq_event *ev, snd_use_lock_t **lockp)
 {
+	*lockp = NULL;
 	switch (q->s.code) {
 	case SEQ_EXTENDED:
 		return extended_event(dp, q, ev);
@@ -69,7 +71,7 @@ snd_seq_oss_process_event(struct seq_oss_devinfo *dp, union evrec *q, struct snd
 		if (snd_seq_oss_midi_open(dp, q->s.dev, SNDRV_SEQ_OSS_FILE_WRITE))
 			break;
 		if (snd_seq_oss_midi_filemode(dp, q->s.dev) & SNDRV_SEQ_OSS_FILE_WRITE)
-			return snd_seq_oss_midi_putc(dp, q->s.dev, q->s.parm1, ev);
+			return snd_seq_oss_midi_putc(dp, q->s.dev, q->s.parm1, ev, lockp);
 		break;
 
 	case SEQ_ECHO:
diff --git a/sound/core/seq/oss/seq_oss_event.h b/sound/core/seq/oss/seq_oss_event.h
index b4f723949a1709..a4524e51d0e9d7 100644
--- a/sound/core/seq/oss/seq_oss_event.h
+++ b/sound/core/seq/oss/seq_oss_event.h
@@ -91,7 +91,8 @@ union evrec {
 #define ev_is_long(ev) ((ev)->s.code >= 128)
 #define ev_length(ev) ((ev)->s.code >= 128 ? LONG_EVENT_SIZE : SHORT_EVENT_SIZE)
 
-int snd_seq_oss_process_event(struct seq_oss_devinfo *dp, union evrec *q, struct snd_seq_event *ev);
+int snd_seq_oss_process_event(struct seq_oss_devinfo *dp, union evrec *q,
+			      struct snd_seq_event *ev, snd_use_lock_t **lockp);
 int snd_seq_oss_process_timer_event(struct seq_oss_timer *rec, union evrec *q);
 int snd_seq_oss_event_input(struct snd_seq_event *ev, int direct, void *private_data, int atomic, int hop);
 
diff --git a/sound/core/seq/oss/seq_oss_ioctl.c b/sound/core/seq/oss/seq_oss_ioctl.c
index ccf682689ec951..ce7a69d52b308b 100644
--- a/sound/core/seq/oss/seq_oss_ioctl.c
+++ b/sound/core/seq/oss/seq_oss_ioctl.c
@@ -45,14 +45,17 @@ static int snd_seq_oss_oob_user(struct seq_oss_devinfo *dp, void __user *arg)
 {
 	unsigned char ev[8];
 	struct snd_seq_event tmpev;
+	snd_use_lock_t *lock = NULL;
 
 	if (copy_from_user(ev, arg, 8))
 		return -EFAULT;
 	memset(&tmpev, 0, sizeof(tmpev));
 	snd_seq_oss_fill_addr(dp, &tmpev, dp->addr.client, dp->addr.port);
 	tmpev.time.tick = 0;
-	if (! snd_seq_oss_process_event(dp, (union evrec *)ev, &tmpev)) {
+	if (!snd_seq_oss_process_event(dp, (union evrec *)ev, &tmpev, &lock)) {
 		snd_seq_oss_dispatch(dp, &tmpev, 0, 0);
+		if (lock)
+			snd_use_lock_free(lock);
 	}
 	return 0;
 }
diff --git a/sound/core/seq/oss/seq_oss_midi.c b/sound/core/seq/oss/seq_oss_midi.c
index b50a49ca42ff3e..70f94df651446e 100644
--- a/sound/core/seq/oss/seq_oss_midi.c
+++ b/sound/core/seq/oss/seq_oss_midi.c
@@ -593,7 +593,8 @@ send_midi_event(struct seq_oss_devinfo *dp, struct snd_seq_event *ev, struct seq
  *        non-zero : invalid - ignored
  */
 int
-snd_seq_oss_midi_putc(struct seq_oss_devinfo *dp, int dev, unsigned char c, struct snd_seq_event *ev)
+snd_seq_oss_midi_putc(struct seq_oss_devinfo *dp, int dev, unsigned char c,
+		      struct snd_seq_event *ev, snd_use_lock_t **lockp)
 {
 	struct seq_oss_midi *mdev __free(seq_oss_midi) =
 		get_mididev(dp, dev);
@@ -602,6 +603,9 @@ snd_seq_oss_midi_putc(struct seq_oss_devinfo *dp, int dev, unsigned char c, stru
 		return -ENODEV;
 	if (snd_midi_event_encode_byte(mdev->coder, c, ev)) {
 		snd_seq_oss_fill_addr(dp, ev, mdev->client, mdev->port);
+		/* the caller must release this later */
+		*lockp = &mdev->use_lock;
+		snd_use_lock_use(*lockp);
 		return 0;
 	}
 	return -EINVAL;
diff --git a/sound/core/seq/oss/seq_oss_midi.h b/sound/core/seq/oss/seq_oss_midi.h
index bcc1683773dfba..4819d4170bf6d8 100644
--- a/sound/core/seq/oss/seq_oss_midi.h
+++ b/sound/core/seq/oss/seq_oss_midi.h
@@ -26,7 +26,7 @@ void snd_seq_oss_midi_open_all(struct seq_oss_devinfo *dp, int file_mode);
 int snd_seq_oss_midi_close(struct seq_oss_devinfo *dp, int dev);
 void snd_seq_oss_midi_reset(struct seq_oss_devinfo *dp, int dev);
 int snd_seq_oss_midi_putc(struct seq_oss_devinfo *dp, int dev, unsigned char c,
-			  struct snd_seq_event *ev);
+			  struct snd_seq_event *ev, snd_use_lock_t **lockp);
 int snd_seq_oss_midi_input(struct snd_seq_event *ev, int direct, void *private);
 int snd_seq_oss_midi_filemode(struct seq_oss_devinfo *dp, int dev);
 int snd_seq_oss_midi_make_info(struct seq_oss_devinfo *dp, int dev, struct midi_info *inf);
diff --git a/sound/core/seq/oss/seq_oss_rw.c b/sound/core/seq/oss/seq_oss_rw.c
index 307ef98c44c7b5..111c792bc72ca3 100644
--- a/sound/core/seq/oss/seq_oss_rw.c
+++ b/sound/core/seq/oss/seq_oss_rw.c
@@ -153,6 +153,7 @@ insert_queue(struct seq_oss_devinfo *dp, union evrec *rec, struct file *opt)
 {
 	int rc = 0;
 	struct snd_seq_event event;
+	snd_use_lock_t *lock = NULL;
 
 	/* if this is a timing event, process the current time */
 	if (snd_seq_oss_process_timer_event(dp->timer, rec))
@@ -164,7 +165,7 @@ insert_queue(struct seq_oss_devinfo *dp, union evrec *rec, struct file *opt)
 	event.type = SNDRV_SEQ_EVENT_NOTEOFF;
 	snd_seq_oss_fill_addr(dp, &event, dp->addr.client, dp->addr.port);
 
-	if (snd_seq_oss_process_event(dp, rec, &event))
+	if (snd_seq_oss_process_event(dp, rec, &event, &lock))
 		return 0; /* invalid event - no need to insert queue */
 
 	event.time.tick = snd_seq_oss_timer_cur_tick(dp->timer);
@@ -173,6 +174,8 @@ insert_queue(struct seq_oss_devinfo *dp, union evrec *rec, struct file *opt)
 	else
 		rc = snd_seq_kernel_client_enqueue(dp->cseq, &event, opt,
 						   !is_nonblock_mode(dp->file_mode));
+	if (lock)
+		snd_use_lock_free(lock);
 	return rc;
 }
 		
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0325/2077] ALSA: seq: midi: Serialize output teardown with event_input
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (323 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0324/2077] ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 14:59 ` [PATCH 7.1 0326/2077] selftests: Fix Makefile target for nsfs Greg Kroah-Hartman
                   ` (672 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Zhang Cen, Takashi Iwai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhang Cen <rollkingzzc@gmail.com>

[ Upstream commit ef7607ab1c8adc6258fb1b27d08e26aecdc18a58 ]

event_process_midi() borrows msynth->output_rfile.output and then
passes the substream to dump_midi() and snd_rawmidi_kernel_write()
without synchronizing with the output open/close transition.
midisynth_use() also publishes output_rfile before
snd_rawmidi_output_params() has finished.

The last midisynth_unuse() can therefore release the same rawmidi file
and free substream->runtime before snd_rawmidi_kernel_write1() takes
its runtime buffer reference. That leaves the event_input path using a
stale substream or runtime and can end in a NULL-deref or use-after-free.

Fix this with two pieces of synchronization. Keep a short IRQ-safe
spinlock only for publishing or clearing output_rfile and for pairing
the output snapshot with an snd_use_lock_t reference. Once
event_process_midi() has taken that in-flight reference, it drops the
spinlock before calling snd_seq_dump_var_event(), dump_midi(), or
snd_rawmidi_kernel_write(). midisynth_unuse() now detaches the visible
rawmidi file under the same spinlock, waits for the in-flight writers
to drain, and only then drains and releases the saved file.
midisynth_use() likewise opens into a local snd_rawmidi_file and
publishes it only after snd_rawmidi_output_params() succeeds.

The buggy scenario involves two paths, with each column showing the
order within that path:

event_input path:                     last unuse path:
1. event_process_midi() snapshots    1. midisynth_unuse() starts
   output_rfile.output.                 tearing down output_rfile.
2. dump_midi() reaches               2. snd_rawmidi_kernel_release()
   snd_rawmidi_kernel_write()           closes the output file.
   before runtime is pinned.         3. close_substream() frees
3. The callback keeps using             substream->runtime.
   the borrowed substream.

Validation reproduced this kernel report:
KASAN null-ptr-deref in snd_rawmidi_kernel_write1+0x56/0x360
RIP: 0033:0x7fde7dd0837f
RIP: 0010:snd_rawmidi_kernel_write1+0x56/0x360

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: Codex:gpt-5.5
Signed-off-by: Zhang Cen <rollkingzzc@gmail.com>
Link: https://patch.msgid.link/20260527062948.3614025-1-rollkingzzc@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/core/seq/seq_midi.c | 55 +++++++++++++++++++++++++++++----------
 1 file changed, 41 insertions(+), 14 deletions(-)

diff --git a/sound/core/seq/seq_midi.c b/sound/core/seq/seq_midi.c
index ca3f5fc309927b..2eb12199c92f90 100644
--- a/sound/core/seq/seq_midi.c
+++ b/sound/core/seq/seq_midi.c
@@ -24,6 +24,7 @@ Possible options for midisynth module:
 #include <sound/seq_device.h>
 #include <sound/seq_midi_event.h>
 #include <sound/initval.h>
+#include "seq_lock.h"
 
 MODULE_AUTHOR("Frank van de Pol <fvdpol@coil.demon.nl>, Jaroslav Kysela <perex@perex.cz>");
 MODULE_DESCRIPTION("Advanced Linux Sound Architecture sequencer MIDI synth.");
@@ -42,6 +43,8 @@ struct seq_midisynth {
 	int device;
 	int subdevice;
 	struct snd_rawmidi_file input_rfile;
+	spinlock_t output_lock;		/* protects output_rfile publication */
+	snd_use_lock_t output_use_lock;	/* in-flight event_input users */
 	struct snd_rawmidi_file output_rfile;
 	int seq_client;
 	int seq_port;
@@ -125,31 +128,42 @@ static int event_process_midi(struct snd_seq_event *ev, int direct,
 	struct seq_midisynth *msynth = private_data;
 	unsigned char msg[10];	/* buffer for constructing midi messages */
 	struct snd_rawmidi_substream *substream;
+	int err = 0;
 	int len;
 
 	if (snd_BUG_ON(!msynth))
 		return -EINVAL;
-	substream = msynth->output_rfile.output;
-	if (substream == NULL)
-		return -ENODEV;
+
+	scoped_guard(spinlock_irqsave, &msynth->output_lock) {
+		substream = msynth->output_rfile.output;
+		if (!substream)
+			return -ENODEV;
+		snd_use_lock_use(&msynth->output_use_lock);
+	}
+
 	if (ev->type == SNDRV_SEQ_EVENT_SYSEX) {	/* special case, to save space */
 		if ((ev->flags & SNDRV_SEQ_EVENT_LENGTH_MASK) != SNDRV_SEQ_EVENT_LENGTH_VARIABLE) {
 			/* invalid event */
 			pr_debug("ALSA: seq_midi: invalid sysex event flags = 0x%x\n", ev->flags);
-			return 0;
+			goto out;
 		}
 		snd_seq_dump_var_event(ev, __dump_midi, substream);
 		snd_midi_event_reset_decode(msynth->parser);
 	} else {
-		if (msynth->parser == NULL)
-			return -EIO;
+		if (!msynth->parser) {
+			err = -EIO;
+			goto out;
+		}
 		len = snd_midi_event_decode(msynth->parser, msg, sizeof(msg), ev);
 		if (len < 0)
-			return 0;
+			goto out;
 		if (dump_midi(substream, msg, len) < 0)
 			snd_midi_event_reset_decode(msynth->parser);
 	}
-	return 0;
+
+out:
+	snd_use_lock_free(&msynth->output_use_lock);
+	return err;
 }
 
 
@@ -163,6 +177,8 @@ static int snd_seq_midisynth_new(struct seq_midisynth *msynth,
 	msynth->card = card;
 	msynth->device = device;
 	msynth->subdevice = subdevice;
+	spin_lock_init(&msynth->output_lock);
+	snd_use_lock_init(&msynth->output_use_lock);
 	return 0;
 }
 
@@ -215,12 +231,13 @@ static int midisynth_use(void *private_data, struct snd_seq_port_subscribe *info
 {
 	int err;
 	struct seq_midisynth *msynth = private_data;
+	struct snd_rawmidi_file rfile = {};
 	struct snd_rawmidi_params params;
 
 	/* open midi port */
 	err = snd_rawmidi_kernel_open(msynth->rmidi, msynth->subdevice,
 				      SNDRV_RAWMIDI_LFLG_OUTPUT,
-				      &msynth->output_rfile);
+				      &rfile);
 	if (err < 0) {
 		pr_debug("ALSA: seq_midi: midi output open failed!!!\n");
 		return err;
@@ -229,12 +246,14 @@ static int midisynth_use(void *private_data, struct snd_seq_port_subscribe *info
 	params.avail_min = 1;
 	params.buffer_size = output_buffer_size;
 	params.no_active_sensing = 1;
-	err = snd_rawmidi_output_params(msynth->output_rfile.output, &params);
+	err = snd_rawmidi_output_params(rfile.output, &params);
 	if (err < 0) {
-		snd_rawmidi_kernel_release(&msynth->output_rfile);
+		snd_rawmidi_kernel_release(&rfile);
 		return err;
 	}
 	snd_midi_event_reset_decode(msynth->parser);
+	scoped_guard(spinlock_irqsave, &msynth->output_lock)
+		msynth->output_rfile = rfile;
 	return 0;
 }
 
@@ -242,11 +261,19 @@ static int midisynth_use(void *private_data, struct snd_seq_port_subscribe *info
 static int midisynth_unuse(void *private_data, struct snd_seq_port_subscribe *info)
 {
 	struct seq_midisynth *msynth = private_data;
+	struct snd_rawmidi_file rfile = {};
 
-	if (snd_BUG_ON(!msynth->output_rfile.output))
+	scoped_guard(spinlock_irqsave, &msynth->output_lock) {
+		rfile = msynth->output_rfile;
+		msynth->output_rfile = (struct snd_rawmidi_file){};
+	}
+
+	if (snd_BUG_ON(!rfile.output))
 		return -EINVAL;
-	snd_rawmidi_drain_output(msynth->output_rfile.output);
-	return snd_rawmidi_kernel_release(&msynth->output_rfile);
+
+	snd_use_lock_sync(&msynth->output_use_lock);
+	snd_rawmidi_drain_output(rfile.output);
+	return snd_rawmidi_kernel_release(&rfile);
 }
 
 /* delete given midi synth port */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0326/2077] selftests: Fix Makefile target for nsfs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (324 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0325/2077] ALSA: seq: midi: Serialize output teardown with event_input Greg Kroah-Hartman
@ 2026-07-21 14:59 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0327/2077] pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table Greg Kroah-Hartman
                   ` (671 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 14:59 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Florian Schmaus,
	Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Florian Schmaus <flo@geekplace.eu>

[ Upstream commit 77d1a2d2318fa96f8a662c9ad6647abedcd22734 ]

The kselftests for nsfs where moved under filesystem/ with
commit cae73d3bdce5 ("seltests: move nsfs into filesystems
subfolder"). However, the kselftest TARGETS declaration was not
adjusted.

Since the kselftest Makefile ignores errors unless no target builds,
the invalid target declaration can easily be missed.

Fix this by adjusting the TARGETS accordingly.

Fixes: cae73d3bdce5 ("seltests: move nsfs into filesystems subfolder")
Signed-off-by: Florian Schmaus <flo@geekplace.eu>
Link: https://patch.msgid.link/20260526-kselftest-nsfs-v1-1-7b042ebe42d6@geekplace.eu
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/Makefile | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/selftests/Makefile b/tools/testing/selftests/Makefile
index 6e59b8f63e4163..641a180fb35f41 100644
--- a/tools/testing/selftests/Makefile
+++ b/tools/testing/selftests/Makefile
@@ -37,6 +37,7 @@ TARGETS += filesystems/fat
 TARGETS += filesystems/overlayfs
 TARGETS += filesystems/statmount
 TARGETS += filesystems/mount-notify
+TARGETS += filesystems/nsfs
 TARGETS += filesystems/fuse
 TARGETS += filesystems/move_mount
 TARGETS += filesystems/empty_mntns
@@ -85,7 +86,6 @@ TARGETS += net/ppp
 TARGETS += net/rds
 TARGETS += net/tcp_ao
 TARGETS += nolibc
-TARGETS += nsfs
 TARGETS += pci_endpoint
 TARGETS += pcie_bwctrl
 TARGETS += perf_events
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0327/2077] pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (325 preceding siblings ...)
  2026-07-21 14:59 ` [PATCH 7.1 0326/2077] selftests: Fix Makefile target for nsfs Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0328/2077] pinctrl: cs42l43: Fix leaked pm reference on error path Greg Kroah-Hartman
                   ` (670 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Joey Lu, Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joey Lu <a0987203069@gmail.com>

[ Upstream commit ce4e27247ca643645c6d3043aad1c1c67bf7fdac ]

Each GPIO bank has two 32-bit MFP registers: MFPL covering pins 0-7
at the bank base offset, and MFPH covering pins 8-15 at base offset+4.
ma35_pinctrl_parse_groups() computed the register address without
accounting for this split, so any pin with an index >= 8 within its
bank was written to the wrong register.

Also fix the pin descriptor table in pinctrl-ma35d1.c: switch from
sequential to 16-per-bank pin numbering, add missing PC8-PC11 pins
and their mux options, and remove the duplicate PN10-PN15 entries.

Fixes: f805e356313b ("pinctrl: nuvoton: Add ma35d1 pinctrl and GPIO driver")
Signed-off-by: Joey Lu <a0987203069@gmail.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/nuvoton/pinctrl-ma35.c   |   3 +-
 drivers/pinctrl/nuvoton/pinctrl-ma35d1.c | 470 +++++++++++++----------
 2 files changed, 263 insertions(+), 210 deletions(-)

diff --git a/drivers/pinctrl/nuvoton/pinctrl-ma35.c b/drivers/pinctrl/nuvoton/pinctrl-ma35.c
index f01344201628f8..dafa85c105a13c 100644
--- a/drivers/pinctrl/nuvoton/pinctrl-ma35.c
+++ b/drivers/pinctrl/nuvoton/pinctrl-ma35.c
@@ -1014,7 +1014,8 @@ static int ma35_pinctrl_parse_groups(struct fwnode_handle *fwnode, struct group_
 	grp->data = pin;
 
 	for (i = 0, j = 0; i < count; i += 3, j++) {
-		pin->offset = elems[i] * MA35_MFP_REG_SZ_PER_BANK + MA35_MFP_REG_BASE;
+		pin->offset = elems[i] * MA35_MFP_REG_SZ_PER_BANK + MA35_MFP_REG_BASE +
+			      (elems[i + 1] >= 8 ? 4 : 0);
 		pin->shift = (elems[i + 1] * MA35_MFP_BITS_PER_PORT) % 32;
 		pin->muxval = elems[i + 2];
 		pin->configs = configs;
diff --git a/drivers/pinctrl/nuvoton/pinctrl-ma35d1.c b/drivers/pinctrl/nuvoton/pinctrl-ma35d1.c
index eafa06ca087910..9d4627c80a52c7 100644
--- a/drivers/pinctrl/nuvoton/pinctrl-ma35d1.c
+++ b/drivers/pinctrl/nuvoton/pinctrl-ma35d1.c
@@ -113,6 +113,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x0, "GPA14"),
 		MA35_MUX(0x2, "UART7_RXD"),
 		MA35_MUX(0x3, "CAN3_RXD"),
+		MA35_MUX(0x4, "USBHL3_DM"),
 		MA35_MUX(0x6, "NAND_nWP"),
 		MA35_MUX(0x7, "EBI_AD14"),
 		MA35_MUX(0x9, "EBI_ADR14")),
@@ -123,6 +124,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x3, "UART6_RXD"),
 		MA35_MUX(0x4, "I2C4_SDA"),
 		MA35_MUX(0x5, "CAN2_RXD"),
+		MA35_MUX(0x6, "USBHL0_DM"),
 		MA35_MUX(0x7, "EBI_ALE"),
 		MA35_MUX(0x9, "QEI0_A"),
 		MA35_MUX(0xb, "TM1"),
@@ -187,6 +189,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x1, "EPWM2_CH5"),
 		MA35_MUX(0x2, "UART2_RXD"),
 		MA35_MUX(0x3, "CAN0_RXD"),
+		MA35_MUX(0x4, "USBHL2_DM"),
 		MA35_MUX(0x5, "SPI0_MOSI"),
 		MA35_MUX(0x6, "EBI_MCLK"),
 		MA35_MUX(0x7, "CCAP1_VSYNC"),
@@ -202,6 +205,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x1, "EPWM2_BRAKE1"),
 		MA35_MUX(0x2, "UART2_TXD"),
 		MA35_MUX(0x3, "CAN0_TXD"),
+		MA35_MUX(0x4, "USBHL2_DP"),
 		MA35_MUX(0x5, "SPI0_MISO"),
 		MA35_MUX(0x6, "I2S1_MCLK"),
 		MA35_MUX(0x7, "CCAP1_SFIELD"),
@@ -220,6 +224,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x4, "I2C3_SDA"),
 		MA35_MUX(0x5, "CAN2_RXD"),
 		MA35_MUX(0x6, "I2S1_LRCK"),
+		MA35_MUX(0x7, "USBHL1_DM"),
 		MA35_MUX(0x8, "ADC0_CH4"),
 		MA35_MUX(0x9, "EBI_ADR16"),
 		MA35_MUX(0xe, "ECAP2_IC0")),
@@ -231,6 +236,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x4, "I2C3_SCL"),
 		MA35_MUX(0x5, "CAN2_TXD"),
 		MA35_MUX(0x6, "I2S1_BCLK"),
+		MA35_MUX(0x7, "USBHL1_DP"),
 		MA35_MUX(0x8, "ADC0_CH5"),
 		MA35_MUX(0x9, "EBI_ADR17"),
 		MA35_MUX(0xe, "ECAP2_IC1")),
@@ -239,6 +245,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x1, "EPWM2_CH2"),
 		MA35_MUX(0x2, "UART4_RXD"),
 		MA35_MUX(0x3, "CAN1_RXD"),
+		MA35_MUX(0x4, "USBHL3_DM"),
 		MA35_MUX(0x5, "I2C4_SDA"),
 		MA35_MUX(0x6, "I2S1_DI"),
 		MA35_MUX(0x8, "ADC0_CH6"),
@@ -249,6 +256,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x1, "EPWM2_CH3"),
 		MA35_MUX(0x2, "UART4_TXD"),
 		MA35_MUX(0x3, "CAN1_TXD"),
+		MA35_MUX(0x4, "USBHL3_DP"),
 		MA35_MUX(0x5, "I2C4_SCL"),
 		MA35_MUX(0x6, "I2S1_DO"),
 		MA35_MUX(0x8, "ADC0_CH7"),
@@ -264,10 +272,12 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 	MA35_PIN(34, PC2, 0x90, 0x8,
 		MA35_MUX(0x0, "GPC2"),
 		MA35_MUX(0x3, "CAN0_RXD"),
+		MA35_MUX(0x4, "USBHL4_DM"),
 		MA35_MUX(0x6, "SD0_DAT0/eMMC0_DAT0")),
 	MA35_PIN(35, PC3, 0x90, 0xc,
 		MA35_MUX(0x0, "GPC3"),
 		MA35_MUX(0x3, "CAN0_TXD"),
+		MA35_MUX(0x4, "USBHL4_DP"),
 		MA35_MUX(0x6, "SD0_DAT1/eMMC0_DAT1")),
 	MA35_PIN(36, PC4, 0x90, 0x10,
 		MA35_MUX(0x0, "GPC4"),
@@ -280,65 +290,100 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 	MA35_PIN(38, PC6, 0x90, 0x18,
 		MA35_MUX(0x0, "GPC6"),
 		MA35_MUX(0x3, "CAN1_RXD"),
+		MA35_MUX(0x4, "USBHL5_DM"),
 		MA35_MUX(0x6, "SD0_nCD")),
 	MA35_PIN(39, PC7, 0x90, 0x1c,
 		MA35_MUX(0x0, "GPC7"),
 		MA35_MUX(0x3, "CAN1_TXD"),
+		MA35_MUX(0x4, "USBHL5_DP"),
 		MA35_MUX(0x6, "SD0_WP")),
-	MA35_PIN(40, PC12, 0x94, 0x10,
+	MA35_PIN(40, PC8, 0x94, 0x0,
+		MA35_MUX(0x0, "GPC8"),
+		MA35_MUX(0x1, "EPWM2_CH0"),
+		MA35_MUX(0x2, "UART10_nCTS"),
+		MA35_MUX(0x3, "UART9_RXD"),
+		MA35_MUX(0x4, "I2C0_SDA"),
+		MA35_MUX(0x5, "SPI1_SS0"),
+		MA35_MUX(0x6, "SD0_DAT4/eMMC0_DAT4")),
+	MA35_PIN(41, PC9, 0x94, 0x4,
+		MA35_MUX(0x0, "GPC9"),
+		MA35_MUX(0x1, "EPWM2_CH1"),
+		MA35_MUX(0x2, "UART10_nRTS"),
+		MA35_MUX(0x3, "UART9_TXD"),
+		MA35_MUX(0x4, "I2C0_SCL"),
+		MA35_MUX(0x5, "SPI1_CLK"),
+		MA35_MUX(0x6, "SD0_DAT5/eMMC0_DAT5")),
+	MA35_PIN(42, PC10, 0x94, 0x8,
+		MA35_MUX(0x0, "GPC10"),
+		MA35_MUX(0x1, "EPWM2_CH2"),
+		MA35_MUX(0x2, "UART10_RXD"),
+		MA35_MUX(0x3, "CAN2_RXD"),
+		MA35_MUX(0x4, "USBHL0_DM"),
+		MA35_MUX(0x5, "SPI1_MOSI"),
+		MA35_MUX(0x6, "SD0_DAT6/eMMC0_DAT6")),
+	MA35_PIN(43, PC11, 0x94, 0xc,
+		MA35_MUX(0x0, "GPC11"),
+		MA35_MUX(0x1, "EPWM2_CH3"),
+		MA35_MUX(0x2, "UART10_TXD"),
+		MA35_MUX(0x3, "CAN2_TXD"),
+		MA35_MUX(0x4, "USBHL0_DP"),
+		MA35_MUX(0x5, "SPI1_MISO"),
+		MA35_MUX(0x6, "SD0_DAT7/eMMC0_DAT7")),
+	MA35_PIN(44, PC12, 0x94, 0x10,
 		MA35_MUX(0x0, "GPC12"),
 		MA35_MUX(0x2, "UART12_nCTS"),
 		MA35_MUX(0x3, "UART11_RXD"),
 		MA35_MUX(0x6, "LCM_DATA16")),
-	MA35_PIN(41, PC13, 0x94, 0x14,
+	MA35_PIN(45, PC13, 0x94, 0x14,
 		MA35_MUX(0x0, "GPC13"),
 		MA35_MUX(0x2, "UART12_nRTS"),
 		MA35_MUX(0x3, "UART11_TXD"),
 		MA35_MUX(0x6, "LCM_DATA17")),
-	MA35_PIN(42, PC14, 0x94, 0x18,
+	MA35_PIN(46, PC14, 0x94, 0x18,
 		MA35_MUX(0x0, "GPC14"),
 		MA35_MUX(0x2, "UART12_RXD"),
 		MA35_MUX(0x6, "LCM_DATA18")),
-	MA35_PIN(43, PC15, 0x94, 0x1c,
+	MA35_PIN(47, PC15, 0x94, 0x1c,
 		MA35_MUX(0x0, "GPC15"),
 		MA35_MUX(0x2, "UART12_TXD"),
 		MA35_MUX(0x6, "LCM_DATA19"),
 		MA35_MUX(0x7, "LCM_MPU_TE"),
 		MA35_MUX(0x8, "LCM_MPU_VSYNC")),
-	MA35_PIN(44, PD0, 0x98, 0x0,
+	MA35_PIN(48, PD0, 0x98, 0x0,
 		MA35_MUX(0x0, "GPD0"),
 		MA35_MUX(0x2, "UART3_nCTS"),
 		MA35_MUX(0x3, "UART4_RXD"),
 		MA35_MUX(0x5, "QSPI0_SS0")),
-	MA35_PIN(45, PD1, 0x98, 0x4,
+	MA35_PIN(49, PD1, 0x98, 0x4,
 		MA35_MUX(0x0, "GPD1"),
 		MA35_MUX(0x2, "UART3_nRTS"),
 		MA35_MUX(0x3, "UART4_TXD"),
 		MA35_MUX(0x5, "QSPI0_CLK")),
-	MA35_PIN(46, PD2, 0x98, 0x8,
+	MA35_PIN(50, PD2, 0x98, 0x8,
 		MA35_MUX(0x0, "GPD2"),
 		MA35_MUX(0x2, "UART3_RXD"),
 		MA35_MUX(0x5, "QSPI0_MOSI0")),
-	MA35_PIN(47, PD3, 0x98, 0xc,
+	MA35_PIN(51, PD3, 0x98, 0xc,
 		MA35_MUX(0x0, "GPD3"),
 		MA35_MUX(0x2, "UART3_TXD"),
 		MA35_MUX(0x5, "QSPI0_MISO0")),
-	MA35_PIN(48, PD4, 0x98, 0x10,
+	MA35_PIN(52, PD4, 0x98, 0x10,
 		MA35_MUX(0x0, "GPD4"),
 		MA35_MUX(0x2, "UART1_nCTS"),
 		MA35_MUX(0x3, "UART2_RXD"),
 		MA35_MUX(0x4, "I2C2_SDA"),
 		MA35_MUX(0x5, "QSPI0_MOSI1")),
-	MA35_PIN(49, PD5, 0x98, 0x14,
+	MA35_PIN(53, PD5, 0x98, 0x14,
 		MA35_MUX(0x0, "GPD5"),
 		MA35_MUX(0x2, "UART1_nRTS"),
 		MA35_MUX(0x3, "UART2_TXD"),
 		MA35_MUX(0x4, "I2C2_SCL"),
 		MA35_MUX(0x5, "QSPI0_MISO1")),
-	MA35_PIN(50, PD6, 0x98, 0x18,
+	MA35_PIN(54, PD6, 0x98, 0x18,
 		MA35_MUX(0x0, "GPD6"),
 		MA35_MUX(0x1, "EPWM0_SYNC_IN"),
 		MA35_MUX(0x2, "UART1_RXD"),
+		MA35_MUX(0x4, "USBHL3_DM"),
 		MA35_MUX(0x5, "QSPI1_MOSI1"),
 		MA35_MUX(0x6, "I2C0_SDA"),
 		MA35_MUX(0x7, "I2S0_MCLK"),
@@ -346,10 +391,11 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "EBI_AD5"),
 		MA35_MUX(0xa, "SPI3_SS1"),
 		MA35_MUX(0xb, "TRACE_CLK")),
-	MA35_PIN(51, PD7, 0x98, 0x1c,
+	MA35_PIN(55, PD7, 0x98, 0x1c,
 		MA35_MUX(0x0, "GPD7"),
 		MA35_MUX(0x1, "EPWM0_SYNC_OUT"),
 		MA35_MUX(0x2, "UART1_TXD"),
+		MA35_MUX(0x4, "USBHL3_DP"),
 		MA35_MUX(0x5, "QSPI1_MISO1"),
 		MA35_MUX(0x6, "I2C0_SCL"),
 		MA35_MUX(0x7, "I2S1_MCLK"),
@@ -357,7 +403,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "EBI_AD6"),
 		MA35_MUX(0xa, "SC1_nCD"),
 		MA35_MUX(0xb, "EADC0_ST")),
-	MA35_PIN(52, PD8, 0x9c, 0x0,
+	MA35_PIN(56, PD8, 0x9c, 0x0,
 		MA35_MUX(0x0, "GPD8"),
 		MA35_MUX(0x1, "EPWM0_BRAKE0"),
 		MA35_MUX(0x2, "UART16_nCTS"),
@@ -368,7 +414,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "EBI_AD7"),
 		MA35_MUX(0xa, "SC1_CLK"),
 		MA35_MUX(0xb, "TM0")),
-	MA35_PIN(53, PD9, 0x9c, 0x4,
+	MA35_PIN(57, PD9, 0x9c, 0x4,
 		MA35_MUX(0x0, "GPD9"),
 		MA35_MUX(0x1, "EPWM0_BRAKE1"),
 		MA35_MUX(0x2, "UART16_nRTS"),
@@ -379,7 +425,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "EBI_AD8"),
 		MA35_MUX(0xa, "SC1_DAT"),
 		MA35_MUX(0xb, "TM0_EXT")),
-	MA35_PIN(54, PD10, 0x9c, 0x8,
+	MA35_PIN(58, PD10, 0x9c, 0x8,
 		MA35_MUX(0x0, "GPD10"),
 		MA35_MUX(0x1, "EPWM1_BRAKE0"),
 		MA35_MUX(0x2, "UART16_RXD"),
@@ -389,7 +435,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "EBI_AD9"),
 		MA35_MUX(0xa, "SC1_RST"),
 		MA35_MUX(0xb, "TM2")),
-	MA35_PIN(55, PD11, 0x9c, 0xc,
+	MA35_PIN(59, PD11, 0x9c, 0xc,
 		MA35_MUX(0x0, "GPD11"),
 		MA35_MUX(0x1, "EPWM1_BRAKE1"),
 		MA35_MUX(0x2, "UART16_TXD"),
@@ -399,7 +445,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "EBI_AD10"),
 		MA35_MUX(0xa, "SC1_PWR"),
 		MA35_MUX(0xb, "TM2_EXT")),
-	MA35_PIN(56, PD12, 0x9c, 0x10,
+	MA35_PIN(60, PD12, 0x9c, 0x10,
 		MA35_MUX(0x0, "GPD12"),
 		MA35_MUX(0x1, "EPWM0_BRAKE0"),
 		MA35_MUX(0x2, "UART11_TXD"),
@@ -412,7 +458,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xb, "TM5"),
 		MA35_MUX(0xc, "I2S1_LRCK"),
 		MA35_MUX(0xd, "INT1")),
-	MA35_PIN(57, PD13, 0x9c, 0x14,
+	MA35_PIN(61, PD13, 0x9c, 0x14,
 		MA35_MUX(0x0, "GPD13"),
 		MA35_MUX(0x1, "EPWM0_BRAKE1"),
 		MA35_MUX(0x2, "UART11_RXD"),
@@ -424,11 +470,12 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "ECAP0_IC0"),
 		MA35_MUX(0xb, "TM5_EXT"),
 		MA35_MUX(0xc, "I2S1_BCLK")),
-	MA35_PIN(58, PD14, 0x9c, 0x18,
+	MA35_PIN(62, PD14, 0x9c, 0x18,
 		MA35_MUX(0x0, "GPD14"),
 		MA35_MUX(0x1, "EPWM0_SYNC_IN"),
 		MA35_MUX(0x2, "UART11_nCTS"),
 		MA35_MUX(0x3, "CAN3_RXD"),
+		MA35_MUX(0x4, "USBHL5_DM"),
 		MA35_MUX(0x6, "TRACE_DATA2"),
 		MA35_MUX(0x7, "EBI_MCLK"),
 		MA35_MUX(0x8, "EBI_AD6"),
@@ -436,116 +483,117 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xb, "TM6"),
 		MA35_MUX(0xc, "I2S1_DI"),
 		MA35_MUX(0xd, "INT3")),
-	MA35_PIN(59, PD15, 0x9c, 0x1c,
+	MA35_PIN(63, PD15, 0x9c, 0x1c,
 		MA35_MUX(0x0, "GPD15"),
 		MA35_MUX(0x1, "EPWM0_SYNC_OUT"),
 		MA35_MUX(0x2, "UART11_nRTS"),
 		MA35_MUX(0x3, "CAN3_TXD"),
+		MA35_MUX(0x4, "USBHL5_DP"),
 		MA35_MUX(0x6, "TRACE_DATA3"),
 		MA35_MUX(0x7, "EBI_ALE"),
 		MA35_MUX(0x8, "EBI_AD7"),
 		MA35_MUX(0x9, "ECAP0_IC2"),
 		MA35_MUX(0xb, "TM6_EXT"),
 		MA35_MUX(0xc, "I2S1_DO")),
-	MA35_PIN(60, PE0, 0xa0, 0x0,
+	MA35_PIN(64, PE0, 0xa0, 0x0,
 		MA35_MUX(0x0, "GPE0"),
 		MA35_MUX(0x2, "UART9_nCTS"),
 		MA35_MUX(0x3, "UART8_RXD"),
 		MA35_MUX(0x7, "CCAP1_DATA0"),
 		MA35_MUX(0x8, "RGMII0_MDC"),
 		MA35_MUX(0x9, "RMII0_MDC")),
-	MA35_PIN(61, PE1, 0xa0, 0x4,
+	MA35_PIN(65, PE1, 0xa0, 0x4,
 		MA35_MUX(0x0, "GPE1"),
 		MA35_MUX(0x2, "UART9_nRTS"),
 		MA35_MUX(0x3, "UART8_TXD"),
 		MA35_MUX(0x7, "CCAP1_DATA1"),
 		MA35_MUX(0x8, "RGMII0_MDIO"),
 		MA35_MUX(0x9, "RMII0_MDIO")),
-	MA35_PIN(62, PE2, 0xa0, 0x8,
+	MA35_PIN(66, PE2, 0xa0, 0x8,
 		MA35_MUX(0x0, "GPE2"),
 		MA35_MUX(0x2, "UART9_RXD"),
 		MA35_MUX(0x7, "CCAP1_DATA2"),
 		MA35_MUX(0x8, "RGMII0_TXCTL"),
 		MA35_MUX(0x9, "RMII0_TXEN")),
-	MA35_PIN(63, PE3, 0xa0, 0xc,
+	MA35_PIN(67, PE3, 0xa0, 0xc,
 		MA35_MUX(0x0, "GPE3"),
 		MA35_MUX(0x2, "UART9_TXD"),
 		MA35_MUX(0x7, "CCAP1_DATA3"),
 		MA35_MUX(0x8, "RGMII0_TXD0"),
 		MA35_MUX(0x9, "RMII0_TXD0")),
-	MA35_PIN(64, PE4, 0xa0, 0x10,
+	MA35_PIN(68, PE4, 0xa0, 0x10,
 		MA35_MUX(0x0, "GPE4"),
 		MA35_MUX(0x2, "UART4_nCTS"),
 		MA35_MUX(0x3, "UART3_RXD"),
 		MA35_MUX(0x7, "CCAP1_DATA4"),
 		MA35_MUX(0x8, "RGMII0_TXD1"),
 		MA35_MUX(0x9, "RMII0_TXD1")),
-	MA35_PIN(65, PE5, 0xa0, 0x14,
+	MA35_PIN(69, PE5, 0xa0, 0x14,
 		MA35_MUX(0x0, "GPE5"),
 		MA35_MUX(0x2, "UART4_nRTS"),
 		MA35_MUX(0x3, "UART3_TXD"),
 		MA35_MUX(0x7, "CCAP1_DATA5"),
 		MA35_MUX(0x8, "RGMII0_RXCLK"),
 		MA35_MUX(0x9, "RMII0_REFCLK")),
-	MA35_PIN(66, PE6, 0xa0, 0x18,
+	MA35_PIN(70, PE6, 0xa0, 0x18,
 		MA35_MUX(0x0, "GPE6"),
 		MA35_MUX(0x2, "UART4_RXD"),
 		MA35_MUX(0x7, "CCAP1_DATA6"),
 		MA35_MUX(0x8, "RGMII0_RXCTL"),
 		MA35_MUX(0x9, "RMII0_CRSDV")),
-	MA35_PIN(67, PE7, 0xa0, 0x1c,
+	MA35_PIN(71, PE7, 0xa0, 0x1c,
 		MA35_MUX(0x0, "GPE7"),
 		MA35_MUX(0x2, "UART4_TXD"),
 		MA35_MUX(0x7, "CCAP1_DATA7"),
 		MA35_MUX(0x8, "RGMII0_RXD0"),
 		MA35_MUX(0x9, "RMII0_RXD0")),
-	MA35_PIN(68, PE8, 0xa4, 0x0,
+	MA35_PIN(72, PE8, 0xa4, 0x0,
 		MA35_MUX(0x0, "GPE8"),
 		MA35_MUX(0x2, "UART13_nCTS"),
 		MA35_MUX(0x3, "UART12_RXD"),
 		MA35_MUX(0x7, "CCAP1_SCLK"),
 		MA35_MUX(0x8, "RGMII0_RXD1"),
 		MA35_MUX(0x9, "RMII0_RXD1")),
-	MA35_PIN(69, PE9, 0xa4, 0x4,
+	MA35_PIN(73, PE9, 0xa4, 0x4,
 		MA35_MUX(0x0, "GPE9"),
 		MA35_MUX(0x2, "UART13_nRTS"),
 		MA35_MUX(0x3, "UART12_TXD"),
 		MA35_MUX(0x7, "CCAP1_PIXCLK"),
 		MA35_MUX(0x8, "RGMII0_RXD2"),
 		MA35_MUX(0x9, "RMII0_RXERR")),
-	MA35_PIN(70, PE10, 0xa4, 0x8,
+	MA35_PIN(74, PE10, 0xa4, 0x8,
 		MA35_MUX(0x0, "GPE10"),
 		MA35_MUX(0x2, "UART15_nCTS"),
 		MA35_MUX(0x3, "UART14_RXD"),
 		MA35_MUX(0x5, "SPI1_SS0"),
 		MA35_MUX(0x7, "CCAP1_HSYNC"),
 		MA35_MUX(0x8, "RGMII0_RXD3")),
-	MA35_PIN(71, PE11, 0xa4, 0xc,
+	MA35_PIN(75, PE11, 0xa4, 0xc,
 		MA35_MUX(0x0, "GPE11"),
 		MA35_MUX(0x2, "UART15_nRTS"),
 		MA35_MUX(0x3, "UART14_TXD"),
 		MA35_MUX(0x5, "SPI1_CLK"),
 		MA35_MUX(0x7, "CCAP1_VSYNC"),
 		MA35_MUX(0x8, "RGMII0_TXCLK")),
-	MA35_PIN(72, PE12, 0xa4, 0x10,
+	MA35_PIN(76, PE12, 0xa4, 0x10,
 		MA35_MUX(0x0, "GPE12"),
 		MA35_MUX(0x2, "UART15_RXD"),
 		MA35_MUX(0x5, "SPI1_MOSI"),
 		MA35_MUX(0x7, "CCAP1_DATA8"),
 		MA35_MUX(0x8, "RGMII0_TXD2")),
-	MA35_PIN(73, PE13, 0xa4, 0x14,
+	MA35_PIN(77, PE13, 0xa4, 0x14,
 		MA35_MUX(0x0, "GPE13"),
 		MA35_MUX(0x2, "UART15_TXD"),
 		MA35_MUX(0x5, "SPI1_MISO"),
 		MA35_MUX(0x7, "CCAP1_DATA9"),
 		MA35_MUX(0x8, "RGMII0_TXD3")),
-	MA35_PIN(74, PE14, 0xa4, 0x18,
+	MA35_PIN(78, PE14, 0xa4, 0x18,
 		MA35_MUX(0x0, "GPE14"),
 		MA35_MUX(0x1, "UART0_TXD")),
-	MA35_PIN(75, PE15, 0xa4, 0x1c,
+	MA35_PIN(79, PE15, 0xa4, 0x1c,
 		MA35_MUX(0x0, "GPE15"),
 		MA35_MUX(0x1, "UART0_RXD")),
-	MA35_PIN(76, PF0, 0xa8, 0x0,
+	MA35_PIN(80, PF0, 0xa8, 0x0,
 		MA35_MUX(0x0, "GPF0"),
 		MA35_MUX(0x2, "UART2_nCTS"),
 		MA35_MUX(0x3, "UART1_RXD"),
@@ -553,7 +601,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "RGMII1_MDC"),
 		MA35_MUX(0x9, "RMII1_MDC"),
 		MA35_MUX(0xe, "KPI_COL0")),
-	MA35_PIN(77, PF1, 0xa8, 0x4,
+	MA35_PIN(81, PF1, 0xa8, 0x4,
 		MA35_MUX(0x0, "GPF1"),
 		MA35_MUX(0x2, "UART2_nRTS"),
 		MA35_MUX(0x3, "UART1_TXD"),
@@ -561,21 +609,21 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "RGMII1_MDIO"),
 		MA35_MUX(0x9, "RMII1_MDIO"),
 		MA35_MUX(0xe, "KPI_COL1")),
-	MA35_PIN(78, PF2, 0xa8, 0x8,
+	MA35_PIN(82, PF2, 0xa8, 0x8,
 		MA35_MUX(0x0, "GPF2"),
 		MA35_MUX(0x2, "UART2_RXD"),
 		MA35_MUX(0x6, "RGMII0_TXD2"),
 		MA35_MUX(0x8, "RGMII1_TXCTL"),
 		MA35_MUX(0x9, "RMII1_TXEN"),
 		MA35_MUX(0xe, "KPI_COL2")),
-	MA35_PIN(79, PF3, 0xa8, 0xc,
+	MA35_PIN(83, PF3, 0xa8, 0xc,
 		MA35_MUX(0x0, "GPF3"),
 		MA35_MUX(0x2, "UART2_TXD"),
 		MA35_MUX(0x6, "RGMII0_TXD3"),
 		MA35_MUX(0x8, "RGMII1_TXD0"),
 		MA35_MUX(0x9, "RMII1_TXD0"),
 		MA35_MUX(0xe, "KPI_COL3")),
-	MA35_PIN(80, PF4, 0xa8, 0x10,
+	MA35_PIN(84, PF4, 0xa8, 0x10,
 		MA35_MUX(0x0, "GPF4"),
 		MA35_MUX(0x2, "UART11_nCTS"),
 		MA35_MUX(0x3, "UART10_RXD"),
@@ -583,9 +631,10 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x5, "SPI1_SS0"),
 		MA35_MUX(0x8, "RGMII1_TXD1"),
 		MA35_MUX(0x9, "RMII1_TXD1"),
+		MA35_MUX(0xc, "USBHL0_DM"),
 		MA35_MUX(0xd, "CAN2_RXD"),
 		MA35_MUX(0xe, "KPI_ROW0")),
-	MA35_PIN(81, PF5, 0xa8, 0x14,
+	MA35_PIN(85, PF5, 0xa8, 0x14,
 		MA35_MUX(0x0, "GPF5"),
 		MA35_MUX(0x2, "UART11_nRTS"),
 		MA35_MUX(0x3, "UART10_TXD"),
@@ -593,9 +642,10 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x5, "SPI1_CLK"),
 		MA35_MUX(0x8, "RGMII1_RXCLK"),
 		MA35_MUX(0x9, "RMII1_REFCLK"),
+		MA35_MUX(0xc, "USBHL0_DP"),
 		MA35_MUX(0xd, "CAN2_TXD"),
 		MA35_MUX(0xe, "KPI_ROW1")),
-	MA35_PIN(82, PF6, 0xa8, 0x18,
+	MA35_PIN(86, PF6, 0xa8, 0x18,
 		MA35_MUX(0x0, "GPF6"),
 		MA35_MUX(0x2, "UART11_RXD"),
 		MA35_MUX(0x4, "I2S0_DI"),
@@ -605,7 +655,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xa, "I2C4_SDA"),
 		MA35_MUX(0xd, "SC0_CLK"),
 		MA35_MUX(0xe, "KPI_ROW2")),
-	MA35_PIN(83, PF7, 0xa8, 0x1c,
+	MA35_PIN(87, PF7, 0xa8, 0x1c,
 		MA35_MUX(0x0, "GPF7"),
 		MA35_MUX(0x2, "UART11_TXD"),
 		MA35_MUX(0x4, "I2S0_DO"),
@@ -615,7 +665,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xa, "I2C4_SCL"),
 		MA35_MUX(0xd, "SC0_DAT"),
 		MA35_MUX(0xe, "KPI_ROW3")),
-	MA35_PIN(84, PF8, 0xac, 0x0,
+	MA35_PIN(88, PF8, 0xac, 0x0,
 		MA35_MUX(0x0, "GPF8"),
 		MA35_MUX(0x2, "UART13_RXD"),
 		MA35_MUX(0x4, "I2C5_SDA"),
@@ -624,7 +674,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "RMII1_RXD1"),
 		MA35_MUX(0xd, "SC0_RST"),
 		MA35_MUX(0xe, "KPI_COL4")),
-	MA35_PIN(85, PF9, 0xac, 0x4,
+	MA35_PIN(89, PF9, 0xac, 0x4,
 		MA35_MUX(0x0, "GPF9"),
 		MA35_MUX(0x2, "UART13_TXD"),
 		MA35_MUX(0x4, "I2C5_SCL"),
@@ -633,7 +683,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "RMII1_RXERR"),
 		MA35_MUX(0xd, "SC0_PWR"),
 		MA35_MUX(0xe, "KPI_COL5")),
-	MA35_PIN(86, PF10, 0xac, 0x8,
+	MA35_PIN(90, PF10, 0xac, 0x8,
 		MA35_MUX(0x0, "GPF10"),
 		MA35_MUX(0x2, "UART13_nCTS"),
 		MA35_MUX(0x5, "I2S0_LRCK"),
@@ -641,7 +691,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "RGMII1_RXD3"),
 		MA35_MUX(0x9, "SC0_CLK"),
 		MA35_MUX(0xe, "KPI_COL6")),
-	MA35_PIN(87, PF11, 0xac, 0xc,
+	MA35_PIN(91, PF11, 0xac, 0xc,
 		MA35_MUX(0x0, "GPF11"),
 		MA35_MUX(0x2, "UART13_nRTS"),
 		MA35_MUX(0x5, "I2S0_BCLK"),
@@ -649,21 +699,21 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "RGMII1_TXCLK"),
 		MA35_MUX(0x9, "SC0_DAT"),
 		MA35_MUX(0xe, "KPI_COL7")),
-	MA35_PIN(88, PF12, 0xac, 0x10,
+	MA35_PIN(92, PF12, 0xac, 0x10,
 		MA35_MUX(0x0, "GPF12"),
 		MA35_MUX(0x5, "I2S0_DI"),
 		MA35_MUX(0x6, "SPI1_MOSI"),
 		MA35_MUX(0x8, "RGMII1_TXD2"),
 		MA35_MUX(0x9, "SC0_RST"),
 		MA35_MUX(0xe, "KPI_ROW4")),
-	MA35_PIN(89, PF13, 0xac, 0x14,
+	MA35_PIN(93, PF13, 0xac, 0x14,
 		MA35_MUX(0x0, "GPF13"),
 		MA35_MUX(0x5, "I2S0_DO"),
 		MA35_MUX(0x6, "SPI1_MISO"),
 		MA35_MUX(0x8, "RGMII1_TXD3"),
 		MA35_MUX(0x9, "SC0_PWR"),
 		MA35_MUX(0xe, "KPI_ROW5")),
-	MA35_PIN(90, PF14, 0xac, 0x18,
+	MA35_PIN(94, PF14, 0xac, 0x18,
 		MA35_MUX(0x0, "GPF14"),
 		MA35_MUX(0x1, "EPWM2_BRAKE0"),
 		MA35_MUX(0x2, "EADC0_ST"),
@@ -679,10 +729,10 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xd, "SPI1_SS1"),
 		MA35_MUX(0xe, "QEI2_INDEX"),
 		MA35_MUX(0xf, "I2S0_MCLK")),
-	MA35_PIN(91, PF15, 0xac, 0x1c,
+	MA35_PIN(95, PF15, 0xac, 0x1c,
 		MA35_MUX(0x0, "GPF15"),
 		MA35_MUX(0x1, "HSUSB0_VBUSVLD")),
-	MA35_PIN(92, PG0, 0xb0, 0x0,
+	MA35_PIN(96, PG0, 0xb0, 0x0,
 		MA35_MUX(0x0, "GPG0"),
 		MA35_MUX(0x1, "EPWM0_CH0"),
 		MA35_MUX(0x2, "UART7_TXD"),
@@ -696,19 +746,20 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xc, "CLKO"),
 		MA35_MUX(0xd, "INT0"),
 		MA35_MUX(0xf, "EBI_ADR15")),
-	MA35_PIN(93, PG1, 0xb0, 0x4,
+	MA35_PIN(97, PG1, 0xb0, 0x4,
 		MA35_MUX(0x0, "GPG1"),
 		MA35_MUX(0x1, "EPWM0_CH3"),
 		MA35_MUX(0x2, "UART9_nRTS"),
 		MA35_MUX(0x3, "UART6_TXD"),
 		MA35_MUX(0x4, "I2C4_SCL"),
 		MA35_MUX(0x5, "CAN2_TXD"),
+		MA35_MUX(0x6, "USBHL0_DP"),
 		MA35_MUX(0x7, "EBI_nCS0"),
 		MA35_MUX(0x9, "QEI0_B"),
 		MA35_MUX(0xb, "TM1_EXT"),
 		MA35_MUX(0xe, "RGMII1_PPS"),
 		MA35_MUX(0xf, "RMII1_PPS")),
-	MA35_PIN(94, PG2, 0xb0, 0x8,
+	MA35_PIN(98, PG2, 0xb0, 0x8,
 		MA35_MUX(0x0, "GPG2"),
 		MA35_MUX(0x1, "EPWM0_CH4"),
 		MA35_MUX(0x2, "UART9_RXD"),
@@ -719,7 +770,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xa, "QEI0_A"),
 		MA35_MUX(0xb, "TM3"),
 		MA35_MUX(0xd, "INT1")),
-	MA35_PIN(95, PG3, 0xb0, 0xc,
+	MA35_PIN(99, PG3, 0xb0, 0xc,
 		MA35_MUX(0x0, "GPG3"),
 		MA35_MUX(0x1, "EPWM0_CH5"),
 		MA35_MUX(0x2, "UART9_TXD"),
@@ -731,7 +782,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xa, "QEI0_B"),
 		MA35_MUX(0xb, "TM3_EXT"),
 		MA35_MUX(0xc, "I2S1_MCLK")),
-	MA35_PIN(96, PG4, 0xb0, 0x10,
+	MA35_PIN(100, PG4, 0xb0, 0x10,
 		MA35_MUX(0x0, "GPG4"),
 		MA35_MUX(0x1, "EPWM1_CH0"),
 		MA35_MUX(0x2, "UART5_nCTS"),
@@ -745,7 +796,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xb, "TM4"),
 		MA35_MUX(0xd, "INT2"),
 		MA35_MUX(0xe, "ECAP1_IC2")),
-	MA35_PIN(97, PG5, 0xb0, 0x14,
+	MA35_PIN(101, PG5, 0xb0, 0x14,
 		MA35_MUX(0x0, "GPG5"),
 		MA35_MUX(0x1, "EPWM1_CH1"),
 		MA35_MUX(0x2, "UART5_nRTS"),
@@ -757,7 +808,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "I2S1_DI"),
 		MA35_MUX(0xa, "SC1_DAT"),
 		MA35_MUX(0xb, "TM4_EXT")),
-	MA35_PIN(98, PG6, 0xb0, 0x18,
+	MA35_PIN(102, PG6, 0xb0, 0x18,
 		MA35_MUX(0x0, "GPG6"),
 		MA35_MUX(0x1, "EPWM1_CH2"),
 		MA35_MUX(0x2, "UART5_RXD"),
@@ -769,7 +820,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xa, "SC1_RST"),
 		MA35_MUX(0xb, "TM7"),
 		MA35_MUX(0xd, "INT3")),
-	MA35_PIN(99, PG7, 0xb0, 0x1c,
+	MA35_PIN(103, PG7, 0xb0, 0x1c,
 		MA35_MUX(0x0, "GPG7"),
 		MA35_MUX(0x1, "EPWM1_CH3"),
 		MA35_MUX(0x2, "UART5_TXD"),
@@ -780,27 +831,29 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "I2S1_LRCK"),
 		MA35_MUX(0xa, "SC1_PWR"),
 		MA35_MUX(0xb, "TM7_EXT")),
-	MA35_PIN(100, PG8, 0xb4, 0x0,
+	MA35_PIN(104, PG8, 0xb4, 0x0,
 		MA35_MUX(0x0, "GPG8"),
 		MA35_MUX(0x1, "EPWM1_CH4"),
 		MA35_MUX(0x2, "UART12_RXD"),
 		MA35_MUX(0x3, "CAN3_RXD"),
+		MA35_MUX(0x4, "USBHL4_DM"),
 		MA35_MUX(0x5, "SPI2_SS0"),
 		MA35_MUX(0x6, "LCM_VSYNC"),
 		MA35_MUX(0x7, "I2C3_SDA"),
 		MA35_MUX(0xc, "EBI_AD7"),
 		MA35_MUX(0xd, "EBI_nCS0")),
-	MA35_PIN(101, PG9, 0xb4, 0x4,
+	MA35_PIN(105, PG9, 0xb4, 0x4,
 		MA35_MUX(0x0, "GPG9"),
 		MA35_MUX(0x1, "EPWM1_CH5"),
 		MA35_MUX(0x2, "UART12_TXD"),
 		MA35_MUX(0x3, "CAN3_TXD"),
+		MA35_MUX(0x4, "USBHL4_DP"),
 		MA35_MUX(0x5, "SPI2_CLK"),
 		MA35_MUX(0x6, "LCM_HSYNC"),
 		MA35_MUX(0x7, "I2C3_SCL"),
 		MA35_MUX(0xc, "EBI_AD8"),
 		MA35_MUX(0xd, "EBI_nCS1")),
-	MA35_PIN(102, PG10, 0xb4, 0x8,
+	MA35_PIN(106, PG10, 0xb4, 0x8,
 		MA35_MUX(0x0, "GPG10"),
 		MA35_MUX(0x2, "UART12_nRTS"),
 		MA35_MUX(0x3, "UART13_TXD"),
@@ -808,7 +861,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x6, "LCM_CLK"),
 		MA35_MUX(0xc, "EBI_AD9"),
 		MA35_MUX(0xd, "EBI_nWRH")),
-	MA35_PIN(103, PG11, 0xb4, 0xc,
+	MA35_PIN(107, PG11, 0xb4, 0xc,
 		MA35_MUX(0x0, "GPG11"),
 		MA35_MUX(0x3, "JTAG_TDO"),
 		MA35_MUX(0x5, "I2S0_MCLK"),
@@ -816,93 +869,93 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x7, "EBI_nWRH"),
 		MA35_MUX(0x8, "EBI_nCS1"),
 		MA35_MUX(0xa, "EBI_AD0")),
-	MA35_PIN(104, PG12, 0xb4, 0x10,
+	MA35_PIN(108, PG12, 0xb4, 0x10,
 		MA35_MUX(0x0, "GPG12"),
 		MA35_MUX(0x3, "JTAG_TCK/SW_CLK"),
 		MA35_MUX(0x5, "I2S0_LRCK"),
 		MA35_MUX(0x7, "EBI_nWRL"),
 		MA35_MUX(0xa, "EBI_AD1")),
-	MA35_PIN(105, PG13, 0xb4, 0x14,
+	MA35_PIN(109, PG13, 0xb4, 0x14,
 		MA35_MUX(0x0, "GPG13"),
 		MA35_MUX(0x3, "JTAG_TMS/SW_DIO"),
 		MA35_MUX(0x5, "I2S0_BCLK"),
 		MA35_MUX(0x7, "EBI_MCLK"),
 		MA35_MUX(0xa, "EBI_AD2")),
-	MA35_PIN(106, PG14, 0xb4, 0x18,
+	MA35_PIN(110, PG14, 0xb4, 0x18,
 		MA35_MUX(0x0, "GPG14"),
 		MA35_MUX(0x3, "JTAG_TDI"),
 		MA35_MUX(0x5, "I2S0_DI"),
 		MA35_MUX(0x6, "NAND_nCS1"),
 		MA35_MUX(0x7, "EBI_ALE"),
 		MA35_MUX(0xa, "EBI_AD3")),
-	MA35_PIN(107, PG15, 0xb4, 0x1c,
+	MA35_PIN(111, PG15, 0xb4, 0x1c,
 		MA35_MUX(0x0, "GPG15"),
 		MA35_MUX(0x3, "JTAG_nTRST"),
 		MA35_MUX(0x5, "I2S0_DO"),
 		MA35_MUX(0x7, "EBI_nCS0"),
 		MA35_MUX(0xa, "EBI_AD4")),
-	MA35_PIN(108, PH0, 0xb8, 0x0,
+	MA35_PIN(112, PH0, 0xb8, 0x0,
 		MA35_MUX(0x0, "GPH0"),
 		MA35_MUX(0x2, "UART8_nCTS"),
 		MA35_MUX(0x3, "UART7_RXD"),
 		MA35_MUX(0x6, "LCM_DATA8")),
-	MA35_PIN(109, PH1, 0xb8, 0x4,
+	MA35_PIN(113, PH1, 0xb8, 0x4,
 		MA35_MUX(0x0, "GPH1"),
 		MA35_MUX(0x2, "UART8_nRTS"),
 		MA35_MUX(0x3, "UART7_TXD"),
 		MA35_MUX(0x6, "LCM_DATA9")),
-	MA35_PIN(110, PH2, 0xb8, 0x8,
+	MA35_PIN(114, PH2, 0xb8, 0x8,
 		MA35_MUX(0x0, "GPH2"),
 		MA35_MUX(0x2, "UART8_RXD"),
 		MA35_MUX(0x6, "LCM_DATA10")),
-	MA35_PIN(111, PH3, 0xb8, 0xc,
+	MA35_PIN(115, PH3, 0xb8, 0xc,
 		MA35_MUX(0x0, "GPH3"),
 		MA35_MUX(0x2, "UART8_TXD"),
 		MA35_MUX(0x6, "LCM_DATA11")),
-	MA35_PIN(112, PH4, 0xb8, 0x10,
+	MA35_PIN(116, PH4, 0xb8, 0x10,
 		MA35_MUX(0x0, "GPH4"),
 		MA35_MUX(0x2, "UART10_nCTS"),
 		MA35_MUX(0x3, "UART9_RXD"),
 		MA35_MUX(0x6, "LCM_DATA12")),
-	MA35_PIN(113, PH5, 0xb8, 0x14,
+	MA35_PIN(117, PH5, 0xb8, 0x14,
 		MA35_MUX(0x0, "GPH5"),
 		MA35_MUX(0x2, "UART10_nRTS"),
 		MA35_MUX(0x3, "UART9_TXD"),
 		MA35_MUX(0x6, "LCM_DATA13")),
-	MA35_PIN(114, PH6, 0xb8, 0x18,
+	MA35_PIN(118, PH6, 0xb8, 0x18,
 		MA35_MUX(0x0, "GPH6"),
 		MA35_MUX(0x2, "UART10_RXD"),
 		MA35_MUX(0x6, "LCM_DATA14")),
-	MA35_PIN(115, PH7, 0xb8, 0x1c,
+	MA35_PIN(119, PH7, 0xb8, 0x1c,
 		MA35_MUX(0x0, "GPH7"),
 		MA35_MUX(0x2, "UART10_TXD"),
 		MA35_MUX(0x6, "LCM_DATA15")),
-	MA35_PIN(116, PH8, 0xbc, 0x0,
+	MA35_PIN(120, PH8, 0xbc, 0x0,
 		MA35_MUX(0x0, "GPH8"),
 		MA35_MUX(0x6, "TAMPER0")),
-	MA35_PIN(117, PH9, 0xbc, 0x4,
+	MA35_PIN(121, PH9, 0xbc, 0x4,
 		MA35_MUX(0x0, "GPH9"),
 		MA35_MUX(0x4, "CLK_32KOUT"),
 		MA35_MUX(0x6, "TAMPER1")),
-	MA35_PIN(118, PH12, 0xbc, 0x10,
+	MA35_PIN(124, PH12, 0xbc, 0x10,
 		MA35_MUX(0x0, "GPH12"),
 		MA35_MUX(0x2, "UART14_nCTS"),
 		MA35_MUX(0x3, "UART13_RXD"),
 		MA35_MUX(0x6, "LCM_DATA20")),
-	MA35_PIN(119, PH13, 0xbc, 0x14,
+	MA35_PIN(125, PH13, 0xbc, 0x14,
 		MA35_MUX(0x0, "GPH13"),
 		MA35_MUX(0x2, "UART14_nRTS"),
 		MA35_MUX(0x3, "UART13_TXD"),
 		MA35_MUX(0x6, "LCM_DATA21")),
-	MA35_PIN(120, PH14, 0xbc, 0x18,
+	MA35_PIN(126, PH14, 0xbc, 0x18,
 		MA35_MUX(0x0, "GPH14"),
 		MA35_MUX(0x2, "UART14_RXD"),
 		MA35_MUX(0x6, "LCM_DATA22")),
-	MA35_PIN(121, PH15, 0xbc, 0x1c,
+	MA35_PIN(127, PH15, 0xbc, 0x1c,
 		MA35_MUX(0x0, "GPH15"),
 		MA35_MUX(0x2, "UART14_TXD"),
 		MA35_MUX(0x6, "LCM_DATA23")),
-	MA35_PIN(122, PI0, 0xc0, 0x0,
+	MA35_PIN(128, PI0, 0xc0, 0x0,
 		MA35_MUX(0x0, "GPI0"),
 		MA35_MUX(0x1, "EPWM0_CH0"),
 		MA35_MUX(0x2, "UART12_nCTS"),
@@ -913,7 +966,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "EBI_ADR0"),
 		MA35_MUX(0xb, "TM0"),
 		MA35_MUX(0xc, "ECAP1_IC0")),
-	MA35_PIN(123, PI1, 0xc0, 0x4,
+	MA35_PIN(129, PI1, 0xc0, 0x4,
 		MA35_MUX(0x0, "GPI1"),
 		MA35_MUX(0x1, "EPWM0_CH1"),
 		MA35_MUX(0x2, "UART12_nRTS"),
@@ -924,26 +977,28 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "EBI_ADR1"),
 		MA35_MUX(0xb, "TM0_EXT"),
 		MA35_MUX(0xc, "ECAP1_IC1")),
-	MA35_PIN(124, PI2, 0xc0, 0x8,
+	MA35_PIN(130, PI2, 0xc0, 0x8,
 		MA35_MUX(0x0, "GPI2"),
 		MA35_MUX(0x1, "EPWM0_CH2"),
 		MA35_MUX(0x2, "UART12_RXD"),
 		MA35_MUX(0x3, "CAN0_RXD"),
+		MA35_MUX(0x4, "USBHL2_DM"),
 		MA35_MUX(0x5, "SPI3_MOSI"),
 		MA35_MUX(0x7, "SC0_DAT"),
 		MA35_MUX(0x8, "EBI_ADR2"),
 		MA35_MUX(0xb, "TM1"),
 		MA35_MUX(0xc, "ECAP1_IC2")),
-	MA35_PIN(125, PI3, 0xc0, 0xc,
+	MA35_PIN(131, PI3, 0xc0, 0xc,
 		MA35_MUX(0x0, "GPI3"),
 		MA35_MUX(0x1, "EPWM0_CH3"),
 		MA35_MUX(0x2, "UART12_TXD"),
 		MA35_MUX(0x3, "CAN0_TXD"),
+		MA35_MUX(0x4, "USBHL2_DP"),
 		MA35_MUX(0x5, "SPI3_MISO"),
 		MA35_MUX(0x7, "SC0_RST"),
 		MA35_MUX(0x8, "EBI_ADR3"),
 		MA35_MUX(0xb, "TM1_EXT")),
-	MA35_PIN(126, PI4, 0xc0, 0x10,
+	MA35_PIN(132, PI4, 0xc0, 0x10,
 		MA35_MUX(0x0, "GPI4"),
 		MA35_MUX(0x1, "EPWM0_CH4"),
 		MA35_MUX(0x2, "UART14_nCTS"),
@@ -953,7 +1008,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x6, "I2S1_LRCK"),
 		MA35_MUX(0x8, "EBI_ADR4"),
 		MA35_MUX(0xd, "INT0")),
-	MA35_PIN(127, PI5, 0xc0, 0x14,
+	MA35_PIN(133, PI5, 0xc0, 0x14,
 		MA35_MUX(0x0, "GPI5"),
 		MA35_MUX(0x1, "EPWM0_CH5"),
 		MA35_MUX(0x2, "UART14_nRTS"),
@@ -962,65 +1017,67 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x6, "I2S1_BCLK"),
 		MA35_MUX(0x8, "EBI_ADR5"),
 		MA35_MUX(0xd, "INT1")),
-	MA35_PIN(128, PI6, 0xc0, 0x18,
+	MA35_PIN(134, PI6, 0xc0, 0x18,
 		MA35_MUX(0x0, "GPI6"),
 		MA35_MUX(0x1, "EPWM0_BRAKE0"),
 		MA35_MUX(0x2, "UART14_RXD"),
 		MA35_MUX(0x3, "CAN1_RXD"),
+		MA35_MUX(0x4, "USBHL3_DM"),
 		MA35_MUX(0x6, "I2S1_DI"),
 		MA35_MUX(0x8, "EBI_ADR6"),
 		MA35_MUX(0xc, "QEI1_INDEX"),
 		MA35_MUX(0xd, "INT2")),
-	MA35_PIN(129, PI7, 0xc0, 0x1c,
+	MA35_PIN(135, PI7, 0xc0, 0x1c,
 		MA35_MUX(0x0, "GPI7"),
 		MA35_MUX(0x1, "EPWM0_BRAKE1"),
 		MA35_MUX(0x2, "UART14_TXD"),
 		MA35_MUX(0x3, "CAN1_TXD"),
+		MA35_MUX(0x4, "USBHL3_DP"),
 		MA35_MUX(0x6, "I2S1_DO"),
 		MA35_MUX(0x8, "EBI_ADR7"),
 		MA35_MUX(0xc, "ECAP0_IC0"),
 		MA35_MUX(0xd, "INT3")),
-	MA35_PIN(130, PI8, 0xc4, 0x0,
+	MA35_PIN(136, PI8, 0xc4, 0x0,
 		MA35_MUX(0x0, "GPI8"),
 		MA35_MUX(0x2, "UART4_nCTS"),
 		MA35_MUX(0x3, "UART3_RXD"),
 		MA35_MUX(0x6, "LCM_DATA0"),
 		MA35_MUX(0xc, "EBI_AD11")),
-	MA35_PIN(131, PI9, 0xc4, 0x4,
+	MA35_PIN(137, PI9, 0xc4, 0x4,
 		MA35_MUX(0x0, "GPI9"),
 		MA35_MUX(0x2, "UART4_nRTS"),
 		MA35_MUX(0x3, "UART3_TXD"),
 		MA35_MUX(0x6, "LCM_DATA1"),
 		MA35_MUX(0xc, "EBI_AD12")),
-	MA35_PIN(132, PI10, 0xc4, 0x8,
+	MA35_PIN(138, PI10, 0xc4, 0x8,
 		MA35_MUX(0x0, "GPI10"),
 		MA35_MUX(0x2, "UART4_RXD"),
 		MA35_MUX(0x6, "LCM_DATA2"),
 		MA35_MUX(0xc, "EBI_AD13")),
-	MA35_PIN(133, PI11, 0xC4, 0xc,
+	MA35_PIN(139, PI11, 0xC4, 0xc,
 		MA35_MUX(0x0, "GPI11"),
 		MA35_MUX(0x2, "UART4_TXD"),
 		MA35_MUX(0x6, "LCM_DATA3"),
 		MA35_MUX(0xc, "EBI_AD14")),
-	MA35_PIN(134, PI12, 0xc4, 0x10,
+	MA35_PIN(140, PI12, 0xc4, 0x10,
 		MA35_MUX(0x0, "GPI12"),
 		MA35_MUX(0x2, "UART6_nCTS"),
 		MA35_MUX(0x3, "UART5_RXD"),
 		MA35_MUX(0x6, "LCM_DATA4")),
-	MA35_PIN(135, PI13, 0xc4, 0x14,
+	MA35_PIN(141, PI13, 0xc4, 0x14,
 		MA35_MUX(0x0, "GPI13"),
 		MA35_MUX(0x2, "UART6_nRTS"),
 		MA35_MUX(0x3, "UART5_TXD"),
 		MA35_MUX(0x6, "LCM_DATA5")),
-	MA35_PIN(136, PI14, 0xc4, 0x18,
+	MA35_PIN(142, PI14, 0xc4, 0x18,
 		MA35_MUX(0x0, "GPI14"),
 		MA35_MUX(0x2, "UART6_RXD"),
 		MA35_MUX(0x6, "LCM_DATA6")),
-	MA35_PIN(137, PI15, 0xc4, 0x1c,
+	MA35_PIN(143, PI15, 0xc4, 0x1c,
 		MA35_MUX(0x0, "GPI15"),
 		MA35_MUX(0x2, "UART6_TXD"),
 		MA35_MUX(0x6, "LCM_DATA7")),
-	MA35_PIN(138, PJ0, 0xc8, 0x0,
+	MA35_PIN(144, PJ0, 0xc8, 0x0,
 		MA35_MUX(0x0, "GPJ0"),
 		MA35_MUX(0x1, "EPWM1_BRAKE0"),
 		MA35_MUX(0x2, "UART8_nCTS"),
@@ -1034,7 +1091,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xa, "EBI_ADR16"),
 		MA35_MUX(0xb, "EBI_nCS0"),
 		MA35_MUX(0xc, "EBI_AD7")),
-	MA35_PIN(139, PJ1, 0xc8, 0x4,
+	MA35_PIN(145, PJ1, 0xc8, 0x4,
 		MA35_MUX(0x0, "GPJ1"),
 		MA35_MUX(0x1, "EPWM1_BRAKE1"),
 		MA35_MUX(0x2, "UART8_nRTS"),
@@ -1048,11 +1105,12 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xa, "EBI_ADR17"),
 		MA35_MUX(0xb, "EBI_nCS1"),
 		MA35_MUX(0xc, "EBI_AD8")),
-	MA35_PIN(140, PJ2, 0xc8, 0x8,
+	MA35_PIN(146, PJ2, 0xc8, 0x8,
 		MA35_MUX(0x0, "GPJ2"),
 		MA35_MUX(0x1, "EPWM1_CH4"),
 		MA35_MUX(0x2, "UART8_RXD"),
 		MA35_MUX(0x3, "CAN1_RXD"),
+		MA35_MUX(0x4, "USBHL5_DM"),
 		MA35_MUX(0x5, "SPI2_MOSI"),
 		MA35_MUX(0x6, "eMMC1_DAT6"),
 		MA35_MUX(0x7, "I2S0_DI"),
@@ -1061,11 +1119,12 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xa, "EBI_ADR18"),
 		MA35_MUX(0xb, "EBI_nWRH"),
 		MA35_MUX(0xc, "EBI_AD9")),
-	MA35_PIN(141, PJ3, 0xc8, 0xc,
+	MA35_PIN(147, PJ3, 0xc8, 0xc,
 		MA35_MUX(0x0, "GPJ3"),
 		MA35_MUX(0x1, "EPWM1_CH5"),
 		MA35_MUX(0x2, "UART8_TXD"),
 		MA35_MUX(0x3, "CAN1_TXD"),
+		MA35_MUX(0x4, "USBHL5_DP"),
 		MA35_MUX(0x5, "SPI2_MISO"),
 		MA35_MUX(0x6, "eMMC1_DAT7"),
 		MA35_MUX(0x7, "I2S0_DO"),
@@ -1074,39 +1133,43 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xa, "EBI_ADR19"),
 		MA35_MUX(0xb, "EBI_nWRL"),
 		MA35_MUX(0xc, "EBI_AD10")),
-	MA35_PIN(142, PJ4, 0xc8, 0x10,
+	MA35_PIN(148, PJ4, 0xc8, 0x10,
 		MA35_MUX(0x0, "GPJ4"),
 		MA35_MUX(0x4, "I2C3_SDA"),
 		MA35_MUX(0x6, "SD1_WP")),
-	MA35_PIN(143, PJ5, 0xc8, 0x14,
+	MA35_PIN(149, PJ5, 0xc8, 0x14,
 		MA35_MUX(0x0, "GPJ5"),
 		MA35_MUX(0x4, "I2C3_SCL"),
 		MA35_MUX(0x6, "SD1_nCD")),
-	MA35_PIN(144, PJ6, 0xc8, 0x18,
+	MA35_PIN(150, PJ6, 0xc8, 0x18,
 		MA35_MUX(0x0, "GPJ6"),
 		MA35_MUX(0x3, "CAN3_RXD"),
+		MA35_MUX(0x4, "USBHL0_DM"),
 		MA35_MUX(0x6, "SD1_CMD/eMMC1_CMD")),
-	MA35_PIN(145, PJ7, 0xc8, 0x1c,
+	MA35_PIN(151, PJ7, 0xc8, 0x1c,
 		MA35_MUX(0x0, "GPJ7"),
 		MA35_MUX(0x3, "CAN3_TXD"),
+		MA35_MUX(0x4, "USBHL0_DP"),
 		MA35_MUX(0x6, "SD1_CLK/eMMC1_CLK")),
-	MA35_PIN(146, PJ8, 0xcc, 0x0,
+	MA35_PIN(152, PJ8, 0xcc, 0x0,
 		MA35_MUX(0x0, "GPJ8"),
 		MA35_MUX(0x4, "I2C4_SDA"),
 		MA35_MUX(0x6, "SD1_DAT0/eMMC1_DAT0")),
-	MA35_PIN(147, PJ9, 0xcc, 0x4,
+	MA35_PIN(153, PJ9, 0xcc, 0x4,
 		MA35_MUX(0x0, "GPJ9"),
 		MA35_MUX(0x4, "I2C4_SCL"),
 		MA35_MUX(0x6, "SD1_DAT1/eMMC1_DAT1")),
-	MA35_PIN(148, PJ10, 0xcc, 0x8,
+	MA35_PIN(154, PJ10, 0xcc, 0x8,
 		MA35_MUX(0x0, "GPJ10"),
 		MA35_MUX(0x3, "CAN0_RXD"),
+		MA35_MUX(0x4, "USBHL1_DM"),
 		MA35_MUX(0x6, "SD1_DAT2/eMMC1_DAT2")),
-	MA35_PIN(149, PJ11, 0xcc, 0xc,
+	MA35_PIN(155, PJ11, 0xcc, 0xc,
 		MA35_MUX(0x0, "GPJ11"),
 		MA35_MUX(0x3, "CAN0_TXD"),
+		MA35_MUX(0x4, "USBHL1_DP"),
 		MA35_MUX(0x6, "SD1_DAT3/eMMC1_DAT3")),
-	MA35_PIN(150, PJ12, 0xcc, 0x10,
+	MA35_PIN(156, PJ12, 0xcc, 0x10,
 		MA35_MUX(0x0, "GPJ12"),
 		MA35_MUX(0x1, "EPWM1_CH2"),
 		MA35_MUX(0x2, "UART2_nCTS"),
@@ -1117,7 +1180,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "EBI_ADR12"),
 		MA35_MUX(0xb, "TM2"),
 		MA35_MUX(0xc, "QEI0_INDEX")),
-	MA35_PIN(151, PJ13, 0xcc, 0x14,
+	MA35_PIN(157, PJ13, 0xcc, 0x14,
 		MA35_MUX(0x0, "GPJ13"),
 		MA35_MUX(0x1, "EPWM1_CH3"),
 		MA35_MUX(0x2, "UART2_nRTS"),
@@ -1127,27 +1190,29 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x7, "SC1_DAT"),
 		MA35_MUX(0x8, "EBI_ADR13"),
 		MA35_MUX(0xb, "TM2_EXT")),
-	MA35_PIN(152, PJ14, 0xcc, 0x18,
+	MA35_PIN(158, PJ14, 0xcc, 0x18,
 		MA35_MUX(0x0, "GPJ14"),
 		MA35_MUX(0x1, "EPWM1_CH4"),
 		MA35_MUX(0x2, "UART2_RXD"),
 		MA35_MUX(0x3, "CAN3_RXD"),
+		MA35_MUX(0x4, "USBHL5_DM"),
 		MA35_MUX(0x5, "SPI3_MISO"),
 		MA35_MUX(0x7, "SC1_RST"),
 		MA35_MUX(0x8, "EBI_ADR14"),
 		MA35_MUX(0xb, "TM3")),
-	MA35_PIN(153, PJ15, 0xcc, 0x1c,
+	MA35_PIN(159, PJ15, 0xcc, 0x1c,
 		MA35_MUX(0x0, "GPJ15"),
 		MA35_MUX(0x1, "EPWM1_CH5"),
 		MA35_MUX(0x2, "UART2_TXD"),
 		MA35_MUX(0x3, "CAN3_TXD"),
+		MA35_MUX(0x4, "USBHL5_DP"),
 		MA35_MUX(0x5, "SPI3_CLK"),
 		MA35_MUX(0x6, "EADC0_ST"),
 		MA35_MUX(0x7, "SC1_PWR"),
 		MA35_MUX(0x8, "EBI_ADR15"),
 		MA35_MUX(0xb, "TM3_EXT"),
 		MA35_MUX(0xd, "INT1")),
-	MA35_PIN(154, PK0, 0xd0, 0x0,
+	MA35_PIN(160, PK0, 0xd0, 0x0,
 		MA35_MUX(0x0, "GPK0"),
 		MA35_MUX(0x1, "EPWM0_SYNC_IN"),
 		MA35_MUX(0x2, "UART16_nCTS"),
@@ -1157,7 +1222,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "EBI_ADR8"),
 		MA35_MUX(0xb, "TM7"),
 		MA35_MUX(0xc, "ECAP0_IC1")),
-	MA35_PIN(155, PK1, 0xd0, 0x4,
+	MA35_PIN(161, PK1, 0xd0, 0x4,
 		MA35_MUX(0x0, "GPK1"),
 		MA35_MUX(0x1, "EPWM0_SYNC_OUT"),
 		MA35_MUX(0x2, "UART16_nRTS"),
@@ -1167,25 +1232,27 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "EBI_ADR9"),
 		MA35_MUX(0xb, "TM7_EXT"),
 		MA35_MUX(0xc, "ECAP0_IC2")),
-	MA35_PIN(156, PK2, 0xd0, 0x8,
+	MA35_PIN(162, PK2, 0xd0, 0x8,
 		MA35_MUX(0x0, "GPK2"),
 		MA35_MUX(0x1, "EPWM1_CH0"),
 		MA35_MUX(0x2, "UART16_RXD"),
 		MA35_MUX(0x3, "CAN2_RXD"),
+		MA35_MUX(0x4, "USBHL4_DM"),
 		MA35_MUX(0x5, "SPI3_I2SMCLK"),
 		MA35_MUX(0x7, "SC0_PWR"),
 		MA35_MUX(0x8, "EBI_ADR10"),
 		MA35_MUX(0xc, "QEI0_A")),
-	MA35_PIN(157, PK3, 0xd0, 0xc,
+	MA35_PIN(163, PK3, 0xd0, 0xc,
 		MA35_MUX(0x0, "GPK3"),
 		MA35_MUX(0x1, "EPWM1_CH1"),
 		MA35_MUX(0x2, "UART16_TXD"),
 		MA35_MUX(0x3, "CAN2_TXD"),
+		MA35_MUX(0x4, "USBHL4_DP"),
 		MA35_MUX(0x5, "SPI3_SS1"),
 		MA35_MUX(0x7, "SC1_nCD"),
 		MA35_MUX(0x8, "EBI_ADR11"),
 		MA35_MUX(0xc, "QEI0_B")),
-	MA35_PIN(158, PK4, 0xd0, 0x10,
+	MA35_PIN(164, PK4, 0xd0, 0x10,
 		MA35_MUX(0x0, "GPK4"),
 		MA35_MUX(0x2, "UART12_nCTS"),
 		MA35_MUX(0x3, "UART13_RXD"),
@@ -1193,7 +1260,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x6, "LCM_DEN"),
 		MA35_MUX(0xc, "EBI_AD10"),
 		MA35_MUX(0xd, "EBI_nWRL")),
-	MA35_PIN(159, PK5, 0xd0, 0x14,
+	MA35_PIN(165, PK5, 0xd0, 0x14,
 		MA35_MUX(0x0, "GPK5"),
 		MA35_MUX(0x1, "EPWM1_CH1"),
 		MA35_MUX(0x2, "UART12_nRTS"),
@@ -1205,28 +1272,30 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "EADC0_ST"),
 		MA35_MUX(0xb, "TM8_EXT"),
 		MA35_MUX(0xd, "INT1")),
-	MA35_PIN(160, PK6, 0xd0, 0x18,
+	MA35_PIN(166, PK6, 0xd0, 0x18,
 		MA35_MUX(0x0, "GPK6"),
 		MA35_MUX(0x1, "EPWM1_CH2"),
 		MA35_MUX(0x2, "UART12_RXD"),
 		MA35_MUX(0x3, "CAN0_RXD"),
+		MA35_MUX(0x4, "USBHL4_DM"),
 		MA35_MUX(0x5, "SPI2_MOSI"),
 		MA35_MUX(0x7, "I2S1_BCLK"),
 		MA35_MUX(0x8, "SC0_RST"),
 		MA35_MUX(0xb, "TM6"),
 		MA35_MUX(0xd, "INT2")),
-	MA35_PIN(161, PK7, 0xd0, 0x1c,
+	MA35_PIN(167, PK7, 0xd0, 0x1c,
 		MA35_MUX(0x0, "GPK7"),
 		MA35_MUX(0x1, "EPWM1_CH3"),
 		MA35_MUX(0x2, "UART12_TXD"),
 		MA35_MUX(0x3, "CAN0_TXD"),
+		MA35_MUX(0x4, "USBHL4_DP"),
 		MA35_MUX(0x5, "SPI2_MISO"),
 		MA35_MUX(0x7, "I2S1_LRCK"),
 		MA35_MUX(0x8, "SC0_PWR"),
 		MA35_MUX(0x9, "CLKO"),
 		MA35_MUX(0xb, "TM6_EXT"),
 		MA35_MUX(0xd, "INT3")),
-	MA35_PIN(162, PK8, 0xd4, 0x0,
+	MA35_PIN(168, PK8, 0xd4, 0x0,
 		MA35_MUX(0x0, "GPK8"),
 		MA35_MUX(0x1, "EPWM1_CH0"),
 		MA35_MUX(0x4, "I2C3_SDA"),
@@ -1237,25 +1306,27 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xa, "EBI_ADR15"),
 		MA35_MUX(0xb, "TM8"),
 		MA35_MUX(0xc, "QEI1_INDEX")),
-	MA35_PIN(163, PK9, 0xd4, 0x4,
+	MA35_PIN(169, PK9, 0xd4, 0x4,
 		MA35_MUX(0x0, "GPK9"),
 		MA35_MUX(0x4, "I2C3_SCL"),
 		MA35_MUX(0x6, "CCAP0_SCLK"),
 		MA35_MUX(0x8, "EBI_AD0"),
 		MA35_MUX(0xa, "EBI_ADR0")),
-	MA35_PIN(164, PK10, 0xd4, 0x8,
+	MA35_PIN(170, PK10, 0xd4, 0x8,
 		MA35_MUX(0x0, "GPK10"),
 		MA35_MUX(0x3, "CAN1_RXD"),
+		MA35_MUX(0x4, "USBHL3_DM"),
 		MA35_MUX(0x6, "CCAP0_PIXCLK"),
 		MA35_MUX(0x8, "EBI_AD1"),
 		MA35_MUX(0xa, "EBI_ADR1")),
-	MA35_PIN(165, PK11, 0xd4, 0xc,
+	MA35_PIN(171, PK11, 0xd4, 0xc,
 		MA35_MUX(0x0, "GPK11"),
 		MA35_MUX(0x3, "CAN1_TXD"),
+		MA35_MUX(0x4, "USBHL3_DP"),
 		MA35_MUX(0x6, "CCAP0_HSYNC"),
 		MA35_MUX(0x8, "EBI_AD2"),
 		MA35_MUX(0xa, "EBI_ADR2")),
-	MA35_PIN(166, PK12, 0xd4, 0x10,
+	MA35_PIN(172, PK12, 0xd4, 0x10,
 		MA35_MUX(0x0, "GPK12"),
 		MA35_MUX(0x1, "EPWM2_CH0"),
 		MA35_MUX(0x2, "UART1_nCTS"),
@@ -1266,7 +1337,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "SC0_CLK"),
 		MA35_MUX(0xb, "TM10"),
 		MA35_MUX(0xd, "INT2")),
-	MA35_PIN(167, PK13, 0xd4, 0x14,
+	MA35_PIN(173, PK13, 0xd4, 0x14,
 		MA35_MUX(0x0, "GPK13"),
 		MA35_MUX(0x1, "EPWM2_CH1"),
 		MA35_MUX(0x2, "UART1_nRTS"),
@@ -1276,28 +1347,30 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x6, "SPI1_CLK"),
 		MA35_MUX(0x8, "SC0_DAT"),
 		MA35_MUX(0xb, "TM10_EXT")),
-	MA35_PIN(168, PK14, 0xd4, 0x18,
+	MA35_PIN(174, PK14, 0xd4, 0x18,
 		MA35_MUX(0x0, "GPK14"),
 		MA35_MUX(0x1, "EPWM2_CH2"),
 		MA35_MUX(0x2, "UART1_RXD"),
 		MA35_MUX(0x3, "CAN3_RXD"),
+		MA35_MUX(0x4, "USBHL4_DM"),
 		MA35_MUX(0x5, "I2S0_DI"),
 		MA35_MUX(0x6, "SPI1_MOSI"),
 		MA35_MUX(0x8, "SC0_RST"),
 		MA35_MUX(0xa, "I2C5_SDA"),
 		MA35_MUX(0xb, "TM11"),
 		MA35_MUX(0xd, "INT3")),
-	MA35_PIN(169, PK15, 0xd4, 0x1c,
+	MA35_PIN(175, PK15, 0xd4, 0x1c,
 		MA35_MUX(0x0, "GPK15"),
 		MA35_MUX(0x1, "EPWM2_CH3"),
 		MA35_MUX(0x2, "UART1_TXD"),
 		MA35_MUX(0x3, "CAN3_TXD"),
+		MA35_MUX(0x4, "USBHL4_DP"),
 		MA35_MUX(0x5, "I2S0_DO"),
 		MA35_MUX(0x6, "SPI1_MISO"),
 		MA35_MUX(0x8, "SC0_PWR"),
 		MA35_MUX(0xa, "I2C5_SCL"),
 		MA35_MUX(0xb, "TM11_EXT")),
-	MA35_PIN(170, PL0, 0xd8, 0x0,
+	MA35_PIN(176, PL0, 0xd8, 0x0,
 		MA35_MUX(0x0, "GPL0"),
 		MA35_MUX(0x1, "EPWM1_CH0"),
 		MA35_MUX(0x2, "UART11_nCTS"),
@@ -1310,7 +1383,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "SC1_CLK"),
 		MA35_MUX(0xb, "TM5"),
 		MA35_MUX(0xc, "QEI1_A")),
-	MA35_PIN(171, PL1, 0xd8, 0x4,
+	MA35_PIN(177, PL1, 0xd8, 0x4,
 		MA35_MUX(0x0, "GPL1"),
 		MA35_MUX(0x1, "EPWM1_CH1"),
 		MA35_MUX(0x2, "UART11_nRTS"),
@@ -1323,11 +1396,12 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "SC1_DAT"),
 		MA35_MUX(0xb, "TM5_EXT"),
 		MA35_MUX(0xc, "QEI1_B")),
-	MA35_PIN(172, PL2, 0xd8, 0x8,
+	MA35_PIN(178, PL2, 0xd8, 0x8,
 		MA35_MUX(0x0, "GPL2"),
 		MA35_MUX(0x1, "EPWM1_CH2"),
 		MA35_MUX(0x2, "UART11_RXD"),
 		MA35_MUX(0x3, "CAN3_RXD"),
+		MA35_MUX(0x4, "USBHL4_DM"),
 		MA35_MUX(0x5, "SPI2_SS0"),
 		MA35_MUX(0x6, "QSPI1_SS1"),
 		MA35_MUX(0x7, "I2S0_DI"),
@@ -1335,11 +1409,12 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "SC1_RST"),
 		MA35_MUX(0xb, "TM7"),
 		MA35_MUX(0xc, "QEI1_INDEX")),
-	MA35_PIN(173, PL3, 0xd8, 0xc,
+	MA35_PIN(179, PL3, 0xd8, 0xc,
 		MA35_MUX(0x0, "GPL3"),
 		MA35_MUX(0x1, "EPWM1_CH3"),
 		MA35_MUX(0x2, "UART11_TXD"),
 		MA35_MUX(0x3, "CAN3_TXD"),
+		MA35_MUX(0x4, "USBHL4_DP"),
 		MA35_MUX(0x5, "SPI2_CLK"),
 		MA35_MUX(0x6, "QSPI1_CLK"),
 		MA35_MUX(0x7, "I2S0_DO"),
@@ -1347,7 +1422,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "SC1_PWR"),
 		MA35_MUX(0xb, "TM7_EXT"),
 		MA35_MUX(0xc, "ECAP0_IC0")),
-	MA35_PIN(174, PL4, 0xd8, 0x10,
+	MA35_PIN(180, PL4, 0xd8, 0x10,
 		MA35_MUX(0x0, "GPL4"),
 		MA35_MUX(0x1, "EPWM1_CH4"),
 		MA35_MUX(0x2, "UART2_nCTS"),
@@ -1360,7 +1435,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "SC1_nCD"),
 		MA35_MUX(0xb, "TM9"),
 		MA35_MUX(0xc, "ECAP0_IC1")),
-	MA35_PIN(175, PL5, 0xd8, 0x14,
+	MA35_PIN(181, PL5, 0xd8, 0x14,
 		MA35_MUX(0x0, "GPL5"),
 		MA35_MUX(0x1, "EPWM1_CH5"),
 		MA35_MUX(0x2, "UART2_nRTS"),
@@ -1373,28 +1448,30 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "SC0_nCD"),
 		MA35_MUX(0xb, "TM9_EXT"),
 		MA35_MUX(0xc, "ECAP0_IC2")),
-	MA35_PIN(176, PL6, 0xd8, 0x18,
+	MA35_PIN(182, PL6, 0xd8, 0x18,
 		MA35_MUX(0x0, "GPL6"),
 		MA35_MUX(0x1, "EPWM0_CH0"),
 		MA35_MUX(0x2, "UART2_RXD"),
 		MA35_MUX(0x3, "CAN0_RXD"),
+		MA35_MUX(0x4, "USBHL5_DM"),
 		MA35_MUX(0x6, "QSPI1_MOSI1"),
 		MA35_MUX(0x7, "TRACE_CLK"),
 		MA35_MUX(0x8, "EBI_AD5"),
 		MA35_MUX(0xb, "TM3"),
 		MA35_MUX(0xc, "ECAP1_IC0"),
 		MA35_MUX(0xd, "INT0")),
-	MA35_PIN(177, PL7, 0xd8, 0x1c,
+	MA35_PIN(183, PL7, 0xd8, 0x1c,
 		MA35_MUX(0x0, "GPL7"),
 		MA35_MUX(0x1, "EPWM0_CH1"),
 		MA35_MUX(0x2, "UART2_TXD"),
 		MA35_MUX(0x3, "CAN0_TXD"),
+		MA35_MUX(0x4, "USBHL5_DP"),
 		MA35_MUX(0x6, "QSPI1_MISO1"),
 		MA35_MUX(0x8, "EBI_AD6"),
 		MA35_MUX(0xb, "TM3_EXT"),
 		MA35_MUX(0xc, "ECAP1_IC1"),
 		MA35_MUX(0xd, "INT1")),
-	MA35_PIN(178, PL8, 0xdc, 0x0,
+	MA35_PIN(184, PL8, 0xdc, 0x0,
 		MA35_MUX(0x0, "GPL8"),
 		MA35_MUX(0x1, "EPWM0_CH2"),
 		MA35_MUX(0x2, "UART14_nCTS"),
@@ -1408,7 +1485,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xb, "TM4"),
 		MA35_MUX(0xc, "ECAP1_IC2"),
 		MA35_MUX(0xd, "INT2")),
-	MA35_PIN(179, PL9, 0xdc, 0x4,
+	MA35_PIN(185, PL9, 0xdc, 0x4,
 		MA35_MUX(0x0, "GPL9"),
 		MA35_MUX(0x1, "EPWM0_CH3"),
 		MA35_MUX(0x2, "UART14_nRTS"),
@@ -1422,11 +1499,12 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xb, "TM4_EXT"),
 		MA35_MUX(0xc, "QEI0_A"),
 		MA35_MUX(0xd, "INT3")),
-	MA35_PIN(180, PL10, 0xdc, 0x8,
+	MA35_PIN(186, PL10, 0xdc, 0x8,
 		MA35_MUX(0x0, "GPL10"),
 		MA35_MUX(0x1, "EPWM0_CH4"),
 		MA35_MUX(0x2, "UART14_RXD"),
 		MA35_MUX(0x3, "CAN3_RXD"),
+		MA35_MUX(0x4, "USBHL2_DM"),
 		MA35_MUX(0x5, "SPI3_MOSI"),
 		MA35_MUX(0x6, "EPWM0_CH5"),
 		MA35_MUX(0x7, "I2S1_DI"),
@@ -1434,11 +1512,12 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "SC0_RST"),
 		MA35_MUX(0xb, "EBI_nWRH"),
 		MA35_MUX(0xc, "QEI0_B")),
-	MA35_PIN(181, PL11, 0xdc, 0xc,
+	MA35_PIN(187, PL11, 0xdc, 0xc,
 		MA35_MUX(0x0, "GPL11"),
 		MA35_MUX(0x1, "EPWM0_CH5"),
 		MA35_MUX(0x2, "UART14_TXD"),
 		MA35_MUX(0x3, "CAN3_TXD"),
+		MA35_MUX(0x4, "USBHL2_DP"),
 		MA35_MUX(0x5, "SPI3_MISO"),
 		MA35_MUX(0x6, "EPWM1_CH5"),
 		MA35_MUX(0x7, "I2S1_DO"),
@@ -1446,7 +1525,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x9, "SC0_PWR"),
 		MA35_MUX(0xb, "EBI_nWRL"),
 		MA35_MUX(0xc, "QEI0_INDEX")),
-	MA35_PIN(182, PL12, 0xdc, 0x10,
+	MA35_PIN(188, PL12, 0xdc, 0x10,
 		MA35_MUX(0x0, "GPL12"),
 		MA35_MUX(0x1, "EPWM0_SYNC_IN"),
 		MA35_MUX(0x2, "UART7_nCTS"),
@@ -1463,7 +1542,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xd, "EBI_AD11"),
 		MA35_MUX(0xe, "RGMII0_PPS"),
 		MA35_MUX(0xf, "RMII0_PPS")),
-	MA35_PIN(183, PL13, 0xdc, 0x14,
+	MA35_PIN(189, PL13, 0xdc, 0x14,
 		MA35_MUX(0x0, "GPL13"),
 		MA35_MUX(0x1, "EPWM0_SYNC_OUT"),
 		MA35_MUX(0x2, "UART7_nRTS"),
@@ -1480,7 +1559,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xd, "EBI_AD12"),
 		MA35_MUX(0xe, "RGMII1_PPS"),
 		MA35_MUX(0xf, "RMII1_PPS")),
-	MA35_PIN(184, PL14, 0xdc, 0x18,
+	MA35_PIN(190, PL14, 0xdc, 0x18,
 		MA35_MUX(0x0, "GPL14"),
 		MA35_MUX(0x1, "EPWM0_CH2"),
 		MA35_MUX(0x2, "UART7_RXD"),
@@ -1492,7 +1571,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xb, "TM2"),
 		MA35_MUX(0xc, "INT0"),
 		MA35_MUX(0xd, "EBI_AD13")),
-	MA35_PIN(185, PL15, 0xdc, 0x1c,
+	MA35_PIN(191, PL15, 0xdc, 0x1c,
 		MA35_MUX(0x0, "GPL15"),
 		MA35_MUX(0x1, "EPWM0_CH1"),
 		MA35_MUX(0x2, "UART7_TXD"),
@@ -1505,86 +1584,92 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0xb, "TM2_EXT"),
 		MA35_MUX(0xc, "INT2"),
 		MA35_MUX(0xd, "EBI_AD14")),
-	MA35_PIN(186, PM0, 0xe0, 0x0,
+	MA35_PIN(192, PM0, 0xe0, 0x0,
 		MA35_MUX(0x0, "GPM0"),
 		MA35_MUX(0x4, "I2C4_SDA"),
 		MA35_MUX(0x6, "CCAP0_VSYNC"),
 		MA35_MUX(0x8, "EBI_AD3"),
 		MA35_MUX(0xa, "EBI_ADR3")),
-	MA35_PIN(187, PM1, 0xe0, 0x4,
+	MA35_PIN(193, PM1, 0xe0, 0x4,
 		MA35_MUX(0x0, "GPM1"),
 		MA35_MUX(0x4, "I2C4_SCL"),
 		MA35_MUX(0x5, "SPI3_I2SMCLK"),
 		MA35_MUX(0x6, "CCAP0_SFIELD"),
 		MA35_MUX(0x8, "EBI_AD4"),
 		MA35_MUX(0xa, "EBI_ADR4")),
-	MA35_PIN(188, PM2, 0xe0, 0x8,
+	MA35_PIN(194, PM2, 0xe0, 0x8,
 		MA35_MUX(0x0, "GPM2"),
 		MA35_MUX(0x3, "CAN3_RXD"),
+		MA35_MUX(0x4, "USBHL0_DM"),
 		MA35_MUX(0x6, "CCAP0_DATA0"),
 		MA35_MUX(0x8, "EBI_AD5"),
 		MA35_MUX(0xa, "EBI_ADR5")),
-	MA35_PIN(189, PM3, 0xe0, 0xc,
+	MA35_PIN(195, PM3, 0xe0, 0xc,
 		MA35_MUX(0x0, "GPM3"),
 		MA35_MUX(0x3, "CAN3_TXD"),
+		MA35_MUX(0x4, "USBHL0_DP"),
 		MA35_MUX(0x6, "CCAP0_DATA1"),
 		MA35_MUX(0x8, "EBI_AD6"),
 		MA35_MUX(0xa, "EBI_ADR6")),
-	MA35_PIN(190, PM4, 0xe0, 0x10,
+	MA35_PIN(196, PM4, 0xe0, 0x10,
 		MA35_MUX(0x0, "GPM4"),
 		MA35_MUX(0x4, "I2C5_SDA"),
 		MA35_MUX(0x6, "CCAP0_DATA2"),
 		MA35_MUX(0x8, "EBI_AD7"),
 		MA35_MUX(0xa, "EBI_ADR7")),
-	MA35_PIN(191, PM5, 0xe0, 0x14,
+	MA35_PIN(197, PM5, 0xe0, 0x14,
 		MA35_MUX(0x0, "GPM5"),
 		MA35_MUX(0x4, "I2C5_SCL"),
 		MA35_MUX(0x6, "CCAP0_DATA3"),
 		MA35_MUX(0x8, "EBI_AD8"),
 		MA35_MUX(0xa, "EBI_ADR8")),
-	MA35_PIN(192, PM6, 0xe0, 0x18,
+	MA35_PIN(198, PM6, 0xe0, 0x18,
 		MA35_MUX(0x0, "GPM6"),
 		MA35_MUX(0x3, "CAN0_RXD"),
+		MA35_MUX(0x4, "USBHL1_DM"),
 		MA35_MUX(0x6, "CCAP0_DATA4"),
 		MA35_MUX(0x8, "EBI_AD9"),
 		MA35_MUX(0xa, "EBI_ADR9")),
-	MA35_PIN(193, PM7, 0xe0, 0x1c,
+	MA35_PIN(199, PM7, 0xe0, 0x1c,
 		MA35_MUX(0x0, "GPM7"),
 		MA35_MUX(0x3, "CAN0_TXD"),
+		MA35_MUX(0x4, "USBHL1_DP"),
 		MA35_MUX(0x6, "CCAP0_DATA5"),
 		MA35_MUX(0x8, "EBI_AD10"),
 		MA35_MUX(0xa, "EBI_ADR10")),
-	MA35_PIN(194, PM8, 0xe4, 0x0,
+	MA35_PIN(200, PM8, 0xe4, 0x0,
 		MA35_MUX(0x0, "GPM8"),
 		MA35_MUX(0x4, "I2C0_SDA"),
 		MA35_MUX(0x6, "CCAP0_DATA6"),
 		MA35_MUX(0x8, "EBI_AD11"),
 		MA35_MUX(0xa, "EBI_ADR11")),
-	MA35_PIN(195, PM9, 0xe4, 0x4,
+	MA35_PIN(201, PM9, 0xe4, 0x4,
 		MA35_MUX(0x0, "GPM9"),
 		MA35_MUX(0x4, "I2C0_SCL"),
 		MA35_MUX(0x6, "CCAP0_DATA7"),
 		MA35_MUX(0x8, "EBI_AD12"),
 		MA35_MUX(0xa, "EBI_ADR12")),
-	MA35_PIN(196, PM10, 0xe4, 0x8,
+	MA35_PIN(202, PM10, 0xe4, 0x8,
 		MA35_MUX(0x0, "GPM10"),
 		MA35_MUX(0x1, "EPWM1_CH2"),
 		MA35_MUX(0x3, "CAN2_RXD"),
+		MA35_MUX(0x4, "USBHL4_DM"),
 		MA35_MUX(0x5, "SPI3_SS0"),
 		MA35_MUX(0x6, "CCAP0_DATA8"),
 		MA35_MUX(0x7, "SPI2_I2SMCLK"),
 		MA35_MUX(0x8, "EBI_AD13"),
 		MA35_MUX(0xa, "EBI_ADR13")),
-	MA35_PIN(197, PM11, 0xe4, 0xc,
+	MA35_PIN(203, PM11, 0xe4, 0xc,
 		MA35_MUX(0x0, "GPM11"),
 		MA35_MUX(0x1, "EPWM1_CH3"),
 		MA35_MUX(0x3, "CAN2_TXD"),
+		MA35_MUX(0x4, "USBHL4_DP"),
 		MA35_MUX(0x5, "SPI3_SS1"),
 		MA35_MUX(0x6, "CCAP0_DATA9"),
 		MA35_MUX(0x7, "SPI2_SS1"),
 		MA35_MUX(0x8, "EBI_AD14"),
 		MA35_MUX(0xa, "EBI_ADR14")),
-	MA35_PIN(198, PM12, 0xe4, 0x10,
+	MA35_PIN(204, PM12, 0xe4, 0x10,
 		MA35_MUX(0x0, "GPM12"),
 		MA35_MUX(0x1, "EPWM1_CH4"),
 		MA35_MUX(0x2, "UART10_nCTS"),
@@ -1595,7 +1680,7 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "EBI_AD8"),
 		MA35_MUX(0x9, "I2S1_MCLK"),
 		MA35_MUX(0xb, "TM8")),
-	MA35_PIN(199, PM13, 0xe4, 0x14,
+	MA35_PIN(205, PM13, 0xe4, 0x14,
 		MA35_MUX(0x0, "GPM13"),
 		MA35_MUX(0x1, "EPWM1_CH5"),
 		MA35_MUX(0x2, "UART10_nRTS"),
@@ -1605,99 +1690,66 @@ static const struct pinctrl_pin_desc ma35d1_pins[] = {
 		MA35_MUX(0x8, "EBI_AD9"),
 		MA35_MUX(0x9, "ECAP1_IC0"),
 		MA35_MUX(0xb, "TM8_EXT")),
-	MA35_PIN(200, PM14, 0xe4, 0x18,
+	MA35_PIN(206, PM14, 0xe4, 0x18,
 		MA35_MUX(0x0, "GPM14"),
 		MA35_MUX(0x1, "EPWM1_BRAKE0"),
 		MA35_MUX(0x2, "UART10_RXD"),
 		MA35_MUX(0x3, "TRACE_DATA2"),
 		MA35_MUX(0x4, "CAN2_RXD"),
+		MA35_MUX(0x5, "USBHL3_DM"),
 		MA35_MUX(0x6, "I2C3_SDA"),
 		MA35_MUX(0x8, "EBI_AD10"),
 		MA35_MUX(0x9, "ECAP1_IC1"),
 		MA35_MUX(0xb, "TM10"),
 		MA35_MUX(0xd, "INT1")),
-	MA35_PIN(201, PM15, 0xe4, 0x1c,
+	MA35_PIN(207, PM15, 0xe4, 0x1c,
 		MA35_MUX(0x0, "GPM15"),
 		MA35_MUX(0x1, "EPWM1_BRAKE1"),
 		MA35_MUX(0x2, "UART10_TXD"),
 		MA35_MUX(0x3, "TRACE_DATA3"),
 		MA35_MUX(0x4, "CAN2_TXD"),
+		MA35_MUX(0x5, "USBHL3_DP"),
 		MA35_MUX(0x6, "I2C3_SCL"),
 		MA35_MUX(0x8, "EBI_AD11"),
 		MA35_MUX(0x9, "ECAP1_IC2"),
 		MA35_MUX(0xb, "TM10_EXT"),
 		MA35_MUX(0xd, "INT2")),
-	MA35_PIN(202, PN0, 0xe8, 0x0,
+	MA35_PIN(208, PN0, 0xe8, 0x0,
 		MA35_MUX(0x0, "GPN0"),
 		MA35_MUX(0x4, "I2C2_SDA"),
 		MA35_MUX(0x6, "CCAP1_DATA0")),
-	MA35_PIN(203, PN1, 0xe8, 0x4,
+	MA35_PIN(209, PN1, 0xe8, 0x4,
 		MA35_MUX(0x0, "GPN1"),
 		MA35_MUX(0x4, "I2C2_SCL"),
 		MA35_MUX(0x6, "CCAP1_DATA1")),
-	MA35_PIN(204, PN2, 0xe8, 0x8,
+	MA35_PIN(210, PN2, 0xe8, 0x8,
 		MA35_MUX(0x0, "GPN2"),
 		MA35_MUX(0x3, "CAN0_RXD"),
+		MA35_MUX(0x4, "USBHL0_DM"),
 		MA35_MUX(0x6, "CCAP1_DATA2")),
-	MA35_PIN(205, PN3, 0xe8, 0xc,
+	MA35_PIN(211, PN3, 0xe8, 0xc,
 		MA35_MUX(0x0, "GPN3"),
 		MA35_MUX(0x3, "CAN0_TXD"),
+		MA35_MUX(0x4, "USBHL0_DP"),
 		MA35_MUX(0x6, "CCAP1_DATA3")),
-	MA35_PIN(206, PN4, 0xe8, 0x10,
+	MA35_PIN(212, PN4, 0xe8, 0x10,
 		MA35_MUX(0x0, "GPN4"),
 		MA35_MUX(0x4, "I2C1_SDA"),
 		MA35_MUX(0x6, "CCAP1_DATA4")),
-	MA35_PIN(207, PN5, 0xe8, 0x14,
+	MA35_PIN(213, PN5, 0xe8, 0x14,
 		MA35_MUX(0x0, "GPN5"),
 		MA35_MUX(0x4, "I2C1_SCL"),
 		MA35_MUX(0x6, "CCAP1_DATA5")),
-	MA35_PIN(208, PN6, 0xe8, 0x18,
+	MA35_PIN(214, PN6, 0xe8, 0x18,
 		MA35_MUX(0x0, "GPN6"),
 		MA35_MUX(0x3, "CAN1_RXD"),
+		MA35_MUX(0x4, "USBHL1_DM"),
 		MA35_MUX(0x6, "CCAP1_DATA6")),
-	MA35_PIN(209, PN7, 0xe8, 0x1c,
+	MA35_PIN(215, PN7, 0xe8, 0x1c,
 		MA35_MUX(0x0, "GPN7"),
 		MA35_MUX(0x3, "CAN1_TXD"),
+		MA35_MUX(0x4, "USBHL1_DP"),
 		MA35_MUX(0x6, "CCAP1_DATA7")),
-	MA35_PIN(210, PN10, 0xec, 0x8,
-		MA35_MUX(0x0, "GPN10"),
-		MA35_MUX(0x3, "CAN2_RXD"),
-		MA35_MUX(0x6, "CCAP1_SCLK")),
-	MA35_PIN(211, PN11, 0xec, 0xc,
-		MA35_MUX(0x0, "GPN11"),
-		MA35_MUX(0x3, "CAN2_TXD"),
-		MA35_MUX(0x6, "CCAP1_PIXCLK")),
-	MA35_PIN(212, PN12, 0xec, 0x10,
-		MA35_MUX(0x0, "GPN12"),
-		MA35_MUX(0x2, "UART6_nCTS"),
-		MA35_MUX(0x3, "UART12_RXD"),
-		MA35_MUX(0x4, "I2C5_SDA"),
-		MA35_MUX(0x6, "CCAP1_HSYNC")),
-	MA35_PIN(213, PN13, 0xec, 0x14,
-		MA35_MUX(0x0, "GPN13"),
-		MA35_MUX(0x2, "UART6_nRTS"),
-		MA35_MUX(0x3, "UART12_TXD"),
-		MA35_MUX(0x4, "I2C5_SCL"),
-		MA35_MUX(0x6, "CCAP1_VSYNC")),
-	MA35_PIN(214, PN14, 0xec, 0x18,
-		MA35_MUX(0x0, "GPN14"),
-		MA35_MUX(0x2, "UART6_RXD"),
-		MA35_MUX(0x3, "CAN3_RXD"),
-		MA35_MUX(0x5, "SPI1_SS1"),
-		MA35_MUX(0x6, "CCAP1_SFIELD"),
-		MA35_MUX(0x7, "SPI1_I2SMCLK")),
-	MA35_PIN(215, PN15, 0xec, 0x1c,
-		MA35_MUX(0x0, "GPN15"),
-		MA35_MUX(0x1, "EPWM2_CH4"),
-		MA35_MUX(0x2, "UART6_TXD"),
-		MA35_MUX(0x3, "CAN3_TXD"),
-		MA35_MUX(0x5, "I2S0_MCLK"),
-		MA35_MUX(0x6, "SPI1_SS1"),
-		MA35_MUX(0x7, "SPI1_I2SMCLK"),
-		MA35_MUX(0x8, "SC0_nCD"),
-		MA35_MUX(0x9, "EADC0_ST"),
-		MA35_MUX(0xa, "CLKO"),
-		MA35_MUX(0xb, "TM6")),
 	MA35_PIN(216, PN8, 0xec, 0x0,
 		MA35_MUX(0x0, "GPN8"),
 		MA35_MUX(0x1, "EPWM2_CH4"),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0328/2077] pinctrl: cs42l43: Fix leaked pm reference on error path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (326 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0327/2077] pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0329/2077] pinctrl: cs42l43: Fix polarity on debounce Greg Kroah-Hartman
                   ` (669 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Charles Keepax, Bartosz Golaszewski,
	Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Charles Keepax <ckeepax@opensource.cirrus.com>

[ Upstream commit 1cb73b83ab6dec8159d0280345a46fbb282c378f ]

Returning directly if the regmap_update_bits() fails causes a pm runtime
reference to be leaked, let things run to the end of the function
instead.

Fixes: e52c741907fb ("pinctrl: cirrus: cs42l43: use new GPIO line value setter callbacks")
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/cirrus/pinctrl-cs42l43.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/drivers/pinctrl/cirrus/pinctrl-cs42l43.c b/drivers/pinctrl/cirrus/pinctrl-cs42l43.c
index 227c37c360e19a..3cc18352060770 100644
--- a/drivers/pinctrl/cirrus/pinctrl-cs42l43.c
+++ b/drivers/pinctrl/cirrus/pinctrl-cs42l43.c
@@ -499,12 +499,10 @@ static int cs42l43_gpio_set(struct gpio_chip *chip, unsigned int offset,
 
 	ret = regmap_update_bits(priv->regmap, CS42L43_GPIO_CTRL1,
 				 BIT(shift), value << shift);
-	if (ret)
-		return ret;
 
 	pm_runtime_put(priv->dev);
 
-	return 0;
+	return ret;
 }
 
 static int cs42l43_gpio_direction_out(struct gpio_chip *chip,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0329/2077] pinctrl: cs42l43: Fix polarity on debounce
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (327 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0328/2077] pinctrl: cs42l43: Fix leaked pm reference on error path Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0330/2077] init/initramfs_test: wait_for_initramfs() before running Greg Kroah-Hartman
                   ` (668 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Charles Keepax, Bartosz Golaszewski,
	Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Charles Keepax <ckeepax@opensource.cirrus.com>

[ Upstream commit 9da52ee80aee3ab3c69208bd1cfbb4be01371214 ]

The debounce bit sets a bypass on the debounce rather than enabling it,
as such the current polarity of the debounce is set incorrectly. Invert
the polarity to correct this.

Fixes: d5282a539297 ("pinctrl: cs42l43: Add support for the cs42l43")
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/cirrus/pinctrl-cs42l43.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pinctrl/cirrus/pinctrl-cs42l43.c b/drivers/pinctrl/cirrus/pinctrl-cs42l43.c
index 3cc18352060770..305233fc198762 100644
--- a/drivers/pinctrl/cirrus/pinctrl-cs42l43.c
+++ b/drivers/pinctrl/cirrus/pinctrl-cs42l43.c
@@ -343,7 +343,7 @@ static int cs42l43_pin_set_db(struct cs42l43_pin *priv, unsigned int pin,
 
 	return regmap_update_bits(priv->regmap, CS42L43_GPIO_CTRL2,
 				  CS42L43_GPIO1_DEGLITCH_BYP_MASK << pin,
-				  !!us << pin);
+				  !us << pin);
 }
 
 static int cs42l43_pin_config_get(struct pinctrl_dev *pctldev,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0330/2077] init/initramfs_test: wait_for_initramfs() before running
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (328 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0329/2077] pinctrl: cs42l43: Fix polarity on debounce Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0331/2077] nvmet-tcp: fix page fragment cache leak in error path Greg Kroah-Hartman
                   ` (667 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jia He, David Disseldorp,
	Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jia He <justin.he@arm.com>

[ Upstream commit ec3f4e0443a61e68092ac07111f16dd4ca89ddb4 ]

initramfs_test_extract() and friends call unpack_to_rootfs() from a
kunit kthread while do_populate_rootfs() may still be running
asynchronously from rootfs_initcall. unpack_to_rootfs() keeps its
parser state in module-static variables (victim, byte_count, state,
this_header, header_buf, name_buf, ...), so the two writers corrupt
each other.

On arm64 v7.0-rc5+ this oopses early in boot:

  Unable to handle kernel paging request at virtual address ffff80018f9f0ffc
  pc : do_reset+0x3c/0x98
  Call trace:
   do_reset
   initramfs_test_extract
   kunit_try_run_case
  Initramfs unpacking failed: junk within compressed archive

do_reset() faults because 'victim' was overwritten by the boot-time
unpacker; the boot unpacker meanwhile logs the bogus "junk within
compressed archive" on the real initrd because the test wrecked its
state machine.

Add a .suite_init callback that calls wait_for_initramfs() so the async
unpack is quiescent before the first case runs. suite_init runs once per
suite rather than before every individual test case.

Fixes: 83c0b27266ec ("initramfs_test: kunit tests for initramfs unpacking")
Signed-off-by: Jia He <justin.he@arm.com>
Link: https://patch.msgid.link/20260519093937.1064628-1-justin.he@arm.com
Reviewed-by: David Disseldorp <ddiss@suse.de>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 init/initramfs_test.c | 17 ++++++++++++++++-
 1 file changed, 16 insertions(+), 1 deletion(-)

diff --git a/init/initramfs_test.c b/init/initramfs_test.c
index 2ce38d9a8fd0fa..a4c06ec3436899 100644
--- a/init/initramfs_test.c
+++ b/init/initramfs_test.c
@@ -3,7 +3,9 @@
 #include <linux/fcntl.h>
 #include <linux/file.h>
 #include <linux/fs.h>
+#include <linux/init.h>
 #include <linux/init_syscalls.h>
+#include <linux/initrd.h>
 #include <linux/stringify.h>
 #include <linux/timekeeping.h>
 #include "initramfs_internal.h"
@@ -510,8 +512,21 @@ static struct kunit_case __refdata initramfs_test_cases[] = {
 	{},
 };
 
-static struct kunit_suite initramfs_test_suite = {
+static int __init initramfs_test_init(struct kunit_suite *suite)
+{
+	/*
+	 * unpack_to_rootfs() uses module-static state (victim, byte_count,
+	 * state, ...). The boot-time async do_populate_rootfs() may still be
+	 * running, so wait for it to finish before we call unpack_to_rootfs()
+	 * from the test thread, otherwise the two writers race and crash.
+	 */
+	wait_for_initramfs();
+	return 0;
+}
+
+static struct kunit_suite __refdata initramfs_test_suite = {
 	.name = "initramfs",
+	.suite_init = initramfs_test_init,
 	.test_cases = initramfs_test_cases,
 };
 kunit_test_init_section_suites(&initramfs_test_suite);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0331/2077] nvmet-tcp: fix page fragment cache leak in error path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (329 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0330/2077] init/initramfs_test: wait_for_initramfs() before running Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0332/2077] nvmet-tcp: check return value of nvmet_tcp_set_queue_sock Greg Kroah-Hartman
                   ` (666 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Geliang Tang,
	Keith Busch, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Geliang Tang <tanggeliang@kylinos.cn>

[ Upstream commit 4dae393956093c807212918fd91a8fc70df15338 ]

In nvmet_tcp_alloc_queue(), when a connection is closed during the
allocation process (e.g., nvmet_tcp_set_queue_sock() returns -ENOTCONN),
the error handling jumps to out_destroy_sq and then to out_ida_remove
without draining the page fragment cache.

Although nvmet_tcp_free_cmd() is called in some error paths to release
individual page fragments, the underlying page cache reference held by
queue->pf_cache is never released. The first allocation using pf_cache
is the call to nvmet_tcp_alloc_cmd() for queue->connect, which happens
after ida_alloc() returns successfully. This results in a page leak each
time a connection fails during allocation, which could lead to memory
exhaustion over time if connections are repeatedly opened and closed.

Fix this by calling page_frag_cache_drain() before freeing the queue
structure in the out_ida_remove label.

Fixes: 872d26a391da ("nvmet-tcp: add NVMe over TCP target driver")
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Geliang Tang <tanggeliang@kylinos.cn>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/nvme/target/tcp.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/nvme/target/tcp.c b/drivers/nvme/target/tcp.c
index 20f150d17a9625..57a6da696fa0b0 100644
--- a/drivers/nvme/target/tcp.c
+++ b/drivers/nvme/target/tcp.c
@@ -1999,6 +1999,12 @@ static void nvmet_tcp_alloc_queue(struct nvmet_tcp_port *port,
 	nvmet_tcp_free_cmd(&queue->connect);
 out_ida_remove:
 	ida_free(&nvmet_tcp_queue_ida, queue->idx);
+	/*
+	 * Drain the page fragment cache if any allocations were done.
+	 * The first allocation using pf_cache is nvmet_tcp_alloc_cmd()
+	 * for queue->connect after ida_alloc().
+	 */
+	page_frag_cache_drain(&queue->pf_cache);
 out_sock:
 	fput(queue->sock->file);
 out_free_queue:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0332/2077] nvmet-tcp: check return value of nvmet_tcp_set_queue_sock
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (330 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0331/2077] nvmet-tcp: fix page fragment cache leak in error path Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0333/2077] nvme-multipath: fix flex array size in struct nvme_ns_head Greg Kroah-Hartman
                   ` (665 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hannes Reinecke, Chaitanya Kulkarni,
	Geliang Tang, Keith Busch, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Geliang Tang <tanggeliang@kylinos.cn>

[ Upstream commit 7ef789703e2b91775dcb36b2efa46325be31a2a0 ]

The return value of nvmet_tcp_set_queue_sock() is currently ignored in
nvmet_tcp_tls_handshake_done(). If it fails (e.g., due to the socket
not being in TCP_ESTABLISHED state), the socket callbacks will not be
properly set, leading to queue and socket leakage.

Fix this by capturing the return value and calling
nvmet_tcp_schedule_release_queue() on failure to ensure proper cleanup.

Fixes: 675b453e0241 ("nvmet-tcp: enable TLS handshake upcall")
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Reviewed-by: Chaitanya Kulkarni <kch@nvidia.com>
Signed-off-by: Geliang Tang <tanggeliang@kylinos.cn>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/nvme/target/tcp.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/nvme/target/tcp.c b/drivers/nvme/target/tcp.c
index 57a6da696fa0b0..15c52f1f95f1b0 100644
--- a/drivers/nvme/target/tcp.c
+++ b/drivers/nvme/target/tcp.c
@@ -1844,10 +1844,11 @@ static void nvmet_tcp_tls_handshake_done(void *data, int status,
 	if (!status)
 		status = nvmet_tcp_tls_key_lookup(queue, peerid);
 
+	if (!status)
+		status = nvmet_tcp_set_queue_sock(queue);
+
 	if (status)
 		nvmet_tcp_schedule_release_queue(queue);
-	else
-		nvmet_tcp_set_queue_sock(queue);
 	kref_put(&queue->kref, nvmet_tcp_release_queue);
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0333/2077] nvme-multipath: fix flex array size in struct nvme_ns_head
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (331 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0332/2077] nvmet-tcp: check return value of nvmet_tcp_set_queue_sock Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0334/2077] nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools Greg Kroah-Hartman
                   ` (664 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mukesh Kumar Chaurasiya (IBM),
	Hannes Reinecke, John Garry, Christoph Hellwig, Nilay Shroff,
	Keith Busch, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilay Shroff <nilay@linux.ibm.com>

[ Upstream commit 001e57554de81aa79c25c18fd53911d8a415c304 ]

struct nvme_ns_head contains a flexible array member, current_path[],
which is indexed using the NUMA node ID:
head->current_path[numa_node_id()]

The structure is currently allocated as:
size = sizeof(struct nvme_ns_head) +
       (num_possible_nodes() * sizeof(struct nvme_ns *));
head = kzalloc(size, GFP_KERNEL);

This allocation assumes that NUMA node IDs are sequential and densely
packed from 0 .. num_possible_nodes() - 1. While this assumption holds
on many systems, it is not always true on some architectures such as
powerpc.

On some powerpc systems, NUMA node IDs can be sparse. For example:
NUMA:
  NUMA node(s):              6
  NUMA node0 CPU(s):         80-159
  NUMA node8 CPU(s):         0-79
  NUMA node252 CPU(s):
  NUMA node253 CPU(s):
  NUMA node254 CPU(s):
  NUMA node255 CPU(s):

That is, the possible/online NUMA node IDs are: 0, 8, 252, 253, 254, 255
In this case: num_possible_nodes() = 6

So memory is allocated for only 6 entries in current_path[]. However,
the array is later indexed using the actual NUMA node ID. As a result,
accesses such as:
head->current_path[8] or
head->current_path[252]
goes out of bounds, leading to the following KASAN splat:

==================================================================
BUG: KASAN: slab-out-of-bounds in nvme_mpath_revalidate_paths+0x22c/0x290 [nvme_core]
Write of size 8 at addr c00020003bda35b8 by task kworker/u641:2/1997

CPU: 1 UID: 0 PID: 1997 Comm: kworker/u641:2 Not tainted 7.1.0-rc5-dirty #14 PREEMPT(lazy)
Hardware name: 8335-GTH POWER9 0x4e1202 opal:skiboot-v6.5.3-35-g1851b2a06 PowerNV
Workqueue: async async_run_entry_fn
Call Trace:
[c000200037fa7510] [c0000000021c23d4] dump_stack_lvl+0x88/0xdc (unreliable)
[c000200037fa7540] [c0000000009fda90] print_report+0x22c/0x67c
[c000200037fa7630] [c0000000009fd508] kasan_report+0x108/0x220
[c000200037fa7740] [c0000000009fff48] __asan_store8+0xe8/0x120
[c000200037fa7760] [c008000018e76474] nvme_mpath_revalidate_paths+0x22c/0x290 [nvme_core]
[c000200037fa7800] [c008000018e6556c] nvme_update_ns_info+0x4a4/0x5e0 [nvme_core]
[c000200037fa7a50] [c008000018e66270] nvme_alloc_ns+0x6d8/0x1a70 [nvme_core]
[c000200037fa7c20] [c008000018e679fc] nvme_scan_ns+0x3f4/0x630 [nvme_core]
[c000200037fa7d10] [c00000000031f22c] async_run_entry_fn+0x9c/0x3a0
[c000200037fa7db0] [c0000000002fa544] process_one_work+0x414/0xa10
[c000200037fa7ec0] [c0000000002fbf00] worker_thread+0x320/0x640
[c000200037fa7f80] [c00000000030d0f8] kthread+0x278/0x290
[c000200037fa7fe0] [c00000000000ded8] start_kernel_thread+0x14/0x18

Allocated by task 1997 on cpu 1 at 35.928317s:

The buggy address belongs to the object at c00020003bda3000
 which belongs to the cache kmalloc-rnd-15-2k of size 2048
The buggy address is located 16 bytes to the right of
 allocated 1448-byte region [c00020003bda3000, c00020003bda35a8)

The buggy address belongs to the physical page:

Memory state around the buggy address:
 c00020003bda3480: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
 c00020003bda3500: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>c00020003bda3580: 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc fc
                                        ^
 c00020003bda3600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
 c00020003bda3680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
==================================================================

Fix this by allocating the flexible array using nr_node_ids instead
of num_possible_nodes(). Since nr_node_ids represents the maximum
possible NUMA node IDs, indexing current_path[] using numa_node_id()
becomes safe even on systems with sparse node IDs.

Fixes: f333444708f8 ("nvme: take node locality into account when selecting a path")
Tested-by: Mukesh Kumar Chaurasiya (IBM) <mkchauras@gmail.com>
Reviewed-by: Mukesh Kumar Chaurasiya (IBM) <mkchauras@gmail.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Nilay Shroff <nilay@linux.ibm.com>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/nvme/host/core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/nvme/host/core.c b/drivers/nvme/host/core.c
index c3032d6ad6b1e2..96809227a0e229 100644
--- a/drivers/nvme/host/core.c
+++ b/drivers/nvme/host/core.c
@@ -3926,7 +3926,7 @@ static struct nvme_ns_head *nvme_alloc_ns_head(struct nvme_ctrl *ctrl,
 	int ret = -ENOMEM;
 
 #ifdef CONFIG_NVME_MULTIPATH
-	size += num_possible_nodes() * sizeof(struct nvme_ns *);
+	size += nr_node_ids * sizeof(struct nvme_ns *);
 #endif
 
 	head = kzalloc(size, GFP_KERNEL);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0334/2077] nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (332 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0333/2077] nvme-multipath: fix flex array size in struct nvme_ns_head Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0335/2077] workqueue: drop spurious * from print_worker_info() fn declaration Greg Kroah-Hartman
                   ` (663 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sung-woo Kim, Christoph Hellwig,
	Mateusz Nowicki, Keith Busch, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mateusz Nowicki <mateusz.nowicki@posteo.net>

[ Upstream commit a192b8cfa447e1b3701a13434a31c392b2e7ed29 ]

nvme_setup_descriptor_pools() indexes dev->descriptor_pools[] using the
numa_node forwarded from hctx->numa_node by its single caller,
nvme_init_hctx_common().  On a non-NUMA kernel hctx->numa_node is
NUMA_NO_NODE (-1).  Because the parameter was declared 'unsigned', the
value becomes UINT_MAX and the index walks off the array (sized to
nr_node_ids), faulting during nvme_alloc_ns() and leaving the namespace
without a /dev node.

Reproduces on any NVMe controller probed by a CONFIG_NUMA=n kernel:

  BUG: unable to handle page fault for address: ffff889101603d38
  RIP: 0010:nvme_init_hctx_common+0x5a/0x190 [nvme]
  Call Trace:
   nvme_init_hctx+0x10/0x20 [nvme]
   nvme_alloc_ns+0x9e/0xa10 [nvme_core]
   nvme_scan_ns+0x301/0x3b0 [nvme_core]
   nvme_scan_ns_async+0x23/0x30 [nvme_core]

Switch the parameter to int and fall back to node 0 when it is
NUMA_NO_NODE; node 0 is always present.

Fixes: d977506f8863 ("nvme-pci: make PRP list DMA pools per-NUMA-node")
Link: https://lore.kernel.org/r/20260309062840.2937858-2-iam@sung-woo.kim
Reported-by: Sung-woo Kim <iam@sung-woo.kim>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Mateusz Nowicki <mateusz.nowicki@posteo.net>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/nvme/host/pci.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/nvme/host/pci.c b/drivers/nvme/host/pci.c
index b5f84620067899..0de6844ca56c0c 100644
--- a/drivers/nvme/host/pci.c
+++ b/drivers/nvme/host/pci.c
@@ -587,11 +587,16 @@ static bool nvme_dbbuf_update_and_check_event(u16 value, __le32 *dbbuf_db,
 }
 
 static struct nvme_descriptor_pools *
-nvme_setup_descriptor_pools(struct nvme_dev *dev, unsigned numa_node)
+nvme_setup_descriptor_pools(struct nvme_dev *dev, int numa_node)
 {
-	struct nvme_descriptor_pools *pools = &dev->descriptor_pools[numa_node];
+	struct nvme_descriptor_pools *pools;
 	size_t small_align = NVME_SMALL_POOL_SIZE;
 
+	if (numa_node == NUMA_NO_NODE)
+		numa_node = 0;
+
+	pools = &dev->descriptor_pools[numa_node];
+
 	if (pools->small)
 		return pools; /* already initialized */
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0335/2077] workqueue: drop spurious * from print_worker_info() fn declaration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (333 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0334/2077] nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0336/2077] ipv6: guard against possible NULL deref in __in6_dev_stats_get() Greg Kroah-Hartman
                   ` (662 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Breno Leitao, Tejun Heo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Breno Leitao <leitao@debian.org>

[ Upstream commit 611583a76ea97991b0f65ec1ff099eac7fe0bae4 ]

print_worker_info() declares its local 'fn' as work_func_t * but
worker->current_func has type work_func_t (a function pointer). The
extra level of indirection is wrong and only happens to be harmless
today because every supported Linux architecture has
sizeof(work_func_t) == sizeof(work_func_t *):
copy_from_kernel_nofault() reads the correct number of bytes by
accident, and %ps still resolves the printed address because the
stored value is the function address regardless of declared type.

On any future ABI where sizeof(void (*)()) differs from
sizeof(void *), the nofault copy would transfer the wrong number of
bytes and the subsequent %ps would print an incorrect address.

Match the field type so the intent is explicit and the code does not
silently rely on equal pointer sizes.

Fixes: 3d1cb2059d93 ("workqueue: include workqueue info when printing debug dump of a worker task")
Signed-off-by: Breno Leitao <leitao@debian.org>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/workqueue.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/workqueue.c b/kernel/workqueue.c
index 33b721a9af0223..bd79b3b5ca878f 100644
--- a/kernel/workqueue.c
+++ b/kernel/workqueue.c
@@ -6310,7 +6310,7 @@ EXPORT_SYMBOL_GPL(set_worker_desc);
  */
 void print_worker_info(const char *log_lvl, struct task_struct *task)
 {
-	work_func_t *fn = NULL;
+	work_func_t fn = NULL;
 	char name[WQ_NAME_LEN] = { };
 	char desc[WORKER_DESC_LEN] = { };
 	struct pool_workqueue *pwq = NULL;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0336/2077] ipv6: guard against possible NULL deref in __in6_dev_stats_get()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (334 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0335/2077] workqueue: drop spurious * from print_worker_info() fn declaration Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0337/2077] net/sched: cls_bpf: prevent unbounded recursion in offload rollback Greg Kroah-Hartman
                   ` (661 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Stephen Suryaputra,
	Ido Schimmel, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 507541c2a8eeb76c02bd2511958f73a8cfa3e1bc ]

dev_get_by_index_rcu() could return NULL if the original physical
device is unregistered.

Found by Sashiko.

Fixes: e1ae5c2ea478 ("vrf: Increment Icmp6InMsgs on the original netdev")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Stephen Suryaputra <ssuryaextr@gmail.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260526145529.3587126-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/net/addrconf.h | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/include/net/addrconf.h b/include/net/addrconf.h
index 9e96776945e5f6..539bbbe54b14e8 100644
--- a/include/net/addrconf.h
+++ b/include/net/addrconf.h
@@ -369,8 +369,11 @@ static inline struct inet6_dev *__in6_dev_get_rtnl_net(const struct net_device *
 static inline struct inet6_dev *__in6_dev_stats_get(const struct net_device *dev,
 						    const struct sk_buff *skb)
 {
-	if (netif_is_l3_master(dev))
+	if (netif_is_l3_master(dev)) {
 		dev = dev_get_by_index_rcu(dev_net(dev), inet6_iif(skb));
+		if (!dev)
+			return NULL;
+	}
 	return __in6_dev_get(dev);
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0337/2077] net/sched: cls_bpf: prevent unbounded recursion in offload rollback
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (335 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0336/2077] ipv6: guard against possible NULL deref in __in6_dev_stats_get() Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0338/2077] iommu/amd: Fix premature break in init_iommu_one() Greg Kroah-Hartman
                   ` (660 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jakub Kicinski, Jiayuan Chen,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiayuan Chen <jiayuan.chen@linux.dev>

[ Upstream commit 27db54b90bcc7c37867fe664107fa25ea6a116e4 ]

Quan Sun reported [1] a stack overflow in cls_bpf_offload_cmd().

Reproducer on netdevsim: add a skip_sw cls_bpf filter, set the
bpf_tc_accept debugfs knob to 0, then `tc filter replace`. The replace
calls tc_setup_cb_replace() which fails. cls_bpf_offload_cmd() then
swaps prog/oldprog and recursively calls itself to roll back. But
bpf_tc_accept=0 makes the rollback fail too, which triggers yet another
rollback frame with the same arguments, and so on until the stack is
exhausted.

bpf_tc_accept is just a convenient knob for the reproducer. Any driver
whose tc_setup_cb_replace() fails twice in a row can hit the same loop,
so this is not a netdevsim-only issue.

Two ways to fix it:

  1) Have the rollback call tc_setup_cb_add() on oldprog instead of
     re-entering cls_bpf_offload_cmd().
  2) Mark the rollback frame with a flag and skip a second-level
     rollback from inside it.

Go with (2). It is the smaller change and keeps the original behaviour:
the rollback still goes through tc_setup_cb_replace(), so the driver
gets one real chance to restore its state. If that attempt also fails,
we just return the original error instead of recursing.

[1]: https://lore.kernel.org/bpf/ce5a6005-3c5e-4696-9e05-eba9461dc860@std.uestc.edu.cn/T/#u

Fixes: 102740bd9436 ("cls_bpf: fix offload assumptions after callback conversion")
Reviewed-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://patch.msgid.link/20260526025529.24382-1-jiayuan.chen@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/cls_bpf.c | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/net/sched/cls_bpf.c b/net/sched/cls_bpf.c
index 9a346b6221b359..001d8c4ebfedc1 100644
--- a/net/sched/cls_bpf.c
+++ b/net/sched/cls_bpf.c
@@ -142,7 +142,8 @@ static bool cls_bpf_is_ebpf(const struct cls_bpf_prog *prog)
 
 static int cls_bpf_offload_cmd(struct tcf_proto *tp, struct cls_bpf_prog *prog,
 			       struct cls_bpf_prog *oldprog,
-			       struct netlink_ext_ack *extack)
+			       struct netlink_ext_ack *extack,
+			       bool is_rollback)
 {
 	struct tcf_block *block = tp->chain->block;
 	struct tc_cls_bpf_offload cls_bpf = {};
@@ -177,7 +178,8 @@ static int cls_bpf_offload_cmd(struct tcf_proto *tp, struct cls_bpf_prog *prog,
 					  &oldprog->in_hw_count, true);
 
 	if (prog && err) {
-		cls_bpf_offload_cmd(tp, oldprog, prog, extack);
+		if (!is_rollback)
+			cls_bpf_offload_cmd(tp, oldprog, prog, extack, true);
 		return err;
 	}
 
@@ -208,7 +210,7 @@ static int cls_bpf_offload(struct tcf_proto *tp, struct cls_bpf_prog *prog,
 	if (!prog && !oldprog)
 		return 0;
 
-	return cls_bpf_offload_cmd(tp, prog, oldprog, extack);
+	return cls_bpf_offload_cmd(tp, prog, oldprog, extack, false);
 }
 
 static void cls_bpf_stop_offload(struct tcf_proto *tp,
@@ -217,7 +219,7 @@ static void cls_bpf_stop_offload(struct tcf_proto *tp,
 {
 	int err;
 
-	err = cls_bpf_offload_cmd(tp, NULL, prog, extack);
+	err = cls_bpf_offload_cmd(tp, NULL, prog, extack, false);
 	if (err)
 		pr_err("Stopping hardware offload failed: %d\n", err);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0338/2077] iommu/amd: Fix premature break in init_iommu_one()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (336 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0337/2077] net/sched: cls_bpf: prevent unbounded recursion in offload rollback Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0339/2077] ALSA: hda/realtek:ALC269 fixup for Yoga Pro 7 15ASH11 mic mute LED Greg Kroah-Hartman
                   ` (659 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sudheer Dantuluri,
	Dheeraj Kumar Srivastava, Vasant Hegde, Joerg Roedel, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vasant Hegde <vasant.hegde@amd.com>

[ Upstream commit 283d245468a2b61c41aa8b582f25ed5615d1c304 ]

In init_iommu_one(), when processing IOMMU EFR attributes, the code checks
whether GASUP is enabled. If GASUP is not enabled, the code falls back to
legacy guest IR mode and then breaks out of the switch statement.

This break incorrectly skips the subsequent initialization steps that
follow the GASUP check. These initializations are independent of GASUP
support and must always be performed.

Fix this by replacing the early break with a conditional else block,
ensuring that the XTSUP check is only skipped when GASUP is not available.

Fixes: a44092e326d4 ("iommu/amd: Use IVHD EFR for early initialization of IOMMU features")
Reported-by: Sudheer Dantuluri <dantuluris@google.com>
Tested-by: Dheeraj Kumar Srivastava <dheerajkumar.srivastava@amd.com>
Signed-off-by: Vasant Hegde <vasant.hegde@amd.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iommu/amd/init.c | 7 +++----
 1 file changed, 3 insertions(+), 4 deletions(-)

diff --git a/drivers/iommu/amd/init.c b/drivers/iommu/amd/init.c
index 3bdb380d23e9a9..9a846dcd030638 100644
--- a/drivers/iommu/amd/init.c
+++ b/drivers/iommu/amd/init.c
@@ -1939,12 +1939,11 @@ static int __init init_iommu_one(struct amd_iommu *iommu, struct ivhd_header *h,
 		/* XT and GAM require GA mode. */
 		if ((h->efr_reg & (0x1 << IOMMU_EFR_GASUP_SHIFT)) == 0) {
 			amd_iommu_guest_ir = AMD_IOMMU_GUEST_IR_LEGACY;
-			break;
+		} else {
+			if (h->efr_reg & BIT(IOMMU_EFR_XTSUP_SHIFT))
+				amd_iommu_xt_mode = IRQ_REMAP_X2APIC_MODE;
 		}
 
-		if (h->efr_reg & BIT(IOMMU_EFR_XTSUP_SHIFT))
-			amd_iommu_xt_mode = IRQ_REMAP_X2APIC_MODE;
-
 		if (h->efr_attr & BIT(IOMMU_IVHD_ATTR_HATDIS_SHIFT)) {
 			pr_warn_once("Host Address Translation is not supported.\n");
 			amd_iommu_hatdis = true;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0339/2077] ALSA: hda/realtek:ALC269 fixup for Yoga Pro 7 15ASH11 mic mute LED
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (337 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0338/2077] iommu/amd: Fix premature break in init_iommu_one() Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0340/2077] dt-bindings: vendor-prefixes: Add Verbatim Corporation Greg Kroah-Hartman
                   ` (658 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jackie Dong, Takashi Iwai,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jackie Dong <xy-jackie@139.com>

[ Upstream commit 17065203e1bc7e7f2786998d532cd93a06265156 ]

Lenovo Yoga Pro 7 15ASH11 with AMD RYZEN AI MAX+ 388 (Strix Halo, ACP
7.0) uses Realtek ALC287 series codec. The ALC269_FIXUP_LENOVO_XPAD_ACPI
in alc269_fixup_vendor_tbl[] can load lenovo_wmi_hotkey_utilities module
by default in this laptop, but the driver doesn't control mic mute LED.

If users run below command and the mic mute LED can work normally.

$sudo echo 'Capture Switch' >/sys/class/sound/ctl-led/mic/card1/attach

After added the SND_PCI_QUIRK quirk special for Lenovo Yoga Pro 7
15ASH11, the mic mute LED works well.

Fixes: 83dca2530fb3 ("ALSA: hda/realtek: ALC269 fixup for Lenovo Yoga Pro 7 15ASH111 audio")
Signed-off-by: Jackie Dong <xy-jackie@139.com>
Link: https://patch.msgid.link/20260527130353.5658-1-xy-jackie@139.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/hda/codecs/realtek/alc269.c |   10 +++++++++-
 1 file changed, 9 insertions(+), 1 deletion(-)

--- a/sound/hda/codecs/realtek/alc269.c
+++ b/sound/hda/codecs/realtek/alc269.c
@@ -4076,6 +4076,7 @@ enum {
 	ALC287_FIXUP_YOGA7_14ITL_SPEAKERS,
 	ALC298_FIXUP_LENOVO_C940_DUET7,
 	ALC287_FIXUP_LENOVO_YOGA_BOOK_9I,
+	ALC287_FIXUP_LENOVO_YOGA_PRO7,
 	ALC287_FIXUP_13S_GEN2_SPEAKERS,
 	ALC256_FIXUP_SET_COEF_DEFAULTS,
 	ALC256_FIXUP_SYSTEM76_MIC_NO_PRESENCE,
@@ -6101,6 +6102,13 @@ static const struct hda_fixup alc269_fix
 		.chained = true,
 		.chain_id = ALC285_FIXUP_THINKPAD_HEADSET_JACK,
 	},
+	[ALC287_FIXUP_LENOVO_YOGA_PRO7] = {
+		.type = HDA_FIXUP_FUNC,
+		/* Reuse the DAC routing selected for ThinkPad X1 Gen7 */
+		.v.func = alc285_fixup_thinkpad_x1_gen7,
+		.chained = true,
+		.chain_id = ALC269_FIXUP_LENOVO_XPAD_ACPI,
+	},
 	[ALC623_FIXUP_LENOVO_THINKSTATION_P340] = {
 		.type = HDA_FIXUP_FUNC,
 		.v.func = alc_fixup_no_shutup,
@@ -7771,7 +7779,7 @@ static const struct hda_quirk alc269_fix
 	SND_PCI_QUIRK(0x17aa, 0x38df, "Y990 YG DUAL", ALC287_FIXUP_TAS2781_I2C),
 	SND_PCI_QUIRK(0x17aa, 0x38f9, "Thinkbook 16P Gen5", ALC287_FIXUP_MG_RTKC_CSAMP_CS35L41_I2C_THINKPAD),
 	SND_PCI_QUIRK(0x17aa, 0x38fa, "Thinkbook 16P Gen5", ALC287_FIXUP_MG_RTKC_CSAMP_CS35L41_I2C_THINKPAD),
-	SND_PCI_QUIRK(0x17aa, 0x38fc, "Lenovo Yoga Pro 7 15ASH11", ALC245_FIXUP_BASS_HP_DAC),
+	SND_PCI_QUIRK(0x17aa, 0x38fc, "Lenovo Yoga Pro 7 15ASH11", ALC287_FIXUP_LENOVO_YOGA_PRO7),
 	SND_PCI_QUIRK(0x17aa, 0x38fd, "ThinkBook plus Gen5 Hybrid", ALC287_FIXUP_TAS2781_I2C),
 	SND_PCI_QUIRK(0x17aa, 0x3902, "Lenovo E50-80", ALC269_FIXUP_DMIC_THINKPAD_ACPI),
 	SND_PCI_QUIRK(0x17aa, 0x390d, "Lenovo Yoga Pro 7 14ASP10", ALC287_FIXUP_YOGA9_14IAP7_BASS_SPK_PIN),



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0340/2077] dt-bindings: vendor-prefixes: Add Verbatim Corporation
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (338 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0339/2077] ALSA: hda/realtek:ALC269 fixup for Yoga Pro 7 15ASH11 mic mute LED Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0341/2077] rtla/actions: Restore continue flag in actions_perform() Greg Kroah-Hartman
                   ` (657 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Linus Walleij,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Linus Walleij <linusw@kernel.org>

[ Upstream commit 4b8c63c6a2811c23995c5d8cc8bb63d26caab299 ]

Verbatim Corporation has manufactured a few electronics items
over the years.

Link: https://en.wikipedia.org/wiki/Verbatim_(company)
Acked-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/devicetree/bindings/vendor-prefixes.yaml | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/Documentation/devicetree/bindings/vendor-prefixes.yaml b/Documentation/devicetree/bindings/vendor-prefixes.yaml
index 11c55b5df0e4ca..ac83310259a914 100644
--- a/Documentation/devicetree/bindings/vendor-prefixes.yaml
+++ b/Documentation/devicetree/bindings/vendor-prefixes.yaml
@@ -1785,6 +1785,8 @@ patternProperties:
     description: Variscite Ltd.
   "^vdl,.*":
     description: Van der Laan b.v.
+  "^verbatim,.*":
+    description: Verbatim Corporation
   "^verisilicon,.*":
     description: VeriSilicon Microelectronics (Shanghai) Co., Ltd.
   "^vertexcom,.*":
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0341/2077] rtla/actions: Restore continue flag in actions_perform()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (339 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0340/2077] dt-bindings: vendor-prefixes: Add Verbatim Corporation Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0342/2077] drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered Greg Kroah-Hartman
                   ` (656 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Tomas Glozar, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tomas Glozar <tglozar@redhat.com>

[ Upstream commit dd520daffbc901f10d49a51a58313547d417b506 ]

Currently, actions_perform() only ever sets the continue flag (when
performing the continue action), but never resets it. That leads to
RTLA continuing tracing even if the continue action was not performed in
the current iteration.

For example, the following command:

$ rtla timerlat hist -T 100 --on-threshold shell,command='
    echo Spike!
    if [ -f /tmp/a ]
    then
      exit 1
    else
      touch /tmp/a
    fi' --on-threshold continue

should print Spike! at most once, because after hitting the threshold
for the first time, /tmp/a exists, the shell action will fail, and the
continue action is not performed. However, unless /tmp/a exists before
the measurement, it will print Spike! until stopped, as the continue
flag stays set.

Set the continue flag to false in the beginning of actions_perform() to
make RTLA continue only if the action was actually performed.

Fixes: 8d933d5c89e8 ("rtla/timerlat: Add continue action")
Link: https://lore.kernel.org/r/20260526102523.2662391-1-tglozar@redhat.com
[ correct Fixes tag to include 12 characters of hash ]
Signed-off-by: Tomas Glozar <tglozar@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/tracing/rtla/src/actions.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/tools/tracing/rtla/src/actions.c b/tools/tracing/rtla/src/actions.c
index b0d68b5de08db2..bf13d9d68f1694 100644
--- a/tools/tracing/rtla/src/actions.c
+++ b/tools/tracing/rtla/src/actions.c
@@ -247,6 +247,8 @@ actions_perform(struct actions *self)
 	int pid, retval;
 	const struct action *action;
 
+	self->continue_flag = false;
+
 	for_each_action(self, action) {
 		switch (action->type) {
 		case ACTION_TRACE_OUTPUT:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0342/2077] drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (340 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0341/2077] rtla/actions: Restore continue flag in actions_perform() Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0343/2077] drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove Greg Kroah-Hartman
                   ` (655 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikko Perttunen, Svyatoslav Ryhel,
	Thierry Reding, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Svyatoslav Ryhel <clamor95@gmail.com>

[ Upstream commit c4ef5ba1131346159e31f4ef858525cf377380a6 ]

The host1x_client_register() function is called just prior to register map
initialization loop, making the device available to userspace. This may
result in userspace attempting to submits a job before the register map is
initialized. Address this by moving register initialization before host1x
client registration.

Acked-by: Mikko Perttunen <mperttunen@nvidia.com>
Signed-off-by: Svyatoslav Ryhel <clamor95@gmail.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260517091450.46728-2-clamor95@gmail.com
Stable-dep-of: ace01e2af387 ("drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/tegra/gr2d.c | 8 ++++----
 drivers/gpu/drm/tegra/gr3d.c | 8 ++++----
 2 files changed, 8 insertions(+), 8 deletions(-)

diff --git a/drivers/gpu/drm/tegra/gr2d.c b/drivers/gpu/drm/tegra/gr2d.c
index 21f4dd0fa6aff7..e4148b034af745 100644
--- a/drivers/gpu/drm/tegra/gr2d.c
+++ b/drivers/gpu/drm/tegra/gr2d.c
@@ -276,16 +276,16 @@ static int gr2d_probe(struct platform_device *pdev)
 	if (err)
 		return err;
 
+	/* initialize address register map */
+	for (i = 0; i < ARRAY_SIZE(gr2d_addr_regs); i++)
+		set_bit(gr2d_addr_regs[i], gr2d->addr_regs);
+
 	err = host1x_client_register(&gr2d->client.base);
 	if (err < 0) {
 		dev_err(dev, "failed to register host1x client: %d\n", err);
 		return err;
 	}
 
-	/* initialize address register map */
-	for (i = 0; i < ARRAY_SIZE(gr2d_addr_regs); i++)
-		set_bit(gr2d_addr_regs[i], gr2d->addr_regs);
-
 	return 0;
 }
 
diff --git a/drivers/gpu/drm/tegra/gr3d.c b/drivers/gpu/drm/tegra/gr3d.c
index 42e9656ab80c91..47b0c6c56bfd08 100644
--- a/drivers/gpu/drm/tegra/gr3d.c
+++ b/drivers/gpu/drm/tegra/gr3d.c
@@ -506,6 +506,10 @@ static int gr3d_probe(struct platform_device *pdev)
 	if (err)
 		return err;
 
+	/* initialize address register map */
+	for (i = 0; i < ARRAY_SIZE(gr3d_addr_regs); i++)
+		set_bit(gr3d_addr_regs[i], gr3d->addr_regs);
+
 	err = host1x_client_register(&gr3d->client.base);
 	if (err < 0) {
 		dev_err(&pdev->dev, "failed to register host1x client: %d\n",
@@ -513,10 +517,6 @@ static int gr3d_probe(struct platform_device *pdev)
 		return err;
 	}
 
-	/* initialize address register map */
-	for (i = 0; i < ARRAY_SIZE(gr3d_addr_regs); i++)
-		set_bit(gr3d_addr_regs[i], gr3d->addr_regs);
-
 	return 0;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0343/2077] drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (341 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0342/2077] drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0344/2077] gpu: host1x: Allow entries in BO caches to be freed Greg Kroah-Hartman
                   ` (654 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikko Perttunen, Ion Agorria,
	Svyatoslav Ryhel, Thierry Reding, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ion Agorria <ion@agorria.com>

[ Upstream commit ace01e2af3871343d700fb60c6f64d8f8e3180e1 ]

The current power management configuration causes GR2G/GR3D to malfunction
after resume. Reconfigure all PM actions to be handled within the GR*D
probe and remove operations to address this.

Fixes: 62fa0a985e2c ("drm/tegra: Enable runtime PM during probe")
Acked-by: Mikko Perttunen <mperttunen@nvidia.com>
Signed-off-by: Ion Agorria <ion@agorria.com>
Signed-off-by: Svyatoslav Ryhel <clamor95@gmail.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260517091450.46728-3-clamor95@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/tegra/gr2d.c | 13 ++++++-------
 drivers/gpu/drm/tegra/gr3d.c | 13 ++++++-------
 2 files changed, 12 insertions(+), 14 deletions(-)

diff --git a/drivers/gpu/drm/tegra/gr2d.c b/drivers/gpu/drm/tegra/gr2d.c
index e4148b034af745..892e3450b281e4 100644
--- a/drivers/gpu/drm/tegra/gr2d.c
+++ b/drivers/gpu/drm/tegra/gr2d.c
@@ -100,9 +100,6 @@ static int gr2d_exit(struct host1x_client *client)
 	if (err < 0)
 		return err;
 
-	pm_runtime_dont_use_autosuspend(client->dev);
-	pm_runtime_force_suspend(client->dev);
-
 	host1x_client_iommu_detach(client);
 	host1x_syncpt_put(client->syncpts[0]);
 	host1x_channel_put(gr2d->channel);
@@ -280,12 +277,18 @@ static int gr2d_probe(struct platform_device *pdev)
 	for (i = 0; i < ARRAY_SIZE(gr2d_addr_regs); i++)
 		set_bit(gr2d_addr_regs[i], gr2d->addr_regs);
 
+	pm_runtime_enable(dev);
+
 	err = host1x_client_register(&gr2d->client.base);
 	if (err < 0) {
+		pm_runtime_disable(dev);
 		dev_err(dev, "failed to register host1x client: %d\n", err);
 		return err;
 	}
 
+	pm_runtime_use_autosuspend(dev);
+	pm_runtime_set_autosuspend_delay(dev, 500);
+
 	return 0;
 }
 
@@ -367,10 +370,6 @@ static int __maybe_unused gr2d_runtime_resume(struct device *dev)
 		goto disable_clk;
 	}
 
-	pm_runtime_enable(dev);
-	pm_runtime_use_autosuspend(dev);
-	pm_runtime_set_autosuspend_delay(dev, 500);
-
 	return 0;
 
 disable_clk:
diff --git a/drivers/gpu/drm/tegra/gr3d.c b/drivers/gpu/drm/tegra/gr3d.c
index 47b0c6c56bfd08..388e47943d5ec6 100644
--- a/drivers/gpu/drm/tegra/gr3d.c
+++ b/drivers/gpu/drm/tegra/gr3d.c
@@ -109,9 +109,6 @@ static int gr3d_exit(struct host1x_client *client)
 	if (err < 0)
 		return err;
 
-	pm_runtime_dont_use_autosuspend(client->dev);
-	pm_runtime_force_suspend(client->dev);
-
 	host1x_client_iommu_detach(client);
 	host1x_syncpt_put(client->syncpts[0]);
 	host1x_channel_put(gr3d->channel);
@@ -510,13 +507,19 @@ static int gr3d_probe(struct platform_device *pdev)
 	for (i = 0; i < ARRAY_SIZE(gr3d_addr_regs); i++)
 		set_bit(gr3d_addr_regs[i], gr3d->addr_regs);
 
+	pm_runtime_enable(&pdev->dev);
+
 	err = host1x_client_register(&gr3d->client.base);
 	if (err < 0) {
+		pm_runtime_disable(&pdev->dev);
 		dev_err(&pdev->dev, "failed to register host1x client: %d\n",
 			err);
 		return err;
 	}
 
+	pm_runtime_use_autosuspend(&pdev->dev);
+	pm_runtime_set_autosuspend_delay(&pdev->dev, 500);
+
 	return 0;
 }
 
@@ -578,10 +581,6 @@ static int __maybe_unused gr3d_runtime_resume(struct device *dev)
 		goto disable_clk;
 	}
 
-	pm_runtime_enable(dev);
-	pm_runtime_use_autosuspend(dev);
-	pm_runtime_set_autosuspend_delay(dev, 500);
-
 	return 0;
 
 disable_clk:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0344/2077] gpu: host1x: Allow entries in BO caches to be freed
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (342 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0343/2077] drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0345/2077] drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info Greg Kroah-Hartman
                   ` (653 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Aaron Kling, Mikko Perttunen,
	Thierry Reding, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikko Perttunen <mperttunen@nvidia.com>

[ Upstream commit 3cbf5e3c46e66d9b3b6b91099bb720c6cb1be3bc ]

When a buffer object is pinned via host1x_bo_pin() with a cache, the
resulting mapping is kept in the cache so it can be reused on subsequent
pins. Each mapping held a reference to the underlying host1x_bo (taken
in tegra_bo_pin / gather_bo_pin), so as long as a mapping was cached,
the bo itself could not be freed.

However, the only way to remove the cached mapping was through the free
path of the buffer object. This meant that if a bo got cached, it could
never get freed again.

Resolve the circularity by holding a weak reference to the bo from the
cache side. This is done by having the .pin callbacks not bump the bo's
refcount -- instead the common Host1x bo code does so, except for the
cache reference.

Also move the remove-cache-mapping-on-free code into a common function
inside Host1x code. This is only called from the TegraDRM GEM buffers
since those are the only ones that can be cached at the moment.

Reported-by: Aaron Kling <webgeek1234@gmail.com>
Fixes: 1f39b1dfa53c ("drm/tegra: Implement buffer object cache")
Signed-off-by: Mikko Perttunen <mperttunen@nvidia.com>
Tested-by: Aaron Kling <webgeek1234@gmail.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260515-host1x-bocache-leak-v1-1-a0375f68aeab@nvidia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/tegra/gem.c    | 13 ++------
 drivers/gpu/drm/tegra/submit.c |  3 +-
 drivers/gpu/host1x/bus.c       | 60 +++++++++++++++++++++++++++++++++-
 include/linux/host1x.h         |  7 ++++
 4 files changed, 69 insertions(+), 14 deletions(-)

diff --git a/drivers/gpu/drm/tegra/gem.c b/drivers/gpu/drm/tegra/gem.c
index d2bae88ad545f4..2377e2b76397a3 100644
--- a/drivers/gpu/drm/tegra/gem.c
+++ b/drivers/gpu/drm/tegra/gem.c
@@ -69,7 +69,7 @@ static struct host1x_bo_mapping *tegra_bo_pin(struct device *dev, struct host1x_
 		return ERR_PTR(-ENOMEM);
 
 	kref_init(&map->ref);
-	map->bo = host1x_bo_get(bo);
+	map->bo = bo;
 	map->direction = direction;
 	map->dev = dev;
 
@@ -170,7 +170,6 @@ static void tegra_bo_unpin(struct host1x_bo_mapping *map)
 		kfree(map->sgt);
 	}
 
-	host1x_bo_put(map->bo);
 	kfree(map);
 }
 
@@ -509,17 +508,9 @@ static struct tegra_bo *tegra_bo_import(struct drm_device *drm,
 void tegra_bo_free_object(struct drm_gem_object *gem)
 {
 	struct tegra_drm *tegra = gem->dev->dev_private;
-	struct host1x_bo_mapping *mapping, *tmp;
 	struct tegra_bo *bo = to_tegra_bo(gem);
 
-	/* remove all mappings of this buffer object from any caches */
-	list_for_each_entry_safe(mapping, tmp, &bo->base.mappings, list) {
-		if (mapping->cache)
-			host1x_bo_unpin(mapping);
-		else
-			dev_err(gem->dev->dev, "mapping %p stale for device %s\n", mapping,
-				dev_name(mapping->dev));
-	}
+	host1x_bo_clear_cached_mappings(&bo->base);
 
 	if (tegra->domain) {
 		tegra_bo_iommu_unmap(tegra, bo);
diff --git a/drivers/gpu/drm/tegra/submit.c b/drivers/gpu/drm/tegra/submit.c
index 3009b8b9e61977..e5841857c9378f 100644
--- a/drivers/gpu/drm/tegra/submit.c
+++ b/drivers/gpu/drm/tegra/submit.c
@@ -76,7 +76,7 @@ gather_bo_pin(struct device *dev, struct host1x_bo *bo, enum dma_data_direction
 		return ERR_PTR(-ENOMEM);
 
 	kref_init(&map->ref);
-	map->bo = host1x_bo_get(bo);
+	map->bo = bo;
 	map->direction = direction;
 	map->dev = dev;
 
@@ -117,7 +117,6 @@ static void gather_bo_unpin(struct host1x_bo_mapping *map)
 	dma_unmap_sgtable(map->dev, map->sgt, map->direction, 0);
 	sg_free_table(map->sgt);
 	kfree(map->sgt);
-	host1x_bo_put(map->bo);
 
 	kfree(map);
 }
diff --git a/drivers/gpu/host1x/bus.c b/drivers/gpu/host1x/bus.c
index f814eb4941c02e..772e05a7b45b3a 100644
--- a/drivers/gpu/host1x/bus.c
+++ b/drivers/gpu/host1x/bus.c
@@ -887,6 +887,20 @@ int host1x_client_resume(struct host1x_client *client)
 }
 EXPORT_SYMBOL(host1x_client_resume);
 
+/**
+ * host1x_bo_pin() - Create a DMA mapping for the buffer object
+ * @dev: Device onto which DMA map to
+ * @bo: Buffer object to map
+ * @dir: DMA direction
+ * @cache: Cache in which to store mapping, or NULL
+ *
+ * Creates a DMA mapping pointing to @bo for @dev. The refcount of @bo is incremented
+ * until host1x_bo_unpin is called.
+ *
+ * If @cache is specified, the mapping is also stored in the cache and not released
+ * until @bo is freed (refcount drops to zero). This improves performance when a buffer
+ * is pinned and unpinned frequently as in the case of display use.
+ */
 struct host1x_bo_mapping *host1x_bo_pin(struct device *dev, struct host1x_bo *bo,
 					enum dma_data_direction dir,
 					struct host1x_bo_cache *cache)
@@ -899,6 +913,7 @@ struct host1x_bo_mapping *host1x_bo_pin(struct device *dev, struct host1x_bo *bo
 		list_for_each_entry(mapping, &cache->mappings, entry) {
 			if (mapping->bo == bo && mapping->direction == dir) {
 				kref_get(&mapping->ref);
+				host1x_bo_get(bo);
 				goto unlock;
 			}
 		}
@@ -908,6 +923,8 @@ struct host1x_bo_mapping *host1x_bo_pin(struct device *dev, struct host1x_bo *bo
 	if (IS_ERR(mapping))
 		goto unlock;
 
+	host1x_bo_get(bo);
+
 	spin_lock(&mapping->bo->lock);
 	list_add_tail(&mapping->list, &bo->mappings);
 	spin_unlock(&mapping->bo->lock);
@@ -918,7 +935,12 @@ struct host1x_bo_mapping *host1x_bo_pin(struct device *dev, struct host1x_bo *bo
 
 		list_add_tail(&mapping->entry, &cache->mappings);
 
-		/* bump reference count to track the copy in the cache */
+		/*
+		 * Bump the mapping reference count to track the mapping in the cache,
+		 * but do not bump the BO's refcount. This allows the BO to still get freed,
+		 * triggering the release of the cache mapping through
+		 * host1x_bo_clear_cached_mappings.
+		 */
 		kref_get(&mapping->ref);
 	}
 
@@ -948,9 +970,17 @@ static void __host1x_bo_unpin(struct kref *ref)
 	mapping->bo->ops->unpin(mapping);
 }
 
+/**
+ * host1x_bo_unpin() - Release an established DMA mapping of a buffer object
+ * @mapping: Mapping to release
+ *
+ * Unmaps the given @mapping, unless it is cached. Decreases the refcount on
+ * the underlying buffer object.
+ */
 void host1x_bo_unpin(struct host1x_bo_mapping *mapping)
 {
 	struct host1x_bo_cache *cache = mapping->cache;
+	struct host1x_bo *bo = mapping->bo;
 
 	if (cache)
 		mutex_lock(&cache->lock);
@@ -959,5 +989,33 @@ void host1x_bo_unpin(struct host1x_bo_mapping *mapping)
 
 	if (cache)
 		mutex_unlock(&cache->lock);
+
+	host1x_bo_put(bo);
 }
 EXPORT_SYMBOL(host1x_bo_unpin);
+
+/**
+ * host1x_bo_clear_cached_mappings() - Remove all cached mappings pointing at a bo
+ * @bo: Buffer object to release mappings of
+ *
+ * Drops references to any mappings pointing to @bo left in any caches. This must
+ * be called by any host1x_bo implementers that may be pinned with caching enabled
+ * before freeing the bo.
+ */
+void host1x_bo_clear_cached_mappings(struct host1x_bo *bo)
+{
+	struct host1x_bo_mapping *mapping, *tmp;
+	struct host1x_bo_cache *cache;
+
+	list_for_each_entry_safe(mapping, tmp, &bo->mappings, list) {
+		cache = mapping->cache;
+		if (WARN_ON(!cache))
+			continue;
+
+		mutex_lock(&mapping->cache->lock);
+		WARN_ON(kref_read(&mapping->ref) != 1);
+		__host1x_bo_unpin(&mapping->ref);
+		mutex_unlock(&mapping->cache->lock);
+	}
+}
+EXPORT_SYMBOL(host1x_bo_clear_cached_mappings);
diff --git a/include/linux/host1x.h b/include/linux/host1x.h
index 1f5f55917d1cd0..a7a67578313624 100644
--- a/include/linux/host1x.h
+++ b/include/linux/host1x.h
@@ -143,6 +143,12 @@ static inline struct host1x_bo_mapping *to_host1x_bo_mapping(struct kref *ref)
 	return container_of(ref, struct host1x_bo_mapping, ref);
 }
 
+/**
+ * struct host1x_bo_ops - operations implemented by a host1x_bo provider
+ *
+ * @pin: create a DMA mapping. Implementation must not touch the bo's refcount.
+ * @unpin: destroy a DMA mapping. Implementation must not touch the bo's refcount.
+ */
 struct host1x_bo_ops {
 	struct host1x_bo *(*get)(struct host1x_bo *bo);
 	void (*put)(struct host1x_bo *bo);
@@ -181,6 +187,7 @@ struct host1x_bo_mapping *host1x_bo_pin(struct device *dev, struct host1x_bo *bo
 					enum dma_data_direction dir,
 					struct host1x_bo_cache *cache);
 void host1x_bo_unpin(struct host1x_bo_mapping *map);
+void host1x_bo_clear_cached_mappings(struct host1x_bo *bo);
 
 static inline void *host1x_bo_mmap(struct host1x_bo *bo)
 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0345/2077] drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (343 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0344/2077] gpu: host1x: Allow entries in BO caches to be freed Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0346/2077] gpu: host1x: mipi: Fix device_node reference leak in tegra_mipi_request() Greg Kroah-Hartman
                   ` (652 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann, linux-tegra,
	Thierry Reding, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Zimmermann <tzimmermann@suse.de>

[ Upstream commit d23bd83f3e47a928e783c0d6a004737519dc77dc ]

That field already contains the value being assigned. No need to do
this twice.

Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Fixes: 63c971af4036 ("drm/fb-helper: Allocate and release fb_info in single place")
Cc: linux-tegra@vger.kernel.org
Signed-off-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260421073646.144712-2-tzimmermann@suse.de
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/tegra/fbdev.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/gpu/drm/tegra/fbdev.c b/drivers/gpu/drm/tegra/fbdev.c
index 8f40882aa76ec9..19e39fa54bfae2 100644
--- a/drivers/gpu/drm/tegra/fbdev.c
+++ b/drivers/gpu/drm/tegra/fbdev.c
@@ -110,7 +110,6 @@ int tegra_fbdev_driver_fbdev_probe(struct drm_fb_helper *helper,
 
 	helper->funcs = &tegra_fbdev_helper_funcs;
 	helper->fb = fb;
-	helper->info = info;
 
 	info->fbops = &tegra_fb_ops;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0346/2077] gpu: host1x: mipi: Fix device_node reference leak in tegra_mipi_request()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (344 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0345/2077] drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0347/2077] drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() Greg Kroah-Hartman
                   ` (651 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Thierry Reding,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit b217fb77ca4fd0cc267329500b291c0ad8f8b211 ]

In tegra_mipi_request(), when provider.np is not equal with args.np, it
returns without calling of_node_put(args.np), causing a reference leak.

Convert to use the existing goto out pattern to ensure proper cleanup.

Fixes: 767598d447aa ("gpu: host1x: mipi: Update tegra_mipi_request() to be node based")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260416-mipi-v1-1-9c027175abdf@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/host1x/mipi.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/host1x/mipi.c b/drivers/gpu/host1x/mipi.c
index 01513b775d8996..98868142398172 100644
--- a/drivers/gpu/host1x/mipi.c
+++ b/drivers/gpu/host1x/mipi.c
@@ -114,8 +114,10 @@ struct tegra_mipi_device *tegra_mipi_request(struct device *device,
 	if (err < 0)
 		return ERR_PTR(err);
 
-	if (provider.np != args.np)
-		return ERR_PTR(-ENODEV);
+	if (provider.np != args.np) {
+		err = -ENODEV;
+		goto out;
+	}
 
 	mipidev = kzalloc_obj(*mipidev);
 	if (!mipidev) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0347/2077] drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (345 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0346/2077] gpu: host1x: mipi: Fix device_node reference leak in tegra_mipi_request() Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0348/2077] gpu: host1x: Fix iommu_map_sgtable() return value check Greg Kroah-Hartman
                   ` (650 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Felix Gu, Mikko Perttunen,
	Thierry Reding, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit 63a3998d792ab5c45304bf879e385a31fa923b61 ]

The of_for_each_phandle() macro increments the reference count of the
device node it iterates over. If the loop exits early, the reference must
be released manually.

In tegra_dc_has_output(), the function returns true immediately when a
match is found, failing to release the current node's reference.

Fix this by adding a call to of_node_put() before returning from the loop.

Fixes: c57997bce423 ("drm/tegra: sor: Add Tegra186 support")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Acked-by: Mikko Perttunen <mperttunen@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260128-dc-v1-1-a88205826301@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/tegra/dc.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/tegra/dc.c b/drivers/gpu/drm/tegra/dc.c
index 06370b7e0e5678..c6734a87ef0aff 100644
--- a/drivers/gpu/drm/tegra/dc.c
+++ b/drivers/gpu/drm/tegra/dc.c
@@ -101,8 +101,10 @@ bool tegra_dc_has_output(struct tegra_dc *dc, struct device *dev)
 	int err;
 
 	of_for_each_phandle(&it, err, np, "nvidia,outputs", NULL, 0)
-		if (it.node == dev->of_node)
+		if (it.node == dev->of_node) {
+			of_node_put(it.node);
 			return true;
+		}
 
 	return false;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0348/2077] gpu: host1x: Fix iommu_map_sgtable() return value check
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (346 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0347/2077] drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0349/2077] drm/tegra: " Greg Kroah-Hartman
                   ` (649 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikko Perttunen, Thierry Reding,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikko Perttunen <mperttunen@nvidia.com>

[ Upstream commit 18f74762013a4b6aa6f905c4459e0f506f9c5c7b ]

Commit "iommu: return full error code from iommu_map_sg[_atomic]()"
changed iommu_map_sgtable() to return an ssize_t and negative values
in error cases, rather than a size_t and a zero.

pin_job() also was incorrectly assigning to 'int', which could cause
overflows into negative values.

Update pin_job() to correctly check for errors from iommu_map_sgtable.

Fixes: ad8f36e4b6b1 ("iommu: return full error code from iommu_map_sg[_atomic]()")
Signed-off-by: Mikko Perttunen <mperttunen@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260421-iommu_map_sgtable-return-v1-1-fb484c07d2a1@nvidia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/host1x/job.c | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/drivers/gpu/host1x/job.c b/drivers/gpu/host1x/job.c
index 3ed49e1fd93322..70bda32f1ff488 100644
--- a/drivers/gpu/host1x/job.c
+++ b/drivers/gpu/host1x/job.c
@@ -235,6 +235,8 @@ static unsigned int pin_job(struct host1x *host, struct host1x_job *job)
 		}
 
 		if (host->domain) {
+			ssize_t map_err;
+
 			for_each_sgtable_sg(map->sgt, sg, j)
 				gather_size += sg->length;
 
@@ -248,11 +250,11 @@ static unsigned int pin_job(struct host1x *host, struct host1x_job *job)
 				goto put;
 			}
 
-			err = iommu_map_sgtable(host->domain, iova_dma_addr(&host->iova, alloc),
-						map->sgt, IOMMU_READ);
-			if (err == 0) {
+			map_err = iommu_map_sgtable(host->domain, iova_dma_addr(&host->iova, alloc),
+						    map->sgt, IOMMU_READ);
+			if (map_err < 0) {
 				__free_iova(&host->iova, alloc);
-				err = -EINVAL;
+				err = map_err;
 				goto put;
 			}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0349/2077] drm/tegra: Fix iommu_map_sgtable() return value check
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (347 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0348/2077] gpu: host1x: Fix iommu_map_sgtable() return value check Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0350/2077] drm/nouveau/bios: specify correct display fuse register for Ampere and Ada Greg Kroah-Hartman
                   ` (648 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikko Perttunen, Thierry Reding,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikko Perttunen <mperttunen@nvidia.com>

[ Upstream commit b3f349517de8f4469c385ebb7bfdfcc148790c0f ]

Commit "iommu: return full error code from iommu_map_sg[_atomic]()"
changed iommu_map_sgtable() to return an ssize_t and negative values
in error cases, rather than a size_t and a zero.

Update tegra_bo_iommu_map() to correctly check for errors from
iommu_map_sgtable.

Fixes: ad8f36e4b6b1 ("iommu: return full error code from iommu_map_sg[_atomic]()")
Signed-off-by: Mikko Perttunen <mperttunen@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260421-iommu_map_sgtable-return-v1-2-fb484c07d2a1@nvidia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/tegra/gem.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/drivers/gpu/drm/tegra/gem.c b/drivers/gpu/drm/tegra/gem.c
index 2377e2b76397a3..436394e0481252 100644
--- a/drivers/gpu/drm/tegra/gem.c
+++ b/drivers/gpu/drm/tegra/gem.c
@@ -234,6 +234,7 @@ static const struct host1x_bo_ops tegra_bo_ops = {
 static int tegra_bo_iommu_map(struct tegra_drm *tegra, struct tegra_bo *bo)
 {
 	int prot = IOMMU_READ | IOMMU_WRITE;
+	ssize_t size;
 	int err;
 
 	if (bo->mm)
@@ -255,13 +256,15 @@ static int tegra_bo_iommu_map(struct tegra_drm *tegra, struct tegra_bo *bo)
 
 	bo->iova = bo->mm->start;
 
-	bo->size = iommu_map_sgtable(tegra->domain, bo->iova, bo->sgt, prot);
-	if (!bo->size) {
+	size = iommu_map_sgtable(tegra->domain, bo->iova, bo->sgt, prot);
+	if (size < 0) {
 		dev_err(tegra->drm->dev, "failed to map buffer\n");
-		err = -ENOMEM;
+		err = size;
 		goto remove;
 	}
 
+	bo->size = size;
+
 	mutex_unlock(&tegra->mm_lock);
 
 	return 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0350/2077] drm/nouveau/bios: specify correct display fuse register for Ampere and Ada
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (348 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0349/2077] drm/tegra: " Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0351/2077] libbpf: Harden parse_vma_segs() path parsing Greg Kroah-Hartman
                   ` (647 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Timur Tabi, Lyude Paul,
	Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Timur Tabi <ttabi@nvidia.com>

[ Upstream commit c1cf2d5db80ce91a85855bbaf4da85ff603e089a ]

The NV_FUSE_STATUS_OPT_DISPLAY register is used to determine whether
the GPU has display hardware.  The current code that normally reads
this register is instead hard-coded to check for GA100 vs later GPUs.
Since this function is called only on pre-Hopper GPUs, and this
if-statement applies only to GA100 and later, the check works
because GA100 is the only non-display Ampere and Ada GPU.

However, there actually is a register that can be read, so we should
use it.

Fixes: a34632482f1e ("drm/nouveau/bios/ga10[024]: initial support")
Signed-off-by: Timur Tabi <ttabi@nvidia.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260430223838.2530778-8-ttabi@nvidia.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/nouveau/nvkm/subdev/bios/shadowramin.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/bios/shadowramin.c b/drivers/gpu/drm/nouveau/nvkm/subdev/bios/shadowramin.c
index d5411d176e3a80..0d9e6cdd611930 100644
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/bios/shadowramin.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/bios/shadowramin.c
@@ -65,13 +65,14 @@ pramin_init(struct nvkm_bios *bios, const char *name)
 
 	/* we can't get the bios image pointer without PDISP */
 	if (device->card_type >= GA100)
-		addr = device->chipset == 0x170; /*XXX: find the fuse reg for this */
+		addr = nvkm_rd32(device, 0x820c04);
 	else
 	if (device->card_type >= GM100)
 		addr = nvkm_rd32(device, 0x021c04);
 	else
 	if (device->card_type >= NV_C0)
 		addr = nvkm_rd32(device, 0x022500);
+
 	if (addr & 0x00000001) {
 		nvkm_debug(subdev, "... display disabled\n");
 		return ERR_PTR(-ENODEV);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0351/2077] libbpf: Harden parse_vma_segs() path parsing
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (349 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0350/2077] drm/nouveau/bios: specify correct display fuse register for Ampere and Ada Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0352/2077] bpftool: Fix typo in struct_ops map FD generation for light skeleton Greg Kroah-Hartman
                   ` (646 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Andrii Nakryiko,
	Emil Tsalapatis, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Bommarito <michael.bommarito@gmail.com>

[ Upstream commit fee9a38174f4c6454fb1fbaf2b9b5a1cca9070d0 ]

parse_vma_segs() in tools/lib/bpf/usdt.c parses /proc/<pid>/maps
with two widthless scansets, "%s" into mode[16] and "%[^\n]"
into line[4096]. A VMA name in maps is not limited to that local
buffer; a deeply nested backing path can produce a maps record long
enough to overflow the stack buffer.

Bound both scansets to the declared buffer sizes ("%15s" for mode[16]
and "%4095[^\n]" for line[4096]) and drain any residue past line[4094]
with "%*[^\n]" before the trailing "\n". Without the drain, the residue
of an over-long record would stay in the stream and break the next
"%zx-%zx" parse, so the loop would exit early and silently skip later
maps records.

Also stop using sscanf(..., "%s") to peel the /proc/<pid>/root prefix
from lib_path. Parse the pid and prefix length with "%n", check for the
following slash, and copy the remainder with libbpf_strlcpy(). That
removes a second unbounded stack write and preserves paths containing
spaces.

Fixes: 74cc6311cec9 ("libbpf: Add USDT notes parsing and resolution logic")
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/bpf/20260522201353.1454653-1-michael.bommarito@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/lib/bpf/usdt.c | 16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

diff --git a/tools/lib/bpf/usdt.c b/tools/lib/bpf/usdt.c
index e3710933fd52a6..57fb82bb81b588 100644
--- a/tools/lib/bpf/usdt.c
+++ b/tools/lib/bpf/usdt.c
@@ -468,10 +468,10 @@ static int parse_elf_segs(Elf *elf, const char *path, struct elf_seg **segs, siz
 
 static int parse_vma_segs(int pid, const char *lib_path, struct elf_seg **segs, size_t *seg_cnt)
 {
-	char path[PATH_MAX], line[PATH_MAX], mode[16];
+	char path[PATH_MAX], line[4096], mode[16];
 	size_t seg_start, seg_end, seg_off;
 	struct elf_seg *seg;
-	int tmp_pid, i, err;
+	int tmp_pid, n, i, err;
 	FILE *f;
 
 	*seg_cnt = 0;
@@ -480,8 +480,13 @@ static int parse_vma_segs(int pid, const char *lib_path, struct elf_seg **segs,
 	 * /proc/<pid>/root/<path>. They will be reported as just /<path> in
 	 * /proc/<pid>/maps.
 	 */
-	if (sscanf(lib_path, "/proc/%d/root%s", &tmp_pid, path) == 2 && pid == tmp_pid)
+	/* %n is not counted in sscanf() return value, so initialize it. */
+	n = 0;
+	if (sscanf(lib_path, "/proc/%d/root%n", &tmp_pid, &n) == 1 &&
+	    n > 0 && pid == tmp_pid && lib_path[n] == '/') {
+		libbpf_strlcpy(path, lib_path + n, sizeof(path));
 		goto proceed;
+	}
 
 	if (!realpath(lib_path, path)) {
 		pr_warn("usdt: failed to get absolute path of '%s' (err %s), using path as is...\n",
@@ -504,8 +509,11 @@ static int parse_vma_segs(int pid, const char *lib_path, struct elf_seg **segs,
 	 * 7f5c6f5d1000-7f5c6f5d3000 rw-p 001c7000 08:04 21238613      /usr/lib64/libc-2.17.so
 	 * 7f5c6f5d3000-7f5c6f5d8000 rw-p 00000000 00:00 0
 	 * 7f5c6f5d8000-7f5c6f5d9000 r-xp 00000000 103:01 362990598    /data/users/andriin/linux/tools/bpf/usdt/libhello_usdt.so
+	 *
+	 * Some VMA names can be longer than the local buffer. Bound the
+	 * writes, but still consume the rest of the line.
 	 */
-	while (fscanf(f, "%zx-%zx %s %zx %*s %*d%[^\n]\n",
+	while (fscanf(f, "%zx-%zx %15s %zx %*s %*d%4095[^\n]%*[^\n]\n",
 		      &seg_start, &seg_end, mode, &seg_off, line) == 5) {
 		void *tmp;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0352/2077] bpftool: Fix typo in struct_ops map FD generation for light skeleton
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (350 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0351/2077] libbpf: Harden parse_vma_segs() path parsing Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0353/2077] libbpf: Fix UAF in strset__add_str() Greg Kroah-Hartman
                   ` (645 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Siddharth Nayyar, Andrii Nakryiko,
	Quentin Monnet, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Siddharth Nayyar <sidnayyar@google.com>

[ Upstream commit be4c6c7bc42952b71188894933946b410deadcfe ]

When generating light skeletons for BPF programs containing struct_ops
maps, bpftool incorrectly outputs a stray literal 't' instead of a tab
character for the map file descriptor member in the links structure.
This causes a compilation error when the generated light skeleton is
used.

Correct the format string by replacing 't' with '\t'.

Fixes: 08ac454e258e ("libbpf: Auto-attach struct_ops BPF maps in BPF skeleton")
Signed-off-by: Siddharth Nayyar <sidnayyar@google.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Acked-by: Quentin Monnet <qmo@kernel.org>
Link: https://lore.kernel.org/bpf/20260520-struct_ops_gen_typo_fix-v1-1-4dee3771da46@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/bpf/bpftool/gen.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/bpf/bpftool/gen.c b/tools/bpf/bpftool/gen.c
index 2f9e10752e288d..d6040b52d4e1bf 100644
--- a/tools/bpf/bpftool/gen.c
+++ b/tools/bpf/bpftool/gen.c
@@ -1399,7 +1399,7 @@ static int do_skeleton(int argc, char **argv)
 				continue;
 
 			if (use_loader)
-				printf("t\tint %s_fd;\n", ident);
+				printf("\t\tint %s_fd;\n", ident);
 			else
 				printf("\t\tstruct bpf_link *%s;\n", ident);
 		}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0353/2077] libbpf: Fix UAF in strset__add_str()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (351 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0352/2077] bpftool: Fix typo in struct_ops map FD generation for light skeleton Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0354/2077] ARM: tegra: Add #{address,size}-cells to Chromium-based /firmware Greg Kroah-Hartman
                   ` (644 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Andrii Nakryiko, Mykyta Yatsenko,
	Carlos Llamas, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Carlos Llamas <cmllamas@google.com>

[ Upstream commit b23705e6afb6ac4ae6d220dcb35975698667dd76 ]

strset_add_str_mem() might reallocate the strset data buffer in order to
accommodate the provided string 's'. However, if 's' points to a string
already present in the buffer, it becomes dangling after the realloc.
This leads to a use-after-free when attempting to memcpy() the string
into the new buffer.

One scenario that triggers this problematic path is when resolve_btfids
attempts to patch kfunc prototypes using existing BTF parameter names:

 | resolve_btfids: function bpf_list_push_back_impl already exists in BTF
 | Segmentation fault (core dumped)

Compiling resolve_btfids with fsanitize=address generates a detailed
report of the UAF:

 | =================================================================
 | ERROR: AddressSanitizer: heap-use-after-free on address 0x7f4c4a500bd4
 | ==1507892==ERROR: AddressSanitizer: heap-use-after-free on address 0x7f4c4a500bd4 at pc 0x55d25155a2a8 bp 0x7ffcef879060 sp 0x7ffcef878818
 | READ of size 5 at 0x7f4c4a500bd4 thread T0
 |     #0 0x55d25155a2a7 in memcpy (tools/bpf/resolve_btfids/resolve_btfids+0xcf2a7)
 |     #1 0x55d2515d708e in strset__add_str tools/lib/bpf/strset.c:162:2
 |     #2 0x55d2515c730b in btf__add_str tools/lib/bpf/btf.c:2109:8
 |     #3 0x55d2515c9020 in btf__add_func_param tools/lib/bpf/btf.c:3108:14
 |     #4 0x55d25159f0b5 in process_kfunc_with_implicit_args tools/bpf/resolve_btfids/main.c:1196:9
 |     #5 0x55d25159e004 in btf2btf tools/bpf/resolve_btfids/main.c:1229:9
 |     #6 0x55d25159cee7 in main tools/bpf/resolve_btfids/main.c:1535:6
 |     #7 0x7f4c78e29f76 in __libc_start_call_main csu/../sysdeps/nptl/libc_start_call_main.h:58:16
 |     #8 0x7f4c78e2a026 in __libc_start_main csu/../csu/libc-start.c:360:3
 |     #9 0x55d2514bb860 in _start (tools/bpf/resolve_btfids/resolve_btfids+0x30860)
 |
 | 0x7f4c4a500bd4 is located 13268 bytes inside of 2829000-byte region [0x7f4c4a4fd800,0x7f4c4a7b02c8)
 | freed by thread T0 here:
 |     #0 0x55d25155b700 in realloc (tools/bpf/resolve_btfids/resolve_btfids+0xd0700)
 |     #1 0x55d2515c426c in libbpf_reallocarray tools/lib/bpf/./libbpf_internal.h:220:9
 |     #2 0x55d2515c426c in libbpf_add_mem tools/lib/bpf/btf.c:224:13
 |
 | previously allocated by thread T0 here:
 |     #0 0x55d25155b2e3 in malloc (tools/bpf/resolve_btfids/resolve_btfids+0xd02e3)
 |     #1 0x55d2515d6e7d in strset__new tools/lib/bpf/strset.c:58:20

While resolve_btfids could be refactored to avoid this call path, let's
instead fix this issue at the source in strset__add_str() and avoid
similar scenarios.

Let's check if set->strs_data was reallocated and whether 's' points to
an internal string within the old strset buffer. In such case, 's' is
reconstructed to point to the new buffer.

While already here, also fix strset__find_str() which suffers from the
same problem by factoring out the common operations into a new helper
function strset_str_append().

Fixes: 90d76d3ececc ("libbpf: Extract internal set-of-strings datastructure APIs")
Suggested-by: Andrii Nakryiko <andrii@kernel.org>
Suggested-by: Mykyta Yatsenko <yatsenko@meta.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20260523162722.2718940-1-cmllamas@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/lib/bpf/strset.c | 62 ++++++++++++++++++++++++++++--------------
 1 file changed, 41 insertions(+), 21 deletions(-)

diff --git a/tools/lib/bpf/strset.c b/tools/lib/bpf/strset.c
index 2464bcbd04e037..ace73c6b3d62b4 100644
--- a/tools/lib/bpf/strset.c
+++ b/tools/lib/bpf/strset.c
@@ -107,6 +107,41 @@ static void *strset_add_str_mem(struct strset *set, size_t add_sz)
 			      set->strs_data_len, set->strs_data_max_len, add_sz);
 }
 
+static long strset_str_append(struct strset *set, const char *s)
+{
+	uintptr_t old_data = (uintptr_t)set->strs_data;
+	size_t old_data_len = set->strs_data_len;
+	uintptr_t old_s = (uintptr_t)s;
+	long len = strlen(s) + 1;
+	void *p;
+
+	/*
+	 * Hashmap keys are always offsets within set->strs_data, so to even
+	 * look up some string from the "outside", we need to first append it
+	 * at the end, so that it can be addressed with an offset. Luckily,
+	 * until set->strs_data_len is incremented, that string is just a piece
+	 * of garbage for the rest of the code, so no harm, no foul. On the
+	 * other hand, if the string is unique, it's already appended and
+	 * ready to be used, only a simple set->strs_data_len increment away.
+	 */
+	p = strset_add_str_mem(set, len);
+	if (!p)
+		return -ENOMEM;
+
+	/*
+	 * The set->strs_data might have reallocated and if 's' pointed
+	 * to an internal string within the old buffer, then it became
+	 * dangling and needs to be reconstructed before the copy.
+	 */
+	if (old_data && old_data != (uintptr_t)set->strs_data &&
+	    old_s >= old_data && old_s < old_data + old_data_len)
+		s = set->strs_data + (old_s - old_data);
+
+	memcpy(p, s, len);
+
+	return len;
+}
+
 /* Find string offset that corresponds to a given string *s*.
  * Returns:
  *   - >0 offset into string data, if string is found;
@@ -116,16 +151,12 @@ static void *strset_add_str_mem(struct strset *set, size_t add_sz)
 int strset__find_str(struct strset *set, const char *s)
 {
 	long old_off, new_off, len;
-	void *p;
 
-	/* see strset__add_str() for why we do this */
-	len = strlen(s) + 1;
-	p = strset_add_str_mem(set, len);
-	if (!p)
-		return -ENOMEM;
+	len = strset_str_append(set, s);
+	if (len < 0)
+		return len;
 
 	new_off = set->strs_data_len;
-	memcpy(p, s, len);
 
 	if (hashmap__find(set->strs_hash, new_off, &old_off))
 		return old_off;
@@ -142,24 +173,13 @@ int strset__find_str(struct strset *set, const char *s)
 int strset__add_str(struct strset *set, const char *s)
 {
 	long old_off, new_off, len;
-	void *p;
 	int err;
 
-	/* Hashmap keys are always offsets within set->strs_data, so to even
-	 * look up some string from the "outside", we need to first append it
-	 * at the end, so that it can be addressed with an offset. Luckily,
-	 * until set->strs_data_len is incremented, that string is just a piece
-	 * of garbage for the rest of the code, so no harm, no foul. On the
-	 * other hand, if the string is unique, it's already appended and
-	 * ready to be used, only a simple set->strs_data_len increment away.
-	 */
-	len = strlen(s) + 1;
-	p = strset_add_str_mem(set, len);
-	if (!p)
-		return -ENOMEM;
+	len = strset_str_append(set, s);
+	if (len < 0)
+		return len;
 
 	new_off = set->strs_data_len;
-	memcpy(p, s, len);
 
 	/* Now attempt to add the string, but only if the string with the same
 	 * contents doesn't exist already (HASHMAP_ADD strategy). If such
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0354/2077] ARM: tegra: Add #{address,size}-cells to Chromium-based /firmware
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (352 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0353/2077] libbpf: Fix UAF in strset__add_str() Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0355/2077] arm64: " Greg Kroah-Hartman
                   ` (643 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Brian Norris, Douglas Anderson,
	Thierry Reding, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Brian Norris <briannorris@chromium.org>

[ Upstream commit 1fe27b10dc97c85821dfae1e4e6f9db4472287aa ]

Chromium/Depthcharge bootloaders may dynamically add a few device nodes
to a system's DTB under a /firmware node. A typical DT looks something
like the following:

/ {
        firmware {
                ranges;

                coreboot {
                        compatible = "coreboot";
                        reg = <...>;
                        ...;
                };
        };
};

Notably, the /firmware node has an empty 'ranges', but does not have
address/size-cells.

Commit 6e5773d52f4a ("of/address: Fix WARN when attempting translating
non-translatable addresses") started requiring #address-cells for a
device's parent if we want to use the reg resource in a device node.
This leads to errors like the following:

[    7.763870] coreboot_table firmware:coreboot: probe with driver coreboot_table failed with error -22

Add appropriate #{address,size}-cells to work around the problem.

Note that Google has also patched the Depthcharge bootloader source to
add {address,size}-cells [1], but bootloader updates are typically
delivered only via Google OS updates. Not all users install Google
software updates, and even if they do, Google may not produce updated
binaries for all/older devices.

[1] https://lore.kernel.org/all/20241209092809.GA3246424@google.com/
    https://crrev.com/c/6051580 ("coreboot: Insert #address-cells and
    #size-cells for firmware node")

Closes: https://lore.kernel.org/all/aeKlYzTiL0OB1y3g@google.com/
Fixes: 6e5773d52f4a ("of/address: Fix WARN when attempting translating non-translatable addresses")
Signed-off-by: Brian Norris <briannorris@chromium.org>
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm/boot/dts/nvidia/tegra124-nyan.dtsi   | 5 +++++
 arch/arm/boot/dts/nvidia/tegra124-venice2.dts | 5 +++++
 2 files changed, 10 insertions(+)

diff --git a/arch/arm/boot/dts/nvidia/tegra124-nyan.dtsi b/arch/arm/boot/dts/nvidia/tegra124-nyan.dtsi
index 974c76f007db4d..89a749cb893388 100644
--- a/arch/arm/boot/dts/nvidia/tegra124-nyan.dtsi
+++ b/arch/arm/boot/dts/nvidia/tegra124-nyan.dtsi
@@ -14,6 +14,11 @@ chosen {
 		stdout-path = "serial0:115200n8";
 	};
 
+	firmware {
+		#address-cells = <1>;
+		#size-cells = <1>;
+	};
+
 	/*
 	 * Note that recent version of the device tree compiler (starting with
 	 * version 1.4.2) warn about this node containing a reg property, but
diff --git a/arch/arm/boot/dts/nvidia/tegra124-venice2.dts b/arch/arm/boot/dts/nvidia/tegra124-venice2.dts
index df98dc2a67b858..059ee6c5b13cdb 100644
--- a/arch/arm/boot/dts/nvidia/tegra124-venice2.dts
+++ b/arch/arm/boot/dts/nvidia/tegra124-venice2.dts
@@ -18,6 +18,11 @@ chosen {
 		stdout-path = "serial0:115200n8";
 	};
 
+	firmware {
+		#address-cells = <1>;
+		#size-cells = <1>;
+	};
+
 	memory@80000000 {
 		reg = <0x0 0x80000000 0x0 0x80000000>;
 	};
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0355/2077] arm64: tegra: Add #{address,size}-cells to Chromium-based /firmware
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (353 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0354/2077] ARM: tegra: Add #{address,size}-cells to Chromium-based /firmware Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0356/2077] rust: devres: add static bound to Devres<T> Greg Kroah-Hartman
                   ` (642 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Brian Norris, Douglas Anderson,
	Thierry Reding, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Brian Norris <briannorris@chromium.org>

[ Upstream commit f0fbedccae9e16624977cca02216ab2399f5a3ab ]

Chromium/Depthcharge bootloaders may dynamically add a few device nodes
to a system's DTB under a /firmware node. A typical DT looks something
like the following:

/ {
        firmware {
                ranges;

                coreboot {
                        compatible = "coreboot";
                        reg = <...>;
                        ...;
                };
        };
};

Notably, the /firmware node has an empty 'ranges', but does not have
address/size-cells.

Commit 6e5773d52f4a ("of/address: Fix WARN when attempting translating
non-translatable addresses") started requiring #address-cells for a
device's parent if we want to use the reg resource in a device node.
This leads to errors like the following:

[    7.763870] coreboot_table firmware:coreboot: probe with driver coreboot_table failed with error -22

Add appropriate #{address,size}-cells to work around the problem.

Note that Google has also patched the Depthcharge bootloader source to
add {address,size}-cells [1], but bootloader updates are typically
delivered only via Google OS updates. Not all users install Google
software updates, and even if they do, Google may not produce updated
binaries for all/older devices.

[1] https://lore.kernel.org/all/20241209092809.GA3246424@google.com/
    https://crrev.com/c/6051580 ("coreboot: Insert #address-cells and
    #size-cells for firmware node")

Closes: https://lore.kernel.org/all/aeKlYzTiL0OB1y3g@google.com/
Fixes: 6e5773d52f4a ("of/address: Fix WARN when attempting translating non-translatable addresses")
Signed-off-by: Brian Norris <briannorris@chromium.org>
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/nvidia/tegra132-norrin.dts | 5 +++++
 arch/arm64/boot/dts/nvidia/tegra210-smaug.dts  | 5 +++++
 2 files changed, 10 insertions(+)

diff --git a/arch/arm64/boot/dts/nvidia/tegra132-norrin.dts b/arch/arm64/boot/dts/nvidia/tegra132-norrin.dts
index 683ac124523b3b..1f5222d43e62c1 100644
--- a/arch/arm64/boot/dts/nvidia/tegra132-norrin.dts
+++ b/arch/arm64/boot/dts/nvidia/tegra132-norrin.dts
@@ -18,6 +18,11 @@ chosen {
 		stdout-path = "serial0:115200n8";
 	};
 
+	firmware {
+		#address-cells = <2>;
+		#size-cells = <2>;
+	};
+
 	memory@80000000 {
 		device_type = "memory";
 		reg = <0x0 0x80000000 0x0 0x80000000>;
diff --git a/arch/arm64/boot/dts/nvidia/tegra210-smaug.dts b/arch/arm64/boot/dts/nvidia/tegra210-smaug.dts
index f0b8c2c80aa502..a6d31650245d32 100644
--- a/arch/arm64/boot/dts/nvidia/tegra210-smaug.dts
+++ b/arch/arm64/boot/dts/nvidia/tegra210-smaug.dts
@@ -25,6 +25,11 @@ chosen {
 		stdout-path = "serial0:115200n8";
 	};
 
+	firmware {
+		#address-cells = <2>;
+		#size-cells = <2>;
+	};
+
 	memory@80000000 {
 		device_type = "memory";
 		reg = <0x0 0x80000000 0x0 0xc0000000>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0356/2077] rust: devres: add static bound to Devres<T>
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (354 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0355/2077] arm64: " Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0357/2077] dax/kmem: account for partial discontiguous resource upon removal Greg Kroah-Hartman
                   ` (641 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alexandre Courbot, Eliot Courtney,
	Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Danilo Krummrich <dakr@kernel.org>

[ Upstream commit 016267b521b18529c977c9eca9597a1669c3d73c ]

Devres::new() registers a callback with the C devres subsystem via
devres_node_add(). If the Devres is leaked (e.g. via
core::mem::forget(), which is safe), its Drop impl never runs, and the
devres release callback will revoke the inner Revocable on device
unbind, which drops T in place. If T contains non-'static references,
those may be dangling by that point.

Add a 'static bound to prevent storing types with borrowed data in
Devres.

Fixes: 76c01ded724b ("rust: add devres abstraction")
Reviewed-by: Alexandre Courbot <acourbot@nvidia.com>
Reviewed-by: Eliot Courtney <ecourtney@nvidia.com>
Link: https://patch.msgid.link/20260526000447.350558-1-dakr@kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 rust/kernel/devres.rs | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/rust/kernel/devres.rs b/rust/kernel/devres.rs
index 9e5f93aed20cf1..2e258d31a45cac 100644
--- a/rust/kernel/devres.rs
+++ b/rust/kernel/devres.rs
@@ -122,7 +122,7 @@ struct Inner<T> {
 /// # Ok(())
 /// # }
 /// ```
-pub struct Devres<T: Send> {
+pub struct Devres<T: Send + 'static> {
     dev: ARef<Device>,
     inner: Arc<Inner<T>>,
 }
@@ -184,7 +184,7 @@ mod base {
     }
 }
 
-impl<T: Send> Devres<T> {
+impl<T: Send + 'static> Devres<T> {
     /// Creates a new [`Devres`] instance of the given `data`.
     ///
     /// The `data` encapsulated within the returned `Devres` instance' `data` will be
@@ -349,7 +349,7 @@ unsafe impl<T: Send> Send for Devres<T> {}
 // SAFETY: `Devres` can be shared with any task, if `T: Sync`.
 unsafe impl<T: Send + Sync> Sync for Devres<T> {}
 
-impl<T: Send> Drop for Devres<T> {
+impl<T: Send + 'static> Drop for Devres<T> {
     fn drop(&mut self) {
         // SAFETY: When `drop` runs, it is guaranteed that nobody is accessing the revocable data
         // anymore, hence it is safe not to wait for the grace period to finish.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0357/2077] dax/kmem: account for partial discontiguous resource upon removal
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (355 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0356/2077] rust: devres: add static bound to Devres<T> Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0358/2077] lib/base64: validate before writing in decode tail path Greg Kroah-Hartman
                   ` (640 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Davidlohr Bueso, Ben Cheatham,
	Alison Schofield, Jonathan Cameron, Dan Williams, Dave Jiang,
	Vishal Verma, Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Davidlohr Bueso <dave@stgolabs.net>

[ Upstream commit 8aa442cfce79e2d69e72fc8e0c0864ac2971149d ]

When dev_dax_kmem_probe() partially succeeds (at least one range is
mapped) but a subsequent range fails request_mem_region() or
add_memory_driver_managed(), the probe silently continues, ultimately
returning success, but with the corresponding range resource NULL'ed out.

dev_dax_kmem_remove() iterates over all dax_device ranges regardless of if
the underlying resource exists.  When remove_memory() is called later, it
returns 0 because the memory was never added which causes
dev_dax_kmem_remove() to incorrectly assume the (nonexistent) resource can
be removed and attempts cleanup on a NULL pointer.

Fix this by skipping these ranges altogether, noting that these cases are
considered success, such that the cleanup is still reached when all
actually-added ranges are successfully removed.

Link: https://lore.kernel.org/20260223201516.1517657-1-dave@stgolabs.net
Fixes: 60e93dc097f7 ("device-dax: add dis-contiguous resource support")
Signed-off-by: Davidlohr Bueso <dave@stgolabs.net>
Reviewed-by: Ben Cheatham <benjamin.cheatham@amd.com>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Reviewed-by: Jonathan Cameron <jonathan.cameron@huawei.com>
Cc: Dan Williams <dan.j.williams@intel.com>
Cc: Dave Jiang <dave.jiang@intel.com>
Cc: Vishal Verma <vishal.l.verma@intel.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dax/kmem.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/dax/kmem.c b/drivers/dax/kmem.c
index 2cc8749bc8711b..a18e2b968e4dae 100644
--- a/drivers/dax/kmem.c
+++ b/drivers/dax/kmem.c
@@ -227,6 +227,12 @@ static void dev_dax_kmem_remove(struct dev_dax *dev_dax)
 		if (rc)
 			continue;
 
+		/* range was never added during probe */
+		if (!data->res[i]) {
+			success++;
+			continue;
+		}
+
 		rc = remove_memory(range.start, range_len(&range));
 		if (rc == 0) {
 			remove_resource(data->res[i]);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0358/2077] lib/base64: validate before writing in decode tail path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (356 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0357/2077] dax/kmem: account for partial discontiguous resource upon removal Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0359/2077] rust: uaccess: use INLINE_COPY_TO_USER to guard copy_to_user() Greg Kroah-Hartman
                   ` (639 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Josh Law, Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josh Law <objecting@objecting.org>

[ Upstream commit cae29a5787e38ce7ec7727a87ac7e393a85cb1ef ]

Patch series "lib/base64: decode fixes", v2.

Two small fixes for lib/base64.c:

1. base64_decode() writes a decoded byte to the output buffer before
   validating the input in the trailing-bytes path. Move the validity
   checks before any writes so dst is untouched on invalid input.

2. The @padding kernel-doc for base64_decode() was copy-pasted from
   base64_encode() and describes the wrong direction.

This patch (of 2):

The trailing-bytes path in base64_decode() writes a decoded byte to the
output buffer before checking whether the input characters are valid.  If
the input is malformed, garbage is written to dst before the function
returns -1.

Move the validity checks before any writes so the output buffer is left
untouched on invalid input.

Link: https://lore.kernel.org/20260324223210.47676-1-objecting@objecting.org
Link: https://lore.kernel.org/20260324223210.47676-2-objecting@objecting.org
Fixes: 9c7d3cf94d33 ("lib/base64: rework encode/decode for speed and stricter validation")
Signed-off-by: Josh Law <objecting@objecting.org>
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 lib/base64.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/lib/base64.c b/lib/base64.c
index 41961a444028b6..20dacee25f6508 100644
--- a/lib/base64.c
+++ b/lib/base64.c
@@ -168,15 +168,16 @@ int base64_decode(const char *src, int srclen, u8 *dst, bool padding, enum base6
 		return -1;
 
 	val = (base64_rev_tables[s[0]] << 12) | (base64_rev_tables[s[1]] << 6);
-	*bp++ = val >> 10;
 
 	if (srclen == 2) {
 		if (val & 0x800003ff)
 			return -1;
+		*bp++ = val >> 10;
 	} else {
 		val |= base64_rev_tables[s[2]];
 		if (val & 0x80000003)
 			return -1;
+		*bp++ = val >> 10;
 		*bp++ = val >> 2;
 	}
 	return bp - dst;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0359/2077] rust: uaccess: use INLINE_COPY_TO_USER to guard copy_to_user()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (357 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0358/2077] lib/base64: validate before writing in decode tail path Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0360/2077] uaccess: unify inline vs outline copy_{from,to}_user() selection Greg Kroah-Hartman
                   ` (638 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yury Norov,
	Christophe Leroy (CS GROUP), Alice Ryhl, Mathieu Desnoyers,
	Peter Zijlstra, Randy Dunlap, Viktor Malik, Arnd Bergmann,
	Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yury Norov <ynorov@nvidia.com>

[ Upstream commit f829d4d911cc296b32d14436a8a517e907228475 ]

Patch series "uaccess: unify inline vs outline copy_{from,to}_user()
selection", v2.

The kernel allows arches to select between inline and outline
implementations of the copy_{from,to}_user() by defining individual
INLINE_COPY_FROM_USER and INLINE_COPY_TO_USER, correspondingly.  However,
all arches enable or disable them always together.

Without the real use-case for one helper being inlined while the other
outlined, having independent controls is excessive and error prone.

The first patch of the series fixes rust/uaccess coppy_to_user() wrapper
guarded with INLINE_COPY_FROM_USER.  The 2nd patch switches codebase to
the unified INLINE_COPY_USER.  And the last patch cleans up ifdefery in
the include/linux/uaccess.h

This patch (of 3):

The copy_to_user() rust helper is only needed when the main kernel inlines
the function.  It is controlled by INLINE_COPY_TO_USER, but the rust
helper is protected with INLINE_COPY_FROM_USER.

Fix that.

Link: https://lore.kernel.org/20260425020857.356850-1-ynorov@nvidia.com
Link: https://lore.kernel.org/20260425020857.356850-2-ynorov@nvidia.com
Fixes: d99dc586ca7c7 ("uaccess: decouple INLINE_COPY_FROM_USER and CONFIG_RUST")
Signed-off-by: Yury Norov <ynorov@nvidia.com>
Reported-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Closes: https://lore.kernel.org/all/746c9c50-20c4-4dc9-a539-bf1310ff9414@kernel.org/
Cc: Alice Ryhl <aliceryhl@google.com>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Randy Dunlap <rdunlap@infradead.org>
Cc: Viktor Malik <vmalik@redhat.com>
Cc: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 rust/helpers/uaccess.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/rust/helpers/uaccess.c b/rust/helpers/uaccess.c
index d9625b9ee04669..aff22f16ab3884 100644
--- a/rust/helpers/uaccess.c
+++ b/rust/helpers/uaccess.c
@@ -20,7 +20,9 @@ unsigned long rust_helper__copy_from_user(void *to, const void __user *from, uns
 {
 	return _inline_copy_from_user(to, from, n);
 }
+#endif
 
+#ifdef INLINE_COPY_TO_USER
 __rust_helper
 unsigned long rust_helper__copy_to_user(void __user *to, const void *from, unsigned long n)
 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0360/2077] uaccess: unify inline vs outline copy_{from,to}_user() selection
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (358 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0359/2077] rust: uaccess: use INLINE_COPY_TO_USER to guard copy_to_user() Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0361/2077] uaccess: minimize INLINE_COPY_USER-related ifdefery Greg Kroah-Hartman
                   ` (637 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yury Norov, Alice Ryhl,
	Arnd Bergmann, Christophe Leroy (CS GROUP), Mathieu Desnoyers,
	Peter Zijlstra, Randy Dunlap, Viktor Malik, Andrew Morton,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yury Norov <ynorov@nvidia.com>

[ Upstream commit c02be2ad2b88c67c5d7c06b6aa7083b5b40e1077 ]

The kernel allows arches to select between inline and outline
implementations of the copy_{from,to}_user() by defining individual
INLINE_COPY_FROM_USER and INLINE_COPY_TO_USER, correspondingly.  However,
all arches enable or disable them always together.

Without the real use-case for one helper being inlined while the other
outlined, having independent controls is excessive and error prone.

Switch the codebase to the single unified INLINE_COPY_USER control.

Link: https://lore.kernel.org/20260425020857.356850-3-ynorov@nvidia.com
Signed-off-by: Yury Norov <ynorov@nvidia.com>
Tested-by: Alice Ryhl <aliceryhl@google.com>
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Randy Dunlap <rdunlap@infradead.org>
Cc: Viktor Malik <vmalik@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Stable-dep-of: bd99fcfc6219 ("uaccess: minimize INLINE_COPY_USER-related ifdefery")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arc/include/asm/uaccess.h        |  3 +--
 arch/arm/include/asm/uaccess.h        |  3 +--
 arch/arm64/include/asm/uaccess.h      |  3 +--
 arch/hexagon/include/asm/uaccess.h    |  3 +--
 arch/loongarch/include/asm/uaccess.h  |  3 +--
 arch/m68k/include/asm/uaccess.h       |  3 +--
 arch/microblaze/include/asm/uaccess.h |  3 +--
 arch/mips/include/asm/uaccess.h       |  3 +--
 arch/nios2/include/asm/uaccess.h      |  3 +--
 arch/openrisc/include/asm/uaccess.h   |  3 +--
 arch/parisc/include/asm/uaccess.h     |  3 +--
 arch/s390/include/asm/uaccess.h       |  3 +--
 arch/sh/include/asm/uaccess.h         |  3 +--
 arch/sparc/include/asm/uaccess_32.h   |  3 +--
 arch/sparc/include/asm/uaccess_64.h   |  3 +--
 arch/um/include/asm/uaccess.h         |  3 +--
 arch/xtensa/include/asm/uaccess.h     |  3 +--
 include/asm-generic/uaccess.h         |  3 +--
 include/linux/uaccess.h               | 12 ++++++------
 lib/usercopy.c                        |  4 +---
 rust/helpers/uaccess.c                |  4 +---
 21 files changed, 26 insertions(+), 48 deletions(-)

diff --git a/arch/arc/include/asm/uaccess.h b/arch/arc/include/asm/uaccess.h
index 1e8809ea000a35..6df2209541ac01 100644
--- a/arch/arc/include/asm/uaccess.h
+++ b/arch/arc/include/asm/uaccess.h
@@ -628,8 +628,7 @@ static inline unsigned long __clear_user(void __user *to, unsigned long n)
 	return res;
 }
 
-#define INLINE_COPY_TO_USER
-#define INLINE_COPY_FROM_USER
+#define INLINE_COPY_USER
 
 #define __clear_user			__clear_user
 
diff --git a/arch/arm/include/asm/uaccess.h b/arch/arm/include/asm/uaccess.h
index d6ae80b5df36f6..1593cf3b980088 100644
--- a/arch/arm/include/asm/uaccess.h
+++ b/arch/arm/include/asm/uaccess.h
@@ -616,8 +616,7 @@ raw_copy_to_user(void __user *to, const void *from, unsigned long n)
 }
 #define __clear_user(addr, n)		(memset((void __force *)addr, 0, n), 0)
 #endif
-#define INLINE_COPY_TO_USER
-#define INLINE_COPY_FROM_USER
+#define INLINE_COPY_USER
 
 static inline unsigned long __must_check clear_user(void __user *to, unsigned long n)
 {
diff --git a/arch/arm64/include/asm/uaccess.h b/arch/arm64/include/asm/uaccess.h
index b0c83a08dda97b..9f5bd9c69c249a 100644
--- a/arch/arm64/include/asm/uaccess.h
+++ b/arch/arm64/include/asm/uaccess.h
@@ -456,8 +456,7 @@ do {									\
 	unsafe_copy_loop(__ucu_dst, __ucu_src, __ucu_len, u8, label);	\
 } while (0)
 
-#define INLINE_COPY_TO_USER
-#define INLINE_COPY_FROM_USER
+#define INLINE_COPY_USER
 
 extern unsigned long __must_check __arch_clear_user(void __user *to, unsigned long n);
 static inline unsigned long __must_check __clear_user(void __user *to, unsigned long n)
diff --git a/arch/hexagon/include/asm/uaccess.h b/arch/hexagon/include/asm/uaccess.h
index bff77efc0d9a9c..1aecf60ec4f5a3 100644
--- a/arch/hexagon/include/asm/uaccess.h
+++ b/arch/hexagon/include/asm/uaccess.h
@@ -26,8 +26,7 @@ unsigned long raw_copy_from_user(void *to, const void __user *from,
 				     unsigned long n);
 unsigned long raw_copy_to_user(void __user *to, const void *from,
 				   unsigned long n);
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 __kernel_size_t __clear_user_hexagon(void __user *dest, unsigned long count);
 #define __clear_user(a, s) __clear_user_hexagon((a), (s))
diff --git a/arch/loongarch/include/asm/uaccess.h b/arch/loongarch/include/asm/uaccess.h
index 438269313e78c4..428f373feabf18 100644
--- a/arch/loongarch/include/asm/uaccess.h
+++ b/arch/loongarch/include/asm/uaccess.h
@@ -292,8 +292,7 @@ raw_copy_to_user(void __user *to, const void *from, unsigned long n)
 	return __copy_user((__force void *)to, from, n);
 }
 
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 /*
  * __clear_user: - Zero a block of memory in user space, with less checking.
diff --git a/arch/m68k/include/asm/uaccess.h b/arch/m68k/include/asm/uaccess.h
index 64914872a5c98d..31d133faa45ef4 100644
--- a/arch/m68k/include/asm/uaccess.h
+++ b/arch/m68k/include/asm/uaccess.h
@@ -377,8 +377,7 @@ raw_copy_to_user(void __user *to, const void *from, unsigned long n)
 		return __constant_copy_to_user(to, from, n);
 	return __generic_copy_to_user(to, from, n);
 }
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 #define __get_kernel_nofault(dst, src, type, err_label)			\
 do {									\
diff --git a/arch/microblaze/include/asm/uaccess.h b/arch/microblaze/include/asm/uaccess.h
index 3aab2f17e04628..afa0dd8d013fbc 100644
--- a/arch/microblaze/include/asm/uaccess.h
+++ b/arch/microblaze/include/asm/uaccess.h
@@ -250,8 +250,7 @@ raw_copy_to_user(void __user *to, const void *from, unsigned long n)
 {
 	return __copy_tofrom_user(to, (__force const void __user *)from, n);
 }
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 /*
  * Copy a null terminated string from userspace.
diff --git a/arch/mips/include/asm/uaccess.h b/arch/mips/include/asm/uaccess.h
index c0cede273c7c04..f00c36676b7378 100644
--- a/arch/mips/include/asm/uaccess.h
+++ b/arch/mips/include/asm/uaccess.h
@@ -433,8 +433,7 @@ raw_copy_to_user(void __user *to, const void *from, unsigned long n)
 	return __cu_len_r;
 }
 
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 extern __kernel_size_t __bzero(void __user *addr, __kernel_size_t size);
 
diff --git a/arch/nios2/include/asm/uaccess.h b/arch/nios2/include/asm/uaccess.h
index 6ccc9a232c2394..5e6e05cc6efc73 100644
--- a/arch/nios2/include/asm/uaccess.h
+++ b/arch/nios2/include/asm/uaccess.h
@@ -57,8 +57,7 @@ extern unsigned long
 raw_copy_from_user(void *to, const void __user *from, unsigned long n);
 extern unsigned long
 raw_copy_to_user(void __user *to, const void *from, unsigned long n);
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 extern long strncpy_from_user(char *__to, const char __user *__from,
 			      long __len);
diff --git a/arch/openrisc/include/asm/uaccess.h b/arch/openrisc/include/asm/uaccess.h
index d6500a374e1834..db934ebc0069f2 100644
--- a/arch/openrisc/include/asm/uaccess.h
+++ b/arch/openrisc/include/asm/uaccess.h
@@ -218,8 +218,7 @@ raw_copy_to_user(void __user *to, const void *from, unsigned long size)
 {
 	return __copy_tofrom_user((__force void *)to, from, size);
 }
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 extern unsigned long __clear_user(void __user *addr, unsigned long size);
 
diff --git a/arch/parisc/include/asm/uaccess.h b/arch/parisc/include/asm/uaccess.h
index 6c531d2c847eb1..0d17f81c8b2708 100644
--- a/arch/parisc/include/asm/uaccess.h
+++ b/arch/parisc/include/asm/uaccess.h
@@ -197,7 +197,6 @@ unsigned long __must_check raw_copy_to_user(void __user *dst, const void *src,
 					    unsigned long len);
 unsigned long __must_check raw_copy_from_user(void *dst, const void __user *src,
 					    unsigned long len);
-#define INLINE_COPY_TO_USER
-#define INLINE_COPY_FROM_USER
+#define INLINE_COPY_USER
 
 #endif /* __PARISC_UACCESS_H */
diff --git a/arch/s390/include/asm/uaccess.h b/arch/s390/include/asm/uaccess.h
index dff035372601e7..a9f32c53f699b8 100644
--- a/arch/s390/include/asm/uaccess.h
+++ b/arch/s390/include/asm/uaccess.h
@@ -30,8 +30,7 @@ void debug_user_asce(int exit);
 #define uaccess_kmsan_or_inline __always_inline
 #endif
 
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 static uaccess_kmsan_or_inline __must_check unsigned long
 raw_copy_from_user(void *to, const void __user *from, unsigned long size)
diff --git a/arch/sh/include/asm/uaccess.h b/arch/sh/include/asm/uaccess.h
index a79609eb14be43..02e7a066538ec3 100644
--- a/arch/sh/include/asm/uaccess.h
+++ b/arch/sh/include/asm/uaccess.h
@@ -95,8 +95,7 @@ raw_copy_to_user(void __user *to, const void *from, unsigned long n)
 {
 	return __copy_user((__force void *)to, from, n);
 }
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 /*
  * Clear the area and return remaining number of bytes
diff --git a/arch/sparc/include/asm/uaccess_32.h b/arch/sparc/include/asm/uaccess_32.h
index 43284b6ec46a68..5542d5b32994fa 100644
--- a/arch/sparc/include/asm/uaccess_32.h
+++ b/arch/sparc/include/asm/uaccess_32.h
@@ -190,8 +190,7 @@ static inline unsigned long raw_copy_from_user(void *to, const void __user *from
 	return __copy_user((__force void __user *) to, from, n);
 }
 
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 static inline unsigned long __clear_user(void __user *addr, unsigned long size)
 {
diff --git a/arch/sparc/include/asm/uaccess_64.h b/arch/sparc/include/asm/uaccess_64.h
index b825a5dd0210ea..e2989cfba626d5 100644
--- a/arch/sparc/include/asm/uaccess_64.h
+++ b/arch/sparc/include/asm/uaccess_64.h
@@ -231,8 +231,7 @@ unsigned long __must_check raw_copy_from_user(void *to,
 unsigned long __must_check raw_copy_to_user(void __user *to,
 					   const void *from,
 					   unsigned long size);
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 unsigned long __must_check raw_copy_in_user(void __user *to,
 					   const void __user *from,
diff --git a/arch/um/include/asm/uaccess.h b/arch/um/include/asm/uaccess.h
index 0df9ea4abda830..4417c8b1d37a6d 100644
--- a/arch/um/include/asm/uaccess.h
+++ b/arch/um/include/asm/uaccess.h
@@ -27,8 +27,7 @@ static inline int __access_ok(const void __user *ptr, unsigned long size);
 #define __access_ok __access_ok
 #define __clear_user __clear_user
 
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 #include <asm-generic/uaccess.h>
 
diff --git a/arch/xtensa/include/asm/uaccess.h b/arch/xtensa/include/asm/uaccess.h
index 56aec6d504fee3..6538a29a2bbd4c 100644
--- a/arch/xtensa/include/asm/uaccess.h
+++ b/arch/xtensa/include/asm/uaccess.h
@@ -237,8 +237,7 @@ raw_copy_to_user(void __user *to, const void *from, unsigned long n)
 	prefetch(from);
 	return __xtensa_copy_user((__force void *)to, from, n);
 }
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 
 /*
  * We need to return the number of bytes not cleared.  Our memset()
diff --git a/include/asm-generic/uaccess.h b/include/asm-generic/uaccess.h
index b276f783494c4b..4569045e7139fd 100644
--- a/include/asm-generic/uaccess.h
+++ b/include/asm-generic/uaccess.h
@@ -91,8 +91,7 @@ raw_copy_to_user(void __user *to, const void *from, unsigned long n)
 	memcpy((void __force *)to, from, n);
 	return 0;
 }
-#define INLINE_COPY_FROM_USER
-#define INLINE_COPY_TO_USER
+#define INLINE_COPY_USER
 #endif /* CONFIG_UACCESS_MEMCPY */
 
 /*
diff --git a/include/linux/uaccess.h b/include/linux/uaccess.h
index 09a09cc4aac274..add9ceea7b1edb 100644
--- a/include/linux/uaccess.h
+++ b/include/linux/uaccess.h
@@ -84,7 +84,7 @@
  * the 6 functions (copy_{to,from}_user(), __copy_{to,from}_user_inatomic())
  * that are used instead.  Out of those, __... ones are inlined.  Plain
  * copy_{to,from}_user() might or might not be inlined.  If you want them
- * inlined, have asm/uaccess.h define INLINE_COPY_{TO,FROM}_USER.
+ * inlined, have asm/uaccess.h define INLINE_COPY_USER.
  *
  * NOTE: only copy_from_user() zero-pads the destination in case of short copy.
  * Neither __copy_from_user() nor __copy_from_user_inatomic() zero anything
@@ -157,7 +157,7 @@ __copy_to_user(void __user *to, const void *from, unsigned long n)
 }
 
 /*
- * Architectures that #define INLINE_COPY_TO_USER use this function
+ * Architectures that #define INLINE_COPY_USER use this function
  * directly in the normal copy_to/from_user(), the other ones go
  * through an extern _copy_to/from_user(), which expands the same code
  * here.
@@ -190,7 +190,7 @@ _inline_copy_from_user(void *to, const void __user *from, unsigned long n)
 	memset(to + (n - res), 0, res);
 	return res;
 }
-#ifndef INLINE_COPY_FROM_USER
+#ifndef INLINE_COPY_USER
 extern __must_check unsigned long
 _copy_from_user(void *, const void __user *, unsigned long);
 #endif
@@ -207,7 +207,7 @@ _inline_copy_to_user(void __user *to, const void *from, unsigned long n)
 	}
 	return n;
 }
-#ifndef INLINE_COPY_TO_USER
+#ifndef INLINE_COPY_USER
 extern __must_check unsigned long
 _copy_to_user(void __user *, const void *, unsigned long);
 #endif
@@ -217,7 +217,7 @@ copy_from_user(void *to, const void __user *from, unsigned long n)
 {
 	if (!check_copy_size(to, n, false))
 		return n;
-#ifdef INLINE_COPY_FROM_USER
+#ifdef INLINE_COPY_USER
 	return _inline_copy_from_user(to, from, n);
 #else
 	return _copy_from_user(to, from, n);
@@ -230,7 +230,7 @@ copy_to_user(void __user *to, const void *from, unsigned long n)
 	if (!check_copy_size(from, n, true))
 		return n;
 
-#ifdef INLINE_COPY_TO_USER
+#ifdef INLINE_COPY_USER
 	return _inline_copy_to_user(to, from, n);
 #else
 	return _copy_to_user(to, from, n);
diff --git a/lib/usercopy.c b/lib/usercopy.c
index b00a3a957de6be..e2f0bf104a591b 100644
--- a/lib/usercopy.c
+++ b/lib/usercopy.c
@@ -12,15 +12,13 @@
 
 /* out-of-line parts */
 
-#if !defined(INLINE_COPY_FROM_USER)
+#if !defined(INLINE_COPY_USER)
 unsigned long _copy_from_user(void *to, const void __user *from, unsigned long n)
 {
 	return _inline_copy_from_user(to, from, n);
 }
 EXPORT_SYMBOL(_copy_from_user);
-#endif
 
-#if !defined(INLINE_COPY_TO_USER)
 unsigned long _copy_to_user(void __user *to, const void *from, unsigned long n)
 {
 	return _inline_copy_to_user(to, from, n);
diff --git a/rust/helpers/uaccess.c b/rust/helpers/uaccess.c
index aff22f16ab3884..6e59cc9c665cce 100644
--- a/rust/helpers/uaccess.c
+++ b/rust/helpers/uaccess.c
@@ -14,15 +14,13 @@ rust_helper_copy_to_user(void __user *to, const void *from, unsigned long n)
 	return copy_to_user(to, from, n);
 }
 
-#ifdef INLINE_COPY_FROM_USER
+#ifdef INLINE_COPY_USER
 __rust_helper
 unsigned long rust_helper__copy_from_user(void *to, const void __user *from, unsigned long n)
 {
 	return _inline_copy_from_user(to, from, n);
 }
-#endif
 
-#ifdef INLINE_COPY_TO_USER
 __rust_helper
 unsigned long rust_helper__copy_to_user(void __user *to, const void *from, unsigned long n)
 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0361/2077] uaccess: minimize INLINE_COPY_USER-related ifdefery
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (359 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0360/2077] uaccess: unify inline vs outline copy_{from,to}_user() selection Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0362/2077] rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() Greg Kroah-Hartman
                   ` (636 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yury Norov, Alice Ryhl,
	Arnd Bergmann, Christophe Leroy (CS GROUP), Mathieu Desnoyers,
	Peter Zijlstra, Randy Dunlap, Viktor Malik, Andrew Morton,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yury Norov <ynorov@nvidia.com>

[ Upstream commit bd99fcfc6219ebe36ae4d0bf5333b5ecc17b53df ]

Now that we've got the same config selecting inline vs outline
copy_to_user() and copy_from_user(), we can simplify the corresponding
logic in the uaccess.h.

Link: https://lore.kernel.org/20260425020857.356850-4-ynorov@nvidia.com
Fixes: 1f9a8286bc0c ("uaccess: always export _copy_[from|to]_user with CONFIG_RUST")
Signed-off-by: Yury Norov <ynorov@nvidia.com>
Tested-by: Alice Ryhl <aliceryhl@google.com>
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Randy Dunlap <rdunlap@infradead.org>
Cc: Viktor Malik <vmalik@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/uaccess.h | 21 +++++++--------------
 1 file changed, 7 insertions(+), 14 deletions(-)

diff --git a/include/linux/uaccess.h b/include/linux/uaccess.h
index add9ceea7b1edb..9d39b640f0674b 100644
--- a/include/linux/uaccess.h
+++ b/include/linux/uaccess.h
@@ -190,10 +190,6 @@ _inline_copy_from_user(void *to, const void __user *from, unsigned long n)
 	memset(to + (n - res), 0, res);
 	return res;
 }
-#ifndef INLINE_COPY_USER
-extern __must_check unsigned long
-_copy_from_user(void *, const void __user *, unsigned long);
-#endif
 
 static inline __must_check unsigned long
 _inline_copy_to_user(void __user *to, const void *from, unsigned long n)
@@ -207,7 +203,13 @@ _inline_copy_to_user(void __user *to, const void *from, unsigned long n)
 	}
 	return n;
 }
-#ifndef INLINE_COPY_USER
+#ifdef INLINE_COPY_USER
+# define _copy_to_user _inline_copy_to_user
+# define _copy_from_user _inline_copy_from_user
+#else
+extern __must_check unsigned long
+_copy_from_user(void *, const void __user *, unsigned long);
+
 extern __must_check unsigned long
 _copy_to_user(void __user *, const void *, unsigned long);
 #endif
@@ -217,11 +219,7 @@ copy_from_user(void *to, const void __user *from, unsigned long n)
 {
 	if (!check_copy_size(to, n, false))
 		return n;
-#ifdef INLINE_COPY_USER
-	return _inline_copy_from_user(to, from, n);
-#else
 	return _copy_from_user(to, from, n);
-#endif
 }
 
 static __always_inline unsigned long __must_check
@@ -229,12 +227,7 @@ copy_to_user(void __user *to, const void *from, unsigned long n)
 {
 	if (!check_copy_size(from, n, true))
 		return n;
-
-#ifdef INLINE_COPY_USER
-	return _inline_copy_to_user(to, from, n);
-#else
 	return _copy_to_user(to, from, n);
-#endif
 }
 
 #ifndef copy_mc_to_kernel
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0362/2077] rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (360 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0361/2077] uaccess: minimize INLINE_COPY_USER-related ifdefery Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0363/2077] ocfs2: dont BUG_ON an invalid journal dinode Greg Kroah-Hartman
                   ` (635 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Alexandre Bounine,
	Chul Kim, Matt Porter, Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dan Carpenter <error27@gmail.com>

[ Upstream commit fc15e3a30ddd950f009c76765331783b9af94a87 ]

With a list_for_each() loop, if we don't find the item we are looking for
in the list, then the loop exits with the iterator, which is "dbell" in
this loop, pointing to invalid memory.

This code uses the "found" variable to determine if we have found the
doorbell we are looking for or not.  However, the problem that the "found"
variable needs to be set to false at the start of each iteration,
otherwise after the first correct doorbell, then everything is marked as
found.

Reset the "found" to false at the start of the iteration and move the
variable inside the loop.

Link: https://lore.kernel.org/af2WHMZiqMwdYveO@stanley.mountain
Fixes: 48618fb4e522 ("RapidIO: add mport driver for Tsi721 bridge")
Signed-off-by: Dan Carpenter <error27@gmail.com>
Cc: Alexandre Bounine <alex.bou9@gmail.com>
Cc: Chul Kim <chul.kim@idt.com>
Cc: Matt Porter <mporter@kernel.crashing.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/rapidio/devices/tsi721.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/rapidio/devices/tsi721.c b/drivers/rapidio/devices/tsi721.c
index 66331e67cf4efc..71b87bf8c31d85 100644
--- a/drivers/rapidio/devices/tsi721.c
+++ b/drivers/rapidio/devices/tsi721.c
@@ -394,7 +394,6 @@ static void tsi721_db_dpc(struct work_struct *work)
 						    idb_work);
 	struct rio_mport *mport;
 	struct rio_dbell *dbell;
-	int found = 0;
 	u32 wr_ptr, rd_ptr;
 	u64 *idb_entry;
 	u32 regval;
@@ -412,6 +411,8 @@ static void tsi721_db_dpc(struct work_struct *work)
 	rd_ptr = ioread32(priv->regs + TSI721_IDQ_RP(IDB_QUEUE)) % IDB_QSIZE;
 
 	while (wr_ptr != rd_ptr) {
+		int found = 0;
+
 		idb_entry = (u64 *)(priv->idb_base +
 					(TSI721_IDB_ENTRY_SIZE * rd_ptr));
 		rd_ptr++;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0363/2077] ocfs2: dont BUG_ON an invalid journal dinode
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (361 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0362/2077] rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0364/2077] ocfs2: kill osb->system_file_mutex lock Greg Kroah-Hartman
                   ` (634 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, ZhengYuan Huang, Joseph Qi,
	Mark Fasheh, Joel Becker, Junxiao Bi, Changwei Ge, Jun Piao,
	Heming Zhao, Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: ZhengYuan Huang <gality369@gmail.com>

[ Upstream commit c0438198c28b1d22c272751af5e717c11d9fa8dd ]

[BUG]
A fuzzed OCFS2 image can corrupt the current slot journal dinode while
mount is still in progress. The mount path first reports the invalid
journal block and then crashes in shutdown:

kernel BUG at fs/ocfs2/journal.c:1034!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:ocfs2_journal_toggle_dirty+0x2d6/0x340 fs/ocfs2/journal.c:1034
Call Trace:
 ocfs2_journal_shutdown+0x414/0xc30 fs/ocfs2/journal.c:1116
 ocfs2_mount_volume fs/ocfs2/super.c:1785 [inline]
 ocfs2_fill_super+0x30a9/0x3cd0 fs/ocfs2/super.c:1083
 get_tree_bdev_flags+0x38b/0x640 fs/super.c:1698
 get_tree_bdev+0x24/0x40 fs/super.c:1721
 ocfs2_get_tree+0x21/0x30 fs/ocfs2/super.c:1184
 vfs_get_tree+0x9a/0x370 fs/super.c:1758
 fc_mount fs/namespace.c:1199 [inline]
 do_new_mount_fc fs/namespace.c:3642 [inline]
 do_new_mount fs/namespace.c:3718 [inline]
 path_mount+0x5b8/0x1ea0 fs/namespace.c:4028
 do_mount fs/namespace.c:4041 [inline]
 __do_sys_mount fs/namespace.c:4229 [inline]
 __se_sys_mount fs/namespace.c:4206 [inline]
 __x64_sys_mount+0x282/0x320 fs/namespace.c:4206
 ...

[CAUSE]
ocfs2_journal_toggle_dirty() used to return -EIO when journal->j_bh no
longer contained a valid dinode, because the startup and shutdown paths
already handled that failure. Commit 10995aa2451a
("ocfs2: Morph the haphazard OCFS2_IS_VALID_DINODE() checks.") changed
the check to a BUG_ON() under the assumption that the journal dinode had
already been validated. That turns an unexpected invalid journal dinode
during mount teardown into a kernel crash instead of a normal mount
failure.

[FIX]
Replace the BUG_ON() with WARN_ON() and return -EIO. This keeps the
invariant warning for debugging, but restores the original behavior of
failing startup or shutdown cleanly instead of panicking the kernel.

Link: https://lore.kernel.org/20260512024115.4036371-1-gality369@gmail.com
Fixes: 10995aa2451a ("ocfs2: Morph the haphazard OCFS2_IS_VALID_DINODE() checks.")
Signed-off-by: ZhengYuan Huang <gality369@gmail.com>
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ocfs2/journal.c | 7 ++-----
 1 file changed, 2 insertions(+), 5 deletions(-)

diff --git a/fs/ocfs2/journal.c b/fs/ocfs2/journal.c
index f9bf3bac085db1..fc54cc798ce352 100644
--- a/fs/ocfs2/journal.c
+++ b/fs/ocfs2/journal.c
@@ -1022,11 +1022,8 @@ static int ocfs2_journal_toggle_dirty(struct ocfs2_super *osb,
 	struct ocfs2_dinode *fe;
 
 	fe = (struct ocfs2_dinode *)bh->b_data;
-
-	/* The journal bh on the osb always comes from ocfs2_journal_init()
-	 * and was validated there inside ocfs2_inode_lock_full().  It's a
-	 * code bug if we mess it up. */
-	BUG_ON(!OCFS2_IS_VALID_DINODE(fe));
+	if (WARN_ON(!OCFS2_IS_VALID_DINODE(fe)))
+		return -EIO;
 
 	flags = le32_to_cpu(fe->id1.journal1.ij_flags);
 	if (dirty)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0364/2077] ocfs2: kill osb->system_file_mutex lock
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (362 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0363/2077] ocfs2: dont BUG_ON an invalid journal dinode Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0365/2077] crypto: hisilicon/qm - disable error report before flr Greg Kroah-Hartman
                   ` (633 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tetsuo Handa, Heming Zhao, Joseph Qi,
	Mark Fasheh, Joel Becker, Junxiao Bi, Changwei Ge, Jun Piao,
	Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>

[ Upstream commit f5b1910e23f1233c8d4185268b2e659df2bc5dbf ]

Commit 43b10a20372d ("ocfs2: avoid system inode ref confusion by adding
mutex lock") tried to avoid a refcount leak caused by allowing multiple
threads to call igrab(inode).  But addition of osb->system_file_mutex made
locking dependency complicated and is causing lockdep to warn about
possibility of AB-BA deadlock.

Since _ocfs2_get_system_file_inode() returns the same inode for the same
input arguments, we don't need to serialize
_ocfs2_get_system_file_inode().  What we need to make sure is that
igrab(inode) is called for only once().  Therefore, replace
osb->system_file_mutex with cmpxchg()-based locking.

Link: https://lore.kernel.org/fea8d1fd-afb0-4302-a560-c202e2ef7afd@I-love.SAKURA.ne.jp
Fixes: 43b10a20372d ("ocfs2: avoid system inode ref confusion by adding mutex lock")
Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Reviewed-by: Heming Zhao <heming.zhao@suse.com>
Acked-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ocfs2/ocfs2.h   | 2 --
 fs/ocfs2/super.c   | 2 --
 fs/ocfs2/sysfile.c | 9 +++------
 3 files changed, 3 insertions(+), 10 deletions(-)

diff --git a/fs/ocfs2/ocfs2.h b/fs/ocfs2/ocfs2.h
index 7b50e03dfa664a..62cad6522c7a31 100644
--- a/fs/ocfs2/ocfs2.h
+++ b/fs/ocfs2/ocfs2.h
@@ -494,8 +494,6 @@ struct ocfs2_super
 	struct rb_root	osb_rf_lock_tree;
 	struct ocfs2_refcount_tree *osb_ref_tree_lru;
 
-	struct mutex system_file_mutex;
-
 	/*
 	 * OCFS2 needs to schedule several different types of work which
 	 * require cluster locking, disk I/O, recovery waits, etc. Since these
diff --git a/fs/ocfs2/super.c b/fs/ocfs2/super.c
index b875f01c97564d..6dd45c2153f88e 100644
--- a/fs/ocfs2/super.c
+++ b/fs/ocfs2/super.c
@@ -1997,8 +1997,6 @@ static int ocfs2_initialize_super(struct super_block *sb,
 	spin_lock_init(&osb->osb_xattr_lock);
 	ocfs2_init_steal_slots(osb);
 
-	mutex_init(&osb->system_file_mutex);
-
 	atomic_set(&osb->alloc_stats.moves, 0);
 	atomic_set(&osb->alloc_stats.local_data, 0);
 	atomic_set(&osb->alloc_stats.bitmap_data, 0);
diff --git a/fs/ocfs2/sysfile.c b/fs/ocfs2/sysfile.c
index d53a6cc866bef6..67e492f4b828b6 100644
--- a/fs/ocfs2/sysfile.c
+++ b/fs/ocfs2/sysfile.c
@@ -98,11 +98,9 @@ struct inode *ocfs2_get_system_file_inode(struct ocfs2_super *osb,
 	} else
 		arr = get_local_system_inode(osb, type, slot);
 
-	mutex_lock(&osb->system_file_mutex);
 	if (arr && ((inode = *arr) != NULL)) {
 		/* get a ref in addition to the array ref */
 		inode = igrab(inode);
-		mutex_unlock(&osb->system_file_mutex);
 		BUG_ON(!inode);
 
 		return inode;
@@ -112,11 +110,10 @@ struct inode *ocfs2_get_system_file_inode(struct ocfs2_super *osb,
 	inode = _ocfs2_get_system_file_inode(osb, type, slot);
 
 	/* add one more if putting into array for first time */
-	if (arr && inode) {
-		*arr = igrab(inode);
-		BUG_ON(!*arr);
+	if (inode && arr && !*arr && !cmpxchg(&(*arr), NULL, inode)) {
+		inode = igrab(inode);
+		BUG_ON(!inode);
 	}
-	mutex_unlock(&osb->system_file_mutex);
 	return inode;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0365/2077] crypto: hisilicon/qm - disable error report before flr
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (363 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0364/2077] ocfs2: kill osb->system_file_mutex lock Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0366/2077] crypto: inside-secure/eip93 - Add check for devm_request_threaded_irq Greg Kroah-Hartman
                   ` (632 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Weili Qian, Zongyu Wu, Herbert Xu,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Weili Qian <qianweili@huawei.com>

[ Upstream commit e71dc5602b9a29027f6aedd5990d3e8c4f638c8c ]

Before function level reset, driver first disable device error report
and then waits for the device reset to complete. However, when the
error is recovered, the error bits will be enabled again, resulting in
invalid disable. It is modified to detect that there is no error
before disable error report, and then do FLR.

Fixes: 7ce396fa12a9 ("crypto: hisilicon - add FLR support")
Signed-off-by: Weili Qian <qianweili@huawei.com>
Signed-off-by: Zongyu Wu <wuzongyu1@huawei.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/hisilicon/qm.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/crypto/hisilicon/qm.c b/drivers/crypto/hisilicon/qm.c
index 3ca47e2a9719f1..26e2ccb70c2ae0 100644
--- a/drivers/crypto/hisilicon/qm.c
+++ b/drivers/crypto/hisilicon/qm.c
@@ -4917,8 +4917,6 @@ void hisi_qm_reset_prepare(struct pci_dev *pdev)
 	u32 delay = 0;
 	int ret;
 
-	hisi_qm_dev_err_uninit(pf_qm);
-
 	/*
 	 * Check whether there is an ECC mbit error, If it occurs, need to
 	 * wait for soft reset to fix it.
@@ -4935,6 +4933,8 @@ void hisi_qm_reset_prepare(struct pci_dev *pdev)
 		return;
 	}
 
+	hisi_qm_dev_err_uninit(pf_qm);
+
 	/* PF obtains the information of VF by querying the register. */
 	if (qm->fun_type == QM_HW_PF)
 		qm_cmd_uninit(qm);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0366/2077] crypto: inside-secure/eip93 - Add check for devm_request_threaded_irq
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (364 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0365/2077] crypto: hisilicon/qm - disable error report before flr Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0367/2077] crypto: tegra - Fix dma_free_coherent size error Greg Kroah-Hartman
                   ` (631 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Aleksander Jan Bajkowski, Herbert Xu,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aleksander Jan Bajkowski <olek2@wp.pl>

[ Upstream commit 85a61bf9145d4097c740ffcf3aa832d930a8913b ]

As the potential failure of the devm_request_threaded_irq(),
it should be better to check the return value and return
error if fails.

Fixes: 9739f5f93b78 ("crypto: eip93 - Add Inside Secure SafeXcel EIP-93 crypto engine support")
Signed-off-by: Aleksander Jan Bajkowski <olek2@wp.pl>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/inside-secure/eip93/eip93-main.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/crypto/inside-secure/eip93/eip93-main.c b/drivers/crypto/inside-secure/eip93/eip93-main.c
index 7dccfdeb7b11c0..276839e1a515fc 100644
--- a/drivers/crypto/inside-secure/eip93/eip93-main.c
+++ b/drivers/crypto/inside-secure/eip93/eip93-main.c
@@ -433,6 +433,8 @@ static int eip93_crypto_probe(struct platform_device *pdev)
 	ret = devm_request_threaded_irq(eip93->dev, eip93->irq, eip93_irq_handler,
 					NULL, IRQF_ONESHOT,
 					dev_name(eip93->dev), eip93);
+	if (ret)
+		return ret;
 
 	eip93->ring = devm_kcalloc(eip93->dev, 1, sizeof(*eip93->ring), GFP_KERNEL);
 	if (!eip93->ring)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0367/2077] crypto: tegra - Fix dma_free_coherent size error
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (365 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0366/2077] crypto: inside-secure/eip93 - Add check for devm_request_threaded_irq Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0368/2077] crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm Greg Kroah-Hartman
                   ` (630 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Herbert Xu, Vladislav Dronov,
	Sasha Levin, Patrick Talbert

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

[ Upstream commit 03215b8457784540acc741e6331e355b62c6c8ab ]

When freeing a coherent DMA buffer, the size must match the value
that was used during the allocation.

Unfortunately the size field in the tegra driver gets overwritten
by this point so it no longer matches and creates a warning.

Fix this by saving a copy of the size on the stack.

Note that the ccm function actually mixes up the inbuf and outbuf
sizes, but it doesn't matter because the two sizes are actually
equal.

Fixes: 1cb328da4e8f ("crypto: tegra - Do not use fixed size buffers")
Reporeted-by: Patrick Talbert <ptalbert@redhat.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Reviewed-by: Vladislav Dronov <vdronov@redhat.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/tegra/tegra-se-aes.c | 28 ++++++++++++++++------------
 1 file changed, 16 insertions(+), 12 deletions(-)

diff --git a/drivers/crypto/tegra/tegra-se-aes.c b/drivers/crypto/tegra/tegra-se-aes.c
index 30c78afe3dea63..5086e7f140c303 100644
--- a/drivers/crypto/tegra/tegra-se-aes.c
+++ b/drivers/crypto/tegra/tegra-se-aes.c
@@ -1201,6 +1201,7 @@ static int tegra_ccm_do_one_req(struct crypto_engine *engine, void *areq)
 	struct crypto_aead *tfm = crypto_aead_reqtfm(req);
 	struct tegra_aead_ctx *ctx = crypto_aead_ctx(tfm);
 	struct tegra_se *se = ctx->se;
+	unsigned int bufsize;
 	int ret;
 
 	ret = tegra_ccm_crypt_init(req, se, rctx);
@@ -1210,14 +1211,15 @@ static int tegra_ccm_do_one_req(struct crypto_engine *engine, void *areq)
 	rctx->key_id = ctx->key_id;
 
 	/* Allocate buffers required */
-	rctx->inbuf.size = rctx->assoclen + rctx->authsize + rctx->cryptlen + 100;
-	rctx->inbuf.buf = dma_alloc_coherent(ctx->se->dev, rctx->inbuf.size,
+	bufsize = rctx->assoclen + rctx->authsize + rctx->cryptlen + 100;
+	rctx->inbuf.size = bufsize;
+	rctx->inbuf.buf = dma_alloc_coherent(ctx->se->dev, bufsize,
 					     &rctx->inbuf.addr, GFP_KERNEL);
 	if (!rctx->inbuf.buf)
 		goto out_finalize;
 
-	rctx->outbuf.size = rctx->assoclen + rctx->authsize + rctx->cryptlen + 100;
-	rctx->outbuf.buf = dma_alloc_coherent(ctx->se->dev, rctx->outbuf.size,
+	rctx->outbuf.size = bufsize;
+	rctx->outbuf.buf = dma_alloc_coherent(ctx->se->dev, bufsize,
 					      &rctx->outbuf.addr, GFP_KERNEL);
 	if (!rctx->outbuf.buf) {
 		ret = -ENOMEM;
@@ -1254,11 +1256,11 @@ static int tegra_ccm_do_one_req(struct crypto_engine *engine, void *areq)
 	}
 
 out:
-	dma_free_coherent(ctx->se->dev, rctx->inbuf.size,
+	dma_free_coherent(ctx->se->dev, bufsize,
 			  rctx->outbuf.buf, rctx->outbuf.addr);
 
 out_free_inbuf:
-	dma_free_coherent(ctx->se->dev, rctx->outbuf.size,
+	dma_free_coherent(ctx->se->dev, bufsize,
 			  rctx->inbuf.buf, rctx->inbuf.addr);
 
 	if (tegra_key_is_reserved(rctx->key_id))
@@ -1278,6 +1280,7 @@ static int tegra_gcm_do_one_req(struct crypto_engine *engine, void *areq)
 	struct crypto_aead *tfm = crypto_aead_reqtfm(req);
 	struct tegra_aead_ctx *ctx = crypto_aead_ctx(tfm);
 	struct tegra_aead_reqctx *rctx = aead_request_ctx(req);
+	unsigned int bufsize;
 	int ret;
 
 	rctx->src_sg = req->src;
@@ -1296,16 +1299,17 @@ static int tegra_gcm_do_one_req(struct crypto_engine *engine, void *areq)
 	rctx->key_id = ctx->key_id;
 
 	/* Allocate buffers required */
-	rctx->inbuf.size = rctx->assoclen + rctx->authsize + rctx->cryptlen;
-	rctx->inbuf.buf = dma_alloc_coherent(ctx->se->dev, rctx->inbuf.size,
+	bufsize = rctx->assoclen + rctx->authsize + rctx->cryptlen;
+	rctx->inbuf.size = bufsize;
+	rctx->inbuf.buf = dma_alloc_coherent(ctx->se->dev, bufsize,
 					     &rctx->inbuf.addr, GFP_KERNEL);
 	if (!rctx->inbuf.buf) {
 		ret = -ENOMEM;
 		goto out_finalize;
 	}
 
-	rctx->outbuf.size = rctx->assoclen + rctx->authsize + rctx->cryptlen;
-	rctx->outbuf.buf = dma_alloc_coherent(ctx->se->dev, rctx->outbuf.size,
+	rctx->outbuf.size = bufsize;
+	rctx->outbuf.buf = dma_alloc_coherent(ctx->se->dev, bufsize,
 					      &rctx->outbuf.addr, GFP_KERNEL);
 	if (!rctx->outbuf.buf) {
 		ret = -ENOMEM;
@@ -1342,11 +1346,11 @@ static int tegra_gcm_do_one_req(struct crypto_engine *engine, void *areq)
 		ret = tegra_gcm_do_verify(ctx->se, rctx);
 
 out:
-	dma_free_coherent(ctx->se->dev, rctx->outbuf.size,
+	dma_free_coherent(ctx->se->dev, bufsize,
 			  rctx->outbuf.buf, rctx->outbuf.addr);
 
 out_free_inbuf:
-	dma_free_coherent(ctx->se->dev, rctx->inbuf.size,
+	dma_free_coherent(ctx->se->dev, bufsize,
 			  rctx->inbuf.buf, rctx->inbuf.addr);
 
 	if (tegra_key_is_reserved(rctx->key_id))
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0368/2077] crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (366 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0367/2077] crypto: tegra - Fix dma_free_coherent size error Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0369/2077] crypto: ccp/tsm - Enable the root port after the endpoint Greg Kroah-Hartman
                   ` (629 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Vladislav Dronov, Herbert Xu,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

[ Upstream commit 690a5f9e5c972a580565ce544ed1627ccf1e84de ]

Ensure the ENOMEM error value is set when the input buffer allocation
fails in tegra_ccm_do_one_req.

Fixes: 1e245948ca0c ("crypto: tegra - finalize crypto req on error")
Reported-by: Vladislav Dronov <vdronov@redhat.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Reviewed-by: Vladislav Dronov <vdronov@redhat.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/tegra/tegra-se-aes.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/drivers/crypto/tegra/tegra-se-aes.c b/drivers/crypto/tegra/tegra-se-aes.c
index 5086e7f140c303..9094c03e991f65 100644
--- a/drivers/crypto/tegra/tegra-se-aes.c
+++ b/drivers/crypto/tegra/tegra-se-aes.c
@@ -1215,16 +1215,15 @@ static int tegra_ccm_do_one_req(struct crypto_engine *engine, void *areq)
 	rctx->inbuf.size = bufsize;
 	rctx->inbuf.buf = dma_alloc_coherent(ctx->se->dev, bufsize,
 					     &rctx->inbuf.addr, GFP_KERNEL);
+	ret = -ENOMEM;
 	if (!rctx->inbuf.buf)
 		goto out_finalize;
 
 	rctx->outbuf.size = bufsize;
 	rctx->outbuf.buf = dma_alloc_coherent(ctx->se->dev, bufsize,
 					      &rctx->outbuf.addr, GFP_KERNEL);
-	if (!rctx->outbuf.buf) {
-		ret = -ENOMEM;
+	if (!rctx->outbuf.buf)
 		goto out_free_inbuf;
-	}
 
 	if (!ctx->key_id) {
 		ret = tegra_key_submit_reserved_aes(ctx->se, ctx->key,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0369/2077] crypto: ccp/tsm - Enable the root port after the endpoint
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (367 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0368/2077] crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0370/2077] sched/deadline: Reject debugfs dl_server writes for offline CPUs Greg Kroah-Hartman
                   ` (628 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alexey Kardashevskiy, Herbert Xu,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexey Kardashevskiy <aik@amd.com>

[ Upstream commit 50e506201bab875545c7a9443bd7e1c71804e553 ]

The PCIe r7.0, chapter "6.33.8 Other IDE Rules" mandates if selective IDE
is enabled for config requersts, a stream must be enabled on the endpoint
before enabling it on the rootport:

===
For Selective IDE, the Stream must not be used until it has been enabled in
both Partner Ports. For cases where one of the Partner Ports is a Root Port
and Selective IDE for Configuration Requests is enabled, the other
Partner Port must be enabled prior to the Root Port. For other scenarios,
the mechanisms to satisfy this requirement are implementation-specific.
===

Do what the spec says.

Fixes: 4be423572da1 ("crypto/ccp: Implement SEV-TIO PCIe IDE (phase1)")
Signed-off-by: Alexey Kardashevskiy <aik@amd.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/ccp/sev-dev-tsm.c | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

diff --git a/drivers/crypto/ccp/sev-dev-tsm.c b/drivers/crypto/ccp/sev-dev-tsm.c
index f303d8f55991b5..46f2539d2d5ab2 100644
--- a/drivers/crypto/ccp/sev-dev-tsm.c
+++ b/drivers/crypto/ccp/sev-dev-tsm.c
@@ -58,13 +58,13 @@ static int stream_enable(struct pci_ide *ide)
 	struct pci_dev *rp = pcie_find_root_port(ide->pdev);
 	int ret;
 
-	ret = pci_ide_stream_enable(rp, ide);
-	if (ret)
+	ret = pci_ide_stream_enable(ide->pdev, ide);
+	if (ret && ret != -ENXIO)
 		return ret;
 
-	ret = pci_ide_stream_enable(ide->pdev, ide);
-	if (ret)
-		pci_ide_stream_disable(rp, ide);
+	ret = pci_ide_stream_enable(rp, ide);
+	if (ret && ret != -ENXIO)
+		pci_ide_stream_disable(ide->pdev, ide);
 
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0370/2077] sched/deadline: Reject debugfs dl_server writes for offline CPUs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (368 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0369/2077] crypto: ccp/tsm - Enable the root port after the endpoint Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0371/2077] drm/msm/dp: fix HPD state status bit shift value Greg Kroah-Hartman
                   ` (627 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Andrea Righi,
	Peter Zijlstra (Intel), Juri Lelli, abaci-kreproducer,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Andrea Righi <arighi@nvidia.com>

[ Upstream commit 4043f549841619a01999bf5d4e0b7931ef87f6cc ]

Writing runtime or period via the per-CPU dl_server debugfs files
(/sys/kernel/debug/sched/{fair,ext}_server/cpu*/{runtime,period}) on an
offline CPU can trigger two distinct kernel issues:

1) Divide-by-zero in dl_server_apply_params():

  Oops: divide error: 0000 [#1] SMP NOPTI
  RIP: 0010:dl_server_apply_params+0x239/0x3a0
  Call Trace:
   sched_server_write_common.isra.0+0x21a/0x3c0
   full_proxy_write+0x78/0xd0
   vfs_write+0xe7/0x6e0

  Both __dl_sub() and __dl_add() divide by cpus internally, which can be
  0 once the CPU has been removed from any active root-domain span (this
  has been latent since the debugfs interface was introduced).

2) WARN_ON_ONCE in dl_server_start():

  WARNING: kernel/sched/deadline.c:1805 at dl_server_start+0x232/0x270

  Commit ee6e44dfe6e5 ("sched/deadline: Stop dl_server before CPU goes
  offline") added this check to catch enqueueing the server on an
  offline rq.

There's no meaningful semantics for re-configuring the per-CPU dl_server
bandwidth while the CPU is offline, so simply reject the write with
-EBUSY so userspace gets a clear error.

Closes: https://lore.kernel.org/all/20260526092228.3B6891F00A3A@smtp.kernel.org/
Fixes: d741f297bcea ("sched/fair: Fair server interface")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Andrea Righi <arighi@nvidia.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Juri Lelli <juri.lelli@redhat.com>
Tested-by: abaci-kreproducer <abaci@linux.alibaba.com>
Link: https://patch.msgid.link/20260526100502.575774-1-arighi@nvidia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/sched/debug.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/kernel/sched/debug.c b/kernel/sched/debug.c
index 74c1617cf65234..6f74bde684376e 100644
--- a/kernel/sched/debug.c
+++ b/kernel/sched/debug.c
@@ -373,6 +373,9 @@ static ssize_t sched_server_write_common(struct file *filp, const char __user *u
 			return  -EINVAL;
 		}
 
+		if (!cpu_online(cpu_of(rq)))
+			return -EBUSY;
+
 		update_rq_clock(rq);
 		dl_server_stop(dl_se);
 		retval = dl_server_apply_params(dl_se, runtime, period, 0);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0371/2077] drm/msm/dp: fix HPD state status bit shift value
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (369 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0370/2077] sched/deadline: Reject debugfs dl_server writes for offline CPUs Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0372/2077] drm/msm/dp: Fix the ISR_* enum values Greg Kroah-Hartman
                   ` (626 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jessica Zhang, Konrad Dybcio,
	Dmitry Baryshkov, Sasha Levin, Val Packett, Yongxing Mou

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jessica Zhang <jessica.zhang@oss.qualcomm.com>

[ Upstream commit 2e6c2e81d81251623c458a60e2a57447dcbc988e ]

The HPD state status is the 3 most significant bits, not 4 bits of the
HPD_INT_STATUS register.

Fix the bit shift macro so that the correct bits are returned in
msm_dp_aux_is_link_connected().

Fixes: 19e52bcb27c2 ("drm/msm/dp: return correct connection status after suspend")
Signed-off-by: Jessica Zhang <jessica.zhang@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Tested-by: Val Packett <val@packett.cool> # x1e80100-dell-latitude-7455
Tested-by: Yongxing Mou <yongxing.mou@oss.qualcomm.com> # Hamoa IOT EVK, QCS8300 Ride
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/727611/
Link: https://lore.kernel.org/r/20260524-hpd-refactor-v6-1-cf3ab488dd7b@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/msm/dp/dp_reg.h | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/msm/dp/dp_reg.h b/drivers/gpu/drm/msm/dp/dp_reg.h
index 7c44d4e2cf1396..3689642b7fc061 100644
--- a/drivers/gpu/drm/msm/dp/dp_reg.h
+++ b/drivers/gpu/drm/msm/dp/dp_reg.h
@@ -68,8 +68,8 @@
 #define DP_DP_IRQ_HPD_INT_ACK			(0x00000002)
 #define DP_DP_HPD_REPLUG_INT_ACK		(0x00000004)
 #define DP_DP_HPD_UNPLUG_INT_ACK		(0x00000008)
-#define DP_DP_HPD_STATE_STATUS_BITS_MASK	(0x0000000F)
-#define DP_DP_HPD_STATE_STATUS_BITS_SHIFT	(0x1C)
+#define DP_DP_HPD_STATE_STATUS_BITS_MASK	(0x00000007)
+#define DP_DP_HPD_STATE_STATUS_BITS_SHIFT	(0x1D)
 
 #define REG_DP_DP_HPD_INT_MASK			(0x0000000C)
 #define DP_DP_HPD_PLUG_INT_MASK			(0x00000001)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0372/2077] drm/msm/dp: Fix the ISR_* enum values
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (370 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0371/2077] drm/msm/dp: fix HPD state status bit shift value Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0373/2077] firmware: samsung: acpm: Add devm_acpm_get_by_phandle helper Greg Kroah-Hartman
                   ` (625 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jessica Zhang, Konrad Dybcio,
	Dmitry Baryshkov, Sasha Levin, Val Packett, Yongxing Mou

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jessica Zhang <jessica.zhang@oss.qualcomm.com>

[ Upstream commit 3fbfdc3b1d48cc115a86953e5df0c76cd2efc42b ]

The ISR_HPD_* enum should represent values that can be read from the
REG_DP_DP_HPD_INT_STATUS register. Swap ISR_HPD_IO_GLITCH_COUNT and
ISR_HPD_REPLUG_COUNT to map them correctly to register values.

While we are at it, correct the spelling for ISR_HPD_REPLUG_COUNT.

Fixes: 8ede2ecc3e5e ("drm/msm/dp: Add DP compliance tests on Snapdragon Chipsets")
Signed-off-by: Jessica Zhang <jessica.zhang@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Tested-by: Val Packett <val@packett.cool> # x1e80100-dell-latitude-7455
Tested-by: Yongxing Mou <yongxing.mou@oss.qualcomm.com> # Hamoa IOT EVK, QCS8300 Ride
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/727602/
Link: https://lore.kernel.org/r/20260524-hpd-refactor-v6-2-cf3ab488dd7b@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/msm/dp/dp_display.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/msm/dp/dp_display.c b/drivers/gpu/drm/msm/dp/dp_display.c
index d2124d6254855b..cf2415635c426f 100644
--- a/drivers/gpu/drm/msm/dp/dp_display.c
+++ b/drivers/gpu/drm/msm/dp/dp_display.c
@@ -38,9 +38,9 @@ enum {
 	ISR_DISCONNECTED,
 	ISR_CONNECT_PENDING,
 	ISR_CONNECTED,
-	ISR_HPD_REPLUG_COUNT,
+	ISR_HPD_IO_GLITCH_COUNT,
 	ISR_IRQ_HPD_PULSE_COUNT,
-	ISR_HPD_LO_GLITH_COUNT,
+	ISR_HPD_REPLUG_COUNT,
 };
 
 /* event thread connection state */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0373/2077] firmware: samsung: acpm: Add devm_acpm_get_by_phandle helper
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (371 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0372/2077] drm/msm/dp: Fix the ISR_* enum values Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0374/2077] firmware: samsung: acpm: remove compile-testing stubs Greg Kroah-Hartman
                   ` (624 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tudor Ambarus, Peter Griffin,
	Krzysztof Kozlowski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tudor Ambarus <tudor.ambarus@linaro.org>

[ Upstream commit fc13a4b9b9c8cb0b8e5ba54b21712d00f810496c ]

Introduce devm_acpm_get_by_phandle() to standardize how consumer
drivers acquire a handle to the ACPM IPC interface. Enforce the
use of the "samsung,acpm-ipc" property name across the SoC and
simplify the boilerplate code in client drivers.

The first consumer of this helper is the Exynos ACPM Thermal Management
Unit (TMU) driver. The TMU utilizes a hybrid management approach: direct
register access from the Application Processor (AP) is restricted to the
interrupt pending (INTPEND) registers for event identification.
High-level functional tasks, such as sensor initialization, threshold
programming, and temperature reads, are delegated to the ACPM firmware
via this IPC interface.

Signed-off-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Reviewed-by: Peter Griffin <peter.griffin@linaro.org>
Link: https://patch.msgid.link/20260515-acpm-tmu-helpers-v2-6-8ca011d5a965@linaro.org
Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Stable-dep-of: 7b661285aa75 ("firmware: samsung: acpm: remove compile-testing stubs")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/firmware/samsung/exynos-acpm.c        | 23 +++++++++++++++++++
 .../firmware/samsung/exynos-acpm-protocol.h   |  6 +++++
 2 files changed, 29 insertions(+)

diff --git a/drivers/firmware/samsung/exynos-acpm.c b/drivers/firmware/samsung/exynos-acpm.c
index 19db3674a28f3e..65949e7fd430d9 100644
--- a/drivers/firmware/samsung/exynos-acpm.c
+++ b/drivers/firmware/samsung/exynos-acpm.c
@@ -819,6 +819,29 @@ struct acpm_handle *devm_acpm_get_by_node(struct device *dev,
 }
 EXPORT_SYMBOL_GPL(devm_acpm_get_by_node);
 
+/**
+ * devm_acpm_get_by_phandle - Resource managed lookup of the standardized
+ * "samsung,acpm-ipc" handle.
+ * @dev: consumer device
+ *
+ * Return: pointer to handle on success, ERR_PTR(-errno) otherwise.
+ */
+struct acpm_handle *devm_acpm_get_by_phandle(struct device *dev)
+{
+	struct acpm_handle *handle;
+	struct device_node *np;
+
+	np = of_parse_phandle(dev->of_node, "samsung,acpm-ipc", 0);
+	if (!np)
+		return ERR_PTR(-ENODEV);
+
+	handle = devm_acpm_get_by_node(dev, np);
+	of_node_put(np);
+
+	return handle;
+}
+EXPORT_SYMBOL_GPL(devm_acpm_get_by_phandle);
+
 static const struct acpm_match_data acpm_gs101 = {
 	.initdata_base = ACPM_GS101_INITDATA_BASE,
 	.acpm_clk_dev_name = "gs101-acpm-clk",
diff --git a/include/linux/firmware/samsung/exynos-acpm-protocol.h b/include/linux/firmware/samsung/exynos-acpm-protocol.h
index 13f17dc4443b8f..596d17f0384f43 100644
--- a/include/linux/firmware/samsung/exynos-acpm-protocol.h
+++ b/include/linux/firmware/samsung/exynos-acpm-protocol.h
@@ -52,6 +52,7 @@ struct device;
 #if IS_ENABLED(CONFIG_EXYNOS_ACPM_PROTOCOL)
 struct acpm_handle *devm_acpm_get_by_node(struct device *dev,
 					  struct device_node *np);
+struct acpm_handle *devm_acpm_get_by_phandle(struct device *dev);
 #else
 
 static inline struct acpm_handle *devm_acpm_get_by_node(struct device *dev,
@@ -59,6 +60,11 @@ static inline struct acpm_handle *devm_acpm_get_by_node(struct device *dev,
 {
 	return NULL;
 }
+
+static inline struct acpm_handle *devm_acpm_get_by_phandle(struct device *dev)
+{
+	return ERR_PTR(-ENODEV);
+}
 #endif
 
 #endif /* __EXYNOS_ACPM_PROTOCOL_H */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0374/2077] firmware: samsung: acpm: remove compile-testing stubs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (372 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0373/2077] firmware: samsung: acpm: Add devm_acpm_get_by_phandle helper Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0375/2077] drm/msm/a8xx: Make a8xx_recover IFPC safe Greg Kroah-Hartman
                   ` (623 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tudor Ambarus, Arnd Bergmann,
	Krzysztof Kozlowski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

[ Upstream commit 7b661285aa7507eab79efff0a418445157db4141 ]

Sashiko reported an inconsistent use of NULL vs ERR_PTR()
returns in the stub helpers in xynos-acpm-protocol.h.

Since this only happens on dead code for COMPILE_TEST=y, this is not
really a bug though.  Having stub functions that return NULL is a common
way to define optional interfaces, where callers still work when the
feature is disabled, though this clearly does not work for acpm because
some callers have a NULL pointer dereference when compile testing.

Since CONFIG_EXYNOS_ACPM_PROTOCOL already supports compile-testing itself,
and all (both) drivers using it clearly require the support, so this
just simplifies the option space without losing any build coverage.

Remove the stub functions entirely and adjust the one Kconfig
dependency to require EXYNOS_ACPM_PROTOCOL unconditionally.

Fixes: 6837c006d4e7 ("firmware: exynos-acpm: add empty method to allow compile test")
Closes: https://sashiko.dev/#/patchset/20260420-acpm-tmu-v3-0-3dc8e93f0b26%40linaro.org
Link: https://lore.kernel.org/all/a7994860-24a3-4f87-84bf-109ed653dda4@linaro.org/
Reviewed-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Link: https://patch.msgid.link/20260529134454.2147446-1-arnd@kernel.org
[krzk: Rebase on difference in devm_acpm_get_by_node()]
Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clk/samsung/Kconfig                        |  2 +-
 .../linux/firmware/samsung/exynos-acpm-protocol.h  | 14 --------------
 2 files changed, 1 insertion(+), 15 deletions(-)

diff --git a/drivers/clk/samsung/Kconfig b/drivers/clk/samsung/Kconfig
index 70a8b82a0136b4..198d8b62128931 100644
--- a/drivers/clk/samsung/Kconfig
+++ b/drivers/clk/samsung/Kconfig
@@ -97,7 +97,7 @@ config EXYNOS_CLKOUT
 
 config EXYNOS_ACPM_CLK
 	tristate "Clock driver controlled via ACPM interface"
-	depends on EXYNOS_ACPM_PROTOCOL || (COMPILE_TEST && !EXYNOS_ACPM_PROTOCOL)
+	depends on EXYNOS_ACPM_PROTOCOL
 	help
 	  This driver provides support for clocks that are controlled by
 	  firmware that implements the ACPM interface.
diff --git a/include/linux/firmware/samsung/exynos-acpm-protocol.h b/include/linux/firmware/samsung/exynos-acpm-protocol.h
index 596d17f0384f43..24eacc7c16d25c 100644
--- a/include/linux/firmware/samsung/exynos-acpm-protocol.h
+++ b/include/linux/firmware/samsung/exynos-acpm-protocol.h
@@ -49,22 +49,8 @@ struct acpm_handle {
 
 struct device;
 
-#if IS_ENABLED(CONFIG_EXYNOS_ACPM_PROTOCOL)
 struct acpm_handle *devm_acpm_get_by_node(struct device *dev,
 					  struct device_node *np);
 struct acpm_handle *devm_acpm_get_by_phandle(struct device *dev);
-#else
-
-static inline struct acpm_handle *devm_acpm_get_by_node(struct device *dev,
-							struct device_node *np)
-{
-	return NULL;
-}
-
-static inline struct acpm_handle *devm_acpm_get_by_phandle(struct device *dev)
-{
-	return ERR_PTR(-ENODEV);
-}
-#endif
 
 #endif /* __EXYNOS_ACPM_PROTOCOL_H */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0375/2077] drm/msm/a8xx: Make a8xx_recover IFPC safe
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (373 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0374/2077] firmware: samsung: acpm: remove compile-testing stubs Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0376/2077] drm/msm/a8xx: Fix RSCC offset Greg Kroah-Hartman
                   ` (622 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Akhil P Oommen, Konrad Dybcio,
	Taniya Das, Rob Clark, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Akhil P Oommen <akhilpo@oss.qualcomm.com>

[ Upstream commit e7c45d9838b7487c1846a0202c649336b2f5bf87 ]

Similar to a6xx_recover(), check the GX power domain status before
accessing mmio in GX domain a8xx_recover().

Fixes: 288a93200892 ("drm/msm/adreno: Introduce A8x GPU Support")
Signed-off-by: Akhil P Oommen <akhilpo@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Taniya Das <taniya.das@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/720977/
Message-ID: <20260427-gfx-clk-fixes-v2-5-797e54b3d464@oss.qualcomm.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/msm/adreno/a8xx_gpu.c | 15 ++++++++++-----
 1 file changed, 10 insertions(+), 5 deletions(-)

diff --git a/drivers/gpu/drm/msm/adreno/a8xx_gpu.c b/drivers/gpu/drm/msm/adreno/a8xx_gpu.c
index ccfccc45133fda..9b99ec5ceeb582 100644
--- a/drivers/gpu/drm/msm/adreno/a8xx_gpu.c
+++ b/drivers/gpu/drm/msm/adreno/a8xx_gpu.c
@@ -886,17 +886,22 @@ void a8xx_recover(struct msm_gpu *gpu)
 
 	adreno_dump_info(gpu);
 
-	if (hang_debug)
-		a8xx_dump(gpu);
-
 	/*
 	 * To handle recovery specific sequences during the rpm suspend we are
 	 * about to trigger
 	 */
 	a6xx_gpu->hung = true;
 
-	/* Halt SQE first */
-	gpu_write(gpu, REG_A8XX_CP_SQE_CNTL, 3);
+	if (adreno_gpu->funcs->gx_is_on(adreno_gpu)) {
+		/*
+		 * Sometimes crashstate capture is skipped, so SQE should be
+		 * halted here again
+		 */
+		gpu_write(gpu, REG_A8XX_CP_SQE_CNTL, 3);
+
+		if (hang_debug)
+			a8xx_dump(gpu);
+	}
 
 	pm_runtime_dont_use_autosuspend(&gpu->pdev->dev);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0376/2077] drm/msm/a8xx: Fix RSCC offset
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (374 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0375/2077] drm/msm/a8xx: Make a8xx_recover IFPC safe Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0377/2077] EDAC/igen6: Fix call trace due to missing release() Greg Kroah-Hartman
                   ` (621 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Akhil P Oommen, Rob Clark,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Akhil P Oommen <akhilpo@oss.qualcomm.com>

[ Upstream commit 586a34dafc08c4fa68d1b4673de24cd84d09df05 ]

In A8xx, the RSCC block is part of GPU's register space. Update the
virtual base address of rscc to point to the correct address.

Fixes: 50e8a557d8d3 ("drm/msm/a8xx: Add support for A8x GMU")
Signed-off-by: Akhil P Oommen <akhilpo@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/727117/
Message-ID: <20260522-glymur-gpu-dt-v5-1-562c406b210c@oss.qualcomm.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/msm/adreno/a6xx_gmu.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/msm/adreno/a6xx_gmu.c b/drivers/gpu/drm/msm/adreno/a6xx_gmu.c
index 1b44b9e21ad868..cab4c46c6cf2ea 100644
--- a/drivers/gpu/drm/msm/adreno/a6xx_gmu.c
+++ b/drivers/gpu/drm/msm/adreno/a6xx_gmu.c
@@ -2357,7 +2357,12 @@ int a6xx_gmu_init(struct a6xx_gpu *a6xx_gpu, struct device_node *node)
 			goto err_mmio;
 		}
 	} else if (adreno_is_a8xx(adreno_gpu)) {
-		gmu->rscc = gmu->mmio + 0x19000;
+		/*
+		 * On a8xx , RSCC lives at GPU base + 0x50000, which falls
+		 * inside the GPU's kgsl_3d0_reg_memory range rather than the
+		 * GMU's.
+		 */
+		gmu->rscc = gpu->mmio + 0x50000;
 	} else {
 		gmu->rscc = gmu->mmio + 0x23000;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0377/2077] EDAC/igen6: Fix call trace due to missing release()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (375 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0376/2077] drm/msm/a8xx: Fix RSCC offset Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0378/2077] EDAC/igen6: Fix memory topology parsing for Panther Lake-H SoCs Greg Kroah-Hartman
                   ` (620 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Qiuxu Zhuo, Tony Luck, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Qiuxu Zhuo <qiuxu.zhuo@intel.com>

[ Upstream commit ab1f9d466c7d83ab0d2a529e07984e53b5960dcd ]

When unloading the igen6_edac driver, there is a call trace:

  Device '(null)' does not have a release() function, it is broken and must be fixed.
  See Documentation/core-api/kobject.rst.
  WARNING: drivers/base/core.c:2567 at device_release+0x84/0x90, CPU#5: rmmod/127209
  ...
  RIP: 0010:device_release+0x84/0x90
  Call Trace:
   <TASK>
   kobject_put+0x8c/0x220
   put_device+0x17/0x30
   igen6_unregister_mcis+0xa2/0xe0 [igen6_edac]
   igen6_remove+0x82/0xb0 [igen6_edac]
   ...

Fix the call trace by providing empty release() functions for the
memory controller devices.

Fixes: 10590a9d4f23 ("EDAC/igen6: Add EDAC driver for Intel client SoCs using IBECC")
Signed-off-by: Qiuxu Zhuo <qiuxu.zhuo@intel.com>
Signed-off-by: Tony Luck <tony.luck@intel.com>
Link: https://patch.msgid.link/20260403054029.3950383-2-qiuxu.zhuo@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/edac/igen6_edac.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/edac/igen6_edac.c b/drivers/edac/igen6_edac.c
index fcb8ab44cba55b..0bf9cf349d0b4e 100644
--- a/drivers/edac/igen6_edac.c
+++ b/drivers/edac/igen6_edac.c
@@ -1296,6 +1296,11 @@ static bool igen6_imc_absent(void __iomem *window)
 	return readl(window + MAD_INTER_CHANNEL_OFFSET) == ~0;
 }
 
+static void imc_release(struct device *dev)
+{
+	/* Nothing to do, the 'imc' owns the 'dev' and will also release it. */
+}
+
 static int igen6_register_mci(int mc, void __iomem *window, struct pci_dev *pdev)
 {
 	struct edac_mc_layer layers[2];
@@ -1334,6 +1339,7 @@ static int igen6_register_mci(int mc, void __iomem *window, struct pci_dev *pdev
 	mci->pvt_info = &igen6_pvt->imc[mc];
 
 	imc = mci->pvt_info;
+	imc->dev.release = imc_release;
 	device_initialize(&imc->dev);
 	/*
 	 * EDAC core uses mci->pdev(pointer of structure device) as
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0378/2077] EDAC/igen6: Fix memory topology parsing for Panther Lake-H SoCs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (376 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0377/2077] EDAC/igen6: Fix call trace due to missing release() Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0379/2077] EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info Greg Kroah-Hartman
                   ` (619 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Qiuxu Zhuo, Tony Luck, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Qiuxu Zhuo <qiuxu.zhuo@intel.com>

[ Upstream commit 114bfa24eacb688488caa2e459358a1b9b89b16d ]

Panther Lake-H SoC memory controller registers for memory topology have
been updated, but the current igen6_edac driver still uses old generation
ones to incorrectly parse memory topology.

Fix the issue by adding memory topology parsing function pointers to the
'struct res_config' and creating a new configuration structure for Panther
Lake-H SoCs to enable igen6_edac to parse memory correctly.

Fixes: 0be9f1af3902 ("EDAC/igen6: Add Intel Panther Lake-H SoCs support")
Fixes: 4c36e6106997 ("EDAC/igen6: Add more Intel Panther Lake-H SoCs support")
Signed-off-by: Qiuxu Zhuo <qiuxu.zhuo@intel.com>
Signed-off-by: Tony Luck <tony.luck@intel.com>
Link: https://patch.msgid.link/20260403054029.3950383-3-qiuxu.zhuo@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/edac/igen6_edac.c | 373 +++++++++++++++++++++++++++++++-------
 include/linux/edac.h      |   3 +
 2 files changed, 307 insertions(+), 69 deletions(-)

diff --git a/drivers/edac/igen6_edac.c b/drivers/edac/igen6_edac.c
index 0bf9cf349d0b4e..f849e3299593f7 100644
--- a/drivers/edac/igen6_edac.c
+++ b/drivers/edac/igen6_edac.c
@@ -122,6 +122,20 @@
 #define MEM_SLICE_HASH_MASK(v)		(GET_BITFIELD(v, 6, 19) << 6)
 #define MEM_SLICE_HASH_LSB_MASK_BIT(v)	GET_BITFIELD(v, 24, 26)
 
+struct igen6_imc {
+	int mc;
+	struct mem_ctl_info *mci;
+	struct pci_dev *pdev;
+	struct device dev;
+	void __iomem *window;
+	u64 size;
+	u64 ch_s_size;
+	int ch_l_map;
+	u64 dimm_s_size[NUM_CHANNELS];
+	u64 dimm_l_size[NUM_CHANNELS];
+	int dimm_l_map[NUM_CHANNELS];
+};
+
 static struct res_config {
 	bool machine_check;
 	/* The number of present memory controllers. */
@@ -134,12 +148,29 @@ static struct res_config {
 	u64 reg_touud_mask;
 	/* IBECC error log */
 	u64 reg_eccerrlog_addr_mask;
+	/* MEMSS_PMA_CR registers. */
+	u32 reg_mem_config_offset;
+	u32 reg_mem_config_ddr_type_mask;
+	/* Memory controller registers. */
+	u32 reg_mad_inter_size_mask[NUM_CHANNELS];
+	u64 reg_mad_inter_size_granularity;
+	u32 reg_mad_intra_rank_mask[NUM_DIMMS];
+	u32 reg_mad_intra_width_mask[NUM_DIMMS];
+	u32 reg_mad_intra_density_mask[NUM_DIMMS];
 	u32 imc_base;
 	u32 cmf_base;
 	u32 cmf_size;
 	u32 ms_hash_offset;
 	u32 ibecc_base;
 	u32 ibecc_error_log_offset;
+	/* Get memory type. */
+	enum mem_type (*get_mem_type)(struct igen6_imc *imc);
+	/* Get DRAM chip type. */
+	enum dev_type (*get_dev_type)(struct igen6_imc *imc, int chan, int dimm_l);
+	/* Set imc->ch_{s_size,l_map}. */
+	void (*set_chan_params)(struct igen6_imc *imc);
+	/* Set imc->dimm_{l_size,s_size,l_map}[chan]. */
+	void (*set_dimm_params)(struct igen6_imc *imc, int chan);
 	bool (*ibecc_available)(struct pci_dev *pdev);
 	/* Extract error address logged in IBECC */
 	u64 (*err_addr)(u64 ecclog);
@@ -149,22 +180,9 @@ static struct res_config {
 	u64 (*err_addr_to_imc_addr)(u64 eaddr, int mc);
 } *res_cfg;
 
-struct igen6_imc {
-	int mc;
-	struct mem_ctl_info *mci;
-	struct pci_dev *pdev;
-	struct device dev;
-	void __iomem *window;
-	u64 size;
-	u64 ch_s_size;
-	int ch_l_map;
-	u64 dimm_s_size[NUM_CHANNELS];
-	u64 dimm_l_size[NUM_CHANNELS];
-	int dimm_l_map[NUM_CHANNELS];
-};
-
 static struct igen6_pvt {
 	struct igen6_imc imc[NUM_IMC];
+	void __iomem *memss_pma_cr;
 	u64 ms_hash;
 	u64 ms_s_size;
 	int ms_l_map;
@@ -500,6 +518,119 @@ static u64 rpl_p_err_addr(u64 ecclog)
 	return field_get(res_cfg->reg_eccerrlog_addr_mask, ecclog);
 }
 
+static enum mem_type ptl_h_get_mem_type(struct igen6_imc *imc)
+{
+	u32 mtype, val;
+
+	val = readl(igen6_pvt->memss_pma_cr + res_cfg->reg_mem_config_offset);
+	mtype = field_get(res_cfg->reg_mem_config_ddr_type_mask, val);
+
+	edac_dbg(2, "mtype %u (reg 0x%x)\n", mtype, val);
+
+	switch (mtype) {
+	case 1:
+		return MEM_DDR5;
+	case 2:
+		return MEM_LPDDR5;
+	case 3:
+		return MEM_LPDDR4;
+	default:
+		return MEM_UNKNOWN;
+	}
+}
+
+static enum dev_type ptl_h_get_dev_type(struct igen6_imc *imc, int chan, int dimm)
+{
+	u32 width, val;
+
+	val = readl(imc->window + MAD_INTRA_CH0_OFFSET + chan * 4);
+	width = field_get(res_cfg->reg_mad_intra_width_mask[dimm], val);
+
+	switch (width) {
+	case 1:
+		return DEV_X8;
+	default:
+		return DEV_X16;
+	}
+}
+
+static u64 ptl_h_get_chan_size(struct igen6_imc *imc, int chan)
+{
+	u32 val = readl(imc->window + MAD_INTER_CHANNEL_OFFSET);
+
+	return field_get(res_cfg->reg_mad_inter_size_mask[chan], val) *
+	       res_cfg->reg_mad_inter_size_granularity;
+}
+
+static u64 ptl_h_get_dimm_size(struct igen6_imc *imc, int chan, int dimm)
+{
+	u32 val = readl(imc->window + MAD_INTRA_CH0_OFFSET + chan * 4);
+	u32 ranks = 1 << field_get(res_cfg->reg_mad_intra_rank_mask[dimm], val);
+	/* DRAM device density in Gb */
+	u64 density = field_get(res_cfg->reg_mad_intra_density_mask[dimm], val) * 4;
+
+	enum mem_type mtype = ptl_h_get_mem_type(imc);
+	enum dev_type dtype = ptl_h_get_dev_type(imc, chan, dimm);
+	u64 sub_ch_width, dev_num;
+
+	switch (mtype) {
+	case MEM_DDR5:
+		sub_ch_width = 32;
+		break;
+	case MEM_LPDDR5:
+	case MEM_LPDDR4:
+		sub_ch_width = 16;
+		break;
+	default:
+		sub_ch_width = 0;
+	}
+
+	switch (dtype) {
+	case DEV_X8:
+		dev_num = sub_ch_width / 8;
+		break;
+	case DEV_X16:
+		dev_num = sub_ch_width / 16;
+		break;
+	default:
+		dev_num = 0;
+	}
+
+	edac_dbg(2, "ranks %d, density %lluGb, sub_ch_width %llu, dev_num %llu (reg 0x%x)\n", ranks, density, sub_ch_width, dev_num, val);
+
+	return ((dev_num * density / 8) * ranks) << 30;
+}
+
+static void ptl_h_set_chan_params(struct igen6_imc *imc)
+{
+	u64 ch0_size = ptl_h_get_chan_size(imc, 0);
+	u64 ch1_size = ptl_h_get_chan_size(imc, 1);
+
+	if (ch0_size <= ch1_size) {
+		imc->ch_s_size = ch0_size;
+		imc->ch_l_map = 1;
+	} else {
+		imc->ch_s_size = ch1_size;
+		imc->ch_l_map = 0;
+	}
+}
+
+static void ptl_h_set_dimm_params(struct igen6_imc *imc, int chan)
+{
+	u64 dimm0_size = ptl_h_get_dimm_size(imc, chan, 0);
+	u64 dimm1_size = ptl_h_get_dimm_size(imc, chan, 1);
+
+	if (dimm0_size <= dimm1_size) {
+		imc->dimm_s_size[chan] = dimm0_size;
+		imc->dimm_l_size[chan] = dimm1_size;
+		imc->dimm_l_map[chan]  = 1;
+	} else {
+		imc->dimm_s_size[chan] = dimm1_size;
+		imc->dimm_l_size[chan] = dimm0_size;
+		imc->dimm_l_map[chan]  = 0;
+	}
+}
+
 static struct res_config ehl_cfg = {
 	.num_imc		= 1,
 	.reg_mchbar_mask	= GENMASK_ULL(38, 16),
@@ -622,6 +753,36 @@ static struct res_config mtl_p_cfg = {
 	.err_addr_to_imc_addr	= adl_err_addr_to_imc_addr,
 };
 
+static struct res_config ptl_h_cfg = {
+	.machine_check			= true,
+	.num_imc			= 2,
+	.reg_mchbar_mask		= GENMASK_ULL(41, 17),
+	.reg_tom_mask			= GENMASK_ULL(41, 20),
+	.reg_touud_mask			= GENMASK_ULL(41, 20),
+	.reg_eccerrlog_addr_mask	= GENMASK_ULL(38, 5),
+	.reg_mem_config_offset		= 0x13d04,
+	.reg_mem_config_ddr_type_mask	= GENMASK(8, 6),
+	.reg_mad_inter_size_mask[0]	= GENMASK(15, 8),
+	.reg_mad_inter_size_mask[1]	= GENMASK(23, 16),
+	.reg_mad_inter_size_granularity	= BIT_ULL(29),
+	.reg_mad_intra_rank_mask[0]	= BIT(7),
+	.reg_mad_intra_rank_mask[1]	= BIT(15),
+	.reg_mad_intra_width_mask[0]	= BIT(6),
+	.reg_mad_intra_width_mask[1]	= BIT(14),
+	.reg_mad_intra_density_mask[0]	= GENMASK(3, 0),
+	.reg_mad_intra_density_mask[1]	= GENMASK(11, 8),
+	.imc_base			= 0xd800,
+	.ibecc_base			= 0xd400,
+	.ibecc_error_log_offset		= 0x170,
+	.get_mem_type			= ptl_h_get_mem_type,
+	.get_dev_type			= ptl_h_get_dev_type,
+	.set_chan_params		= ptl_h_set_chan_params,
+	.set_dimm_params		= ptl_h_set_dimm_params,
+	.ibecc_available		= mtl_p_ibecc_available,
+	.err_addr_to_sys_addr		= adl_err_addr_to_sys_addr,
+	.err_addr_to_imc_addr		= adl_err_addr_to_imc_addr,
+};
+
 static struct res_config wcl_cfg = {
 	.machine_check		= true,
 	.num_imc		= 1,
@@ -689,46 +850,34 @@ static struct pci_device_id igen6_pci_tbl[] = {
 	{ PCI_VDEVICE(INTEL, DID_ARL_UH_SKU1), (kernel_ulong_t)&mtl_p_cfg },
 	{ PCI_VDEVICE(INTEL, DID_ARL_UH_SKU2), (kernel_ulong_t)&mtl_p_cfg },
 	{ PCI_VDEVICE(INTEL, DID_ARL_UH_SKU3), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU1), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU2), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU3), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU4), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU5), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU6), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU7), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU8), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU9), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU10), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU11), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU12), (kernel_ulong_t)&mtl_p_cfg },
-	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU13), (kernel_ulong_t)&mtl_p_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU1), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU2), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU3), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU4), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU5), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU6), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU7), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU8), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU9), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU10), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU11), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU12), (kernel_ulong_t)&ptl_h_cfg },
+	{ PCI_VDEVICE(INTEL, DID_PTL_H_SKU13), (kernel_ulong_t)&ptl_h_cfg },
 	{ PCI_VDEVICE(INTEL, DID_WCL_SKU1), (kernel_ulong_t)&wcl_cfg },
 	{ },
 };
 MODULE_DEVICE_TABLE(pci, igen6_pci_tbl);
 
-static enum dev_type get_width(int dimm_l, u32 mad_dimm)
+static enum mem_type get_mem_type(struct igen6_imc *imc)
 {
-	u32 w = dimm_l ? MAD_DIMM_CH_DLW(mad_dimm) :
-			 MAD_DIMM_CH_DSW(mad_dimm);
+	u32 val;
 
-	switch (w) {
-	case 0:
-		return DEV_X8;
-	case 1:
-		return DEV_X16;
-	case 2:
-		return DEV_X32;
-	default:
-		return DEV_UNKNOWN;
-	}
-}
+	if (res_cfg->get_mem_type)
+		return res_cfg->get_mem_type(imc);
 
-static enum mem_type get_memory_type(u32 mad_inter)
-{
-	u32 t = MAD_INTER_CHANNEL_DDR_TYPE(mad_inter);
+	val = readl(imc->window + MAD_INTER_CHANNEL_OFFSET);
 
-	switch (t) {
+	switch (MAD_INTER_CHANNEL_DDR_TYPE(val)) {
 	case 0:
 		return MEM_DDR4;
 	case 1:
@@ -744,6 +893,73 @@ static enum mem_type get_memory_type(u32 mad_inter)
 	}
 }
 
+static bool large_dimm(struct igen6_imc *imc, int chan, int dimm)
+{
+	return dimm == imc->dimm_l_map[chan];
+}
+
+static enum dev_type get_dev_type(struct igen6_imc *imc, int chan, int dimm)
+{
+	u32 width, val;
+
+	if (res_cfg->get_dev_type)
+		return res_cfg->get_dev_type(imc, chan, dimm);
+
+	val = readl(imc->window + MAD_DIMM_CH0_OFFSET + chan * 4);
+	width = large_dimm(imc, chan, dimm) ? MAD_DIMM_CH_DLW(val) :
+					  MAD_DIMM_CH_DSW(val);
+
+	switch (width) {
+	case 0:
+		return DEV_X8;
+	case 1:
+		return DEV_X16;
+	case 2:
+		return DEV_X32;
+	default:
+		return DEV_UNKNOWN;
+	}
+}
+
+static u64 get_dimm_size(struct igen6_imc *imc, int chan, int dimm)
+{
+	if (large_dimm(imc, chan, dimm))
+		return imc->dimm_l_size[chan];
+
+	return imc->dimm_s_size[chan];
+}
+
+static void set_chan_params(struct igen6_imc *imc)
+{
+	u32 val;
+
+	if (res_cfg->set_chan_params) {
+		res_cfg->set_chan_params(imc);
+		return;
+	}
+
+	val = readl(imc->window + MAD_INTER_CHANNEL_OFFSET);
+	imc->ch_s_size = MAD_INTER_CHANNEL_CH_S_SIZE(val);
+	imc->ch_l_map = MAD_INTER_CHANNEL_CH_L_MAP(val);
+}
+
+static void set_dimm_params(struct igen6_imc *imc, int chan)
+{
+	u32 val;
+
+	if (res_cfg->set_dimm_params) {
+		res_cfg->set_dimm_params(imc, chan);
+		return;
+	}
+
+	val = readl(imc->window + MAD_INTRA_CH0_OFFSET + chan * 4);
+	imc->dimm_l_map[chan]  = MAD_INTRA_CH_DIMM_L_MAP(val);
+
+	val = readl(imc->window + MAD_DIMM_CH0_OFFSET + chan * 4);
+	imc->dimm_l_size[chan] = MAD_DIMM_CH_DIMM_L_SIZE(val);
+	imc->dimm_s_size[chan] = MAD_DIMM_CH_DIMM_S_SIZE(val);
+}
+
 static int decode_chan_idx(u64 addr, u64 mask, int intlv_bit)
 {
 	u64 hash_addr = addr & mask, hash = 0;
@@ -1084,7 +1300,6 @@ static bool igen6_check_ecc(struct igen6_imc *imc)
 static int igen6_get_dimm_config(struct mem_ctl_info *mci)
 {
 	struct igen6_imc *imc = mci->pvt_info;
-	u32 mad_inter, mad_intra, mad_dimm;
 	int i, j, ndimms, mc = imc->mc;
 	struct dimm_info *dimm;
 	enum mem_type mtype;
@@ -1094,33 +1309,20 @@ static int igen6_get_dimm_config(struct mem_ctl_info *mci)
 
 	edac_dbg(2, "\n");
 
-	mad_inter = readl(imc->window + MAD_INTER_CHANNEL_OFFSET);
-	mtype = get_memory_type(mad_inter);
+	mtype = get_mem_type(imc);
 	ecc = igen6_check_ecc(imc);
-	imc->ch_s_size = MAD_INTER_CHANNEL_CH_S_SIZE(mad_inter);
-	imc->ch_l_map  = MAD_INTER_CHANNEL_CH_L_MAP(mad_inter);
+	set_chan_params(imc);
 
 	for (i = 0; i < NUM_CHANNELS; i++) {
-		mad_intra = readl(imc->window + MAD_INTRA_CH0_OFFSET + i * 4);
-		mad_dimm  = readl(imc->window + MAD_DIMM_CH0_OFFSET + i * 4);
-
-		imc->dimm_l_size[i] = MAD_DIMM_CH_DIMM_L_SIZE(mad_dimm);
-		imc->dimm_s_size[i] = MAD_DIMM_CH_DIMM_S_SIZE(mad_dimm);
-		imc->dimm_l_map[i]  = MAD_INTRA_CH_DIMM_L_MAP(mad_intra);
+		set_dimm_params(imc, i);
 		imc->size += imc->dimm_s_size[i];
 		imc->size += imc->dimm_l_size[i];
 		ndimms = 0;
 
 		for (j = 0; j < NUM_DIMMS; j++) {
 			dimm = edac_get_dimm(mci, i, j, 0);
-
-			if (j ^ imc->dimm_l_map[i]) {
-				dtype = get_width(0, mad_dimm);
-				dsize = imc->dimm_s_size[i];
-			} else {
-				dtype = get_width(1, mad_dimm);
-				dsize = imc->dimm_l_size[i];
-			}
+			dtype = get_dev_type(imc, i, j);
+			dsize = get_dimm_size(imc, i, j);
 
 			if (!dsize)
 				continue;
@@ -1223,6 +1425,39 @@ static void igen6_debug_setup(void) {}
 static void igen6_debug_teardown(void) {}
 #endif
 
+static struct igen6_pvt *igen6_pvt_setup(struct pci_dev *pdev)
+{
+	void __iomem *memss_pma_cr;
+	struct igen6_pvt *pvt;
+	u64 mchbar;
+	int rc;
+
+	pvt = kzalloc_obj(*igen6_pvt);
+	if (!pvt)
+		return NULL;
+
+	rc = get_mchbar(pdev, &mchbar);
+	if (rc) {
+		kfree(pvt);
+		return NULL;
+	}
+
+	memss_pma_cr = ioremap(mchbar, MCHBAR_SIZE * 2);
+	if (!memss_pma_cr) {
+		kfree(pvt);
+		return NULL;
+	}
+	pvt->memss_pma_cr = memss_pma_cr;
+
+	return pvt;
+}
+
+static void igen6_pvt_release(struct igen6_pvt *pvt)
+{
+	iounmap(pvt->memss_pma_cr);
+	kfree(pvt);
+}
+
 static int igen6_pci_setup(struct pci_dev *pdev, u64 *mchbar)
 {
 	union  {
@@ -1555,12 +1790,12 @@ static int igen6_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
 
 	edac_dbg(2, "\n");
 
-	igen6_pvt = kzalloc_obj(*igen6_pvt);
+	res_cfg = (struct res_config *)ent->driver_data;
+
+	igen6_pvt = igen6_pvt_setup(pdev);
 	if (!igen6_pvt)
 		return -ENOMEM;
 
-	res_cfg = (struct res_config *)ent->driver_data;
-
 	rc = igen6_pci_setup(pdev, &mchbar);
 	if (rc)
 		goto fail;
@@ -1609,7 +1844,7 @@ static int igen6_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
 fail2:
 	igen6_unregister_mcis();
 fail:
-	kfree(igen6_pvt);
+	igen6_pvt_release(igen6_pvt);
 	return rc;
 }
 
@@ -1624,7 +1859,7 @@ static void igen6_remove(struct pci_dev *pdev)
 	flush_work(&ecclog_work);
 	gen_pool_destroy(ecclog_pool);
 	igen6_unregister_mcis();
-	kfree(igen6_pvt);
+	igen6_pvt_release(igen6_pvt);
 }
 
 static struct pci_driver igen6_driver = {
diff --git a/include/linux/edac.h b/include/linux/edac.h
index deba46b3ee25d9..e6b4e51130e5ff 100644
--- a/include/linux/edac.h
+++ b/include/linux/edac.h
@@ -184,6 +184,7 @@ static inline char *mc_event_error_type(const unsigned int err_type)
  * @MEM_DDR5:		Unbuffered DDR5 RAM
  * @MEM_RDDR5:		Registered DDR5 RAM
  * @MEM_LRDDR5:		Load-Reduced DDR5 memory.
+ * @MEM_LPDDR5:		Low-Power DDR5 memory.
  * @MEM_NVDIMM:		Non-volatile RAM
  * @MEM_WIO2:		Wide I/O 2.
  * @MEM_HBM2:		High bandwidth Memory Gen 2.
@@ -216,6 +217,7 @@ enum mem_type {
 	MEM_DDR5,
 	MEM_RDDR5,
 	MEM_LRDDR5,
+	MEM_LPDDR5,
 	MEM_NVDIMM,
 	MEM_WIO2,
 	MEM_HBM2,
@@ -247,6 +249,7 @@ enum mem_type {
 #define MEM_FLAG_DDR5		BIT(MEM_DDR5)
 #define MEM_FLAG_RDDR5		BIT(MEM_RDDR5)
 #define MEM_FLAG_LRDDR5		BIT(MEM_LRDDR5)
+#define MEM_FLAG_LPDDR5		BIT(MEM_LPDDR5)
 #define MEM_FLAG_NVDIMM		BIT(MEM_NVDIMM)
 #define MEM_FLAG_WIO2		BIT(MEM_WIO2)
 #define MEM_FLAG_HBM2		BIT(MEM_HBM2)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0379/2077] EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (377 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0378/2077] EDAC/igen6: Fix memory topology parsing for Panther Lake-H SoCs Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0380/2077] arm64: dts: st: Fix SAI addresses on stm32mp251 Greg Kroah-Hartman
                   ` (618 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, zhoumin, Tony Luck, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: zhoumin <teczm@foxmail.com>

[ Upstream commit c63ed6e1f5fe648a4a099b6717f679999be482ef ]

When the skx_get_dimm_attr() helper returns -EINVAL,
skx_get_dimm_info() does not validate these return values before using
them in a shift operation:

    size = ((1ull << (rows + cols + ranks)) * banks) >> (20 - 3);

If all three values are -22, the shift exponent becomes -66, triggering
a UBSAN shift-out-of-bounds error:

    UBSAN: shift-out-of-bounds in drivers/edac/skx_common.c
    shift exponent -66 is negative

Fixes: 88a242c98740 ("EDAC, skx_common: Separate common code out from skx_edac")
Signed-off-by: zhoumin <teczm@foxmail.com>
Signed-off-by: Tony Luck <tony.luck@intel.com>
Link: https://patch.msgid.link/tencent_2A0CC835A18366643CBD2865B169948AB409@qq.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/edac/skx_common.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/edac/skx_common.c b/drivers/edac/skx_common.c
index a9557c8344bc13..f15de0ea96c87e 100644
--- a/drivers/edac/skx_common.c
+++ b/drivers/edac/skx_common.c
@@ -466,6 +466,9 @@ int skx_get_dimm_info(u32 mtr, u32 mcmtr, u32 amap, struct dimm_info *dimm,
 	rows = numrow(mtr);
 	cols = imc->hbm_mc ? 6 : numcol(mtr);
 
+	if (ranks < 0 || rows < 0 || cols < 0)
+		return 0;
+
 	if (imc->hbm_mc) {
 		banks = 32;
 		mtype = MEM_HBM2;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0380/2077] arm64: dts: st: Fix SAI addresses on stm32mp251
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (378 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0379/2077] EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0381/2077] arm: dts: bcm2711: Fix typo in gpio-line-names Greg Kroah-Hartman
                   ` (617 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Marek Vasut, Olivier Moysan,
	Alexandre Torgue, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marek Vasut <marex@nabladev.com>

[ Upstream commit fba4a31a7f3b6b29b01c83180f83e7ed4c398738 ]

The second field of SAI register addresses should be within 0x3f0 bytes
from the start of the SAI register addresses, the second field describes
the ID registers which are at that addrses. Currently, the second field
does not match RM, fix it.

Fixes: bf26d75a95f1 ("arm64: dts: st: add sai support on stm32mp251")
Signed-off-by: Marek Vasut <marex@nabladev.com>
Reviewed-by: Olivier Moysan <olivier.moysan@foss.st.com>
Link: https://lore.kernel.org/r/20260411130300.19603-1-marex@nabladev.com
Signed-off-by: Alexandre Torgue <alexandre.torgue@foss.st.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/st/stm32mp251.dtsi | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/arch/arm64/boot/dts/st/stm32mp251.dtsi b/arch/arm64/boot/dts/st/stm32mp251.dtsi
index 673fbc5632e69f..9c63fdb5a885af 100644
--- a/arch/arm64/boot/dts/st/stm32mp251.dtsi
+++ b/arch/arm64/boot/dts/st/stm32mp251.dtsi
@@ -1202,7 +1202,7 @@ spi5: spi@40280000 {
 
 			sai1: sai@40290000 {
 				compatible = "st,stm32mp25-sai";
-				reg = <0x40290000 0x4>, <0x4029a3f0 0x10>;
+				reg = <0x40290000 0x4>, <0x402903f0 0x10>;
 				ranges = <0 0x40290000 0x400>;
 				#address-cells = <1>;
 				#size-cells = <1>;
@@ -1236,7 +1236,7 @@ sai1b: audio-controller@40290024 {
 
 			sai2: sai@402a0000 {
 				compatible = "st,stm32mp25-sai";
-				reg = <0x402a0000 0x4>, <0x402aa3f0 0x10>;
+				reg = <0x402a0000 0x4>, <0x402a03f0 0x10>;
 				ranges = <0 0x402a0000 0x400>;
 				#address-cells = <1>;
 				#size-cells = <1>;
@@ -1270,7 +1270,7 @@ sai2b: audio-controller@402a0024 {
 
 			sai3: sai@402b0000 {
 				compatible = "st,stm32mp25-sai";
-				reg = <0x402b0000 0x4>, <0x402ba3f0 0x10>;
+				reg = <0x402b0000 0x4>, <0x402b03f0 0x10>;
 				ranges = <0 0x402b0000 0x400>;
 				#address-cells = <1>;
 				#size-cells = <1>;
@@ -1362,7 +1362,7 @@ usart1: serial@40330000 {
 
 			sai4: sai@40340000 {
 				compatible = "st,stm32mp25-sai";
-				reg = <0x40340000 0x4>, <0x4034a3f0 0x10>;
+				reg = <0x40340000 0x4>, <0x403403f0 0x10>;
 				ranges = <0 0x40340000 0x400>;
 				#address-cells = <1>;
 				#size-cells = <1>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0381/2077] arm: dts: bcm2711: Fix typo in gpio-line-names
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (379 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0380/2077] arm64: dts: st: Fix SAI addresses on stm32mp251 Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0382/2077] RDMA/umem: Add ib_umem_is_contiguous() stub for !CONFIG_INFINIBAND_USER_MEM Greg Kroah-Hartman
                   ` (616 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jinseok Kim, Florian Fainelli,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jinseok Kim <always.starving0@gmail.com>

[ Upstream commit 245552af869d35ae27cac2121696dd630f15b3bf ]

Replace "RGMIO_MDC" with "RGMII_MDC" in gpio-line-names.

Signed-off-by: Jinseok Kim <always.starving0@gmail.com>
Link: https://lore.kernel.org/r/20260527103930.2973-1-always.starving0@gmail.com
Fixes: cd87c180b301 ("ARM: dts: bcm2711-rpi-4-b: Add SoC GPIO labels")
Fixes: ea93ada05c9e ("ARM: dts: Add Raspberry Pi Compute Module 4 IO Board")
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm/boot/dts/broadcom/bcm2711-rpi-4-b.dts    | 2 +-
 arch/arm/boot/dts/broadcom/bcm2711-rpi-cm4-io.dts | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/arm/boot/dts/broadcom/bcm2711-rpi-4-b.dts b/arch/arm/boot/dts/broadcom/bcm2711-rpi-4-b.dts
index 353bb50ce5425c..5469fa663526f7 100644
--- a/arch/arm/boot/dts/broadcom/bcm2711-rpi-4-b.dts
+++ b/arch/arm/boot/dts/broadcom/bcm2711-rpi-4-b.dts
@@ -110,7 +110,7 @@ &gpio {
 			  "GPIO26",
 			  "GPIO27",
 			  "RGMII_MDIO",
-			  "RGMIO_MDC",
+			  "RGMII_MDC",
 			  /* Used by BT module */
 			  "CTS0",		/* 30 */
 			  "RTS0",
diff --git a/arch/arm/boot/dts/broadcom/bcm2711-rpi-cm4-io.dts b/arch/arm/boot/dts/broadcom/bcm2711-rpi-cm4-io.dts
index 6bc77dd48c0d9b..1f4ebec68370c9 100644
--- a/arch/arm/boot/dts/broadcom/bcm2711-rpi-cm4-io.dts
+++ b/arch/arm/boot/dts/broadcom/bcm2711-rpi-cm4-io.dts
@@ -56,7 +56,7 @@ &gpio {
 			  "GPIO26",
 			  "GPIO27",
 			  "RGMII_MDIO",
-			  "RGMIO_MDC",
+			  "RGMII_MDC",
 			  /* Used by BT module */
 			  "CTS0",
 			  "RTS0",
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0382/2077] RDMA/umem: Add ib_umem_is_contiguous() stub for !CONFIG_INFINIBAND_USER_MEM
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (380 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0381/2077] arm: dts: bcm2711: Fix typo in gpio-line-names Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0383/2077] RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe Greg Kroah-Hartman
                   ` (615 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jiri Pirko, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiri Pirko <jiri@nvidia.com>

[ Upstream commit 2cc10972f5f4f123e5a7658824db4f7b5abfc410 ]

ib_umem_is_contiguous() is defined under #ifdef
CONFIG_INFINIBAND_USER_MEM, but the #else branch lacks a stub.

Add the missing inline to fix potential broken build.

Fixes: c897c2c8b8e8 ("RDMA/core: Add umem "is_contiguous" and "start_dma_addr" helpers")
Link: https://patch.msgid.link/r/20260529134312.2836341-15-jiri@resnulli.us
Signed-off-by: Jiri Pirko <jiri@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/rdma/ib_umem.h | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/include/rdma/ib_umem.h b/include/rdma/ib_umem.h
index 49172098a8de14..3e0c2c356d142b 100644
--- a/include/rdma/ib_umem.h
+++ b/include/rdma/ib_umem.h
@@ -185,6 +185,10 @@ static inline unsigned long ib_umem_find_best_pgoff(struct ib_umem *umem,
 {
 	return 0;
 }
+static inline bool ib_umem_is_contiguous(struct ib_umem *umem)
+{
+	return false;
+}
 static inline
 struct ib_umem_dmabuf *ib_umem_dmabuf_get(struct ib_device *device,
 					  unsigned long offset,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0383/2077] RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (381 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0382/2077] RDMA/umem: Add ib_umem_is_contiguous() stub for !CONFIG_INFINIBAND_USER_MEM Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0384/2077] RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path Greg Kroah-Hartman
                   ` (614 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tristan Madani, Zhu Yanjun,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tristan Madani <tristmd@gmail.com>

[ Upstream commit 22b8fbded65b8c441b634a185f8da67657df6c50 ]

get_srq_wqe() reads wqe->dma.num_sge from the shared receive queue
buffer, which is mapped into userspace. It validates num_sge against
max_sge, but then re-reads the same field to calculate the memcpy
size. A concurrent userspace thread can modify num_sge between
validation and use, causing a heap buffer overflow when copying the
WQE into qp->resp.srq_wqe.

Read num_sge into a local variable and use it for both the bounds
check and the size calculation.

Fixes: 8700e3e7c485 ("Soft RoCE driver")
Link: https://patch.msgid.link/r/20260518215040.1598586-2-tristan@talencesecurity.com
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/sw/rxe/rxe_resp.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/infiniband/sw/rxe/rxe_resp.c b/drivers/infiniband/sw/rxe/rxe_resp.c
index 9cb2f6fbf2dd6a..8a0a9739636014 100644
--- a/drivers/infiniband/sw/rxe/rxe_resp.c
+++ b/drivers/infiniband/sw/rxe/rxe_resp.c
@@ -264,6 +264,7 @@ static enum resp_states get_srq_wqe(struct rxe_qp *qp)
 	struct rxe_recv_wqe *wqe;
 	struct ib_event ev;
 	unsigned int count;
+	unsigned int num_sge;
 	size_t size;
 	unsigned long flags;
 
@@ -279,12 +280,13 @@ static enum resp_states get_srq_wqe(struct rxe_qp *qp)
 	}
 
 	/* don't trust user space data */
-	if (unlikely(wqe->dma.num_sge > srq->rq.max_sge)) {
+	num_sge = wqe->dma.num_sge;
+	if (unlikely(num_sge > srq->rq.max_sge)) {
 		spin_unlock_irqrestore(&srq->rq.consumer_lock, flags);
 		rxe_dbg_qp(qp, "invalid num_sge in SRQ entry\n");
 		return RESPST_ERR_MALFORMED_WQE;
 	}
-	size = sizeof(*wqe) + wqe->dma.num_sge*sizeof(struct rxe_sge);
+	size = sizeof(*wqe) + num_sge * sizeof(struct rxe_sge);
 	memcpy(&qp->resp.srq_wqe, wqe, size);
 
 	qp->resp.wqe = &qp->resp.srq_wqe.wqe;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0384/2077] RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (382 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0383/2077] RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0385/2077] dts: riscv: spacemit: k3: Fix I/O power settings Greg Kroah-Hartman
                   ` (613 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tristan Madani, Zhu Yanjun,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tristan Madani <tristmd@gmail.com>

[ Upstream commit d6ab440240a04b8737ee4c7bb21af9182e451733 ]

For non-SRQ QPs, the responder reads WQE fields directly from the
shared queue buffer mapped into userspace. This allows a malicious
user to modify fields like num_sge or sge entries while the kernel
is processing the WQE, leading to out-of-bounds reads in
rxe_resp_check_length() and copy_data().

Introduce get_recv_wqe() that validates num_sge and copies the WQE
to a kernel-local buffer before processing, matching the approach
already used for SRQ WQEs in get_srq_wqe(). The srq_wqe buffer is
reused since SRQ and non-SRQ paths are mutually exclusive per QP.

Fixes: 8700e3e7c485 ("Soft RoCE driver")
Link: https://patch.msgid.link/r/20260518215040.1598586-3-tristan@talencesecurity.com
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/sw/rxe/rxe_resp.c | 27 ++++++++++++++++++++++++---
 1 file changed, 24 insertions(+), 3 deletions(-)

diff --git a/drivers/infiniband/sw/rxe/rxe_resp.c b/drivers/infiniband/sw/rxe/rxe_resp.c
index 8a0a9739636014..e0294b7c956936 100644
--- a/drivers/infiniband/sw/rxe/rxe_resp.c
+++ b/drivers/infiniband/sw/rxe/rxe_resp.c
@@ -310,6 +310,29 @@ static enum resp_states get_srq_wqe(struct rxe_qp *qp)
 	return RESPST_CHK_LENGTH;
 }
 
+static enum resp_states rxe_get_recv_wqe(struct rxe_qp *qp)
+{
+	struct rxe_queue *q = qp->rq.queue;
+	struct rxe_recv_wqe *wqe;
+	unsigned int num_sge;
+	size_t size;
+
+	wqe = queue_head(q, QUEUE_TYPE_FROM_CLIENT);
+	if (!wqe)
+		return RESPST_ERR_RNR;
+
+	num_sge = wqe->dma.num_sge;
+	if (unlikely(num_sge > qp->rq.max_sge)) {
+		rxe_dbg_qp(qp, "invalid num_sge in recv WQE\n");
+		return RESPST_ERR_MALFORMED_WQE;
+	}
+	size = sizeof(*wqe) + num_sge * sizeof(struct rxe_sge);
+	memcpy(&qp->resp.srq_wqe, wqe, size);
+
+	qp->resp.wqe = &qp->resp.srq_wqe.wqe;
+	return RESPST_CHK_LENGTH;
+}
+
 static enum resp_states check_resource(struct rxe_qp *qp,
 				       struct rxe_pkt_info *pkt)
 {
@@ -330,9 +353,7 @@ static enum resp_states check_resource(struct rxe_qp *qp,
 		if (srq)
 			return get_srq_wqe(qp);
 
-		qp->resp.wqe = queue_head(qp->rq.queue,
-				QUEUE_TYPE_FROM_CLIENT);
-		return (qp->resp.wqe) ? RESPST_CHK_LENGTH : RESPST_ERR_RNR;
+		return rxe_get_recv_wqe(qp);
 	}
 
 	return RESPST_CHK_LENGTH;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0385/2077] dts: riscv: spacemit: k3: Fix I/O power settings
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (383 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0384/2077] RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:00 ` [PATCH 7.1 0386/2077] Revert "media: venus: hfi_platform: Correct supported codecs for sc7280" Greg Kroah-Hartman
                   ` (612 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Han Gao, Yixun Lan, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yixun Lan <dlan@kernel.org>

[ Upstream commit 3ea695eb111fc5a7ffddd21d5c3fee6d82560413 ]

SpacemiT K3 SoC support dual-voltage I/O power domain, while initially
configure to 3.3v, and need to access register from APBC space to switch
to 1.8v domain.

Fix the GMAC0's I/O pins 1.8v switch failure that will result a broken
ethernet driver.

Fixes: d8944577496b ("riscv: dts: spacemit: k3: add pinctrl support")
Reported-by: Han Gao <gaohan@iscas.ac.cn>
Link: https://patch.msgid.link/20260518-07-dts-pinctrl-io-power-v1-1-abe19c14a726@kernel.org
Signed-off-by: Yixun Lan <dlan@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/boot/dts/spacemit/k3.dtsi | 1 +
 1 file changed, 1 insertion(+)

diff --git a/arch/riscv/boot/dts/spacemit/k3.dtsi b/arch/riscv/boot/dts/spacemit/k3.dtsi
index e6faf8d8759e1f..719850aa7aac5a 100644
--- a/arch/riscv/boot/dts/spacemit/k3.dtsi
+++ b/arch/riscv/boot/dts/spacemit/k3.dtsi
@@ -803,6 +803,7 @@ pinctrl: pinctrl@d401e000 {
 			clocks = <&syscon_apbc CLK_APBC_AIB>,
 				 <&syscon_apbc CLK_APBC_AIB_BUS>;
 			clock-names = "func", "bus";
+			spacemit,apbc = <&syscon_apbc>;
 		};
 
 		uart10: serial@d401f000 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0386/2077] Revert "media: venus: hfi_platform: Correct supported codecs for sc7280"
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (384 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0385/2077] dts: riscv: spacemit: k3: Fix I/O power settings Greg Kroah-Hartman
@ 2026-07-21 15:00 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0387/2077] media: qcom: venus: drop extra padding in NV12 raw size calculation Greg Kroah-Hartman
                   ` (611 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:00 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Bryan ODonoghue,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>

[ Upstream commit 3eb9ba0da0ab73e135f93ffccf07381ba11f100e ]

This reverts commit c0ab2901fc68 ("media: venus: hfi_platform: Correct
supported codecs for sc7280"). The codecs might be deprecated, but they
still work (somewhat) perfectly and don't cause any issues with the rest
of the system. Reenable VP8 codecs by reverting the offending commit.

Tested with fluster:

|Test|FFmpeg-VP8-v4l2m2m|GStreamer-VP8-V4L2|
|TOTAL|50/61|50/61|
|TOTAL TIME|12.171s|11.824s|

Fixes: c0ab2901fc68 ("media: venus: hfi_platform: Correct supported codecs for sc7280")
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../media/platform/qcom/venus/hfi_parser.c    |  6 ++---
 .../media/platform/qcom/venus/hfi_platform.c  | 24 -------------------
 .../media/platform/qcom/venus/hfi_platform.h  |  2 --
 3 files changed, 2 insertions(+), 30 deletions(-)

diff --git a/drivers/media/platform/qcom/venus/hfi_parser.c b/drivers/media/platform/qcom/venus/hfi_parser.c
index 92765f9c88730a..c4cf6cd50a9a03 100644
--- a/drivers/media/platform/qcom/venus/hfi_parser.c
+++ b/drivers/media/platform/qcom/venus/hfi_parser.c
@@ -268,7 +268,6 @@ static int hfi_platform_parser(struct venus_core *core, struct venus_inst *inst)
 	const struct hfi_plat_caps *caps = NULL;
 	u32 enc_codecs, dec_codecs, count = 0;
 	unsigned int entries;
-	int ret;
 
 	plat = hfi_platform_get(core->res->hfi_version);
 	if (!plat)
@@ -277,9 +276,8 @@ static int hfi_platform_parser(struct venus_core *core, struct venus_inst *inst)
 	if (inst)
 		return 0;
 
-	ret = hfi_platform_get_codecs(core, &enc_codecs, &dec_codecs, &count);
-	if (ret)
-		return ret;
+	if (plat->codecs)
+		plat->codecs(core, &enc_codecs, &dec_codecs, &count);
 
 	if (plat->capabilities)
 		caps = plat->capabilities(core, &entries);
diff --git a/drivers/media/platform/qcom/venus/hfi_platform.c b/drivers/media/platform/qcom/venus/hfi_platform.c
index cde7f93045ac45..f19572ab1d1613 100644
--- a/drivers/media/platform/qcom/venus/hfi_platform.c
+++ b/drivers/media/platform/qcom/venus/hfi_platform.c
@@ -2,9 +2,7 @@
 /*
  * Copyright (c) 2020, The Linux Foundation. All rights reserved.
  */
-#include <linux/of.h>
 #include "hfi_platform.h"
-#include "core.h"
 
 const struct hfi_platform *hfi_platform_get(enum hfi_version version)
 {
@@ -73,25 +71,3 @@ hfi_platform_get_codec_lp_freq(struct venus_core *core,
 
 	return freq;
 }
-
-int
-hfi_platform_get_codecs(struct venus_core *core, u32 *enc_codecs,
-			u32 *dec_codecs, u32 *count)
-{
-	const struct hfi_platform *plat;
-
-	plat = hfi_platform_get(core->res->hfi_version);
-	if (!plat)
-		return -EINVAL;
-
-	if (plat->codecs)
-		plat->codecs(core, enc_codecs, dec_codecs, count);
-
-	if (IS_IRIS2_1(core)) {
-		*enc_codecs &= ~HFI_VIDEO_CODEC_VP8;
-		*dec_codecs &= ~HFI_VIDEO_CODEC_VP8;
-	}
-
-	return 0;
-}
-
diff --git a/drivers/media/platform/qcom/venus/hfi_platform.h b/drivers/media/platform/qcom/venus/hfi_platform.h
index 5e4f8013a6b1db..a0b6d19f3e1a04 100644
--- a/drivers/media/platform/qcom/venus/hfi_platform.h
+++ b/drivers/media/platform/qcom/venus/hfi_platform.h
@@ -74,6 +74,4 @@ unsigned long hfi_platform_get_codec_vsp_freq(struct venus_core *core,
 unsigned long hfi_platform_get_codec_lp_freq(struct venus_core *core,
 					     enum hfi_version version,
 					     u32 codec, u32 session_type);
-int hfi_platform_get_codecs(struct venus_core *core, u32 *enc_codecs,
-			    u32 *dec_codecs, u32 *count);
 #endif
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0387/2077] media: qcom: venus: drop extra padding in NV12 raw size calculation
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (385 preceding siblings ...)
  2026-07-21 15:00 ` [PATCH 7.1 0386/2077] Revert "media: venus: hfi_platform: Correct supported codecs for sc7280" Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0388/2077] media: qcom: venus: relax encoder frame/blur dimension steps on v4 Greg Kroah-Hartman
                   ` (610 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Renjiang Han, Dikshita Agarwal,
	Bryan ODonoghue, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Renjiang Han <renjiang.han@oss.qualcomm.com>

[ Upstream commit e1c9adabb268cc5d56723b7df1da49e59070f309 ]

get_framesize_raw_nv12() currently adds SZ_4K to the UV plane size and an
additional SZ_8K to the total buffer size. This inflates the calculated
sizeimage and leads userspace to over-allocate buffers without a clear
requirement.

Remove the extra SZ_4K/SZ_8K padding and compute the NV12 size as the sum
of Y and UV planes, keeping the final ALIGN(size, SZ_4K) intact.

Fixes: e1cb72de702ad ("media: venus: helpers: move frame size calculations on common place")
Signed-off-by: Renjiang Han <renjiang.han@oss.qualcomm.com>
Reviewed-by: Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/media/platform/qcom/venus/helpers.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/media/platform/qcom/venus/helpers.c b/drivers/media/platform/qcom/venus/helpers.c
index 747c388fe25fa3..59eee3dd9e06c2 100644
--- a/drivers/media/platform/qcom/venus/helpers.c
+++ b/drivers/media/platform/qcom/venus/helpers.c
@@ -954,8 +954,8 @@ static u32 get_framesize_raw_nv12(u32 width, u32 height)
 	uv_sclines = ALIGN(((height + 1) >> 1), 16);
 
 	y_plane = y_stride * y_sclines;
-	uv_plane = uv_stride * uv_sclines + SZ_4K;
-	size = y_plane + uv_plane + SZ_8K;
+	uv_plane = uv_stride * uv_sclines;
+	size = y_plane + uv_plane;
 
 	return ALIGN(size, SZ_4K);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0388/2077] media: qcom: venus: relax encoder frame/blur dimension steps on v4
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (386 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0387/2077] media: qcom: venus: drop extra padding in NV12 raw size calculation Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0389/2077] media: qcom: venus: relax encoder frame/blur step size on v6 Greg Kroah-Hartman
                   ` (609 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Renjiang Han, Dikshita Agarwal,
	Bryan ODonoghue, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Renjiang Han <renjiang.han@oss.qualcomm.com>

[ Upstream commit 35428ae3a6a40912f1f7b47bb6c65f1a63d0b8f8 ]

Encoder HFI capabilities on v4 advertise a 16-pixel step for frame and
blur dimensions. This is overly restrictive and can cause userspace caps
negotiation to fail even for valid resolutions.

Relax the advertised step size to 1 and keep alignment enforcement in
buffer layout and size calculations.

Fixes: 8b88cabef404e ("media: venus: hfi_plat_v4: Populate codecs and capabilities for v4")
Signed-off-by: Renjiang Han <renjiang.han@oss.qualcomm.com>
Reviewed-by: Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../platform/qcom/venus/hfi_platform_v4.c     | 20 +++++++++----------
 1 file changed, 10 insertions(+), 10 deletions(-)

diff --git a/drivers/media/platform/qcom/venus/hfi_platform_v4.c b/drivers/media/platform/qcom/venus/hfi_platform_v4.c
index cda888b56b5d48..e0b3652bb44093 100644
--- a/drivers/media/platform/qcom/venus/hfi_platform_v4.c
+++ b/drivers/media/platform/qcom/venus/hfi_platform_v4.c
@@ -136,8 +136,8 @@ static const struct hfi_plat_caps caps[] = {
 	.codec = HFI_VIDEO_CODEC_H264,
 	.domain = VIDC_SESSION_TYPE_ENC,
 	.cap_bufs_mode_dynamic = true,
-	.caps[0] = {HFI_CAPABILITY_FRAME_WIDTH, 96, 4096, 16},
-	.caps[1] = {HFI_CAPABILITY_FRAME_HEIGHT, 96, 4096, 16},
+	.caps[0] = {HFI_CAPABILITY_FRAME_WIDTH, 96, 4096, 1},
+	.caps[1] = {HFI_CAPABILITY_FRAME_HEIGHT, 96, 4096, 1},
 	.caps[2] = {HFI_CAPABILITY_MBS_PER_FRAME, 1, 36864, 1},
 	.caps[3] = {HFI_CAPABILITY_BITRATE, 1, 120000000, 1},
 	.caps[4] = {HFI_CAPABILITY_SCALE_X, 8192, 65536, 1},
@@ -173,8 +173,8 @@ static const struct hfi_plat_caps caps[] = {
 	.codec = HFI_VIDEO_CODEC_HEVC,
 	.domain = VIDC_SESSION_TYPE_ENC,
 	.cap_bufs_mode_dynamic = true,
-	.caps[0] = {HFI_CAPABILITY_FRAME_WIDTH, 96, 4096, 16},
-	.caps[1] = {HFI_CAPABILITY_FRAME_HEIGHT, 96, 4096, 16},
+	.caps[0] = {HFI_CAPABILITY_FRAME_WIDTH, 96, 4096, 1},
+	.caps[1] = {HFI_CAPABILITY_FRAME_HEIGHT, 96, 4096, 1},
 	.caps[2] = {HFI_CAPABILITY_MBS_PER_FRAME, 1, 36864, 1},
 	.caps[3] = {HFI_CAPABILITY_BITRATE, 1, 120000000, 1},
 	.caps[4] = {HFI_CAPABILITY_SCALE_X, 8192, 65536, 1},
@@ -195,8 +195,8 @@ static const struct hfi_plat_caps caps[] = {
 	.caps[19] = {HFI_CAPABILITY_RATE_CONTROL_MODES, 0x1000001, 0x1000005, 1},
 	.caps[20] = {HFI_CAPABILITY_COLOR_SPACE_CONVERSION, 0, 2, 1},
 	.caps[21] = {HFI_CAPABILITY_ROTATION, 1, 4, 90},
-	.caps[22] = {HFI_CAPABILITY_BLUR_WIDTH, 96, 4096, 16},
-	.caps[23] = {HFI_CAPABILITY_BLUR_HEIGHT, 96, 4096, 16},
+	.caps[22] = {HFI_CAPABILITY_BLUR_WIDTH, 96, 4096, 1},
+	.caps[23] = {HFI_CAPABILITY_BLUR_HEIGHT, 96, 4096, 1},
 	.num_caps = 24,
 	.pl[0] = {HFI_HEVC_PROFILE_MAIN, HFI_HEVC_LEVEL_6 | HFI_HEVC_TIER_HIGH0},
 	.pl[1] = {HFI_HEVC_PROFILE_MAIN10, HFI_HEVC_LEVEL_6 | HFI_HEVC_TIER_HIGH0},
@@ -210,8 +210,8 @@ static const struct hfi_plat_caps caps[] = {
 	.codec = HFI_VIDEO_CODEC_VP8,
 	.domain = VIDC_SESSION_TYPE_ENC,
 	.cap_bufs_mode_dynamic = true,
-	.caps[0] = {HFI_CAPABILITY_FRAME_WIDTH, 96, 4096, 16},
-	.caps[1] = {HFI_CAPABILITY_FRAME_HEIGHT, 96, 4096, 16},
+	.caps[0] = {HFI_CAPABILITY_FRAME_WIDTH, 96, 4096, 1},
+	.caps[1] = {HFI_CAPABILITY_FRAME_HEIGHT, 96, 4096, 1},
 	.caps[2] = {HFI_CAPABILITY_MBS_PER_FRAME, 1, 36864, 1},
 	.caps[3] = {HFI_CAPABILITY_BITRATE, 1, 120000000, 1},
 	.caps[4] = {HFI_CAPABILITY_SCALE_X, 8192, 65536, 1},
@@ -229,8 +229,8 @@ static const struct hfi_plat_caps caps[] = {
 	.caps[16] = {HFI_CAPABILITY_P_FRAME_QP, 0, 127, 1},
 	.caps[17] = {HFI_CAPABILITY_MAX_WORKMODES, 1, 2, 1},
 	.caps[18] = {HFI_CAPABILITY_RATE_CONTROL_MODES, 0x1000001, 0x1000005, 1},
-	.caps[19] = {HFI_CAPABILITY_BLUR_WIDTH, 96, 4096, 16},
-	.caps[20] = {HFI_CAPABILITY_BLUR_HEIGHT, 96, 4096, 16},
+	.caps[19] = {HFI_CAPABILITY_BLUR_WIDTH, 96, 4096, 1},
+	.caps[20] = {HFI_CAPABILITY_BLUR_HEIGHT, 96, 4096, 1},
 	.caps[21] = {HFI_CAPABILITY_COLOR_SPACE_CONVERSION, 0, 2, 1},
 	.caps[22] = {HFI_CAPABILITY_ROTATION, 1, 4, 90},
 	.num_caps = 23,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0389/2077] media: qcom: venus: relax encoder frame/blur step size on v6
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (387 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0388/2077] media: qcom: venus: relax encoder frame/blur dimension steps on v4 Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0390/2077] amba: use generic driver_override infrastructure Greg Kroah-Hartman
                   ` (608 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Renjiang Han, Dikshita Agarwal,
	Bryan ODonoghue, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Renjiang Han <renjiang.han@oss.qualcomm.com>

[ Upstream commit c53e0550288b2e08b984b24035c471941b7820c7 ]

Encoder HFI capabilities on v6 enforce a 16-pixel step for frame and blur
dimensions, which does not reflect actual hardware requirements and can
reject valid userspace configurations.

Relax the step size to 1 while leaving min/max limits unchanged.

Fixes: 869d77e706290 ("media: venus: hfi_plat_v6: Populate capabilities for v6")
Signed-off-by: Renjiang Han <renjiang.han@oss.qualcomm.com>
Reviewed-by: Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../media/platform/qcom/venus/hfi_platform_v6.c  | 16 ++++++++--------
 1 file changed, 8 insertions(+), 8 deletions(-)

diff --git a/drivers/media/platform/qcom/venus/hfi_platform_v6.c b/drivers/media/platform/qcom/venus/hfi_platform_v6.c
index d8568c08cc3612..fb8d10ab34043e 100644
--- a/drivers/media/platform/qcom/venus/hfi_platform_v6.c
+++ b/drivers/media/platform/qcom/venus/hfi_platform_v6.c
@@ -173,8 +173,8 @@ static const struct hfi_plat_caps caps[] = {
 	.codec = HFI_VIDEO_CODEC_HEVC,
 	.domain = VIDC_SESSION_TYPE_ENC,
 	.cap_bufs_mode_dynamic = true,
-	.caps[0] = {HFI_CAPABILITY_FRAME_WIDTH, 128, 8192, 16},
-	.caps[1] = {HFI_CAPABILITY_FRAME_HEIGHT, 128, 8192, 16},
+	.caps[0] = {HFI_CAPABILITY_FRAME_WIDTH, 128, 8192, 1},
+	.caps[1] = {HFI_CAPABILITY_FRAME_HEIGHT, 128, 8192, 1},
 	.caps[2] = {HFI_CAPABILITY_MBS_PER_FRAME, 64, 138240, 1},
 	.caps[3] = {HFI_CAPABILITY_BITRATE, 1, 160000000, 1},
 	.caps[4] = {HFI_CAPABILITY_SCALE_X, 8192, 65536, 1},
@@ -195,8 +195,8 @@ static const struct hfi_plat_caps caps[] = {
 	.caps[19] = {HFI_CAPABILITY_RATE_CONTROL_MODES, 0x1000001, 0x1000005, 1},
 	.caps[20] = {HFI_CAPABILITY_COLOR_SPACE_CONVERSION, 0, 2, 1},
 	.caps[21] = {HFI_CAPABILITY_ROTATION, 1, 4, 90},
-	.caps[22] = {HFI_CAPABILITY_BLUR_WIDTH, 96, 4096, 16},
-	.caps[23] = {HFI_CAPABILITY_BLUR_HEIGHT, 96, 4096, 16},
+	.caps[22] = {HFI_CAPABILITY_BLUR_WIDTH, 96, 4096, 1},
+	.caps[23] = {HFI_CAPABILITY_BLUR_HEIGHT, 96, 4096, 1},
 	.num_caps = 24,
 	.pl[0] = {HFI_HEVC_PROFILE_MAIN, HFI_HEVC_LEVEL_6 | HFI_HEVC_TIER_HIGH0},
 	.pl[1] = {HFI_HEVC_PROFILE_MAIN10, HFI_HEVC_LEVEL_6 | HFI_HEVC_TIER_HIGH0},
@@ -210,8 +210,8 @@ static const struct hfi_plat_caps caps[] = {
 	.codec = HFI_VIDEO_CODEC_VP8,
 	.domain = VIDC_SESSION_TYPE_ENC,
 	.cap_bufs_mode_dynamic = true,
-	.caps[0] = {HFI_CAPABILITY_FRAME_WIDTH, 128, 4096, 16},
-	.caps[1] = {HFI_CAPABILITY_FRAME_HEIGHT, 128, 4096, 16},
+	.caps[0] = {HFI_CAPABILITY_FRAME_WIDTH, 128, 4096, 1},
+	.caps[1] = {HFI_CAPABILITY_FRAME_HEIGHT, 128, 4096, 1},
 	.caps[2] = {HFI_CAPABILITY_MBS_PER_FRAME, 64, 36864, 1},
 	.caps[3] = {HFI_CAPABILITY_BITRATE, 1, 74000000, 1},
 	.caps[4] = {HFI_CAPABILITY_SCALE_X, 8192, 65536, 1},
@@ -229,8 +229,8 @@ static const struct hfi_plat_caps caps[] = {
 	.caps[16] = {HFI_CAPABILITY_P_FRAME_QP, 0, 127, 1},
 	.caps[17] = {HFI_CAPABILITY_MAX_WORKMODES, 1, 2, 1},
 	.caps[18] = {HFI_CAPABILITY_RATE_CONTROL_MODES, 0x1000001, 0x1000005, 1},
-	.caps[19] = {HFI_CAPABILITY_BLUR_WIDTH, 96, 4096, 16},
-	.caps[20] = {HFI_CAPABILITY_BLUR_HEIGHT, 96, 4096, 16},
+	.caps[19] = {HFI_CAPABILITY_BLUR_WIDTH, 96, 4096, 1},
+	.caps[20] = {HFI_CAPABILITY_BLUR_HEIGHT, 96, 4096, 1},
 	.caps[21] = {HFI_CAPABILITY_COLOR_SPACE_CONVERSION, 0, 2, 1},
 	.caps[22] = {HFI_CAPABILITY_ROTATION, 1, 4, 90},
 	.num_caps = 23,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0390/2077] amba: use generic driver_override infrastructure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (388 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0389/2077] media: qcom: venus: relax encoder frame/blur step size on v6 Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0391/2077] cdx: " Greg Kroah-Hartman
                   ` (607 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Gui-Dong Han, Danilo Krummrich,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Danilo Krummrich <dakr@kernel.org>

[ Upstream commit 1947229f5f2a8d4ecf8c971aca68a1242bb7b37c ]

When a driver is probed through __driver_attach(), the bus' match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.

Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.

Note that calling match() from __driver_attach() without the device lock
held is intentional. [1]

Link: https://lore.kernel.org/driver-core/DGRGTIRHA62X.3RY09D9SOK77P@kernel.org/ [1]
Reported-by: Gui-Dong Han <hanguidong02@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=220789
Fixes: 3cf385713460 ("ARM: 8256/1: driver coamba: add device binding path 'driver_override'")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Link: https://patch.msgid.link/20260505133935.3772495-2-dakr@kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/amba/bus.c       | 37 ++++++-------------------------------
 include/linux/amba/bus.h |  5 -----
 2 files changed, 6 insertions(+), 36 deletions(-)

diff --git a/drivers/amba/bus.c b/drivers/amba/bus.c
index 6d479caf89cbd7..d721d64a985803 100644
--- a/drivers/amba/bus.c
+++ b/drivers/amba/bus.c
@@ -82,33 +82,6 @@ static void amba_put_disable_pclk(struct amba_device *pcdev)
 }
 
 
-static ssize_t driver_override_show(struct device *_dev,
-				    struct device_attribute *attr, char *buf)
-{
-	struct amba_device *dev = to_amba_device(_dev);
-	ssize_t len;
-
-	device_lock(_dev);
-	len = sprintf(buf, "%s\n", dev->driver_override);
-	device_unlock(_dev);
-	return len;
-}
-
-static ssize_t driver_override_store(struct device *_dev,
-				     struct device_attribute *attr,
-				     const char *buf, size_t count)
-{
-	struct amba_device *dev = to_amba_device(_dev);
-	int ret;
-
-	ret = driver_set_override(_dev, &dev->driver_override, buf, count);
-	if (ret)
-		return ret;
-
-	return count;
-}
-static DEVICE_ATTR_RW(driver_override);
-
 #define amba_attr_func(name,fmt,arg...)					\
 static ssize_t name##_show(struct device *_dev,				\
 			   struct device_attribute *attr, char *buf)	\
@@ -126,7 +99,6 @@ amba_attr_func(resource, "\t%016llx\t%016llx\t%016lx\n",
 static struct attribute *amba_dev_attrs[] = {
 	&dev_attr_id.attr,
 	&dev_attr_resource.attr,
-	&dev_attr_driver_override.attr,
 	NULL,
 };
 ATTRIBUTE_GROUPS(amba_dev);
@@ -209,10 +181,11 @@ static int amba_match(struct device *dev, const struct device_driver *drv)
 {
 	struct amba_device *pcdev = to_amba_device(dev);
 	const struct amba_driver *pcdrv = to_amba_driver(drv);
+	int ret;
 
 	mutex_lock(&pcdev->periphid_lock);
 	if (!pcdev->periphid) {
-		int ret = amba_read_periphid(pcdev);
+		ret = amba_read_periphid(pcdev);
 
 		/*
 		 * Returning any error other than -EPROBE_DEFER from bus match
@@ -230,8 +203,9 @@ static int amba_match(struct device *dev, const struct device_driver *drv)
 	mutex_unlock(&pcdev->periphid_lock);
 
 	/* When driver_override is set, only bind to the matching driver */
-	if (pcdev->driver_override)
-		return !strcmp(pcdev->driver_override, drv->name);
+	ret = device_match_driver_override(dev, drv);
+	if (ret >= 0)
+		return ret;
 
 	return amba_lookup(pcdrv->id_table, pcdev) != NULL;
 }
@@ -436,6 +410,7 @@ static const struct dev_pm_ops amba_pm = {
 const struct bus_type amba_bustype = {
 	.name		= "amba",
 	.dev_groups	= amba_dev_groups,
+	.driver_override = true,
 	.match		= amba_match,
 	.uevent		= amba_uevent,
 	.probe		= amba_probe,
diff --git a/include/linux/amba/bus.h b/include/linux/amba/bus.h
index 9946276aff7377..6c54d5c0d21f7f 100644
--- a/include/linux/amba/bus.h
+++ b/include/linux/amba/bus.h
@@ -71,11 +71,6 @@ struct amba_device {
 	unsigned int		cid;
 	struct amba_cs_uci_id	uci;
 	unsigned int		irq[AMBA_NR_IRQS];
-	/*
-	 * Driver name to force a match.  Do not set directly, because core
-	 * frees it.  Use driver_set_override() to set or clear it.
-	 */
-	const char		*driver_override;
 };
 
 struct amba_driver {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0391/2077] cdx: use generic driver_override infrastructure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (389 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0390/2077] amba: use generic driver_override infrastructure Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0392/2077] Drivers: hv: vmbus: " Greg Kroah-Hartman
                   ` (606 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Gui-Dong Han, Danilo Krummrich,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Danilo Krummrich <dakr@kernel.org>

[ Upstream commit d541aa1897f67f4f14c805785bff894bcc61dca1 ]

When a driver is probed through __driver_attach(), the bus' match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.

Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.

Note that calling match() from __driver_attach() without the device lock
held is intentional. [1]

Link: https://lore.kernel.org/driver-core/DGRGTIRHA62X.3RY09D9SOK77P@kernel.org/ [1]
Reported-by: Gui-Dong Han <hanguidong02@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=220789
Fixes: 2959ab247061 ("cdx: add the cdx bus driver")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Link: https://patch.msgid.link/20260505133935.3772495-3-dakr@kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cdx/cdx.c           | 40 +++++--------------------------------
 include/linux/cdx/cdx_bus.h |  4 ----
 2 files changed, 5 insertions(+), 39 deletions(-)

diff --git a/drivers/cdx/cdx.c b/drivers/cdx/cdx.c
index 9196dc50a48db4..d3d23024726215 100644
--- a/drivers/cdx/cdx.c
+++ b/drivers/cdx/cdx.c
@@ -156,8 +156,6 @@ static int cdx_unregister_device(struct device *dev,
 	} else {
 		cdx_destroy_res_attr(cdx_dev, MAX_CDX_DEV_RESOURCES);
 		debugfs_remove_recursive(cdx_dev->debugfs_dir);
-		kfree(cdx_dev->driver_override);
-		cdx_dev->driver_override = NULL;
 	}
 
 	/*
@@ -268,6 +266,7 @@ static int cdx_bus_match(struct device *dev, const struct device_driver *drv)
 	const struct cdx_driver *cdx_drv = to_cdx_driver(drv);
 	const struct cdx_device_id *found_id = NULL;
 	const struct cdx_device_id *ids;
+	int ret;
 
 	if (cdx_dev->is_bus)
 		return false;
@@ -275,7 +274,8 @@ static int cdx_bus_match(struct device *dev, const struct device_driver *drv)
 	ids = cdx_drv->match_id_table;
 
 	/* When driver_override is set, only bind to the matching driver */
-	if (cdx_dev->driver_override && strcmp(cdx_dev->driver_override, drv->name))
+	ret = device_match_driver_override(dev, drv);
+	if (ret == 0)
 		return false;
 
 	found_id = cdx_match_id(ids, cdx_dev);
@@ -289,7 +289,7 @@ static int cdx_bus_match(struct device *dev, const struct device_driver *drv)
 		 */
 		if (!found_id->override_only)
 			return true;
-		if (cdx_dev->driver_override)
+		if (ret > 0)
 			return true;
 
 		ids = found_id + 1;
@@ -453,36 +453,6 @@ static ssize_t modalias_show(struct device *dev, struct device_attribute *attr,
 }
 static DEVICE_ATTR_RO(modalias);
 
-static ssize_t driver_override_store(struct device *dev,
-				     struct device_attribute *attr,
-				     const char *buf, size_t count)
-{
-	struct cdx_device *cdx_dev = to_cdx_device(dev);
-	int ret;
-
-	if (WARN_ON(dev->bus != &cdx_bus_type))
-		return -EINVAL;
-
-	ret = driver_set_override(dev, &cdx_dev->driver_override, buf, count);
-	if (ret)
-		return ret;
-
-	return count;
-}
-
-static ssize_t driver_override_show(struct device *dev,
-				    struct device_attribute *attr, char *buf)
-{
-	struct cdx_device *cdx_dev = to_cdx_device(dev);
-	ssize_t len;
-
-	device_lock(dev);
-	len = sysfs_emit(buf, "%s\n", cdx_dev->driver_override);
-	device_unlock(dev);
-	return len;
-}
-static DEVICE_ATTR_RW(driver_override);
-
 static ssize_t enable_store(struct device *dev, struct device_attribute *attr,
 			    const char *buf, size_t count)
 {
@@ -552,7 +522,6 @@ static struct attribute *cdx_dev_attrs[] = {
 	&dev_attr_class.attr,
 	&dev_attr_revision.attr,
 	&dev_attr_modalias.attr,
-	&dev_attr_driver_override.attr,
 	NULL,
 };
 
@@ -646,6 +615,7 @@ ATTRIBUTE_GROUPS(cdx_bus);
 
 const struct bus_type cdx_bus_type = {
 	.name		= "cdx",
+	.driver_override = true,
 	.match		= cdx_bus_match,
 	.probe		= cdx_probe,
 	.remove		= cdx_remove,
diff --git a/include/linux/cdx/cdx_bus.h b/include/linux/cdx/cdx_bus.h
index b1ba97f6c9ad66..f54770f110bc8b 100644
--- a/include/linux/cdx/cdx_bus.h
+++ b/include/linux/cdx/cdx_bus.h
@@ -137,9 +137,6 @@ struct cdx_controller {
  * @enabled: is this bus enabled
  * @msi_dev_id: MSI Device ID associated with CDX device
  * @num_msi: Number of MSI's supported by the device
- * @driver_override: driver name to force a match; do not set directly,
- *                   because core frees it; use driver_set_override() to
- *                   set or clear it.
  * @irqchip_lock: lock to synchronize irq/msi configuration
  * @msi_write_pending: MSI write pending for this device
  */
@@ -165,7 +162,6 @@ struct cdx_device {
 	bool enabled;
 	u32 msi_dev_id;
 	u32 num_msi;
-	const char *driver_override;
 	struct mutex irqchip_lock;
 	bool msi_write_pending;
 };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0392/2077] Drivers: hv: vmbus: use generic driver_override infrastructure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (390 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0391/2077] cdx: " Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0393/2077] rpmsg: " Greg Kroah-Hartman
                   ` (605 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Kelley, Gui-Dong Han,
	Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Danilo Krummrich <dakr@kernel.org>

[ Upstream commit 331d8900121a1d74ecd45cd2db742ddcb5a0a565 ]

When a driver is probed through __driver_attach(), the bus' match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.

Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.

Note that calling match() from __driver_attach() without the device lock
held is intentional. [1]

Tested-by: Michael Kelley <mhklinux@outlook.com>
Reviewed-by: Michael Kelley <mhklinux@outlook.com>
Link: https://lore.kernel.org/driver-core/DGRGTIRHA62X.3RY09D9SOK77P@kernel.org/ [1]
Reported-by: Gui-Dong Han <hanguidong02@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=220789
Fixes: d765edbb301c ("vmbus: add driver_override support")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Link: https://patch.msgid.link/20260505133935.3772495-4-dakr@kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hv/vmbus_drv.c | 43 ++++++++++--------------------------------
 include/linux/hyperv.h |  5 -----
 2 files changed, 10 insertions(+), 38 deletions(-)

diff --git a/drivers/hv/vmbus_drv.c b/drivers/hv/vmbus_drv.c
index b80a35c778ab46..23206640c61397 100644
--- a/drivers/hv/vmbus_drv.c
+++ b/drivers/hv/vmbus_drv.c
@@ -548,34 +548,6 @@ static ssize_t device_show(struct device *dev,
 }
 static DEVICE_ATTR_RO(device);
 
-static ssize_t driver_override_store(struct device *dev,
-				     struct device_attribute *attr,
-				     const char *buf, size_t count)
-{
-	struct hv_device *hv_dev = device_to_hv_device(dev);
-	int ret;
-
-	ret = driver_set_override(dev, &hv_dev->driver_override, buf, count);
-	if (ret)
-		return ret;
-
-	return count;
-}
-
-static ssize_t driver_override_show(struct device *dev,
-				    struct device_attribute *attr, char *buf)
-{
-	struct hv_device *hv_dev = device_to_hv_device(dev);
-	ssize_t len;
-
-	device_lock(dev);
-	len = sysfs_emit(buf, "%s\n", hv_dev->driver_override);
-	device_unlock(dev);
-
-	return len;
-}
-static DEVICE_ATTR_RW(driver_override);
-
 /* Set up per device attributes in /sys/bus/vmbus/devices/<bus device> */
 static struct attribute *vmbus_dev_attrs[] = {
 	&dev_attr_id.attr,
@@ -606,7 +578,6 @@ static struct attribute *vmbus_dev_attrs[] = {
 	&dev_attr_channel_vp_mapping.attr,
 	&dev_attr_vendor.attr,
 	&dev_attr_device.attr,
-	&dev_attr_driver_override.attr,
 	NULL,
 };
 
@@ -718,9 +689,11 @@ static const struct hv_vmbus_device_id *hv_vmbus_get_id(const struct hv_driver *
 {
 	const guid_t *guid = &dev->dev_type;
 	const struct hv_vmbus_device_id *id;
+	int ret;
 
-	/* When driver_override is set, only bind to the matching driver */
-	if (dev->driver_override && strcmp(dev->driver_override, drv->name))
+	/* If a driver override is set, only bind to the matching driver */
+	ret = device_match_driver_override(&dev->device, &drv->driver);
+	if (ret == 0)
 		return NULL;
 
 	/* Look at the dynamic ids first, before the static ones */
@@ -728,8 +701,11 @@ static const struct hv_vmbus_device_id *hv_vmbus_get_id(const struct hv_driver *
 	if (!id)
 		id = hv_vmbus_dev_match(drv->id_table, guid);
 
-	/* driver_override will always match, send a dummy id */
-	if (!id && dev->driver_override)
+	/*
+	 * If there's a matching driver override, this function should succeed,
+	 * thus return a dummy device ID if no matching ID is found.
+	 */
+	if (!id && ret > 0)
 		id = &vmbus_device_null;
 
 	return id;
@@ -1031,6 +1007,7 @@ static const struct dev_pm_ops vmbus_pm = {
 /* The one and only one */
 static const struct bus_type  hv_bus = {
 	.name =		"vmbus",
+	.driver_override =	true,
 	.match =		vmbus_match,
 	.shutdown =		vmbus_shutdown,
 	.remove =		vmbus_remove,
diff --git a/include/linux/hyperv.h b/include/linux/hyperv.h
index 734b7ef98f4d2e..9de2c8d6037aad 100644
--- a/include/linux/hyperv.h
+++ b/include/linux/hyperv.h
@@ -1272,11 +1272,6 @@ struct hv_device {
 	u16 device_id;
 
 	struct device device;
-	/*
-	 * Driver name to force a match.  Do not set directly, because core
-	 * frees it.  Use driver_set_override() to set or clear it.
-	 */
-	const char *driver_override;
 
 	struct vmbus_channel *channel;
 	struct kset	     *channels_kset;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0393/2077] rpmsg: use generic driver_override infrastructure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (391 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0392/2077] Drivers: hv: vmbus: " Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0394/2077] arm64: dts: renesas: r8a78000: Fix GIC-720AE View 1 Redistributor description Greg Kroah-Hartman
                   ` (604 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Gui-Dong Han, Mathieu Poirier,
	Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Danilo Krummrich <dakr@kernel.org>

[ Upstream commit 55ced13c42921714e90f8fae94b6ed803330dc6a ]

When a driver is probed through __driver_attach(), the bus' match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.

Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.

Note that calling match() from __driver_attach() without the device lock
held is intentional. [1]

Link: https://lore.kernel.org/driver-core/DGRGTIRHA62X.3RY09D9SOK77P@kernel.org/ [1]
Reported-by: Gui-Dong Han <hanguidong02@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=220789
Fixes: e95060478244 ("rpmsg: Introduce a driver override mechanism")
Reviewed-by: Mathieu Poirier <mathieu.poirier@linaro.org>
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Link: https://patch.msgid.link/20260505133935.3772495-5-dakr@kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/rpmsg/qcom_glink_native.c |  2 --
 drivers/rpmsg/rpmsg_core.c        | 43 +++++--------------------------
 drivers/rpmsg/virtio_rpmsg_bus.c  |  1 -
 include/linux/rpmsg.h             |  4 ---
 4 files changed, 7 insertions(+), 43 deletions(-)

diff --git a/drivers/rpmsg/qcom_glink_native.c b/drivers/rpmsg/qcom_glink_native.c
index 401a4ece0c9777..d9d4468e4cbdfd 100644
--- a/drivers/rpmsg/qcom_glink_native.c
+++ b/drivers/rpmsg/qcom_glink_native.c
@@ -1626,7 +1626,6 @@ static void qcom_glink_rpdev_release(struct device *dev)
 {
 	struct rpmsg_device *rpdev = to_rpmsg_device(dev);
 
-	kfree(rpdev->driver_override);
 	kfree(rpdev);
 }
 
@@ -1862,7 +1861,6 @@ static void qcom_glink_device_release(struct device *dev)
 
 	/* Release qcom_glink_alloc_channel() reference */
 	kref_put(&channel->refcount, qcom_glink_channel_release);
-	kfree(rpdev->driver_override);
 	kfree(rpdev);
 }
 
diff --git a/drivers/rpmsg/rpmsg_core.c b/drivers/rpmsg/rpmsg_core.c
index e7f7831d37f899..c56f69c22e420c 100644
--- a/drivers/rpmsg/rpmsg_core.c
+++ b/drivers/rpmsg/rpmsg_core.c
@@ -358,33 +358,6 @@ rpmsg_show_attr(src, src, "0x%x\n");
 rpmsg_show_attr(dst, dst, "0x%x\n");
 rpmsg_show_attr(announce, announce ? "true" : "false", "%s\n");
 
-static ssize_t driver_override_store(struct device *dev,
-				     struct device_attribute *attr,
-				     const char *buf, size_t count)
-{
-	struct rpmsg_device *rpdev = to_rpmsg_device(dev);
-	int ret;
-
-	ret = driver_set_override(dev, &rpdev->driver_override, buf, count);
-	if (ret)
-		return ret;
-
-	return count;
-}
-
-static ssize_t driver_override_show(struct device *dev,
-				    struct device_attribute *attr, char *buf)
-{
-	struct rpmsg_device *rpdev = to_rpmsg_device(dev);
-	ssize_t len;
-
-	device_lock(dev);
-	len = sysfs_emit(buf, "%s\n", rpdev->driver_override);
-	device_unlock(dev);
-	return len;
-}
-static DEVICE_ATTR_RW(driver_override);
-
 static ssize_t modalias_show(struct device *dev,
 			     struct device_attribute *attr, char *buf)
 {
@@ -405,7 +378,6 @@ static struct attribute *rpmsg_dev_attrs[] = {
 	&dev_attr_dst.attr,
 	&dev_attr_src.attr,
 	&dev_attr_announce.attr,
-	&dev_attr_driver_override.attr,
 	NULL,
 };
 ATTRIBUTE_GROUPS(rpmsg_dev);
@@ -424,9 +396,11 @@ static int rpmsg_dev_match(struct device *dev, const struct device_driver *drv)
 	const struct rpmsg_driver *rpdrv = to_rpmsg_driver(drv);
 	const struct rpmsg_device_id *ids = rpdrv->id_table;
 	unsigned int i;
+	int ret;
 
-	if (rpdev->driver_override)
-		return !strcmp(rpdev->driver_override, drv->name);
+	ret = device_match_driver_override(dev, drv);
+	if (ret >= 0)
+		return ret;
 
 	if (ids)
 		for (i = 0; ids[i].name[0]; i++)
@@ -535,6 +509,7 @@ static const struct bus_type rpmsg_bus = {
 	.name		= "rpmsg",
 	.match		= rpmsg_dev_match,
 	.dev_groups	= rpmsg_dev_groups,
+	.driver_override = true,
 	.uevent		= rpmsg_uevent,
 	.probe		= rpmsg_dev_probe,
 	.remove		= rpmsg_dev_remove,
@@ -560,11 +535,9 @@ int rpmsg_register_device_override(struct rpmsg_device *rpdev,
 
 	device_initialize(dev);
 	if (driver_override) {
-		ret = driver_set_override(dev, &rpdev->driver_override,
-					  driver_override,
-					  strlen(driver_override));
+		ret = device_set_driver_override(dev, driver_override);
 		if (ret) {
-			dev_err(dev, "device_set_override failed: %d\n", ret);
+			dev_err(dev, "device_set_driver_override() failed: %d\n", ret);
 			put_device(dev);
 			return ret;
 		}
@@ -573,8 +546,6 @@ int rpmsg_register_device_override(struct rpmsg_device *rpdev,
 	ret = device_add(dev);
 	if (ret) {
 		dev_err(dev, "device_add failed: %d\n", ret);
-		kfree(rpdev->driver_override);
-		rpdev->driver_override = NULL;
 		put_device(dev);
 	}
 
diff --git a/drivers/rpmsg/virtio_rpmsg_bus.c b/drivers/rpmsg/virtio_rpmsg_bus.c
index 5ae15111fb4f18..1b8bb05924af73 100644
--- a/drivers/rpmsg/virtio_rpmsg_bus.c
+++ b/drivers/rpmsg/virtio_rpmsg_bus.c
@@ -374,7 +374,6 @@ static void virtio_rpmsg_release_device(struct device *dev)
 	struct rpmsg_device *rpdev = to_rpmsg_device(dev);
 	struct virtio_rpmsg_channel *vch = to_virtio_rpmsg_channel(rpdev);
 
-	kfree(rpdev->driver_override);
 	kfree(vch);
 }
 
diff --git a/include/linux/rpmsg.h b/include/linux/rpmsg.h
index 83266ce1464204..2e40eb54155e02 100644
--- a/include/linux/rpmsg.h
+++ b/include/linux/rpmsg.h
@@ -41,9 +41,6 @@ struct rpmsg_channel_info {
  * rpmsg_device - device that belong to the rpmsg bus
  * @dev: the device struct
  * @id: device id (used to match between rpmsg drivers and devices)
- * @driver_override: driver name to force a match; do not set directly,
- *                   because core frees it; use driver_set_override() to
- *                   set or clear it.
  * @src: local address
  * @dst: destination address
  * @ept: the rpmsg endpoint of this channel
@@ -53,7 +50,6 @@ struct rpmsg_channel_info {
 struct rpmsg_device {
 	struct device dev;
 	struct rpmsg_device_id id;
-	const char *driver_override;
 	u32 src;
 	u32 dst;
 	struct rpmsg_endpoint *ept;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0394/2077] arm64: dts: renesas: r8a78000: Fix GIC-720AE View 1 Redistributor description
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (392 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0393/2077] rpmsg: " Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0395/2077] arm64: dts: renesas: ironhide: Describe all reserved memory Greg Kroah-Hartman
                   ` (603 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Marc Zyngier, Marek Vasut,
	Geert Uytterhoeven, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marek Vasut <marek.vasut+renesas@mailbox.org>

[ Upstream commit 54613573ff1495b928e2841b257c081a58566901 ]

The Renesas R-Car X5H (R8A78000) SoC contains Arm CoreLink GIC-720AE
Generic Interrupt Controller with Multi View capability. Firmware has
access to configuration View 0, Linux kernel has access to View 1.

The Arm CoreLink GIC-720AE Generic Interrupt Controller Technical
Reference Manual, currently latest r2p1 [1], chapter "5. Programmers
model for GIC-720AE", subchapter "5.4 Redistributor registers
for control and physical LPIs summary", part "5.4.3 GICR_TYPER,
Redistributor Type Register", "Table 5-50: GICR_TYPER bit descriptions"
on page 200, clarifies register "GICR_TYPER" bit 4 "Last" behavior
in Multi View setup as follows:

    Last
    Last Redistributor:

    0 ... This Redistributor is not the last Redistributor on the chip.
    1 ... This Redistributor is the last Redistributor on the chip.
	  When GICD_CFGID.VIEW == 1, for views 1, 2, or 3 this bit
	  always returns 1.

On this SoC, GICD_CFGID.VIEW is 1 and the Linux kernel has access to
View 1, therefore Linux kernel GICv3 driver will interpret register
"GICR_TYPER" bit 4 "Last" = 1 in the first Redistributor in continuous
Redistributor page as that first Redistributor being the one and only
Redistributor and will stop processing the continuous Redistributor
page further. This will prevent the other Redistributors from being
recognized by the system and used for other PEs.

Because the hardware indicates that the continuous Redistributor page
is not continuous for View 1, 2, or 3, describe every Redistributor
separately in the DT. This makes all Redistributors for all cores
accessible in Linux.

[1] https://documentation-service.arm.com/static/69ef3c1cd35efd294e335c43
    Arm® CoreLink™ GIC-720AE Generic Interrupt Controller
    Revision: r2p1 / Issue 12 / 102666_0201_12_en

Fixes: 63500d12cf76 ("arm64: dts: renesas: Add R8A78000 SoC support")
Acked-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Marek Vasut <marek.vasut+renesas@mailbox.org>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260514125328.20954-1-marek.vasut+renesas@mailbox.org
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/renesas/r8a78000.dtsi | 36 +++++++++++++++++++++--
 1 file changed, 34 insertions(+), 2 deletions(-)

diff --git a/arch/arm64/boot/dts/renesas/r8a78000.dtsi b/arch/arm64/boot/dts/renesas/r8a78000.dtsi
index 3ec1b53d278282..73be51787265c3 100644
--- a/arch/arm64/boot/dts/renesas/r8a78000.dtsi
+++ b/arch/arm64/boot/dts/renesas/r8a78000.dtsi
@@ -689,8 +689,40 @@ gic: interrupt-controller@39000000 {
 			#interrupt-cells = <3>;
 			#address-cells = <0>;
 			interrupt-controller;
-			reg = <0 0x39000000 0 0x10000>,
-			      <0 0x39080000 0 0x800000>;
+			#redistributor-regions = <32>;
+			reg = <0x0 0x39000000 0x0 0x10000>,
+			      <0x0 0x39080000 0x0 0x40000>,
+			      <0x0 0x390c0000 0x0 0x40000>,
+			      <0x0 0x39100000 0x0 0x40000>,
+			      <0x0 0x39140000 0x0 0x40000>,
+			      <0x0 0x39180000 0x0 0x40000>,
+			      <0x0 0x391c0000 0x0 0x40000>,
+			      <0x0 0x39200000 0x0 0x40000>,
+			      <0x0 0x39240000 0x0 0x40000>,
+			      <0x0 0x39280000 0x0 0x40000>,
+			      <0x0 0x392c0000 0x0 0x40000>,
+			      <0x0 0x39300000 0x0 0x40000>,
+			      <0x0 0x39340000 0x0 0x40000>,
+			      <0x0 0x39380000 0x0 0x40000>,
+			      <0x0 0x393c0000 0x0 0x40000>,
+			      <0x0 0x39400000 0x0 0x40000>,
+			      <0x0 0x39440000 0x0 0x40000>,
+			      <0x0 0x39480000 0x0 0x40000>,
+			      <0x0 0x394c0000 0x0 0x40000>,
+			      <0x0 0x39500000 0x0 0x40000>,
+			      <0x0 0x39540000 0x0 0x40000>,
+			      <0x0 0x39580000 0x0 0x40000>,
+			      <0x0 0x395c0000 0x0 0x40000>,
+			      <0x0 0x39600000 0x0 0x40000>,
+			      <0x0 0x39640000 0x0 0x40000>,
+			      <0x0 0x39680000 0x0 0x40000>,
+			      <0x0 0x396c0000 0x0 0x40000>,
+			      <0x0 0x39700000 0x0 0x40000>,
+			      <0x0 0x39740000 0x0 0x40000>,
+			      <0x0 0x39780000 0x0 0x40000>,
+			      <0x0 0x397c0000 0x0 0x40000>,
+			      <0x0 0x39800000 0x0 0x40000>,
+			      <0x0 0x39840000 0x0 0x40000>;
 			interrupts = <GIC_PPI 9 IRQ_TYPE_LEVEL_HIGH>;
 		};
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0395/2077] arm64: dts: renesas: ironhide: Describe all reserved memory
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (393 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0394/2077] arm64: dts: renesas: r8a78000: Fix GIC-720AE View 1 Redistributor description Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0396/2077] md/raid10: reset read_slot when reusing r10bio for discard Greg Kroah-Hartman
                   ` (602 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Marek Vasut, Geert Uytterhoeven,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marek Vasut <marek.vasut+renesas@mailbox.org>

[ Upstream commit 5250b3b1ad99d216b31c98b2b321f1dee362a1b5 ]

Fully describe all available DRAM in the DT, and describe regions which
are not accessible because they are used by firmware in reserved-memory
nodes.

Replace the first memory bank memory@60600000 with memory@40000000 and a
518 MiB long reserved-memory no-map subnode. This memory region is used
by other cores in the system.

Reserve 32 kiB of memory at 0x8c100000 for parameters shared by IPL,
SCP, TFA BL31 and TEE.

Reserve 512 kiB of memory at 0x8c200000 for TFA BL31.  The upcoming
upstream TFA 2.15 BL31 uses memory from 0x8c200000..0x8c242fff; rounding
up to 512 kiB is slight future-proofing.

Reserve 32 MiB of memory at 0x8c400000 for OPTEE-OS, which is the entire
OPTEE-OS TZ protected DRAM area.

Neither TFA BL31 nor OPTEE-OS modify the DT passed to Linux in any way
with any new reserved-memory {} nodes to reserve memory areas used by
the TFA BL31 or OPTEE-OS to prevent the next stage from using those
areas, which lets Linux use all of the available DRAM as it is described
in the DT that was passed in by U-Boot, including the areas that are
newly utilized by TFA BL31 or OPTEE-OS.

In case of high DRAM utilization, unless the memory used by TFA BL31 or
OPTEE-OS is properly reserved, Linux may use and corrupt the memory used
by TFA BL31 or OPTEE-OS, which would lead to the system becoming
unresponsive.

Fixes: ad142a4ef710 ("arm64: dts: renesas: r8a78000: Add initial Ironhide board support")
Signed-off-by: Marek Vasut <marek.vasut+renesas@mailbox.org>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260517163212.18016-1-marek.vasut+renesas@mailbox.org
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../boot/dts/renesas/r8a78000-ironhide.dts    | 35 +++++++++++++++++--
 1 file changed, 32 insertions(+), 3 deletions(-)

diff --git a/arch/arm64/boot/dts/renesas/r8a78000-ironhide.dts b/arch/arm64/boot/dts/renesas/r8a78000-ironhide.dts
index a721734fbd5d01..ed027a6c356ed1 100644
--- a/arch/arm64/boot/dts/renesas/r8a78000-ironhide.dts
+++ b/arch/arm64/boot/dts/renesas/r8a78000-ironhide.dts
@@ -20,10 +20,9 @@ chosen {
 		stdout-path = "serial0:1843200n8";
 	};
 
-	memory@60600000 {
+	memory@40000000 {
 		device_type = "memory";
-		/* first 518MiB is reserved for other purposes. */
-		reg = <0x0 0x60600000 0x0 0x5fa00000>;
+		reg = <0x0 0x40000000 0x0 0x80000000>;
 	};
 
 	memory@1080000000 {
@@ -65,6 +64,36 @@ memory@1e00000000 {
 		device_type = "memory";
 		reg = <0x1e 0x00000000 0x1 0x00000000>;
 	};
+
+	reserved-memory {
+		#address-cells = <2>;
+		#size-cells = <2>;
+		ranges;
+
+		/* First 518 MiB is reserved for other purposes. */
+		firmware@40000000 {
+			reg = <0x0 0x40000000 0x0 0x20600000>;
+			no-map;
+		};
+
+		/* Parameters set by IPL. */
+		parameters@8c100000 {
+			reg = <0x0 0x8c100000 0x0 0x00008000>;
+			no-map;
+		};
+
+		/* TFA BL31. */
+		tfa-bl31@8c200000 {
+			reg = <0x0 0x8c200000 0x0 0x00080000>;
+			no-map;
+		};
+
+		/* TEE TZ DRAM. */
+		tee@8c400000 {
+			reg = <0x0 0x8c400000 0x0 0x02000000>;
+			no-map;
+		};
+	};
 };
 
 &extal_clk {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0396/2077] md/raid10: reset read_slot when reusing r10bio for discard
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (394 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0395/2077] arm64: dts: renesas: ironhide: Describe all reserved memory Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0397/2077] md/raid1,raid10: fix deadlock in read error recovery path Greg Kroah-Hartman
                   ` (601 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chen Cheng, Xiao Ni, Yu Kuai,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chen Cheng <chencheng@fnnas.com>

[ Upstream commit 6b8a26af065ddc93de2aa5c9f0df98dce9723442 ]

put_all_bios() always drops devs[i].bio, but it only drops
devs[i].repl_bio when r10_bio->read_slot < 0. If discard reuses an
r10bio that was previously used for a read, read_slot can still be
non-negative, and discard cleanup can skip bio_put() on repl_bio.

Reset read_slot to -1 when preparing an r10bio for discard so the
replacement bio is always released correctly.

Fixes: d30588b2731f ("md/raid10: improve raid10 discard request")
Signed-off-by: Chen Cheng <chencheng@fnnas.com>
Reviewed-by: Xiao Ni <xiao@kernel.org>
Link: https://patch.msgid.link/20260515093019.3436882-1-chencheng@fnnas.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/md/raid10.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/md/raid10.c b/drivers/md/raid10.c
index 39085e7dd6d26d..7dc2a5a127e893 100644
--- a/drivers/md/raid10.c
+++ b/drivers/md/raid10.c
@@ -1727,6 +1727,7 @@ static int raid10_handle_discard(struct mddev *mddev, struct bio *bio)
 	r10_bio->mddev = mddev;
 	r10_bio->state = 0;
 	r10_bio->sectors = 0;
+	r10_bio->read_slot = -1;
 	memset(r10_bio->devs, 0, sizeof(r10_bio->devs[0]) * geo->raid_disks);
 	wait_blocked_dev(mddev, r10_bio);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0397/2077] md/raid1,raid10: fix deadlock in read error recovery path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (395 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0396/2077] md/raid10: reset read_slot when reusing r10bio for discard Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0398/2077] md/raid1,raid10: fix error-path detection with md_cloned_bio() Greg Kroah-Hartman
                   ` (600 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Abd-Alrhman Masalkhi, Xiao Ni,
	Yu Kuai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>

[ Upstream commit 7b15c24f805339a585cfe7d72f446b7e88b9bcc0 ]

raid1d and raid10d may resubmit a split md cloned bio while handling
a read error. In this case, resubmitting the bio can lead to a deadlock
if the array is suspended before md_handle_request() acquires an
active_io reference via percpu_ref_tryget_live().

Since the cloned bio already holds an active_io reference,
trying to acquire another reference via percpu_ref_tryget_live()
can lead to a deadlock while the array is suspended.

Fix this by using percpu_ref_get() for md cloned bios.

Fixes: bb2a9acefaf9 ("md/raid1: switch to use md_account_bio() for io accounting")
Fixes: 820455238366 ("md/raid10: switch to use md_account_bio() for io accounting")
Signed-off-by: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
Reviewed-by: Xiao Ni <xiao@kernel.org>
Reviewed-by: Yu Kuai <yukuai@fygo.io>
Link: https://patch.msgid.link/20260501114652.590037-2-abd.masalkhi@gmail.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/md/md.c | 25 ++++++++++++++++---------
 drivers/md/md.h |  5 +++++
 2 files changed, 21 insertions(+), 9 deletions(-)

diff --git a/drivers/md/md.c b/drivers/md/md.c
index 8b568eee87433a..518d1d9c22031f 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -395,17 +395,24 @@ static bool is_suspended(struct mddev *mddev, struct bio *bio)
 bool md_handle_request(struct mddev *mddev, struct bio *bio)
 {
 check_suspended:
-	if (is_suspended(mddev, bio)) {
-		/* Bail out if REQ_NOWAIT is set for the bio */
-		if (bio->bi_opf & REQ_NOWAIT) {
-			bio_wouldblock_error(bio);
-			return true;
+	if (unlikely(md_cloned_bio(mddev, bio))) {
+		/*
+		 * This bio is an MD cloned bio and already holds an
+		 * active_io reference, so percpu_ref_get() is safe here.
+		 */
+		percpu_ref_get(&mddev->active_io);
+	} else {
+		if (is_suspended(mddev, bio)) {
+			/* Bail out if REQ_NOWAIT is set for the bio */
+			if (bio->bi_opf & REQ_NOWAIT) {
+				bio_wouldblock_error(bio);
+				return true;
+			}
+			wait_event(mddev->sb_wait, !is_suspended(mddev, bio));
 		}
-		wait_event(mddev->sb_wait, !is_suspended(mddev, bio));
+		if (!percpu_ref_tryget_live(&mddev->active_io))
+			goto check_suspended;
 	}
-	if (!percpu_ref_tryget_live(&mddev->active_io))
-		goto check_suspended;
-
 	if (!mddev->pers->make_request(mddev, bio)) {
 		percpu_ref_put(&mddev->active_io);
 		if (mddev_is_dm(mddev) && mddev->pers->prepare_suspend)
diff --git a/drivers/md/md.h b/drivers/md/md.h
index 52c37808604646..aca5c06e5fe31c 100644
--- a/drivers/md/md.h
+++ b/drivers/md/md.h
@@ -1042,6 +1042,11 @@ void mddev_update_io_opt(struct mddev *mddev, unsigned int nr_stripes);
 
 extern const struct block_device_operations md_fops;
 
+static inline bool md_cloned_bio(struct mddev *mddev, struct bio *bio)
+{
+	return bio->bi_pool == &mddev->io_clone_set;
+}
+
 /*
  * MD devices can be used undeneath by DM, in which case ->gendisk is NULL.
  */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0398/2077] md/raid1,raid10: fix error-path detection with md_cloned_bio()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (396 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0397/2077] md/raid1,raid10: fix deadlock in read error recovery path Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0399/2077] md/raid1,raid10: fix bio accounting for split md cloned bios Greg Kroah-Hartman
                   ` (599 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Abd-Alrhman Masalkhi, Xiao Ni,
	Yu Kuai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>

[ Upstream commit 811545e0926d02a6a0b1a1258bb5544777c164d4 ]

Detect the error path using md_cloned_bio() instead of relying
on r1_bio in raid1 or r10_bio->read_slot in raid10, which may be
NULL or -1 after splitting and resubmitting a failed bio.

As a result, the error path may not be recognized and memory
allocations can incorrectly use GFP_NOIO instead of
(GFP_NOIO | __GFP_HIGH), which can lead to a deadlock under
memory pressure.

Fixes: 689389a06ce7 ("md/raid1: simplify handle_read_error().")
Fixes: 545250f24809 ("md/raid10: simplify handle_read_error()")
Signed-off-by: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
Reviewed-by: Xiao Ni <xiao@kernel.org>
Link: https://patch.msgid.link/20260501114652.590037-3-abd.masalkhi@gmail.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/md/raid1.c  | 13 ++++++++++---
 drivers/md/raid10.c | 20 ++++++++++++++------
 2 files changed, 24 insertions(+), 9 deletions(-)

diff --git a/drivers/md/raid1.c b/drivers/md/raid1.c
index 64d970e2ef50fd..22458df5069e9d 100644
--- a/drivers/md/raid1.c
+++ b/drivers/md/raid1.c
@@ -1343,11 +1343,18 @@ static void raid1_read_request(struct mddev *mddev, struct bio *bio,
 	bool r1bio_existed = !!r1_bio;
 
 	/*
-	 * If r1_bio is set, we are blocking the raid1d thread
-	 * so there is a tiny risk of deadlock.  So ask for
+	 * An md cloned bio indicates we are in the error path.
+	 * This is more reliable than checking r1_bio, which might
+	 * be NULL even in the error path if a failed bio was split.
+	 */
+	bool err_path = md_cloned_bio(mddev, bio);
+
+	/*
+	 * If we are in the error path, we are blocking the raid1d
+	 * thread so there is a tiny risk of deadlock.  So ask for
 	 * emergency memory if needed.
 	 */
-	gfp_t gfp = r1_bio ? (GFP_NOIO | __GFP_HIGH) : GFP_NOIO;
+	gfp_t gfp = err_path ? (GFP_NOIO | __GFP_HIGH) : GFP_NOIO;
 
 	/*
 	 * Still need barrier for READ in case that whole
diff --git a/drivers/md/raid10.c b/drivers/md/raid10.c
index 7dc2a5a127e893..b38a0ccd4661a3 100644
--- a/drivers/md/raid10.c
+++ b/drivers/md/raid10.c
@@ -1155,7 +1155,20 @@ static void raid10_read_request(struct mddev *mddev, struct bio *bio,
 	char b[BDEVNAME_SIZE];
 	int slot = r10_bio->read_slot;
 	struct md_rdev *err_rdev = NULL;
-	gfp_t gfp = GFP_NOIO;
+
+	/*
+	 * An md cloned bio indicates we are in the error path.
+	 * This is more reliable than checking slot, which might
+	 * be -1 even in the error path if a failed bio was split.
+	 */
+	bool err_path = md_cloned_bio(mddev, bio);
+
+	/*
+	 * If we are in the error path, we are blocking the raid10d
+	 * thread so there is a tiny risk of deadlock.  So ask for
+	 * emergency memory if needed.
+	 */
+	gfp_t gfp = err_path ? (GFP_NOIO | __GFP_HIGH) : GFP_NOIO;
 
 	if (slot >= 0 && r10_bio->devs[slot].rdev) {
 		/*
@@ -1166,11 +1179,6 @@ static void raid10_read_request(struct mddev *mddev, struct bio *bio,
 		 * we lose the device name in error messages.
 		 */
 		int disk;
-		/*
-		 * As we are blocking raid10, it is a little safer to
-		 * use __GFP_HIGH.
-		 */
-		gfp = GFP_NOIO | __GFP_HIGH;
 
 		disk = r10_bio->devs[slot].devnum;
 		err_rdev = conf->mirrors[disk].rdev;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0399/2077] md/raid1,raid10: fix bio accounting for split md cloned bios
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (397 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0398/2077] md/raid1,raid10: fix error-path detection with md_cloned_bio() Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0400/2077] raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path Greg Kroah-Hartman
                   ` (598 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Abd-Alrhman Masalkhi, Xiao Ni,
	Yu Kuai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>

[ Upstream commit ba976e3501111d11c550848b3b7341a73035f582 ]

Use md_cloned_bio() to control bio accounting instead of relying
on r1bio_existed in raid1 or the io_accounting flag in raid10.

The previous logic does not reliably reflect whether a bio is an
md cloned bio. When a failed bio is split and resubmitted via
bio_submit_split_bioset() on the error path, this can lead to either
double accounting for md cloned bios, or missing accounting for bios
returned from bio_submit_split_bioset()

Fix this by using md_cloned_bio() to detect md cloned bios and
skip accounting accordingly.

Fixes: bb2a9acefaf9 ("md/raid1: switch to use md_account_bio() for io accounting")
Fixes: 820455238366 ("md/raid10: switch to use md_account_bio() for io accounting")
Signed-off-by: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
Reviewed-by: Xiao Ni <xiao@kernel.org>
Link: https://patch.msgid.link/20260501114652.590037-4-abd.masalkhi@gmail.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/md/raid1.c  | 2 +-
 drivers/md/raid10.c | 8 ++++----
 2 files changed, 5 insertions(+), 5 deletions(-)

diff --git a/drivers/md/raid1.c b/drivers/md/raid1.c
index 22458df5069e9d..603aa09088f05a 100644
--- a/drivers/md/raid1.c
+++ b/drivers/md/raid1.c
@@ -1418,7 +1418,7 @@ static void raid1_read_request(struct mddev *mddev, struct bio *bio,
 	}
 
 	r1_bio->read_disk = rdisk;
-	if (!r1bio_existed) {
+	if (likely(!md_cloned_bio(mddev, bio))) {
 		md_account_bio(mddev, &bio);
 		r1_bio->master_bio = bio;
 	}
diff --git a/drivers/md/raid10.c b/drivers/md/raid10.c
index b38a0ccd4661a3..5bd7698e0a1b54 100644
--- a/drivers/md/raid10.c
+++ b/drivers/md/raid10.c
@@ -1146,7 +1146,7 @@ static bool regular_request_wait(struct mddev *mddev, struct r10conf *conf,
 }
 
 static void raid10_read_request(struct mddev *mddev, struct bio *bio,
-				struct r10bio *r10_bio, bool io_accounting)
+				struct r10bio *r10_bio)
 {
 	struct r10conf *conf = mddev->private;
 	struct bio *read_bio;
@@ -1226,7 +1226,7 @@ static void raid10_read_request(struct mddev *mddev, struct bio *bio,
 	}
 	slot = r10_bio->read_slot;
 
-	if (io_accounting) {
+	if (likely(!md_cloned_bio(mddev, bio))) {
 		md_account_bio(mddev, &bio);
 		r10_bio->master_bio = bio;
 	}
@@ -1552,7 +1552,7 @@ static void __make_request(struct mddev *mddev, struct bio *bio, int sectors)
 			conf->geo.raid_disks);
 
 	if (bio_data_dir(bio) == READ)
-		raid10_read_request(mddev, bio, r10_bio, true);
+		raid10_read_request(mddev, bio, r10_bio);
 	else
 		raid10_write_request(mddev, bio, r10_bio);
 }
@@ -2867,7 +2867,7 @@ static void handle_read_error(struct mddev *mddev, struct r10bio *r10_bio)
 
 	rdev_dec_pending(rdev, mddev);
 	r10_bio->state = 0;
-	raid10_read_request(mddev, r10_bio->master_bio, r10_bio, false);
+	raid10_read_request(mddev, r10_bio->master_bio, r10_bio);
 	/*
 	 * allow_barrier after re-submit to ensure no sync io
 	 * can be issued while regular io pending.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0400/2077] raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (398 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0399/2077] md/raid1,raid10: fix bio accounting for split md cloned bios Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0401/2077] bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat Greg Kroah-Hartman
                   ` (597 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Abd-Alrhman Masalkhi, Yu Kuai,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>

[ Upstream commit 909d9dc3b5730c8ed7b764c68bc788342df2a07b ]

In raid1_write_request(), each per-mirror loop iteration begins by
incrementing rdev->nr_pending. If a REQ_ATOMIC write encounters a
badblock within the requested range, the code jumps to err_handle
without dropping the reference taken for the current mirror.

err_handle's cleanup loop will only decrements for k < i and
r1_bio->bios[k] is non-NULL. The current slot is therefore skipped,
leaving its nr_pending reference leaked permanently. The reference
prevents the rdev from ever being removed, since raid1_remove_conf()
refuses to remove an rdev with nr_pending > 0.

Fix this by calling rdev_dec_pending() before jumping to err_handle.

Fixes: f2a38abf5f1c ("md/raid1: Atomic write support")
Signed-off-by: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
Link: https://patch.msgid.link/20260530151411.4119-1-abd.masalkhi@gmail.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/md/raid1.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/md/raid1.c b/drivers/md/raid1.c
index 603aa09088f05a..1f22250334bca4 100644
--- a/drivers/md/raid1.c
+++ b/drivers/md/raid1.c
@@ -1603,8 +1603,10 @@ static void raid1_write_request(struct mddev *mddev, struct bio *bio,
 				 * complexity of supporting that is not worth
 				 * the benefit.
 				 */
-				if (bio->bi_opf & REQ_ATOMIC)
+				if (bio->bi_opf & REQ_ATOMIC) {
+					rdev_dec_pending(rdev, mddev);
 					goto err_handle;
+				}
 
 				good_sectors = first_bad - r1_bio->sector;
 				if (good_sectors < max_sectors)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0401/2077] bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (399 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0400/2077] raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0402/2077] selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries Greg Kroah-Hartman
                   ` (596 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Maciej Żenczykowski,
	Lorenzo Colitti, Yuyang Huang, Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yuyang Huang <yuyanghuang@google.com>

[ Upstream commit 21c4b99b27f3f85b89256e81b3e997dec0a460d0 ]

BPF_PROG_QUERY writes back the 'query.revision' field unconditionally to
userspace. If userspace passes a smaller 'bpf_attr' structure (e.g. 40
bytes, which was the layout before the addition of 'query.revision'),
the kernel performs an out-of-bounds write.

Fix this by propagating the user-provided attribute size 'uattr_size'
down to the cgroup query handlers, and conditionally skipping writing
the revision field to userspace when the provided buffer size is
insufficient.

query.revision in bpf_mprog_query is structurally identical to the
cgroup case: a late tail field, written unconditionally.

But the backward-compat hazard is not the same.

The min-historical-size test is per command, and bpf_mprog_query only
serves attach types that were born with revision in the struct:

- tcx_prog_query -> BPF_TCX_INGRESS/EGRESS
- netkit_prog_query -> BPF_NETKIT_PRIMARY/PEER

tcx, netkit, the revision field, and bpf_mprog_query itself all landed in
the same v6.6 merge window (053c8e1f235d added the mprog query API +
revision; tcx in e420bed02507, netkit in 35dfaad7188c). There has never
been a tcx/netkit BPF_PROG_QUERY userspace that doesn't know about
revision. So for these commands the minimum legitimate struct already
covers offset 56-64 — no old binary can be broken here.

Contrast with cgroup: BPF_PROG_QUERY on cgroup attach types shipped in
2017; revision write-back was bolted on years later (120933984460). That
path has a real population of pre-revision callers.

Fixes: 120933984460 ("bpf: Implement mprog API on top of existing cgroup progs")
Cc: Maciej Żenczykowski <maze@google.com>
Cc: Lorenzo Colitti <lorenzo@google.com>
Signed-off-by: Yuyang Huang <yuyanghuang@google.com>
Link: https://lore.kernel.org/r/20260531075600.4058207-2-yuyanghuang@google.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/bpf-cgroup.h |  5 +++--
 kernel/bpf/cgroup.c        | 13 +++++++------
 kernel/bpf/syscall.c       |  6 +++---
 3 files changed, 13 insertions(+), 11 deletions(-)

diff --git a/include/linux/bpf-cgroup.h b/include/linux/bpf-cgroup.h
index b2e79c2b41d516..4d0cc65976a14a 100644
--- a/include/linux/bpf-cgroup.h
+++ b/include/linux/bpf-cgroup.h
@@ -421,7 +421,7 @@ int cgroup_bpf_prog_detach(const union bpf_attr *attr,
 			   enum bpf_prog_type ptype);
 int cgroup_bpf_link_attach(const union bpf_attr *attr, struct bpf_prog *prog);
 int cgroup_bpf_prog_query(const union bpf_attr *attr,
-			  union bpf_attr __user *uattr);
+			  union bpf_attr __user *uattr, u32 uattr_size);
 
 const struct bpf_func_proto *
 cgroup_common_func_proto(enum bpf_func_id func_id, const struct bpf_prog *prog);
@@ -452,7 +452,8 @@ static inline int cgroup_bpf_link_attach(const union bpf_attr *attr,
 }
 
 static inline int cgroup_bpf_prog_query(const union bpf_attr *attr,
-					union bpf_attr __user *uattr)
+					union bpf_attr __user *uattr,
+					u32 uattr_size)
 {
 	return -EINVAL;
 }
diff --git a/kernel/bpf/cgroup.c b/kernel/bpf/cgroup.c
index f4eefdacd45339..89ea605457906e 100644
--- a/kernel/bpf/cgroup.c
+++ b/kernel/bpf/cgroup.c
@@ -1208,7 +1208,7 @@ static int cgroup_bpf_detach(struct cgroup *cgrp, struct bpf_prog *prog,
 
 /* Must be called with cgroup_mutex held to avoid races. */
 static int __cgroup_bpf_query(struct cgroup *cgrp, const union bpf_attr *attr,
-			      union bpf_attr __user *uattr)
+			      union bpf_attr __user *uattr, u32 uattr_size)
 {
 	__u32 __user *prog_attach_flags = u64_to_user_ptr(attr->query.prog_attach_flags);
 	bool effective_query = attr->query.query_flags & BPF_F_QUERY_EFFECTIVE;
@@ -1259,7 +1259,8 @@ static int __cgroup_bpf_query(struct cgroup *cgrp, const union bpf_attr *attr,
 		return -EFAULT;
 	if (!effective_query && from_atype == to_atype)
 		revision = cgrp->bpf.revisions[from_atype];
-	if (copy_to_user(&uattr->query.revision, &revision, sizeof(revision)))
+	if (uattr_size >= offsetofend(union bpf_attr, query.revision) &&
+	    copy_to_user(&uattr->query.revision, &revision, sizeof(revision)))
 		return -EFAULT;
 	if (attr->query.prog_cnt == 0 || !prog_ids || !total_cnt)
 		/* return early if user requested only program count + flags */
@@ -1312,12 +1313,12 @@ static int __cgroup_bpf_query(struct cgroup *cgrp, const union bpf_attr *attr,
 }
 
 static int cgroup_bpf_query(struct cgroup *cgrp, const union bpf_attr *attr,
-			    union bpf_attr __user *uattr)
+			    union bpf_attr __user *uattr, u32 uattr_size)
 {
 	int ret;
 
 	cgroup_lock();
-	ret = __cgroup_bpf_query(cgrp, attr, uattr);
+	ret = __cgroup_bpf_query(cgrp, attr, uattr, uattr_size);
 	cgroup_unlock();
 	return ret;
 }
@@ -1520,7 +1521,7 @@ int cgroup_bpf_link_attach(const union bpf_attr *attr, struct bpf_prog *prog)
 }
 
 int cgroup_bpf_prog_query(const union bpf_attr *attr,
-			  union bpf_attr __user *uattr)
+			  union bpf_attr __user *uattr, u32 uattr_size)
 {
 	struct cgroup *cgrp;
 	int ret;
@@ -1529,7 +1530,7 @@ int cgroup_bpf_prog_query(const union bpf_attr *attr,
 	if (IS_ERR(cgrp))
 		return PTR_ERR(cgrp);
 
-	ret = cgroup_bpf_query(cgrp, attr, uattr);
+	ret = cgroup_bpf_query(cgrp, attr, uattr, uattr_size);
 
 	cgroup_put(cgrp);
 	return ret;
diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
index 630d530782fe8a..d1274486a564ee 100644
--- a/kernel/bpf/syscall.c
+++ b/kernel/bpf/syscall.c
@@ -4654,7 +4654,7 @@ static int bpf_prog_detach(const union bpf_attr *attr)
 #define BPF_PROG_QUERY_LAST_FIELD query.revision
 
 static int bpf_prog_query(const union bpf_attr *attr,
-			  union bpf_attr __user *uattr)
+			  union bpf_attr __user *uattr, u32 uattr_size)
 {
 	if (!bpf_net_capable())
 		return -EPERM;
@@ -4693,7 +4693,7 @@ static int bpf_prog_query(const union bpf_attr *attr,
 	case BPF_CGROUP_GETSOCKOPT:
 	case BPF_CGROUP_SETSOCKOPT:
 	case BPF_LSM_CGROUP:
-		return cgroup_bpf_prog_query(attr, uattr);
+		return cgroup_bpf_prog_query(attr, uattr, uattr_size);
 	case BPF_LIRC_MODE2:
 		return lirc_prog_query(attr, uattr);
 	case BPF_FLOW_DISSECTOR:
@@ -6286,7 +6286,7 @@ static int __sys_bpf(enum bpf_cmd cmd, bpfptr_t uattr, unsigned int size)
 		err = bpf_prog_detach(&attr);
 		break;
 	case BPF_PROG_QUERY:
-		err = bpf_prog_query(&attr, uattr.user);
+		err = bpf_prog_query(&attr, uattr.user, size);
 		break;
 	case BPF_PROG_TEST_RUN:
 		err = bpf_prog_test_run(&attr, uattr.user);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0402/2077] selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (400 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0401/2077] bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0403/2077] liveupdate: Use refcount_t for FLB reference counts Greg Kroah-Hartman
                   ` (595 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Maciej Żenczykowski,
	Lorenzo Colitti, Yuyang Huang, Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yuyang Huang <yuyanghuang@google.com>

[ Upstream commit 5add3a4ad1a3bc15404e8bd338813ed0a636f5c9 ]

Add a new selftest to verify that the BPF syscall (specifically
BPF_PROG_QUERY) correctly handles different user-declared attribute sizes.

Specifically, verify that:
- For cgroup queries, a query with a size that covers 'prog_cnt' but is
  smaller than 'revision' (OLD_QUERY_SIZE) succeeds, but does not write
  to 'revision' (verifying backward compatibility).
- A query with full size (FULL_QUERY_SIZE) succeeds and writes both
  'prog_cnt' and 'revision'.

Fixes: 120933984460 ("bpf: Implement mprog API on top of existing cgroup progs")
Cc: Maciej Żenczykowski <maze@google.com>
Cc: Lorenzo Colitti <lorenzo@google.com>
Signed-off-by: Yuyang Huang <yuyanghuang@google.com>
Link: https://lore.kernel.org/r/20260531075600.4058207-3-yuyanghuang@google.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../selftests/bpf/prog_tests/bpf_attr_size.c  | 69 +++++++++++++++++++
 1 file changed, 69 insertions(+)
 create mode 100644 tools/testing/selftests/bpf/prog_tests/bpf_attr_size.c

diff --git a/tools/testing/selftests/bpf/prog_tests/bpf_attr_size.c b/tools/testing/selftests/bpf/prog_tests/bpf_attr_size.c
new file mode 100644
index 00000000000000..32159dc64da8b0
--- /dev/null
+++ b/tools/testing/selftests/bpf/prog_tests/bpf_attr_size.c
@@ -0,0 +1,69 @@
+// SPDX-License-Identifier: GPL-2.0
+/* Copyright (c) 2026 Google LLC */
+#include <linux/bpf.h>
+#include <unistd.h>
+#include <sys/syscall.h>
+#include <test_progs.h>
+#include <cgroup_helpers.h>
+#include "cgroup_skb_direct_packet_access.skel.h"
+
+#define OLD_QUERY_SIZE		offsetofend(union bpf_attr, query.prog_cnt)
+#define FULL_QUERY_SIZE		offsetofend(union bpf_attr, query.revision)
+
+static void test_query_size_boundaries(void)
+{
+	struct cgroup_skb_direct_packet_access *skel;
+	struct bpf_link *link = NULL;
+	union bpf_attr attr;
+	int cg_fd = -1;
+	int err;
+
+	skel = cgroup_skb_direct_packet_access__open_and_load();
+	if (!ASSERT_OK_PTR(skel, "skel_load"))
+		return;
+
+	cg_fd = test__join_cgroup("/attr_size_cg");
+	if (!ASSERT_GE(cg_fd, 0, "join_cgroup"))
+		goto cleanup;
+
+	link = bpf_program__attach_cgroup(skel->progs.direct_packet_access,
+					  cg_fd);
+	if (!ASSERT_OK_PTR(link, "cg_attach"))
+		goto cleanup;
+
+	memset(&attr, 0, sizeof(attr));
+	attr.query.target_fd = cg_fd;
+	attr.query.attach_type = BPF_CGROUP_INET_INGRESS;
+	attr.query.revision = 0xdeadbeefdeadbeefULL;
+
+	err = syscall(__NR_bpf, BPF_PROG_QUERY, &attr, OLD_QUERY_SIZE);
+	if (ASSERT_OK(err, "query_old_size")) {
+		ASSERT_EQ(attr.query.prog_cnt, 1, "prog_cnt_written_old");
+		ASSERT_EQ(attr.query.revision, 0xdeadbeefdeadbeefULL,
+			  "revision_not_written_old");
+	}
+
+	memset(&attr, 0, sizeof(attr));
+	attr.query.target_fd = cg_fd;
+	attr.query.attach_type = BPF_CGROUP_INET_INGRESS;
+
+	err = syscall(__NR_bpf, BPF_PROG_QUERY, &attr, FULL_QUERY_SIZE);
+	if (!ASSERT_OK(err, "query_full_size"))
+		goto cleanup;
+
+	ASSERT_EQ(attr.query.prog_cnt, 1, "prog_cnt_written");
+	ASSERT_GT(attr.query.revision, 0, "revision_written");
+
+cleanup:
+	if (link)
+		bpf_link__destroy(link);
+	if (cg_fd >= 0)
+		close(cg_fd);
+	cgroup_skb_direct_packet_access__destroy(skel);
+}
+
+void test_bpf_attr_size(void)
+{
+	if (test__start_subtest("query_size_boundaries"))
+		test_query_size_boundaries();
+}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0403/2077] liveupdate: Use refcount_t for FLB reference counts
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (401 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0402/2077] selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0404/2077] liveupdate: Reference count incoming FLB data Greg Kroah-Hartman
                   ` (594 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Matlack, Samiullah Khawaja,
	Pasha Tatashin, Mike Rapoport (Microsoft), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Matlack <dmatlack@google.com>

[ Upstream commit d2850ff2f8c5acda4c1097aa53c006a75b091f2c ]

Use refcount_t instead of a raw integer to keep track of references on
incoming and outgoing FLBs. Using refcount_t provides protection from
overflow, underflow, and other issues.

Fixes: cab056f2aae7 ("liveupdate: luo_flb: introduce File-Lifecycle-Bound global state")
Signed-off-by: David Matlack <dmatlack@google.com>
Reviewed-by: Samiullah Khawaja <skhawaja@google.com>
Reviewed-by: Pasha Tatashin <pasha.tatashin@soleen.com>
Link: https://lore.kernel.org/r/20260423174032.3140399-2-dmatlack@google.com
Signed-off-by: Pasha Tatashin <pasha.tatashin@soleen.com>
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/liveupdate.h  |  3 ++-
 kernel/liveupdate/luo_flb.c | 22 ++++++++++------------
 2 files changed, 12 insertions(+), 13 deletions(-)

diff --git a/include/linux/liveupdate.h b/include/linux/liveupdate.h
index 30c5a39ff9e9c2..8d3bbc35c828b8 100644
--- a/include/linux/liveupdate.h
+++ b/include/linux/liveupdate.h
@@ -12,6 +12,7 @@
 #include <linux/kho/abi/luo.h>
 #include <linux/list.h>
 #include <linux/mutex.h>
+#include <linux/refcount.h>
 #include <linux/rwsem.h>
 #include <linux/types.h>
 #include <uapi/linux/liveupdate.h>
@@ -175,7 +176,7 @@ struct liveupdate_flb_ops {
  * @retrieved: True once the FLB's retrieve() callback has run.
  */
 struct luo_flb_private_state {
-	long count;
+	refcount_t count;
 	u64 data;
 	void *obj;
 	struct mutex lock;
diff --git a/kernel/liveupdate/luo_flb.c b/kernel/liveupdate/luo_flb.c
index 00f5494812c4ab..59c5f31ab76740 100644
--- a/kernel/liveupdate/luo_flb.c
+++ b/kernel/liveupdate/luo_flb.c
@@ -111,7 +111,7 @@ static int luo_flb_file_preserve_one(struct liveupdate_flb *flb)
 	struct luo_flb_private *private = luo_flb_get_private(flb);
 
 	scoped_guard(mutex, &private->outgoing.lock) {
-		if (!private->outgoing.count) {
+		if (!refcount_read(&private->outgoing.count)) {
 			struct liveupdate_flb_op_args args = {0};
 			int err;
 
@@ -126,8 +126,10 @@ static int luo_flb_file_preserve_one(struct liveupdate_flb *flb)
 			}
 			private->outgoing.data = args.data;
 			private->outgoing.obj = args.obj;
+			refcount_set(&private->outgoing.count, 1);
+		} else {
+			refcount_inc(&private->outgoing.count);
 		}
-		private->outgoing.count++;
 	}
 
 	return 0;
@@ -138,8 +140,7 @@ static void luo_flb_file_unpreserve_one(struct liveupdate_flb *flb)
 	struct luo_flb_private *private = luo_flb_get_private(flb);
 
 	scoped_guard(mutex, &private->outgoing.lock) {
-		private->outgoing.count--;
-		if (!private->outgoing.count) {
+		if (refcount_dec_and_test(&private->outgoing.count)) {
 			struct liveupdate_flb_op_args args = {0};
 
 			args.flb = flb;
@@ -178,7 +179,7 @@ static int luo_flb_retrieve_one(struct liveupdate_flb *flb)
 	for (int i = 0; i < fh->header_ser->count; i++) {
 		if (!strcmp(fh->ser[i].name, flb->compatible)) {
 			private->incoming.data = fh->ser[i].data;
-			private->incoming.count = fh->ser[i].count;
+			refcount_set(&private->incoming.count, fh->ser[i].count);
 			found = true;
 			break;
 		}
@@ -208,12 +209,8 @@ static int luo_flb_retrieve_one(struct liveupdate_flb *flb)
 static void luo_flb_file_finish_one(struct liveupdate_flb *flb)
 {
 	struct luo_flb_private *private = luo_flb_get_private(flb);
-	u64 count;
 
-	scoped_guard(mutex, &private->incoming.lock)
-		count = --private->incoming.count;
-
-	if (!count) {
+	if (refcount_dec_and_test(&private->incoming.count)) {
 		struct liveupdate_flb_op_args args = {0};
 
 		if (!private->incoming.retrieved) {
@@ -652,12 +649,13 @@ void luo_flb_serialize(void)
 	guard(rwsem_read)(&luo_register_rwlock);
 	list_private_for_each_entry(gflb, &luo_flb_global.list, private.list) {
 		struct luo_flb_private *private = luo_flb_get_private(gflb);
+		long count = refcount_read(&private->outgoing.count);
 
-		if (private->outgoing.count > 0) {
+		if (count > 0) {
 			strscpy(fh->ser[i].name, gflb->compatible,
 				sizeof(fh->ser[i].name));
 			fh->ser[i].data = private->outgoing.data;
-			fh->ser[i].count = private->outgoing.count;
+			fh->ser[i].count = count;
 			i++;
 		}
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0404/2077] liveupdate: Reference count incoming FLB data
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (402 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0403/2077] liveupdate: Use refcount_t for FLB reference counts Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0405/2077] libbpf: Skip hash computation when loader generation failed Greg Kroah-Hartman
                   ` (593 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Matlack, Samiullah Khawaja,
	Pasha Tatashin, Mike Rapoport (Microsoft), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Matlack <dmatlack@google.com>

[ Upstream commit d8e47bd066d7e626f9f45d416182d585b7e18b9b ]

Increment the incoming FLB refcount in liveupdate_flb_get_incoming() so
that the FLB structure cannot be freed while the caller is actively using
it. Add an additional liveupdate_flb_put_incoming() function so the
caller can explicitly indicate when it is done using the FLB data.

During a Live Update, a subsystem might need to hold onto the incoming
File-Lifecycle-Bound (FLB) data for an extended period, such as during
device enumeration. Incrementing the reference count guarantees that the
data remains valid and accessible until the subsystem releases it,
preventing future use-after-free bugs.

Fixes: cab056f2aae7 ("liveupdate: luo_flb: introduce File-Lifecycle-Bound global state")
Signed-off-by: David Matlack <dmatlack@google.com>
Reviewed-by: Samiullah Khawaja <skhawaja@google.com>
Reviewed-by: Pasha Tatashin <pasha.tatashin@soleen.com>
Link: https://lore.kernel.org/r/20260423174032.3140399-3-dmatlack@google.com
Signed-off-by: Pasha Tatashin <pasha.tatashin@soleen.com>
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/liveupdate.h  |  6 ++++++
 kernel/liveupdate/luo_flb.c | 32 +++++++++++++++++---------------
 lib/tests/liveupdate.c      |  3 +++
 3 files changed, 26 insertions(+), 15 deletions(-)

diff --git a/include/linux/liveupdate.h b/include/linux/liveupdate.h
index 8d3bbc35c828b8..88722e5caf020b 100644
--- a/include/linux/liveupdate.h
+++ b/include/linux/liveupdate.h
@@ -240,6 +240,8 @@ void liveupdate_unregister_flb(struct liveupdate_file_handler *fh,
 			       struct liveupdate_flb *flb);
 
 int liveupdate_flb_get_incoming(struct liveupdate_flb *flb, void **objp);
+void liveupdate_flb_put_incoming(struct liveupdate_flb *flb);
+
 int liveupdate_flb_get_outgoing(struct liveupdate_flb *flb, void **objp);
 
 #else /* CONFIG_LIVEUPDATE */
@@ -280,6 +282,10 @@ static inline int liveupdate_flb_get_incoming(struct liveupdate_flb *flb,
 	return -EOPNOTSUPP;
 }
 
+static inline void liveupdate_flb_put_incoming(struct liveupdate_flb *flb)
+{
+}
+
 static inline int liveupdate_flb_get_outgoing(struct liveupdate_flb *flb,
 					      void **objp)
 {
diff --git a/kernel/liveupdate/luo_flb.c b/kernel/liveupdate/luo_flb.c
index 59c5f31ab76740..8f5c5dd01cd048 100644
--- a/kernel/liveupdate/luo_flb.c
+++ b/kernel/liveupdate/luo_flb.c
@@ -165,7 +165,7 @@ static int luo_flb_retrieve_one(struct liveupdate_flb *flb)
 	bool found = false;
 	int err;
 
-	guard(mutex)(&private->incoming.lock);
+	lockdep_assert_held(&private->incoming.lock);
 
 	if (private->incoming.finished)
 		return -ENODATA;
@@ -206,12 +206,14 @@ static int luo_flb_retrieve_one(struct liveupdate_flb *flb)
 	return 0;
 }
 
-static void luo_flb_file_finish_one(struct liveupdate_flb *flb)
+void liveupdate_flb_put_incoming(struct liveupdate_flb *flb)
 {
 	struct luo_flb_private *private = luo_flb_get_private(flb);
+	struct liveupdate_flb_op_args args = {0};
 
-	if (refcount_dec_and_test(&private->incoming.count)) {
-		struct liveupdate_flb_op_args args = {0};
+	scoped_guard(mutex, &private->incoming.lock) {
+		if (!refcount_dec_and_test(&private->incoming.count))
+			return;
 
 		if (!private->incoming.retrieved) {
 			int err = luo_flb_retrieve_one(flb);
@@ -220,16 +222,14 @@ static void luo_flb_file_finish_one(struct liveupdate_flb *flb)
 				return;
 		}
 
-		scoped_guard(mutex, &private->incoming.lock) {
-			args.flb = flb;
-			args.obj = private->incoming.obj;
-			flb->ops->finish(&args);
+		args.flb = flb;
+		args.obj = private->incoming.obj;
+		flb->ops->finish(&args);
 
-			private->incoming.data = 0;
-			private->incoming.obj = NULL;
-			private->incoming.finished = true;
-			module_put(flb->ops->owner);
-		}
+		private->incoming.data = 0;
+		private->incoming.obj = NULL;
+		private->incoming.finished = true;
+		module_put(flb->ops->owner);
 	}
 }
 
@@ -312,7 +312,7 @@ void luo_flb_file_finish(struct liveupdate_file_handler *fh)
 
 	guard(rwsem_read)(&luo_register_rwlock);
 	list_for_each_entry_reverse(iter, flb_list, list)
-		luo_flb_file_finish_one(iter->flb);
+		liveupdate_flb_put_incoming(iter->flb);
 }
 
 static void luo_flb_unregister_one(struct liveupdate_file_handler *fh,
@@ -509,6 +509,8 @@ int liveupdate_flb_get_incoming(struct liveupdate_flb *flb, void **objp)
 	if (!liveupdate_enabled())
 		return -EOPNOTSUPP;
 
+	guard(mutex)(&private->incoming.lock);
+
 	if (!private->incoming.obj) {
 		int err = luo_flb_retrieve_one(flb);
 
@@ -516,7 +518,7 @@ int liveupdate_flb_get_incoming(struct liveupdate_flb *flb, void **objp)
 			return err;
 	}
 
-	guard(mutex)(&private->incoming.lock);
+	refcount_inc(&private->incoming.count);
 	*objp = private->incoming.obj;
 
 	return 0;
diff --git a/lib/tests/liveupdate.c b/lib/tests/liveupdate.c
index e4b0ecbee32fe6..4c08a7c6fb788a 100644
--- a/lib/tests/liveupdate.c
+++ b/lib/tests/liveupdate.c
@@ -105,6 +105,9 @@ static void liveupdate_test_init(void)
 			pr_err("liveupdate_flb_get_incoming for %s failed: %pe\n",
 			       flb->compatible, ERR_PTR(err));
 		}
+
+		if (!err)
+			liveupdate_flb_put_incoming(flb);
 	}
 	initialized = true;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0405/2077] libbpf: Skip hash computation when loader generation failed
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (403 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0404/2077] liveupdate: Reference count incoming FLB data Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0406/2077] libbpf: Skip endianness swap " Greg Kroah-Hartman
                   ` (592 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko, Daniel Borkmann,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

[ Upstream commit 3c5e2f1a85844abbb65df4694f5ebad0a13e219c ]

bpf_gen__finish() calls compute_sha_update_offsets() gated only on
the gen_hash option, without first consulting gen->error. On a failed
generation this is buggy: a failed realloc_data_buf() sets gen->data_start
to NULL (leaving gen->data_cur dangling), so compute_sha_update_offsets()
runs libbpf_sha256() over a NULL buffer with a bogus length; a failed
realloc_insn_buf() likewise sets gen->insn_start to NULL and the hash
immediates get patched through that NULL base.

The computed program is discarded in either case, since the following
"if (!gen->error)" block does not publish opts->insns once an error is
set. Thus, skip the hash pass when generation has already failed.

Fixes: ea923080c145 ("libbpf: Embed and verify the metadata hash in the loader")
Reported-by: sashiko <sashiko@sashiko.dev>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20260529094119.307264-2-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/lib/bpf/gen_loader.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/tools/lib/bpf/gen_loader.c b/tools/lib/bpf/gen_loader.c
index 9478b8f78f260c..e2fe841a56698b 100644
--- a/tools/lib/bpf/gen_loader.c
+++ b/tools/lib/bpf/gen_loader.c
@@ -398,13 +398,12 @@ int bpf_gen__finish(struct bpf_gen *gen, int nr_progs, int nr_maps)
 			      blob_fd_array_off(gen, i));
 	emit(gen, BPF_MOV64_IMM(BPF_REG_0, 0));
 	emit(gen, BPF_EXIT_INSN());
-	if (OPTS_GET(gen->opts, gen_hash, false))
-		compute_sha_update_offsets(gen);
-
-	pr_debug("gen: finish %s\n", errstr(gen->error));
 	if (!gen->error) {
 		struct gen_loader_opts *opts = gen->opts;
 
+		if (OPTS_GET(opts, gen_hash, false))
+			compute_sha_update_offsets(gen);
+
 		opts->insns = gen->insn_start;
 		opts->insns_sz = gen->insn_cur - gen->insn_start;
 		opts->data = gen->data_start;
@@ -419,6 +418,7 @@ int bpf_gen__finish(struct bpf_gen *gen, int nr_progs, int nr_maps)
 				bpf_insn_bswap(insn++);
 		}
 	}
+	pr_debug("gen: finish %s\n", errstr(gen->error));
 	return gen->error;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0406/2077] libbpf: Skip endianness swap when loader generation failed
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (404 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0405/2077] libbpf: Skip hash computation when loader generation failed Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0407/2077] liveupdate: skip serialization for context-preserving kexec Greg Kroah-Hartman
                   ` (591 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko, Daniel Borkmann,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

[ Upstream commit 41300d032a1b1d91a3ed996ad21905463e344beb ]

bpf_gen__prog_load() byte-swaps the program insns and the {func,line}_info
and CO-RE relo blobs in place for cross-endian targets. The blob offsets
come from add_data(), which returns 0 on failure: realloc_data_buf() either
frees and NULLs gen->data_start (realloc OOM) or returns early on an
already-latched gen->error, leaving a stale, possibly too-small buffer.

Neither bswap site checked for this. With gen->swapped_endian set and a
failed generation, "gen->data_start + off" becomes NULL + 0. Guard the
same way via !gen->error so they are skipped once generation has failed.

Fixes: 8ca3323dce43 ("libbpf: Support creating light skeleton of either endianness")
Reported-by: sashiko <sashiko@sashiko.dev>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20260529162829.315921-1-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/lib/bpf/gen_loader.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/tools/lib/bpf/gen_loader.c b/tools/lib/bpf/gen_loader.c
index e2fe841a56698b..e63a01101e2d85 100644
--- a/tools/lib/bpf/gen_loader.c
+++ b/tools/lib/bpf/gen_loader.c
@@ -1053,7 +1053,7 @@ void bpf_gen__prog_load(struct bpf_gen *gen,
 		 prog_idx, prog_type, insns_off, insn_cnt, license_off);
 
 	/* convert blob insns to target endianness */
-	if (gen->swapped_endian) {
+	if (gen->swapped_endian && !gen->error) {
 		struct bpf_insn *insn = gen->data_start + insns_off;
 		int i;
 
@@ -1091,7 +1091,7 @@ void bpf_gen__prog_load(struct bpf_gen *gen,
 		 sizeof(struct bpf_core_relo));
 
 	/* convert all info blobs to target endianness */
-	if (gen->swapped_endian)
+	if (gen->swapped_endian && !gen->error)
 		info_blob_bswap(gen, func_info, line_info, core_relos, load_attr);
 
 	libbpf_strlcpy(attr.prog_name, prog_name, sizeof(attr.prog_name));
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0407/2077] liveupdate: skip serialization for context-preserving kexec
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (405 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0406/2077] libbpf: Skip endianness swap " Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0408/2077] liveupdate: fix TOCTOU race in luo_session_retrieve() Greg Kroah-Hartman
                   ` (590 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Oskar Gerlicz Kowalczuk,
	Pratyush Yadav (Google), Mike Rapoport (Microsoft),
	Pasha Tatashin, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pasha Tatashin <pasha.tatashin@soleen.com>

[ Upstream commit 5eff62b051fbdb686e885c1468301d964f2e3d66 ]

A preserve_context kexec returns to the current kernel, which is
unrelated to live update where the state is passed to the next kernel.
Skip liveupdate_reboot() in this case to avoid serialization and prevent
sessions from being left in a frozen state upon return.

Fixes: db8bed8082dc ("kexec: call liveupdate_reboot() before kexec")
Reported-by: Oskar Gerlicz Kowalczuk <oskar@gerlicz.space>
Reviewed-by: Pratyush Yadav (Google) <pratyush@kernel.org>
Acked-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Pasha Tatashin <pasha.tatashin@soleen.com>
Link: https://patch.msgid.link/20260527202737.1345192-2-pasha.tatashin@soleen.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/kexec_core.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/kernel/kexec_core.c b/kernel/kexec_core.c
index a43d2da0fe3e70..dc770b9a6d0539 100644
--- a/kernel/kexec_core.c
+++ b/kernel/kexec_core.c
@@ -1146,9 +1146,11 @@ int kernel_kexec(void)
 		goto Unlock;
 	}
 
-	error = liveupdate_reboot();
-	if (error)
-		goto Unlock;
+	if (!kexec_image->preserve_context) {
+		error = liveupdate_reboot();
+		if (error)
+			goto Unlock;
+	}
 
 #ifdef CONFIG_KEXEC_JUMP
 	if (kexec_image->preserve_context) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0408/2077] liveupdate: fix TOCTOU race in luo_session_retrieve()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (406 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0407/2077] liveupdate: skip serialization for context-preserving kexec Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0409/2077] liveupdate: block session mutations during reboot Greg Kroah-Hartman
                   ` (589 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mike Rapoport (Microsoft),
	Pratyush Yadav (Google), Pasha Tatashin, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pasha Tatashin <pasha.tatashin@soleen.com>

[ Upstream commit d3ae9e7fddb4036f50003d7fa1ef52801fdb961b ]

Extend the scope of the rwsem_read lock in luo_session_retrieve() to
overlap with the acquisition of the session mutex. This prevents a
concurrent thread from releasing and freeing the session between the
lookup and the mutex lock.

Fixes: 0153094d03df ("liveupdate: luo_session: add sessions support")
Acked-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Reviewed-by: Pratyush Yadav (Google) <pratyush@kernel.org>
Signed-off-by: Pasha Tatashin <pasha.tatashin@soleen.com>
Link: https://patch.msgid.link/20260527202737.1345192-3-pasha.tatashin@soleen.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/liveupdate/luo_session.c | 11 +++++------
 1 file changed, 5 insertions(+), 6 deletions(-)

diff --git a/kernel/liveupdate/luo_session.c b/kernel/liveupdate/luo_session.c
index ec7aebc15a8016..85af0963d66ae0 100644
--- a/kernel/liveupdate/luo_session.c
+++ b/kernel/liveupdate/luo_session.c
@@ -419,12 +419,11 @@ int luo_session_retrieve(const char *name, struct file **filep)
 	struct luo_session *it;
 	int err;
 
-	scoped_guard(rwsem_read, &sh->rwsem) {
-		list_for_each_entry(it, &sh->list, list) {
-			if (!strncmp(it->name, name, sizeof(it->name))) {
-				session = it;
-				break;
-			}
+	guard(rwsem_read)(&sh->rwsem);
+	list_for_each_entry(it, &sh->list, list) {
+		if (!strncmp(it->name, name, sizeof(it->name))) {
+			session = it;
+			break;
 		}
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0409/2077] liveupdate: block session mutations during reboot
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (407 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0408/2077] liveupdate: fix TOCTOU race in luo_session_retrieve() Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0410/2077] liveupdate: fix u-a-f in luo_file_unpreserve_files() and luo_file_finish() Greg Kroah-Hartman
                   ` (588 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Oskar Gerlicz Kowalczuk,
	Mike Rapoport (Microsoft), Pasha Tatashin,
	Pratyush Yadav (Google), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pasha Tatashin <pasha.tatashin@soleen.com>

[ Upstream commit bb1328be35bf43c88288c5c31ceb45181b574c0c ]

During the reboot() syscall, user processes may still be running
concurrently and attempting to mutate sessions (e.g., creating,
retrieving, or releasing sessions). To prevent this, introduce
luo_session_serialize_rwsem to synchronize mutations with the
serialization process.

All session mutation operations (create, retrieve, release, ioctl) take
the read lock. The serialization process (luo_session_serialize) takes
the write lock and holds it indefinitely on success. This effectively
freezes the LUO session subsystem during the transition to the new
kernel. If serialization fails, the lock is released to allow recovery.

Fixes: 0153094d03df ("liveupdate: luo_session: add sessions support")
Reported-by: Oskar Gerlicz Kowalczuk <oskar@gerlicz.space>
Acked-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Pasha Tatashin <pasha.tatashin@soleen.com>
Reviewed-by: Pratyush Yadav (Google) <pratyush@kernel.org>
Link: https://patch.msgid.link/20260527202737.1345192-4-pasha.tatashin@soleen.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/liveupdate/luo_session.c | 51 +++++++++++++++++++++++++++++++--
 1 file changed, 48 insertions(+), 3 deletions(-)

diff --git a/kernel/liveupdate/luo_session.c b/kernel/liveupdate/luo_session.c
index 85af0963d66ae0..5486e834c4514c 100644
--- a/kernel/liveupdate/luo_session.c
+++ b/kernel/liveupdate/luo_session.c
@@ -46,6 +46,38 @@
  * 4.  Retrieval: A userspace agent in the new kernel can then call
  *     `luo_session_retrieve()` with a session name to get a new file
  *     descriptor and access the preserved state.
+ *
+ * Locking:
+ *
+ * The LUO session subsystem uses a three-tier locking hierarchy to ensure thread
+ * safety and prevent deadlocks during concurrent session mutations and kexec
+ * serialization:
+ *
+ * 1. `luo_session_serialize_rwsem` (global rwsem):
+ *    Protects session mutations (creation, retrieval, release, and ioctls)
+ *    against the serialization process during reboot.
+ *
+ *    - Readers: Taken by any path modifying or accessing session state (e.g.,
+ *      `luo_session_create()`, `luo_session_retrieve()`, `luo_session_release()`,
+ *      and `luo_session_ioctl()`).
+ *    - Writer: Taken by the serialization process (`luo_session_serialize()`)
+ *      during reboot. On success, the write lock is held indefinitely to freeze
+ *      the subsystem. On failure, it is released to allow recovery.
+ *
+ * 2. `luo_session_header->rwsem` (per-list rwsem):
+ *    Synchronizes list-level operations for the incoming and outgoing session headers.
+ *
+ *    - Writer: Taken during list mutation operations (inserting or removing a
+ *      session from the list).
+ *    - Reader: Taken when traversing the list (e.g., retrieving a session by name).
+ *
+ * 3. `luo_session->mutex` (per-session mutex):
+ *    Protects the internal state and file sets of an individual session. It is
+ *    acquired during per-session operations such as preserving, retrieving,
+ *    or freezing files.
+ *
+ * Lock Hierarchy:
+ *   `luo_session_serialize_rwsem` -> `luo_session_header->rwsem` -> `luo_session->mutex`
  */
 
 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
@@ -75,6 +107,8 @@
 		sizeof(struct luo_session_header_ser)) /		\
 		sizeof(struct luo_session_ser))
 
+static DECLARE_RWSEM(luo_session_serialize_rwsem);
+
 /**
  * struct luo_session_header - Header struct for managing LUO sessions.
  * @count:      The number of sessions currently tracked in the @list.
@@ -205,6 +239,7 @@ static int luo_session_release(struct inode *inodep, struct file *filep)
 	struct luo_session *session = filep->private_data;
 	struct luo_session_header *sh;
 
+	guard(rwsem_read)(&luo_session_serialize_rwsem);
 	/* If retrieved is set, it means this session is from incoming list */
 	if (session->retrieved) {
 		int err = luo_session_finish_one(session);
@@ -354,6 +389,7 @@ static long luo_session_ioctl(struct file *filep, unsigned int cmd,
 	if (ret)
 		return ret;
 
+	guard(rwsem_read)(&luo_session_serialize_rwsem);
 	return op->execute(session, &ucmd);
 }
 
@@ -393,14 +429,17 @@ int luo_session_create(const char *name, struct file **filep)
 	if (IS_ERR(session))
 		return PTR_ERR(session);
 
+	down_read(&luo_session_serialize_rwsem);
 	err = luo_session_insert(&luo_session_global.outgoing, session);
 	if (err)
 		goto err_free;
 
-	scoped_guard(mutex, &session->mutex)
-		err = luo_session_getfile(session, filep);
+	mutex_lock(&session->mutex);
+	err = luo_session_getfile(session, filep);
+	mutex_unlock(&session->mutex);
 	if (err)
 		goto err_remove;
+	up_read(&luo_session_serialize_rwsem);
 
 	return 0;
 
@@ -408,6 +447,7 @@ int luo_session_create(const char *name, struct file **filep)
 	luo_session_remove(&luo_session_global.outgoing, session);
 err_free:
 	luo_session_free(session);
+	up_read(&luo_session_serialize_rwsem);
 
 	return err;
 }
@@ -419,6 +459,7 @@ int luo_session_retrieve(const char *name, struct file **filep)
 	struct luo_session *it;
 	int err;
 
+	guard(rwsem_read)(&luo_session_serialize_rwsem);
 	guard(rwsem_read)(&sh->rwsem);
 	list_for_each_entry(it, &sh->list, list) {
 		if (!strncmp(it->name, name, sizeof(it->name))) {
@@ -591,7 +632,8 @@ int luo_session_serialize(void)
 	int i = 0;
 	int err;
 
-	guard(rwsem_write)(&sh->rwsem);
+	down_write(&luo_session_serialize_rwsem);
+	down_write(&sh->rwsem);
 	list_for_each_entry(session, &sh->list, list) {
 		err = luo_session_freeze_one(session, &sh->ser[i]);
 		if (err)
@@ -602,6 +644,7 @@ int luo_session_serialize(void)
 		i++;
 	}
 	sh->header_ser->count = sh->count;
+	up_write(&sh->rwsem);
 
 	return 0;
 
@@ -611,6 +654,8 @@ int luo_session_serialize(void)
 		luo_session_unfreeze_one(session, &sh->ser[i]);
 		memset(sh->ser[i].name, 0, sizeof(sh->ser[i].name));
 	}
+	up_write(&sh->rwsem);
+	up_write(&luo_session_serialize_rwsem);
 
 	return err;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0410/2077] liveupdate: fix u-a-f in luo_file_unpreserve_files() and luo_file_finish()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (408 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0409/2077] liveupdate: block session mutations during reboot Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0411/2077] ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback Greg Kroah-Hartman
                   ` (587 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mike Rapoport (Microsoft),
	Pratyush Yadav (Google), Pasha Tatashin, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pasha Tatashin <pasha.tatashin@soleen.com>

[ Upstream commit 291dcd37c8c8f8f8e1bccc92228f44bf371762a8 ]

In luo_file_unpreserve_files() and luo_file_finish(), reorder
module_put() and xa_erase() to ensure the file handler module remains
pinned while its operations are being accessed.

Specifically, luo_get_id() dereferences fh->ops->get_id, so the module
reference must be held until after xa_erase() (which calls luo_get_id)
completes.

For luo_file_finish(), this requires moving the module_put() call out of
the luo_file_finish_one() helper and into the main loop of
luo_file_finish() itself.

Fixes: 00d0b372374f ("liveupdate: prevent double management of files")
Acked-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Reviewed-by: Pratyush Yadav (Google) <pratyush@kernel.org>
Signed-off-by: Pasha Tatashin <pasha.tatashin@soleen.com>
Link: https://patch.msgid.link/20260527202737.1345192-5-pasha.tatashin@soleen.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/liveupdate/luo_file.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/kernel/liveupdate/luo_file.c b/kernel/liveupdate/luo_file.c
index a0a419085e2830..208987502f73a9 100644
--- a/kernel/liveupdate/luo_file.c
+++ b/kernel/liveupdate/luo_file.c
@@ -385,10 +385,11 @@ void luo_file_unpreserve_files(struct luo_file_set *file_set)
 		args.private_data = luo_file->private_data;
 		luo_file->fh->ops->unpreserve(&args);
 		luo_flb_file_unpreserve(luo_file->fh);
-		module_put(luo_file->fh->ops->owner);
 
 		xa_erase(&luo_preserved_files,
 			 luo_get_id(luo_file->fh, luo_file->file));
+		module_put(luo_file->fh->ops->owner);
+
 		list_del(&luo_file->list);
 		file_set->count--;
 
@@ -677,7 +678,6 @@ static void luo_file_finish_one(struct luo_file_set *file_set,
 
 	luo_file->fh->ops->finish(&args);
 	luo_flb_file_finish(luo_file->fh);
-	module_put(luo_file->fh->ops->owner);
 }
 
 /**
@@ -738,6 +738,7 @@ int luo_file_finish(struct luo_file_set *file_set)
 				 luo_get_id(luo_file->fh, luo_file->file));
 			fput(luo_file->file);
 		}
+		module_put(luo_file->fh->ops->owner);
 		list_del(&luo_file->list);
 		file_set->count--;
 		mutex_destroy(&luo_file->mutex);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0411/2077] ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (409 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0410/2077] liveupdate: fix u-a-f in luo_file_unpreserve_files() and luo_file_finish() Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0412/2077] spi: atmel: fix DMA channel and bounce buffer leaks Greg Kroah-Hartman
                   ` (586 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhang Yi, Baokun Li, Jan Kara,
	Theodore Tso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhang Yi <yi.zhang@huawei.com>

[ Upstream commit d99748ef1695ce17eaf51c64b7a06952fa7cddab ]

In EXT4_GOING_FLAGS_LOGFLUSH mode, the EXT4_FLAGS_SHUTDOWN flag was set
before calling ext4_force_commit().  This caused ordered-mode data
writeback (triggered by journal commit) to fail with -EIO, since
ext4_do_writepages() checks for the shutdown flag.  The journal would
then be aborted prematurely before the commit could succeed.

Fix this by calling ext4_force_commit() first, then setting the
shutdown flag, so that pending data can be written back correctly.

Note that moving ext4_force_commit() before setting the shutdown flag
creates a small window in which new writes may occur and generate new
journal transactions.  When the journal is subsequently aborted, the
new transactions will not be able to write to disk.  This is intentional
because LOGFLUSH's semantics are to flush pre-existing journal entries
before shutdown, not to guarantee atomicity for writes that race with
the ioctl.

Fixes: 783d94854499 ("ext4: add EXT4_IOC_GOINGDOWN ioctl")
Signed-off-by: Zhang Yi <yi.zhang@huawei.com>
Reviewed-by: Baokun Li <libaokun@linux.alibaba.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20260424104201.1930823-1-yi.zhang@huaweicloud.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ext4/ioctl.c | 12 +++++++++---
 1 file changed, 9 insertions(+), 3 deletions(-)

diff --git a/fs/ext4/ioctl.c b/fs/ext4/ioctl.c
index 1d0c3d4bdf4727..110e3fb194ec6b 100644
--- a/fs/ext4/ioctl.c
+++ b/fs/ext4/ioctl.c
@@ -830,11 +830,17 @@ int ext4_force_shutdown(struct super_block *sb, u32 flags)
 		bdev_thaw(sb->s_bdev);
 		break;
 	case EXT4_GOING_FLAGS_LOGFLUSH:
+		/*
+		 * Call ext4_force_commit() before setting EXT4_FLAGS_SHUTDOWN.
+		 * This is because in data=ordered mode, journal commit
+		 * triggers data writeback which fails if shutdown is already
+		 * set, causing the journal to be aborted prematurely before
+		 * the commit succeeds.
+		 */
+		(void) ext4_force_commit(sb);
 		set_bit(EXT4_FLAGS_SHUTDOWN, &sbi->s_ext4_flags);
-		if (sbi->s_journal && !is_journal_aborted(sbi->s_journal)) {
-			(void) ext4_force_commit(sb);
+		if (sbi->s_journal && !is_journal_aborted(sbi->s_journal))
 			jbd2_journal_abort(sbi->s_journal, -ESHUTDOWN);
-		}
 		break;
 	case EXT4_GOING_FLAGS_NOLOGFLUSH:
 		set_bit(EXT4_FLAGS_SHUTDOWN, &sbi->s_ext4_flags);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0412/2077] spi: atmel: fix DMA channel and bounce buffer leaks
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (410 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0411/2077] ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0413/2077] spi: imx: replace dmaengine_terminate_all() with dmaengine_terminate_sync() Greg Kroah-Hartman
                   ` (585 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit bd7e9843ec95bffe2643c901dd625f0bab32e639 ]

The original code set use_dma to false when dma_alloc_coherent() for
bounce buffers failed, but DMA channels acquired earlier via
atmel_spi_configure_dma() were never freed.

When devm_request_irq() or clk_prepare_enable() failed later in probe,
the driver also did not release DMA channels or bounce buffers already
allocated.

The out_free_dma error path released DMA channels but did not free the
bounce buffers.

Fix by moving bounce buffer allocation into atmel_spi_configure_dma()
and registering the devres cleanup for DMA channels and bounce buffers.

Fixes: a9889ed62d06 ("spi: atmel: Implements transfers with bounce buffer")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Link: https://patch.msgid.link/20260522-atmel-v3-1-23f8c6e6aa43@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/spi/spi-atmel.c | 133 ++++++++++++++++++++--------------------
 1 file changed, 68 insertions(+), 65 deletions(-)

diff --git a/drivers/spi/spi-atmel.c b/drivers/spi/spi-atmel.c
index 42db85d7ff8e13..397bc819e7161e 100644
--- a/drivers/spi/spi-atmel.c
+++ b/drivers/spi/spi-atmel.c
@@ -559,6 +559,38 @@ static int atmel_spi_dma_slave_config(struct atmel_spi *as, u8 bits_per_word)
 	return err;
 }
 
+static void atmel_spi_release_dma(void *data)
+{
+	struct spi_controller *host = data;
+	struct atmel_spi *as = spi_controller_get_devdata(host);
+	struct device *dev = &as->pdev->dev;
+
+	if (host->dma_tx) {
+		dma_release_channel(host->dma_tx);
+		host->dma_tx = NULL;
+	}
+
+	if (host->dma_rx) {
+		dma_release_channel(host->dma_rx);
+		host->dma_rx = NULL;
+	}
+
+	if (IS_ENABLED(CONFIG_SOC_SAM_V4_V5)) {
+		if (as->addr_tx_bbuf) {
+			dma_free_coherent(dev, SPI_MAX_DMA_XFER,
+					  as->addr_tx_bbuf,
+					  as->dma_addr_tx_bbuf);
+			as->addr_tx_bbuf = NULL;
+		}
+		if (as->addr_rx_bbuf) {
+			dma_free_coherent(dev, SPI_MAX_DMA_XFER,
+					  as->addr_rx_bbuf,
+					  as->dma_addr_rx_bbuf);
+			as->addr_rx_bbuf = NULL;
+		}
+	}
+}
+
 static int atmel_spi_configure_dma(struct spi_controller *host,
 				   struct atmel_spi *as)
 {
@@ -569,7 +601,8 @@ static int atmel_spi_configure_dma(struct spi_controller *host,
 	if (IS_ERR(host->dma_tx)) {
 		err = PTR_ERR(host->dma_tx);
 		dev_dbg(dev, "No TX DMA channel, DMA is disabled\n");
-		goto error_clear;
+		host->dma_tx = NULL;
+		return err;
 	}
 
 	host->dma_rx = dma_request_chan(dev, "rx");
@@ -580,26 +613,45 @@ static int atmel_spi_configure_dma(struct spi_controller *host,
 		 * requested tx channel.
 		 */
 		dev_dbg(dev, "No RX DMA channel, DMA is disabled\n");
-		goto error;
+		host->dma_rx = NULL;
+		goto err_release_dma;
 	}
 
 	err = atmel_spi_dma_slave_config(as, 8);
 	if (err)
-		goto error;
+		goto err_release_dma;
+
+	if (IS_ENABLED(CONFIG_SOC_SAM_V4_V5)) {
+		as->addr_tx_bbuf = dma_alloc_coherent(dev, SPI_MAX_DMA_XFER,
+						      &as->dma_addr_tx_bbuf,
+						      GFP_KERNEL | GFP_DMA);
+		if (!as->addr_tx_bbuf) {
+			err = -ENOMEM;
+			goto err_release_dma;
+		}
+
+		as->addr_rx_bbuf = dma_alloc_coherent(dev, SPI_MAX_DMA_XFER,
+						      &as->dma_addr_rx_bbuf,
+						      GFP_KERNEL | GFP_DMA);
+		if (!as->addr_rx_bbuf) {
+			err = -ENOMEM;
+			goto err_release_dma;
+		}
+	}
+
+	err = devm_add_action_or_reset(dev, atmel_spi_release_dma, host);
+	if (err)
+		return err;
 
 	dev_info(&as->pdev->dev,
-			"Using %s (tx) and %s (rx) for DMA transfers\n",
-			dma_chan_name(host->dma_tx),
-			dma_chan_name(host->dma_rx));
+		 "Using %s (tx) and %s (rx) for DMA transfers\n",
+		 dma_chan_name(host->dma_tx), dma_chan_name(host->dma_rx));
 
 	return 0;
-error:
-	if (!IS_ERR(host->dma_rx))
-		dma_release_channel(host->dma_rx);
-	if (!IS_ERR(host->dma_tx))
-		dma_release_channel(host->dma_tx);
-error_clear:
-	host->dma_tx = host->dma_rx = NULL;
+
+err_release_dma:
+	atmel_spi_release_dma(host);
+
 	return err;
 }
 
@@ -611,18 +663,6 @@ static void atmel_spi_stop_dma(struct spi_controller *host)
 		dmaengine_terminate_all(host->dma_tx);
 }
 
-static void atmel_spi_release_dma(struct spi_controller *host)
-{
-	if (host->dma_rx) {
-		dma_release_channel(host->dma_rx);
-		host->dma_rx = NULL;
-	}
-	if (host->dma_tx) {
-		dma_release_channel(host->dma_tx);
-		host->dma_tx = NULL;
-	}
-}
-
 /* This function is called by the DMA driver from tasklet context */
 static void dma_callback(void *data)
 {
@@ -1585,30 +1625,6 @@ static int atmel_spi_probe(struct platform_device *pdev)
 		as->use_pdc = true;
 	}
 
-	if (IS_ENABLED(CONFIG_SOC_SAM_V4_V5)) {
-		as->addr_rx_bbuf = dma_alloc_coherent(&pdev->dev,
-						      SPI_MAX_DMA_XFER,
-						      &as->dma_addr_rx_bbuf,
-						      GFP_KERNEL | GFP_DMA);
-		if (!as->addr_rx_bbuf) {
-			as->use_dma = false;
-		} else {
-			as->addr_tx_bbuf = dma_alloc_coherent(&pdev->dev,
-					SPI_MAX_DMA_XFER,
-					&as->dma_addr_tx_bbuf,
-					GFP_KERNEL | GFP_DMA);
-			if (!as->addr_tx_bbuf) {
-				as->use_dma = false;
-				dma_free_coherent(&pdev->dev, SPI_MAX_DMA_XFER,
-						  as->addr_rx_bbuf,
-						  as->dma_addr_rx_bbuf);
-			}
-		}
-		if (!as->use_dma)
-			dev_info(host->dev.parent,
-				 "  can not allocate dma coherent memory\n");
-	}
-
 	if (as->caps.has_dma_support && !as->use_dma)
 		dev_info(&pdev->dev, "Atmel SPI Controller using PIO only\n");
 
@@ -1668,13 +1684,10 @@ static int atmel_spi_probe(struct platform_device *pdev)
 out_free_dma:
 	pm_runtime_disable(&pdev->dev);
 	pm_runtime_set_suspended(&pdev->dev);
-
-	if (as->use_dma)
-		atmel_spi_release_dma(host);
-
 	spi_writel(as, CR, SPI_BIT(SWRST));
 	spi_writel(as, CR, SPI_BIT(SWRST)); /* AT91SAM9263 Rev B workaround */
-	clk_disable_unprepare(as->gclk);
+	if (as->gclk)
+		clk_disable_unprepare(as->gclk);
 out_disable_clk:
 	clk_disable_unprepare(clk);
 out_free_irq:
@@ -1695,18 +1708,8 @@ static void atmel_spi_remove(struct platform_device *pdev)
 	spi_unregister_controller(host);
 
 	/* reset the hardware and block queue progress */
-	if (as->use_dma) {
+	if (as->use_dma)
 		atmel_spi_stop_dma(host);
-		atmel_spi_release_dma(host);
-		if (IS_ENABLED(CONFIG_SOC_SAM_V4_V5)) {
-			dma_free_coherent(&pdev->dev, SPI_MAX_DMA_XFER,
-					  as->addr_tx_bbuf,
-					  as->dma_addr_tx_bbuf);
-			dma_free_coherent(&pdev->dev, SPI_MAX_DMA_XFER,
-					  as->addr_rx_bbuf,
-					  as->dma_addr_rx_bbuf);
-		}
-	}
 
 	spin_lock_irq(&as->lock);
 	spi_writel(as, CR, SPI_BIT(SWRST));
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0413/2077] spi: imx: replace dmaengine_terminate_all() with dmaengine_terminate_sync()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (411 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0412/2077] spi: atmel: fix DMA channel and bounce buffer leaks Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0414/2077] ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble Greg Kroah-Hartman
                   ` (584 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Carlos Song, Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Carlos Song <carlos.song@nxp.com>

[ Upstream commit 4503b2fe761c2bfd33ed043d9b9deec0d1eb40e0 ]

dmaengine_terminate_all() has been deprecated, so replace it with
dmaengine_terminate_sync().

Fixes: ba9b28652c75 ("spi: imx: enable DMA mode for target operation")
Fixes: a450c8b77f92 ("spi: imx: handle DMA submission errors with dma_submit_error()")
Signed-off-by: Carlos Song <carlos.song@nxp.com>
Link: https://patch.msgid.link/20260525062928.3191821-1-carlos.song@oss.nxp.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/spi/spi-imx.c | 16 ++++++++--------
 1 file changed, 8 insertions(+), 8 deletions(-)

diff --git a/drivers/spi/spi-imx.c b/drivers/spi/spi-imx.c
index 480d1e8b281f19..ae9912905c67ad 100644
--- a/drivers/spi/spi-imx.c
+++ b/drivers/spi/spi-imx.c
@@ -1774,8 +1774,8 @@ static int spi_imx_dma_submit(struct spi_imx_data *spi_imx,
 							transfer_timeout);
 		if (!time_left) {
 			dev_err(spi_imx->dev, "I/O Error in DMA TX\n");
-			dmaengine_terminate_all(controller->dma_tx);
-			dmaengine_terminate_all(controller->dma_rx);
+			dmaengine_terminate_sync(controller->dma_tx);
+			dmaengine_terminate_sync(controller->dma_rx);
 			return -ETIMEDOUT;
 		}
 
@@ -1784,7 +1784,7 @@ static int spi_imx_dma_submit(struct spi_imx_data *spi_imx,
 		if (!time_left) {
 			dev_err(&controller->dev, "I/O Error in DMA RX\n");
 			spi_imx->devtype_data->reset(spi_imx);
-			dmaengine_terminate_all(controller->dma_rx);
+			dmaengine_terminate_sync(controller->dma_rx);
 			return -ETIMEDOUT;
 		}
 	} else {
@@ -1793,15 +1793,15 @@ static int spi_imx_dma_submit(struct spi_imx_data *spi_imx,
 		if (wait_for_completion_interruptible(&spi_imx->dma_tx_completion) ||
 		    READ_ONCE(spi_imx->target_aborted)) {
 			dev_dbg(spi_imx->dev, "I/O Error in DMA TX interrupted\n");
-			dmaengine_terminate_all(controller->dma_tx);
-			dmaengine_terminate_all(controller->dma_rx);
+			dmaengine_terminate_sync(controller->dma_tx);
+			dmaengine_terminate_sync(controller->dma_rx);
 			return -EINTR;
 		}
 
 		if (wait_for_completion_interruptible(&spi_imx->dma_rx_completion) ||
 		    READ_ONCE(spi_imx->target_aborted)) {
 			dev_dbg(spi_imx->dev, "I/O Error in DMA RX interrupted\n");
-			dmaengine_terminate_all(controller->dma_rx);
+			dmaengine_terminate_sync(controller->dma_rx);
 			return -EINTR;
 		}
 
@@ -1818,9 +1818,9 @@ static int spi_imx_dma_submit(struct spi_imx_data *spi_imx,
 	return 0;
 
 dmaengine_terminate_tx:
-	dmaengine_terminate_all(controller->dma_tx);
+	dmaengine_terminate_sync(controller->dma_tx);
 dmaengine_terminate_rx:
-	dmaengine_terminate_all(controller->dma_rx);
+	dmaengine_terminate_sync(controller->dma_rx);
 
 	return -EINVAL;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0414/2077] ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (412 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0413/2077] spi: imx: replace dmaengine_terminate_all() with dmaengine_terminate_sync() Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0415/2077] NFSD: Fix delegation reference leak in nfsd4_revoke_states Greg Kroah-Hartman
                   ` (583 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, John Madieu, Kuninori Morimoto,
	Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: John Madieu <john.madieu.xa@bp.renesas.com>

[ Upstream commit c0758279367e9d82eb7d7b4959718d7d32e96b7d ]

RSND_SOC_MASK was defined as (0xFF << 4), spanning bits 4-11. This is
wider than needed since only nibble B (bits 7:4) is used for SoC
identifiers. Narrow it to (0xF << 4) to match the intended single-nibble
allocation and prevent overlap with bits 8-11 which will be used by
upcoming RZ series flags.

No functional change, since the only current user (RSND_SOC_E) fits
within a single nibble.

Fixes: ba164a49f8f7 ("ASoC: rsnd: src: Avoid a potential deadlock")
Signed-off-by: John Madieu <john.madieu.xa@bp.renesas.com>
Acked-by: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
Link: https://patch.msgid.link/20260525110230.4014435-3-john.madieu.xa@bp.renesas.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/renesas/rcar/rsnd.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/soc/renesas/rcar/rsnd.h b/sound/soc/renesas/rcar/rsnd.h
index 04c70690f7a258..3e666125959b47 100644
--- a/sound/soc/renesas/rcar/rsnd.h
+++ b/sound/soc/renesas/rcar/rsnd.h
@@ -624,7 +624,7 @@ struct rsnd_priv {
 #define RSND_GEN2	(2 << 0)
 #define RSND_GEN3	(3 << 0)
 #define RSND_GEN4	(4 << 0)
-#define RSND_SOC_MASK	(0xFF << 4)
+#define RSND_SOC_MASK	(0xF << 4)
 #define RSND_SOC_E	(1 << 4) /* E1/E2/E3 */
 
 	/*
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0415/2077] NFSD: Fix delegation reference leak in nfsd4_revoke_states
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (413 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0414/2077] ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0416/2077] ARM: imx3: Fix CCM node reference leak Greg Kroah-Hartman
                   ` (582 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jeff Layton, Chuck Lever,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 625981c8f3da0cc2d236d7b46c39dd75554b8276 ]

When revoking delegation state, nfsd4_revoke_states() takes an extra
reference on the stid before calling unhash_delegation_locked(). If
unhash_delegation_locked() returns false (the delegation was already
unhashed by a concurrent path), dp is set to NULL and
revoke_delegation() is skipped, but the extra reference is never
released. Each occurrence permanently pins the stid in memory. The
leaked reference also prevents nfs4_put_stid() from decrementing
cl_admin_revoked, leaving the counter permanently inflated.

Drop the extra reference in the failure path.

Fixes: 8dd91e8d31fe ("nfsd: fix race between laundromat and free_stateid")
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/nfsd/nfs4state.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c
index d875e98d4dcbd0..2696a9fef0291c 100644
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -1376,7 +1376,8 @@ static void destroy_delegation(struct nfs4_delegation *dp)
  * stateid or it's called from a laundromat thread (nfsd4_landromat()) that
  * determined that this specific state has expired and needs to be revoked
  * (both mark state with the appropriate stid sc_status mode). It is also
- * assumed that a reference was taken on the @dp state.
+ * assumed that a reference was taken on the @dp state. This function
+ * consumes that reference.
  *
  * If this function finds that the @dp state is SC_STATUS_FREED it means
  * that a FREE_STATEID operation for this stateid has been processed and
@@ -1839,6 +1840,10 @@ void nfsd4_revoke_states(struct nfsd_net *nn, struct super_block *sb)
 					mutex_unlock(&stp->st_mutex);
 					break;
 				case SC_TYPE_DELEG:
+					/* Extra reference guards against concurrent
+					 * FREE_STATEID; revoke_delegation() consumes
+					 * it, otherwise release it directly.
+					 */
 					refcount_inc(&stid->sc_count);
 					dp = delegstateid(stid);
 					spin_lock(&nn->deleg_lock);
@@ -1848,6 +1853,8 @@ void nfsd4_revoke_states(struct nfsd_net *nn, struct super_block *sb)
 					spin_unlock(&nn->deleg_lock);
 					if (dp)
 						revoke_delegation(dp);
+					else
+						nfs4_put_stid(stid);
 					break;
 				case SC_TYPE_LAYOUT:
 					ls = layoutstateid(stid);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0416/2077] ARM: imx3: Fix CCM node reference leak
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (414 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0415/2077] NFSD: Fix delegation reference leak in nfsd4_revoke_states Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0417/2077] HID: wiimote: Fix table layout and whitespace errors Greg Kroah-Hartman
                   ` (581 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yuho Choi <dbgh9129@gmail.com>

[ Upstream commit 36d46348eb5fc4bc505cd2290ddd70c25fbe6bb3 ]

of_find_compatible_node() returns a referenced device node. The i.MX31
and i.MX35 early init paths use the node to map the CCM registers with
of_iomap(), but never drop the node reference.

Release the node after the mapping is created.

Fixes: 2cf98d12958c ("ARM: imx3: Retrieve the CCM base address from devicetree")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm/mach-imx/mm-imx3.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/arch/arm/mach-imx/mm-imx3.c b/arch/arm/mach-imx/mm-imx3.c
index 0788c5cc7f9e64..9b0b014d7fe276 100644
--- a/arch/arm/mach-imx/mm-imx3.c
+++ b/arch/arm/mach-imx/mm-imx3.c
@@ -106,6 +106,7 @@ void __init imx31_init_early(void)
 	arm_pm_idle = imx31_idle;
 	np = of_find_compatible_node(NULL, NULL, "fsl,imx31-ccm");
 	mx3_ccm_base = of_iomap(np, 0);
+	of_node_put(np);
 	BUG_ON(!mx3_ccm_base);
 }
 #endif /* ifdef CONFIG_SOC_IMX31 */
@@ -143,6 +144,7 @@ void __init imx35_init_early(void)
 	arch_ioremap_caller = imx3_ioremap_caller;
 	np = of_find_compatible_node(NULL, NULL, "fsl,imx35-ccm");
 	mx3_ccm_base = of_iomap(np, 0);
+	of_node_put(np);
 	BUG_ON(!mx3_ccm_base);
 }
 #endif /* ifdef CONFIG_SOC_IMX35 */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0417/2077] HID: wiimote: Fix table layout and whitespace errors
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (415 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0416/2077] ARM: imx3: Fix CCM node reference leak Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0418/2077] wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode Greg Kroah-Hartman
                   ` (580 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Rheinsberg,
	J .  Neuschäfer, Benjamin Tissoires, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: J. Neuschäfer <j.ne@posteo.net>

[ Upstream commit 12b7731995ca577d86e02196e99ba9c126f47282 ]

Some tab characters snuck into the data layout table for turntable
extensions, which resulted in the table only looking right at a tabstop
of 4, which is uncommon in the kernel. Change them to the equivalent
amount of spaces, which should look correct in any editor.

While at it, also fix the other whitespace errors (trailing spaces at
end of line) introduced in the same commit.

Fixes: 05086f3db530b3 ("HID: wiimote: Add support for the DJ Hero turntable")
Reviewed-by: David Rheinsberg <david@readahead.eu>
Signed-off-by: J. Neuschäfer <j.ne@posteo.net>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hid/hid-wiimote-modules.c | 58 +++++++++++++++----------------
 1 file changed, 29 insertions(+), 29 deletions(-)

diff --git a/drivers/hid/hid-wiimote-modules.c b/drivers/hid/hid-wiimote-modules.c
index dbccdfa6391672..dccb78bb3afd61 100644
--- a/drivers/hid/hid-wiimote-modules.c
+++ b/drivers/hid/hid-wiimote-modules.c
@@ -2403,7 +2403,7 @@ static const struct wiimod_ops wiimod_guitar = {
 	.in_ext = wiimod_guitar_in_ext,
 };
 
-/* 
+/*
  * Turntable
  * DJ Hero came with a Turntable Controller that was plugged in
  * as an extension.
@@ -2439,15 +2439,15 @@ static const __u16 wiimod_turntable_map[] = {
 static void wiimod_turntable_in_ext(struct wiimote_data *wdata, const __u8 *ext)
 {
 	__u8 be, cs, sx, sy, ed, rtt, rbg, rbr, rbb, ltt, lbg, lbr, lbb, bp, bm;
-	/* 
+	/*
 	 * Byte |  7   |  6  |  5  |  4  |  3  |  2   |  1   |  0     |
 	 *------+------+-----+-----+-----+-----+------+------+--------+
-	 *   0  | RTT<4:3>   | 		      	  SX <5:0> 			      |
-	 *   1  | RTT<2:1>   |				  SY <5:0>			      |
+	 *   0  | RTT<4:3>   |                SX <5:0>                |
+	 *   1  | RTT<2:1>   |                SY <5:0>                |
 	 *------+------+-----+-----+-----+-----+------+------+--------+
 	 *   2  |RTT<0>|  ED<4:3>  |          CS<3:0>        | RTT<5> |
 	 *------+------+-----+-----+-----+-----+------+------+--------+
-	 *   3  |     ED<2:0> 	   | 			 LTT<4:0>			  |
+	 *   3  |     ED<2:0>      |             LTT<4:0>             |
 	 *------+------+-----+-----+-----+-----+------+------+--------+
 	 *   4  |  0   |  0  | LBR |  B- |  0  |  B+  |  RBR | LTT<5> |
 	 *------+------+-----+-----+-----+-----+------+------+--------+
@@ -2458,20 +2458,20 @@ static void wiimod_turntable_in_ext(struct wiimote_data *wdata, const __u8 *ext)
 	 * With Motion+ enabled, it will look like this:
 	 * Byte |  8   |  7  |  6  |  5  |  4  |  3   |  2   |  1     |
 	 *------+------+-----+-----+-----+-----+------+------+--------+
-	 *   1  | RTT<4:3>   | 		      	  SX <5:1> 		 |	  0   |
-	 *   2  | RTT<2:1>   |				  SY <5:1>		 |	  0   |
+	 *   1  | RTT<4:3>   |                SX <5:1>       |    0   |
+	 *   2  | RTT<2:1>   |                SY <5:1>       |    0   |
 	 *------+------+-----+-----+-----+-----+------+------+--------+
 	 *   3  |RTT<0>|  ED<4:3>  |          CS<3:0>        | RTT<5> |
 	 *------+------+-----+-----+-----+-----+------+------+--------+
-	 *   4  |     ED<2:0> 	   | 			 LTT<4:0>			  |
+	 *   4  |     ED<2:0>      |             LTT<4:0>             |
 	 *------+------+-----+-----+-----+-----+------+------+--------+
 	 *   5  |  0   |  0  | LBR |  B- |  0  |  B+  | RBR  |  XXXX  |
 	 *------+------+-----+-----+-----+-----+------+------+--------+
 	 *   6  | LBB  |  0  | RBG |  BE | LBG | RBB  | XXXX |  XXXX  |
 	 *------+------+-----+-----+-----+-----+------+------+--------+
 	 */
-	
-	be = !(ext[5] & 0x10); 
+
+	be = !(ext[5] & 0x10);
 	cs = ((ext[2] & 0x1e));
 	sx = ext[0] & 0x3f;
 	sy = ext[1] & 0x3f;
@@ -2499,32 +2499,32 @@ static void wiimod_turntable_in_ext(struct wiimote_data *wdata, const __u8 *ext)
 	input_report_abs(wdata->extension.input, ABS_HAT1X, ltt);
 	input_report_abs(wdata->extension.input, ABS_HAT2X, cs);
 	input_report_abs(wdata->extension.input, ABS_HAT3X, ed);
-	input_report_key(wdata->extension.input, 
-					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_G_RIGHT], 
+	input_report_key(wdata->extension.input,
+					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_G_RIGHT],
 					rbg);
 	input_report_key(wdata->extension.input,
 					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_R_RIGHT],
 					rbr);
-	input_report_key(wdata->extension.input, 
-					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_B_RIGHT], 
+	input_report_key(wdata->extension.input,
+					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_B_RIGHT],
 					rbb);
-	input_report_key(wdata->extension.input, 
-					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_G_LEFT], 
+	input_report_key(wdata->extension.input,
+					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_G_LEFT],
 					lbg);
-	input_report_key(wdata->extension.input, 
-					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_R_LEFT], 
+	input_report_key(wdata->extension.input,
+					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_R_LEFT],
 					lbr);
-	input_report_key(wdata->extension.input, 
-					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_B_LEFT], 
+	input_report_key(wdata->extension.input,
+					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_B_LEFT],
 					lbb);
-	input_report_key(wdata->extension.input, 
-					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_EUPHORIA], 
+	input_report_key(wdata->extension.input,
+					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_EUPHORIA],
 					be);
-	input_report_key(wdata->extension.input, 
-					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_PLUS], 
+	input_report_key(wdata->extension.input,
+					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_PLUS],
 					bp);
-	input_report_key(wdata->extension.input, 
-					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_MINUS], 
+	input_report_key(wdata->extension.input,
+					wiimod_turntable_map[WIIMOD_TURNTABLE_KEY_MINUS],
 					bm);
 
 	input_sync(wdata->extension.input);
@@ -2557,7 +2557,7 @@ static void wiimod_turntable_close(struct input_dev *dev)
 static int wiimod_turntable_probe(const struct wiimod_ops *ops,
 			       struct wiimote_data *wdata)
 {
- 	int ret, i;
+	int ret, i;
 
 	wdata->extension.input = input_allocate_device();
 	if (!wdata->extension.input)
@@ -2594,9 +2594,9 @@ static int wiimod_turntable_probe(const struct wiimod_ops *ops,
 	input_set_abs_params(wdata->extension.input,
 			     ABS_HAT1X, -8, 8, 0, 0);
 	input_set_abs_params(wdata->extension.input,
-			     ABS_HAT2X, 0, 31, 1, 1);	
+			     ABS_HAT2X, 0, 31, 1, 1);
 	input_set_abs_params(wdata->extension.input,
-			     ABS_HAT3X, 0, 7, 0, 0);	 
+			     ABS_HAT3X, 0, 7, 0, 0);
 	ret = input_register_device(wdata->extension.input);
 	if (ret)
 		goto err_free;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0418/2077] wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (416 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0417/2077] HID: wiimote: Fix table layout and whitespace errors Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0419/2077] wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic() Greg Kroah-Hartman
                   ` (579 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kwan Lai Chee Hou,
	Rameshkumar Sundaram, Baochen Qiang, Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kwan Lai Chee Hou <laicheehou9@gmail.com>

[ Upstream commit 10085a654a4c2331d5f0cdc20bfc839a49fbb886 ]

In monitor mode, the driver incorrectly assigns the legacy rate
to the rate_idx field of the radiotap header for HT/VHT/HE/EHT
frames, ignoring the actual MCS value parsed from the hardware.

This causes packet analyzers (like Wireshark) to display incorrect
MCS values (e.g., legacy base rates instead of the true MCS).

Fix this by assigning ppdu_info->mcs as the default rate_mcs
in ath12k_dp_mon_fill_rx_rate(), and remove rate_idx assignments in
ath12k_dp_mon_update_radiotap() to preserve
the previously calculated MCS values (including the HT NSS offset).

Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ

Fixes: 5393dcb45209 ("wifi: ath12k: change the status update in the monitor Rx")
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=220864
Signed-off-by: Kwan Lai Chee Hou <laicheehou9@gmail.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260507015336.14636-1-laicheehou9@gmail.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/ath12k/dp_mon.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

diff --git a/drivers/net/wireless/ath/ath12k/dp_mon.c b/drivers/net/wireless/ath/ath12k/dp_mon.c
index 737287a9aa4629..44c5cff75f1695 100644
--- a/drivers/net/wireless/ath/ath12k/dp_mon.c
+++ b/drivers/net/wireless/ath/ath12k/dp_mon.c
@@ -115,13 +115,14 @@ ath12k_dp_mon_fill_rx_rate(struct ath12k_pdev_dp *dp_pdev,
 	bool is_cck;
 
 	pkt_type = ppdu_info->preamble_type;
-	rate_mcs = ppdu_info->rate;
+	rate_mcs = ppdu_info->mcs;
 	nss = ppdu_info->nss;
 	sgi = ppdu_info->gi;
 
 	switch (pkt_type) {
 	case RX_MSDU_START_PKT_TYPE_11A:
 	case RX_MSDU_START_PKT_TYPE_11B:
+		rate_mcs = ppdu_info->rate;
 		is_cck = (pkt_type == RX_MSDU_START_PKT_TYPE_11B);
 		if (rx_status->band < NUM_NL80211_BANDS) {
 			struct ath12k *ar = ath12k_pdev_dp_to_ar(dp_pdev);
@@ -471,13 +472,10 @@ void ath12k_dp_mon_update_radiotap(struct ath12k_pdev_dp *dp_pdev,
 		rxs->encoding = RX_ENC_HE;
 		ptr = skb_push(mon_skb, sizeof(struct ieee80211_radiotap_he));
 		ath12k_dp_mon_rx_update_radiotap_he(ppduinfo, ptr);
-		rxs->rate_idx = ppduinfo->rate;
 	} else if (ppduinfo->vht_flags) {
 		rxs->encoding = RX_ENC_VHT;
-		rxs->rate_idx = ppduinfo->rate;
 	} else if (ppduinfo->ht_flags) {
 		rxs->encoding = RX_ENC_HT;
-		rxs->rate_idx = ppduinfo->rate;
 	} else {
 		struct ath12k *ar;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0419/2077] wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (417 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0418/2077] wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0420/2077] wifi: ath12k: fix inconsistent arvif state in vdev_create error paths Greg Kroah-Hartman
                   ` (578 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Miaoqing Pan, Tamizh Chelvam Raja,
	Baochen Qiang, Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Miaoqing Pan <miaoqing.pan@oss.qualcomm.com>

[ Upstream commit 98d4f92ab6a1af2ea2ab590d7e2801b203110981 ]

In ath12k_wifi7_dp_rx_h_verify_tkip_mic(), the call to
ath12k_dp_rx_check_nwifi_hdr_len_valid() may return false when the
NWIFI header length is invalid, causing the function to abort early with
-EINVAL.

When this happens, the error propagates to
ath12k_wifi7_dp_rx_h_defrag(), which clears first_frag by setting it
to NULL. As a result, the corresponding MSDU is no longer referenced
by the defragmentation path and is never freed.

This leads to a memory leak for the affected MSDU on this error path.
Proper cleanup is required to ensure the MSDU is released when header
validation fails during TKIP MIC verification.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3

Fixes: 9a0dddfb30f1 ("wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi")
Signed-off-by: Miaoqing Pan <miaoqing.pan@oss.qualcomm.com>
Reviewed-by: Tamizh Chelvam Raja <tamizh.raja@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260512021108.2031651-1-miaoqing.pan@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/ath12k/wifi7/dp_rx.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/net/wireless/ath/ath12k/wifi7/dp_rx.c b/drivers/net/wireless/ath/ath12k/wifi7/dp_rx.c
index 945680b3ebdfce..a5e290edaa898c 100644
--- a/drivers/net/wireless/ath/ath12k/wifi7/dp_rx.c
+++ b/drivers/net/wireless/ath/ath12k/wifi7/dp_rx.c
@@ -1028,8 +1028,10 @@ static int ath12k_wifi7_dp_rx_h_verify_tkip_mic(struct ath12k_pdev_dp *dp_pdev,
 	skb_pull(msdu, hal_rx_desc_sz);
 
 	if (unlikely(!ath12k_dp_rx_check_nwifi_hdr_len_valid(dp, msdu,
-							     rx_info)))
+							     rx_info))) {
+		dev_kfree_skb_any(msdu);
 		return -EINVAL;
+	}
 
 	ath12k_dp_rx_h_ppdu(dp_pdev, rx_info);
 	ath12k_dp_rx_h_undecap(dp_pdev, msdu, HAL_ENCRYPT_TYPE_TKIP_MIC, true,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0420/2077] wifi: ath12k: fix inconsistent arvif state in vdev_create error paths
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (418 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0419/2077] wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic() Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0421/2077] wifi: ath12k: fix NULL deref in change_sta_links for unready link Greg Kroah-Hartman
                   ` (577 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wei Zhang, Baochen Qiang,
	Rameshkumar Sundaram, Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wei Zhang <wei.zhang@oss.qualcomm.com>

[ Upstream commit c972636efc63f0f43d725b59805dd1ae5bc4b31e ]

ath12k_mac_vdev_create() has three error path issues that leave arvif
in an inconsistent state:

1. When ath12k_wmi_vdev_create() fails, the function returns directly
   without clearing arvif->ar, which was already set before the WMI
   call. Subsequent code checking arvif->ar to determine vdev readiness
   will see a non-NULL value despite no vdev existing in firmware.

2. When ath12k_wmi_send_peer_delete_cmd() fails in err_peer_del, the
   code jumped to err: skipping the DP peer cleanup and vdev rollback,
   leaving num_created_vdevs, vdev maps and arvif list membership live.

3. When ath12k_wait_for_peer_delete_done() fails, the code jumped to
   err_vdev_del: skipping the DP peer cleanup.

Fix by changing the ath12k_wmi_vdev_create() failure to goto err instead
of returning directly, routing both err_peer_del failure paths through
err_dp_peer_del: for proper DP peer and vdev rollback, and consolidating
the arvif state cleanup at err:.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3

Fixes: 477cabfdb776 ("wifi: ath12k: modify link arvif creation and removal for MLO")
Signed-off-by: Wei Zhang <wei.zhang@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Link: https://patch.msgid.link/20260512044906.1735821-2-wei.zhang@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/ath12k/mac.c | 9 ++++-----
 1 file changed, 4 insertions(+), 5 deletions(-)

diff --git a/drivers/net/wireless/ath/ath12k/mac.c b/drivers/net/wireless/ath/ath12k/mac.c
index 2cff9485c95afb..6a3aaa1ba47acf 100644
--- a/drivers/net/wireless/ath/ath12k/mac.c
+++ b/drivers/net/wireless/ath/ath12k/mac.c
@@ -10293,7 +10293,7 @@ int ath12k_mac_vdev_create(struct ath12k *ar, struct ath12k_link_vif *arvif)
 	if (ret) {
 		ath12k_warn(ab, "failed to create WMI vdev %d: %d\n",
 			    arvif->vdev_id, ret);
-		return ret;
+		goto err;
 	}
 
 	ar->num_created_vdevs++;
@@ -10440,13 +10440,13 @@ int ath12k_mac_vdev_create(struct ath12k *ar, struct ath12k_link_vif *arvif)
 		if (ret) {
 			ath12k_warn(ar->ab, "failed to delete peer vdev_id %d addr %pM\n",
 				    arvif->vdev_id, arvif->bssid);
-			goto err;
+			goto err_dp_peer_del;
 		}
 
 		ret = ath12k_wait_for_peer_delete_done(ar, arvif->vdev_id,
 						       arvif->bssid);
 		if (ret)
-			goto err_vdev_del;
+			goto err_dp_peer_del;
 
 		ar->num_peers--;
 	}
@@ -10463,8 +10463,6 @@ int ath12k_mac_vdev_create(struct ath12k *ar, struct ath12k_link_vif *arvif)
 
 	ath12k_wmi_vdev_delete(ar, arvif->vdev_id);
 	ar->num_created_vdevs--;
-	arvif->is_created = false;
-	arvif->ar = NULL;
 	ar->allocated_vdev_map &= ~(1LL << arvif->vdev_id);
 	ab->free_vdev_map |= 1LL << arvif->vdev_id;
 	ab->free_vdev_stats_id_map &= ~(1LL << arvif->vdev_stats_id);
@@ -10473,6 +10471,7 @@ int ath12k_mac_vdev_create(struct ath12k *ar, struct ath12k_link_vif *arvif)
 	spin_unlock_bh(&ar->data_lock);
 
 err:
+	arvif->is_created = false;
 	arvif->ar = NULL;
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0421/2077] wifi: ath12k: fix NULL deref in change_sta_links for unready link
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (419 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0420/2077] wifi: ath12k: fix inconsistent arvif state in vdev_create error paths Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0422/2077] ata: libata: Fix ata_exec_internal() Greg Kroah-Hartman
                   ` (576 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wei Zhang, Baochen Qiang,
	Rameshkumar Sundaram, Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wei Zhang <wei.zhang@oss.qualcomm.com>

[ Upstream commit 47809a7c8348bc4a332ccc26a37c7145a5f609f8 ]

_ieee80211_set_active_links() calls _ieee80211_link_use_channel() for
each newly-added link and WARN_ON_ONCE()s if it fails. The call uses
assign_on_failure=true, which allows mac80211 to continue despite
driver failures, but when a mac80211-level channel validation fails
(e.g., combinations check, DFS, or no available radio),
drv_assign_vif_chanctx() is never reached. Since ath12k_mac_vdev_create()
is only called from that path, arvif->is_created remains false and
arvif->ar remains NULL for the failed link.

The subsequent drv_change_sta_links() call reaches
ath12k_mac_op_change_sta_links(), which allocates an arsta and sets
ahsta->links_map |= BIT(link_id) for the broken link before checking
whether the link is ready. When the vdev was never created, only
station_add() is skipped, but the link remains in links_map.

Any subsequent operation iterating links_map and dereferencing arvif->ar
without a NULL check will crash. Two observed examples are NULL deref in
ath12k_mac_ml_station_remove() on disconnect and in ath12k_mac_op_set_key()
when wpa_supplicant installs PTK keys.

  BUG: Unable to handle kernel NULL pointer dereference at 0x00000000
  pc : ath12k_mac_station_post_remove+0x40/0xe8 [ath12k]
  Call trace:
   ath12k_mac_station_post_remove+0x40/0xe8 [ath12k]
   ath12k_mac_op_sta_state+0xb60/0x1720 [ath12k]
   drv_sta_state+0x100/0xbd8 [mac80211]
   __sta_info_destroy_part2+0x148/0x178 [mac80211]
   ieee80211_set_disassoc+0x500/0x678 [mac80211]

  BUG: Unable to handle kernel NULL pointer dereference at 0x00000000
  pc : ath12k_mac_op_set_key+0x1f8/0x2c0 [ath12k]
  Call trace:
   ath12k_mac_op_set_key+0x1f8/0x2c0 [ath12k]
   drv_set_key+0x70/0x100 [mac80211]
   ieee80211_key_enable_hw_accel+0x78/0x260 [mac80211]
   ieee80211_add_key+0x16c/0x2ac [mac80211]
   nl80211_new_key+0x138/0x280 [cfg80211]

Fix this by checking arvif->is_created before calling
ath12k_mac_alloc_assign_link_sta(). This prevents the broken link from
entering links_map, so all subsequent operations iterating the bitmap
are protected. The reliability of arvif->is_created across all error
paths is ensured by the preceding patch.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3

Fixes: a27fa6148dac ("wifi: ath12k: support change_sta_links() mac80211 op")
Signed-off-by: Wei Zhang <wei.zhang@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Link: https://patch.msgid.link/20260512044906.1735821-3-wei.zhang@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/ath12k/mac.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/net/wireless/ath/ath12k/mac.c b/drivers/net/wireless/ath/ath12k/mac.c
index 6a3aaa1ba47acf..74af291350241d 100644
--- a/drivers/net/wireless/ath/ath12k/mac.c
+++ b/drivers/net/wireless/ath/ath12k/mac.c
@@ -8054,16 +8054,16 @@ int ath12k_mac_op_change_sta_links(struct ieee80211_hw *hw,
 			continue;
 
 		arvif = wiphy_dereference(hw->wiphy, ahvif->link[link_id]);
-		arsta = ath12k_mac_alloc_assign_link_sta(ah, ahsta, ahvif, link_id);
+		if (!arvif || !arvif->is_created)
+			continue;
 
-		if (!arvif || !arsta) {
+		arsta = ath12k_mac_alloc_assign_link_sta(ah, ahsta, ahvif, link_id);
+		if (!arsta) {
 			ath12k_hw_warn(ah, "Failed to alloc/assign link sta");
 			continue;
 		}
 
 		ar = arvif->ar;
-		if (!ar)
-			continue;
 
 		ret = ath12k_mac_station_add(ar, arvif, arsta);
 		if (ret) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0422/2077] ata: libata: Fix ata_exec_internal()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (420 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0421/2077] wifi: ath12k: fix NULL deref in change_sta_links for unready link Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0423/2077] ACPI: button: Fix lid_device value leak past driver removal Greg Kroah-Hartman
                   ` (575 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bart Van Assche, Niklas Cassel,
	Damien Le Moal, Hannes Reinecke, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bart Van Assche <bvanassche@acm.org>

[ Upstream commit aa0ae1c35f7b3e9afed2324bed5f5c87ad55b92c ]

Some but not all ata_exec_internal() calls happen from the context of
the ATA error handler. Commit c0c362b60e25 ("libata: implement cross-port
EH exclusion") added ata_eh_release() and ata_eh_acquire() calls in
ata_exec_internal(). Calling these functions is necessary if the caller
holds the eh_mutex but is not allowed if the caller doesn't hold that
mutex. Fix this by only calling ata_eh_release() and ata_eh_acquire() if
the caller holds the eh_mutex. An example of an indirect caller of
ata_exec_internal() that does not hold the eh_mutex is
ata_host_register().

Fixes: c0c362b60e25 ("libata: implement cross-port EH exclusion")
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: Niklas Cassel <cassel@kernel.org>
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/ata/libata-core.c | 19 +++++++++++++++++--
 1 file changed, 17 insertions(+), 2 deletions(-)

diff --git a/drivers/ata/libata-core.c b/drivers/ata/libata-core.c
index 3d0027ec33c2a2..3e19a00a92393f 100644
--- a/drivers/ata/libata-core.c
+++ b/drivers/ata/libata-core.c
@@ -1540,6 +1540,7 @@ unsigned int ata_exec_internal(struct ata_device *dev, struct ata_taskfile *tf,
 {
 	struct ata_link *link = dev->link;
 	struct ata_port *ap = link->ap;
+	const bool owns_eh_mutex = ap->host->eh_owner == current;
 	u8 command = tf->command;
 	struct ata_queued_cmd *qc;
 	struct scatterlist sgl;
@@ -1617,11 +1618,25 @@ unsigned int ata_exec_internal(struct ata_device *dev, struct ata_taskfile *tf,
 		}
 	}
 
-	ata_eh_release(ap);
+	if (owns_eh_mutex) {
+		/*
+		 * To prevent that the compiler complains about the
+		 * ata_eh_release() call below.
+		 */
+		__acquire(&ap->host->eh_mutex);
+		ata_eh_release(ap);
+	}
 
 	rc = wait_for_completion_timeout(&wait, msecs_to_jiffies(timeout));
 
-	ata_eh_acquire(ap);
+	if (owns_eh_mutex) {
+		ata_eh_acquire(ap);
+		/*
+		 * To prevent that the compiler complains about the above
+		 * ata_eh_acquire() call.
+		 */
+		__release(&ap->host->eh_mutex);
+	}
 
 	ata_sff_flush_pio_task(ap);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0423/2077] ACPI: button: Fix lid_device value leak past driver removal
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (421 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0422/2077] ata: libata: Fix ata_exec_internal() Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0424/2077] ARM: imx31: Fix IIM mapping leak in revision check Greg Kroah-Hartman
                   ` (574 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit f8600e0d1ac60e6eac34bc9c7e8cf78f7a4c368f ]

Static variable lid_device is set when the ACPI button driver probes
the last lid device (under the assumptions that there will be only
one lid device in the system) and never cleared, but in principle it
should be reset when the driver unbinds from the lid device pointed
to by it.

Address that and add locking that is needed to clear and set that
variable safely.

Fixes: 7e12715ecc47 ("ACPI button: provide lid status functions")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/6281379.lOV4Wx5bFT@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/acpi/button.c | 26 ++++++++++++++++++++++++--
 1 file changed, 24 insertions(+), 2 deletions(-)

diff --git a/drivers/acpi/button.c b/drivers/acpi/button.c
index d80276368b810f..5df470eea7540c 100644
--- a/drivers/acpi/button.c
+++ b/drivers/acpi/button.c
@@ -182,7 +182,6 @@ struct acpi_button {
 	bool gpe_enabled;
 };
 
-static struct acpi_device *lid_device;
 static long lid_init_state = -1;
 
 static unsigned long lid_report_interval __read_mostly = 500;
@@ -378,9 +377,29 @@ static int acpi_button_remove_fs(struct acpi_button *button)
 	return 0;
 }
 
+static struct acpi_device *lid_device;
+static DEFINE_MUTEX(acpi_lid_lock);
+
+static void acpi_lid_save(struct acpi_device *adev)
+{
+	guard(mutex)(&acpi_lid_lock);
+
+	lid_device = adev;
+}
+
+static void acpi_lid_forget(struct acpi_device *adev)
+{
+	guard(mutex)(&acpi_lid_lock);
+
+	if (lid_device == adev)
+		lid_device = NULL;
+}
+
 /* Driver Interface */
 int acpi_lid_open(void)
 {
+	guard(mutex)(&acpi_lid_lock);
+
 	if (!lid_device)
 		return -ENODEV;
 
@@ -674,7 +693,7 @@ static int acpi_button_probe(struct platform_device *pdev)
 		 * This assumes there's only one lid device, or if there are
 		 * more we only care about the last one...
 		 */
-		lid_device = device;
+		acpi_lid_save(device);
 	}
 
 	pr_info("%s [%s]\n", name, acpi_device_bid(device));
@@ -696,6 +715,9 @@ static void acpi_button_remove(struct platform_device *pdev)
 	struct acpi_button *button = platform_get_drvdata(pdev);
 	struct acpi_device *adev = button->adev;
 
+	if (button->type == ACPI_BUTTON_TYPE_LID)
+		acpi_lid_forget(adev);
+
 	switch (adev->device_type) {
 	case ACPI_BUS_TYPE_POWER_BUTTON:
 		acpi_remove_fixed_event_handler(ACPI_EVENT_POWER_BUTTON,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0424/2077] ARM: imx31: Fix IIM mapping leak in revision check
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (422 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0423/2077] ACPI: button: Fix lid_device value leak past driver removal Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0425/2077] x86/cpu: Keep the PROCESSOR_SELECT menu together Greg Kroah-Hartman
                   ` (573 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yuho Choi <dbgh9129@gmail.com>

[ Upstream commit ccb4b54b8ecf1ebafef96d538cd6c5c8455bb390 ]

mx31_read_cpu_rev() maps the IIM registers with of_iomap() to read the
silicon revision, but returns without unmapping the MMIO mapping.

Keep the normalized revision value in a local variable and route the
return path through iounmap() after the revision register has been read.

Fixes: 3172225d45bd ("ARM: imx31: Retrieve the IIM base address from devicetree")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm/mach-imx/cpu-imx31.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/arch/arm/mach-imx/cpu-imx31.c b/arch/arm/mach-imx/cpu-imx31.c
index 35c544924e5095..e81ef9e36a1fab 100644
--- a/arch/arm/mach-imx/cpu-imx31.c
+++ b/arch/arm/mach-imx/cpu-imx31.c
@@ -36,6 +36,7 @@ static int mx31_read_cpu_rev(void)
 	void __iomem *iim_base;
 	struct device_node *np;
 	u32 i, srev;
+	int rev = IMX_CHIP_REVISION_UNKNOWN;
 
 	np = of_find_compatible_node(NULL, NULL, "fsl,imx31-iim");
 	iim_base = of_iomap(np, 0);
@@ -48,13 +49,17 @@ static int mx31_read_cpu_rev(void)
 
 	for (i = 0; i < ARRAY_SIZE(mx31_cpu_type); i++)
 		if (srev == mx31_cpu_type[i].srev) {
+			rev = mx31_cpu_type[i].rev;
 			imx_print_silicon_rev(mx31_cpu_type[i].name,
 						mx31_cpu_type[i].rev);
-			return mx31_cpu_type[i].rev;
+			goto out;
 		}
 
 	imx_print_silicon_rev("i.MX31", IMX_CHIP_REVISION_UNKNOWN);
-	return IMX_CHIP_REVISION_UNKNOWN;
+
+out:
+	iounmap(iim_base);
+	return rev;
 }
 
 int mx31_revision(void)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0425/2077] x86/cpu: Keep the PROCESSOR_SELECT menu together
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (423 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0424/2077] ARM: imx31: Fix IIM mapping leak in revision check Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0426/2077] nvdimm/btt: Handle preemption in BTT lane acquisition Greg Kroah-Hartman
                   ` (572 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Randy Dunlap, Borislav Petkov (AMD),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Randy Dunlap <rdunlap@infradead.org>

[ Upstream commit 1df61a8b2d01c560822a0421f2a76af7fda34c1f ]

Having a stray kconfig symbol in the middle of the PROCESSOR_SELECT menu
(this symbol plus its dependent symbols) causes the menu dependencies
not to be displayed correctly in "make {menu,n,g,x}config".

Move the BROADCAST_TLB_FLUSH symbol away from the PROCESSOR_SELECT menu
so that the list of processors is displayed correctly.

Fixes: 767ae437a32d ("x86/mm: Add INVLPGB feature and Kconfig entry")
Signed-off-by: Randy Dunlap <rdunlap@infradead.org>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Link: https://patch.msgid.link/20260519173526.10985-1-rdunlap@infradead.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/x86/Kconfig.cpu | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/arch/x86/Kconfig.cpu b/arch/x86/Kconfig.cpu
index d7ba9219cb47dc..df003a42d25a6d 100644
--- a/arch/x86/Kconfig.cpu
+++ b/arch/x86/Kconfig.cpu
@@ -334,10 +334,6 @@ menuconfig PROCESSOR_SELECT
 	  This lets you choose what x86 vendor support code your kernel
 	  will include.
 
-config BROADCAST_TLB_FLUSH
-	def_bool y
-	depends on CPU_SUP_AMD && 64BIT
-
 config CPU_SUP_INTEL
 	default y
 	bool "Support Intel processors" if PROCESSOR_SELECT
@@ -458,3 +454,7 @@ config CPU_SUP_VORTEX_32
 	  makes the kernel a tiny bit smaller.
 
 	  If unsure, say N.
+
+config BROADCAST_TLB_FLUSH
+	def_bool y
+	depends on CPU_SUP_AMD && 64BIT
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0426/2077] nvdimm/btt: Handle preemption in BTT lane acquisition
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (424 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0425/2077] x86/cpu: Keep the PROCESSOR_SELECT menu together Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0427/2077] tcp_bbr: fix SPDX-License-Identifier to be GPL-2.0 OR BSD-3-Clause Greg Kroah-Hartman
                   ` (571 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Aboorva Devarajan, Vishal Verma,
	Dave Jiang, Alison Schofield, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alison Schofield <alison.schofield@intel.com>

[ Upstream commit 8d4b989d9c9afe5f185aa5853b666fc4617afe9e ]

BTT lanes serialize access to per-lane metadata and workspace state
during BTT I/O. The btt-check unit test reports data mismatches during
BTT writes due to a race in lane acquisition that can lead to silent
data corruption.

The existing lane model uses a spinlock together with a per-CPU
recursion count. That recursion model stopped being valid after BTT
lanes became preemptible: another task can run on the same CPU,
observe a non-zero recursion count, bypass locking, and use the same
lane concurrently.

BTT lanes are also held across arena_write_bytes() calls. That path
reaches nsio_rw_bytes(), which flushes writes with nvdimm_flush().
Some provider flush callbacks can sleep, making a spinlock the wrong
primitive for the lane lifetime.

Replace the spinlock-based recursion model with a dynamically
allocated per-lane mutex array and take the lane lock
unconditionally.

Add might_sleep() to catch any future atomic-context caller.

Found with the ndctl unit test btt-check.sh.

Fixes: 36c75ce3bd29 ("nd_btt: Make BTT lanes preemptible")
Assisted-by: Claude-Sonnet:4.5
Tested-by: Aboorva Devarajan <aboorvad@linux.ibm.com>
Reviewed-by: Aboorva Devarajan <aboorvad@linux.ibm.com>
Reviewed-by: Vishal Verma <vishal.l.verma@intel.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Link: https://patch.msgid.link/20260528021625.618462-1-alison.schofield@intel.com
Signed-off-by: Alison Schofield <alison.schofield@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/driver-api/nvdimm/btt.rst |  5 +-
 drivers/nvdimm/nd.h                     | 11 ++---
 drivers/nvdimm/region_devs.c            | 66 +++++++++----------------
 3 files changed, 29 insertions(+), 53 deletions(-)

diff --git a/Documentation/driver-api/nvdimm/btt.rst b/Documentation/driver-api/nvdimm/btt.rst
index 2d8269f834bd60..d29fab95f14942 100644
--- a/Documentation/driver-api/nvdimm/btt.rst
+++ b/Documentation/driver-api/nvdimm/btt.rst
@@ -161,9 +161,8 @@ process::
 	nlanes = min(nfree, num_cpus)
 
 A lane number is obtained at the start of any IO, and is used for indexing into
-all the on-disk and in-memory data structures for the duration of the IO. If
-there are more CPUs than the max number of available lanes, than lanes are
-protected by spinlocks.
+all the on-disk and in-memory data structures for the duration of the IO. Lanes
+are protected by mutexes.
 
 
 d. In-memory data structure: Read Tracking Table (RTT)
diff --git a/drivers/nvdimm/nd.h b/drivers/nvdimm/nd.h
index b199eea3260ef6..197e5368c0a46b 100644
--- a/drivers/nvdimm/nd.h
+++ b/drivers/nvdimm/nd.h
@@ -365,11 +365,6 @@ unsigned sizeof_namespace_label(struct nvdimm_drvdata *ndd);
 	for (res = (ndd)->dpa.child, next = res ? res->sibling : NULL; \
 			res; res = next, next = next ? next->sibling : NULL)
 
-struct nd_percpu_lane {
-	int count;
-	spinlock_t lock;
-};
-
 enum nd_label_flags {
 	ND_LABEL_REAP,
 };
@@ -400,6 +395,10 @@ struct nd_mapping {
 	struct nvdimm_drvdata *ndd;
 };
 
+struct nd_lane {
+	struct mutex lock; /* serialize lane access */
+} ____cacheline_aligned_in_smp;
+
 struct nd_region {
 	struct device dev;
 	struct ida ns_ida;
@@ -420,7 +419,7 @@ struct nd_region {
 	struct kernfs_node *bb_state;
 	struct badblocks bb;
 	struct nd_interleave_set *nd_set;
-	struct nd_percpu_lane __percpu *lane;
+	struct nd_lane *lane;
 	int (*flush)(struct nd_region *nd_region, struct bio *bio);
 	struct nd_mapping mapping[] __counted_by(ndr_mappings);
 };
diff --git a/drivers/nvdimm/region_devs.c b/drivers/nvdimm/region_devs.c
index e35c2e18518f0c..5e079d61cbaa32 100644
--- a/drivers/nvdimm/region_devs.c
+++ b/drivers/nvdimm/region_devs.c
@@ -192,7 +192,9 @@ static void nd_region_release(struct device *dev)
 
 		put_device(&nvdimm->dev);
 	}
-	free_percpu(nd_region->lane);
+	for (i = 0; i < nd_region->num_lanes; i++)
+		mutex_destroy(&nd_region->lane[i].lock);
+	kfree(nd_region->lane);
 	if (!test_bit(ND_REGION_CXL, &nd_region->flags))
 		memregion_free(nd_region->id);
 	kfree(nd_region);
@@ -904,52 +906,30 @@ void nd_region_advance_seeds(struct nd_region *nd_region, struct device *dev)
  * nd_region_acquire_lane - allocate and lock a lane
  * @nd_region: region id and number of lanes possible
  *
- * A lane correlates to a BLK-data-window and/or a log slot in the BTT.
- * We optimize for the common case where there are 256 lanes, one
- * per-cpu.  For larger systems we need to lock to share lanes.  For now
- * this implementation assumes the cost of maintaining an allocator for
- * free lanes is on the order of the lock hold time, so it implements a
- * static lane = cpu % num_lanes mapping.
+ * A lane correlates to a log slot in the BTT. Lanes are shared across
+ * CPUs using a static lane = cpu % num_lanes mapping, with a per-lane
+ * mutex to serialize access.
  *
- * In the case of a BTT instance on top of a BLK namespace a lane may be
- * acquired recursively.  We lock on the first instance.
- *
- * In the case of a BTT instance on top of PMEM, we only acquire a lane
- * for the BTT metadata updates.
+ * Callers must be in sleepable context. The only in-tree caller is
+ * BTT's ->submit_bio handler (btt_read_pg / btt_write_pg).
  */
 unsigned int nd_region_acquire_lane(struct nd_region *nd_region)
+	__acquires(&nd_region->lane[lane].lock)
 {
-	unsigned int cpu, lane;
-
-	migrate_disable();
-	cpu = smp_processor_id();
-	if (nd_region->num_lanes < nr_cpu_ids) {
-		struct nd_percpu_lane *ndl_lock, *ndl_count;
+	unsigned int lane;
 
-		lane = cpu % nd_region->num_lanes;
-		ndl_count = per_cpu_ptr(nd_region->lane, cpu);
-		ndl_lock = per_cpu_ptr(nd_region->lane, lane);
-		if (ndl_count->count++ == 0)
-			spin_lock(&ndl_lock->lock);
-	} else
-		lane = cpu;
+	might_sleep();
 
+	lane = raw_smp_processor_id() % nd_region->num_lanes;
+	mutex_lock(&nd_region->lane[lane].lock);
 	return lane;
 }
 EXPORT_SYMBOL(nd_region_acquire_lane);
 
 void nd_region_release_lane(struct nd_region *nd_region, unsigned int lane)
+	__releases(&nd_region->lane[lane].lock)
 {
-	if (nd_region->num_lanes < nr_cpu_ids) {
-		unsigned int cpu = smp_processor_id();
-		struct nd_percpu_lane *ndl_lock, *ndl_count;
-
-		ndl_count = per_cpu_ptr(nd_region->lane, cpu);
-		ndl_lock = per_cpu_ptr(nd_region->lane, lane);
-		if (--ndl_count->count == 0)
-			spin_unlock(&ndl_lock->lock);
-	}
-	migrate_enable();
+	mutex_unlock(&nd_region->lane[lane].lock);
 }
 EXPORT_SYMBOL(nd_region_release_lane);
 
@@ -1019,17 +999,16 @@ static struct nd_region *nd_region_create(struct nvdimm_bus *nvdimm_bus,
 			goto err_id;
 	}
 
-	nd_region->lane = alloc_percpu(struct nd_percpu_lane);
+	nd_region->num_lanes = ndr_desc->num_lanes;
+	if (!nd_region->num_lanes)
+		goto err_percpu;
+	nd_region->lane = kcalloc(nd_region->num_lanes,
+				  sizeof(*nd_region->lane), GFP_KERNEL);
 	if (!nd_region->lane)
 		goto err_percpu;
 
-        for (i = 0; i < nr_cpu_ids; i++) {
-		struct nd_percpu_lane *ndl;
-
-		ndl = per_cpu_ptr(nd_region->lane, i);
-		spin_lock_init(&ndl->lock);
-		ndl->count = 0;
-	}
+	for (i = 0; i < nd_region->num_lanes; i++)
+		mutex_init(&nd_region->lane[i].lock);
 
 	for (i = 0; i < ndr_desc->num_mappings; i++) {
 		struct nd_mapping_desc *mapping = &ndr_desc->mapping[i];
@@ -1046,7 +1025,6 @@ static struct nd_region *nd_region_create(struct nvdimm_bus *nvdimm_bus,
 	}
 	nd_region->provider_data = ndr_desc->provider_data;
 	nd_region->nd_set = ndr_desc->nd_set;
-	nd_region->num_lanes = ndr_desc->num_lanes;
 	nd_region->flags = ndr_desc->flags;
 	nd_region->ro = ro;
 	nd_region->numa_node = ndr_desc->numa_node;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0427/2077] tcp_bbr: fix SPDX-License-Identifier to be GPL-2.0 OR BSD-3-Clause
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (425 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0426/2077] nvdimm/btt: Handle preemption in BTT lane acquisition Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0428/2077] scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans" Greg Kroah-Hartman
                   ` (570 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Neal Cardwell, Yuchung Cheng,
	Van Jacobson, Soheil Hassas Yeganeh, Tim Bird, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Neal Cardwell <ncardwell@google.com>

[ Upstream commit 4490516d2109e105daf732681435c5c075b5d61b ]

Since TCP BBR congestion control was introduced in
commit 0f8782ea1497 ("tcp_bbr: add BBR congestion control")
it has always been offered as "Dual BSD/GPL":

  MODULE_LICENSE("Dual BSD/GPL");

A GPL-2.0-only SPDX header was erroneously added in the recent
commit 2ed4b46b4fc7 ("net: Add SPDX ids to some source files").

This commit revises the tcp_bbr.c SPDX-License-Identifier to note that
this file is licensed as "GPL-2.0 OR BSD-3-Clause".

Fixes: 2ed4b46b4fc7 ("net: Add SPDX ids to some source files")
Signed-off-by: Neal Cardwell <ncardwell@google.com>
Cc: Yuchung Cheng <ycheng@google.com>
Cc: Van Jacobson <vanj@google.com>
Cc: Soheil Hassas Yeganeh <soheil@google.com>
Reviewed-by: Tim Bird <tim.bird@sony.com>
Link: https://patch.msgid.link/20260531183558.2337381-1-ncardwell.sw@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/ipv4/tcp_bbr.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv4/tcp_bbr.c b/net/ipv4/tcp_bbr.c
index aec7805b1d3763..82378a2bfd1e19 100644
--- a/net/ipv4/tcp_bbr.c
+++ b/net/ipv4/tcp_bbr.c
@@ -1,4 +1,4 @@
-// SPDX-License-Identifier: GPL-2.0
+// SPDX-License-Identifier: GPL-2.0 OR BSD-3-Clause
 /* Bottleneck Bandwidth and RTT (BBR) congestion control
  *
  * BBR congestion control computes the sending rate based on the delivery
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0428/2077] scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans"
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (426 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0427/2077] tcp_bbr: fix SPDX-License-Identifier to be GPL-2.0 OR BSD-3-Clause Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0429/2077] bpf: Reject exclusive maps as inner maps in map-in-map Greg Kroah-Hartman
                   ` (569 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Martin Wilck, Don Brace, storagedev,
	Ranjan Kumar, Sathya Prakash Veerichetty, Kashyap Desai,
	Sumit Saxena, mpi3mr-linuxdrv.pdl, MPT-FusionLinux.pdl, Yihang Li,
	Christoph Hellwig, Martin K. Petersen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Martin Wilck <martin.wilck@suse.com>

[ Upstream commit 8c292e89bd831c8a13e92f3429ef66bbe0b83677 ]

This reverts commit 37c4e72b0651e7697eb338cd1fb09feef472cc1a.

Said commit causes excessive resource usage and even system freeze with
some controllers, e.g. smartpqi and hisi_sas. The justification provided
by the patch authors [1] was supporting a special mode of the mpi3mr and
mpt3sas, so-called "Tri-mode", in which NVMe drives are exposed as SCSI
devices on a separate channel. While that's useful for these drivers, it
seems wrong to cause major breakage for other drivers for the sake of
this feature.

[1] https://lore.kernel.org/linux-scsi/CAFdVvOwjy+2ORJ6uJkspiLTPF05481U7gcS4QohFOFGPqAs8ig@mail.gmail.com/

Fixes: 37c4e72b0651 ("scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans")
Signed-off-by: Martin Wilck <martin.wilck@suse.com>
Cc: Don Brace <don.brace@microchip.com>
Cc: storagedev@microchip.com
Cc: Ranjan Kumar <ranjan.kumar@broadcom.com>
Cc: Sathya Prakash Veerichetty <sathya.prakash@broadcom.com>
Cc: Kashyap Desai <kashyap.desai@broadcom.com>
Cc: Sumit Saxena <sumit.saxena@broadcom.com>
Cc: mpi3mr-linuxdrv.pdl@broadcom.com
Cc: MPT-FusionLinux.pdl@broadcom.com
Cc: Yihang Li <liyihang9@h-partners.c>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260513174236.430465-3-mwilck@suse.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/scsi/scsi_scan.c          |  2 +-
 drivers/scsi/scsi_transport_sas.c | 60 +++++++------------------------
 2 files changed, 13 insertions(+), 49 deletions(-)

diff --git a/drivers/scsi/scsi_scan.c b/drivers/scsi/scsi_scan.c
index ef22a4228b8550..b118ed0bf53f81 100644
--- a/drivers/scsi/scsi_scan.c
+++ b/drivers/scsi/scsi_scan.c
@@ -1910,7 +1910,7 @@ int scsi_scan_host_selected(struct Scsi_Host *shost, unsigned int channel,
 
 	return 0;
 }
-EXPORT_SYMBOL(scsi_scan_host_selected);
+
 static void scsi_sysfs_add_devices(struct Scsi_Host *shost)
 {
 	struct scsi_device *sdev;
diff --git a/drivers/scsi/scsi_transport_sas.c b/drivers/scsi/scsi_transport_sas.c
index 13412702188e44..d8f2377b017fe4 100644
--- a/drivers/scsi/scsi_transport_sas.c
+++ b/drivers/scsi/scsi_transport_sas.c
@@ -40,8 +40,6 @@
 #include <scsi/scsi_transport_sas.h>
 
 #include "scsi_sas_internal.h"
-#include "scsi_priv.h"
-
 struct sas_host_attrs {
 	struct list_head rphy_list;
 	struct mutex lock;
@@ -1685,22 +1683,6 @@ int scsi_is_sas_rphy(const struct device *dev)
 }
 EXPORT_SYMBOL(scsi_is_sas_rphy);
 
-static void scan_channel_zero(struct Scsi_Host *shost, uint id, u64 lun)
-{
-	struct sas_host_attrs *sas_host = to_sas_host_attrs(shost);
-	struct sas_rphy *rphy;
-
-	list_for_each_entry(rphy, &sas_host->rphy_list, list) {
-		if (rphy->identify.device_type != SAS_END_DEVICE ||
-		    rphy->scsi_target_id == -1)
-			continue;
-
-		if (id == SCAN_WILD_CARD || id == rphy->scsi_target_id) {
-			scsi_scan_target(&rphy->dev, 0, rphy->scsi_target_id,
-					 lun, SCSI_SCAN_MANUAL);
-		}
-	}
-}
 
 /*
  * SCSI scan helper
@@ -1710,41 +1692,23 @@ static int sas_user_scan(struct Scsi_Host *shost, uint channel,
 		uint id, u64 lun)
 {
 	struct sas_host_attrs *sas_host = to_sas_host_attrs(shost);
-	int res = 0;
-	int i;
-
-	switch (channel) {
-	case 0:
-		mutex_lock(&sas_host->lock);
-		scan_channel_zero(shost, id, lun);
-		mutex_unlock(&sas_host->lock);
-		break;
-
-	case SCAN_WILD_CARD:
-		mutex_lock(&sas_host->lock);
-		scan_channel_zero(shost, id, lun);
-		mutex_unlock(&sas_host->lock);
+	struct sas_rphy *rphy;
 
-		for (i = 1; i <= shost->max_channel; i++) {
-			res = scsi_scan_host_selected(shost, i, id, lun,
-						      SCSI_SCAN_MANUAL);
-			if (res)
-				goto exit_scan;
-		}
-		break;
+	mutex_lock(&sas_host->lock);
+	list_for_each_entry(rphy, &sas_host->rphy_list, list) {
+		if (rphy->identify.device_type != SAS_END_DEVICE ||
+		    rphy->scsi_target_id == -1)
+			continue;
 
-	default:
-		if (channel <= shost->max_channel) {
-			res = scsi_scan_host_selected(shost, channel, id, lun,
-						      SCSI_SCAN_MANUAL);
-		} else {
-			res = -EINVAL;
+		if ((channel == SCAN_WILD_CARD || channel == 0) &&
+		    (id == SCAN_WILD_CARD || id == rphy->scsi_target_id)) {
+			scsi_scan_target(&rphy->dev, 0, rphy->scsi_target_id,
+					 lun, SCSI_SCAN_MANUAL);
 		}
-		break;
 	}
+	mutex_unlock(&sas_host->lock);
 
-exit_scan:
-	return res;
+	return 0;
 }
 
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0429/2077] bpf: Reject exclusive maps as inner maps in map-in-map
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (427 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0428/2077] scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans" Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0430/2077] libbpf: Reject non-exclusive metadata maps in the signed loader Greg Kroah-Hartman
                   ` (568 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko, Daniel Borkmann,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

[ Upstream commit 9a3c3c49c333760c8944dadacbe114c1884546ef ]

An exclusive map (created with excl_prog_hash) is bound to a single
program by hash: check_map_prog_compatibility() refuses to load any
program whose digest does not match map->excl_prog_sha. That check
only runs for maps a program references directly, i.e. its used_maps.
A map reached at runtime through a map-of-maps is never in used_maps,
and bpf_map_meta_equal() does not consider excl_prog_sha, so an
exclusive map can be inserted into a non-exclusive outer map and
then looked up and mutated by an unrelated program, bypassing the
exclusivity guarantee.

For the signed loader this defeats the metadata map exclusivity check
added in the signed loader: the cached map->sha[] is validated against
the signed hash while another program on a hostile host rewrites the
frozen map's contents through the outer map.

Fixes: baefdbdf6812 ("bpf: Implement exclusive map creation")
Reported-by: sashiko <sashiko@sashiko.dev>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20260601150248.394863-2-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/bpf/map_in_map.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/kernel/bpf/map_in_map.c b/kernel/bpf/map_in_map.c
index 645bd30bc9a9d5..d2cbab4bdf644a 100644
--- a/kernel/bpf/map_in_map.c
+++ b/kernel/bpf/map_in_map.c
@@ -20,7 +20,8 @@ struct bpf_map *bpf_map_meta_alloc(int inner_map_ufd)
 	/* Does not support >1 level map-in-map */
 	if (inner_map->inner_map_meta)
 		return ERR_PTR(-EINVAL);
-
+	if (inner_map->excl_prog_sha)
+		return ERR_PTR(-ENOTSUPP);
 	if (!inner_map->ops->map_meta_equal)
 		return ERR_PTR(-ENOTSUPP);
 
@@ -101,6 +102,8 @@ void *bpf_map_fd_get_ptr(struct bpf_map *map,
 	inner_map = __bpf_map_get(f);
 	if (IS_ERR(inner_map))
 		return inner_map;
+	if (inner_map->excl_prog_sha)
+		return ERR_PTR(-ENOTSUPP);
 
 	inner_map_meta = map->inner_map_meta;
 	if (inner_map_meta->ops->map_meta_equal(inner_map_meta, inner_map))
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0430/2077] libbpf: Reject non-exclusive metadata maps in the signed loader
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (428 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0429/2077] bpf: Reject exclusive maps as inner maps in map-in-map Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0431/2077] libbpf: Skip initial_value override on signed loaders Greg Kroah-Hartman
                   ` (567 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, KP Singh, Daniel Borkmann,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: KP Singh <kpsingh@kernel.org>

[ Upstream commit 0fb6c9ed6493b4af01be8bb0a384574eba7df636 ]

The loader verifies map->sha against the metadata hash in its
instructions. map->sha is calculated when BPF_OBJ_GET_INFO_BY_FD is
called on the frozen map.

While the map is frozen, the /signed loader/ must also ensure the map
is exclusive, as, without exclusivity (which a hostile host could just
omit when loading the loader), another BPF program with map access can
mutate the contents afterwards, so the check passes on stale data.

With the extra check as part of the signed loader, it now refuses to
move on with map->sha validation if the host set it up wrongly.

Fixes: fb2b0e290147 ("libbpf: Update light skeleton for signing")
Signed-off-by: KP Singh <kpsingh@kernel.org>
Co-developed-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20260601150248.394863-4-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/bpf.h        |  1 +
 kernel/bpf/syscall.c       |  7 +++++++
 tools/lib/bpf/gen_loader.c | 17 +++++++++++++++++
 3 files changed, 25 insertions(+)

diff --git a/include/linux/bpf.h b/include/linux/bpf.h
index cd191c5fdb0a5e..487f4653d8a669 100644
--- a/include/linux/bpf.h
+++ b/include/linux/bpf.h
@@ -295,6 +295,7 @@ struct bpf_map_owner {
 
 struct bpf_map {
 	u8 sha[SHA256_DIGEST_SIZE];
+	u32 excl;
 	const struct bpf_map_ops *ops;
 	struct bpf_map *inner_map_meta;
 #ifdef CONFIG_SECURITY
diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
index d1274486a564ee..2edda1844ec7fd 100644
--- a/kernel/bpf/syscall.c
+++ b/kernel/bpf/syscall.c
@@ -1572,6 +1572,13 @@ static int map_create(union bpf_attr *attr, bpfptr_t uattr)
 			err = -EFAULT;
 			goto free_map;
 		}
+
+		/* See libbpf: emit_signature_match() */
+		BUILD_BUG_ON(offsetof(struct bpf_map, excl) != SHA256_DIGEST_SIZE);
+		BUILD_BUG_ON(!__same_type(map->excl, u32));
+		BUILD_BUG_ON(offsetof(struct bpf_map, sha)  != 0);
+		BUILD_BUG_ON(!__same_type(map->sha, u8[SHA256_DIGEST_SIZE]));
+		map->excl = 1;
 	} else if (attr->excl_prog_hash_size) {
 		err = -EINVAL;
 		goto free_map;
diff --git a/tools/lib/bpf/gen_loader.c b/tools/lib/bpf/gen_loader.c
index e63a01101e2d85..91790dc82eb6c8 100644
--- a/tools/lib/bpf/gen_loader.c
+++ b/tools/lib/bpf/gen_loader.c
@@ -585,6 +585,23 @@ static void emit_signature_match(struct bpf_gen *gen)
 	__s64 off;
 	int i;
 
+	/*
+	 * Reject if the metadata map is not exclusive. Without exclusivity
+	 * the cached map->sha[] verified above can be stale: another BPF
+	 * program with map access could have mutated the contents between
+	 * BPF_OBJ_GET_INFO_BY_FD and loader execution.
+	 */
+	emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX,
+					 0, 0, 0, 0));
+	emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_2, BPF_REG_1, SHA256_DIGEST_LENGTH));
+	off = -(gen->insn_cur - gen->insn_start - gen->cleanup_label) / 8 - 2;
+	if (is_simm16(off)) {
+		emit(gen, BPF_MOV64_IMM(BPF_REG_7, -EINVAL));
+		emit(gen, BPF_JMP_IMM(BPF_JNE, BPF_REG_2, 1, off));
+	} else {
+		gen->error = -ERANGE;
+	}
+
 	for (i = 0; i < SHA256_DWORD_SIZE; i++) {
 		emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX,
 						 0, 0, 0, 0));
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0431/2077] libbpf: Skip initial_value override on signed loaders
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (429 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0430/2077] libbpf: Reject non-exclusive metadata maps in the signed loader Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0432/2077] libbpf: Skip max_entries " Greg Kroah-Hartman
                   ` (566 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Daniel Borkmann, Alexei Starovoitov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

[ Upstream commit 61e084152328867fe2279cc790573aae39959cd5 ]

bpf_gen__map_update_elem() emits code that, when the host-supplied
loader ctx provides a non-NULL map_desc[idx].initial_value, overwrites
the blob value with bytes read from the host (bpf_copy_from_user /
bpf_probe_read_kernel) before the BPF_MAP_UPDATE_ELEM that populates
the program's .data/.rodata/.bss maps.

This override runs after emit_signature_match() has validated map->sha[],
and initial_value is part of neither the signed loader instructions nor
the hashed data blob. For a signed loader this lets an untrusted host
substitute global-variable contents into a program whose code carries
a valid signature, thus weakening what the signature attests to.

The blob already contains the signer-provided value (added via add_data()
and covered by the embedded, signed hash), so simply skip emitting the
override for signed loaders (gen_hash). Runtime initialization stays
available for the unsigned light-skeleton path as before. The jump
offsets within the override block are internal to it, so guarding the
whole block leaves them unchanged.

Fixes: ea923080c145 ("libbpf: Embed and verify the metadata hash in the loader")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20260601150248.394863-5-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/lib/bpf/gen_loader.c | 39 +++++++++++++++++++++++---------------
 1 file changed, 24 insertions(+), 15 deletions(-)

diff --git a/tools/lib/bpf/gen_loader.c b/tools/lib/bpf/gen_loader.c
index 91790dc82eb6c8..0cb14e030b8be6 100644
--- a/tools/lib/bpf/gen_loader.c
+++ b/tools/lib/bpf/gen_loader.c
@@ -1186,27 +1186,36 @@ void bpf_gen__map_update_elem(struct bpf_gen *gen, int map_idx, void *pvalue,
 	value = add_data(gen, pvalue, value_size);
 	key = add_data(gen, &zero, sizeof(zero));
 
-	/* if (map_desc[map_idx].initial_value) {
+	/*
+	 * if (map_desc[map_idx].initial_value) {
 	 *    if (ctx->flags & BPF_SKEL_KERNEL)
 	 *        bpf_probe_read_kernel(value, value_size, initial_value);
 	 *    else
 	 *        bpf_copy_from_user(value, value_size, initial_value);
 	 * }
+	 *
+	 * The runtime initial_value comes from the host-supplied loader
+	 * ctx and would overwrite the blob value after emit_signature_match()
+	 * has already validated map->sha[]. For a signed loader (gen_hash)
+	 * the attested blob value must be authoritative, so skip the override
+	 * and leave the hashed value in place.
 	 */
-	emit(gen, BPF_LDX_MEM(BPF_DW, BPF_REG_3, BPF_REG_6,
-			      sizeof(struct bpf_loader_ctx) +
-			      sizeof(struct bpf_map_desc) * map_idx +
-			      offsetof(struct bpf_map_desc, initial_value)));
-	emit(gen, BPF_JMP_IMM(BPF_JEQ, BPF_REG_3, 0, 8));
-	emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
-					 0, 0, 0, value));
-	emit(gen, BPF_MOV64_IMM(BPF_REG_2, value_size));
-	emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_0, BPF_REG_6,
-			      offsetof(struct bpf_loader_ctx, flags)));
-	emit(gen, BPF_JMP_IMM(BPF_JSET, BPF_REG_0, BPF_SKEL_KERNEL, 2));
-	emit(gen, BPF_EMIT_CALL(BPF_FUNC_copy_from_user));
-	emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 1));
-	emit(gen, BPF_EMIT_CALL(BPF_FUNC_probe_read_kernel));
+	if (!OPTS_GET(gen->opts, gen_hash, false)) {
+		emit(gen, BPF_LDX_MEM(BPF_DW, BPF_REG_3, BPF_REG_6,
+				      sizeof(struct bpf_loader_ctx) +
+				      sizeof(struct bpf_map_desc) * map_idx +
+				      offsetof(struct bpf_map_desc, initial_value)));
+		emit(gen, BPF_JMP_IMM(BPF_JEQ, BPF_REG_3, 0, 8));
+		emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
+						 0, 0, 0, value));
+		emit(gen, BPF_MOV64_IMM(BPF_REG_2, value_size));
+		emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_0, BPF_REG_6,
+				      offsetof(struct bpf_loader_ctx, flags)));
+		emit(gen, BPF_JMP_IMM(BPF_JSET, BPF_REG_0, BPF_SKEL_KERNEL, 2));
+		emit(gen, BPF_EMIT_CALL(BPF_FUNC_copy_from_user));
+		emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 1));
+		emit(gen, BPF_EMIT_CALL(BPF_FUNC_probe_read_kernel));
+	}
 
 	map_update_attr = add_data(gen, &attr, attr_size);
 	pr_debug("gen: map_update_elem: idx %d, value: off %d size %d, attr: off %d size %d\n",
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0432/2077] libbpf: Skip max_entries override on signed loaders
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (430 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0431/2077] libbpf: Skip initial_value override on signed loaders Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0433/2077] scsi: pm8001: Fix error code in non_fatal_log_show() Greg Kroah-Hartman
                   ` (565 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Daniel Borkmann, Alexei Starovoitov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

[ Upstream commit 60214435b365ecdd40b2f96d4e54564b5c927645 ]

bpf_gen__map_create() lets the host-supplied loader ctx override a
map's max_entries at runtime (map_desc[idx].max_entries, when non-zero).
This is how the light skeleton sizes maps to the target machine, but
it happens after emit_signature_match() and is covered by neither the
signed loader instructions nor the hashed blob.

For a signed loader this means an untrusted host can re-dimension the
program's maps, outside what the signature attests to. Gate the override
on gen_hash so signed loaders use the signer-provided max_entries baked
into the blob.

Fixes: ea923080c145 ("libbpf: Embed and verify the metadata hash in the loader")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20260601150248.394863-6-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/lib/bpf/gen_loader.c | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/tools/lib/bpf/gen_loader.c b/tools/lib/bpf/gen_loader.c
index 0cb14e030b8be6..40004aa3af71bc 100644
--- a/tools/lib/bpf/gen_loader.c
+++ b/tools/lib/bpf/gen_loader.c
@@ -545,13 +545,22 @@ void bpf_gen__map_create(struct bpf_gen *gen,
 	default:
 		break;
 	}
-	/* conditionally update max_entries */
-	if (map_idx >= 0)
+
+	/*
+	 * Conditionally update max_entries from the host-supplied loader
+	 * ctx. This sizes the map at runtime, but for a signed loader
+	 * (gen_hash) it would let an untrusted host re-dimension the
+	 * program's maps after emit_signature_match(), outside what the
+	 * signature attests to. Keep the signer-provided max_entries
+	 * baked into the blob in that case.
+	 */
+	if (map_idx >= 0 && !OPTS_GET(gen->opts, gen_hash, false))
 		move_ctx2blob(gen, attr_field(map_create_attr, max_entries), 4,
 			      sizeof(struct bpf_loader_ctx) +
 			      sizeof(struct bpf_map_desc) * map_idx +
 			      offsetof(struct bpf_map_desc, max_entries),
 			      true /* check that max_entries != 0 */);
+
 	/* emit MAP_CREATE command */
 	emit_sys_bpf(gen, BPF_MAP_CREATE, map_create_attr, attr_size);
 	debug_ret(gen, "map_create %s idx %d type %d value_size %d value_btf_id %d",
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0433/2077] scsi: pm8001: Fix error code in non_fatal_log_show()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (431 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0432/2077] libbpf: Skip max_entries " Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0434/2077] scsi: ufs: Fix wrong value printed in unexpected UPIU response case Greg Kroah-Hartman
                   ` (564 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Jack Wang,
	Martin K. Petersen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dan Carpenter <error27@gmail.com>

[ Upstream commit 1b6f03b7ae9ee27054c55bb55a69d05555a78516 ]

The non_fatal_log_show() function is supposed to return negative error
codes on failure.  But because the error codes are saved in a u32 and
then cast to signed long, they end up being high positive values instead
of negative.  Remove the intermediary u32 variable to fix this bug.

Fixes: dba2cc03b9db ("scsi: pm80xx: sysfs attribute for non fatal dump")
Signed-off-by: Dan Carpenter <error27@gmail.com>
Acked-by: Jack Wang <jinpu.wang@ionos.com>
Link: https://patch.msgid.link/ahs-bEsBJH0KhnsX@stanley.mountain
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/scsi/pm8001/pm8001_ctl.c | 5 +----
 1 file changed, 1 insertion(+), 4 deletions(-)

diff --git a/drivers/scsi/pm8001/pm8001_ctl.c b/drivers/scsi/pm8001/pm8001_ctl.c
index cbfda8c04e956a..c10854ec44c7bd 100644
--- a/drivers/scsi/pm8001/pm8001_ctl.c
+++ b/drivers/scsi/pm8001/pm8001_ctl.c
@@ -588,10 +588,7 @@ static DEVICE_ATTR(fatal_log, S_IRUGO, pm8001_ctl_fatal_log_show, NULL);
 static ssize_t non_fatal_log_show(struct device *cdev,
 	struct device_attribute *attr, char *buf)
 {
-	u32 count;
-
-	count = pm80xx_get_non_fatal_dump(cdev, attr, buf);
-	return count;
+	return pm80xx_get_non_fatal_dump(cdev, attr, buf);
 }
 static DEVICE_ATTR_RO(non_fatal_log);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0434/2077] scsi: ufs: Fix wrong value printed in unexpected UPIU response case
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (432 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0433/2077] scsi: pm8001: Fix error code in non_fatal_log_show() Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0435/2077] bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs Greg Kroah-Hartman
                   ` (563 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chanwoo Lee, Bart Van Assche,
	Martin K. Petersen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chanwoo Lee <cw9316.lee@samsung.com>

[ Upstream commit 2483ae0a56231a915c706411421c6c002a2bf83e ]

In ufshcd_transfer_rsp_status(), the default case of the inner switch
statement prints the UPIU response code when an unexpected response is
received. However, the code was printing 'result' variable which is
always 0 at that point, making the error message useless for debugging.

Fix this by printing the actual UPIU response code returned by
ufshcd_get_req_rsp().

Fixes: 08108d31129a ("scsi: ufs: Improve type safety")
Signed-off-by: Chanwoo Lee <cw9316.lee@samsung.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260527092134.275887-1-cw9316.lee@samsung.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/ufs/core/ufshcd.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/ufs/core/ufshcd.c b/drivers/ufs/core/ufshcd.c
index c3f08957d179ac..385e1a8eec1620 100644
--- a/drivers/ufs/core/ufshcd.c
+++ b/drivers/ufs/core/ufshcd.c
@@ -5634,7 +5634,7 @@ static inline int ufshcd_transfer_rsp_status(struct ufs_hba *hba,
 		default:
 			dev_err(hba->dev,
 				"Unexpected request response code = %x\n",
-				result);
+				ufshcd_get_req_rsp(lrbp->ucd_rsp_ptr));
 			result = DID_ERROR << 16;
 			break;
 		}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0435/2077] bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (433 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0434/2077] scsi: ufs: Fix wrong value printed in unexpected UPIU response case Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0436/2077] mm/fake-numa: fix under-allocation detection in uniform split Greg Kroah-Hartman
                   ` (562 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+36e50496c8ac4bcde3f9, Al Viro,
	Deepanshu Kartikey, Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Deepanshu Kartikey <kartikey406@gmail.com>

[ Upstream commit b93c55b4932dd7e32dca8cf34a3443cc87a02906 ]

commit 4f375ade6aa9 ("bpf: Avoid RCU context warning when unpinning
htab with internal structs") moved inode cleanup from ->free_inode()
into ->destroy_inode() to avoid sleeping in RCU context when calling
bpf_any_put(). However this removed the RCU delay on freeing the
inode itself and the cached symlink body (i_link), both of which
can be accessed by RCU pathwalk (pick_link, may_lookup etc.).

This causes a use-after-free when a concurrent unlinkat() drops the
last inode reference and destroy_inode() frees the inode immediately,
while another task is still walking the path in RCU mode and reads
inode->i_opflags (offset +2) inside current_time() -> is_mgtime().

KASAN reports:
  BUG: KASAN: slab-use-after-free in is_mgtime include/linux/fs.h:2313
  Read of size 2 at addr ffff8880407e4282 (offset +2 = i_opflags)

The rules (per Al Viro):
  ->destroy_inode()  called immediately, can sleep, use for blocking
                     cleanup e.g. bpf_any_put()
  ->free_inode()     called after RCU grace period, use for freeing
                     inode and anything RCU-accessible e.g. i_link

Fix: split the two concerns properly:
  - keep bpf_any_put() in bpf_destroy_inode() since it is blocking
    and needs to run promptly
  - introduce bpf_free_inode() to handle kfree(i_link) and
    free_inode_nonrcu() with proper RCU delay, preventing the UAF

Fixes: 4f375ade6aa9 ("bpf: Avoid RCU context warning when unpinning htab with internal structs")
Reported-by: syzbot+36e50496c8ac4bcde3f9@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=36e50496c8ac4bcde3f9
Suggested-by: Al Viro <viro@zeniv.linux.org.uk>
Link: https://lore.kernel.org/all/20260423043906.GN3518998@ZenIV/
Link: https://lore.kernel.org/all/20260602002607.110866-1-kartikey406@gmail.com/T/ [v1]
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Acked-by: Al Viro <viro@zeniv.linux.org.uk>
Link: https://lore.kernel.org/r/20260602025249.113828-1-kartikey406@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/bpf/inode.c | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/kernel/bpf/inode.c b/kernel/bpf/inode.c
index 25c06a0118258d..188c774a469ca5 100644
--- a/kernel/bpf/inode.c
+++ b/kernel/bpf/inode.c
@@ -766,10 +766,18 @@ static void bpf_destroy_inode(struct inode *inode)
 {
 	enum bpf_type type;
 
-	if (S_ISLNK(inode->i_mode))
-		kfree(inode->i_link);
 	if (!bpf_inode_type(inode, &type))
 		bpf_any_put(inode->i_private, type);
+}
+
+/*
+ * Called after RCU grace period - safe to free inode and anything
+ *  that might be accessed by RCU pathwalk (inode fields, i_link).
+ */
+static void bpf_free_inode(struct inode *inode)
+{
+	if (S_ISLNK(inode->i_mode))
+		kfree(inode->i_link);
 	free_inode_nonrcu(inode);
 }
 
@@ -778,6 +786,7 @@ const struct super_operations bpf_super_ops = {
 	.drop_inode	= inode_just_drop,
 	.show_options	= bpf_show_options,
 	.destroy_inode	= bpf_destroy_inode,
+	.free_inode	= bpf_free_inode,
 };
 
 enum {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0436/2077] mm/fake-numa: fix under-allocation detection in uniform split
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (434 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0435/2077] bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0437/2077] ext2: fix ignored return value of generic_write_sync() Greg Kroah-Hartman
                   ` (561 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sang-Heon Jeon, Donghyeon Lee,
	Munhui Chae, Mike Rapoport (Microsoft), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sang-Heon Jeon <ekffu200098@gmail.com>

[ Upstream commit 3a3fc1dfd6a958615ebaab8fb251e89fc2b3f2f2 ]

When splitting NUMA node uniformly, split_nodes_size_interleave_uniform()
returns the next absolute node ID, not the number of nodes created.

The existing under-allocation detection logic compares next absolute node
ID (ret) and request count (n), which only works when nid starts at 0.

For example, on a system with 2 physical NUMA nodes (node 0: 2GB, node
1: 128MB) and numa=fake=8U, 8 fake nodes are successfully created from
node 0 and split_nodes_size_interleave_uniform() returns 8. For node 1,
fake node nid starts at 8, but only 4 fake nodes are created due to
current FAKE_NODE_MIN_SIZE being 32MB, and
split_nodes_size_interleave_uniform() returns 12. By existing
under-allocation detection logic, "ret < n" (12 < 8) is false, so the
under-allocation will not be detected.

Fix under-allocation detection logic to compare the number of actually
created nodes (ret - nid) against the request count (n). Also skip
under-allocation detection logic for memoryless physical nodes where no
fake nodes are created.

Also, fix the outdated comment describing
split_nodes_size_interleave_uniform() to match the actual return value.

Signed-off-by: Sang-Heon Jeon <ekffu200098@gmail.com>
Reported-by: Donghyeon Lee <asd142513@gmail.com>
Reported-by: Munhui Chae <mochae@student.42seoul.kr>
Fixes: cc9aec03e58f ("x86/numa_emulation: Introduce uniform split capability") # 4.19
Link: https://patch.msgid.link/20260417135805.1758378-1-ekffu200098@gmail.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 mm/numa_emulation.c | 17 +++++++++++++----
 1 file changed, 13 insertions(+), 4 deletions(-)

diff --git a/mm/numa_emulation.c b/mm/numa_emulation.c
index 703c8fa0504801..55f26b22bb0be2 100644
--- a/mm/numa_emulation.c
+++ b/mm/numa_emulation.c
@@ -214,7 +214,7 @@ static u64 uniform_size(u64 max_addr, u64 base, u64 hole, int nr_nodes)
  * Sets up fake nodes of `size' interleaved over physical nodes ranging from
  * `addr' to `max_addr'.
  *
- * Returns zero on success or negative on error.
+ * Returns node ID of the next node on success or negative error code.
  */
 static int __init split_nodes_size_interleave_uniform(struct numa_meminfo *ei,
 					      struct numa_meminfo *pi,
@@ -398,7 +398,7 @@ void __init numa_emulation(struct numa_meminfo *numa_meminfo, int numa_dist_cnt)
 	 */
 	if (strchr(emu_cmdline, 'U')) {
 		unsigned long n;
-		int nid = 0;
+		int nid = 0, nr_created;
 
 		n = simple_strtoul(emu_cmdline, &emu_cmdline, 0);
 		ret = -1;
@@ -416,9 +416,18 @@ void __init numa_emulation(struct numa_meminfo *numa_meminfo, int numa_dist_cnt)
 					n, &pi.blk[0], nid);
 			if (ret < 0)
 				break;
-			if (ret < n) {
+
+			/*
+			 * If no memory was found for this physical node,
+			 * skip the under-allocation check.
+			 */
+			if (ret == nid)
+				continue;
+
+			nr_created = ret - nid;
+			if (nr_created < n) {
 				pr_info("%s: phys: %d only got %d of %ld nodes, failing\n",
-						__func__, i, ret, n);
+						__func__, i, nr_created, n);
 				ret = -1;
 				break;
 			}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0437/2077] ext2: fix ignored return value of generic_write_sync()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (435 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0436/2077] mm/fake-numa: fix under-allocation detection in uniform split Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0438/2077] sched: restore timer_slack_ns when resetting RT policy on fork Greg Kroah-Hartman
                   ` (560 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Danila Chernetsov, Jan Kara,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Danila Chernetsov <listdansp@mail.ru>

[ Upstream commit a4659be0bc7cb1856ffb15b67f903229ae8891ec ]

Fix ext2_dio_write_iter() to propagate the error returned by
generic_write_sync() instead of silently discarding it, which could
cause write(2) to return success to userspace on O_SYNC/O_DSYNC files
even when the sync failed.

The correct pattern, already used in ext2_dax_write_iter() in the same
file and in ext4, xfs, f2fs among others, is:
    if (ret > 0)
        ret = generic_write_sync(iocb, ret);

Found by Linux Verification Center (linuxtesting.org) with SVACE.

[JK: Reflect also filemap_write_and_wait() return value]

Fixes: fb5de4358e1a ("ext2: Move direct-io to use iomap")
Signed-off-by: Danila Chernetsov <listdansp@mail.ru>
Link: https://patch.msgid.link/20260530122311.136803-1-listdansp@mail.ru
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ext2/file.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/fs/ext2/file.c b/fs/ext2/file.c
index d9b1eb34694a04..781d227aff1556 100644
--- a/fs/ext2/file.c
+++ b/fs/ext2/file.c
@@ -267,12 +267,15 @@ static ssize_t ext2_dio_write_iter(struct kiocb *iocb, struct iov_iter *from)
 		endbyte = pos + status - 1;
 		ret2 = filemap_write_and_wait_range(inode->i_mapping, pos,
 						    endbyte);
-		if (!ret2)
+		if (!ret2) {
 			invalidate_mapping_pages(inode->i_mapping,
 						 pos >> PAGE_SHIFT,
 						 endbyte >> PAGE_SHIFT);
-		if (ret > 0)
-			generic_write_sync(iocb, ret);
+			if (ret > 0)
+				ret = generic_write_sync(iocb, ret);
+		} else {
+			ret = ret2;
+		}
 	}
 
 out_unlock:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0438/2077] sched: restore timer_slack_ns when resetting RT policy on fork
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (436 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0437/2077] ext2: fix ignored return value of generic_write_sync() Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0439/2077] nvme: fix FDP fdpcidx bounds check Greg Kroah-Hartman
                   ` (559 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Qiaoting.Lin, Guanyou.Chen,
	Chunhui.Li, Peter Zijlstra (Intel), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guanyou.Chen <chenguanyou9338@gmail.com>

[ Upstream commit 63c1a12bc0e09af7dee919c4fb4a300a719d5125 ]

Commit ed4fb6d7ef68 ("hrtimer: Use and report correct timerslack values
for realtime tasks") sets timer_slack_ns to 0 for RT tasks in
__setscheduler_params(). However, when an RT task with SCHED_RESET_ON_FORK
creates child threads, the children inherit timer_slack_ns=0 from the
parent. sched_fork() resets the child's policy to SCHED_NORMAL but does
not restore timer_slack_ns, leaving the child permanently running with
zero slack.

Fix this by restoring timer_slack_ns from default_timer_slack_ns in
sched_fork() when resetting from RT/DL to NORMAL policy, matching the
existing behavior in __setscheduler_params().

Note: this fix alone requires a correct default_timer_slack_ns to be
effective. See the following patch for that fix.

Fixes: ed4fb6d7ef68 ("hrtimer: Use and report correct timerslack values for realtime tasks")
Reported-by: Qiaoting.Lin <linqiaoting@xiaomi.com>
Signed-off-by: Guanyou.Chen <chenguanyou@xiaomi.com>
Signed-off-by: Chunhui.Li <chunhui.li@mediatek.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/20260522131000.1664983-2-chenguanyou@xiaomi.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/sched/core.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/kernel/sched/core.c b/kernel/sched/core.c
index 091ee8d2b17a89..69c2aa8c624663 100644
--- a/kernel/sched/core.c
+++ b/kernel/sched/core.c
@@ -4710,6 +4710,7 @@ int sched_fork(u64 clone_flags, struct task_struct *p)
 			p->policy = SCHED_NORMAL;
 			p->static_prio = NICE_TO_PRIO(0);
 			p->rt_priority = 0;
+			p->timer_slack_ns = p->default_timer_slack_ns;
 		} else if (PRIO_TO_NICE(p->static_prio) < 0)
 			p->static_prio = NICE_TO_PRIO(0);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0439/2077] nvme: fix FDP fdpcidx bounds check
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (437 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0438/2077] sched: restore timer_slack_ns when resetting RT policy on fork Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0440/2077] driver core: Use system_percpu_wq instead of system_wq Greg Kroah-Hartman
                   ` (558 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nitesh Shetty, Christoph Hellwig,
	liuxixin, Keith Busch, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: liuxixin <gliuxen@gmail.com>

[ Upstream commit 0967074f6830718fd2597404ef119bddd0dbfd00 ]

The fdpcidx bounds check sets n = NUMFDPC + 1 but used > instead of >=,
incorrectly accepting fdp_idx when it equals n (i.e. NUMFDPC + 1).

Fixes: 30b5f20bb2dd ("nvme: register fdp parameters with the block layer")
Reviewed-by: Nitesh Shetty <nj.shetty@samsung.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: liuxixin <gliuxen@gmail.com>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/nvme/host/core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/nvme/host/core.c b/drivers/nvme/host/core.c
index 96809227a0e229..a231da68658537 100644
--- a/drivers/nvme/host/core.c
+++ b/drivers/nvme/host/core.c
@@ -2263,7 +2263,7 @@ static int nvme_query_fdp_granularity(struct nvme_ctrl *ctrl,
 	}
 
 	n = le16_to_cpu(h->numfdpc) + 1;
-	if (fdp_idx > n) {
+	if (fdp_idx >= n) {
 		dev_warn(ctrl->device, "FDP index:%d out of range:%d\n",
 			 fdp_idx, n);
 		/* Proceed without registering FDP streams */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0440/2077] driver core: Use system_percpu_wq instead of system_wq
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (438 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0439/2077] nvme: fix FDP fdpcidx bounds check Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0441/2077] bpf: Reject exclusive maps for bpf_map_elem iterators Greg Kroah-Hartman
                   ` (557 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nathan Chancellor,
	Rafael J. Wysocki (Intel), Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nathan Chancellor <nathan@kernel.org>

[ Upstream commit fda8355f13ea3c0f9499acdeff3024995b474948 ]

Commit 1137838865bf ("driver core: Use mod_delayed_work to prevent lost
deferred probe work") added a use of system_wq, which is deprecated in
favor of system_percpu_wq added by commit 128ea9f6ccfb ("workqueue: Add
system_percpu_wq and system_dfl_wq"). An upcoming warning in the
workqueue tree flags this with:

  workqueue: work func deferred_probe_timeout_work_func enqueued on deprecated workqueue. Use system_{percpu|dfl}_wq instead.

Switch to system_percpu_wq to clear up the warning.

Fixes: 1137838865bf ("driver core: Use mod_delayed_work to prevent lost deferred probe work")
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Reviewed-by: Rafael J. Wysocki (Intel) <rafael@kernel.org>
Link: https://patch.msgid.link/20260601-driver-core-fix-system_wq-warning-v1-1-f9001a70ee25@kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/base/dd.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/base/dd.c b/drivers/base/dd.c
index f64175afefc915..51c7132e98a07c 100644
--- a/drivers/base/dd.c
+++ b/drivers/base/dd.c
@@ -324,7 +324,7 @@ void deferred_probe_extend_timeout(void)
 	 * start a new one.
 	 */
 	if (delayed_work_pending(&deferred_probe_timeout_work) &&
-	    mod_delayed_work(system_wq, &deferred_probe_timeout_work,
+	    mod_delayed_work(system_percpu_wq, &deferred_probe_timeout_work,
 			     secs_to_jiffies(driver_deferred_probe_timeout)))
 		pr_debug("Extended deferred probe timeout by %d secs\n",
 					driver_deferred_probe_timeout);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0441/2077] bpf: Reject exclusive maps for bpf_map_elem iterators
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (439 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0440/2077] driver core: Use system_percpu_wq instead of system_wq Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0442/2077] tick/sched: Fix TOCTOU in nohz idle time fetch Greg Kroah-Hartman
                   ` (556 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Daniel Borkmann, Alexei Starovoitov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

[ Upstream commit 3c56ee343f9412d81918635c3e25e22a5dd6d87e ]

Exclusive maps (aka excl_prog_hash) are meant to be reachable only
from the single program whose hash matches. This is enforced by
check_map_prog_compatibility() when the map is referenced from a
program such as signed BPF loaders.

A bpf_map_elem iterator, however, binds its target map at attach
time in bpf_iter_attach_map() instead of referencing it from the
program, so the exclusivity check is never reached. On top of that,
the iterator exposes the map value as a writable buffer.

Fixes: baefdbdf6812 ("bpf: Implement exclusive map creation")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20260602133052.423725-2-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/bpf/map_iter.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/kernel/bpf/map_iter.c b/kernel/bpf/map_iter.c
index 261a03ea73d349..ae0741a09c6dee 100644
--- a/kernel/bpf/map_iter.c
+++ b/kernel/bpf/map_iter.c
@@ -112,6 +112,10 @@ static int bpf_iter_attach_map(struct bpf_prog *prog,
 	map = bpf_map_get_with_uref(linfo->map.map_fd);
 	if (IS_ERR(map))
 		return PTR_ERR(map);
+	if (map->excl_prog_sha) {
+		err = -EPERM;
+		goto put_map;
+	}
 
 	if (map->map_type == BPF_MAP_TYPE_PERCPU_HASH ||
 	    map->map_type == BPF_MAP_TYPE_LRU_PERCPU_HASH ||
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0442/2077] tick/sched: Fix TOCTOU in nohz idle time fetch
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (440 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0441/2077] bpf: Reject exclusive maps for bpf_map_elem iterators Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0443/2077] lib/test_meminit: use && for bools Greg Kroah-Hartman
                   ` (555 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Frederic Weisbecker, Thomas Gleixner,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Frederic Weisbecker <frederic@kernel.org>

[ Upstream commit 86db4084b4b5d1a074bcc66c108a4c9d266812d4 ]

When the nohz idle time is fetched, the current clock timestamp is taken
outside the seqcount, which can result in a race as reported by Sashiko:

    get_cpu_sleep_time_us()                 tick_nohz_start_idle()
    -----------------------                 ---------------------
    now = ktime_get()
                                            write_seqcount_begin(idle_sleeptime_seq);
                                            idle_entrytime = ktime_get()
                                            tick_sched_flag_set(ts, TS_FLAG_IDLE_ACTIVE);
                                            write_seqcount_end(&ts->idle_sleeptime_seq);
    read_seqcount_begin(idle_sleeptime_seq)
    delta = now - idle_entrytime);
    //!! But now < idle_entrytime
    idle = *sleeptime +  delta;
    read_seqcount_retry(&ts->idle_sleeptime_seq, seq)

Here the read side fetches the timestamp before the write side and its
update. As a result the time delta computed on the read side is negative
(ktime_t is signed) and breaks the cputime monotonicity guarantee.

This could possibly be fixed with reading the current clock timestamp
inside the seqcount but the reader overhead might then increase. Also
simply checking that the current timestamp is above the idle entry time
is enough to prevent any issue of the like.

Fixes: 620a30fa0bd1 ("timers/nohz: Protect idle/iowait sleep time under seqcount")
Reported-by: Sashiko
Signed-off-by: Frederic Weisbecker <frederic@kernel.org>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260508131647.43868-2-frederic@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/time/tick-sched.c | 11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

diff --git a/kernel/time/tick-sched.c b/kernel/time/tick-sched.c
index cbbb87a0c6e7ce..171393367b5c1e 100644
--- a/kernel/time/tick-sched.c
+++ b/kernel/time/tick-sched.c
@@ -797,15 +797,16 @@ static u64 get_cpu_sleep_time_us(struct tick_sched *ts, ktime_t *sleeptime,
 		*last_update_time = ktime_to_us(now);
 
 	do {
+		ktime_t delta = 0;
+
 		seq = read_seqcount_begin(&ts->idle_sleeptime_seq);
 
 		if (tick_sched_flag_test(ts, TS_FLAG_IDLE_ACTIVE) && compute_delta) {
-			ktime_t delta = ktime_sub(now, ts->idle_entrytime);
-
-			idle = ktime_add(*sleeptime, delta);
-		} else {
-			idle = *sleeptime;
+			if (now > ts->idle_entrytime)
+				delta = ktime_sub(now, ts->idle_entrytime);
 		}
+
+		idle = ktime_add(*sleeptime, delta);
 	} while (read_seqcount_retry(&ts->idle_sleeptime_seq, seq));
 
 	return ktime_to_us(idle);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0443/2077] lib/test_meminit: use && for bools
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (441 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0442/2077] tick/sched: Fix TOCTOU in nohz idle time fetch Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0444/2077] riscv: dts: sophgo: sg2044: use hex for CPU unit address Greg Kroah-Hartman
                   ` (554 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alexander Potapenko, Dan Carpenter,
	Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexander Potapenko <glider@google.com>

[ Upstream commit 8e0c2085c978ed6d9764d79fc785920360096f21 ]

As pointed out by Dan Carpenter, test_kmemcache() was using a bitwise AND
on two bools instead of a boolean AND.  Fix this for the sake of code
cleanliness.

Link: https://lore.kernel.org/20260504100637.1535762-1-glider@google.com
Fixes: 5015a300a522 ("lib: introduce test_meminit module")
Signed-off-by: Alexander Potapenko <glider@google.com>
Reported-by: Dan Carpenter <error27@gmail.com>
Closes: https://lore.kernel.org/kernel-janitors/afOcIan1ap9kD26M@stanley.mountain/
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 lib/test_meminit.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/lib/test_meminit.c b/lib/test_meminit.c
index 6298f66c964bb1..d028a6552cd61c 100644
--- a/lib/test_meminit.c
+++ b/lib/test_meminit.c
@@ -387,7 +387,7 @@ static int __init test_kmemcache(int *total_failures)
 			ctor = flags & 1;
 			rcu = flags & 2;
 			zero = flags & 4;
-			if (ctor & zero)
+			if (ctor && zero)
 				continue;
 			num_tests += do_kmem_cache_size(size, ctor, rcu, zero,
 							&failures);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0444/2077] riscv: dts: sophgo: sg2044: use hex for CPU unit address
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (442 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0443/2077] lib/test_meminit: use && for bools Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0445/2077] riscv: dts: sophgo: sg2042: " Greg Kroah-Hartman
                   ` (553 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chen Wang, Guo Ren, Inochi Amaoto,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Inochi Amaoto <inochiama@gmail.com>

[ Upstream commit 207cbc477406a72952e27ace2eadbae55164f129 ]

Previous the CPU unit address cpu of sg2044 use decimal, it is
not following the general convention for unit addresses of the
OF. Convent the unit address to hex to resolve this problem.

The introduces a small change for the CPU node name, but it should
nothing since there is no direct full-path reference to these
CPU nodes.

Fixes: 967a94a92aaa ("riscv: dts: add initial Sophgo SG2042 SoC device tree")
Reviewed-by: Chen Wang <unicorn_wang@outlook.com>
Reviewed-by: Guo Ren <guoren@kernel.org>
Link: https://patch.msgid.link/20260426013449.694435-2-inochiama@gmail.com
Signed-off-by: Inochi Amaoto <inochiama@gmail.com>
Signed-off-by: Chen Wang <unicorn_wang@outlook.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/boot/dts/sophgo/sg2044-cpus.dtsi | 236 ++++++++++----------
 1 file changed, 118 insertions(+), 118 deletions(-)

diff --git a/arch/riscv/boot/dts/sophgo/sg2044-cpus.dtsi b/arch/riscv/boot/dts/sophgo/sg2044-cpus.dtsi
index 3135409c21492f..f66a382c95bd9c 100644
--- a/arch/riscv/boot/dts/sophgo/sg2044-cpus.dtsi
+++ b/arch/riscv/boot/dts/sophgo/sg2044-cpus.dtsi
@@ -14,7 +14,7 @@ cpus {
 
 		cpu0: cpu@0 {
 			compatible = "thead,c920", "riscv";
-			reg = <0>;
+			reg = <0x0>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -50,7 +50,7 @@ cpu0_intc: interrupt-controller {
 
 		cpu1: cpu@1 {
 			compatible = "thead,c920", "riscv";
-			reg = <1>;
+			reg = <0x1>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -86,7 +86,7 @@ cpu1_intc: interrupt-controller {
 
 		cpu2: cpu@2 {
 			compatible = "thead,c920", "riscv";
-			reg = <2>;
+			reg = <0x2>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -122,7 +122,7 @@ cpu2_intc: interrupt-controller {
 
 		cpu3: cpu@3 {
 			compatible = "thead,c920", "riscv";
-			reg = <3>;
+			reg = <0x3>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -158,7 +158,7 @@ cpu3_intc: interrupt-controller {
 
 		cpu4: cpu@4 {
 			compatible = "thead,c920", "riscv";
-			reg = <4>;
+			reg = <0x4>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -194,7 +194,7 @@ cpu4_intc: interrupt-controller {
 
 		cpu5: cpu@5 {
 			compatible = "thead,c920", "riscv";
-			reg = <5>;
+			reg = <0x5>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -230,7 +230,7 @@ cpu5_intc: interrupt-controller {
 
 		cpu6: cpu@6 {
 			compatible = "thead,c920", "riscv";
-			reg = <6>;
+			reg = <0x6>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -266,7 +266,7 @@ cpu6_intc: interrupt-controller {
 
 		cpu7: cpu@7 {
 			compatible = "thead,c920", "riscv";
-			reg = <7>;
+			reg = <0x7>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -302,7 +302,7 @@ cpu7_intc: interrupt-controller {
 
 		cpu8: cpu@8 {
 			compatible = "thead,c920", "riscv";
-			reg = <8>;
+			reg = <0x8>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -338,7 +338,7 @@ cpu8_intc: interrupt-controller {
 
 		cpu9: cpu@9 {
 			compatible = "thead,c920", "riscv";
-			reg = <9>;
+			reg = <0x9>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -372,9 +372,9 @@ cpu9_intc: interrupt-controller {
 			};
 		};
 
-		cpu10: cpu@10 {
+		cpu10: cpu@a {
 			compatible = "thead,c920", "riscv";
-			reg = <10>;
+			reg = <0xa>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -408,9 +408,9 @@ cpu10_intc: interrupt-controller {
 			};
 		};
 
-		cpu11: cpu@11 {
+		cpu11: cpu@b {
 			compatible = "thead,c920", "riscv";
-			reg = <11>;
+			reg = <0xb>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -444,9 +444,9 @@ cpu11_intc: interrupt-controller {
 			};
 		};
 
-		cpu12: cpu@12 {
+		cpu12: cpu@c {
 			compatible = "thead,c920", "riscv";
-			reg = <12>;
+			reg = <0xc>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -480,9 +480,9 @@ cpu12_intc: interrupt-controller {
 			};
 		};
 
-		cpu13: cpu@13 {
+		cpu13: cpu@d {
 			compatible = "thead,c920", "riscv";
-			reg = <13>;
+			reg = <0xd>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -516,9 +516,9 @@ cpu13_intc: interrupt-controller {
 			};
 		};
 
-		cpu14: cpu@14 {
+		cpu14: cpu@e {
 			compatible = "thead,c920", "riscv";
-			reg = <14>;
+			reg = <0xe>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -552,9 +552,9 @@ cpu14_intc: interrupt-controller {
 			};
 		};
 
-		cpu15: cpu@15 {
+		cpu15: cpu@f {
 			compatible = "thead,c920", "riscv";
-			reg = <15>;
+			reg = <0xf>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -588,9 +588,9 @@ cpu15_intc: interrupt-controller {
 			};
 		};
 
-		cpu16: cpu@16 {
+		cpu16: cpu@10 {
 			compatible = "thead,c920", "riscv";
-			reg = <16>;
+			reg = <0x10>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -624,9 +624,9 @@ cpu16_intc: interrupt-controller {
 			};
 		};
 
-		cpu17: cpu@17 {
+		cpu17: cpu@11 {
 			compatible = "thead,c920", "riscv";
-			reg = <17>;
+			reg = <0x11>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -660,9 +660,9 @@ cpu17_intc: interrupt-controller {
 			};
 		};
 
-		cpu18: cpu@18 {
+		cpu18: cpu@12 {
 			compatible = "thead,c920", "riscv";
-			reg = <18>;
+			reg = <0x12>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -696,9 +696,9 @@ cpu18_intc: interrupt-controller {
 			};
 		};
 
-		cpu19: cpu@19 {
+		cpu19: cpu@13 {
 			compatible = "thead,c920", "riscv";
-			reg = <19>;
+			reg = <0x13>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -732,9 +732,9 @@ cpu19_intc: interrupt-controller {
 			};
 		};
 
-		cpu20: cpu@20 {
+		cpu20: cpu@14 {
 			compatible = "thead,c920", "riscv";
-			reg = <20>;
+			reg = <0x14>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -768,9 +768,9 @@ cpu20_intc: interrupt-controller {
 			};
 		};
 
-		cpu21: cpu@21 {
+		cpu21: cpu@15 {
 			compatible = "thead,c920", "riscv";
-			reg = <21>;
+			reg = <0x15>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -804,9 +804,9 @@ cpu21_intc: interrupt-controller {
 			};
 		};
 
-		cpu22: cpu@22 {
+		cpu22: cpu@16 {
 			compatible = "thead,c920", "riscv";
-			reg = <22>;
+			reg = <0x16>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -840,9 +840,9 @@ cpu22_intc: interrupt-controller {
 			};
 		};
 
-		cpu23: cpu@23 {
+		cpu23: cpu@17 {
 			compatible = "thead,c920", "riscv";
-			reg = <23>;
+			reg = <0x17>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -876,9 +876,9 @@ cpu23_intc: interrupt-controller {
 			};
 		};
 
-		cpu24: cpu@24 {
+		cpu24: cpu@18 {
 			compatible = "thead,c920", "riscv";
-			reg = <24>;
+			reg = <0x18>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -912,9 +912,9 @@ cpu24_intc: interrupt-controller {
 			};
 		};
 
-		cpu25: cpu@25 {
+		cpu25: cpu@19 {
 			compatible = "thead,c920", "riscv";
-			reg = <25>;
+			reg = <0x19>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -948,9 +948,9 @@ cpu25_intc: interrupt-controller {
 			};
 		};
 
-		cpu26: cpu@26 {
+		cpu26: cpu@1a {
 			compatible = "thead,c920", "riscv";
-			reg = <26>;
+			reg = <0x1a>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -984,9 +984,9 @@ cpu26_intc: interrupt-controller {
 			};
 		};
 
-		cpu27: cpu@27 {
+		cpu27: cpu@1b {
 			compatible = "thead,c920", "riscv";
-			reg = <27>;
+			reg = <0x1b>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1020,9 +1020,9 @@ cpu27_intc: interrupt-controller {
 			};
 		};
 
-		cpu28: cpu@28 {
+		cpu28: cpu@1c {
 			compatible = "thead,c920", "riscv";
-			reg = <28>;
+			reg = <0x1c>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1056,9 +1056,9 @@ cpu28_intc: interrupt-controller {
 			};
 		};
 
-		cpu29: cpu@29 {
+		cpu29: cpu@1d {
 			compatible = "thead,c920", "riscv";
-			reg = <29>;
+			reg = <0x1d>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1092,9 +1092,9 @@ cpu29_intc: interrupt-controller {
 			};
 		};
 
-		cpu30: cpu@30 {
+		cpu30: cpu@1e {
 			compatible = "thead,c920", "riscv";
-			reg = <30>;
+			reg = <0x1e>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1128,9 +1128,9 @@ cpu30_intc: interrupt-controller {
 			};
 		};
 
-		cpu31: cpu@31 {
+		cpu31: cpu@1f {
 			compatible = "thead,c920", "riscv";
-			reg = <31>;
+			reg = <0x1f>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1164,9 +1164,9 @@ cpu31_intc: interrupt-controller {
 			};
 		};
 
-		cpu32: cpu@32 {
+		cpu32: cpu@20 {
 			compatible = "thead,c920", "riscv";
-			reg = <32>;
+			reg = <0x20>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1200,9 +1200,9 @@ cpu32_intc: interrupt-controller {
 			};
 		};
 
-		cpu33: cpu@33 {
+		cpu33: cpu@21 {
 			compatible = "thead,c920", "riscv";
-			reg = <33>;
+			reg = <0x21>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1236,9 +1236,9 @@ cpu33_intc: interrupt-controller {
 			};
 		};
 
-		cpu34: cpu@34 {
+		cpu34: cpu@22 {
 			compatible = "thead,c920", "riscv";
-			reg = <34>;
+			reg = <0x22>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1272,9 +1272,9 @@ cpu34_intc: interrupt-controller {
 			};
 		};
 
-		cpu35: cpu@35 {
+		cpu35: cpu@23 {
 			compatible = "thead,c920", "riscv";
-			reg = <35>;
+			reg = <0x23>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1308,9 +1308,9 @@ cpu35_intc: interrupt-controller {
 			};
 		};
 
-		cpu36: cpu@36 {
+		cpu36: cpu@24 {
 			compatible = "thead,c920", "riscv";
-			reg = <36>;
+			reg = <0x24>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1344,9 +1344,9 @@ cpu36_intc: interrupt-controller {
 			};
 		};
 
-		cpu37: cpu@37 {
+		cpu37: cpu@25 {
 			compatible = "thead,c920", "riscv";
-			reg = <37>;
+			reg = <0x25>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1380,9 +1380,9 @@ cpu37_intc: interrupt-controller {
 			};
 		};
 
-		cpu38: cpu@38 {
+		cpu38: cpu@26 {
 			compatible = "thead,c920", "riscv";
-			reg = <38>;
+			reg = <0x26>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1416,9 +1416,9 @@ cpu38_intc: interrupt-controller {
 			};
 		};
 
-		cpu39: cpu@39 {
+		cpu39: cpu@27 {
 			compatible = "thead,c920", "riscv";
-			reg = <39>;
+			reg = <0x27>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1452,9 +1452,9 @@ cpu39_intc: interrupt-controller {
 			};
 		};
 
-		cpu40: cpu@40 {
+		cpu40: cpu@28 {
 			compatible = "thead,c920", "riscv";
-			reg = <40>;
+			reg = <0x28>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1488,9 +1488,9 @@ cpu40_intc: interrupt-controller {
 			};
 		};
 
-		cpu41: cpu@41 {
+		cpu41: cpu@29 {
 			compatible = "thead,c920", "riscv";
-			reg = <41>;
+			reg = <0x29>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1524,9 +1524,9 @@ cpu41_intc: interrupt-controller {
 			};
 		};
 
-		cpu42: cpu@42 {
+		cpu42: cpu@2a {
 			compatible = "thead,c920", "riscv";
-			reg = <42>;
+			reg = <0x2a>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1560,9 +1560,9 @@ cpu42_intc: interrupt-controller {
 			};
 		};
 
-		cpu43: cpu@43 {
+		cpu43: cpu@2b {
 			compatible = "thead,c920", "riscv";
-			reg = <43>;
+			reg = <0x2b>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1596,9 +1596,9 @@ cpu43_intc: interrupt-controller {
 			};
 		};
 
-		cpu44: cpu@44 {
+		cpu44: cpu@2c {
 			compatible = "thead,c920", "riscv";
-			reg = <44>;
+			reg = <0x2c>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1632,9 +1632,9 @@ cpu44_intc: interrupt-controller {
 			};
 		};
 
-		cpu45: cpu@45 {
+		cpu45: cpu@2d {
 			compatible = "thead,c920", "riscv";
-			reg = <45>;
+			reg = <0x2d>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1668,9 +1668,9 @@ cpu45_intc: interrupt-controller {
 			};
 		};
 
-		cpu46: cpu@46 {
+		cpu46: cpu@2e {
 			compatible = "thead,c920", "riscv";
-			reg = <46>;
+			reg = <0x2e>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1704,9 +1704,9 @@ cpu46_intc: interrupt-controller {
 			};
 		};
 
-		cpu47: cpu@47 {
+		cpu47: cpu@2f {
 			compatible = "thead,c920", "riscv";
-			reg = <47>;
+			reg = <0x2f>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1740,9 +1740,9 @@ cpu47_intc: interrupt-controller {
 			};
 		};
 
-		cpu48: cpu@48 {
+		cpu48: cpu@30 {
 			compatible = "thead,c920", "riscv";
-			reg = <48>;
+			reg = <0x30>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1776,9 +1776,9 @@ cpu48_intc: interrupt-controller {
 			};
 		};
 
-		cpu49: cpu@49 {
+		cpu49: cpu@31 {
 			compatible = "thead,c920", "riscv";
-			reg = <49>;
+			reg = <0x31>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1812,9 +1812,9 @@ cpu49_intc: interrupt-controller {
 			};
 		};
 
-		cpu50: cpu@50 {
+		cpu50: cpu@32 {
 			compatible = "thead,c920", "riscv";
-			reg = <50>;
+			reg = <0x32>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1848,9 +1848,9 @@ cpu50_intc: interrupt-controller {
 			};
 		};
 
-		cpu51: cpu@51 {
+		cpu51: cpu@33 {
 			compatible = "thead,c920", "riscv";
-			reg = <51>;
+			reg = <0x33>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1884,9 +1884,9 @@ cpu51_intc: interrupt-controller {
 			};
 		};
 
-		cpu52: cpu@52 {
+		cpu52: cpu@34 {
 			compatible = "thead,c920", "riscv";
-			reg = <52>;
+			reg = <0x34>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1920,9 +1920,9 @@ cpu52_intc: interrupt-controller {
 			};
 		};
 
-		cpu53: cpu@53 {
+		cpu53: cpu@35 {
 			compatible = "thead,c920", "riscv";
-			reg = <53>;
+			reg = <0x35>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1956,9 +1956,9 @@ cpu53_intc: interrupt-controller {
 			};
 		};
 
-		cpu54: cpu@54 {
+		cpu54: cpu@36 {
 			compatible = "thead,c920", "riscv";
-			reg = <54>;
+			reg = <0x36>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1992,9 +1992,9 @@ cpu54_intc: interrupt-controller {
 			};
 		};
 
-		cpu55: cpu@55 {
+		cpu55: cpu@37 {
 			compatible = "thead,c920", "riscv";
-			reg = <55>;
+			reg = <0x37>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -2028,9 +2028,9 @@ cpu55_intc: interrupt-controller {
 			};
 		};
 
-		cpu56: cpu@56 {
+		cpu56: cpu@38 {
 			compatible = "thead,c920", "riscv";
-			reg = <56>;
+			reg = <0x38>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -2064,9 +2064,9 @@ cpu56_intc: interrupt-controller {
 			};
 		};
 
-		cpu57: cpu@57 {
+		cpu57: cpu@39 {
 			compatible = "thead,c920", "riscv";
-			reg = <57>;
+			reg = <0x39>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -2100,9 +2100,9 @@ cpu57_intc: interrupt-controller {
 			};
 		};
 
-		cpu58: cpu@58 {
+		cpu58: cpu@3a {
 			compatible = "thead,c920", "riscv";
-			reg = <58>;
+			reg = <0x3a>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -2136,9 +2136,9 @@ cpu58_intc: interrupt-controller {
 			};
 		};
 
-		cpu59: cpu@59 {
+		cpu59: cpu@3b {
 			compatible = "thead,c920", "riscv";
-			reg = <59>;
+			reg = <0x3b>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -2172,9 +2172,9 @@ cpu59_intc: interrupt-controller {
 			};
 		};
 
-		cpu60: cpu@60 {
+		cpu60: cpu@3c {
 			compatible = "thead,c920", "riscv";
-			reg = <60>;
+			reg = <0x3c>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -2208,9 +2208,9 @@ cpu60_intc: interrupt-controller {
 			};
 		};
 
-		cpu61: cpu@61 {
+		cpu61: cpu@3d {
 			compatible = "thead,c920", "riscv";
-			reg = <61>;
+			reg = <0x3d>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -2244,9 +2244,9 @@ cpu61_intc: interrupt-controller {
 			};
 		};
 
-		cpu62: cpu@62 {
+		cpu62: cpu@3e {
 			compatible = "thead,c920", "riscv";
-			reg = <62>;
+			reg = <0x3e>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -2280,9 +2280,9 @@ cpu62_intc: interrupt-controller {
 			};
 		};
 
-		cpu63: cpu@63 {
+		cpu63: cpu@3f {
 			compatible = "thead,c920", "riscv";
-			reg = <63>;
+			reg = <0x3f>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0445/2077] riscv: dts: sophgo: sg2042: use hex for CPU unit address
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (443 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0444/2077] riscv: dts: sophgo: sg2044: use hex for CPU unit address Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:01 ` [PATCH 7.1 0446/2077] configfs_lookup(): dont leave ->s_dentry dangling on failure Greg Kroah-Hartman
                   ` (552 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guo Ren, Chen Wang, Conor Dooley,
	Inochi Amaoto, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Inochi Amaoto <inochiama@gmail.com>

[ Upstream commit a7e658907686528fe06a11828b04a3e42df9ef18 ]

Previous the CPU unit address cpu of sg2042 use decimal, it is
not following the general convention for unit addresses of the
OF. Convent the unit address to hex to resolve this problem.

The introduces a small change for the CPU node name, but it should
affect nothing since there is no direct full-path reference to
these CPU nodes.

Fixes: ae5bac370ed4 ("riscv: dts: sophgo: Add initial device tree of Sophgo SRD3-10")
Tested-by: Chen Wang <unicorn_wang@outlook.com> # Pioneerbox.
Reviewed-by: Guo Ren <guoren@kernel.org>
Reviewed-by: Chen Wang <unicorn_wang@outlook.com>
Acked-by: Conor Dooley <conor.dooley@microchip.com>
Tested-by: Chen Wang <unicorn_wang@outlook.com> on Pioneerbox.
Link: https://patch.msgid.link/20260426013449.694435-3-inochiama@gmail.com
Signed-off-by: Inochi Amaoto <inochiama@gmail.com>
Signed-off-by: Chen Wang <unicorn_wang@outlook.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/boot/dts/sophgo/sg2042-cpus.dtsi | 236 ++++++++++----------
 1 file changed, 118 insertions(+), 118 deletions(-)

diff --git a/arch/riscv/boot/dts/sophgo/sg2042-cpus.dtsi b/arch/riscv/boot/dts/sophgo/sg2042-cpus.dtsi
index 509488eee4321c..fd8906b313d2eb 100644
--- a/arch/riscv/boot/dts/sophgo/sg2042-cpus.dtsi
+++ b/arch/riscv/boot/dts/sophgo/sg2042-cpus.dtsi
@@ -263,7 +263,7 @@ cpu0: cpu@0 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <0>;
+			reg = <0x0>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -291,7 +291,7 @@ cpu1: cpu@1 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <1>;
+			reg = <0x1>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -319,7 +319,7 @@ cpu2: cpu@2 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <2>;
+			reg = <0x2>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -347,7 +347,7 @@ cpu3: cpu@3 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <3>;
+			reg = <0x3>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -375,7 +375,7 @@ cpu4: cpu@4 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <4>;
+			reg = <0x4>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -403,7 +403,7 @@ cpu5: cpu@5 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <5>;
+			reg = <0x5>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -431,7 +431,7 @@ cpu6: cpu@6 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <6>;
+			reg = <0x6>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -459,7 +459,7 @@ cpu7: cpu@7 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <7>;
+			reg = <0x7>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -487,7 +487,7 @@ cpu8: cpu@8 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <8>;
+			reg = <0x8>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -515,7 +515,7 @@ cpu9: cpu@9 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <9>;
+			reg = <0x9>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -533,7 +533,7 @@ cpu9_intc: interrupt-controller {
 			};
 		};
 
-		cpu10: cpu@10 {
+		cpu10: cpu@a {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -543,7 +543,7 @@ cpu10: cpu@10 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <10>;
+			reg = <0xa>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -561,7 +561,7 @@ cpu10_intc: interrupt-controller {
 			};
 		};
 
-		cpu11: cpu@11 {
+		cpu11: cpu@b {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -571,7 +571,7 @@ cpu11: cpu@11 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <11>;
+			reg = <0xb>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -589,7 +589,7 @@ cpu11_intc: interrupt-controller {
 			};
 		};
 
-		cpu12: cpu@12 {
+		cpu12: cpu@c {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -599,7 +599,7 @@ cpu12: cpu@12 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <12>;
+			reg = <0xc>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -617,7 +617,7 @@ cpu12_intc: interrupt-controller {
 			};
 		};
 
-		cpu13: cpu@13 {
+		cpu13: cpu@d {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -627,7 +627,7 @@ cpu13: cpu@13 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <13>;
+			reg = <0xd>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -645,7 +645,7 @@ cpu13_intc: interrupt-controller {
 			};
 		};
 
-		cpu14: cpu@14 {
+		cpu14: cpu@e {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -655,7 +655,7 @@ cpu14: cpu@14 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <14>;
+			reg = <0xe>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -673,7 +673,7 @@ cpu14_intc: interrupt-controller {
 			};
 		};
 
-		cpu15: cpu@15 {
+		cpu15: cpu@f {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -683,7 +683,7 @@ cpu15: cpu@15 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <15>;
+			reg = <0xf>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -701,7 +701,7 @@ cpu15_intc: interrupt-controller {
 			};
 		};
 
-		cpu16: cpu@16 {
+		cpu16: cpu@10 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -711,7 +711,7 @@ cpu16: cpu@16 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <16>;
+			reg = <0x10>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -729,7 +729,7 @@ cpu16_intc: interrupt-controller {
 			};
 		};
 
-		cpu17: cpu@17 {
+		cpu17: cpu@11 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -739,7 +739,7 @@ cpu17: cpu@17 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <17>;
+			reg = <0x11>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -757,7 +757,7 @@ cpu17_intc: interrupt-controller {
 			};
 		};
 
-		cpu18: cpu@18 {
+		cpu18: cpu@12 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -767,7 +767,7 @@ cpu18: cpu@18 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <18>;
+			reg = <0x12>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -785,7 +785,7 @@ cpu18_intc: interrupt-controller {
 			};
 		};
 
-		cpu19: cpu@19 {
+		cpu19: cpu@13 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -795,7 +795,7 @@ cpu19: cpu@19 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <19>;
+			reg = <0x13>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -813,7 +813,7 @@ cpu19_intc: interrupt-controller {
 			};
 		};
 
-		cpu20: cpu@20 {
+		cpu20: cpu@14 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -823,7 +823,7 @@ cpu20: cpu@20 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <20>;
+			reg = <0x14>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -841,7 +841,7 @@ cpu20_intc: interrupt-controller {
 			};
 		};
 
-		cpu21: cpu@21 {
+		cpu21: cpu@15 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -851,7 +851,7 @@ cpu21: cpu@21 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <21>;
+			reg = <0x15>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -869,7 +869,7 @@ cpu21_intc: interrupt-controller {
 			};
 		};
 
-		cpu22: cpu@22 {
+		cpu22: cpu@16 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -879,7 +879,7 @@ cpu22: cpu@22 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <22>;
+			reg = <0x16>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -897,7 +897,7 @@ cpu22_intc: interrupt-controller {
 			};
 		};
 
-		cpu23: cpu@23 {
+		cpu23: cpu@17 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -907,7 +907,7 @@ cpu23: cpu@23 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <23>;
+			reg = <0x17>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -925,7 +925,7 @@ cpu23_intc: interrupt-controller {
 			};
 		};
 
-		cpu24: cpu@24 {
+		cpu24: cpu@18 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -935,7 +935,7 @@ cpu24: cpu@24 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <24>;
+			reg = <0x18>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -953,7 +953,7 @@ cpu24_intc: interrupt-controller {
 			};
 		};
 
-		cpu25: cpu@25 {
+		cpu25: cpu@19 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -963,7 +963,7 @@ cpu25: cpu@25 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <25>;
+			reg = <0x19>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -981,7 +981,7 @@ cpu25_intc: interrupt-controller {
 			};
 		};
 
-		cpu26: cpu@26 {
+		cpu26: cpu@1a {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -991,7 +991,7 @@ cpu26: cpu@26 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <26>;
+			reg = <0x1a>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1009,7 +1009,7 @@ cpu26_intc: interrupt-controller {
 			};
 		};
 
-		cpu27: cpu@27 {
+		cpu27: cpu@1b {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1019,7 +1019,7 @@ cpu27: cpu@27 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <27>;
+			reg = <0x1b>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1037,7 +1037,7 @@ cpu27_intc: interrupt-controller {
 			};
 		};
 
-		cpu28: cpu@28 {
+		cpu28: cpu@1c {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1047,7 +1047,7 @@ cpu28: cpu@28 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <28>;
+			reg = <0x1c>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1065,7 +1065,7 @@ cpu28_intc: interrupt-controller {
 			};
 		};
 
-		cpu29: cpu@29 {
+		cpu29: cpu@1d {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1075,7 +1075,7 @@ cpu29: cpu@29 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <29>;
+			reg = <0x1d>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1093,7 +1093,7 @@ cpu29_intc: interrupt-controller {
 			};
 		};
 
-		cpu30: cpu@30 {
+		cpu30: cpu@1e {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1103,7 +1103,7 @@ cpu30: cpu@30 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <30>;
+			reg = <0x1e>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1121,7 +1121,7 @@ cpu30_intc: interrupt-controller {
 			};
 		};
 
-		cpu31: cpu@31 {
+		cpu31: cpu@1f {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1131,7 +1131,7 @@ cpu31: cpu@31 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <31>;
+			reg = <0x1f>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1149,7 +1149,7 @@ cpu31_intc: interrupt-controller {
 			};
 		};
 
-		cpu32: cpu@32 {
+		cpu32: cpu@20 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1159,7 +1159,7 @@ cpu32: cpu@32 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <32>;
+			reg = <0x20>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1177,7 +1177,7 @@ cpu32_intc: interrupt-controller {
 			};
 		};
 
-		cpu33: cpu@33 {
+		cpu33: cpu@21 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1187,7 +1187,7 @@ cpu33: cpu@33 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <33>;
+			reg = <0x21>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1205,7 +1205,7 @@ cpu33_intc: interrupt-controller {
 			};
 		};
 
-		cpu34: cpu@34 {
+		cpu34: cpu@22 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1215,7 +1215,7 @@ cpu34: cpu@34 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <34>;
+			reg = <0x22>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1233,7 +1233,7 @@ cpu34_intc: interrupt-controller {
 			};
 		};
 
-		cpu35: cpu@35 {
+		cpu35: cpu@23 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1243,7 +1243,7 @@ cpu35: cpu@35 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <35>;
+			reg = <0x23>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1261,7 +1261,7 @@ cpu35_intc: interrupt-controller {
 			};
 		};
 
-		cpu36: cpu@36 {
+		cpu36: cpu@24 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1271,7 +1271,7 @@ cpu36: cpu@36 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <36>;
+			reg = <0x24>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1289,7 +1289,7 @@ cpu36_intc: interrupt-controller {
 			};
 		};
 
-		cpu37: cpu@37 {
+		cpu37: cpu@25 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1299,7 +1299,7 @@ cpu37: cpu@37 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <37>;
+			reg = <0x25>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1317,7 +1317,7 @@ cpu37_intc: interrupt-controller {
 			};
 		};
 
-		cpu38: cpu@38 {
+		cpu38: cpu@26 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1327,7 +1327,7 @@ cpu38: cpu@38 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <38>;
+			reg = <0x26>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1345,7 +1345,7 @@ cpu38_intc: interrupt-controller {
 			};
 		};
 
-		cpu39: cpu@39 {
+		cpu39: cpu@27 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1355,7 +1355,7 @@ cpu39: cpu@39 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <39>;
+			reg = <0x27>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1373,7 +1373,7 @@ cpu39_intc: interrupt-controller {
 			};
 		};
 
-		cpu40: cpu@40 {
+		cpu40: cpu@28 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1383,7 +1383,7 @@ cpu40: cpu@40 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <40>;
+			reg = <0x28>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1401,7 +1401,7 @@ cpu40_intc: interrupt-controller {
 			};
 		};
 
-		cpu41: cpu@41 {
+		cpu41: cpu@29 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1411,7 +1411,7 @@ cpu41: cpu@41 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <41>;
+			reg = <0x29>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1429,7 +1429,7 @@ cpu41_intc: interrupt-controller {
 			};
 		};
 
-		cpu42: cpu@42 {
+		cpu42: cpu@2a {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1439,7 +1439,7 @@ cpu42: cpu@42 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <42>;
+			reg = <0x2a>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1457,7 +1457,7 @@ cpu42_intc: interrupt-controller {
 			};
 		};
 
-		cpu43: cpu@43 {
+		cpu43: cpu@2b {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1467,7 +1467,7 @@ cpu43: cpu@43 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <43>;
+			reg = <0x2b>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1485,7 +1485,7 @@ cpu43_intc: interrupt-controller {
 			};
 		};
 
-		cpu44: cpu@44 {
+		cpu44: cpu@2c {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1495,7 +1495,7 @@ cpu44: cpu@44 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <44>;
+			reg = <0x2c>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1513,7 +1513,7 @@ cpu44_intc: interrupt-controller {
 			};
 		};
 
-		cpu45: cpu@45 {
+		cpu45: cpu@2d {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1523,7 +1523,7 @@ cpu45: cpu@45 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <45>;
+			reg = <0x2d>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1541,7 +1541,7 @@ cpu45_intc: interrupt-controller {
 			};
 		};
 
-		cpu46: cpu@46 {
+		cpu46: cpu@2e {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1551,7 +1551,7 @@ cpu46: cpu@46 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <46>;
+			reg = <0x2e>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1569,7 +1569,7 @@ cpu46_intc: interrupt-controller {
 			};
 		};
 
-		cpu47: cpu@47 {
+		cpu47: cpu@2f {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1579,7 +1579,7 @@ cpu47: cpu@47 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <47>;
+			reg = <0x2f>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1597,7 +1597,7 @@ cpu47_intc: interrupt-controller {
 			};
 		};
 
-		cpu48: cpu@48 {
+		cpu48: cpu@30 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1607,7 +1607,7 @@ cpu48: cpu@48 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <48>;
+			reg = <0x30>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1625,7 +1625,7 @@ cpu48_intc: interrupt-controller {
 			};
 		};
 
-		cpu49: cpu@49 {
+		cpu49: cpu@31 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1635,7 +1635,7 @@ cpu49: cpu@49 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <49>;
+			reg = <0x31>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1653,7 +1653,7 @@ cpu49_intc: interrupt-controller {
 			};
 		};
 
-		cpu50: cpu@50 {
+		cpu50: cpu@32 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1663,7 +1663,7 @@ cpu50: cpu@50 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <50>;
+			reg = <0x32>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1681,7 +1681,7 @@ cpu50_intc: interrupt-controller {
 			};
 		};
 
-		cpu51: cpu@51 {
+		cpu51: cpu@33 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1691,7 +1691,7 @@ cpu51: cpu@51 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <51>;
+			reg = <0x33>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1709,7 +1709,7 @@ cpu51_intc: interrupt-controller {
 			};
 		};
 
-		cpu52: cpu@52 {
+		cpu52: cpu@34 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1719,7 +1719,7 @@ cpu52: cpu@52 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <52>;
+			reg = <0x34>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1737,7 +1737,7 @@ cpu52_intc: interrupt-controller {
 			};
 		};
 
-		cpu53: cpu@53 {
+		cpu53: cpu@35 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1747,7 +1747,7 @@ cpu53: cpu@53 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <53>;
+			reg = <0x35>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1765,7 +1765,7 @@ cpu53_intc: interrupt-controller {
 			};
 		};
 
-		cpu54: cpu@54 {
+		cpu54: cpu@36 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1775,7 +1775,7 @@ cpu54: cpu@54 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <54>;
+			reg = <0x36>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1793,7 +1793,7 @@ cpu54_intc: interrupt-controller {
 			};
 		};
 
-		cpu55: cpu@55 {
+		cpu55: cpu@37 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1803,7 +1803,7 @@ cpu55: cpu@55 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <55>;
+			reg = <0x37>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1821,7 +1821,7 @@ cpu55_intc: interrupt-controller {
 			};
 		};
 
-		cpu56: cpu@56 {
+		cpu56: cpu@38 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1831,7 +1831,7 @@ cpu56: cpu@56 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <56>;
+			reg = <0x38>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1849,7 +1849,7 @@ cpu56_intc: interrupt-controller {
 			};
 		};
 
-		cpu57: cpu@57 {
+		cpu57: cpu@39 {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1859,7 +1859,7 @@ cpu57: cpu@57 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <57>;
+			reg = <0x39>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1877,7 +1877,7 @@ cpu57_intc: interrupt-controller {
 			};
 		};
 
-		cpu58: cpu@58 {
+		cpu58: cpu@3a {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1887,7 +1887,7 @@ cpu58: cpu@58 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <58>;
+			reg = <0x3a>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1905,7 +1905,7 @@ cpu58_intc: interrupt-controller {
 			};
 		};
 
-		cpu59: cpu@59 {
+		cpu59: cpu@3b {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1915,7 +1915,7 @@ cpu59: cpu@59 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <59>;
+			reg = <0x3b>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1933,7 +1933,7 @@ cpu59_intc: interrupt-controller {
 			};
 		};
 
-		cpu60: cpu@60 {
+		cpu60: cpu@3c {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1943,7 +1943,7 @@ cpu60: cpu@60 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <60>;
+			reg = <0x3c>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1961,7 +1961,7 @@ cpu60_intc: interrupt-controller {
 			};
 		};
 
-		cpu61: cpu@61 {
+		cpu61: cpu@3d {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1971,7 +1971,7 @@ cpu61: cpu@61 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <61>;
+			reg = <0x3d>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -1989,7 +1989,7 @@ cpu61_intc: interrupt-controller {
 			};
 		};
 
-		cpu62: cpu@62 {
+		cpu62: cpu@3e {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -1999,7 +1999,7 @@ cpu62: cpu@62 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <62>;
+			reg = <0x3e>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
@@ -2017,7 +2017,7 @@ cpu62_intc: interrupt-controller {
 			};
 		};
 
-		cpu63: cpu@63 {
+		cpu63: cpu@3f {
 			compatible = "thead,c920", "riscv";
 			device_type = "cpu";
 			riscv,isa = "rv64imafdc";
@@ -2027,7 +2027,7 @@ cpu63: cpu@63 {
 					       "zifencei", "zihpm", "zfh",
 					       "xtheadvector";
 			thead,vlenb = <16>;
-			reg = <63>;
+			reg = <0x3f>;
 			i-cache-block-size = <64>;
 			i-cache-size = <65536>;
 			i-cache-sets = <512>;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0446/2077] configfs_lookup(): dont leave ->s_dentry dangling on failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (444 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0445/2077] riscv: dts: sophgo: sg2042: " Greg Kroah-Hartman
@ 2026-07-21 15:01 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0447/2077] lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT Greg Kroah-Hartman
                   ` (551 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:01 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jan Kara, Breno Leitao, Al Viro,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Al Viro <viro@zeniv.linux.org.uk>

[ Upstream commit 10da12d352b7b2bb330a8609fdda9a58bf0e9856 ]

Normally ->s_dentry is cleared when dentry it's pointing to becomes
negative (on eviction, realistically).  However, that only happens
if dentry gets to be positive in the first place; in case of inode
allocation failure dentry never becomes positive, so ->d_iput()
is not called at all.

We do part of what normally would've been done by configfs_d_iput()
(dropping the reference to configfs_dirent) manually, but we do
not clear ->s_dentry there.  Sloppy as it is, it does not matter in
case of configfs_create_{dir,link}() - there configfs_dirent does
not survive dropping the sole reference to it.

However, for configfs_lookup() it *does* survive, with a dangling
pointer to soon to be freed dentry sitting it its ->s_dentry.

Subsequent getdents(2) in that directory will end up dereferencing
that pointer in order to pick the inode number.  Use after free...

This is the minimal fix; the right approach is to set the linkage
between dentry and configfs_dirent only after we know that we have
an inode, but that takes more surgery and the bug had been there
since 2006, so...

Fixes: 3d0f89bb1694 ("configfs: Add permission and ownership to configfs objects") # 2.6.16-rc3
Reviewed-by: Jan Kara <jack@suse.cz>
Reviewed-by: Breno Leitao <leitao@debian.org>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/configfs/dir.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/fs/configfs/dir.c b/fs/configfs/dir.c
index 362b6ff9b908f1..e84483a0836d8e 100644
--- a/fs/configfs/dir.c
+++ b/fs/configfs/dir.c
@@ -486,6 +486,9 @@ static struct dentry * configfs_lookup(struct inode *dir,
 
 			inode = configfs_create(dentry, mode);
 			if (IS_ERR(inode)) {
+				spin_lock(&configfs_dirent_lock);
+				sd->s_dentry = NULL;
+				spin_unlock(&configfs_dirent_lock);
 				configfs_put(sd);
 				return ERR_CAST(inode);
 			}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0447/2077] lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (445 preceding siblings ...)
  2026-07-21 15:01 ` [PATCH 7.1 0446/2077] configfs_lookup(): dont leave ->s_dentry dangling on failure Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0448/2077] lockdep/selftests: Restore sched_rt_mutex " Greg Kroah-Hartman
                   ` (550 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Karl Mehltretter,
	Peter Zijlstra (Intel), Sebastian Andrzej Siewior, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Karl Mehltretter <kmehltretter@gmail.com>

[ Upstream commit d8c897b20bf4d4cbb1e935a8ceb666bcc0f82580 ]

The lockdep selftests deliberately run unbalanced locking patterns.
dotest() restores the task state they leave behind before running the
next testcase.

On PREEMPT_RT, spin_lock() uses migrate_disable() instead of disabling
preemption. dotest() cleans up the resulting migration-disabled state, but
that cleanup is still guarded by CONFIG_SMP.

That used to match the scheduler data model, where migration_disabled was
also CONFIG_SMP-only. The commit referenced below made SMP scheduler state
unconditional, so CONFIG_SMP=n PREEMPT_RT kernels with
CONFIG_DEBUG_LOCKING_API_SELFTESTS=y report success from the selftests and
then trip over stale current->migration_disabled state:

  releasing a pinned lock
  bad: scheduling from the idle thread!
  Kernel panic - not syncing: Fatal exception

Save and restore current->migration_disabled for every PREEMPT_RT build.

Fixes: cac5cefbade9 ("sched/smp: Make SMP unconditional")
Assisted-by: Codex:gpt-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Link: https://patch.msgid.link/20260523185123.17482-2-kmehltretter@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 lib/locking-selftest.c | 4 ----
 1 file changed, 4 deletions(-)

diff --git a/lib/locking-selftest.c b/lib/locking-selftest.c
index d939403331b5a6..cb806b628352b9 100644
--- a/lib/locking-selftest.c
+++ b/lib/locking-selftest.c
@@ -1431,9 +1431,7 @@ static void dotest(void (*testcase_fn)(void), int expected, int lockclass_mask)
 {
 	int saved_preempt_count = preempt_count();
 #ifdef CONFIG_PREEMPT_RT
-#ifdef CONFIG_SMP
 	int saved_mgd_count = current->migration_disabled;
-#endif
 	int saved_rcu_count = current->rcu_read_lock_nesting;
 #endif
 
@@ -1471,10 +1469,8 @@ static void dotest(void (*testcase_fn)(void), int expected, int lockclass_mask)
 	preempt_count_set(saved_preempt_count);
 
 #ifdef CONFIG_PREEMPT_RT
-#ifdef CONFIG_SMP
 	while (current->migration_disabled > saved_mgd_count)
 		migrate_enable();
-#endif
 
 	while (current->rcu_read_lock_nesting > saved_rcu_count)
 		rcu_read_unlock();
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0448/2077] lockdep/selftests: Restore sched_rt_mutex state on PREEMPT_RT
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (446 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0447/2077] lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0449/2077] ext4: fix fast commit wait/wake bit mapping on 64-bit Greg Kroah-Hartman
                   ` (549 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Karl Mehltretter,
	Peter Zijlstra (Intel), Sebastian Andrzej Siewior, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Karl Mehltretter <kmehltretter@gmail.com>

[ Upstream commit 06961d60a0e410bf8df69ccff7eb1bd824912b8f ]

The WW-mutex selftests deliberately exercise failing lock paths. On
PREEMPT_RT, some of those paths enter the RT-mutex scheduler helpers.

The change referenced by the Fixes tag made those helpers track RT-mutex
scheduling state in current->sched_rt_mutex. The bit is normally cleared by
the matching post-schedule helper, but some WW-mutex selftests disable
the runtime debug_locks flag before that happens. With debug_locks cleared,
lockdep_assert() does not evaluate the expression that clears the bit,
leaving stale state for the next testcase.

With CONFIG_PREEMPT_RT=y and CONFIG_DEBUG_LOCKING_API_SELFTESTS=y, that
stale state produces warnings such as:

  WARNING: kernel/sched/core.c:7557 at rt_mutex_pre_schedule+0x26/0x2d
  RIP: 0010:rt_mutex_pre_schedule+0x26/0x2d

Save and restore current->sched_rt_mutex around each testcase, matching the
existing PREEMPT_RT cleanup for task-local migration and RCU state.

Fixes: d14f9e930b90 ("locking/rtmutex: Use rt_mutex specific scheduler helpers")
Assisted-by: Codex:gpt-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Link: https://patch.msgid.link/20260523185123.17482-3-kmehltretter@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 lib/locking-selftest.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/lib/locking-selftest.c b/lib/locking-selftest.c
index cb806b628352b9..bfafe1204c7b6f 100644
--- a/lib/locking-selftest.c
+++ b/lib/locking-selftest.c
@@ -1433,6 +1433,7 @@ static void dotest(void (*testcase_fn)(void), int expected, int lockclass_mask)
 #ifdef CONFIG_PREEMPT_RT
 	int saved_mgd_count = current->migration_disabled;
 	int saved_rcu_count = current->rcu_read_lock_nesting;
+	int saved_sched_rt_mutex = current->sched_rt_mutex;
 #endif
 
 	WARN_ON(irqs_disabled());
@@ -1469,6 +1470,8 @@ static void dotest(void (*testcase_fn)(void), int expected, int lockclass_mask)
 	preempt_count_set(saved_preempt_count);
 
 #ifdef CONFIG_PREEMPT_RT
+	current->sched_rt_mutex = saved_sched_rt_mutex;
+
 	while (current->migration_disabled > saved_mgd_count)
 		migrate_enable();
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0449/2077] ext4: fix fast commit wait/wake bit mapping on 64-bit
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (447 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0448/2077] lockdep/selftests: Restore sched_rt_mutex " Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0450/2077] irqchip/exynos-combiner: Remove useless spinlock Greg Kroah-Hartman
                   ` (548 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko AI review, Li Chen,
	Baokun Li, Zhang Yi, Jan Kara, Theodore Tso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Li Chen <me@linux.beauty>

[ Upstream commit 8b3bc93fee6771775243665a0cf31857d6659775 ]

On 64-bit, ext4 dynamic inode states live in the upper half of i_flags,
and ext4_test_inode_state() applies the corresponding +32 offset.

The fast-commit wait and wake paths open-coded the wait key with the raw
EXT4_STATE_* value. Add small helpers for the state wait word and bit,
and use them for the FC_COMMITTING and FC_FLUSHING_DATA waits so the wait
key follows the same mapping as the state helpers.

Fixes: 857d32f26181 ("ext4: rework fast commit commit path")
Reported-by: Sashiko AI review <sashiko-bot@kernel.org>
Signed-off-by: Li Chen <chenl311@chinatelecom.cn>
Reviewed-by: Baokun Li <libaokun@linux.alibaba.com>
Reviewed-by: Zhang Yi <yi.zhang@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20260513085818.552432-1-me@linux.beauty
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ext4/ext4.h        | 20 +++++++++++++++++
 fs/ext4/fast_commit.c | 50 ++++++++++++++++---------------------------
 2 files changed, 38 insertions(+), 32 deletions(-)

diff --git a/fs/ext4/ext4.h b/fs/ext4/ext4.h
index 94283a991e5c4f..6569d1d575a01a 100644
--- a/fs/ext4/ext4.h
+++ b/fs/ext4/ext4.h
@@ -2000,6 +2000,8 @@ EXT4_INODE_BIT_FNS(flag, flags, 0)
 static inline int ext4_test_inode_state(struct inode *inode, int bit);
 static inline void ext4_set_inode_state(struct inode *inode, int bit);
 static inline void ext4_clear_inode_state(struct inode *inode, int bit);
+static inline unsigned long *ext4_inode_state_wait_word(struct inode *inode);
+static inline int ext4_inode_state_wait_bit(int bit);
 #if (BITS_PER_LONG < 64)
 EXT4_INODE_BIT_FNS(state, state_flags, 0)
 
@@ -2015,6 +2017,24 @@ static inline void ext4_clear_state_flags(struct ext4_inode_info *ei)
 	/* We depend on the fact that callers will set i_flags */
 }
 #endif
+
+static inline unsigned long *ext4_inode_state_wait_word(struct inode *inode)
+{
+#if (BITS_PER_LONG < 64)
+	return &EXT4_I(inode)->i_state_flags;
+#else
+	return &EXT4_I(inode)->i_flags;
+#endif
+}
+
+static inline int ext4_inode_state_wait_bit(int bit)
+{
+#if (BITS_PER_LONG < 64)
+	return bit;
+#else
+	return bit + 32;
+#endif
+}
 #else
 /* Assume that user mode programs are passing in an ext4fs superblock, not
  * a kernel struct super_block.  This will allow us to call the feature-test
diff --git a/fs/ext4/fast_commit.c b/fs/ext4/fast_commit.c
index b3c22636251dde..1775bce9649a93 100644
--- a/fs/ext4/fast_commit.c
+++ b/fs/ext4/fast_commit.c
@@ -239,6 +239,8 @@ void ext4_fc_del(struct inode *inode)
 	struct ext4_inode_info *ei = EXT4_I(inode);
 	struct ext4_fc_dentry_update *fc_dentry;
 	wait_queue_head_t *wq;
+	unsigned long *wait_word = ext4_inode_state_wait_word(inode);
+	int wait_bit = ext4_inode_state_wait_bit(EXT4_STATE_FC_FLUSHING_DATA);
 	int alloc_ctx;
 
 	if (ext4_fc_disabled(inode->i_sb))
@@ -268,17 +270,9 @@ void ext4_fc_del(struct inode *inode)
 	WARN_ON(ext4_test_inode_state(inode, EXT4_STATE_FC_COMMITTING)
 		&& !ext4_test_mount_flag(inode->i_sb, EXT4_MF_FC_INELIGIBLE));
 	while (ext4_test_inode_state(inode, EXT4_STATE_FC_FLUSHING_DATA)) {
-#if (BITS_PER_LONG < 64)
-		DEFINE_WAIT_BIT(wait, &ei->i_state_flags,
-				EXT4_STATE_FC_FLUSHING_DATA);
-		wq = bit_waitqueue(&ei->i_state_flags,
-				   EXT4_STATE_FC_FLUSHING_DATA);
-#else
-		DEFINE_WAIT_BIT(wait, &ei->i_flags,
-				EXT4_STATE_FC_FLUSHING_DATA);
-		wq = bit_waitqueue(&ei->i_flags,
-				   EXT4_STATE_FC_FLUSHING_DATA);
-#endif
+		DEFINE_WAIT_BIT(wait, wait_word, wait_bit);
+
+		wq = bit_waitqueue(wait_word, wait_bit);
 		prepare_to_wait(wq, &wait.wq_entry, TASK_UNINTERRUPTIBLE);
 		if (ext4_test_inode_state(inode, EXT4_STATE_FC_FLUSHING_DATA)) {
 			ext4_fc_unlock(inode->i_sb, alloc_ctx);
@@ -542,6 +536,8 @@ void ext4_fc_track_inode(handle_t *handle, struct inode *inode)
 {
 	struct ext4_inode_info *ei = EXT4_I(inode);
 	wait_queue_head_t *wq;
+	unsigned long *wait_word = ext4_inode_state_wait_word(inode);
+	int wait_bit = ext4_inode_state_wait_bit(EXT4_STATE_FC_COMMITTING);
 	int ret;
 
 	if (S_ISDIR(inode->i_mode))
@@ -564,17 +560,9 @@ void ext4_fc_track_inode(handle_t *handle, struct inode *inode)
 	lockdep_assert_not_held(&ei->i_data_sem);
 
 	while (ext4_test_inode_state(inode, EXT4_STATE_FC_COMMITTING)) {
-#if (BITS_PER_LONG < 64)
-		DEFINE_WAIT_BIT(wait, &ei->i_state_flags,
-				EXT4_STATE_FC_COMMITTING);
-		wq = bit_waitqueue(&ei->i_state_flags,
-				   EXT4_STATE_FC_COMMITTING);
-#else
-		DEFINE_WAIT_BIT(wait, &ei->i_flags,
-				EXT4_STATE_FC_COMMITTING);
-		wq = bit_waitqueue(&ei->i_flags,
-				   EXT4_STATE_FC_COMMITTING);
-#endif
+		DEFINE_WAIT_BIT(wait, wait_word, wait_bit);
+
+		wq = bit_waitqueue(wait_word, wait_bit);
 		prepare_to_wait(wq, &wait.wq_entry, TASK_UNINTERRUPTIBLE);
 		if (ext4_test_inode_state(inode, EXT4_STATE_FC_COMMITTING))
 			schedule();
@@ -1034,6 +1022,8 @@ static int ext4_fc_perform_commit(journal_t *journal)
 	int ret = 0;
 	u32 crc = 0;
 	int alloc_ctx;
+	int flushing_wait_bit =
+		ext4_inode_state_wait_bit(EXT4_STATE_FC_FLUSHING_DATA);
 
 	/*
 	 * Step 1: Mark all inodes on s_fc_q[MAIN] with
@@ -1059,11 +1049,8 @@ static int ext4_fc_perform_commit(journal_t *journal)
 	list_for_each_entry(iter, &sbi->s_fc_q[FC_Q_MAIN], i_fc_list) {
 		ext4_clear_inode_state(&iter->vfs_inode,
 				       EXT4_STATE_FC_FLUSHING_DATA);
-#if (BITS_PER_LONG < 64)
-		wake_up_bit(&iter->i_state_flags, EXT4_STATE_FC_FLUSHING_DATA);
-#else
-		wake_up_bit(&iter->i_flags, EXT4_STATE_FC_FLUSHING_DATA);
-#endif
+		wake_up_bit(ext4_inode_state_wait_word(&iter->vfs_inode),
+			    flushing_wait_bit);
 	}
 
 	/*
@@ -1279,6 +1266,8 @@ static void ext4_fc_cleanup(journal_t *journal, int full, tid_t tid)
 	struct ext4_inode_info *ei;
 	struct ext4_fc_dentry_update *fc_dentry;
 	int alloc_ctx;
+	int committing_wait_bit =
+		ext4_inode_state_wait_bit(EXT4_STATE_FC_COMMITTING);
 
 	if (full && sbi->s_fc_bh)
 		sbi->s_fc_bh = NULL;
@@ -1315,11 +1304,8 @@ static void ext4_fc_cleanup(journal_t *journal, int full, tid_t tid)
 		 * barrier in prepare_to_wait() in ext4_fc_track_inode().
 		 */
 		smp_mb();
-#if (BITS_PER_LONG < 64)
-		wake_up_bit(&ei->i_state_flags, EXT4_STATE_FC_COMMITTING);
-#else
-		wake_up_bit(&ei->i_flags, EXT4_STATE_FC_COMMITTING);
-#endif
+		wake_up_bit(ext4_inode_state_wait_word(&ei->vfs_inode),
+			    committing_wait_bit);
 	}
 
 	while (!list_empty(&sbi->s_fc_dentry_q[FC_Q_MAIN])) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0450/2077] irqchip/exynos-combiner: Remove useless spinlock
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (448 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0449/2077] ext4: fix fast commit wait/wake bit mapping on 64-bit Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0451/2077] drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump Greg Kroah-Hartman
                   ` (547 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Gleixner,
	Sebastian Andrzej Siewior, Marek Szyprowski, Peter Griffin,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marek Szyprowski <m.szyprowski@samsung.com>

[ Upstream commit 6fe450074626eaab3def4b3e8c1819d46d2d682c ]

irq_controller_lock doesn't protect anything, it is a leftover from early
development or copy/paste. Remove it completely.

Fixes: 96031b31a4b3 ("irqchip/exynos-combiner: Switch to raw_spinlock")
Suggested-by: Thomas Gleixner <tglx@kernel.org>
Suggested-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Reviewed-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Reviewed-by: Peter Griffin <peter.griffin@linaro.org>
Link: https://lore.kernel.org/all/20260521090453.bbUZ00tS@linutronix.de
Link: https://patch.msgid.link/20260522061012.2687122-1-m.szyprowski@samsung.com/
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/irqchip/exynos-combiner.c | 4 ----
 1 file changed, 4 deletions(-)

diff --git a/drivers/irqchip/exynos-combiner.c b/drivers/irqchip/exynos-combiner.c
index 03cafcc5c8355d..d9d408cb4711e8 100644
--- a/drivers/irqchip/exynos-combiner.c
+++ b/drivers/irqchip/exynos-combiner.c
@@ -24,8 +24,6 @@
 
 #define IRQ_IN_COMBINER		8
 
-static DEFINE_RAW_SPINLOCK(irq_controller_lock);
-
 struct combiner_chip_data {
 	unsigned int hwirq_offset;
 	unsigned int irq_mask;
@@ -72,9 +70,7 @@ static void combiner_handle_cascade_irq(struct irq_desc *desc)
 
 	chained_irq_enter(chip, desc);
 
-	raw_spin_lock(&irq_controller_lock);
 	status = readl_relaxed(chip_data->base + COMBINER_INT_STATUS);
-	raw_spin_unlock(&irq_controller_lock);
 	status &= chip_data->irq_mask;
 
 	if (status == 0)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0451/2077] drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (449 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0450/2077] irqchip/exynos-combiner: Remove useless spinlock Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0452/2077] drm/amd/pm: Add empty string validation to sysfs store functions Greg Kroah-Hartman
                   ` (546 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Pierre-Eric Pelloux-Prayer,
	Christian König, Alex Deucher, Vitaly Prosyak, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vitaly Prosyak <vitaly.prosyak@amd.com>

[ Upstream commit 08ac3a7879d300302a1927ce2038629539a37f8b ]

The ring content dump in amdgpu_coredump() uses two separate loops over
adev->rings[]: the first counts rings with unsignalled fences to size
the allocation, and the second copies ring data into the allocated
buffers.

Both loops use the same condition to skip rings:

    atomic_read(&ring->fence_drv.last_seq) == ring->fence_drv.sync_seq

Because last_seq is an atomic that is updated concurrently by the fence
signalling path, additional rings may appear unsignalled in the second
loop that were signalled during the first. When this happens, idx
exceeds the allocated ring_count and the store to coredump->rings[idx]
writes past the end of the kcalloc-ed buffer.

This was found during IGT stressful test amd_queue_reset which
triggers random GPU resets. The OVERSIZE subtest
(CMD_STREAM_EXEC_INVALID_PACKET_LENGTH_OVERSIZE on GFX ring) provokes
a ring timeout and subsequent coredump, which hits the race between
the counting and copying loops. The failure is non-deterministic and
depends on fence signalling timing during the reset.

KASAN log:

  BUG: KASAN: slab-out-of-bounds in amdgpu_coredump+0x1274/0x12f0 [amdgpu]
  Write of size 4 at addr ffff888106154258 by task kworker/u128:5/23625
  CPU: 16 UID: 0 PID: 23625 Comm: kworker/u128:5 Not tainted 6.19.0+ #35
  Workqueue: amdgpu-reset-dev drm_sched_job_timedout [gpu_sched]
  Call Trace:
   <TASK>
   dump_stack_lvl+0xa5/0x110
   print_report+0xd1/0x660
   kasan_report+0xf3/0x130
   __asan_report_store4_noabort+0x17/0x30
   amdgpu_coredump+0x1274/0x12f0 [amdgpu]
   amdgpu_job_timedout+0xef0/0x16c0 [amdgpu]
   drm_sched_job_timedout+0x194/0x5c0 [gpu_sched]
   process_one_work+0x84b/0x1990
   worker_thread+0x6b8/0x11b0
   </TASK>

  Allocated by task 23625:
   kasan_save_stack+0x39/0x70
   __kasan_kmalloc+0xc3/0xd0
   __kmalloc_noprof+0x2ec/0x910
   amdgpu_coredump+0x5c5/0x12f0 [amdgpu]
   amdgpu_job_timedout+0xef0/0x16c0 [amdgpu]

  The buggy address belongs to the object at ffff888106154200
   which belongs to the cache kmalloc-rnd-09-96 of size 96
  The buggy address is located 16 bytes to the right of
   allocated 72-byte region [ffff888106154200, ffff888106154248)

72 bytes = 3 * sizeof(struct amdgpu_coredump_ring), so ring_count was 3
but idx reached 3+, writing ring_index (at struct offset 16) 16 bytes
past the allocation.

Fix by adding an idx < ring_count guard to the copy loop so it cannot
exceed the allocated count even when the fence state changes between
the two passes.

Fixes: eea85914d15b (drm/amdgpu: save ring content before resetting the device)
Cc: Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>
Cc: Christian König <christian.koenig@amd.com>
Cc: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Vitaly Prosyak <vitaly.prosyak@amd.com>
Reviewed-by: Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c
index d386bc775d03c6..3d5a2abf27c634 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c
@@ -553,7 +553,7 @@ void amdgpu_coredump(struct amdgpu_device *adev, bool skip_vram_check,
 	coredump->rings_dw = kzalloc(total_ring_size, GFP_NOWAIT);
 	coredump->rings = kcalloc(ring_count, sizeof(struct amdgpu_coredump_ring), GFP_NOWAIT);
 	if (coredump->rings && coredump->rings_dw) {
-		for (i = 0, off = 0, idx = 0; i < adev->num_rings; i++) {
+		for (i = 0, off = 0, idx = 0; i < adev->num_rings && idx < ring_count; i++) {
 			ring = adev->rings[i];
 
 			if (atomic_read(&ring->fence_drv.last_seq) == ring->fence_drv.sync_seq &&
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0452/2077] drm/amd/pm: Add empty string validation to sysfs store functions
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (450 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0451/2077] drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0453/2077] drm/amdgpu: set sub_block_index for mca ras sub-blocks Greg Kroah-Hartman
                   ` (545 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian König, Alex Deucher,
	Jesse Zhang, Vitaly Prosyak, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vitaly Prosyak <vitaly.prosyak@amd.com>

[ Upstream commit c872fc05380c4eb2761ab289ce6a215c9bfa9576 ]

Discovery: Fuzzing for secure supply chain requirements
Tool: amd_fuzzing_sysfs (IGT test)

The AMDGPU power management sysfs store functions accept whitespace-only
strings when they should reject them with -EINVAL. This was discovered via
systematic fuzzing of sysfs interfaces crossing the user/kernel trust
boundary.

Affected functions:
- amdgpu_set_power_dpm_force_performance_level (power_dpm_force_performance_level)
- amdgpu_set_power_dpm_state (power_dpm_state)
- amdgpu_set_pp_power_profile_mode (pp_power_profile_mode)
- amdgpu_read_mask (used by pp_dpm_sclk/mclk/fclk/socclk/pcie)
- amdgpu_set_pp_features (pp_features)

Impact:
- Whitespace-only writes (e.g., "\n", " ") can cause unexpected behavior
- Better input validation at user/kernel trust boundary
- Defense-in-depth improvement

Root Cause:
The sysfs_streq() function matches whitespace-only strings against empty
string, allowing invalid input to be processed.

Fix:
Add explicit validation at the start of each affected store function:

    if (count == 0 || sysfs_streq(buf, ""))
        return -EINVAL;

This rejects whitespace-only inputs before they are processed. Note that
write() calls with count=0 (truly empty strings) are handled by the VFS
layer before reaching the sysfs .store() callback - the VFS returns 0
(success) without calling the kernel function. This is POSIX-compliant
behavior and cannot be changed at the kernel driver level.

What This Patch Fixes:
- Whitespace-only strings: "\n", " ", "  ", etc. are now rejected
- Defense-in-depth: Explicit validation at trust boundary
- Code clarity: Intent to reject invalid input is explicit

What This Patch Cannot Fix:
- write(fd, "", 0) returning success - this is VFS layer behavior
- Fuzzer tests for empty strings (count=0) will still report "accepted"
  because the VFS handles this before the kernel callback

Test Results After Fix:
- Whitespace strings ("\n", " ") now properly rejected
- Empty string tests (count=0) still show as "accepted" due to VFS behavior
- Overall improvement in input validation robustness
- No impact on valid inputs

This is a defense-in-depth improvement that hardens input validation
even though VFS layer behavior prevents catching all edge cases.

Tested: amd_fuzzing_sysfs IGT test

Cc: Christian König <christian.koenig@amd.com>
Cc: Alex Deucher <alexander.deucher@amd.com>
Cc: Jesse Zhang <jesse.zhang@amd.com>
Signed-off-by: Vitaly Prosyak <vitaly.prosyak@amd.com>
Acked-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/amd/pm/amdgpu_pm.c | 20 ++++++++++++++++++++
 1 file changed, 20 insertions(+)

diff --git a/drivers/gpu/drm/amd/pm/amdgpu_pm.c b/drivers/gpu/drm/amd/pm/amdgpu_pm.c
index 024bfdb7c1571c..952391aecf2d32 100644
--- a/drivers/gpu/drm/amd/pm/amdgpu_pm.c
+++ b/drivers/gpu/drm/amd/pm/amdgpu_pm.c
@@ -244,6 +244,10 @@ static ssize_t amdgpu_set_power_dpm_state(struct device *dev,
 	enum amd_pm_state_type  state;
 	int ret;
 
+	/* Reject empty/whitespace strings - fuzzing found this is not validated */
+	if (count == 0 || sysfs_streq(buf, ""))
+		return -EINVAL;
+
 	if (sysfs_streq(buf, "battery"))
 		state = POWER_STATE_TYPE_BATTERY;
 	else if (sysfs_streq(buf, "balanced"))
@@ -364,6 +368,10 @@ static ssize_t amdgpu_set_power_dpm_force_performance_level(struct device *dev,
 	enum amd_dpm_forced_level level;
 	int ret = 0;
 
+	/* Reject empty/whitespace strings - fuzzing found this is not validated */
+	if (count == 0 || sysfs_streq(buf, ""))
+		return -EINVAL;
+
 	if (sysfs_streq(buf, "low"))
 		level = AMD_DPM_FORCED_LEVEL_LOW;
 	else if (sysfs_streq(buf, "high"))
@@ -902,6 +910,10 @@ static ssize_t amdgpu_set_pp_features(struct device *dev,
 	uint64_t featuremask;
 	int ret;
 
+	/* Reject empty/whitespace strings - fuzzing found kstrtou64 accepts "" as 0 */
+	if (count == 0 || sysfs_streq(buf, ""))
+		return -EINVAL;
+
 	ret = kstrtou64(buf, 0, &featuremask);
 	if (ret)
 		return -EINVAL;
@@ -1027,6 +1039,10 @@ static ssize_t amdgpu_read_mask(const char *buf, size_t count, uint32_t *mask)
 
 	*mask = 0;
 
+	/* Reject empty/whitespace strings - fuzzing found this is not validated */
+	if (count == 0 || sysfs_streq(buf, ""))
+		return -EINVAL;
+
 	bytes = min(count, sizeof(buf_cpy) - 1);
 	memcpy(buf_cpy, buf, bytes);
 	buf_cpy[bytes] = '\0';
@@ -1378,6 +1394,10 @@ static ssize_t amdgpu_set_pp_power_profile_mode(struct device *dev,
 	long int profile_mode = 0;
 	const char delimiter[3] = {' ', '\n', '\0'};
 
+	/* Reject empty/whitespace strings - fuzzing found this is not validated */
+	if (count == 0 || sysfs_streq(buf, ""))
+		return -EINVAL;
+
 	tmp[0] = *(buf);
 	tmp[1] = '\0';
 	ret = kstrtol(tmp, 0, &profile_mode);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0453/2077] drm/amdgpu: set sub_block_index for mca ras sub-blocks
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (451 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0452/2077] drm/amd/pm: Add empty string validation to sysfs store functions Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0454/2077] accel/amdxdna: Return errors for failed debug BO commands Greg Kroah-Hartman
                   ` (544 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yunxiang Li, Hawking Zhang,
	Alex Deucher, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yunxiang Li <Yunxiang.Li@amd.com>

[ Upstream commit baa286df5fb366e4aee5b747443dfc7194fdaa59 ]

The mca ras sub-blocks (mp0, mp1, mpio) all share the
AMDGPU_RAS_BLOCK__MCA block id and are distinguished only by
sub_block_index. The ras manager object for an mca block is selected
with:

	con->objs[AMDGPU_RAS_BLOCK__LAST + head->sub_block_index]

Since the rework in commit 7f544c5488cf ("drm/amdgpu: Rework mca ras
sw_init") moved the ras_comm setup into amdgpu_mca_mp*_ras_sw_init() but
left sub_block_index unset, mp0/mp1/mpio all default to index 0 and
collide on the same object slot. mp0 grabs the slot and creates its
sysfs node first; mp1 (and mpio) then find the slot already in use, so
amdgpu_ras_block_late_init() -> amdgpu_ras_sysfs_create() returns
-EINVAL:

  amdgpu: mca.mp1 failed to execute ras_block_late_init_default! ret:-22
  amdgpu: amdgpu_ras_late_init failed -22
  amdgpu: amdgpu_device_ip_late_init failed
  amdgpu: Fatal error during GPU init

The error is currently masked because amdgpu_ras_late_init() does not
check the return value of amdgpu_ras_block_late_init_default(), but it
already leaves mp1/mpio without their sysfs nodes and becomes a fatal
init failure as soon as that return value is honored.

Restore the per-sub-block sub_block_index assignment so each mca
sub-block maps to its own object slot.

Fixes: 7f544c5488cf ("drm/amdgpu: Rework mca ras sw_init")
Signed-off-by: Yunxiang Li <Yunxiang.Li@amd.com>
Reviewed-by: Hawking Zhang <Hawking.Zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_mca.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_mca.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_mca.c
index 823ba17e32af4d..cc6d1a4e4c3afd 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_mca.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_mca.c
@@ -99,6 +99,7 @@ int amdgpu_mca_mp0_ras_sw_init(struct amdgpu_device *adev)
 
 	strcpy(ras->ras_block.ras_comm.name, "mca.mp0");
 	ras->ras_block.ras_comm.block = AMDGPU_RAS_BLOCK__MCA;
+	ras->ras_block.ras_comm.sub_block_index = AMDGPU_RAS_MCA_BLOCK__MP0;
 	ras->ras_block.ras_comm.type = AMDGPU_RAS_ERROR__MULTI_UNCORRECTABLE;
 	adev->mca.mp0.ras_if = &ras->ras_block.ras_comm;
 
@@ -123,6 +124,7 @@ int amdgpu_mca_mp1_ras_sw_init(struct amdgpu_device *adev)
 
 	strcpy(ras->ras_block.ras_comm.name, "mca.mp1");
 	ras->ras_block.ras_comm.block = AMDGPU_RAS_BLOCK__MCA;
+	ras->ras_block.ras_comm.sub_block_index = AMDGPU_RAS_MCA_BLOCK__MP1;
 	ras->ras_block.ras_comm.type = AMDGPU_RAS_ERROR__MULTI_UNCORRECTABLE;
 	adev->mca.mp1.ras_if = &ras->ras_block.ras_comm;
 
@@ -147,6 +149,7 @@ int amdgpu_mca_mpio_ras_sw_init(struct amdgpu_device *adev)
 
 	strcpy(ras->ras_block.ras_comm.name, "mca.mpio");
 	ras->ras_block.ras_comm.block = AMDGPU_RAS_BLOCK__MCA;
+	ras->ras_block.ras_comm.sub_block_index = AMDGPU_RAS_MCA_BLOCK__MPIO;
 	ras->ras_block.ras_comm.type = AMDGPU_RAS_ERROR__MULTI_UNCORRECTABLE;
 	adev->mca.mpio.ras_if = &ras->ras_block.ras_comm;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0454/2077] accel/amdxdna: Return errors for failed debug BO commands
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (452 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0453/2077] drm/amdgpu: set sub_block_index for mca ras sub-blocks Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0455/2077] bpftool: Use libbpf error code for flow dissector query Greg Kroah-Hartman
                   ` (543 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mario Limonciello (AMD), Lizhi Hou,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lizhi Hou <lizhi.hou@amd.com>

[ Upstream commit 62c1671f6454ceaa80e9ceff63f821aa36f35154 ]

The config and sync debug BO commands currently may report success even
when the operation fails.

Capture the firmware return status and propagate the corresponding error
to userspace.

Fixes: 7ea046838021 ("accel/amdxdna: Support firmware debug buffer")
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260529162122.1976376-1-lizhi.hou@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/accel/amdxdna/aie2_ctx.c | 13 +++++--------
 1 file changed, 5 insertions(+), 8 deletions(-)

diff --git a/drivers/accel/amdxdna/aie2_ctx.c b/drivers/accel/amdxdna/aie2_ctx.c
index d719000c453252..93535806e72a1b 100644
--- a/drivers/accel/amdxdna/aie2_ctx.c
+++ b/drivers/accel/amdxdna/aie2_ctx.c
@@ -270,17 +270,13 @@ aie2_sched_drvcmd_resp_handler(void *handle, void __iomem *data, size_t size)
 	struct amdxdna_sched_job *job = handle;
 	int ret = 0;
 
-	if (unlikely(!data))
-		goto out;
-
-	if (unlikely(size != sizeof(u32))) {
+	if (unlikely(!data || size != sizeof(u32))) {
+		job->drv_cmd->result = U32_MAX;
 		ret = -EINVAL;
-		goto out;
+	} else {
+		job->drv_cmd->result = readl(data);
 	}
 
-	job->drv_cmd->result = readl(data);
-
-out:
 	aie2_sched_notify(job);
 	return ret;
 }
@@ -894,6 +890,7 @@ static int aie2_hwctx_cfg_debug_bo(struct amdxdna_hwctx *hwctx, u32 bo_hdl,
 	aie2_cmd_wait(hwctx, seq);
 	if (cmd.result) {
 		XDNA_ERR(xdna, "Response failure 0x%x", cmd.result);
+		ret = -EINVAL;
 		goto put_obj;
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0455/2077] bpftool: Use libbpf error code for flow dissector query
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (453 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0454/2077] accel/amdxdna: Return errors for failed debug BO commands Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0456/2077] vhost: fix vhost_get_avail_idx for a non empty ring Greg Kroah-Hartman
                   ` (542 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Woojin Ji, Andrii Nakryiko,
	Leon Hwang, Yonghong Song, Quentin Monnet, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Woojin Ji <random6.xyz@gmail.com>

[ Upstream commit 8a7f2bff2165e53595d1e91c160b340f978c0ab7 ]

bpf_prog_query() returns a negative errno on failure.
query_flow_dissector() currently closes the namespace fd and then reads
errno to decide whether -EINVAL means that the running kernel does not
support flow dissector queries.

That errno check controls behavior, not just diagnostics: -EINVAL is
handled as a non-fatal old-kernel case, while any other error makes bpftool
net fail.

The namespace fd is opened read-only, so close() is not expected to
commonly fail in normal use. Still, the BPF_PROG_QUERY error is already
available in err, and reading errno after an intervening close() is
fragile. If close() does change errno, the compatibility branch may be
based on close()'s error instead of the BPF_PROG_QUERY result.

This was reproduced with an LD_PRELOAD fault injector that forced
BPF_PROG_QUERY for BPF_FLOW_DISSECTOR to fail with EINVAL and then
forced close() on the netns fd to fail with EIO. The unpatched bpftool
reported "can't query prog: Input/output error". With this change, the
same injected failure is handled as the intended non-fatal EINVAL
compatibility case.

Use the libbpf-returned error code instead. Keep the existing errno reset
in the non-fatal path to preserve batch mode behavior. The success path
is unchanged.

Fixes: 7f0c57fec80f ("bpftool: show flow_dissector attachment status")
Signed-off-by: Woojin Ji <random6.xyz@gmail.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Acked-by: Leon Hwang <leon.hwang@linux.dev>
Acked-by: Yonghong Song <yonghong.song@linux.dev>
Acked-by: Quentin Monnet <qmo@kernel.org>
Link: https://lore.kernel.org/bpf/20260603003339.33791-1-random6.xyz@gmail.com

Assisted-by: ChatGPT:gpt-5.5
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/bpf/bpftool/net.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/tools/bpf/bpftool/net.c b/tools/bpf/bpftool/net.c
index 974189da8a916a..dba28755d28490 100644
--- a/tools/bpf/bpftool/net.c
+++ b/tools/bpf/bpftool/net.c
@@ -603,14 +603,14 @@ static int query_flow_dissector(struct bpf_attach_info *attach_info)
 			     &attach_flags, prog_ids, &prog_cnt);
 	close(fd);
 	if (err) {
-		if (errno == EINVAL) {
+		if (err == -EINVAL) {
 			/* Older kernel's don't support querying
 			 * flow dissector programs.
 			 */
 			errno = 0;
 			return 0;
 		}
-		p_err("can't query prog: %s", strerror(errno));
+		p_err("can't query prog: %s", strerror(-err));
 		return -1;
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0456/2077] vhost: fix vhost_get_avail_idx for a non empty ring
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (454 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0455/2077] bpftool: Use libbpf error code for flow dissector query Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0457/2077] iommu/vt-d: Fix RB-tree corruption in probe error path Greg Kroah-Hartman
                   ` (541 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, ShuangYu, Stefan Hajnoczi,
	Jason Wang, Stefano Garzarella, Michael S. Tsirkin, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael S. Tsirkin <mst@redhat.com>

[ Upstream commit 09861858a68342f851f71c669ac0f69865c32151 ]

vhost_get_avail_idx is supposed to report whether it has updated
vq->avail_idx. Instead, it returns whether all entries have been
consumed, which is usually the same. But not always - in
drivers/vhost/net.c and when mergeable buffers have been enabled, the
driver checks whether the combined entries are big enough to store an
incoming packet. If not, the driver re-enables notifications with
available entries still in the ring. The incorrect return value from
vhost_get_avail_idx propagates through vhost_enable_notify and causes
the host to livelock if the guest is not making progress, as vhost will
immediately disable notifications and retry using the available entries.

This goes back to commit d3bb267bbdcb ("vhost: cache avail index in
vhost_enable_notify()") which changed vhost_enable_notify() to compare
the freshly read avail index against vq->last_avail_idx instead of the
previously cached vq->avail_idx. Commit 7ad472397667 ("vhost: move
smp_rmb() into vhost_get_avail_idx()") then carried over the same
comparison when refactoring vhost_enable_notify() to call the unified
vhost_get_avail_idx().

The obvious fix is to make vhost_get_avail_idx do what the comment
says it does and report whether new entries have been added.

Reported-by: ShuangYu <shuangyu@yunyoo.cc>
Fixes: d3bb267bbdcb ("vhost: cache avail index in vhost_enable_notify()")
Cc: Stefan Hajnoczi <stefanha@redhat.com>
Acked-by: Jason Wang <jasowang@redhat.com>
Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-Id: <559b04ae6ce52973c535dc47e461638b7f4c3d63.1772441455.git.mst@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/vhost/vhost.c | 11 +++++++----
 1 file changed, 7 insertions(+), 4 deletions(-)

diff --git a/drivers/vhost/vhost.c b/drivers/vhost/vhost.c
index 2f2c45d2088320..db329a6f614589 100644
--- a/drivers/vhost/vhost.c
+++ b/drivers/vhost/vhost.c
@@ -1522,6 +1522,7 @@ static void vhost_dev_unlock_vqs(struct vhost_dev *d)
 static inline int vhost_get_avail_idx(struct vhost_virtqueue *vq)
 {
 	__virtio16 idx;
+	u16 avail_idx;
 	int r;
 
 	r = vhost_get_avail(vq, idx, &vq->avail->idx);
@@ -1532,17 +1533,19 @@ static inline int vhost_get_avail_idx(struct vhost_virtqueue *vq)
 	}
 
 	/* Check it isn't doing very strange thing with available indexes */
-	vq->avail_idx = vhost16_to_cpu(vq, idx);
-	if (unlikely((u16)(vq->avail_idx - vq->last_avail_idx) > vq->num)) {
+	avail_idx = vhost16_to_cpu(vq, idx);
+	if (unlikely((u16)(avail_idx - vq->last_avail_idx) > vq->num)) {
 		vq_err(vq, "Invalid available index change from %u to %u",
-		       vq->last_avail_idx, vq->avail_idx);
+		       vq->last_avail_idx, avail_idx);
 		return -EINVAL;
 	}
 
 	/* We're done if there is nothing new */
-	if (vq->avail_idx == vq->last_avail_idx)
+	if (avail_idx == vq->avail_idx)
 		return 0;
 
+	vq->avail_idx = avail_idx;
+
 	/*
 	 * We updated vq->avail_idx so we need a memory barrier between
 	 * the index read above and the caller reading avail ring entries.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0457/2077] iommu/vt-d: Fix RB-tree corruption in probe error path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (455 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0456/2077] vhost: fix vhost_get_avail_idx for a non empty ring Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0458/2077] mm: preserve PG_dropbehind flag during folio split Greg Kroah-Hartman
                   ` (540 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Baolu Lu,
	Pranjal Shrivastava, Joerg Roedel, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pranjal Shrivastava <praan@google.com>

[ Upstream commit 43bd9e6d5513cb1edbafdeef146a1edc3aaced56 ]

The info->node RB-tree member is zero-initialized via kzalloc. If
a device does not support ATS, the device_rbtree_insert() call is
skipped. If a subsequent probe step fails, the error path jumps to
device_rbtree_remove(), which misinterprets the zeroed node as
a tree root and corrupts the device RB-tree.

Fix this by explicitly initializing the RB-node as empty using
RB_CLEAR_NODE() during initialization and guarding the removal with
RB_EMPTY_NODE().

Fixes: 4f1492efb495 ("iommu/vt-d: Revert ATS timing change to fix boot failure")
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/all/20260525205628.CD4431F000E9@smtp.kernel.org/
Suggested-by: Baolu Lu <baolu.lu@linux.intel.com>
Signed-off-by: Pranjal Shrivastava <praan@google.com>
Link: https://lore.kernel.org/r/20260531170254.60493-2-praan@google.com
Signed-off-by: Lu Baolu <baolu.lu@linux.intel.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iommu/intel/iommu.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/iommu/intel/iommu.c b/drivers/iommu/intel/iommu.c
index 4d0e65bc131d77..849d06dfe1aecf 100644
--- a/drivers/iommu/intel/iommu.c
+++ b/drivers/iommu/intel/iommu.c
@@ -157,7 +157,10 @@ static void device_rbtree_remove(struct device_domain_info *info)
 	unsigned long flags;
 
 	spin_lock_irqsave(&iommu->device_rbtree_lock, flags);
-	rb_erase(&info->node, &iommu->device_rbtree);
+	if (!RB_EMPTY_NODE(&info->node)) {
+		rb_erase(&info->node, &iommu->device_rbtree);
+		RB_CLEAR_NODE(&info->node);
+	}
 	spin_unlock_irqrestore(&iommu->device_rbtree_lock, flags);
 }
 
@@ -3254,6 +3257,7 @@ static struct iommu_device *intel_iommu_probe_device(struct device *dev)
 
 	info->dev = dev;
 	info->iommu = iommu;
+	RB_CLEAR_NODE(&info->node);
 	if (dev_is_pci(dev)) {
 		if (ecap_dev_iotlb_support(iommu->ecap) &&
 		    pci_ats_supported(pdev) &&
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0458/2077] mm: preserve PG_dropbehind flag during folio split
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (456 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0457/2077] iommu/vt-d: Fix RB-tree corruption in probe error path Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0459/2077] eventpoll: rename attach_epitem() to ep_attach_file() Greg Kroah-Hartman
                   ` (539 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jeff Layton, David Hildenbrand (Arm),
	Jan Kara, Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jeff Layton <jlayton@kernel.org>

[ Upstream commit 0ad186cf167fdbeb6b29a8005c71973781036bd3 ]

__split_folio_to_order() copies page flags from the original folio to
newly created sub-folios using an explicit allowlist, but PG_dropbehind
is not included. When a large folio with PG_dropbehind set is split,
only the head sub-folio retains the flag; all tail sub-folios silently
lose it and will not be reclaimed eagerly after writeback completes.

Add PG_dropbehind to the flag copy mask so that the drop-behind hint
is preserved across folio splits.

Fixes: a323281cdfec ("mm: add PG_dropbehind folio flag")
Assisted-by: Claude:claude-opus-4-6
Signed-off-by: Jeff Layton <jlayton@kernel.org>
Link: https://patch.msgid.link/20260511-dontcache-v7-1-2848ddce8090@kernel.org
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 mm/huge_memory.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/mm/huge_memory.c b/mm/huge_memory.c
index b118bcd392cb35..d29e85495091d4 100644
--- a/mm/huge_memory.c
+++ b/mm/huge_memory.c
@@ -3644,6 +3644,7 @@ static void __split_folio_to_order(struct folio *folio, int old_order,
 				 (1L << PG_arch_3) |
 #endif
 				 (1L << PG_dirty) |
+				 (1L << PG_dropbehind) |
 				 LRU_GEN_MASK | LRU_REFS_MASK));
 
 		if (handle_hwpoison &&
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0459/2077] eventpoll: rename attach_epitem() to ep_attach_file()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (457 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0458/2077] mm: preserve PG_dropbehind flag during folio split Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0460/2077] eventpoll: split ep_insert() into alloc + register stages Greg Kroah-Hartman
                   ` (538 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Brauner (Amutable),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Brauner <brauner@kernel.org>

[ Upstream commit 6a3f1a494bc91d7976cf0d2b200bb3f1a22eef64 ]

ep_remove_file() tears down the f_ep linkage that attach_epitem()
establishes, so the pair should look like one. Rename to
ep_attach_file() for the "ep_*" + subject symmetry and to match the
naming used elsewhere in the file (ep_insert, ep_modify, ep_remove,
ep_remove_file, ep_remove_epi, ep_unregister_pollwait).

Pure rename; no functional change.

Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Link: https://patch.msgid.link/20260424-work-epoll-rework-v1-8-249ed00a20f3@kernel.org
Signed-off-by: Christian Brauner <brauner@kernel.org>
Stable-dep-of: 0c4aefe3c2d0 ("eventpoll: Fix epoll_wait() report false negative")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/eventpoll.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/eventpoll.c b/fs/eventpoll.c
index a3090b446af102..556049d0da3fbb 100644
--- a/fs/eventpoll.c
+++ b/fs/eventpoll.c
@@ -1526,7 +1526,7 @@ static noinline void ep_destroy_wakeup_source(struct epitem *epi)
 	wakeup_source_unregister(ws);
 }
 
-static int attach_epitem(struct file *file, struct epitem *epi)
+static int ep_attach_file(struct file *file, struct epitem *epi)
 {
 	struct epitems_head *to_free = NULL;
 	struct hlist_head *head = NULL;
@@ -1597,7 +1597,7 @@ static int ep_insert(struct eventpoll *ep, const struct epoll_event *event,
 	if (tep)
 		mutex_lock_nested(&tep->mtx, 1);
 	/* Add the current item to the list of active epoll hook for this file */
-	if (unlikely(attach_epitem(tfile, epi) < 0)) {
+	if (unlikely(ep_attach_file(tfile, epi) < 0)) {
 		if (tep)
 			mutex_unlock(&tep->mtx);
 		kmem_cache_free(epi_cache, epi);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0460/2077] eventpoll: split ep_insert() into alloc + register stages
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (458 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0459/2077] eventpoll: rename attach_epitem() to ep_attach_file() Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0461/2077] eventpoll: extract ep_deliver_event() from ep_send_events() Greg Kroah-Hartman
                   ` (537 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Brauner (Amutable),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Brauner <brauner@kernel.org>

[ Upstream commit e0e35f4cb983a55a36e79e9b2a20ca0e0688fae6 ]

ep_insert() was 130 lines and mixed four concerns in one body: user
quota charge and epitem allocation, attach-into-file-hlist plus
rbtree insert plus target-ep locking, reverse-path + EPOLLWAKEUP +
poll-queue install with rollback, and ready-list publication.
Factor the first two concerns into named helpers so the body reduces
to orchestration.

ep_alloc_epitem() charges the user's epoll_watches quota, allocates
a fresh epitem, and initializes its fields. On failure it returns
ERR_PTR(-ENOSPC) or ERR_PTR(-ENOMEM); on success the epi is not yet
linked into anything.

ep_register_epitem() installs @epi into @tfile's f_ep hlist and
@ep's rbtree, optionally chains @tfile onto tfile_check_list for the
path check, takes the tep->mtx nested lock for the epoll-watches-
epoll case, and finally takes the ep_get() reference that pairs
with ep_remove()'s ep_put() in ep_insert()'s error paths. On failure
it frees the epi and decrements epoll_watches to match
ep_alloc_epitem().

ep_insert()'s remaining body is the rollback-via-ep_remove() chain
(reverse_path_check, EPOLLWAKEUP source creation, ep_ptable_queue_proc
allocation) and the ready-list / wake publication. Remove a few
stale comments that duplicated function-level documentation or
described obvious code.

No functional change; rollback boundaries unchanged -- every error
path after ep_register_epitem() still calls ep_remove(), preserving
the ep->refcount invariant that keeps ep_remove()'s WARN_ON_ONCE safe.

Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Link: https://patch.msgid.link/20260424-work-epoll-rework-v1-10-249ed00a20f3@kernel.org
Signed-off-by: Christian Brauner <brauner@kernel.org>
Stable-dep-of: 0c4aefe3c2d0 ("eventpoll: Fix epoll_wait() report false negative")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/eventpoll.c | 111 ++++++++++++++++++++++++++++++++-----------------
 1 file changed, 74 insertions(+), 37 deletions(-)

diff --git a/fs/eventpoll.c b/fs/eventpoll.c
index 556049d0da3fbb..1b340efc1166ee 100644
--- a/fs/eventpoll.c
+++ b/fs/eventpoll.c
@@ -1561,68 +1561,112 @@ static int ep_attach_file(struct file *file, struct epitem *epi)
 }
 
 /*
- * Must be called with "mtx" held.
+ * Charge the user's epoll_watches quota, allocate a fresh epitem for
+ * @tfile/@fd, and initialize its fields. The returned item is not yet
+ * linked into any data structure; the caller must install it via
+ * ep_register_epitem() (which takes over on success) or kmem_cache_free()
+ * it and decrement epoll_watches on its own.
+ *
+ * Returns ERR_PTR(-ENOSPC) if the quota is exceeded, ERR_PTR(-ENOMEM)
+ * if the slab allocation fails.
  */
-static int ep_insert(struct eventpoll *ep, const struct epoll_event *event,
-		     struct file *tfile, int fd, int full_check)
+static struct epitem *ep_alloc_epitem(struct eventpoll *ep,
+				      const struct epoll_event *event,
+				      struct file *tfile, int fd)
 {
-	int error, pwake = 0;
-	__poll_t revents;
 	struct epitem *epi;
-	struct ep_pqueue epq;
-	struct eventpoll *tep = NULL;
-
-	if (is_file_epoll(tfile))
-		tep = tfile->private_data;
-
-	lockdep_assert_irqs_enabled();
 
 	if (unlikely(percpu_counter_compare(&ep->user->epoll_watches,
 					    max_user_watches) >= 0))
-		return -ENOSPC;
+		return ERR_PTR(-ENOSPC);
 	percpu_counter_inc(&ep->user->epoll_watches);
 
-	if (!(epi = kmem_cache_zalloc(epi_cache, GFP_KERNEL))) {
+	epi = kmem_cache_zalloc(epi_cache, GFP_KERNEL);
+	if (unlikely(!epi)) {
 		percpu_counter_dec(&ep->user->epoll_watches);
-		return -ENOMEM;
+		return ERR_PTR(-ENOMEM);
 	}
 
-	/* Item initialization follow here ... */
 	INIT_LIST_HEAD(&epi->rdllink);
 	epi->ep = ep;
 	ep_set_ffd(&epi->ffd, tfile, fd);
 	epi->event = *event;
 	epi->next = EP_UNACTIVE_PTR;
 
+	return epi;
+}
+
+/*
+ * Install @epi into its target file's f_ep hlist and into @ep's rbtree,
+ * taking one additional reference on @ep for the lifetime of the item.
+ *
+ * If @tep is non-NULL, the target file is itself an eventpoll; we hold
+ * tep->mtx at subclass 1 across the attach + rbtree insert to serialize
+ * with the target side. RB tree ops are protected by @ep->mtx, which
+ * the caller already holds.
+ *
+ * On failure the epi is freed and the epoll_watches counter decremented,
+ * matching ep_alloc_epitem()'s allocation. After this returns
+ * successfully, ep_insert()'s later error paths use ep_remove() for
+ * unwind; that cannot drop @ep's refcount to zero because the ep file
+ * itself still holds the original reference.
+ */
+static int ep_register_epitem(struct eventpoll *ep, struct epitem *epi,
+			      struct eventpoll *tep, int full_check)
+{
+	struct file *tfile = epi->ffd.file;
+	int error;
+
 	if (tep)
 		mutex_lock_nested(&tep->mtx, 1);
-	/* Add the current item to the list of active epoll hook for this file */
-	if (unlikely(ep_attach_file(tfile, epi) < 0)) {
+
+	error = ep_attach_file(tfile, epi);
+	if (unlikely(error)) {
 		if (tep)
 			mutex_unlock(&tep->mtx);
 		kmem_cache_free(epi_cache, epi);
 		percpu_counter_dec(&ep->user->epoll_watches);
-		return -ENOMEM;
+		return error;
 	}
 
 	if (full_check && !tep)
 		list_file(tfile);
 
-	/*
-	 * Add the current item to the RB tree. All RB tree operations are
-	 * protected by "mtx", and ep_insert() is called with "mtx" held.
-	 */
 	ep_rbtree_insert(ep, epi);
+
 	if (tep)
 		mutex_unlock(&tep->mtx);
 
-	/*
-	 * ep_remove() calls in the later error paths can't lead to
-	 * ep_free() as the ep file itself still holds an ep reference.
-	 */
 	ep_get(ep);
+	return 0;
+}
+
+/*
+ * Must be called with "mtx" held.
+ */
+static int ep_insert(struct eventpoll *ep, const struct epoll_event *event,
+		     struct file *tfile, int fd, int full_check)
+{
+	int error, pwake = 0;
+	__poll_t revents;
+	struct epitem *epi;
+	struct ep_pqueue epq;
+	struct eventpoll *tep = NULL;
+
+	if (is_file_epoll(tfile))
+		tep = tfile->private_data;
+
+	lockdep_assert_irqs_enabled();
+
+	epi = ep_alloc_epitem(ep, event, tfile, fd);
+	if (IS_ERR(epi))
+		return PTR_ERR(epi);
 
-	/* now check if we've created too many backpaths */
+	error = ep_register_epitem(ep, epi, tep, full_check);
+	if (error)
+		return error;
+
+	/* Reject the insert if the new link would create too many back-paths. */
 	if (unlikely(full_check && reverse_path_check())) {
 		ep_remove(ep, epi);
 		return -EINVAL;
@@ -1649,28 +1693,21 @@ static int ep_insert(struct eventpoll *ep, const struct epoll_event *event,
 	 */
 	revents = ep_item_poll(epi, &epq.pt, 1);
 
-	/*
-	 * We have to check if something went wrong during the poll wait queue
-	 * install process. Namely an allocation for a wait queue failed due
-	 * high memory pressure.
-	 */
+	/* ep_ptable_queue_proc() signals allocation failure by clearing epq.epi. */
 	if (unlikely(!epq.epi)) {
 		ep_remove(ep, epi);
 		return -ENOMEM;
 	}
 
-	/* We have to drop the new item inside our item list to keep track of it */
+	/* Drop the new item onto the ready list if it is already ready. */
 	spin_lock_irq(&ep->lock);
 
-	/* record NAPI ID of new item if present */
 	ep_set_busy_poll_napi_id(epi);
 
-	/* If the file is already "ready" we drop it inside the ready list */
 	if (revents && !ep_is_linked(epi)) {
 		list_add_tail(&epi->rdllink, &ep->rdllist);
 		ep_pm_stay_awake(epi);
 
-		/* Notify waiting tasks that events are available */
 		if (waitqueue_active(&ep->wq))
 			wake_up(&ep->wq);
 		if (waitqueue_active(&ep->poll_wait))
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0461/2077] eventpoll: extract ep_deliver_event() from ep_send_events()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (459 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0460/2077] eventpoll: split ep_insert() into alloc + register stages Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0462/2077] eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers Greg Kroah-Hartman
                   ` (536 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Brauner (Amutable),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Brauner <brauner@kernel.org>

[ Upstream commit 499a5e7f4a57fa08a297c627d007a55069acac9a ]

ep_send_events()'s body covered two concerns: per-item work (PM
wakeup-source bookkeeping, re-poll, copy_to_user, level-trigger
re-queue, EPOLLONESHOT mask clear) and the scan-level accumulator
(maxevents cap, EFAULT preservation, txlist/rdllist splice).

Extract the per-item work as ep_deliver_event(), which returns a
tri-state int:

  1       one event was delivered; caller advances the counter,
  0       re-poll produced no caller-requested events (item drops
          out of the ready list; a future callback will re-queue),
 -EFAULT  copy_to_user() faulted; item is already re-inserted at
          the head of the txlist so ep_done_scan() splices it back
          to rdllist.

The per-item comments (PM ordering, the "sole writer to rdllist"
invariant for the LT re-queue, the EFAULT semantics) move into
ep_deliver_event(). ep_send_events() reduces to the fatal-signal
short-circuit, scan bracket, and a short txlist walk that accumulates
the deliveries and preserves the "first error wins" EFAULT contract
(res = delivered only if no event was previously delivered; otherwise
the success count is returned and -EFAULT is reported on the next
call).

No functional change.

Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Link: https://patch.msgid.link/20260424-work-epoll-rework-v1-12-249ed00a20f3@kernel.org
Signed-off-by: Christian Brauner <brauner@kernel.org>
Stable-dep-of: 0c4aefe3c2d0 ("eventpoll: Fix epoll_wait() report false negative")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/eventpoll.c | 138 ++++++++++++++++++++++++++++++-------------------
 1 file changed, 84 insertions(+), 54 deletions(-)

diff --git a/fs/eventpoll.c b/fs/eventpoll.c
index 1b340efc1166ee..94667f0f21546e 100644
--- a/fs/eventpoll.c
+++ b/fs/eventpoll.c
@@ -1799,6 +1799,82 @@ static int ep_modify(struct eventpoll *ep, struct epitem *epi,
 	return 0;
 }
 
+/*
+ * Attempt to deliver one event for @epi into @*uevents.
+ *
+ * Returns 1 if an event was delivered (with *uevents advanced to the
+ * next slot), 0 if the re-poll reported no caller-requested events
+ * (@epi drops out of the ready list; a future callback will re-add
+ * it), or -EFAULT if copy_to_user() faulted (in which case @epi is
+ * re-inserted at the head of @txlist so ep_done_scan() merges it
+ * back to rdllist for the next attempt).
+ *
+ * PM bookkeeping and level-triggered re-queue are handled here.
+ * Caller holds ep->mtx and the scan is active.
+ */
+static int ep_deliver_event(struct eventpoll *ep, struct epitem *epi,
+			    poll_table *pt,
+			    struct epoll_event __user **uevents,
+			    struct list_head *txlist)
+{
+	struct epoll_event __user *next;
+	struct wakeup_source *ws;
+	__poll_t revents;
+
+	/*
+	 * Activate ep->ws before deactivating epi->ws to prevent
+	 * triggering auto-suspend here (in case we reactivate epi->ws
+	 * below).  Rearranging to delay the deactivation would let
+	 * epi->ws drift out of sync with ep_is_linked().
+	 */
+	ws = ep_wakeup_source(epi);
+	if (ws) {
+		if (ws->active)
+			__pm_stay_awake(ep->ws);
+		__pm_relax(ws);
+	}
+
+	list_del_init(&epi->rdllink);
+
+	/*
+	 * Re-poll under ep->mtx so userspace cannot change the item
+	 * out from under us. If no caller-requested events remain,
+	 * @epi stays off the ready list; the poll callback will
+	 * re-queue it when events next appear.
+	 */
+	revents = ep_item_poll(epi, pt, 1);
+	if (!revents)
+		return 0;
+
+	next = epoll_put_uevent(revents, epi->event.data, *uevents);
+	if (!next) {
+		/*
+		 * copy_to_user() faulted: put the item back so
+		 * ep_done_scan() splices it onto rdllist for the next
+		 * attempt.
+		 */
+		list_add(&epi->rdllink, txlist);
+		ep_pm_stay_awake(epi);
+		return -EFAULT;
+	}
+	*uevents = next;
+
+	if (epi->event.events & EPOLLONESHOT) {
+		epi->event.events &= EP_PRIVATE_BITS;
+	} else if (!(epi->event.events & EPOLLET)) {
+		/*
+		 * Level-triggered: re-queue so the next epoll_wait()
+		 * rechecks availability. We are the sole writer to
+		 * rdllist here -- epoll_ctl() callers are locked out
+		 * by ep->mtx, and the poll callback queues to ovflist
+		 * during scans.
+		 */
+		list_add_tail(&epi->rdllink, &ep->rdllist);
+		ep_pm_stay_awake(epi);
+	}
+	return 1;
+}
+
 static int ep_send_events(struct eventpoll *ep,
 			  struct epoll_event __user *events, int maxevents)
 {
@@ -1821,70 +1897,24 @@ static int ep_send_events(struct eventpoll *ep,
 	ep_start_scan(ep, &txlist);
 
 	/*
-	 * We can loop without lock because we are passed a task private list.
-	 * Items cannot vanish during the loop we are holding ep->mtx.
+	 * We can loop without lock because we are passed a task-private
+	 * txlist; items cannot vanish while we hold ep->mtx.
 	 */
 	list_for_each_entry_safe(epi, tmp, &txlist, rdllink) {
-		struct wakeup_source *ws;
-		__poll_t revents;
+		int delivered;
 
 		if (res >= maxevents)
 			break;
 
-		/*
-		 * Activate ep->ws before deactivating epi->ws to prevent
-		 * triggering auto-suspend here (in case we reactive epi->ws
-		 * below).
-		 *
-		 * This could be rearranged to delay the deactivation of epi->ws
-		 * instead, but then epi->ws would temporarily be out of sync
-		 * with ep_is_linked().
-		 */
-		ws = ep_wakeup_source(epi);
-		if (ws) {
-			if (ws->active)
-				__pm_stay_awake(ep->ws);
-			__pm_relax(ws);
-		}
-
-		list_del_init(&epi->rdllink);
-
-		/*
-		 * If the event mask intersect the caller-requested one,
-		 * deliver the event to userspace. Again, we are holding ep->mtx,
-		 * so no operations coming from userspace can change the item.
-		 */
-		revents = ep_item_poll(epi, &pt, 1);
-		if (!revents)
-			continue;
-
-		events = epoll_put_uevent(revents, epi->event.data, events);
-		if (!events) {
-			list_add(&epi->rdllink, &txlist);
-			ep_pm_stay_awake(epi);
+		delivered = ep_deliver_event(ep, epi, &pt, &events, &txlist);
+		if (delivered < 0) {
 			if (!res)
-				res = -EFAULT;
+				res = delivered;
 			break;
 		}
-		res++;
-		if (epi->event.events & EPOLLONESHOT)
-			epi->event.events &= EP_PRIVATE_BITS;
-		else if (!(epi->event.events & EPOLLET)) {
-			/*
-			 * If this file has been added with Level
-			 * Trigger mode, we need to insert back inside
-			 * the ready list, so that the next call to
-			 * epoll_wait() will check again the events
-			 * availability. At this point, no one can insert
-			 * into ep->rdllist besides us. The epoll_ctl()
-			 * callers are locked out by
-			 * ep_send_events() holding "mtx" and the
-			 * poll callback will queue them in ep->ovflist.
-			 */
-			list_add_tail(&epi->rdllink, &ep->rdllist);
-			ep_pm_stay_awake(epi);
-		}
+		res += delivered;
 	}
+
 	ep_done_scan(ep, &txlist);
 	mutex_unlock(&ep->mtx);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0462/2077] eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (460 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0461/2077] eventpoll: extract ep_deliver_event() from ep_send_events() Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0463/2077] perf/x86/amd/core: Always use the NMI latency mitigation Greg Kroah-Hartman
                   ` (535 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Brauner (Amutable),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Brauner <brauner@kernel.org>

[ Upstream commit 0dcb726466a556f273beaadfb76f12d1b0087dd7 ]

ep->ovflist and epi->next both use EP_UNACTIVE_PTR (a cast to
(void *)-1) as a sentinel, with distinct meanings at each site:

  ep->ovflist == EP_UNACTIVE_PTR         no scan in progress
  epi->next   == EP_UNACTIVE_PTR         epi not on ovflist

Call sites had to know the sentinel's value and, by convention, what
it meant in each context. Hide both behind inline helpers:

  ep_is_scanning(ep)       predicate for "scan in progress"
  ep_enter_scan(ep)        WRITE_ONCE flip to NULL (scan start)
  ep_exit_scan(ep)         WRITE_ONCE flip to sentinel (scan end)
  epi_on_ovflist(epi)      predicate for "epi is on ovflist"
  epi_clear_ovflist(epi)   clear epi's ovflist link slot

Convert ep_events_available(), ep_start_scan(), ep_done_scan(),
ep_poll_callback(), and ep_alloc_epitem() to use the wrappers. The
ovflist state-machine transitions are now named, not encoded in
sentinel comparisons, and the top-of-file "Ready-list state machine"
section is the single place that spells out the sentinel's meaning.

ep_alloc() keeps the raw "ep->ovflist = EP_UNACTIVE_PTR" init (no
concurrent access at that point) with an inline "not scanning"
comment, and the tfile_check_list sentinel is left alone -- it will
disappear entirely when the loop-check globals move into a
stack-allocated ep_ctl_ctx in a later commit.

Also rework ep_done_scan()'s for-loop: the combined initializer +
update clause that advanced nepi AND cleared epi->next in one step
was clever but hard to read; splitting the update into two
statements inside the body makes the epi_clear_ovflist() call
visible.

No functional change.

Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Link: https://patch.msgid.link/20260424-work-epoll-rework-v1-14-249ed00a20f3@kernel.org
Signed-off-by: Christian Brauner <brauner@kernel.org>
Stable-dep-of: 0c4aefe3c2d0 ("eventpoll: Fix epoll_wait() report false negative")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/eventpoll.c | 73 +++++++++++++++++++++++++++++++++++---------------
 1 file changed, 52 insertions(+), 21 deletions(-)

diff --git a/fs/eventpoll.c b/fs/eventpoll.c
index 94667f0f21546e..dc8dc529684bfb 100644
--- a/fs/eventpoll.c
+++ b/fs/eventpoll.c
@@ -372,6 +372,43 @@ static inline struct epitem *ep_item_from_wait(wait_queue_entry_t *p)
 	return container_of(p, struct eppoll_entry, wait)->base;
 }
 
+/*
+ * Ready-list / ovflist state (see "Ready-list state machine" in the
+ * top-of-file banner for the full state machine). EP_UNACTIVE_PTR is
+ * the sentinel; these wrappers name each transition and each test so
+ * call sites do not need to know the sentinel's value.
+ */
+
+/* True iff @ep is between ep_enter_scan() and ep_exit_scan(). */
+static inline bool ep_is_scanning(struct eventpoll *ep)
+{
+	return READ_ONCE(ep->ovflist) != EP_UNACTIVE_PTR;
+}
+
+/* Called by ep_start_scan(): divert ep_poll_callback() to ovflist. */
+static inline void ep_enter_scan(struct eventpoll *ep)
+{
+	WRITE_ONCE(ep->ovflist, NULL);
+}
+
+/* Called by ep_done_scan(): redirect ep_poll_callback() back to rdllist. */
+static inline void ep_exit_scan(struct eventpoll *ep)
+{
+	WRITE_ONCE(ep->ovflist, EP_UNACTIVE_PTR);
+}
+
+/* True iff @epi is currently linked on its ep's ovflist. */
+static inline bool epi_on_ovflist(const struct epitem *epi)
+{
+	return epi->next != EP_UNACTIVE_PTR;
+}
+
+/* Mark @epi as not on any ovflist (init and post-drain). */
+static inline void epi_clear_ovflist(struct epitem *epi)
+{
+	epi->next = EP_UNACTIVE_PTR;
+}
+
 /**
  * ep_events_available - Checks if ready events might be available.
  *
@@ -382,8 +419,7 @@ static inline struct epitem *ep_item_from_wait(wait_queue_entry_t *p)
  */
 static inline int ep_events_available(struct eventpoll *ep)
 {
-	return !list_empty_careful(&ep->rdllist) ||
-		READ_ONCE(ep->ovflist) != EP_UNACTIVE_PTR;
+	return !list_empty_careful(&ep->rdllist) || ep_is_scanning(ep);
 }
 
 #ifdef CONFIG_NET_RX_BUSY_POLL
@@ -736,7 +772,7 @@ static void ep_start_scan(struct eventpoll *ep, struct list_head *txlist)
 	lockdep_assert_irqs_enabled();
 	spin_lock_irq(&ep->lock);
 	list_splice_init(&ep->rdllist, txlist);
-	WRITE_ONCE(ep->ovflist, NULL);
+	ep_enter_scan(ep);
 	spin_unlock_irq(&ep->lock);
 }
 
@@ -751,29 +787,24 @@ static void ep_done_scan(struct eventpoll *ep,
 	 * other events might have been queued by the poll callback.
 	 * We re-insert them inside the main ready-list here.
 	 */
-	for (nepi = READ_ONCE(ep->ovflist); (epi = nepi) != NULL;
-	     nepi = epi->next, epi->next = EP_UNACTIVE_PTR) {
+	for (nepi = READ_ONCE(ep->ovflist); (epi = nepi) != NULL; ) {
+		nepi = epi->next;
+		epi_clear_ovflist(epi);
 		/*
-		 * We need to check if the item is already in the list.
-		 * During the "sproc" callback execution time, items are
-		 * queued into ->ovflist but the "txlist" might already
-		 * contain them, and the list_splice() below takes care of them.
+		 * Skip items that the caller already returned via @txlist
+		 * -- the list_splice() below takes care of those.
 		 */
 		if (!ep_is_linked(epi)) {
 			/*
-			 * ->ovflist is LIFO, so we have to reverse it in order
-			 * to keep in FIFO.
+			 * ovflist is LIFO; list_add() head-insert here
+			 * reverses the iteration order into FIFO.
 			 */
 			list_add(&epi->rdllink, &ep->rdllist);
 			ep_pm_stay_awake(epi);
 		}
 	}
-	/*
-	 * We need to set back ep->ovflist to EP_UNACTIVE_PTR, so that after
-	 * releasing the lock, events will be queued in the normal way inside
-	 * ep->rdllist.
-	 */
-	WRITE_ONCE(ep->ovflist, EP_UNACTIVE_PTR);
+	/* Back out of scan mode; callbacks target ep->rdllist again. */
+	ep_exit_scan(ep);
 
 	/*
 	 * Quickly re-inject items left on "txlist".
@@ -1159,7 +1190,7 @@ static int ep_alloc(struct eventpoll **pep)
 	init_waitqueue_head(&ep->poll_wait);
 	INIT_LIST_HEAD(&ep->rdllist);
 	ep->rbr = RB_ROOT_CACHED;
-	ep->ovflist = EP_UNACTIVE_PTR;
+	ep->ovflist = EP_UNACTIVE_PTR;	/* not scanning */
 	ep->user = get_current_user();
 	refcount_set(&ep->refcount, 1);
 
@@ -1283,8 +1314,8 @@ static int ep_poll_callback(wait_queue_entry_t *wait, unsigned mode, int sync, v
 	 * semantics). All the events that happen during that period of time are
 	 * chained in ep->ovflist and requeued later on.
 	 */
-	if (READ_ONCE(ep->ovflist) != EP_UNACTIVE_PTR) {
-		if (epi->next == EP_UNACTIVE_PTR) {
+	if (ep_is_scanning(ep)) {
+		if (!epi_on_ovflist(epi)) {
 			epi->next = READ_ONCE(ep->ovflist);
 			WRITE_ONCE(ep->ovflist, epi);
 			ep_pm_stay_awake_rcu(epi);
@@ -1591,7 +1622,7 @@ static struct epitem *ep_alloc_epitem(struct eventpoll *ep,
 	epi->ep = ep;
 	ep_set_ffd(&epi->ffd, tfile, fd);
 	epi->event = *event;
-	epi->next = EP_UNACTIVE_PTR;
+	epi_clear_ovflist(epi);
 
 	return epi;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0463/2077] perf/x86/amd/core: Always use the NMI latency mitigation
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (461 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0462/2077] eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0464/2077] perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems Greg Kroah-Hartman
                   ` (534 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sandipan Das, Peter Zijlstra (Intel),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sandipan Das <sandipan.das@amd.com>

[ Upstream commit 73a4c02f94a98d94480c3e5c81450215a4da05ba ]

Commit df4d29732fda ("perf/x86/amd: Change/fix NMI latency mitigation
to use a timestamp") fixed handling of late-arriving NMIs but limited
the mitigation to processors having X86_FEATURE_PERFCTR_CORE. However,
it is unclear if processors without this feature are also affected.
When Mediated vPMU is enabled on affected hardware, it is also possible
to bypass the fix inside KVM guests if X86_FEATURE_PERFCTR_CORE is
removed from the guest CPUID (e.g. using "-cpu host,-perfctr-core" with
QEMU). Hence, use the mitigation at all times.

Fixes: df4d29732fda ("perf/x86/amd: Change/fix NMI latency mitigation to use a timestamp")
Signed-off-by: Sandipan Das <sandipan.das@amd.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/29a3c970da289ab8f24282933bdb36545c0403e8.1780325517.git.sandipan.das@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/x86/events/amd/core.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/arch/x86/events/amd/core.c b/arch/x86/events/amd/core.c
index 0c92ed5f464b1c..abc84a92cd5902 100644
--- a/arch/x86/events/amd/core.c
+++ b/arch/x86/events/amd/core.c
@@ -1412,12 +1412,12 @@ static int __init amd_core_pmu_init(void)
 	u64 even_ctr_mask = 0ULL;
 	int i;
 
-	if (!boot_cpu_has(X86_FEATURE_PERFCTR_CORE))
-		return 0;
-
 	/* Avoid calculating the value each time in the NMI handler */
 	perf_nmi_window = msecs_to_jiffies(100);
 
+	if (!boot_cpu_has(X86_FEATURE_PERFCTR_CORE))
+		return 0;
+
 	/*
 	 * If core performance counter extensions exists, we must use
 	 * MSR_F15H_PERF_CTL/MSR_F15H_PERF_CTR msrs. See also
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0464/2077] perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (462 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0463/2077] perf/x86/amd/core: Always use the NMI latency mitigation Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0465/2077] perf/x86/intel/uncore: Fix PCI device refcount leak in UPI discovery Greg Kroah-Hartman
                   ` (533 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zide Chen, Peter Zijlstra (Intel),
	Dapeng Mi, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zide Chen <zide.chen@intel.com>

[ Upstream commit 63f48abd55d0417996bca86022925c853a2b436b ]

In uncore_find_add_unit(), PMON units with the same unit ID may be
added to the uncore discovery RB-tree for different dies. These units
are distinguished by node->die.

However, intel_generic_uncore_box_ctl() uses a fixed die ID of -1 when
looking up the discovery unit, which may retrieve the wrong node on
multi-die systems.

Use box->dieid instead so the correct discovery unit is selected.

No functional issue has been observed so far because currently supported
platforms happen to use the same unit control register for such units.

Remove WARN_ON_ONCE() because with the above change a NULL unit can be
expected, e.g. when a CPU die is offline during uncore enumeration and
the unit is not added to the RB-tree. In this case,
intel_uncore_find_discovery_unit() returns NULL once the die becomes
online, and it is expected that the PMU box is not functional for that
die.

Fixes: b1d9ea2e1ca4 ("perf/x86/uncore: Apply the unit control RB tree to MSR uncore units")
Signed-off-by: Zide Chen <zide.chen@intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260602144908.263680-2-zide.chen@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/x86/events/intel/uncore_discovery.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/x86/events/intel/uncore_discovery.c b/arch/x86/events/intel/uncore_discovery.c
index 583cbd06b9b881..60e1200c4691d7 100644
--- a/arch/x86/events/intel/uncore_discovery.c
+++ b/arch/x86/events/intel/uncore_discovery.c
@@ -481,8 +481,8 @@ static u64 intel_generic_uncore_box_ctl(struct intel_uncore_box *box)
 	struct intel_uncore_discovery_unit *unit;
 
 	unit = intel_uncore_find_discovery_unit(box->pmu->type->boxes,
-						-1, box->pmu->pmu_idx);
-	if (WARN_ON_ONCE(!unit))
+						box->dieid, box->pmu->pmu_idx);
+	if (!unit)
 		return 0;
 
 	return unit->addr;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0465/2077] perf/x86/intel/uncore: Fix PCI device refcount leak in UPI discovery
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (463 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0464/2077] perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0466/2077] perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains Greg Kroah-Hartman
                   ` (532 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zide Chen, Peter Zijlstra (Intel),
	Dapeng Mi, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zide Chen <zide.chen@intel.com>

[ Upstream commit 81ec618f59415bdcf3e8989e2691c1f240be27fb ]

pci_get_domain_bus_and_slot() increments the reference count of the
returned PCI device and therefore requires a matching pci_dev_put().

In skx_upi_topology_cb() and discover_upi_topology(), the lookup is
performed inside a loop, but pci_dev_put() is only called once after
the loop. As a result, references from all previous iterations are
leaked.

Move pci_dev_put(dev) into the if (dev) block immediately after
upi_fill_topology() returns.

Opportunistically, fix uninitialized variable in skx_upi_topology_cb().

Fixes: 4cfce57fa42d ("perf/x86/intel/uncore: Enable UPI topology discovery for Skylake Server")
Fixes: f680b6e6062e ("perf/x86/intel/uncore: Enable UPI topology discovery for Icelake Server")
Signed-off-by: Zide Chen <zide.chen@intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260602144908.263680-4-zide.chen@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/x86/events/intel/uncore_snbep.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/arch/x86/events/intel/uncore_snbep.c b/arch/x86/events/intel/uncore_snbep.c
index 215d33e260ede7..c9ce206fcbb6e7 100644
--- a/arch/x86/events/intel/uncore_snbep.c
+++ b/arch/x86/events/intel/uncore_snbep.c
@@ -4261,7 +4261,7 @@ static int upi_fill_topology(struct pci_dev *dev, struct intel_uncore_topology *
 static int skx_upi_topology_cb(struct intel_uncore_type *type, int segment,
 				int die, u64 cpu_bus_msr)
 {
-	int idx, ret;
+	int idx, ret = 0;
 	struct intel_uncore_topology *upi;
 	unsigned int devfn;
 	struct pci_dev *dev = NULL;
@@ -4274,12 +4274,12 @@ static int skx_upi_topology_cb(struct intel_uncore_type *type, int segment,
 		dev = pci_get_domain_bus_and_slot(segment, bus, devfn);
 		if (dev) {
 			ret = upi_fill_topology(dev, upi, idx);
+			pci_dev_put(dev);
 			if (ret)
 				break;
 		}
 	}
 
-	pci_dev_put(dev);
 	return ret;
 }
 
@@ -5499,6 +5499,7 @@ static int discover_upi_topology(struct intel_uncore_type *type, int ubox_did, i
 							  devfn);
 			if (dev) {
 				ret = upi_fill_topology(dev, upi, idx);
+				pci_dev_put(dev);
 				if (ret)
 					goto err;
 			}
@@ -5506,7 +5507,6 @@ static int discover_upi_topology(struct intel_uncore_type *type, int ubox_did, i
 	}
 err:
 	pci_dev_put(ubox);
-	pci_dev_put(dev);
 	return ret;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0466/2077] perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (464 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0465/2077] perf/x86/intel/uncore: Fix PCI device refcount leak in UPI discovery Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0467/2077] xfrm: fix NAT-related field inheritance in SA migration Greg Kroah-Hartman
                   ` (531 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sandipan Das, Peter Zijlstra (Intel),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sandipan Das <sandipan.das@amd.com>

[ Upstream commit 67d27727854def4a7e2b386429941f5c4741ccc4 ]

For DF and UMC PMUs, a single context is shared across all CPUs that
are connected to the same Data Fabric (DF) instance. Currently, the
Package ID, which also happens to be the Socket ID, is used to identify
DF instances. This approach works for configurations having a single IO
Die (IOD) but fails in the following cases.
  * Older Zen 1 processors, where each chiplet has its own DF instance.
  * Any configurations with multiple DF instances or multiple IODs in
    the same package.

The correct way to identify DF instances is through the Node ID (not to
be confused with NUMA Node ID). This is available in ECX[7:0] of CPUID
leaf 0x8000001e and returned via topology_amd_node_id(). Hence, replace
usage of topology_logical_package_id() with topology_amd_node_id().

Fixes: 07888daa056e ("perf/x86/amd/uncore: Move discovery and registration")
Signed-off-by: Sandipan Das <sandipan.das@amd.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/e7a71a727c6a7b118c23d3e469929c538c4665aa.1780315832.git.sandipan.das@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/x86/events/amd/uncore.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/arch/x86/events/amd/uncore.c b/arch/x86/events/amd/uncore.c
index dd956cfcadefad..a0364ca2f91737 100644
--- a/arch/x86/events/amd/uncore.c
+++ b/arch/x86/events/amd/uncore.c
@@ -700,7 +700,7 @@ void amd_uncore_df_ctx_scan(struct amd_uncore *uncore, unsigned int cpu)
 	info.split.aux_data = 0;
 	info.split.num_pmcs = NUM_COUNTERS_NB;
 	info.split.gid = 0;
-	info.split.cid = topology_logical_package_id(cpu);
+	info.split.cid = topology_amd_node_id(cpu);
 
 	if (pmu_version >= 2) {
 		ebx.full = cpuid_ebx(EXT_PERFMON_DEBUG_FEATURES);
@@ -999,8 +999,8 @@ void amd_uncore_umc_ctx_scan(struct amd_uncore *uncore, unsigned int cpu)
 	cpuid(EXT_PERFMON_DEBUG_FEATURES, &eax, &ebx.full, &ecx, &edx);
 	info.split.aux_data = ecx;	/* stash active mask */
 	info.split.num_pmcs = ebx.split.num_umc_pmc;
-	info.split.gid = topology_logical_package_id(cpu);
-	info.split.cid = topology_logical_package_id(cpu);
+	info.split.gid = topology_amd_node_id(cpu);
+	info.split.cid = topology_amd_node_id(cpu);
 	*per_cpu_ptr(uncore->info, cpu) = info;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0467/2077] xfrm: fix NAT-related field inheritance in SA migration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (465 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0466/2077] perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0468/2077] wifi: wlcore: enable the right set of ciphers Greg Kroah-Hartman
                   ` (530 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sabrina Dubroca, Antony Antony,
	Steffen Klassert, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Antony Antony <antony.antony@secunet.com>

[ Upstream commit 364e165e0b63e8142e76de83e96ae8e36c3b955a ]

During SA migration via xfrm_state_clone_and_setup(),
nat_keepalive_interval was silently dropped and never copied to the new
SA. mapping_maxage was unconditionally copied even when migrating to a
non-encapsulated SA.

Both fields are only meaningful when UDP encapsulation (NAT-T) is in
use. Move mapping_maxage and add nat_keepalive_interval inside the
existing if (encap) block, so both are inherited when migrating with
encapsulation and correctly absent when migrating without it.

Fixes: f531d13bdfe3 ("xfrm: support sending NAT keepalives in ESP in UDP states")
Reviewed-by: Sabrina Dubroca <sd@queasysnail.net>
Signed-off-by: Antony Antony <antony.antony@secunet.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/xfrm/xfrm_state.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/net/xfrm/xfrm_state.c b/net/xfrm/xfrm_state.c
index 589c3b6e467913..4c7eed689cd444 100644
--- a/net/xfrm/xfrm_state.c
+++ b/net/xfrm/xfrm_state.c
@@ -2020,6 +2020,8 @@ static struct xfrm_state *xfrm_state_clone_and_setup(struct xfrm_state *orig,
 
 		if (!x->encap)
 			goto error;
+		x->mapping_maxage = orig->mapping_maxage;
+		x->nat_keepalive_interval = orig->nat_keepalive_interval;
 	}
 
 	if (orig->security)
@@ -2054,7 +2056,6 @@ static struct xfrm_state *xfrm_state_clone_and_setup(struct xfrm_state *orig,
 	x->km.seq = orig->km.seq;
 	x->replay = orig->replay;
 	x->preplay = orig->preplay;
-	x->mapping_maxage = orig->mapping_maxage;
 	x->lastused = orig->lastused;
 	x->new_mapping = 0;
 	x->new_mapping_sport = 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0468/2077] wifi: wlcore: enable the right set of ciphers
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (466 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0467/2077] xfrm: fix NAT-related field inheritance in SA migration Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0469/2077] cxl/fwctl: Fix __fortify_panic Greg Kroah-Hartman
                   ` (529 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Andreas Kemnade, Johannes Berg,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Andreas Kemnade <andreas@kemnade.info>

[ Upstream commit 7495adaa0e45e180f4b6b7436675c6266edff1ff ]

The firmware version number check for IGTK introduced in
commit c34dbc5900b0 ("wifi: wlcore: Add support for IGTK key")

lets the amount of ciphers decrease on every boot of a too old firmware and
that is practically happening. It also does not take into account other
chips than the wl18xx. On some wl128x, the following can be observed
when connecting via nm to a common ap:

[  484.113311] wlcore: WARNING could not set keys
[  484.117828] wlcore: ERROR Could not add or replace key
[  484.123016] wlan0: failed to set key (5, ff:ff:ff:ff:ff:ff) to hardware (-5)
[  484.123046] wlcore: Hardware recovery in progress. FW ver: Rev 7.3.10.0.142
[  484.139923] wlcore: pc: 0x0, hint_sts: 0x00000048 count: 1
[  484.145721] wlcore: down
[  484.148986] ieee80211 phy0: Hardware restart was requested
[  484.610473] wlcore: firmware booted (Rev 7.3.10.0.142)
[  484.633758] wlcore: Association completed.
[  484.690490] wlcore: ERROR command execute failure 14
[  484.690490] ------------[ cut here ]------------
[  484.700195] WARNING: drivers/net/wireless/ti/wlcore/main.c:872 at wl12xx_queue_recovery_work+0x64/0x74 [wlcore], CPU#0: kworker/0:0/892

This repeats endlessly.
Always disable IGTK on wl12xx and fix the decrementing mess.

Fixes: c34dbc5900b0 ("wifi: wlcore: Add support for IGTK key")
Signed-off-by: Andreas Kemnade <andreas@kemnade.info>
Link: https://patch.msgid.link/20260604103316.377251-1-andreas@kemnade.info
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ti/wlcore/main.c | 23 +++++++++++++----------
 1 file changed, 13 insertions(+), 10 deletions(-)

diff --git a/drivers/net/wireless/ti/wlcore/main.c b/drivers/net/wireless/ti/wlcore/main.c
index 1c340a4a09308f..be583ae331c03b 100644
--- a/drivers/net/wireless/ti/wlcore/main.c
+++ b/drivers/net/wireless/ti/wlcore/main.c
@@ -32,6 +32,15 @@
 #define WL1271_BOOT_RETRIES 3
 #define WL1271_WAKEUP_TIMEOUT 500
 
+static const u32 cipher_suites[] = {
+	WLAN_CIPHER_SUITE_WEP40,
+	WLAN_CIPHER_SUITE_WEP104,
+	WLAN_CIPHER_SUITE_TKIP,
+	WLAN_CIPHER_SUITE_CCMP,
+	WL1271_CIPHER_SUITE_GEM,
+	WLAN_CIPHER_SUITE_AES_CMAC,
+};
+
 static char *fwlog_param;
 static int fwlog_mem_blocks = -1;
 static int bug_on_recovery = -1;
@@ -2367,6 +2376,7 @@ static int wl12xx_init_vif_data(struct wl1271 *wl, struct ieee80211_vif *vif)
 
 static int wl12xx_init_fw(struct wl1271 *wl)
 {
+	struct wlcore_platdev_data *pdev_data = dev_get_platdata(&wl->pdev->dev);
 	int retries = WL1271_BOOT_RETRIES;
 	bool booted = false;
 	struct wiphy *wiphy = wl->hw->wiphy;
@@ -2421,8 +2431,9 @@ static int wl12xx_init_fw(struct wl1271 *wl)
 
 	/* WLAN_CIPHER_SUITE_AES_CMAC must be last in cipher_suites;
 	   support only with firmware 8.9.1 and newer */
-	if (wl->chip.fw_ver[FW_VER_MAJOR] < 1)
-		wl->hw->wiphy->n_cipher_suites--;
+	if (wl->chip.fw_ver[FW_VER_MAJOR] < 1  ||
+	    (!strncmp(pdev_data->family->name, "wl12", 4)))
+		wl->hw->wiphy->n_cipher_suites = ARRAY_SIZE(cipher_suites) - 1;
 
 	/*
 	 * Now we know if 11a is supported (info from the NVS), so disable
@@ -6198,14 +6209,6 @@ static void wl1271_unregister_hw(struct wl1271 *wl)
 static int wl1271_init_ieee80211(struct wl1271 *wl)
 {
 	int i;
-	static const u32 cipher_suites[] = {
-		WLAN_CIPHER_SUITE_WEP40,
-		WLAN_CIPHER_SUITE_WEP104,
-		WLAN_CIPHER_SUITE_TKIP,
-		WLAN_CIPHER_SUITE_CCMP,
-		WL1271_CIPHER_SUITE_GEM,
-		WLAN_CIPHER_SUITE_AES_CMAC,
-	};
 
 	/* The tx descriptor buffer */
 	wl->hw->extra_tx_headroom = sizeof(struct wl1271_tx_hw_descr);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0469/2077] cxl/fwctl: Fix __fortify_panic
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (467 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0468/2077] wifi: wlcore: enable the right set of ciphers Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0470/2077] cxl/test: " Greg Kroah-Hartman
                   ` (528 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Williams, Alison Schofield,
	Dave Jiang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dan Williams <djbw@kernel.org>

[ Upstream commit 6c9d2e87df40d606f1c85143e9acb1ecff463d5e ]

Fix a runtime assertion in cxlctl_get_supported_features(). Fortify
complains that it is potentially overflowing the entries array per
__counted_by_le(num_entries). Quiet the false positive by initializing
@num_entries earlier.

 memcpy: detected buffer overflow: 48 byte write of buffer size 0
 WARNING: lib/string_helpers.c:1036 at __fortify_report+0x4d/0xa0, CPU#7: fwctl/1398
 RIP: 0010:__fortify_report+0x50/0xa0
 Call Trace:
  __fortify_panic+0xd/0xf
  cxlctl_get_supported_features.cold+0x23/0x35 [cxl_core]

Fixes: 4d1c09cef2c2 ("cxl: Add support for fwctl RPC command to enable CXL feature commands")
Signed-off-by: Dan Williams <djbw@kernel.org>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Link: https://patch.msgid.link/20260519221204.1517773-2-djbw@kernel.org
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cxl/core/features.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/cxl/core/features.c b/drivers/cxl/core/features.c
index 3435db9ea6b116..85185af46b72d8 100644
--- a/drivers/cxl/core/features.c
+++ b/drivers/cxl/core/features.c
@@ -423,6 +423,7 @@ static void *cxlctl_get_supported_features(struct cxl_features_state *cxlfs,
 
 	rpc_out->size = struct_size(feat_out, ents, requested);
 	feat_out = &rpc_out->get_sup_feats_out;
+	feat_out->num_entries = cpu_to_le16(requested);
 
 	for (i = start, pos = &feat_out->ents[0];
 	     i < cxlfs->entries->num_features; i++, pos++) {
@@ -444,7 +445,6 @@ static void *cxlctl_get_supported_features(struct cxl_features_state *cxlfs,
 		}
 	}
 
-	feat_out->num_entries = cpu_to_le16(requested);
 	feat_out->supported_feats = cpu_to_le16(cxlfs->entries->num_features);
 	rpc_out->retval = CXL_MBOX_CMD_RC_SUCCESS;
 	*out_len = out_size;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0470/2077] cxl/test: Fix __fortify_panic
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (468 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0469/2077] cxl/fwctl: Fix __fortify_panic Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0471/2077] bpf: Take mmap_lock in zap_pages() Greg Kroah-Hartman
                   ` (527 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Williams, Alison Schofield,
	Dave Jiang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dan Williams <djbw@kernel.org>

[ Upstream commit 08326b92c7a414a73b5b308d1daf0e91e0134dfc ]

Fix a runtime assertion in setup_xor_mapping(). Fortify complains that it
is potentially overflowing the xormaps array per __counted_by(nr_maps).
Quiet the false positive by initializing @nr_maps earlier.

 memcpy: detected buffer overflow: 32 byte write of buffer size 0
 WARNING: lib/string_helpers.c:1036 at __fortify_report+0x4d/0xa0, CPU#8: modprobe/2728
 Call Trace:
  __fortify_panic+0xd/0xf
  setup_xor_mapping+0x6c/0xa0 [cxl_translate]

[ dj: Fixed up @nr_entries to @nr_maps in commit log. ]

Fixes: 06377c54a133 ("cxl/test: Add cxl_translate module for address translation testing")
Signed-off-by: Dan Williams <djbw@kernel.org>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Link: https://patch.msgid.link/20260519221204.1517773-3-djbw@kernel.org
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/cxl/test/cxl_translate.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/cxl/test/cxl_translate.c b/tools/testing/cxl/test/cxl_translate.c
index 16328b2112b236..25a27e01ac21b4 100644
--- a/tools/testing/cxl/test/cxl_translate.c
+++ b/tools/testing/cxl/test/cxl_translate.c
@@ -236,8 +236,8 @@ static int setup_xor_mapping(void)
 	if (!cximsd)
 		return -ENOMEM;
 
-	memcpy(cximsd->xormaps, xormaps, nr_maps * sizeof(*cximsd->xormaps));
 	cximsd->nr_maps = nr_maps;
+	memcpy(cximsd->xormaps, xormaps, nr_maps * sizeof(*cximsd->xormaps));
 
 	return 0;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0471/2077] bpf: Take mmap_lock in zap_pages()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (469 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0470/2077] cxl/test: " Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0472/2077] drm/amdkfd: always resume_all after suspend_all Greg Kroah-Hartman
                   ` (526 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Hildenbrand,
	Alexei Starovoitov, Emil Tsalapatis, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexei Starovoitov <ast@kernel.org>

[ Upstream commit 80b89d0226a05e8b67969de99c31b51fcd54f76a ]

zap_vma_range() requires the owning mm's mmap_lock to be held.

Taking mmap_read_lock under arena->lock would AB-BA against
arena_vm_close() and arena_map_mmap(), both of which run with
mmap_write_lock held and then acquire arena->lock. Instead drop
arena->lock, mmget_not_zero() the vma's mm, take mmap_read_lock, and
re-resolve the vma via find_vma() since it may have been unmapped or
replaced while waiting.

Track processed vmls with a per-call generation in vml->zap_gen and
serialize zap_pages() callers with a new arena->zap_mutex so
concurrent callers on different uaddr ranges do not mark each other's
vmls processed before the zap is done.

Reported-by: David Hildenbrand <david@kernel.org>
Fixes: 317460317a02 ("bpf: Introduce bpf_arena.")
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/r/20260528222014.38980-1-alexei.starovoitov@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/bpf/arena.c | 61 +++++++++++++++++++++++++++++++++++++++++++---
 1 file changed, 57 insertions(+), 4 deletions(-)

diff --git a/kernel/bpf/arena.c b/kernel/bpf/arena.c
index 49a8f7b1beef59..40c42e28a6168c 100644
--- a/kernel/bpf/arena.c
+++ b/kernel/bpf/arena.c
@@ -59,6 +59,8 @@ struct bpf_arena {
 	struct list_head vma_list;
 	/* protects vma_list */
 	struct mutex lock;
+	u64 zap_gen;
+	struct mutex zap_mutex;
 	struct irq_work     free_irq;
 	struct work_struct  free_work;
 	struct llist_head   free_spans;
@@ -228,6 +230,7 @@ static struct bpf_map *arena_map_alloc(union bpf_attr *attr)
 		goto err;
 	}
 	mutex_init(&arena->lock);
+	mutex_init(&arena->zap_mutex);
 	raw_res_spin_lock_init(&arena->spinlock);
 	err = populate_pgtable_except_pte(arena);
 	if (err) {
@@ -318,6 +321,7 @@ struct vma_list {
 	struct vm_area_struct *vma;
 	struct list_head head;
 	refcount_t mmap_count;
+	u64 zap_gen;
 };
 
 static int remember_vma(struct bpf_arena *arena, struct vm_area_struct *vma)
@@ -330,6 +334,7 @@ static int remember_vma(struct bpf_arena *arena, struct vm_area_struct *vma)
 	refcount_set(&vml->mmap_count, 1);
 	vma->vm_private_data = vml;
 	vml->vma = vma;
+	vml->zap_gen = 0;
 	list_add(&vml->head, &arena->vma_list);
 	return 0;
 }
@@ -668,12 +673,60 @@ static long arena_alloc_pages(struct bpf_arena *arena, long uaddr, long page_cnt
  */
 static void zap_pages(struct bpf_arena *arena, long uaddr, long page_cnt)
 {
+	unsigned long size = (unsigned long)page_cnt << PAGE_SHIFT;
+	struct vm_area_struct *vma;
+	struct mm_struct *mm;
 	struct vma_list *vml;
+	unsigned long vm_start;
+	u64 my_gen;
 
-	guard(mutex)(&arena->lock);
-	/* iterate link list under lock */
-	list_for_each_entry(vml, &arena->vma_list, head)
-		zap_vma_range(vml->vma, uaddr, PAGE_SIZE * page_cnt);
+	/*
+	 * Taking mmap_read_lock() under arena->lock would deadlock against
+	 * arena_vm_close(), which runs with mmap_write_lock held and then
+	 * acquires arena->lock. Drop arena->lock for mmap_read_lock().
+	 *
+	 * Use per-call my_gen, recorded in vml->zap_gen, to remember which
+	 * vmls this invocation has already processed across the lock drop.
+	 * Hold zap_mutex around the whole walk so concurrent zap_pages()
+	 * callers cannot overwrite each other's marks on shared vmls --
+	 * otherwise call B's mark would make call A skip a vml that A has
+	 * not yet zapped for A's uaddr range.
+	 */
+	mutex_lock(&arena->zap_mutex);
+	mutex_lock(&arena->lock);
+	my_gen = ++arena->zap_gen;
+	for (;;) {
+		mm = NULL;
+		list_for_each_entry(vml, &arena->vma_list, head) {
+			if (vml->zap_gen >= my_gen)
+				continue;
+			vml->zap_gen = my_gen;
+			if (!mmget_not_zero(vml->vma->vm_mm))
+				continue;
+			mm = vml->vma->vm_mm;
+			vm_start = vml->vma->vm_start;
+			break;
+		}
+		if (!mm)
+			break;
+		mutex_unlock(&arena->lock);
+
+		mmap_read_lock(mm);
+		/*
+		 * Re-resolve: while we waited the VMA could have been unmapped
+		 * and a different mapping installed at the same address.
+		 */
+		vma = find_vma(mm, vm_start);
+		if (vma && vma->vm_start == vm_start &&
+		    vma->vm_file && vma->vm_file->private_data == &arena->map)
+			zap_vma_range(vma, uaddr, size);
+		mmap_read_unlock(mm);
+		mmput(mm);
+
+		mutex_lock(&arena->lock);
+	}
+	mutex_unlock(&arena->lock);
+	mutex_unlock(&arena->zap_mutex);
 }
 
 static void arena_free_pages(struct bpf_arena *arena, long uaddr, long page_cnt, bool sleepable)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0472/2077] drm/amdkfd: always resume_all after suspend_all
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (470 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0471/2077] bpf: Take mmap_lock in zap_pages() Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0473/2077] of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails Greg Kroah-Hartman
                   ` (525 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Amber Lin, Alex Deucher, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alex Deucher <alexander.deucher@amd.com>

[ Upstream commit 56ae73c92e200e630c2bdf1e98c88b86c8483b37 ]

Need to restore any good queues even if the suspend_all
failed for some.  Always run remove_queue as that will
schedule a GPU reset is removing the queue fails.

v2: move resume_all after remove

Fixes: eb067d65c33e ("drm/amdkfd: Update BadOpcode Interrupt handling with MES")
Reviewed-by: Amber Lin <Amber.Lin@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../drm/amd/amdkfd/kfd_device_queue_manager.c | 20 ++++++-------------
 1 file changed, 6 insertions(+), 14 deletions(-)

diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c b/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
index 31187ddbb79ea2..ee413117b0ff68 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
@@ -3095,32 +3095,24 @@ int kfd_dqm_suspend_bad_queue_mes(struct kfd_node *knode, u32 pasid, u32 doorbel
 
 		list_for_each_entry(q, &qpd->queues_list, list) {
 			if (q->doorbell_id == doorbell_id && q->properties.is_active) {
-				ret = suspend_all_queues_mes(dqm);
-				if (ret) {
-					dev_err(dev, "Suspending all queues failed");
-					goto out;
-				}
+				/* suspend all queues will save any good queues and mark the rest as bad */
+				suspend_all_queues_mes(dqm);
 
 				q->properties.is_evicted = true;
 				q->properties.is_active = false;
 				decrement_queue_count(dqm, qpd, q);
 
+				/* this will remove the bad queue and sched a GPU reset if needed */
 				ret = remove_queue_mes(dqm, q, qpd);
-				if (ret) {
-					dev_err(dev, "Removing bad queue failed");
-					goto out;
-				}
-
-				ret = resume_all_queues_mes(dqm);
 				if (ret)
-					dev_err(dev, "Resuming all queues failed");
-
+					dev_err(dev, "Removing bad queue failed");
+				/* resume the good queues */
+				resume_all_queues_mes(dqm);
 				break;
 			}
 		}
 	}
 
-out:
 	dqm_unlock(dqm);
 	kfd_unref_process(p);
 	return ret;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0473/2077] of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (471 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0472/2077] drm/amdkfd: always resume_all after suspend_all Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0474/2077] ocfs2: rebase copied fsdlm LVB pointers in locking_state Greg Kroah-Hartman
                   ` (524 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wandun Chen, Rob Herring (Arm),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wandun Chen <chenwandun@lixiang.com>

[ Upstream commit e1686ca81dbf3edbde589b7daf312b45cbf76e03 ]

The global pointer 'reserved_mem' continues to reference the
reserved_mem_array which lives in __initdata if
alloc_reserved_mem_array() fails. of_reserved_mem_lookup() is
exported for post-init use, that would dereference freed memory
and trigger a use-after-free.

So reset reserved_mem_count to 0 when alloc_reserved_mem_array()
fails.

Fixes: 00c9a452a235 ("of: reserved_mem: Add code to dynamically allocate reserved_mem array")
Signed-off-by: Wandun Chen <chenwandun@lixiang.com>
Link: https://patch.msgid.link/20260604015332.3669384-1-chenwandun1@gmail.com
Signed-off-by: Rob Herring (Arm) <robh@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/of/of_reserved_mem.c | 28 +++++++++++++++++++---------
 1 file changed, 19 insertions(+), 9 deletions(-)

diff --git a/drivers/of/of_reserved_mem.c b/drivers/of/of_reserved_mem.c
index 8d5777cb5d1b3d..deaea58c74f2a5 100644
--- a/drivers/of/of_reserved_mem.c
+++ b/drivers/of/of_reserved_mem.c
@@ -69,29 +69,32 @@ static int __init early_init_dt_alloc_reserved_memory_arch(phys_addr_t size,
  * the initial static array is copied over to this new array and
  * the new array is used from this point on.
  */
-static void __init alloc_reserved_mem_array(void)
+static int __init alloc_reserved_mem_array(void)
 {
 	struct reserved_mem *new_array;
 	size_t alloc_size, copy_size, memset_size;
+	int ret;
+
+	if (!total_reserved_mem_cnt)
+		return 0;
 
 	alloc_size = array_size(total_reserved_mem_cnt, sizeof(*new_array));
 	if (alloc_size == SIZE_MAX) {
-		pr_err("Failed to allocate memory for reserved_mem array with err: %d", -EOVERFLOW);
-		return;
+		ret = -EOVERFLOW;
+		goto fail;
 	}
 
 	new_array = memblock_alloc(alloc_size, SMP_CACHE_BYTES);
 	if (!new_array) {
-		pr_err("Failed to allocate memory for reserved_mem array with err: %d", -ENOMEM);
-		return;
+		ret = -ENOMEM;
+		goto fail;
 	}
 
 	copy_size = array_size(reserved_mem_count, sizeof(*new_array));
 	if (copy_size == SIZE_MAX) {
 		memblock_free(new_array, alloc_size);
-		total_reserved_mem_cnt = MAX_RESERVED_REGIONS;
-		pr_err("Failed to allocate memory for reserved_mem array with err: %d", -EOVERFLOW);
-		return;
+		ret = -EOVERFLOW;
+		goto fail;
 	}
 
 	memset_size = alloc_size - copy_size;
@@ -100,6 +103,12 @@ static void __init alloc_reserved_mem_array(void)
 	memset(new_array + reserved_mem_count, 0, memset_size);
 
 	reserved_mem = new_array;
+	return 0;
+
+fail:
+	pr_err("Failed to allocate memory for reserved_mem array with err: %d", ret);
+	reserved_mem_count = 0;
+	return ret;
 }
 
 static void fdt_init_reserved_mem_node(unsigned long node, const char *uname,
@@ -266,7 +275,8 @@ void __init fdt_scan_reserved_mem_late(void)
 	}
 
 	/* Attempt dynamic allocation of a new reserved_mem array */
-	alloc_reserved_mem_array();
+	if (alloc_reserved_mem_array())
+		return;
 
 	if (__reserved_mem_check_root(node)) {
 		pr_err("Reserved memory: unsupported node format, ignoring\n");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0474/2077] ocfs2: rebase copied fsdlm LVB pointers in locking_state
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (472 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0473/2077] of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0475/2077] lib: kunit_iov_iter: repeatedly call alloc_pages_bulk() Greg Kroah-Hartman
                   ` (523 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhang Cen, Joseph Qi, Mark Fasheh,
	Joel Becker, Junxiao Bi, Changwei Ge, Jun Piao, Heming Zhao,
	Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhang Cen <rollkingzzc@gmail.com>

[ Upstream commit 93612d48fa42b3d1a637eb9279e15281c611c000 ]

The locking_state debugfs iterator snapshots struct ocfs2_lock_res by
value under ocfs2_dlm_tracking_lock and later formats that copy in
ocfs2_dlm_seq_show().  That is fine for the inline fields, but the
userspace fsdlm stack stores the LVB through lksb_fsdlm.sb_lvbptr.  Once
the iterator drops the tracking lock, a copied non-NULL sb_lvbptr still
points into the original lockres owner, so teardown can free that
container before the debugfs dump walks the raw LVB bytes.

Rebase the copied sb_lvbptr to the copied l_lksb before dumping the raw
LVB.  The seq snapshot already carries the inline LVB storage reserved in
struct ocfs2_dlm_lksb, so the debugfs reader can dump the copied bytes
without borrowing the original lockres lifetime.

The buggy scenario involves two paths, with each column showing the order
within that path:

locking_state reader:                  lockres teardown:
1. ocfs2_dlm_seq_start()/next()        1. file release or another owner
   copies struct ocfs2_lock_res           teardown reaches
2. ocfs2_dlm_seq_show() formats           ocfs2_lock_res_free()
   the copied row                      2. the lockres is removed from the
3. ocfs2_dlm_lvb() follows the            tracking list
   copied sb_lvbptr                   3. the owner frees the original
                                          lockres container

Validation reproduced this kernel report:
KASAN slab-use-after-free in ocfs2_dlm_seq_show+0x1bd/0x430
RIP: 0033:0x7f8ec4b1e29d
The buggy address belongs to the object at ffff88810a1e0800 which belongs
to the cache kmalloc-1k of size 1024
The buggy address is located 368 bytes inside of freed 1024-byte region
[ffff88810a1e0800, ffff88810a1e0c00)
Read of size 1
Call trace:
  dump_stack_lvl+0x66/0xa0
  print_report+0xce/0x630
  ocfs2_dlm_seq_show+0x1bd/0x430 (fs/ocfs2/dlmglue.c:3137)
  srso_alias_return_thunk+0x5/0xfbef5
  __virt_addr_valid+0x19f/0x330
  kasan_report+0xe0/0x110
  seq_read_iter+0x29d/0x790
  seq_read+0x20a/0x280
  find_held_lock+0x2b/0x80
  rcu_read_unlock+0x18/0x70
  full_proxy_read+0x9e/0xd0
  vfs_read+0x12c/0x590
  ksys_read+0xd2/0x170
  do_user_addr_fault+0x65a/0x890
  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)
  entry_SYSCALL_64_after_hwframe+0x77/0x7f
Allocated by task stack:
  kasan_save_stack+0x33/0x60
  kasan_save_track+0x14/0x30
  __kasan_kmalloc+0xaa/0xb0
  ocfs2_file_open+0x13e/0x300
  do_dentry_open+0x233/0x7f0
  vfs_open+0x5a/0x1b0
  path_openat+0x66d/0x1540
  do_file_open+0x186/0x2b0
  do_sys_openat2+0xce/0x150
  __x64_sys_openat+0xd0/0x140
  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)
  entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task stack:
  kasan_save_stack+0x33/0x60
  kasan_save_track+0x14/0x30
  kasan_save_free_info+0x3b/0x60
  __kasan_slab_free+0x5f/0x80
  kfree+0x313/0x590
  ocfs2_file_release+0x138/0x260
  __fput+0x1df/0x4b0
  fput_close_sync+0xd2/0x170
  __x64_sys_close+0x55/0x90
  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)
  entry_SYSCALL_64_after_hwframe+0x77/0x7f

Link: https://lore.kernel.org/20260525041726.4112882-1-rollkingzzc@gmail.com
Fixes: cf4d8d75d8ab ("ocfs2: add fsdlm to stackglue")
Assisted-by: Codex:gpt-5.5
Signed-off-by: Zhang Cen <rollkingzzc@gmail.com>
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ocfs2/dlmglue.c | 17 +++++++++++++++++
 1 file changed, 17 insertions(+)

diff --git a/fs/ocfs2/dlmglue.c b/fs/ocfs2/dlmglue.c
index 7283bb2c5a31bf..a23dd8f86c8950 100644
--- a/fs/ocfs2/dlmglue.c
+++ b/fs/ocfs2/dlmglue.c
@@ -3134,6 +3134,22 @@ static void *ocfs2_dlm_seq_next(struct seq_file *m, void *v, loff_t *pos)
  *	- Add last pr/ex unlock times and first lock wait time in usecs
  */
 #define OCFS2_DLM_DEBUG_STR_VERSION 4
+
+/*
+ * The debug iterator snapshots lockres by value, so a userspace-stack LVB
+ * pointer copied from the original lockres must be rebased to the copied
+ * lksb before the dump walks the raw bytes.
+ */
+static void ocfs2_dlm_seq_rebase_lvb(struct ocfs2_lock_res *lockres)
+{
+	if (!ocfs2_stack_supports_plocks())
+		return;
+
+	if (lockres->l_lksb.lksb_fsdlm.sb_lvbptr)
+		lockres->l_lksb.lksb_fsdlm.sb_lvbptr =
+			(char *)&lockres->l_lksb + sizeof(struct dlm_lksb);
+}
+
 static int ocfs2_dlm_seq_show(struct seq_file *m, void *v)
 {
 	int i;
@@ -3191,6 +3207,7 @@ static int ocfs2_dlm_seq_show(struct seq_file *m, void *v)
 		   lockres->l_blocking);
 
 	/* Dump the raw LVB */
+	ocfs2_dlm_seq_rebase_lvb(lockres);
 	lvb = ocfs2_dlm_lvb(&lockres->l_lksb);
 	for(i = 0; i < DLM_LVB_LEN; i++)
 		seq_printf(m, "0x%x\t", lvb[i]);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0475/2077] lib: kunit_iov_iter: repeatedly call alloc_pages_bulk()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (473 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0474/2077] ocfs2: rebase copied fsdlm LVB pointers in locking_state Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0476/2077] ocfs2: fix buffer head management in ocfs2_read_blocks() Greg Kroah-Hartman
                   ` (522 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Weißschuh,
	Christian A. Ehrhardt, Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Weißschuh <linux@weissschuh.net>

[ Upstream commit 9ac9a08e4ac4bc063e56e1aff266c5e8aa5c6c03 ]

alloc_pages_bulk() is not guaranteed to return all requested pages in a
single call.

Call it repeatedly until all pages have been allocated or no more progress
is being made.

Link: https://lore.kernel.org/20260526-kunit_iov_iter-alloc_bulk-v2-1-24fbcd995c61@weissschuh.net
Fixes: 2d71340ff1d4 ("iov_iter: Kunit tests for copying to/from an iterator")
Signed-off-by: Thomas Weißschuh <linux@weissschuh.net>
Cc: "Christian A. Ehrhardt" <lk@c--e.de>
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 lib/tests/kunit_iov_iter.c | 12 ++++++++++--
 1 file changed, 10 insertions(+), 2 deletions(-)

diff --git a/lib/tests/kunit_iov_iter.c b/lib/tests/kunit_iov_iter.c
index f02f7b7aa79605..1e6fce9cb255ff 100644
--- a/lib/tests/kunit_iov_iter.c
+++ b/lib/tests/kunit_iov_iter.c
@@ -53,7 +53,7 @@ static void *__init iov_kunit_create_buffer(struct kunit *test,
 					    size_t npages)
 {
 	struct page **pages;
-	unsigned long got;
+	unsigned long got, last;
 	void *buffer;
 	unsigned int i;
 
@@ -61,7 +61,15 @@ static void *__init iov_kunit_create_buffer(struct kunit *test,
 	KUNIT_ASSERT_NOT_ERR_OR_NULL(test, pages);
 	*ppages = pages;
 
-	got = alloc_pages_bulk(GFP_KERNEL, npages, pages);
+	got = 0;
+	while (true) {
+		last = got;
+		got = alloc_pages_bulk(GFP_KERNEL, npages, pages);
+
+		if (last == got || got == npages)
+			break;
+	}
+
 	if (got != npages) {
 		release_pages(pages, got);
 		kvfree(pages);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0476/2077] ocfs2: fix buffer head management in ocfs2_read_blocks()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (474 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0475/2077] lib: kunit_iov_iter: repeatedly call alloc_pages_bulk() Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0477/2077] ocfs2: validate fast symlink target during inode read Greg Kroah-Hartman
                   ` (521 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmitry Antipov,
	syzbot+caacd220635a9cc3bac9, Joseph Qi, Mark Fasheh, Joel Becker,
	Junxiao Bi, Changwei Ge, Jun Piao, Heming Zhao, Andrew Morton,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dmitry Antipov <dmantipov@yandex.ru>

[ Upstream commit 6371a07148ee979af22a9d6f4c277462953a9a4a ]

In ocfs2_read_blocks(), caller should't assume that buffer head returned
by 'sb_getblk()' is exclusively owned and so 'put_bh()' always drops
b_count from 1 to 0.  If it is not so, buffer head remains on hold and
likely to be returned by the next call to 'sb_getblk()' unchanged - that
is, with BH_Uptodate bit set even if it has failed validation previously,
thus allowing to insert that buffer head into OCFS2 metadata cache and
submit it to upper layers.  To avoid such a scenario, BH_Uptodate should
be cleared immediately after 'validate()' callback has detected some data
inconsistency.

Link: https://lore.kernel.org/20260529094128.494293-1-dmantipov@yandex.ru
Fixes: cf76c78595ca ("ocfs2: don't put and assigning null to bh allocated outside")
Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
Reported-by: syzbot+caacd220635a9cc3bac9@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=caacd220635a9cc3bac9
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ocfs2/buffer_head_io.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/fs/ocfs2/buffer_head_io.c b/fs/ocfs2/buffer_head_io.c
index 701d27d908d4b2..6114299b121e52 100644
--- a/fs/ocfs2/buffer_head_io.c
+++ b/fs/ocfs2/buffer_head_io.c
@@ -350,8 +350,6 @@ int ocfs2_read_blocks(struct ocfs2_caching_info *ci, u64 block, int nr,
 						wait_on_buffer(bh);
 					put_bh(bh);
 					bhs[i] = NULL;
-				} else if (bh && buffer_uptodate(bh)) {
-					clear_buffer_uptodate(bh);
 				}
 				continue;
 			}
@@ -380,8 +378,11 @@ int ocfs2_read_blocks(struct ocfs2_caching_info *ci, u64 block, int nr,
 				BUG_ON(buffer_jbd(bh));
 				clear_buffer_needs_validate(bh);
 				status = validate(sb, bh);
-				if (status)
+				if (status) {
+					if (buffer_uptodate(bh))
+						clear_buffer_uptodate(bh);
 					goto read_failure;
+				}
 			}
 		}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0477/2077] ocfs2: validate fast symlink target during inode read
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (475 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0476/2077] ocfs2: fix buffer head management in ocfs2_read_blocks() Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0478/2077] ocfs2: reject FITRIM ranges shorter than a cluster Greg Kroah-Hartman
                   ` (520 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhang Cen, Joseph Qi, Gui-Dong Han,
	Mark Fasheh, Joel Becker, Junxiao Bi, Changwei Ge, Jun Piao,
	Heming Zhao, Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhang Cen <rollkingzzc@gmail.com>

[ Upstream commit e234973f286ed2e8961a24561ec91594ec3e3ff8 ]

ocfs2_validate_inode_block() already rejects several inconsistent
self-contained dinodes before they are exposed to the rest of the
filesystem.  Fast symlinks need the same treatment.

A zero-cluster symlink is treated as a fast symlink and later read through
page_get_link() and ocfs2_fast_symlink_read_folio().  That path uses
strnlen() on the inline payload and then copies len + 1 bytes into the
folio.  If a corrupt dinode stores an i_size that does not fit the inline
area or omits the terminating NUL at i_size, that copy reads past the end
of the inode block buffer.

Reject zero-cluster symlink dinodes whose i_size exceeds the inline
fast-symlink capacity or whose inline payload is not NUL-terminated
exactly at i_size when the inode block is validated.  This keeps malformed
fast symlinks from reaching the read path.

Validation reproduced this kernel report:
KASAN use-after-free in ocfs2_fast_symlink_read_folio+0x12c/0x1f0
RIP: 0033:0x7f5c6d859aa7
Read of size 3905
Call trace:
  dump_stack_lvl+0x66/0xa0 (?:?)
  print_report+0xce/0x630 (?:?)
  ocfs2_fast_symlink_read_folio+0x12c/0x1f0 (fs/ocfs2/inode.c:?)
  srso_alias_return_thunk+0x5/0xfbef5 (?:?)
  __virt_addr_valid+0x19f/0x330 (?:?)
  kasan_report+0xe0/0x110 (?:?)
  kasan_check_range+0x105/0x1b0 (?:?)
  __asan_memcpy+0x23/0x60 (?:?)
  filemap_read_folio+0x27/0xe0 (?:?)
  filemap_read_folio+0x35/0xe0 (?:?)
  do_read_cache_folio+0x138/0x230 (?:?)
  __page_get_link+0x26/0x110 (?:?)
  page_get_link+0x2e/0x70 (?:?)
  vfs_readlink+0x15e/0x250 (?:?)
  touch_atime+0x4d/0x370 (?:?)
  do_readlinkat+0x186/0x200 (?:?)
  do_user_addr_fault+0x65a/0x890 (?:?)
  __x64_sys_readlink+0x46/0x60 (?:?)
  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)
  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)

Link: https://lore.kernel.org/20260528151230.361127-1-rollkingzzc@gmail.com
Fixes: ea022dfb3c2a ("ocfs: simplify symlink handling")
Assisted-by: Codex:gpt-5.5
Signed-off-by: Zhang Cen <rollkingzzc@gmail.com>
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Gui-Dong Han <2045gemini@gmail.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ocfs2/inode.c | 23 +++++++++++++++++++++++
 1 file changed, 23 insertions(+)

diff --git a/fs/ocfs2/inode.c b/fs/ocfs2/inode.c
index a510a0eb1adccb..994d6e46472f54 100644
--- a/fs/ocfs2/inode.c
+++ b/fs/ocfs2/inode.c
@@ -1525,6 +1525,29 @@ int ocfs2_validate_inode_block(struct super_block *sb,
 		}
 	}
 
+	if (S_ISLNK(le16_to_cpu(di->i_mode)) &&
+	    !le32_to_cpu(di->i_clusters)) {
+		int max_inline = ocfs2_fast_symlink_chars(sb);
+		u64 i_size = le64_to_cpu(di->i_size);
+
+		if (i_size >= max_inline) {
+			rc = ocfs2_error(sb,
+					 "Invalid dinode #%llu: fast symlink i_size %llu exceeds max %d\n",
+					 (unsigned long long)bh->b_blocknr,
+					 (unsigned long long)i_size,
+					 max_inline - 1);
+			goto bail;
+		}
+
+		if (strnlen((char *)di->id2.i_symlink, i_size + 1) != i_size) {
+			rc = ocfs2_error(sb,
+					 "Invalid dinode #%llu: fast symlink is not NUL-terminated at i_size %llu\n",
+					 (unsigned long long)bh->b_blocknr,
+					 (unsigned long long)i_size);
+			goto bail;
+		}
+	}
+
 	if (le32_to_cpu(di->i_flags) & OCFS2_CHAIN_FL) {
 		struct ocfs2_chain_list *cl = &di->id2.i_chain;
 		u16 bpc = 1 << (OCFS2_SB(sb)->s_clustersize_bits -
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0478/2077] ocfs2: reject FITRIM ranges shorter than a cluster
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (476 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0477/2077] ocfs2: validate fast symlink target during inode read Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0479/2077] ocfs2/dlm: require a ref for locking_state debugfs open Greg Kroah-Hartman
                   ` (519 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhang Cen, Joseph Qi, Mark Fasheh,
	Joel Becker, Junxiao Bi, Changwei Ge, Jun Piao, Heming Zhao,
	Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhang Cen <rollkingzzc@gmail.com>

[ Upstream commit ca1afd88f5eaaff9168e1466e5401385edf59543 ]

ocfs2_trim_mainbm() trims the global bitmap in cluster units, but its
too-short range validation only checks sb->s_blocksize.

On filesystems with a cluster size larger than the block size, a FITRIM
range that is at least one block but shorter than one cluster is accepted
and shifted down to len == 0.  The later start + len - 1 and len -= ...
arithmetic then underflows and can drive trimming past the requested
range.

Reject ranges shorter than s_clustersize instead.  That preserves the
existing -EINVAL behavior for requests that cannot discard even one
allocation unit and keeps zero-cluster trims out of the group walk.

Link: https://lore.kernel.org/20260528151247.361854-1-rollkingzzc@gmail.com
Fixes: aa89762c5480 ("ocfs2: return EINVAL if the given range to discard is less than block size")
Assisted-by: Codex:gpt-5.5
Signed-off-by: Zhang Cen <rollkingzzc@gmail.com>
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ocfs2/alloc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/ocfs2/alloc.c b/fs/ocfs2/alloc.c
index 6e5fd3f12a84c7..be09e766ac1fc9 100644
--- a/fs/ocfs2/alloc.c
+++ b/fs/ocfs2/alloc.c
@@ -7576,7 +7576,7 @@ int ocfs2_trim_mainbm(struct super_block *sb, struct fstrim_range *range)
 	len = range->len >> osb->s_clustersize_bits;
 	minlen = range->minlen >> osb->s_clustersize_bits;
 
-	if (minlen >= osb->bitmap_cpg || range->len < sb->s_blocksize)
+	if (minlen >= osb->bitmap_cpg || range->len < osb->s_clustersize)
 		return -EINVAL;
 
 	trace_ocfs2_trim_mainbm(start, len, minlen);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0479/2077] ocfs2/dlm: require a ref for locking_state debugfs open
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (477 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0478/2077] ocfs2: reject FITRIM ranges shorter than a cluster Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0480/2077] ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() Greg Kroah-Hartman
                   ` (518 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhang Cen, Joseph Qi, Mark Fasheh,
	Joel Becker, Junxiao Bi, Changwei Ge, Jun Piao, Heming Zhao,
	Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhang Cen <rollkingzzc@gmail.com>

[ Upstream commit 03ad858ce8064861ea580021976dc19b7aabb549 ]

debug_lockres_open() copies inode->i_private into struct debug_lockres and
debug_lockres_release() later drops that pointer with dlm_put().  That
only works if open successfully pins the struct dlm_ctxt.

Today open calls dlm_grab(dlm) but ignores its return value.  Once the
last domain unregister has removed the context from dlm_domains,
dlm_grab() returns NULL, yet open still stores the raw pointer and returns
success.  The later release path is outside the debugfs removal barrier,
so it can call dlm_put() after dlm_free_ctxt_mem() has freed the context.
KASAN reports this as a slab-use-after-free in dlm_put() called from
debug_lockres_release().

Fail the open when dlm_grab() cannot acquire the reference and unwind the
seq_file private state before returning.  That keeps locking_state from
handing out a file descriptor whose release path does not own the
dlm_ctxt.

The buggy scenario involves two paths, with each column showing the order
within that path:

locking_state debugfs open:          last domain unregister:
1. debug_lockres_open() reads        1. dlm_unregister_domain() calls
   inode->i_private.                    dlm_complete_dlm_shutdown().
2. debug_lockres_open() calls        2. shutdown removes the dlm_ctxt from
   dlm_grab(dlm) and gets NULL.         dlm_domains.
3. open still stores the raw dlm     3. final teardown reaches
   pointer in dl->dl_ctxt and           dlm_free_ctxt_mem() and frees it.
   returns success.
4. debug_lockres_release() later
   calls dlm_put(dl->dl_ctxt).

Validation reproduced this kernel report:
KASAN slab-use-after-free in dlm_put+0x82/0x200
RIP: 0033:0x7f4d349bc9e0
The buggy address belongs to the object at ffff888103a3c000 which belongs
to the cache kmalloc-2k of size 2048
The buggy address is located 816 bytes inside of freed 2048-byte region
[ffff888103a3c000, ffff888103a3c800)
Write of size 4
Call trace:
  dump_stack_lvl+0x66/0xa0 (?:?)
  print_report+0xd0/0x630 (?:?)
  dlm_put+0x82/0x200 (?:?)
  srso_alias_return_thunk+0x5/0xfbef5 (?:?)
  __virt_addr_valid+0x188/0x2f0 (?:?)
  kasan_report+0xe4/0x120 (?:?)
  kasan_check_range+0x105/0x1b0 (?:?)
  debug_lockres_release+0x53/0x80 (fs/ocfs2/dlm/dlmdebug.c:587)
  dlm_put+0x9/0x200 (?:?)
  debug_lockres_release+0x5c/0x80 (fs/ocfs2/dlm/dlmdebug.c:587)
  full_proxy_release+0x67/0x90 (?:?)
  __fput+0x1df/0x4b0 (?:?)
  do_raw_spin_lock+0x10f/0x1b0 (?:?)
  fput_close_sync+0xd2/0x170 (?:?)
  __x64_sys_close+0x55/0x90 (?:?)
  do_syscall_64+0x10c/0x640 (arch/x86/entry/syscall_64.c:87)
  irqentry_exit+0xac/0x6e0 (?:?)
  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)
Freed by task stack:
  kasan_save_stack+0x33/0x60 (?:?)
  kasan_save_track+0x14/0x30 (?:?)
  kasan_save_free_info+0x3b/0x60 (?:?)
  __kasan_slab_free+0x5f/0x80 (?:?)
  kfree+0x30f/0x580 (?:?)
  dlm_put+0x1ce/0x200 (?:?)
  dlm_unregister_domain+0xf6/0xb30 (?:?)
  o2cb_cluster_disconnect+0x6b/0x90 (?:?)
  ocfs2_cluster_disconnect+0x41/0x70 (?:?)
  ocfs2_dlm_shutdown+0x1c4/0x220 (?:?)
  ocfs2_dismount_volume+0x38a/0x550 (?:?)
  generic_shutdown_super+0xc3/0x220 (?:?)
  kill_block_super+0x29/0x60 (?:?)
  deactivate_locked_super+0x66/0xe0 (?:?)
  cleanup_mnt+0x13d/0x210 (?:?)
  task_work_run+0xfa/0x170 (?:?)
  exit_to_user_mode_loop+0xd6/0x430 (?:?)
  do_syscall_64+0x3cb/0x640 (arch/x86/entry/syscall_64.c:87)
  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)

Link: https://lore.kernel.org/20260531044714.1640172-1-rollkingzzc@gmail.com
Fixes: 4e3d24ed1a12 ("ocfs2/dlm: Dumps the lockres' into a debugfs file")
Assisted-by: Codex:gpt-5.5
Signed-off-by: Zhang Cen <rollkingzzc@gmail.com>
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ocfs2/dlm/dlmdebug.c | 16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

diff --git a/fs/ocfs2/dlm/dlmdebug.c b/fs/ocfs2/dlm/dlmdebug.c
index fe4fdd09bae398..56456735862011 100644
--- a/fs/ocfs2/dlm/dlmdebug.c
+++ b/fs/ocfs2/dlm/dlmdebug.c
@@ -560,6 +560,7 @@ static int debug_lockres_open(struct inode *inode, struct file *file)
 	struct dlm_ctxt *dlm = inode->i_private;
 	struct debug_lockres *dl;
 	void *buf;
+	int status = -ENOMEM;
 
 	buf = kmalloc(PAGE_SIZE, GFP_KERNEL);
 	if (!buf)
@@ -572,16 +573,23 @@ static int debug_lockres_open(struct inode *inode, struct file *file)
 	dl->dl_len = PAGE_SIZE;
 	dl->dl_buf = buf;
 
-	dlm_grab(dlm);
-	dl->dl_ctxt = dlm;
+	/* ->release uses dl_ctxt after open, so it needs a real pin. */
+	dl->dl_ctxt = dlm_grab(dlm);
+	if (!dl->dl_ctxt) {
+		status = -ENOENT;
+		goto bailseq;
+	}
 
 	return 0;
 
+bailseq:
+	seq_release_private(inode, file);
 bailfree:
 	kfree(buf);
 bail:
-	mlog_errno(-ENOMEM);
-	return -ENOMEM;
+	if (status != -ENOENT)
+		mlog_errno(status);
+	return status;
 }
 
 static int debug_lockres_release(struct inode *inode, struct file *file)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0480/2077] ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (478 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0479/2077] ocfs2/dlm: require a ref for locking_state debugfs open Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0481/2077] ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent Greg Kroah-Hartman
                   ` (517 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joseph Qi, Ginger, Mark Fasheh,
	Joel Becker, Junxiao Bi, Changwei Ge, Jun Piao, Heming Zhao,
	Andrew Morton, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joseph Qi <joseph.qi@linux.alibaba.com>

[ Upstream commit 57dcfd9049d497c31151787a0696d59f0a98f8e6 ]

Move atomic_inc(&ocfs2_control_opened) and the handshake state update
inside ocfs2_control_lock to close a race window where
ocfs2_control_release() can observe ocfs2_control_opened dropping to zero
(resetting ocfs2_control_this_node and running_proto) while
ocfs2_control_install_private() is about to bump the counter and mark the
connection valid.

Link: https://lore.kernel.org/20260601121618.1263346-1-joseph.qi@linux.alibaba.com
Fixes: 3cfd4ab6b6b4 ("ocfs2: Add the local node id to the handshake.")
Signed-off-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Reported-by: Ginger <ginger.jzllee@gmail.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ocfs2/stack_user.c | 10 +++-------
 1 file changed, 3 insertions(+), 7 deletions(-)

diff --git a/fs/ocfs2/stack_user.c b/fs/ocfs2/stack_user.c
index 5803f1dee6790d..91e19d33847c19 100644
--- a/fs/ocfs2/stack_user.c
+++ b/fs/ocfs2/stack_user.c
@@ -327,18 +327,14 @@ static int ocfs2_control_install_private(struct file *file)
 		ocfs2_control_this_node = p->op_this_node;
 		running_proto.pv_major = p->op_proto.pv_major;
 		running_proto.pv_minor = p->op_proto.pv_minor;
-	}
-
-out_unlock:
-	mutex_unlock(&ocfs2_control_lock);
-
-	if (!rc && set_p) {
-		/* We set the global values successfully */
 		atomic_inc(&ocfs2_control_opened);
 		ocfs2_control_set_handshake_state(file,
 					OCFS2_CONTROL_HANDSHAKE_VALID);
 	}
 
+out_unlock:
+	mutex_unlock(&ocfs2_control_lock);
+
 	return rc;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0481/2077] ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (479 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0480/2077] ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0482/2077] cxl/pci: Fix the incorrect check of pci_read_config_word() return Greg Kroah-Hartman
                   ` (516 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Bridges,
	syzbot+3ef989aae096b30f1663, Joseph Qi, Mark Fasheh, Joel Becker,
	Junxiao Bi, Changwei Ge, Jun Piao, Heming Zhao, Andrew Morton,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Bridges <icb@fastmail.org>

[ Upstream commit 1ec3cca2d8b6b9ff6584ca626d4c8918bbf48d44 ]

[BUG]
Unlinking a refcounted file whose refcount tree has leaf blocks
triggers a fortify panic due to an out-of-bounds write.

[CAUSE]
When the last leaf block is removed from a refcount tree,
ocfs2_remove_refcount_extent() converts the root back to leaf mode
with a bulk memset on &rb->rf_records. rf_records sits in an anonymous
union with rf_list. rf_list.l_tree_depth aliases rf_records.rl_count,
and is 0 for a single-level tree. With rl_count equal to 0, the memset
writes past the 16-byte declared size of rf_records, which the fortify
checker catches.

[FIX]
Replace the bulk memset on &rb->rf_records with a correctly-bounded
memset on rl_recs[] alone, after setting rl_count to the correct value.

Link: https://lore.kernel.org/ah3TESOsEO9j_JLU@dev
Fixes: 2f26f58df041 ("ocfs2: annotate flexible array members with __counted_by_le()")
Signed-off-by: Ian Bridges <icb@fastmail.org>
Reported-by: syzbot+3ef989aae096b30f1663@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=3ef989aae096b30f1663
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ocfs2/refcounttree.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/fs/ocfs2/refcounttree.c b/fs/ocfs2/refcounttree.c
index 8eee5be4d1ed4c..7323bde70caaf4 100644
--- a/fs/ocfs2/refcounttree.c
+++ b/fs/ocfs2/refcounttree.c
@@ -2131,10 +2131,15 @@ static int ocfs2_remove_refcount_extent(handle_t *handle,
 		rb->rf_flags = 0;
 		rb->rf_parent = 0;
 		rb->rf_cpos = 0;
-		memset(&rb->rf_records, 0, sb->s_blocksize -
-		       offsetof(struct ocfs2_refcount_block, rf_records));
+		rb->rf_records.rl_used = 0;
+		rb->rf_records.rl_reserved2 = 0;
+		rb->rf_records.rl_reserved1 = 0;
+		/* rl_count determines the memset size and fortify object size. */
 		rb->rf_records.rl_count =
 				cpu_to_le16(ocfs2_refcount_recs_per_rb(sb));
+		memset(rb->rf_records.rl_recs, 0,
+		       le16_to_cpu(rb->rf_records.rl_count) *
+		       sizeof(*rb->rf_records.rl_recs));
 	}
 
 	ocfs2_journal_dirty(handle, ref_root_bh);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0482/2077] cxl/pci: Fix the incorrect check of pci_read_config_word() return
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (480 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0481/2077] ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0483/2077] cxl/pci: Convert PCIBIOS errors to errno on DVSEC config accesses Greg Kroah-Hartman
                   ` (515 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Richard Cheng, Jonathan Cameron,
	Alison Schofield, Dave Jiang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Jiang <dave.jiang@intel.com>

[ Upstream commit 66782cfa0085369e2d8c861042f7c6d43431bdb3 ]

pci_read_config_word() returns PCIBIOS_* status on error which are
positive values. The check should be for non-zero values to indicate
error. Fix cxl_set_mem_enable() to check for non-zero return value
instead of negative value.

While fixing this, also convert the error to negative errno value when
returning on error path.

Fixes: 34e37b4c432c ("cxl/port: Enable HDM Capability after validating DVSEC Ranges")
Reviewed-by: Richard Cheng <icheng@nvidia.com>
Reviewed-by: Jonathan Cameron <jic23@kernel.org>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Assisted-by: Claude:claude-opus-4-8
Link: https://patch.msgid.link/20260604180154.1925149-2-dave.jiang@intel.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cxl/core/pci.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/cxl/core/pci.c b/drivers/cxl/core/pci.c
index d1f487b3d809ad..43885c59a7f246 100644
--- a/drivers/cxl/core/pci.c
+++ b/drivers/cxl/core/pci.c
@@ -187,8 +187,8 @@ static int cxl_set_mem_enable(struct cxl_dev_state *cxlds, u16 val)
 	int rc;
 
 	rc = pci_read_config_word(pdev, d + PCI_DVSEC_CXL_CTRL, &ctrl);
-	if (rc < 0)
-		return rc;
+	if (rc)
+		return pcibios_err_to_errno(rc);
 
 	if ((ctrl & PCI_DVSEC_CXL_MEM_ENABLE) == val)
 		return 1;
@@ -196,8 +196,8 @@ static int cxl_set_mem_enable(struct cxl_dev_state *cxlds, u16 val)
 	ctrl |= val;
 
 	rc = pci_write_config_word(pdev, d + PCI_DVSEC_CXL_CTRL, ctrl);
-	if (rc < 0)
-		return rc;
+	if (rc)
+		return pcibios_err_to_errno(rc);
 
 	return 0;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0483/2077] cxl/pci: Convert PCIBIOS errors to errno on DVSEC config accesses
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (481 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0482/2077] cxl/pci: Fix the incorrect check of pci_read_config_word() return Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0484/2077] netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures Greg Kroah-Hartman
                   ` (514 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Richard Cheng, Jonathan Cameron,
	Alison Schofield, Dave Jiang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Jiang <dave.jiang@intel.com>

[ Upstream commit 26aa60e0276272ae61b843a05a91748dcb1130f9 ]

PCI config space accessors return positive PCIBIOS_* status codes on
failure that are positive integers. Several DVSEC accesses in the CXL
core propagated these raw values to callers that test for failure against
less than 0. Thus silently misinterpret the return value as success.

Convert the positive error values to negative errno values so the checks
are correct on error paths.

While the chances of a config access failure are low, fix for correctness
and to avoid confusion in the future when more DVSEC accesses are added.

Fixes: 14d788740774 ("cxl/mem: Consolidate CXL DVSEC Range enumeration in the core")
Fixes: ce17ad0d5498 ("cxl: Wait Memory_Info_Valid before access memory related info")
Reviewed-by: Richard Cheng <icheng@nvidia.com>
Reviewed-by: Jonathan Cameron <jic23@kernel.org>
Assisted-by: Claude:claude-opus-4-8
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260604180154.1925149-3-dave.jiang@intel.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cxl/core/pci.c | 18 +++++++++---------
 1 file changed, 9 insertions(+), 9 deletions(-)

diff --git a/drivers/cxl/core/pci.c b/drivers/cxl/core/pci.c
index 43885c59a7f246..e4338fd7e01b47 100644
--- a/drivers/cxl/core/pci.c
+++ b/drivers/cxl/core/pci.c
@@ -89,7 +89,7 @@ static int cxl_dvsec_mem_range_valid(struct cxl_dev_state *cxlds, int id)
 					   d + PCI_DVSEC_CXL_RANGE_SIZE_LOW(id),
 					   &temp);
 		if (rc)
-			return rc;
+			return pcibios_err_to_errno(rc);
 
 		valid = FIELD_GET(PCI_DVSEC_CXL_MEM_INFO_VALID, temp);
 		if (valid)
@@ -123,7 +123,7 @@ static int cxl_dvsec_mem_range_active(struct cxl_dev_state *cxlds, int id)
 		rc = pci_read_config_dword(
 			pdev, d + PCI_DVSEC_CXL_RANGE_SIZE_LOW(id), &temp);
 		if (rc)
-			return rc;
+			return pcibios_err_to_errno(rc);
 
 		active = FIELD_GET(PCI_DVSEC_CXL_MEM_ACTIVE, temp);
 		if (active)
@@ -156,7 +156,7 @@ int cxl_await_media_ready(struct cxl_dev_state *cxlds)
 	rc = pci_read_config_word(pdev,
 				  d + PCI_DVSEC_CXL_CAP, &cap);
 	if (rc)
-		return rc;
+		return pcibios_err_to_errno(rc);
 
 	hdm_count = FIELD_GET(PCI_DVSEC_CXL_HDM_COUNT, cap);
 	for (i = 0; i < hdm_count; i++) {
@@ -275,7 +275,7 @@ int cxl_dvsec_rr_decode(struct cxl_dev_state *cxlds,
 
 	rc = pci_read_config_word(pdev, d + PCI_DVSEC_CXL_CAP, &cap);
 	if (rc)
-		return rc;
+		return pcibios_err_to_errno(rc);
 
 	if (!(cap & PCI_DVSEC_CXL_MEM_CAPABLE)) {
 		dev_dbg(dev, "Not MEM Capable\n");
@@ -299,7 +299,7 @@ int cxl_dvsec_rr_decode(struct cxl_dev_state *cxlds,
 	 */
 	rc = pci_read_config_word(pdev, d + PCI_DVSEC_CXL_CTRL, &ctrl);
 	if (rc)
-		return rc;
+		return pcibios_err_to_errno(rc);
 
 	info->mem_enabled = FIELD_GET(PCI_DVSEC_CXL_MEM_ENABLE, ctrl);
 	if (!info->mem_enabled)
@@ -316,14 +316,14 @@ int cxl_dvsec_rr_decode(struct cxl_dev_state *cxlds,
 		rc = pci_read_config_dword(
 			pdev, d + PCI_DVSEC_CXL_RANGE_SIZE_HIGH(i), &temp);
 		if (rc)
-			return rc;
+			return pcibios_err_to_errno(rc);
 
 		size = (u64)temp << 32;
 
 		rc = pci_read_config_dword(
 			pdev, d + PCI_DVSEC_CXL_RANGE_SIZE_LOW(i), &temp);
 		if (rc)
-			return rc;
+			return pcibios_err_to_errno(rc);
 
 		size |= temp & PCI_DVSEC_CXL_MEM_SIZE_LOW;
 		if (!size) {
@@ -333,14 +333,14 @@ int cxl_dvsec_rr_decode(struct cxl_dev_state *cxlds,
 		rc = pci_read_config_dword(
 			pdev, d + PCI_DVSEC_CXL_RANGE_BASE_HIGH(i), &temp);
 		if (rc)
-			return rc;
+			return pcibios_err_to_errno(rc);
 
 		base = (u64)temp << 32;
 
 		rc = pci_read_config_dword(
 			pdev, d + PCI_DVSEC_CXL_RANGE_BASE_LOW(i), &temp);
 		if (rc)
-			return rc;
+			return pcibios_err_to_errno(rc);
 
 		base |= temp & PCI_DVSEC_CXL_MEM_BASE_LOW;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0484/2077] netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (482 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0483/2077] cxl/pci: Convert PCIBIOS errors to errno on DVSEC config accesses Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0485/2077] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags Greg Kroah-Hartman
                   ` (513 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Fernando Fernandez Mancera,
	Pablo Neira Ayuso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fernando Fernandez Mancera <fmancera@suse.de>

[ Upstream commit a625c94144c9b66d32e1f374f909f38db46161c1 ]

The MSS calculation in nf_osf_match_one() manually shifts bytes to
construct a 16-bit value before passing it to ntohs().

This works on little-endian hosts but it does not work on big-endian as
the bytes are being always shifted and set in the same way for all
architectures.

Use get_unaligned_be16() to fix this on big-endian systems. It also
simplifies the code.

Fixes: 11eeef41d5f6 ("netfilter: passive OS fingerprint xtables match")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/netfilter/nfnetlink_osf.c | 6 +-----
 1 file changed, 1 insertion(+), 5 deletions(-)

diff --git a/net/netfilter/nfnetlink_osf.c b/net/netfilter/nfnetlink_osf.c
index acb753ec5697a5..92002079f8eab6 100644
--- a/net/netfilter/nfnetlink_osf.c
+++ b/net/netfilter/nfnetlink_osf.c
@@ -95,11 +95,7 @@ static bool nf_osf_match_one(const struct sk_buff *skb,
 
 			switch (*optp) {
 			case OSFOPT_MSS:
-				mss = optp[3];
-				mss <<= 8;
-				mss |= optp[2];
-
-				mss = ntohs((__force __be16)mss);
+				mss = get_unaligned_be16(&optp[2]);
 				break;
 			case OSFOPT_TS:
 				break;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0485/2077] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (483 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0484/2077] netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0486/2077] netfilter: synproxy: drop packets if timestamp adjustment fails Greg Kroah-Hartman
                   ` (512 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pablo Neira Ayuso <pablo@netfilter.org>

[ Upstream commit f8bf5edf7157984bb8e288c8b04fdb041223b80c ]

Conntrack helper flags are accessed from packet and netlink dump path.
Concurrent update of userspace helper flags is not possible, because the
nfnl_mutex in held on updates. These flags are only used by userspace
helpers. Use {READ,WRITE}_ONCE() to access this flags from lockless
paths.

Fixes: 12f7a505331e ("netfilter: add user-space connection tracking helper infrastructure")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/netfilter/nf_conntrack_core.c  |  4 +++-
 net/netfilter/nfnetlink_cthelper.c | 20 +++++++++++++-------
 2 files changed, 16 insertions(+), 8 deletions(-)

diff --git a/net/netfilter/nf_conntrack_core.c b/net/netfilter/nf_conntrack_core.c
index b521b5ebd66449..c072a14a306afe 100644
--- a/net/netfilter/nf_conntrack_core.c
+++ b/net/netfilter/nf_conntrack_core.c
@@ -2213,6 +2213,7 @@ static int nf_confirm_cthelper(struct sk_buff *skb, struct nf_conn *ct,
 {
 	const struct nf_conntrack_helper *helper;
 	const struct nf_conn_help *help;
+	unsigned int helper_flags;
 	int protoff;
 
 	help = nfct_help(ct);
@@ -2223,7 +2224,8 @@ static int nf_confirm_cthelper(struct sk_buff *skb, struct nf_conn *ct,
 	if (!helper)
 		return NF_ACCEPT;
 
-	if (!(helper->flags & NF_CT_HELPER_F_USERSPACE))
+	helper_flags = READ_ONCE(helper->flags);
+	if (!(helper_flags & NF_CT_HELPER_F_USERSPACE))
 		return NF_ACCEPT;
 
 	switch (nf_ct_l3num(ct)) {
diff --git a/net/netfilter/nfnetlink_cthelper.c b/net/netfilter/nfnetlink_cthelper.c
index 0d16ad82d70c01..61a2407b53bd36 100644
--- a/net/netfilter/nfnetlink_cthelper.c
+++ b/net/netfilter/nfnetlink_cthelper.c
@@ -41,8 +41,9 @@ static int
 nfnl_userspace_cthelper(struct sk_buff *skb, unsigned int protoff,
 			struct nf_conn *ct, enum ip_conntrack_info ctinfo)
 {
-	const struct nf_conn_help *help;
 	struct nf_conntrack_helper *helper;
+	const struct nf_conn_help *help;
+	unsigned int helper_flags;
 
 	help = nfct_help(ct);
 	if (help == NULL)
@@ -53,8 +54,10 @@ nfnl_userspace_cthelper(struct sk_buff *skb, unsigned int protoff,
 	if (helper == NULL)
 		return NF_DROP;
 
+	helper_flags = READ_ONCE(helper->flags);
+
 	/* This is a user-space helper not yet configured, skip. */
-	if ((helper->flags &
+	if ((helper_flags &
 	    (NF_CT_HELPER_F_USERSPACE | NF_CT_HELPER_F_CONFIGURED)) ==
 	     NF_CT_HELPER_F_USERSPACE)
 		return NF_ACCEPT;
@@ -404,10 +407,10 @@ nfnl_cthelper_update(const struct nlattr * const tb[],
 
 		switch(status) {
 		case NFCT_HELPER_STATUS_ENABLED:
-			helper->flags |= NF_CT_HELPER_F_CONFIGURED;
+			WRITE_ONCE(helper->flags, helper->flags | NF_CT_HELPER_F_CONFIGURED);
 			break;
 		case NFCT_HELPER_STATUS_DISABLED:
-			helper->flags &= ~NF_CT_HELPER_F_CONFIGURED;
+			WRITE_ONCE(helper->flags, helper->flags & ~NF_CT_HELPER_F_CONFIGURED);
 			break;
 		}
 	}
@@ -529,8 +532,8 @@ static int
 nfnl_cthelper_fill_info(struct sk_buff *skb, u32 portid, u32 seq, u32 type,
 			int event, struct nf_conntrack_helper *helper)
 {
-	struct nlmsghdr *nlh;
 	unsigned int flags = portid ? NLM_F_MULTI : 0;
+	struct nlmsghdr *nlh;
 	int status;
 
 	event = nfnl_msg_type(NFNL_SUBSYS_CTHELPER, event);
@@ -554,7 +557,7 @@ nfnl_cthelper_fill_info(struct sk_buff *skb, u32 portid, u32 seq, u32 type,
 	if (nla_put_be32(skb, NFCTH_PRIV_DATA_LEN, htonl(helper->data_len)))
 		goto nla_put_failure;
 
-	if (helper->flags & NF_CT_HELPER_F_CONFIGURED)
+	if (READ_ONCE(helper->flags) & NF_CT_HELPER_F_CONFIGURED)
 		status = NFCT_HELPER_STATUS_ENABLED;
 	else
 		status = NFCT_HELPER_STATUS_DISABLED;
@@ -575,6 +578,7 @@ static int
 nfnl_cthelper_dump_table(struct sk_buff *skb, struct netlink_callback *cb)
 {
 	struct nf_conntrack_helper *cur, *last;
+	unsigned int helper_flags;
 
 	rcu_read_lock();
 	last = (struct nf_conntrack_helper *)cb->args[1];
@@ -583,8 +587,10 @@ nfnl_cthelper_dump_table(struct sk_buff *skb, struct netlink_callback *cb)
 		hlist_for_each_entry_rcu(cur,
 				&nf_ct_helper_hash[cb->args[0]], hnode) {
 
+			helper_flags = READ_ONCE(cur->flags);
+
 			/* skip non-userspace conntrack helpers. */
-			if (!(cur->flags & NF_CT_HELPER_F_USERSPACE))
+			if (!(helper_flags & NF_CT_HELPER_F_USERSPACE))
 				continue;
 
 			if (cb->args[1]) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0486/2077] netfilter: synproxy: drop packets if timestamp adjustment fails
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (484 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0485/2077] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0487/2077] netfilter: synproxy: adjust duplicate timestamp options Greg Kroah-Hartman
                   ` (511 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Fernando Fernandez Mancera,
	Pablo Neira Ayuso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fernando Fernandez Mancera <fmancera@suse.de>

[ Upstream commit 63d29ee95c4ab5976d660182d2e4733bb4a091d8 ]

If a packet was malformed or if skb_ensure_writable() failed, the
synproxy_tstamp_adjust() function returned 0 indicating an error but it
was ignored on the callers.

Make the function return a boolean instead to clarify the result and
drop the packet if synproxy_tstamp_adjust() failed due to ENOMEM from
skb_ensure_writable(). In addition, if there are malformed options, skip
the tstamp update but do not drop the packet as that should be done by
the policy directly.

Fixes: 48b1de4c110a ("netfilter: add SYNPROXY core/target")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/netfilter/nf_synproxy_core.c | 22 +++++++++++++---------
 1 file changed, 13 insertions(+), 9 deletions(-)

diff --git a/net/netfilter/nf_synproxy_core.c b/net/netfilter/nf_synproxy_core.c
index ed00114f65f392..f99c22f57b7e52 100644
--- a/net/netfilter/nf_synproxy_core.c
+++ b/net/netfilter/nf_synproxy_core.c
@@ -184,7 +184,7 @@ synproxy_check_timestamp_cookie(struct synproxy_options *opts)
 	opts->options |= opts->tsecr & (1 << 5) ? NF_SYNPROXY_OPT_ECN : 0;
 }
 
-static unsigned int
+static bool
 synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
 		       struct tcphdr *th, struct nf_conn *ct,
 		       enum ip_conntrack_info ctinfo,
@@ -194,13 +194,13 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
 	__be32 *ptr, old;
 
 	if (synproxy->tsoff == 0)
-		return 1;
+		return true;
 
 	optoff = protoff + sizeof(struct tcphdr);
 	optend = protoff + th->doff * 4;
 
 	if (skb_ensure_writable(skb, optend))
-		return 0;
+		return false;
 
 	th = (struct tcphdr *)(skb->data + protoff);
 
@@ -209,7 +209,7 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
 
 		switch (op[0]) {
 		case TCPOPT_EOL:
-			return 1;
+			return true;
 		case TCPOPT_NOP:
 			optoff++;
 			continue;
@@ -217,7 +217,7 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
 			if (optoff + 1 == optend ||
 			    optoff + op[1] > optend ||
 			    op[1] < 2)
-				return 0;
+				return true;
 			if (op[0] == TCPOPT_TIMESTAMP &&
 			    op[1] == TCPOLEN_TIMESTAMP) {
 				if (CTINFO2DIR(ctinfo) == IP_CT_DIR_REPLY) {
@@ -233,12 +233,12 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
 				}
 				inet_proto_csum_replace4(&th->check, skb,
 							 old, *ptr, false);
-				return 1;
+				return true;
 			}
 			optoff += op[1];
 		}
 	}
-	return 1;
+	return true;
 }
 
 #ifdef CONFIG_PROC_FS
@@ -749,7 +749,9 @@ ipv4_synproxy_hook(void *priv, struct sk_buff *skb,
 		break;
 	}
 
-	synproxy_tstamp_adjust(skb, thoff, th, ct, ctinfo, synproxy);
+	if (!synproxy_tstamp_adjust(skb, thoff, th, ct, ctinfo, synproxy))
+		return NF_DROP_REASON(skb, SKB_DROP_REASON_NETFILTER_DROP, ENOMEM);
+
 	return NF_ACCEPT;
 }
 EXPORT_SYMBOL_GPL(ipv4_synproxy_hook);
@@ -1177,7 +1179,9 @@ ipv6_synproxy_hook(void *priv, struct sk_buff *skb,
 		break;
 	}
 
-	synproxy_tstamp_adjust(skb, thoff, th, ct, ctinfo, synproxy);
+	if (!synproxy_tstamp_adjust(skb, thoff, th, ct, ctinfo, synproxy))
+		return NF_DROP_REASON(skb, SKB_DROP_REASON_NETFILTER_DROP, ENOMEM);
+
 	return NF_ACCEPT;
 }
 EXPORT_SYMBOL_GPL(ipv6_synproxy_hook);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0487/2077] netfilter: synproxy: adjust duplicate timestamp options
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (485 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0486/2077] netfilter: synproxy: drop packets if timestamp adjustment fails Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0488/2077] netfilter: synproxy: fix unaligned memory access in timestamp adjustment Greg Kroah-Hartman
                   ` (510 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Fernando Fernandez Mancera,
	Pablo Neira Ayuso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fernando Fernandez Mancera <fmancera@suse.de>

[ Upstream commit 22bb132cfb9b94847d52d73614284b8c5ea8d36e ]

RFC 9293 does not mention anything about duplicated options and each
networking stack handles it in their own way. Currently, Linux kernel is
processing options sequentially and in case of duplicated timestamp
options, the value from the latest one overrides the others.

As SYNPROXY is modifying only the first timestamp option found, a packet
can reach the backend server and it might parse the wrong timestamp
value. Let's just continue parsing the following options and in case a
duplicated timestamp is found, adjust it too.

Fixes: 48b1de4c110a ("netfilter: add SYNPROXY core/target")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/netfilter/nf_synproxy_core.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/net/netfilter/nf_synproxy_core.c b/net/netfilter/nf_synproxy_core.c
index f99c22f57b7e52..a0bcf188810d13 100644
--- a/net/netfilter/nf_synproxy_core.c
+++ b/net/netfilter/nf_synproxy_core.c
@@ -233,7 +233,6 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
 				}
 				inet_proto_csum_replace4(&th->check, skb,
 							 old, *ptr, false);
-				return true;
 			}
 			optoff += op[1];
 		}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0488/2077] netfilter: synproxy: fix unaligned memory access in timestamp adjustment
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (486 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0487/2077] netfilter: synproxy: adjust duplicate timestamp options Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0489/2077] netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock Greg Kroah-Hartman
                   ` (509 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Fernando Fernandez Mancera,
	Pablo Neira Ayuso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fernando Fernandez Mancera <fmancera@suse.de>

[ Upstream commit 992c20bc8a4aba220c8b95b467d049289778dad6 ]

Use get_unaligned_be32() and put_unaligned_be32() to safely read and
write the timestamp fields. This prevents performance degradation due to
unaligned memory access or even a crash on strict alignment
architectures.

This follows the implementation of timestamp parsing in the networking
stack at tcp_parse_options() and synproxy_parse_options().

Fixes: 48b1de4c110a ("netfilter: add SYNPROXY core/target")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/netfilter/nf_synproxy_core.c | 19 +++++++++----------
 1 file changed, 9 insertions(+), 10 deletions(-)

diff --git a/net/netfilter/nf_synproxy_core.c b/net/netfilter/nf_synproxy_core.c
index a0bcf188810d13..acd360515972f7 100644
--- a/net/netfilter/nf_synproxy_core.c
+++ b/net/netfilter/nf_synproxy_core.c
@@ -191,7 +191,7 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
 		       const struct nf_conn_synproxy *synproxy)
 {
 	unsigned int optoff, optend;
-	__be32 *ptr, old;
+	u32 new, old;
 
 	if (synproxy->tsoff == 0)
 		return true;
@@ -221,18 +221,17 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
 			if (op[0] == TCPOPT_TIMESTAMP &&
 			    op[1] == TCPOLEN_TIMESTAMP) {
 				if (CTINFO2DIR(ctinfo) == IP_CT_DIR_REPLY) {
-					ptr = (__be32 *)&op[2];
-					old = *ptr;
-					*ptr = htonl(ntohl(*ptr) -
-						     synproxy->tsoff);
+					old = get_unaligned_be32(&op[2]);
+					new = old - synproxy->tsoff;
+					put_unaligned_be32(new, &op[2]);
 				} else {
-					ptr = (__be32 *)&op[6];
-					old = *ptr;
-					*ptr = htonl(ntohl(*ptr) +
-						     synproxy->tsoff);
+					old = get_unaligned_be32(&op[6]);
+					new = old + synproxy->tsoff;
+					put_unaligned_be32(new, &op[6]);
 				}
 				inet_proto_csum_replace4(&th->check, skb,
-							 old, *ptr, false);
+							 cpu_to_be32(old),
+							 cpu_to_be32(new), false);
 			}
 			optoff += op[1];
 		}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0489/2077] netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (487 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0488/2077] netfilter: synproxy: fix unaligned memory access in timestamp adjustment Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0490/2077] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount Greg Kroah-Hartman
                   ` (508 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Fernando Fernandez Mancera,
	Pablo Neira Ayuso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fernando Fernandez Mancera <fmancera@suse.de>

[ Upstream commit 9e37388b8070afe73d4ab2d973b28593ed65f3ad ]

nf_ct_seqadj_init() is called without holding the ct lock. This can race
with nf_ct_seq_adjust() when a connection is in CLOSE state due to an
RST or connection reopening. In addition for SYN_RECV state, concurrent
processing of packets can trigger nf_ct_seq_adjust() too. These
situations create a read/write data race.

As synproxy is the only user of nf_ct_seqadj_init() at the moment, fix
this by holding ct->lock inside nf_ct_seqadj_init() until all is done.

Fixes: 48b1de4c110a ("netfilter: add SYNPROXY core/target")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/netfilter/nf_conntrack_seqadj.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/net/netfilter/nf_conntrack_seqadj.c b/net/netfilter/nf_conntrack_seqadj.c
index 7ab2b25b57bcc0..b7e99f34dfce86 100644
--- a/net/netfilter/nf_conntrack_seqadj.c
+++ b/net/netfilter/nf_conntrack_seqadj.c
@@ -17,12 +17,14 @@ int nf_ct_seqadj_init(struct nf_conn *ct, enum ip_conntrack_info ctinfo,
 	if (off == 0)
 		return 0;
 
+	spin_lock_bh(&ct->lock);
 	set_bit(IPS_SEQ_ADJUST_BIT, &ct->status);
 
 	seqadj = nfct_seqadj(ct);
 	this_way = &seqadj->seq[dir];
 	this_way->offset_before	 = off;
 	this_way->offset_after	 = off;
+	spin_unlock_bh(&ct->lock);
 	return 0;
 }
 EXPORT_SYMBOL_GPL(nf_ct_seqadj_init);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0490/2077] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (488 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0489/2077] netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0491/2077] ALSA: usb-audio: qcom: Initialize offload control return value Greg Kroah-Hartman
                   ` (507 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pablo Neira Ayuso <pablo@netfilter.org>

[ Upstream commit 7d6a9cdb8d3a51d9cfe546a09a518ab3d2671549 ]

Add a refcount for struct nf_ct_timeout which is used by ct extension to
set the custom ct timeout policy, this tells us that the ct timeout is
being used by a conntrack entry. When the last conntrack entry drops the
refcount on the ct timeout, the ct timeout is released.

Remove the refcount for control plane which controls if the ruleset
refers to the timeout policy. After this update, it is possible to
remove the ct timeout policy from nfnetlink_cttimeout immediately.
This is for simplicity not to handle two refcounts on a single object.

Remove nf_queue_nf_hook_drop(): a packet sitting in nfqueue will just
hold a reference to the nf_ct_timeout object until packet is reinjected,
since this is part of the ct extension, this will be released by the
time the conntrack is freed.

nf_ct_untimeout() is still called to clean up in a best effort basis:
the ct timeout on existing entries gets removed when the ct timeout goes
away, but as long as the iptables ruleset still refers to the ct timeout
through a template, new conntracks may keep attaching it and extend its
lifetime until the rule is removed.

nf_ct_untimeout() is not called anymore from module removal path, this
is unlikely to find timeouts give module refcount is bumped, and the new
refcount already tracks the ct timeout policy use so it is released when
unused.

Fixes: 50978462300f ("netfilter: add cttimeout infrastructure for fine timeout tuning")
Fixes: 7e0b2b57f01d ("netfilter: nft_ct: add ct timeout support")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/net/netfilter/nf_conntrack_timeout.h |  27 ++++-
 net/netfilter/nf_conntrack_core.c            |   6 +-
 net/netfilter/nf_conntrack_timeout.c         |  27 ++++-
 net/netfilter/nfnetlink_cttimeout.c          | 112 +++++++++----------
 net/netfilter/nft_ct.c                       |   7 +-
 net/netfilter/xt_CT.c                        |   2 +-
 6 files changed, 107 insertions(+), 74 deletions(-)

diff --git a/include/net/netfilter/nf_conntrack_timeout.h b/include/net/netfilter/nf_conntrack_timeout.h
index 3a66d4abb6d688..d60aa86be01945 100644
--- a/include/net/netfilter/nf_conntrack_timeout.h
+++ b/include/net/netfilter/nf_conntrack_timeout.h
@@ -12,6 +12,7 @@
 #define CTNL_TIMEOUT_NAME_MAX	32
 
 struct nf_ct_timeout {
+	refcount_t		refcnt;
 	__u16			l3num;
 	const struct nf_conntrack_l4proto *l4proto;
 	struct rcu_head		rcu;
@@ -22,6 +23,22 @@ struct nf_conn_timeout {
 	struct nf_ct_timeout __rcu *timeout;
 };
 
+static inline void nf_ct_timeout_put(const struct nf_conn *ct)
+{
+#ifdef CONFIG_NF_CONNTRACK_TIMEOUT
+	struct nf_conn_timeout *timeout_ext;
+	struct nf_ct_timeout *timeout;
+
+	timeout_ext = nf_ct_ext_find(ct, NF_CT_EXT_TIMEOUT);
+	if (!timeout_ext)
+		return;
+
+	timeout = rcu_dereference(timeout_ext->timeout);
+	if (timeout && refcount_dec_and_test(&timeout->refcnt))
+		kfree_rcu(timeout, rcu);
+#endif
+}
+
 static inline unsigned int *
 nf_ct_timeout_data(const struct nf_conn_timeout *t)
 {
@@ -56,8 +73,14 @@ struct nf_conn_timeout *nf_ct_timeout_ext_add(struct nf_conn *ct,
 #ifdef CONFIG_NF_CONNTRACK_TIMEOUT
 	struct nf_conn_timeout *timeout_ext;
 
+	if (!timeout)
+		return NULL;
+
 	timeout_ext = nf_ct_ext_add(ct, NF_CT_EXT_TIMEOUT, gfp);
-	if (timeout_ext == NULL)
+	if (!timeout_ext || timeout_ext->timeout)
+		return NULL;
+
+	if (!refcount_inc_not_zero(&timeout->refcnt))
 		return NULL;
 
 	rcu_assign_pointer(timeout_ext->timeout, timeout);
@@ -75,7 +98,7 @@ static inline unsigned int *nf_ct_timeout_lookup(const struct nf_conn *ct)
 	struct nf_conn_timeout *timeout_ext;
 
 	timeout_ext = nf_ct_timeout_find(ct);
-	if (timeout_ext)
+	if (timeout_ext && rcu_access_pointer(timeout_ext->timeout))
 		timeouts = nf_ct_timeout_data(timeout_ext);
 #endif
 	return timeouts;
diff --git a/net/netfilter/nf_conntrack_core.c b/net/netfilter/nf_conntrack_core.c
index c072a14a306afe..a45b732393693a 100644
--- a/net/netfilter/nf_conntrack_core.c
+++ b/net/netfilter/nf_conntrack_core.c
@@ -1737,16 +1737,18 @@ void nf_conntrack_free(struct nf_conn *ct)
 	 */
 	WARN_ON(refcount_read(&ct->ct_general.use) != 0);
 
+	rcu_read_lock();
 	if (ct->status & IPS_SRC_NAT_DONE) {
 		const struct nf_nat_hook *nat_hook;
 
-		rcu_read_lock();
 		nat_hook = rcu_dereference(nf_nat_hook);
 		if (nat_hook)
 			nat_hook->remove_nat_bysrc(ct);
-		rcu_read_unlock();
 	}
 
+	nf_ct_timeout_put(ct);
+	rcu_read_unlock();
+
 	kfree(ct->ext);
 	kmem_cache_free(nf_conntrack_cachep, ct);
 	cnet = nf_ct_pernet(net);
diff --git a/net/netfilter/nf_conntrack_timeout.c b/net/netfilter/nf_conntrack_timeout.c
index 0cc584d3dbb1d0..c81becde2afa9f 100644
--- a/net/netfilter/nf_conntrack_timeout.c
+++ b/net/netfilter/nf_conntrack_timeout.c
@@ -25,17 +25,32 @@
 const struct nf_ct_timeout_hooks __rcu *nf_ct_timeout_hook __read_mostly;
 EXPORT_SYMBOL_GPL(nf_ct_timeout_hook);
 
+/* nf_ct_iterate_cleanup() holds the conntrack lock. */
 static int untimeout(struct nf_conn *ct, void *timeout)
 {
 	struct nf_conn_timeout *timeout_ext = nf_ct_timeout_find(ct);
 
 	if (timeout_ext) {
-		const struct nf_ct_timeout *t;
+		struct nf_ct_timeout *t;
 
-		t = rcu_access_pointer(timeout_ext->timeout);
+		rcu_read_lock();
+		t = rcu_dereference(timeout_ext->timeout);
+		if (!t) {
+			rcu_read_unlock();
+			return 0;
+		}
 
-		if (!timeout || t == timeout)
+		if (!timeout || t == timeout) {
 			RCU_INIT_POINTER(timeout_ext->timeout, NULL);
+
+			/* No race with nf_conntrack_free() which is called
+			 * only after the conntrack has been removed from
+			 * the hashes.
+			 */
+			if (refcount_dec_and_test(&t->refcnt))
+				kfree_rcu(t, rcu);
+		}
+		rcu_read_unlock();
 	}
 
 	/* We are not intended to delete this conntrack. */
@@ -70,6 +85,8 @@ int nf_ct_set_timeout(struct net *net, struct nf_conn *ct,
 	const char *errmsg = NULL;
 	int ret = 0;
 
+	WARN_ON_ONCE(!nf_ct_is_template(ct));
+
 	rcu_read_lock();
 	h = rcu_dereference(nf_ct_timeout_hook);
 	if (!h) {
@@ -127,6 +144,8 @@ void nf_ct_destroy_timeout(struct nf_conn *ct)
 	struct nf_conn_timeout *timeout_ext;
 	const struct nf_ct_timeout_hooks *h;
 
+	WARN_ON_ONCE(!nf_ct_is_template(ct));
+
 	rcu_read_lock();
 	h = rcu_dereference(nf_ct_timeout_hook);
 
@@ -139,6 +158,8 @@ void nf_ct_destroy_timeout(struct nf_conn *ct)
 			if (t)
 				h->timeout_put(t);
 			RCU_INIT_POINTER(timeout_ext->timeout, NULL);
+			if (t && refcount_dec_and_test(&t->refcnt))
+				kfree_rcu(t, rcu);
 		}
 	}
 	rcu_read_unlock();
diff --git a/net/netfilter/nfnetlink_cttimeout.c b/net/netfilter/nfnetlink_cttimeout.c
index dca6826af7de3f..170d3db860c564 100644
--- a/net/netfilter/nfnetlink_cttimeout.c
+++ b/net/netfilter/nfnetlink_cttimeout.c
@@ -37,11 +37,8 @@ struct ctnl_timeout {
 	struct list_head	head;
 	struct list_head	free_head;
 	struct rcu_head		rcu_head;
-	refcount_t		refcnt;
 	char			name[CTNL_TIMEOUT_NAME_MAX];
-
-	/* must be at the end */
-	struct nf_ct_timeout	timeout;
+	struct nf_ct_timeout	*timeout;
 };
 
 struct nfct_timeout_pernet {
@@ -132,12 +129,12 @@ static int cttimeout_new_timeout(struct sk_buff *skb,
 			/* You cannot replace one timeout policy by another of
 			 * different kind, sorry.
 			 */
-			if (matching->timeout.l3num != l3num ||
-			    matching->timeout.l4proto->l4proto != l4num)
+			if (matching->timeout->l3num != l3num ||
+			    matching->timeout->l4proto->l4proto != l4num)
 				return -EINVAL;
 
-			return ctnl_timeout_parse_policy(&matching->timeout.data,
-							 matching->timeout.l4proto,
+			return ctnl_timeout_parse_policy(&matching->timeout->data,
+							 matching->timeout->l4proto,
 							 info->net,
 							 cda[CTA_TIMEOUT_DATA]);
 		}
@@ -153,26 +150,35 @@ static int cttimeout_new_timeout(struct sk_buff *skb,
 		goto err_proto_put;
 	}
 
-	timeout = kzalloc(sizeof(struct ctnl_timeout) +
-			  l4proto->ctnl_timeout.obj_size, GFP_KERNEL);
+	timeout = kzalloc(sizeof(*timeout), GFP_KERNEL);
 	if (timeout == NULL) {
 		ret = -ENOMEM;
 		goto err_proto_put;
 	}
 
-	ret = ctnl_timeout_parse_policy(&timeout->timeout.data, l4proto,
+	timeout->timeout = kzalloc(sizeof(*timeout->timeout) +
+				   l4proto->ctnl_timeout.obj_size, GFP_KERNEL);
+	if (!timeout->timeout) {
+		ret = -ENOMEM;
+		goto err;
+	}
+
+	ret = ctnl_timeout_parse_policy(&timeout->timeout->data, l4proto,
 					info->net, cda[CTA_TIMEOUT_DATA]);
 	if (ret < 0)
-		goto err;
+		goto err_free_timeout_policy;
 
 	strcpy(timeout->name, nla_data(cda[CTA_TIMEOUT_NAME]));
-	timeout->timeout.l3num = l3num;
-	timeout->timeout.l4proto = l4proto;
-	refcount_set(&timeout->refcnt, 1);
+	timeout->timeout->l3num = l3num;
+	timeout->timeout->l4proto = l4proto;
+	refcount_set(&timeout->timeout->refcnt, 1);
 	__module_get(THIS_MODULE);
 	list_add_tail_rcu(&timeout->head, &pernet->nfct_timeout_list);
 
 	return 0;
+
+err_free_timeout_policy:
+	kfree(timeout->timeout);
 err:
 	kfree(timeout);
 err_proto_put:
@@ -185,7 +191,7 @@ ctnl_timeout_fill_info(struct sk_buff *skb, u32 portid, u32 seq, u32 type,
 {
 	struct nlmsghdr *nlh;
 	unsigned int flags = portid ? NLM_F_MULTI : 0;
-	const struct nf_conntrack_l4proto *l4proto = timeout->timeout.l4proto;
+	const struct nf_conntrack_l4proto *l4proto = timeout->timeout->l4proto;
 	struct nlattr *nest_parms;
 	int ret;
 
@@ -197,17 +203,17 @@ ctnl_timeout_fill_info(struct sk_buff *skb, u32 portid, u32 seq, u32 type,
 
 	if (nla_put_string(skb, CTA_TIMEOUT_NAME, timeout->name) ||
 	    nla_put_be16(skb, CTA_TIMEOUT_L3PROTO,
-			 htons(timeout->timeout.l3num)) ||
+			 htons(timeout->timeout->l3num)) ||
 	    nla_put_u8(skb, CTA_TIMEOUT_L4PROTO, l4proto->l4proto) ||
 	    nla_put_be32(skb, CTA_TIMEOUT_USE,
-			 htonl(refcount_read(&timeout->refcnt))))
+			 htonl(refcount_read(&timeout->timeout->refcnt))))
 		goto nla_put_failure;
 
 	nest_parms = nla_nest_start(skb, CTA_TIMEOUT_DATA);
 	if (!nest_parms)
 		goto nla_put_failure;
 
-	ret = l4proto->ctnl_timeout.obj_to_nlattr(skb, &timeout->timeout.data);
+	ret = l4proto->ctnl_timeout.obj_to_nlattr(skb, &timeout->timeout->data);
 	if (ret < 0)
 		goto nla_put_failure;
 
@@ -307,23 +313,17 @@ static int cttimeout_get_timeout(struct sk_buff *skb,
 	return ret;
 }
 
-/* try to delete object, fail if it is still in use. */
-static int ctnl_timeout_try_del(struct net *net, struct ctnl_timeout *timeout)
+static void ctnl_timeout_del(struct net *net, struct ctnl_timeout *timeout)
 {
-	int ret = 0;
+	/* We are protected by nfnl mutex. */
+	list_del_rcu(&timeout->head);
+	nf_ct_untimeout(net, timeout->timeout);
 
-	/* We want to avoid races with ctnl_timeout_put. So only when the
-	 * current refcnt is 1, we decrease it to 0.
-	 */
-	if (refcount_dec_if_one(&timeout->refcnt)) {
-		/* We are protected by nfnl mutex. */
-		list_del_rcu(&timeout->head);
-		nf_ct_untimeout(net, &timeout->timeout);
-		kfree_rcu(timeout, rcu_head);
-	} else {
-		ret = -EBUSY;
-	}
-	return ret;
+	if (refcount_dec_and_test(&timeout->timeout->refcnt))
+		kfree_rcu(timeout->timeout, rcu);
+
+	kfree_rcu(timeout, rcu_head);
+	module_put(THIS_MODULE);
 }
 
 static int cttimeout_del_timeout(struct sk_buff *skb,
@@ -338,7 +338,7 @@ static int cttimeout_del_timeout(struct sk_buff *skb,
 	if (!cda[CTA_TIMEOUT_NAME]) {
 		list_for_each_entry_safe(cur, tmp, &pernet->nfct_timeout_list,
 					 head)
-			ctnl_timeout_try_del(info->net, cur);
+			ctnl_timeout_del(info->net, cur);
 
 		return 0;
 	}
@@ -348,10 +348,8 @@ static int cttimeout_del_timeout(struct sk_buff *skb,
 		if (strncmp(cur->name, name, CTNL_TIMEOUT_NAME_MAX) != 0)
 			continue;
 
-		ret = ctnl_timeout_try_del(info->net, cur);
-		if (ret < 0)
-			return ret;
-
+		ctnl_timeout_del(info->net, cur);
+		ret = 0;
 		break;
 	}
 	return ret;
@@ -511,24 +509,22 @@ static struct nf_ct_timeout *ctnl_timeout_find_get(struct net *net,
 		if (strncmp(timeout->name, name, CTNL_TIMEOUT_NAME_MAX) != 0)
 			continue;
 
-		if (!refcount_inc_not_zero(&timeout->refcnt))
+		if (!refcount_inc_not_zero(&timeout->timeout->refcnt))
 			goto err;
 		matching = timeout;
+		__module_get(THIS_MODULE);
 		break;
 	}
 err:
-	return matching ? &matching->timeout : NULL;
+	return matching ? matching->timeout : NULL;
 }
 
-static void ctnl_timeout_put(struct nf_ct_timeout *t)
+static void ctnl_timeout_put(struct nf_ct_timeout *timeout)
 {
-	struct ctnl_timeout *timeout =
-		container_of(t, struct ctnl_timeout, timeout);
+	if (refcount_dec_and_test(&timeout->refcnt))
+		kfree_rcu(timeout, rcu);
 
-	if (refcount_dec_and_test(&timeout->refcnt)) {
-		kfree_rcu(timeout, rcu_head);
-		module_put(THIS_MODULE);
-	}
+	module_put(THIS_MODULE);
 }
 
 static const struct nfnl_callback cttimeout_cb[IPCTNL_MSG_TIMEOUT_MAX] = {
@@ -609,8 +605,11 @@ static void __net_exit cttimeout_net_exit(struct net *net)
 	list_for_each_entry_safe(cur, tmp, &pernet->nfct_timeout_freelist, free_head) {
 		list_del(&cur->free_head);
 
-		if (refcount_dec_and_test(&cur->refcnt))
-			kfree_rcu(cur, rcu_head);
+		if (refcount_dec_and_test(&cur->timeout->refcnt))
+			kfree_rcu(cur->timeout, rcu);
+
+		kfree_rcu(cur, rcu_head);
+		module_put(THIS_MODULE);
 	}
 }
 
@@ -649,24 +648,13 @@ static int __init cttimeout_init(void)
 	return ret;
 }
 
-static int untimeout(struct nf_conn *ct, void *timeout)
-{
-	struct nf_conn_timeout *timeout_ext = nf_ct_timeout_find(ct);
-
-	if (timeout_ext)
-		RCU_INIT_POINTER(timeout_ext->timeout, NULL);
-
-	return 0;
-}
-
 static void __exit cttimeout_exit(void)
 {
 	nfnetlink_subsys_unregister(&cttimeout_subsys);
 
 	unregister_pernet_subsys(&cttimeout_ops);
 	RCU_INIT_POINTER(nf_ct_timeout_hook, NULL);
-
-	nf_ct_iterate_destroy(untimeout, NULL);
+	synchronize_net();
 }
 
 module_init(cttimeout_init);
diff --git a/net/netfilter/nft_ct.c b/net/netfilter/nft_ct.c
index 357513c6dcea08..801c01c6af95fc 100644
--- a/net/netfilter/nft_ct.c
+++ b/net/netfilter/nft_ct.c
@@ -897,8 +897,6 @@ static void nft_ct_timeout_obj_eval(struct nft_object *obj,
 		}
 	}
 
-	rcu_assign_pointer(timeout->timeout, priv->timeout);
-
 	/* adjust the timeout as per 'new' state. ct is unconfirmed,
 	 * so the current timestamp must not be added.
 	 */
@@ -949,6 +947,7 @@ static int nft_ct_timeout_obj_init(const struct nft_ctx *ctx,
 
 	timeout->l3num = l3num;
 	timeout->l4proto = l4proto;
+	refcount_set(&timeout->refcnt, 1);
 
 	ret = nf_ct_netns_get(ctx->net, ctx->family);
 	if (ret < 0)
@@ -969,10 +968,10 @@ static void nft_ct_timeout_obj_destroy(const struct nft_ctx *ctx,
 	struct nft_ct_timeout_obj *priv = nft_obj_data(obj);
 	struct nf_ct_timeout *timeout = priv->timeout;
 
-	nf_queue_nf_hook_drop(ctx->net);
 	nf_ct_untimeout(ctx->net, timeout);
 	nf_ct_netns_put(ctx->net, ctx->family);
-	kfree_rcu(priv->timeout, rcu);
+	if (refcount_dec_and_test(&timeout->refcnt))
+		kfree_rcu(priv->timeout, rcu);
 }
 
 static int nft_ct_timeout_obj_dump(struct sk_buff *skb,
diff --git a/net/netfilter/xt_CT.c b/net/netfilter/xt_CT.c
index d2aeacf94230f8..b94f004d5f5c27 100644
--- a/net/netfilter/xt_CT.c
+++ b/net/netfilter/xt_CT.c
@@ -284,7 +284,7 @@ static void xt_ct_tg_destroy(const struct xt_tgdtor_param *par,
 	struct nf_conn_help *help;
 
 	if (ct) {
-		if (info->helper[0] || info->timeout[0])
+		if (info->helper[0])
 			nf_queue_nf_hook_drop(par->net);
 
 		help = nfct_help(ct);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0491/2077] ALSA: usb-audio: qcom: Initialize offload control return value
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (489 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0490/2077] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0492/2077] mm/slub: preserve original size in _kmalloc_nolock_noprof retry path Greg Kroah-Hartman
                   ` (506 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Takashi Iwai,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cássio Gabriel <cassiogabrielcontato@gmail.com>

[ Upstream commit 2b5632d72fca0841bea283da2e3a478d24118508 ]

snd_usb_offload_create_ctl() returns ret after walking the USB PCM list,
but ret is only assigned after a playback stream passes the endpoint and
PCM-index filters.

If all playback streams are skipped, for example because there is no
playback endpoint or because all PCM indexes exceed the 0xff control
range, the function returns an uninitialized stack value.

Initialize ret to 0 so the no-control-created path returns deterministic
success, while preserving the existing negative error return when
snd_ctl_add() fails.

Fixes: a67656f011d1 ("ALSA: usb-audio: qcom: Add USB offload route kcontrol")
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260605-alsa-usb-qcom-offload-ret-init-v1-1-dc72fcc4bd3b@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/usb/qcom/mixer_usb_offload.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/usb/qcom/mixer_usb_offload.c b/sound/usb/qcom/mixer_usb_offload.c
index 2adeb64f4d33f4..005138714f7249 100644
--- a/sound/usb/qcom/mixer_usb_offload.c
+++ b/sound/usb/qcom/mixer_usb_offload.c
@@ -113,7 +113,7 @@ int snd_usb_offload_create_ctl(struct snd_usb_audio *chip, struct device *bedev)
 	struct snd_usb_substream *subs;
 	struct snd_usb_stream *as;
 	char ctl_name[48];
-	int ret;
+	int ret = 0;
 
 	list_for_each_entry(as, &chip->pcm_list, list) {
 		subs = &as->substream[SNDRV_PCM_STREAM_PLAYBACK];
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0492/2077] mm/slub: preserve original size in _kmalloc_nolock_noprof retry path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (490 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0491/2077] ALSA: usb-audio: qcom: Initialize offload control return value Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0493/2077] x86/cpu: Remove obsolete aperfmperf_get_khz() declaration Greg Kroah-Hartman
                   ` (505 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shengming Hu, Harry Yoo (Oracle),
	Hao Li, Vlastimil Babka (SUSE), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shengming Hu <hu.shengming@zte.com.cn>

[ Upstream commit 19b206b9534a85266efa78febeb4ae185e75bccd ]

_kmalloc_nolock_noprof() retries from the next kmalloc bucket when the
initial allocation fails. The retry currently reuses `size` as the
bucket selector and overwrites it with s->object_size + 1.

That value is later passed as the original allocation size to
__slab_alloc_node(), slab_post_alloc_hook() and kasan_kmalloc(). On a
successful retry this makes KASAN/slub-debug observe the retry bucket
selector rather than the caller requested size, potentially widening the
valid kmalloc range and hiding overflows.

Keep the caller requested size separately as orig_size and pass it to
the allocation/debug/KASAN paths. Continue using `size` as the retry cache
selector.

Fixes: af92793e52c3 ("slab: Introduce kmalloc_nolock() and kfree_nolock()")
Signed-off-by: Shengming Hu <hu.shengming@zte.com.cn>
Reviewed-by: Harry Yoo (Oracle) <harry@kernel.org>
Reviewed-by: Hao Li <hao.li@linux.dev>
Link: https://patch.msgid.link/202606042027323804pk3MRY42Jy7y42OHAhQZ@zte.com.cn
Signed-off-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 mm/slub.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/mm/slub.c b/mm/slub.c
index 9365501d0df148..eed3251eb7d0cc 100644
--- a/mm/slub.c
+++ b/mm/slub.c
@@ -5325,6 +5325,7 @@ EXPORT_SYMBOL(__kmalloc_noprof);
 void *kmalloc_nolock_noprof(size_t size, gfp_t gfp_flags, int node)
 {
 	gfp_t alloc_gfp = __GFP_NOWARN | __GFP_NOMEMALLOC | gfp_flags;
+	size_t orig_size = size;
 	struct kmem_cache *s;
 	bool can_retry = true;
 	void *ret;
@@ -5373,7 +5374,7 @@ void *kmalloc_nolock_noprof(size_t size, gfp_t gfp_flags, int node)
 	 * kfence_alloc. Hence call __slab_alloc_node() (at most twice)
 	 * and slab_post_alloc_hook() directly.
 	 */
-	ret = __slab_alloc_node(s, alloc_gfp, node, _RET_IP_, size);
+	ret = __slab_alloc_node(s, alloc_gfp, node, _RET_IP_, orig_size);
 
 	/*
 	 * It's possible we failed due to trylock as we preempted someone with
@@ -5397,9 +5398,9 @@ void *kmalloc_nolock_noprof(size_t size, gfp_t gfp_flags, int node)
 success:
 	maybe_wipe_obj_freeptr(s, ret);
 	slab_post_alloc_hook(s, NULL, alloc_gfp, 1, &ret,
-			     slab_want_init_on_alloc(alloc_gfp, s), size);
+			     slab_want_init_on_alloc(alloc_gfp, s), orig_size);
 
-	ret = kasan_kmalloc(s, ret, size, alloc_gfp);
+	ret = kasan_kmalloc(s, ret, orig_size, alloc_gfp);
 	return ret;
 }
 EXPORT_SYMBOL_GPL(kmalloc_nolock_noprof);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0493/2077] x86/cpu: Remove obsolete aperfmperf_get_khz() declaration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (491 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0492/2077] mm/slub: preserve original size in _kmalloc_nolock_noprof retry path Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0494/2077] netfilter: conntrack: revert ct extension genid infrastructure Greg Kroah-Hartman
                   ` (504 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Junxiao Chang, Ingo Molnar,
	Nikolay Borisov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Junxiao Chang <junxiao.chang@intel.com>

[ Upstream commit a5f28da54f36f1a8b289d9bdd3e780b2ede0da6f ]

aperfmperf_get_khz() was replaced by arch_freq_get_on_cpu().
The remaining declaration in the header file is no longer used
and should be removed.

Fixes: f3eca381bd49 ("x86/aperfmperf: Replace arch_freq_get_on_cpu()")
Signed-off-by: Junxiao Chang <junxiao.chang@intel.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Nikolay Borisov <nik.borisov@suse.com>
Link: https://patch.msgid.link/20260606021514.1433619-1-junxiao.chang@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/x86/kernel/cpu/cpu.h | 1 -
 1 file changed, 1 deletion(-)

diff --git a/arch/x86/kernel/cpu/cpu.h b/arch/x86/kernel/cpu/cpu.h
index 5c7a3a71191a14..dca2d5845e4276 100644
--- a/arch/x86/kernel/cpu/cpu.h
+++ b/arch/x86/kernel/cpu/cpu.h
@@ -75,7 +75,6 @@ static inline struct amd_northbridge *amd_init_l3_cache(int index)
 }
 #endif
 
-unsigned int aperfmperf_get_khz(int cpu);
 void cpu_select_mitigations(void);
 
 extern void x86_spec_ctrl_setup_ap(void);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0494/2077] netfilter: conntrack: revert ct extension genid infrastructure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (492 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0493/2077] x86/cpu: Remove obsolete aperfmperf_get_khz() declaration Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0495/2077] netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp Greg Kroah-Hartman
                   ` (503 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pablo Neira Ayuso <pablo@netfilter.org>

[ Upstream commit 35e21a4dccc5c255ba59ccfbfeb4629ed21da972 ]

This infrastructure is not used anymore after moving ct timeout and
helper to use datapath refcount to track object use.

Revert commit c56716c69ce1 ("netfilter: extensions: introduce extension
genid count") this patch disables all ct extensions (leading to NULL)
for unconfirmed conntracks, when this is only targeted at ct helper and
ct timeout. There is also codebase that dereferences the ct extension
without checking for NULL which could lead to crash.

Fixes: c56716c69ce1 ("netfilter: extensions: introduce extension genid count")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/net/netfilter/nf_conntrack_extend.h | 12 ----
 net/netfilter/nf_conntrack_core.c           | 61 +--------------------
 net/netfilter/nf_conntrack_extend.c         | 32 +----------
 3 files changed, 2 insertions(+), 103 deletions(-)

diff --git a/include/net/netfilter/nf_conntrack_extend.h b/include/net/netfilter/nf_conntrack_extend.h
index 0b247248b03239..fd5c4dbf72caf7 100644
--- a/include/net/netfilter/nf_conntrack_extend.h
+++ b/include/net/netfilter/nf_conntrack_extend.h
@@ -38,7 +38,6 @@ enum nf_ct_ext_id {
 struct nf_ct_ext {
 	u8 offset[NF_CT_EXT_NUM];
 	u8 len;
-	unsigned int gen_id;
 	char data[] __aligned(8);
 };
 
@@ -52,8 +51,6 @@ static inline bool nf_ct_ext_exist(const struct nf_conn *ct, u8 id)
 	return (ct->ext && __nf_ct_ext_exist(ct->ext, id));
 }
 
-void *__nf_ct_ext_find(const struct nf_ct_ext *ext, u8 id);
-
 static inline void *nf_ct_ext_find(const struct nf_conn *ct, u8 id)
 {
 	struct nf_ct_ext *ext = ct->ext;
@@ -61,19 +58,10 @@ static inline void *nf_ct_ext_find(const struct nf_conn *ct, u8 id)
 	if (!ext || !__nf_ct_ext_exist(ext, id))
 		return NULL;
 
-	if (unlikely(ext->gen_id))
-		return __nf_ct_ext_find(ext, id);
-
 	return (void *)ct->ext + ct->ext->offset[id];
 }
 
 /* Add this type, returns pointer to data or NULL. */
 void *nf_ct_ext_add(struct nf_conn *ct, enum nf_ct_ext_id id, gfp_t gfp);
 
-/* ext genid.  if ext->id != ext_genid, extensions cannot be used
- * anymore unless conntrack has CONFIRMED bit set.
- */
-extern atomic_t nf_conntrack_ext_genid;
-void nf_ct_ext_bump_genid(void);
-
 #endif /* _NF_CONNTRACK_EXTEND_H */
diff --git a/net/netfilter/nf_conntrack_core.c b/net/netfilter/nf_conntrack_core.c
index a45b732393693a..d46faf2d7b9ae6 100644
--- a/net/netfilter/nf_conntrack_core.c
+++ b/net/netfilter/nf_conntrack_core.c
@@ -840,33 +840,6 @@ static void __nf_conntrack_hash_insert(struct nf_conn *ct,
 			   &nf_conntrack_hash[reply_hash]);
 }
 
-static bool nf_ct_ext_valid_pre(const struct nf_ct_ext *ext)
-{
-	/* if ext->gen_id is not equal to nf_conntrack_ext_genid, some extensions
-	 * may contain stale pointers to e.g. helper that has been removed.
-	 *
-	 * The helper can't clear this because the nf_conn object isn't in
-	 * any hash and synchronize_rcu() isn't enough because associated skb
-	 * might sit in a queue.
-	 */
-	return !ext || ext->gen_id == atomic_read(&nf_conntrack_ext_genid);
-}
-
-static bool nf_ct_ext_valid_post(struct nf_ct_ext *ext)
-{
-	if (!ext)
-		return true;
-
-	if (ext->gen_id != atomic_read(&nf_conntrack_ext_genid))
-		return false;
-
-	/* inserted into conntrack table, nf_ct_iterate_cleanup()
-	 * will find it.  Disable nf_ct_ext_find() id check.
-	 */
-	WRITE_ONCE(ext->gen_id, 0);
-	return true;
-}
-
 int
 nf_conntrack_hash_check_insert(struct nf_conn *ct)
 {
@@ -882,9 +855,6 @@ nf_conntrack_hash_check_insert(struct nf_conn *ct)
 
 	zone = nf_ct_zone(ct);
 
-	if (!nf_ct_ext_valid_pre(ct->ext))
-		return -EAGAIN;
-
 	local_bh_disable();
 	do {
 		sequence = read_seqcount_begin(&nf_conntrack_generation);
@@ -918,18 +888,6 @@ nf_conntrack_hash_check_insert(struct nf_conn *ct)
 			goto chaintoolong;
 	}
 
-	/* If genid has changed, we can't insert anymore because ct
-	 * extensions could have stale pointers and nf_ct_iterate_destroy
-	 * might have completed its table scan already.
-	 *
-	 * Increment of the ext genid right after this check is fine:
-	 * nf_ct_iterate_destroy blocks until locks are released.
-	 */
-	if (!nf_ct_ext_valid_post(ct->ext)) {
-		err = -EAGAIN;
-		goto out;
-	}
-
 	smp_wmb();
 	/* The caller holds a reference to this object */
 	refcount_set(&ct->ct_general.use, 2);
@@ -1257,11 +1215,6 @@ __nf_conntrack_confirm(struct sk_buff *skb)
 		return NF_DROP;
 	}
 
-	if (!nf_ct_ext_valid_pre(ct->ext)) {
-		NF_CT_STAT_INC(net, insert_failed);
-		goto dying;
-	}
-
 	/* We have to check the DYING flag after unlink to prevent
 	 * a race against nf_ct_get_next_corpse() possibly called from
 	 * user context, else we insert an already 'dead' hash, blocking
@@ -1324,16 +1277,6 @@ __nf_conntrack_confirm(struct sk_buff *skb)
 	nf_conntrack_double_unlock(hash, reply_hash);
 	local_bh_enable();
 
-	/* ext area is still valid (rcu read lock is held,
-	 * but will go out of scope soon, we need to remove
-	 * this conntrack again.
-	 */
-	if (!nf_ct_ext_valid_post(ct->ext)) {
-		nf_ct_kill(ct);
-		NF_CT_STAT_INC_ATOMIC(net, drop);
-		return NF_DROP;
-	}
-
 	help = nfct_help(ct);
 	if (help && help->helper)
 		nf_conntrack_event_cache(IPCT_HELPER, ct);
@@ -2440,13 +2383,11 @@ nf_ct_iterate_destroy(int (*iter)(struct nf_conn *i, void *data), void *data)
 	 */
 	synchronize_net();
 
-	nf_ct_ext_bump_genid();
 	iter_data.data = data;
 	nf_ct_iterate_cleanup(iter, &iter_data);
 
 	/* Another cpu might be in a rcu read section with
-	 * rcu protected pointer cleared in iter callback
-	 * or hidden via nf_ct_ext_bump_genid() above.
+	 * rcu protected pointer cleared in iter callback.
 	 *
 	 * Wait until those are done.
 	 */
diff --git a/net/netfilter/nf_conntrack_extend.c b/net/netfilter/nf_conntrack_extend.c
index dd62cc12e77507..0da105e1ded939 100644
--- a/net/netfilter/nf_conntrack_extend.c
+++ b/net/netfilter/nf_conntrack_extend.c
@@ -27,8 +27,6 @@
 
 #define NF_CT_EXT_PREALLOC	128u /* conntrack events are on by default */
 
-atomic_t nf_conntrack_ext_genid __read_mostly = ATOMIC_INIT(1);
-
 static const u8 nf_ct_ext_type_len[NF_CT_EXT_NUM] = {
 	[NF_CT_EXT_HELPER] = sizeof(struct nf_conn_help),
 #if IS_ENABLED(CONFIG_NF_NAT)
@@ -118,10 +116,8 @@ void *nf_ct_ext_add(struct nf_conn *ct, enum nf_ct_ext_id id, gfp_t gfp)
 	if (!new)
 		return NULL;
 
-	if (!ct->ext) {
+	if (!ct->ext)
 		memset(new->offset, 0, sizeof(new->offset));
-		new->gen_id = atomic_read(&nf_conntrack_ext_genid);
-	}
 
 	new->offset[id] = newoff;
 	new->len = newlen;
@@ -131,29 +127,3 @@ void *nf_ct_ext_add(struct nf_conn *ct, enum nf_ct_ext_id id, gfp_t gfp)
 	return (void *)new + newoff;
 }
 EXPORT_SYMBOL(nf_ct_ext_add);
-
-/* Use nf_ct_ext_find wrapper. This is only useful for unconfirmed entries. */
-void *__nf_ct_ext_find(const struct nf_ct_ext *ext, u8 id)
-{
-	unsigned int gen_id = atomic_read(&nf_conntrack_ext_genid);
-	unsigned int this_id = READ_ONCE(ext->gen_id);
-
-	if (!__nf_ct_ext_exist(ext, id))
-		return NULL;
-
-	if (this_id == 0 || ext->gen_id == gen_id)
-		return (void *)ext + ext->offset[id];
-
-	return NULL;
-}
-EXPORT_SYMBOL(__nf_ct_ext_find);
-
-void nf_ct_ext_bump_genid(void)
-{
-	unsigned int value = atomic_inc_return(&nf_conntrack_ext_genid);
-
-	if (value == UINT_MAX)
-		atomic_set(&nf_conntrack_ext_genid, 1);
-
-	msleep(HZ);
-}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0495/2077] netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (493 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0494/2077] netfilter: conntrack: revert ct extension genid infrastructure Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0496/2077] ntfs: free link name from ntfs_name_cache Greg Kroah-Hartman
                   ` (502 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pablo Neira Ayuso <pablo@netfilter.org>

[ Upstream commit b0f02608fbcd607b5131cceb91fc0a035264e61c ]

For GRE flows, validate that the ct master helper (if any) is pptp
before calling nf_ct_gre_keymap_destroy(), so the helper data area
can be accessed safely. Note that only the pptp helper provides a
.destroy callback.

Fixes: e56894356f60 ("netfilter: conntrack: remove l4proto destroy hook")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/netfilter/nf_conntrack_core.c | 18 ++++++++++++++++--
 1 file changed, 16 insertions(+), 2 deletions(-)

diff --git a/net/netfilter/nf_conntrack_core.c b/net/netfilter/nf_conntrack_core.c
index d46faf2d7b9ae6..75c91636bf6194 100644
--- a/net/netfilter/nf_conntrack_core.c
+++ b/net/netfilter/nf_conntrack_core.c
@@ -562,9 +562,23 @@ static void destroy_gre_conntrack(struct nf_conn *ct)
 {
 #ifdef CONFIG_NF_CT_PROTO_GRE
 	struct nf_conn *master = ct->master;
+	struct nf_conn_help *help;
+
+	if (!master)
+		return;
+
+	help = nfct_help(master);
+	if (help) {
+		struct nf_conntrack_helper *helper;
 
-	if (master)
-		nf_ct_gre_keymap_destroy(master);
+		rcu_read_lock();
+		helper = rcu_dereference(help->helper);
+		/* Only pptp helper has a destroy callback. */
+		if (helper && helper->destroy)
+			nf_ct_gre_keymap_destroy(master);
+
+		rcu_read_unlock();
+	}
 #endif
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0496/2077] ntfs: free link name from ntfs_name_cache
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (494 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0495/2077] netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0497/2077] RDMA/hfi1: Open-code rvt_set_ibdev_name() Greg Kroah-Hartman
                   ` (501 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, DaeMyung Kang, Namjae Jeon,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: DaeMyung Kang <charsyam@gmail.com>

[ Upstream commit 8488c4d066e6a52937fa5d82ab131c7554ddc9d8 ]

ntfs_link() converts the new link name with ntfs_nlstoucs() using
NTFS_MAX_NAME_LEN. In this case ntfs_nlstoucs() allocates the result
from ntfs_name_cache, and its contract requires callers to release the
buffer with kmem_cache_free(ntfs_name_cache, ...).

All other ntfs_nlstoucs() callers in namei.c do that, but ntfs_link()
uses kfree(), which mismatches the allocator for successfully converted
names.

The conversion failure path reaches the common out label with uname ==
NULL. That was harmless for kfree(), but kmem_cache_free() does not
provide the same NULL contract. Return directly on conversion failure
and free successful conversions with ntfs_name_cache.

Fixes: af0db57d4293 ("ntfs: update inode operations")
Signed-off-by: DaeMyung Kang <charsyam@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs/namei.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/fs/ntfs/namei.c b/fs/ntfs/namei.c
index c4f82846c58c30..9c1c36acfad24e 100644
--- a/fs/ntfs/namei.c
+++ b/fs/ntfs/namei.c
@@ -1532,8 +1532,7 @@ static int ntfs_link(struct dentry *old_dentry, struct inode *dir,
 	if (uname_len < 0) {
 		if (uname_len != -ENAMETOOLONG)
 			ntfs_error(sb, "Failed to convert name to unicode.");
-		err = -ENOMEM;
-		goto out;
+		return -ENOMEM;
 	}
 
 	if (!(vol->vol_flags & VOLUME_IS_DIRTY))
@@ -1563,7 +1562,7 @@ static int ntfs_link(struct dentry *old_dentry, struct inode *dir,
 	mutex_unlock(&ni->mrec_lock);
 
 out:
-	kfree(uname);
+	kmem_cache_free(ntfs_name_cache, uname);
 	return err;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0497/2077] RDMA/hfi1: Open-code rvt_set_ibdev_name()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (495 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0496/2077] ntfs: free link name from ntfs_name_cache Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0498/2077] IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() Greg Kroah-Hartman
                   ` (500 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Kees Cook,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

[ Upstream commit 0ee8ac903e5aa100a70bef8d0afc19a336ffa775 ]

clang warns about a function missing a printf attribute:

include/rdma/rdma_vt.h:457:47: error: diagnostic behavior may be improved by adding the 'format(printf, 2, 3)' attribute to the declaration of 'rvt_set_ibdev_name' [-Werror,-Wmissing-format-attribute]
  447 | static inline void rvt_set_ibdev_name(struct rvt_dev_info *rdi,
      | __attribute__((format(printf, 2, 3)))
  448 |                                       const char *fmt, const char *name,
  449 |                                       const int unit)

The helper was originally added as an abstraction for the hfi1 and
qib drivers needing the same thing, but now qib is gone, and hfi1
is the only remaining user of rdma_vt.

Avoid the warning and allow the compiler to check the format string by
open-coding the helper and directly assigning the device name.

Fixes: 5084c8ff21f2 ("IB/{rdmavt, hfi1, qib}: Self determine driver name")
Link: https://patch.msgid.link/r/20260602140453.3542427-1-arnd@kernel.org
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Reviewed-by: Kees Cook <kees@kernel.org>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/hfi1/init.c | 13 ++++++++++++-
 include/rdma/rdma_vt.h            | 20 --------------------
 2 files changed, 12 insertions(+), 21 deletions(-)

diff --git a/drivers/infiniband/hw/hfi1/init.c b/drivers/infiniband/hw/hfi1/init.c
index 8b5a5b32b0fa26..b7fd8b1fbbbde7 100644
--- a/drivers/infiniband/hw/hfi1/init.c
+++ b/drivers/infiniband/hw/hfi1/init.c
@@ -1206,6 +1206,7 @@ static struct hfi1_devdata *hfi1_alloc_devdata(struct pci_dev *pdev,
 					       size_t extra)
 {
 	struct hfi1_devdata *dd;
+	struct ib_device *ibdev;
 	int ret, nports;
 
 	/* extra is * number of ports */
@@ -1227,7 +1228,17 @@ static struct hfi1_devdata *hfi1_alloc_devdata(struct pci_dev *pdev,
 			"Could not allocate unit ID: error %d\n", -ret);
 		goto bail;
 	}
-	rvt_set_ibdev_name(&dd->verbs_dev.rdi, "%s_%d", class_name(), dd->unit);
+
+	/*
+	 * FIXME: rvt and its users want to touch the ibdev before
+	 * registration and have things like the name work. We don't have the
+	 * infrastructure in the core to support this directly today, hack it
+	 * to work by setting the name manually here.
+	 */
+	ibdev = &dd->verbs_dev.rdi.ibdev;
+	dev_set_name(&ibdev->dev, "%s_%d", class_name(), dd->unit);
+	strscpy(ibdev->name, dev_name(&ibdev->dev), IB_DEVICE_NAME_MAX);
+
 	/*
 	 * If the BIOS does not have the NUMA node information set, select
 	 * NUMA 0 so we get consistent performance.
diff --git a/include/rdma/rdma_vt.h b/include/rdma/rdma_vt.h
index 7d8de561f71b5b..7ffc83262a0166 100644
--- a/include/rdma/rdma_vt.h
+++ b/include/rdma/rdma_vt.h
@@ -438,26 +438,6 @@ struct rvt_dev_info {
 	struct rvt_wss *wss;
 };
 
-/**
- * rvt_set_ibdev_name - Craft an IB device name from client info
- * @rdi: pointer to the client rvt_dev_info structure
- * @name: client specific name
- * @unit: client specific unit number.
- */
-static inline void rvt_set_ibdev_name(struct rvt_dev_info *rdi,
-				      const char *fmt, const char *name,
-				      const int unit)
-{
-	/*
-	 * FIXME: rvt and its users want to touch the ibdev before
-	 * registration and have things like the name work. We don't have the
-	 * infrastructure in the core to support this directly today, hack it
-	 * to work by setting the name manually here.
-	 */
-	dev_set_name(&rdi->ibdev.dev, fmt, name, unit);
-	strscpy(rdi->ibdev.name, dev_name(&rdi->ibdev.dev), IB_DEVICE_NAME_MAX);
-}
-
 /**
  * rvt_get_ibdev_name - return the IB name
  * @rdi: rdmavt device
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0498/2077] IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (496 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0497/2077] RDMA/hfi1: Open-code rvt_set_ibdev_name() Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0499/2077] ALSA: hda: fix Kconfig dependency of HD Audio PCI Greg Kroah-Hartman
                   ` (499 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jason Gunthorpe <jgg@nvidia.com>

[ Upstream commit 9b2207bc5cdb955bdae34b3eec80f04979e17081 ]

Codex pointed out that cm_init_av_by_path() can call cm_set_av_port()
which takes a reference on the cm device, but then can immediately return
error if ib_init_ah_attr_from_path() fails.

Since callers like ib_send_cm_req() put the av on the stack this leaks
that cm device reference.

Re-order cm_init_av_by_path() so it doesn't touch the av until it has done
all its failable work, and then update the av in one shot so it is either
left alone or fully init'd.

Sashiko also pointed out that the cm_destroy_av() prior to
cm_init_av_by_path() is harmful as it leaves the AV broken in the error
case and thus the REJ won't send. Since cm_init_av_by_path() is now atomic
it is safe to delete the cm_destroy_av(). On succees the av from
cm_init_av_for_response() is cleaned up by cm_init_av_by_path(), on
failure the 'goto rejected' guarentees the av is destroyed during
ib_destroy_cm_id().

Fixes: 76039ac9095f ("IB/cm: Protect cm_dev, cm_ports and mad_agent with kref and lock")
Link: https://patch.msgid.link/r/0-v1-38292501f539+14f-ib_cm_av_leak_jgg@nvidia.com
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/core/cm.c | 13 ++++++++-----
 1 file changed, 8 insertions(+), 5 deletions(-)

diff --git a/drivers/infiniband/core/cm.c b/drivers/infiniband/core/cm.c
index 6ab9a0aee1ec60..1a2c2775b14d56 100644
--- a/drivers/infiniband/core/cm.c
+++ b/drivers/infiniband/core/cm.c
@@ -530,6 +530,7 @@ static int cm_init_av_by_path(struct sa_path_rec *path,
 	struct rdma_ah_attr new_ah_attr;
 	struct cm_device *cm_dev;
 	struct cm_port *port;
+	u16 pkey_index;
 	int ret;
 
 	port = get_cm_port_from_path(path, sgid_attr);
@@ -538,12 +539,10 @@ static int cm_init_av_by_path(struct sa_path_rec *path,
 	cm_dev = port->cm_dev;
 
 	ret = ib_find_cached_pkey(cm_dev->ib_device, port->port_num,
-				  be16_to_cpu(path->pkey), &av->pkey_index);
+				  be16_to_cpu(path->pkey), &pkey_index);
 	if (ret)
 		return ret;
 
-	cm_set_av_port(av, port);
-
 	/*
 	 * av->ah_attr might be initialized based on wc or during
 	 * request processing time which might have reference to sgid_attr.
@@ -558,6 +557,8 @@ static int cm_init_av_by_path(struct sa_path_rec *path,
 	if (ret)
 		return ret;
 
+	av->pkey_index = pkey_index;
+	cm_set_av_port(av, port);
 	av->timeout = path->packet_life_time + 1;
 	rdma_move_ah_attr(&av->ah_attr, &new_ah_attr);
 	return 0;
@@ -2184,8 +2185,10 @@ static int cm_req_handler(struct cm_work *work)
 				 cm_id_priv->av.ah_attr.roce.dmac);
 	work->path[0].hop_limit = grh->hop_limit;
 
-	/* This destroy call is needed to pair with cm_init_av_for_response */
-	cm_destroy_av(&cm_id_priv->av);
+	/*
+	 * cm_init_av_by_path() will internally pair with the above
+	 * cm_init_av_for_response() if it succeeds.
+	 */
 	ret = cm_init_av_by_path(&work->path[0], gid_attr, &cm_id_priv->av);
 	if (ret) {
 		int err;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0499/2077] ALSA: hda: fix Kconfig dependency of HD Audio PCI
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (497 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0498/2077] IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0500/2077] RDMA/irdma: Fix OOB read during CQ MR registration Greg Kroah-Hartman
                   ` (498 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Oliver Hartkopp, Takashi Iwai,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Oliver Hartkopp <socketcan@hartkopp.net>

[ Upstream commit 1516134cb65526aba5319bb446c296fc8a192f84 ]

With commit 2d9223d2d64c ("ALSA: hda: Move controller drivers into
sound/hda/controllers directory") the HD Audio drivers have been moved
from linux/sound/pci/hda to linux/sound/hda.

But the Kconfig dependency for SND_HDA_INTEL stayed on SND_PCI instead of
depending on PCI directly. To make the "HD Audio PCI" configuration entry
visible it is currently needed to enable "PCI sound devices" although
no PCI device in the submenu needs to be selected.

Make SND_HDA_INTEL directly depending on hardware/architecture like the
other entries in this Kconfig.

Fixes: 2d9223d2d64c ("ALSA: hda: Move controller drivers into sound/hda/controllers directory")
Signed-off-by: Oliver Hartkopp <socketcan@hartkopp.net>
Link: https://patch.msgid.link/20260529-hda-kconfig-v1-1-4a2c6a0efd56@hartkopp.net
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/hda/controllers/Kconfig | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/hda/controllers/Kconfig b/sound/hda/controllers/Kconfig
index 72855f2df45148..5d6a77e68588e7 100644
--- a/sound/hda/controllers/Kconfig
+++ b/sound/hda/controllers/Kconfig
@@ -1,7 +1,7 @@
 # SPDX-License-Identifier: GPL-2.0-only
 config SND_HDA_INTEL
 	tristate "HD Audio PCI"
-	depends on SND_PCI
+	depends on PCI
 	select SND_HDA
 	select SND_INTEL_DSP_CONFIG
 	help
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0500/2077] RDMA/irdma: Fix OOB read during CQ MR registration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (498 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0499/2077] ALSA: hda: fix Kconfig dependency of HD Audio PCI Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0501/2077] RDMA/irdma: Initialize iwmr->access during " Greg Kroah-Hartman
                   ` (497 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jacob Moroni <jmoroni@google.com>

[ Upstream commit 4385ddd654d90245eeb83b3cb539670ab5c85ba4 ]

Sashiko pointed out an unrelated bug during a previous patch:
https://sashiko.dev/#/patchset/20260512183852.614045-1-jmoroni%40google.com

This change fixes the bug by eliminating the cqmr->split field which
was not being set properly and instead just checks the CQ resize
feature flag directly.

The cqmr->split field essentially tracks whether IRDMA_FEATURE_CQ_RESIZE
is set, but it was not being set until CQ creation time, which is _after_
CQ memory registration (the only other place where it is referenced).

As a result, it would always be false during MR registration and would
therefore cause irdma_handle_q_mem to populate cqmr->shadow even for GEN_2
HW and beyond:

    cqmr->shadow = (dma_addr_t)arr[req->cq_pages];

The issue is that for GEN_2 and beyond, req->cq_pages may be exactly equal
to iwmr->page_cnt and therefore equal to the size of arr, which would cause
an OOB read by one.

Fixes: b48c24c2d710 ("RDMA/irdma: Implement device supported verb APIs")
Link: https://patch.msgid.link/r/20260602214423.1315105-2-jmoroni@google.com
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/irdma/verbs.c | 4 ++--
 drivers/infiniband/hw/irdma/verbs.h | 1 -
 2 files changed, 2 insertions(+), 3 deletions(-)

diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
index 661f2e0299ef7d..d79e130d98ee2a 100644
--- a/drivers/infiniband/hw/irdma/verbs.c
+++ b/drivers/infiniband/hw/irdma/verbs.c
@@ -2572,7 +2572,6 @@ static int irdma_create_cq(struct ib_cq *ibcq,
 			}
 			cqmr_shadow = &iwpbl_shadow->cq_mr;
 			info.shadow_area_pa = cqmr_shadow->cq_pbl.addr;
-			cqmr->split = true;
 		} else {
 			info.shadow_area_pa = cqmr->shadow;
 		}
@@ -2980,7 +2979,8 @@ static int irdma_handle_q_mem(struct irdma_device *iwdev,
 	case IRDMA_MEMREG_TYPE_CQ:
 		hmc_p = &cqmr->cq_pbl;
 
-		if (!cqmr->split)
+		if (!(iwdev->rf->sc_dev.hw_attrs.uk_attrs.feature_flags &
+		      IRDMA_FEATURE_CQ_RESIZE))
 			cqmr->shadow = (dma_addr_t)arr[req->cq_pages];
 
 		if (lvl)
diff --git a/drivers/infiniband/hw/irdma/verbs.h b/drivers/infiniband/hw/irdma/verbs.h
index aabbb3442098bc..289ebc9b23ca78 100644
--- a/drivers/infiniband/hw/irdma/verbs.h
+++ b/drivers/infiniband/hw/irdma/verbs.h
@@ -65,7 +65,6 @@ struct irdma_hmc_pble {
 struct irdma_cq_mr {
 	struct irdma_hmc_pble cq_pbl;
 	dma_addr_t shadow;
-	bool split;
 };
 
 struct irdma_srq_mr {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0501/2077] RDMA/irdma: Initialize iwmr->access during MR registration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (499 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0500/2077] RDMA/irdma: Fix OOB read during CQ MR registration Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0502/2077] arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency Greg Kroah-Hartman
                   ` (496 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jacob Moroni <jmoroni@google.com>

[ Upstream commit 1521d560b7a1a39e437d37fffd9b55435d329ad1 ]

Initialize iwmr->access during initial user mem registration so
that it contains a valid value during a subsequent rereg_mr.

Otherwise, a rereg_mr that doesn't set IB_MR_REREG_ACCESS (for
example, one that only changes the PD) ends up clearing the
access flags in HW since iwmr->access is zero-initialized, which
is not intended.

Fixes: 5ac388db27c4 ("RDMA/irdma: Add support to re-register a memory region")
Link: https://patch.msgid.link/r/20260604154104.4035581-1-jmoroni@google.com
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/irdma/verbs.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
index d79e130d98ee2a..7da7a7e8b30ca2 100644
--- a/drivers/infiniband/hw/irdma/verbs.c
+++ b/drivers/infiniband/hw/irdma/verbs.c
@@ -3325,6 +3325,7 @@ static int irdma_reg_user_mr_type_mem(struct irdma_mr *iwmr, int access,
 	int err;
 
 	lvl = iwmr->page_cnt != 1 ? PBLE_LEVEL_1 | PBLE_LEVEL_2 : PBLE_LEVEL_0;
+	iwmr->access = access;
 
 	err = irdma_setup_pbles(iwdev->rf, iwmr, lvl);
 	if (err)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0502/2077] arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (500 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0501/2077] RDMA/irdma: Initialize iwmr->access during " Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0503/2077] arm64: dts: imx94: fix DDR PMU interrupt number Greg Kroah-Hartman
                   ` (495 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Frieder Schrempf, Frank Li,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Frieder Schrempf <frieder.schrempf@kontron.de>

[ Upstream commit 95f5bc1632ab8f243e517357b5da0dd28d1c6c92 ]

There is an onboard level shifter for the SPI signals that causes
additional propagation delay and renders the SPI transmission
unreliable at 20 MHz. Reduce the clock frequency to a safe value.

Fixes: 946ab10e3f40 ("arm64: dts: Add support for Kontron OSM-S i.MX8MP SoM and BL carrier board")
Signed-off-by: Frieder Schrempf <frieder.schrempf@kontron.de>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx8mp-kontron-bl-osm-s.dts | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/freescale/imx8mp-kontron-bl-osm-s.dts b/arch/arm64/boot/dts/freescale/imx8mp-kontron-bl-osm-s.dts
index 0924ac50fd2dbc..75ae4664278214 100644
--- a/arch/arm64/boot/dts/freescale/imx8mp-kontron-bl-osm-s.dts
+++ b/arch/arm64/boot/dts/freescale/imx8mp-kontron-bl-osm-s.dts
@@ -63,7 +63,7 @@ &ecspi2 {
 	eeram@0 {
 		compatible = "microchip,48l640";
 		reg = <0>;
-		spi-max-frequency = <20000000>;
+		spi-max-frequency = <16000000>;
 	};
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0503/2077] arm64: dts: imx94: fix DDR PMU interrupt number
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (501 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0502/2077] arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0504/2077] arm64: dts: imx95: Correct PCIe outbound address space configuration Greg Kroah-Hartman
                   ` (494 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alice Guo, Xu Yang, Frank Li,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alice Guo <alice.guo@nxp.com>

[ Upstream commit 2521addd5df7e8ab805622d4a0eff9735a45fa11 ]

The DDR Performance Monitor node was added with incorrect interrupt
number 91, which actually belongs to the wdog4 watchdog. Fix it to the
correct interrupt number 374.

Fixes: e918e5f847b3 ("arm64: dts: imx94: add DDR Perf Monitor node")
Signed-off-by: Alice Guo <alice.guo@nxp.com>
Reviewed-by: Xu Yang <xu.yang_2@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx94.dtsi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/freescale/imx94.dtsi b/arch/arm64/boot/dts/freescale/imx94.dtsi
index c460ece6070f83..379429b3072aca 100644
--- a/arch/arm64/boot/dts/freescale/imx94.dtsi
+++ b/arch/arm64/boot/dts/freescale/imx94.dtsi
@@ -1481,7 +1481,7 @@ netc_emdio: mdio@18,0 {
 		ddr-pmu@4e090dc0 {
 			compatible = "fsl,imx94-ddr-pmu", "fsl,imx93-ddr-pmu";
 			reg = <0x0 0x4e090dc0 0x0 0x200>;
-			interrupts = <GIC_SPI 91 IRQ_TYPE_LEVEL_HIGH>;
+			interrupts = <GIC_SPI 374 IRQ_TYPE_LEVEL_HIGH>;
 		};
 	};
 };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0504/2077] arm64: dts: imx95: Correct PCIe outbound address space configuration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (502 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0503/2077] arm64: dts: imx94: fix DDR PMU interrupt number Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0505/2077] arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi Greg Kroah-Hartman
                   ` (493 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Richard Zhu, Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Zhu <hongxing.zhu@nxp.com>

[ Upstream commit dbecf38e60d4ef08c59836b7bc16e8efca01fc47 ]

Fix the PCIe outbound memory ranges for both pcie0 and pcie1
controllers on i.MX95.

The memory window size was incorrectly set to 256MB during initial
bring-up, but the hardware supports up to 4GB of outbound address space
per controller.

Additionally, the ECAM region cannot be mapped as I/O space. Use a
memory-mapped region for I/O space instead, and relocate the 1MB I/O
region to immediately follow the memory region at offset 0xf0000000
within each window.

Update the outbound address space layout per controller as follows:

  - 3.5GB  64-bit prefetchable memory
  - 256MB  32-bit non-prefetchable memory
  - 1MB    I/O

Fixes: 3b1d5deb29ff ("arm64: dts: imx95: add pcie[0,1] and pcie-ep[0,1] support")
Signed-off-by: Richard Zhu <hongxing.zhu@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx95.dtsi | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/arch/arm64/boot/dts/freescale/imx95.dtsi b/arch/arm64/boot/dts/freescale/imx95.dtsi
index 71394871d8dd0f..4330296ed8e43d 100644
--- a/arch/arm64/boot/dts/freescale/imx95.dtsi
+++ b/arch/arm64/boot/dts/freescale/imx95.dtsi
@@ -1852,8 +1852,9 @@ pcie0: pcie@4c300000 {
 			      <0 0x4c360000 0 0x10000>,
 			      <0 0x4c340000 0 0x4000>;
 			reg-names = "dbi", "config", "atu", "app";
-			ranges = <0x81000000 0x0 0x00000000 0x0 0x6ff00000 0 0x00100000>,
-				 <0x82000000 0x0 0x10000000 0x9 0x10000000 0 0x10000000>;
+			ranges = <0x43000000 0x9 0x00000000 0x9 0x00000000 0x0 0xe0000000>,
+				 <0x82000000 0x0 0xe0000000 0x9 0xe0000000 0x0 0x10000000>,
+				 <0x81000000 0x0 0x00000000 0x9 0xf0000000 0x0 0x00100000>;
 			#address-cells = <3>;
 			#size-cells = <2>;
 			device_type = "pci";
@@ -1927,8 +1928,9 @@ pcie1: pcie@4c380000 {
 			      <0 0x4c3e0000 0 0x10000>,
 			      <0 0x4c3c0000 0 0x4000>;
 			reg-names = "dbi", "config", "atu", "app";
-			ranges = <0x81000000 0 0x00000000 0x8 0x8ff00000 0 0x00100000>,
-				 <0x82000000 0 0x10000000 0xa 0x10000000 0 0x10000000>;
+			ranges = <0x43000000 0xa 0x00000000 0xa 0x00000000 0x0 0xe0000000>,
+				 <0x82000000 0x0 0xe0000000 0xa 0xe0000000 0x0 0x10000000>,
+				 <0x81000000 0x0 0x00000000 0xa 0xf0000000 0x0 0x00100000>;
 			#address-cells = <3>;
 			#size-cells = <2>;
 			device_type = "pci";
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0505/2077] arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (503 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0504/2077] arm64: dts: imx95: Correct PCIe outbound address space configuration Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:02 ` [PATCH 7.1 0506/2077] arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well Greg Kroah-Hartman
                   ` (492 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Josua Mayer, Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Josua Mayer <josua@solid-run.com>

[ Upstream commit 13a37b30e464503515625ba891018aec0264c7d2 ]

LX2160A and LX2162A are different packages of the same silicon. While
LX2160A had two revisions, LX2162A was released later based on LX2160A
revision 2.

Commit a8fe6c8dfc40 ("arm64: dts: fsl-lx2160a: add rev2 support") has added
a new soc dtsi for revision 2.

Update LX2162A Clearfog description to use revision 2 dtsi.

Fixes: 5093b190f9ce ("arm64: dts: freescale: Add support for LX2162 SoM & Clearfog Board") # no-stable
Signed-off-by: Josua Mayer <josua@solid-run.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/fsl-lx2162a-clearfog.dts | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/freescale/fsl-lx2162a-clearfog.dts b/arch/arm64/boot/dts/freescale/fsl-lx2162a-clearfog.dts
index 9d50d3e2761da5..f95e9c19bfc758 100644
--- a/arch/arm64/boot/dts/freescale/fsl-lx2162a-clearfog.dts
+++ b/arch/arm64/boot/dts/freescale/fsl-lx2162a-clearfog.dts
@@ -6,7 +6,7 @@
 
 /dts-v1/;
 
-#include "fsl-lx2160a.dtsi"
+#include "fsl-lx2160a-rev2.dtsi"
 #include "fsl-lx2162a-sr-som.dtsi"
 
 / {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0506/2077] arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (504 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0505/2077] arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi Greg Kroah-Hartman
@ 2026-07-21 15:02 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0507/2077] arm64: dts: imx8mp-kontron: Fix GPIO for display power switch Greg Kroah-Hartman
                   ` (491 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:02 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Alexander Stein, Frank Li,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexander Stein <alexander.stein@ew.tq-group.com>

[ Upstream commit 748835fcb2eb2120234aef9556d282272501b96b ]

With deferrable card binding the sound card driver tries to
get the mclk configuration before it is setup in sai3 node.
Fix this by setting the sai clock config for the audio codec as well.

Fixes: d8f9d8126582 ("arm64: dts: imx8mp: Add analog audio output on i.MX8MP TQMa8MPxL/MBa8MPxL")
Signed-off-by: Alexander Stein <alexander.stein@ew.tq-group.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/freescale/imx8mp-tqma8mpql-mba8mpxl.dts | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/arch/arm64/boot/dts/freescale/imx8mp-tqma8mpql-mba8mpxl.dts b/arch/arm64/boot/dts/freescale/imx8mp-tqma8mpql-mba8mpxl.dts
index 890d1e525a4896..6b0f944095e7c4 100644
--- a/arch/arm64/boot/dts/freescale/imx8mp-tqma8mpql-mba8mpxl.dts
+++ b/arch/arm64/boot/dts/freescale/imx8mp-tqma8mpql-mba8mpxl.dts
@@ -609,6 +609,9 @@ tlv320aic3x04: audio-codec@18 {
 		reset-gpios = <&gpio4 29 GPIO_ACTIVE_LOW>;
 		iov-supply = <&reg_vcc_1v8>;
 		ldoin-supply = <&reg_vcc_3v3>;
+		assigned-clocks = <&clk IMX8MP_CLK_SAI3>;
+		assigned-clock-parents = <&clk IMX8MP_AUDIO_PLL1_OUT>;
+		assigned-clock-rates = <12288000>;
 	};
 
 	se97_1c: temperature-sensor@1c {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0507/2077] arm64: dts: imx8mp-kontron: Fix GPIO for display power switch
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (505 preceding siblings ...)
  2026-07-21 15:02 ` [PATCH 7.1 0506/2077] arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0508/2077] arm64: dts: freescale: fsl-ls1028a-tqmls1028a-mbls1028a: switch mmc aliases Greg Kroah-Hartman
                   ` (490 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Frieder Schrempf, Frank Li,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Frieder Schrempf <frieder.schrempf@kontron.de>

[ Upstream commit 5b19ca527471903920d713bc48518a036a95bf6b ]

The GPIO that controls the power supply for the LVDS display
connector has changed between early prototypes and the current
production design of the hardware. Reflect this change in the
devicetree to properly switch on the panel supply.

This was working before even with the wrong GPIO due to the
bidirectional level shifter used on the board which drives the EN
signal high even when the input has a (weak) pull down configured as
reset condition of the SoC pad. As a result the display was working
but the supply was always on.

Tested on BL i.MX8MP to show the correct voltage level on the level
shifter input.

Fixes: 946ab10e3f40 ("arm64: dts: Add support for Kontron OSM-S i.MX8MP SoM and BL carrier board")
Signed-off-by: Frieder Schrempf <frieder.schrempf@kontron.de>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../boot/dts/freescale/imx8mp-kontron-bl-osm-s.dts   | 12 ++++++++++--
 1 file changed, 10 insertions(+), 2 deletions(-)

diff --git a/arch/arm64/boot/dts/freescale/imx8mp-kontron-bl-osm-s.dts b/arch/arm64/boot/dts/freescale/imx8mp-kontron-bl-osm-s.dts
index 75ae4664278214..29ce863403b882 100644
--- a/arch/arm64/boot/dts/freescale/imx8mp-kontron-bl-osm-s.dts
+++ b/arch/arm64/boot/dts/freescale/imx8mp-kontron-bl-osm-s.dts
@@ -49,7 +49,9 @@ pwm-beeper {
 
 	reg_vcc_panel: regulator-vcc-panel {
 		compatible = "regulator-fixed";
-		gpio = <&gpio4 3 GPIO_ACTIVE_HIGH>;
+		pinctrl-names = "default";
+		pinctrl-0 = <&pinctrl_reg_vcc_panel>;
+		gpio = <&gpio5 3 GPIO_ACTIVE_HIGH>;
 		enable-active-high;
 		regulator-max-microvolt = <3300000>;
 		regulator-min-microvolt = <3300000>;
@@ -172,7 +174,7 @@ &gpio4 {
 &gpio5 {
 	pinctrl-names = "default";
 	pinctrl-0 = <&pinctrl_gpio5>;
-	gpio-line-names = "I2S_BITCLK", "I2S_A_DATA_OUT", "I2S_MCLK", "PWM_2",
+	gpio-line-names = "I2S_BITCLK", "I2S_A_DATA_OUT", "I2S_MCLK", "VCC_PANEL_EN",
 			  "PWM_1", "PWM_0", "SPI_A_SCK", "CAN_ADDR1",
 			  "CAN_ADDR0", "SPI_A_CS0", "SPI_B_SCK", "SPI_B_SDO",
 			  "SPI_B_SDI", "SPI_B_CS0", "I2C_A_SCL", "I2C_A_SDA",
@@ -329,4 +331,10 @@ MX8MP_IOMUXC_ECSPI1_MOSI__GPIO5_IO07		0x46 /* CAN_ADR0 */
 			MX8MP_IOMUXC_ECSPI1_MISO__GPIO5_IO08		0x46 /* CAN_ADR1 */
 		>;
 	};
+
+	pinctrl_reg_vcc_panel: regvccpanelgrp {
+		fsl,pins = <
+			MX8MP_IOMUXC_SPDIF_TX__GPIO5_IO03		0x46
+		>;
+	};
 };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0508/2077] arm64: dts: freescale: fsl-ls1028a-tqmls1028a-mbls1028a: switch mmc aliases
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (506 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0507/2077] arm64: dts: imx8mp-kontron: Fix GPIO for display power switch Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0509/2077] RDMA/siw: Fix endpoint/socket association handling Greg Kroah-Hartman
                   ` (489 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nora Schiffer, Alexander Stein,
	Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nora Schiffer <nora.schiffer@ew.tq-group.com>

[ Upstream commit 08886fa69c0f56f886b63d7835da0632ea4082f7 ]

All modern TQ-Systems boards follow the convention that mmc0 is the eMMC
and mmc1 is the SD-card when both interfaces exist, reducing differences
between boards for both documentation and U-Boot code (which uses the
same Device Trees). Adjust the recently added MBLS1028A Device Tree
accordingly.

Fixes: 0538ca1f102d ("arm64: dts: ls1028a: Add mbls1028a and mbls1028a-ind devicetrees")
Signed-off-by: Nora Schiffer <nora.schiffer@ew.tq-group.com>
Reviewed-by: Alexander Stein <alexander.stein@ew.tq-group.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../boot/dts/freescale/fsl-ls1028a-tqmls1028a-mbls1028a.dtsi  | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/arm64/boot/dts/freescale/fsl-ls1028a-tqmls1028a-mbls1028a.dtsi b/arch/arm64/boot/dts/freescale/fsl-ls1028a-tqmls1028a-mbls1028a.dtsi
index cf338b2e800645..426a81e1743f11 100644
--- a/arch/arm64/boot/dts/freescale/fsl-ls1028a-tqmls1028a-mbls1028a.dtsi
+++ b/arch/arm64/boot/dts/freescale/fsl-ls1028a-tqmls1028a-mbls1028a.dtsi
@@ -17,8 +17,8 @@ aliases {
 		gpio0 = &gpio1;
 		gpio1 = &gpio2;
 		gpio2 = &gpio3;
-		mmc0 = &esdhc; /* SD-Card */
-		mmc1 = &esdhc1; /* eMMC */
+		mmc0 = &esdhc1; /* eMMC */
+		mmc1 = &esdhc; /* SD-Card */
 		serial0 = &duart0;
 		serial1 = &duart1;
 	};
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0509/2077] RDMA/siw: Fix endpoint/socket association handling
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (507 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0508/2077] arm64: dts: freescale: fsl-ls1028a-tqmls1028a-mbls1028a: switch mmc aliases Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0510/2077] selftests/bpf: Fix flaky file_reader test Greg Kroah-Hartman
                   ` (488 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Bernard Metzler,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bernard Metzler <bernard.metzler@linux.dev>

[ Upstream commit ea4f6f6c53577fb3f05dbd78b15e586772d49831 ]

Disassociating a socket from an endpoint via siw_socket_disassoc() may
release the last reference on that endpoint and free it. Therefore, don't
clear the endpoints socket pointer after calling that function, but
within.

This fixes a:

  BUG: KASAN: slab-use-after-free in siw_cm_work_handler (drivers/infiniband/sw/siw/siw_cm.c:1053 drivers/infiniband/sw/siw/siw_cm.c:1075)

which occurred after processing a malformed MPA request during connection
establishment, causing the new endpoint to be closed.

Fixes: 6c52fdc244b5c ("rdma/siw: connection management")
Link: https://patch.msgid.link/r/20260604160808.30948-1-bernard.metzler@linux.dev
Reported-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Signed-off-by: Bernard Metzler <bernard.metzler@linux.dev>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/sw/siw/siw_cm.c | 30 +++++++++++++++---------------
 1 file changed, 15 insertions(+), 15 deletions(-)

diff --git a/drivers/infiniband/sw/siw/siw_cm.c b/drivers/infiniband/sw/siw/siw_cm.c
index f7ac81c0f267a6..87c79527ac0903 100644
--- a/drivers/infiniband/sw/siw/siw_cm.c
+++ b/drivers/infiniband/sw/siw/siw_cm.c
@@ -138,6 +138,7 @@ static void siw_socket_disassoc(struct socket *s)
 		cep = sk_to_cep(sk);
 		if (cep) {
 			siw_sk_restore_upcalls(sk, cep);
+			cep->sock = NULL;
 			siw_cep_put(cep);
 		} else {
 			pr_warn("siw: cannot restore sk callbacks: no ep\n");
@@ -418,10 +419,11 @@ static void siw_free_cm_id(struct siw_cep *cep)
 
 static void siw_destroy_cep_sock(struct siw_cep *cep)
 {
-	if (cep->sock) {
-		siw_socket_disassoc(cep->sock);
-		sock_release(cep->sock);
-		cep->sock = NULL;
+	struct socket *s = cep->sock;
+
+	if (s) {
+		siw_socket_disassoc(s);
+		sock_release(s);
 	}
 }
 
@@ -1050,7 +1052,6 @@ static void siw_accept_newconn(struct siw_cep *cep)
 	if (new_s) {
 		siw_socket_disassoc(new_s);
 		sock_release(new_s);
-		new_cep->sock = NULL;
 	}
 	siw_dbg_cep(cep, "error %d\n", rv);
 }
@@ -1202,6 +1203,8 @@ static void siw_cm_work_handler(struct work_struct *w)
 		WARN(1, "Undefined CM work type: %d\n", work->type);
 	}
 	if (release_cep) {
+		struct socket *s = cep->sock;
+
 		siw_dbg_cep(cep,
 			    "release: timer=%s, QP[%u]\n",
 			    cep->mpa_timer ? "y" : "n",
@@ -1227,10 +1230,9 @@ static void siw_cm_work_handler(struct work_struct *w)
 			cep->qp = NULL;
 			siw_qp_put(qp);
 		}
-		if (cep->sock) {
-			siw_socket_disassoc(cep->sock);
-			sock_release(cep->sock);
-			cep->sock = NULL;
+		if (s) {
+			siw_socket_disassoc(s);
+			sock_release(s);
 		}
 		if (cep->cm_id) {
 			siw_free_cm_id(cep);
@@ -1561,7 +1563,6 @@ int siw_connect(struct iw_cm_id *id, struct iw_cm_conn_param *params)
 	if (cep) {
 		siw_socket_disassoc(s);
 		sock_release(s);
-		cep->sock = NULL;
 
 		cep->qp = NULL;
 
@@ -1937,7 +1938,6 @@ int siw_create_listen(struct iw_cm_id *id, int backlog)
 		siw_cep_set_inuse(cep);
 
 		siw_free_cm_id(cep);
-		cep->sock = NULL;
 		siw_socket_disassoc(s);
 		cep->state = SIW_EPSTATE_CLOSED;
 
@@ -1959,6 +1959,7 @@ static void siw_drop_listeners(struct iw_cm_id *id)
 	 */
 	list_for_each_safe(p, tmp, (struct list_head *)id->provider_data) {
 		struct siw_cep *cep = list_entry(p, struct siw_cep, listenq);
+		struct socket *s = cep->sock;
 
 		list_del(p);
 
@@ -1967,10 +1968,9 @@ static void siw_drop_listeners(struct iw_cm_id *id)
 		siw_cep_set_inuse(cep);
 
 		siw_free_cm_id(cep);
-		if (cep->sock) {
-			siw_socket_disassoc(cep->sock);
-			sock_release(cep->sock);
-			cep->sock = NULL;
+		if (s) {
+			siw_socket_disassoc(s);
+			sock_release(s);
 		}
 		cep->state = SIW_EPSTATE_CLOSED;
 		siw_cep_set_free_and_put(cep);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0510/2077] selftests/bpf: Fix flaky file_reader test
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (508 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0509/2077] RDMA/siw: Fix endpoint/socket association handling Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0511/2077] bpf: Clear rb node linkage when freeing bpf_rb_root Greg Kroah-Hartman
                   ` (487 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shung-Hsi Yu, Mykyta Yatsenko,
	Ihor Solodrai, Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mykyta Yatsenko <yatsenko@meta.com>

[ Upstream commit aa22d619ba22177f430693cf5e9495052d996644 ]

file_reader/on_open_expect_fault test expects page fault
when reading pages from the test harness executable.
It is not guaranteed that those are paged out, even
after madvise(MADV_PAGEOUT).
Relax the condition in the test to succeed with both
0 and -EFAULT returned.

Fixes: 784cdf931543 ("selftests/bpf: add file dynptr tests")
Reported-by: Shung-Hsi Yu <shung-hsi.yu@suse.com>
Closes: https://lore.kernel.org/all/ah6g7JSYOWGp2oAG@u94a/
Signed-off-by: Mykyta Yatsenko <yatsenko@meta.com>
Tested-by: Ihor Solodrai <ihor.solodrai@linux.dev>
Link: https://lore.kernel.org/r/20260603-file_reader_flake-v1-1-7f3f52d1e388@meta.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/bpf/progs/file_reader.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/selftests/bpf/progs/file_reader.c b/tools/testing/selftests/bpf/progs/file_reader.c
index 462712ff3b8a0b..aa2c05cce2b302 100644
--- a/tools/testing/selftests/bpf/progs/file_reader.c
+++ b/tools/testing/selftests/bpf/progs/file_reader.c
@@ -50,7 +50,7 @@ int on_open_expect_fault(void *c)
 		goto out;
 
 	local_err = bpf_dynptr_read(tmp_buf, user_buf_sz, &dynptr, user_buf_sz, 0);
-	if (local_err == -EFAULT) { /* Expect page fault */
+	if (local_err == -EFAULT || local_err == 0) { /* Expect page fault or success */
 		local_err = 0;
 		run_success = 1;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0511/2077] bpf: Clear rb node linkage when freeing bpf_rb_root
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (509 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0510/2077] selftests/bpf: Fix flaky file_reader test Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0512/2077] bpf: Check tail zero of bpf_map_info Greg Kroah-Hartman
                   ` (486 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kaitao Cheng, Yonghong Song,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kaitao Cheng <chengkaitao@kylinos.cn>

[ Upstream commit 4a7910ee060d8ce55612f5b3cc267f3a265a3cec ]

bpf_rb_root_free() detaches the root by copying the current rb_root_cached
and then replacing the live root with RB_ROOT_CACHED. It then walks the
copied root and drops each object contained in the tree.

This leaves the rb node state intact while dropping the object. If the
object is refcounted and survives the drop, its bpf_rb_node_kern still
contains an owner pointer to the freed root and stale rb tree linkage. If
a later bpf_rb_root allocation reuses the same address, bpf_rbtree_remove()
can incorrectly pass the owner check and call rb_erase_cached() on a node
whose rb pointers belong to the old tree.

Mirror the list draining behavior by marking nodes as busy while the root
is being detached, then clear the rb node and release the owner before
dropping the containing object. This makes surviving nodes unowned and
safe to reject from remove or accept for a later add.

Fixes: 9c395c1b99bd ("bpf: Add basic bpf_rb_{root,node} support")
Signed-off-by: Kaitao Cheng <chengkaitao@kylinos.cn>
Acked-by: Yonghong Song <yonghong.song@linux.dev>
Link: https://lore.kernel.org/r/20260605094143.5509-1-kaitao.cheng@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/bpf/helpers.c | 11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

diff --git a/kernel/bpf/helpers.c b/kernel/bpf/helpers.c
index b5314c9fed3cf0..5c1e5c8812b12b 100644
--- a/kernel/bpf/helpers.c
+++ b/kernel/bpf/helpers.c
@@ -2295,6 +2295,7 @@ void bpf_rb_root_free(const struct btf_field *field, void *rb_root,
 		      struct bpf_spin_lock *spin_lock)
 {
 	struct rb_root_cached orig_root, *root = rb_root;
+	struct bpf_rb_node_kern *node;
 	struct rb_node *pos, *n;
 	void *obj;
 
@@ -2303,14 +2304,20 @@ void bpf_rb_root_free(const struct btf_field *field, void *rb_root,
 
 	__bpf_spin_lock_irqsave(spin_lock);
 	orig_root = *root;
+	bpf_rbtree_postorder_for_each_entry_safe(pos, n, &orig_root.rb_root) {
+		node = rb_entry(pos, struct bpf_rb_node_kern, rb_node);
+		WRITE_ONCE(node->owner, BPF_PTR_POISON);
+	}
 	*root = RB_ROOT_CACHED;
 	__bpf_spin_unlock_irqrestore(spin_lock);
 
 	bpf_rbtree_postorder_for_each_entry_safe(pos, n, &orig_root.rb_root) {
 		obj = pos;
 		obj -= field->graph_root.node_offset;
-
-
+		node = rb_entry(pos, struct bpf_rb_node_kern, rb_node);
+		RB_CLEAR_NODE(pos);
+		/* Ensure __bpf_rbtree_add() sees the node as unlinked. */
+		smp_store_release(&node->owner, NULL);
 		__bpf_obj_drop_impl(obj, field->graph_root.value_rec, false);
 	}
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0512/2077] bpf: Check tail zero of bpf_map_info
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (510 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0511/2077] bpf: Clear rb node linkage when freeing bpf_rb_root Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0513/2077] bpf: Check tail zero of bpf_prog_info Greg Kroah-Hartman
                   ` (485 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mykyta Yatsenko, Leon Hwang,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leon Hwang <leon.hwang@linux.dev>

[ Upstream commit e2a49fdb1beed150125b4104c90eb2a96ec7f63a ]

Since there're 4 bytes padding at the end of struct bpf_map_info, they
won't be checked by bpf_check_uarg_tail_zero().

pahole -C bpf_map_info ./vmlinux
struct bpf_map_info {
	...
	__u64                      hash __attribute__((__aligned__(8))); /*    88     8 */
	__u32                      hash_size;            /*    96     4 */

	/* size: 104, cachelines: 2, members: 18 */
	/* padding: 4 */
	/* forced alignments: 1 */
	/* last cacheline: 40 bytes */
} __attribute__((__aligned__(8)));

If a future kernel extension adds a new 4-byte field, older userspace
programs allocating this structure on the stack might inadvertently pass
uninitialized stack garbage into the new field, permanently breaking
backward compatibility. -- sashiko [1]

Fix it by changing sizeof(info) to
offsetofend(struct bpf_map_info, hash_size).

And, add "__u32 :32" to the tail of struct bpf_map_info.

[1] https://lore.kernel.org/bpf/20260513224823.6494FC19425@smtp.kernel.org/

Fixes: ea2e6467ac36 ("bpf: Return hashes of maps in BPF_OBJ_GET_INFO_BY_FD")
Acked-by: Mykyta Yatsenko <yatsenko@meta.com>
Signed-off-by: Leon Hwang <leon.hwang@linux.dev>
Link: https://lore.kernel.org/r/20260605155249.20772-2-leon.hwang@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/uapi/linux/bpf.h       | 1 +
 kernel/bpf/syscall.c           | 5 +++--
 tools/include/uapi/linux/bpf.h | 1 +
 3 files changed, 5 insertions(+), 2 deletions(-)

diff --git a/include/uapi/linux/bpf.h b/include/uapi/linux/bpf.h
index 552bc5d9afbd16..93778d60c760e9 100644
--- a/include/uapi/linux/bpf.h
+++ b/include/uapi/linux/bpf.h
@@ -6719,6 +6719,7 @@ struct bpf_map_info {
 	__u64 map_extra;
 	__aligned_u64 hash;
 	__u32 hash_size;
+	__u32 :32;
 } __attribute__((aligned(8)));
 
 struct bpf_btf_info {
diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
index 2edda1844ec7fd..0be81c6437c24f 100644
--- a/kernel/bpf/syscall.c
+++ b/kernel/bpf/syscall.c
@@ -5337,10 +5337,11 @@ static int bpf_map_get_info_by_fd(struct file *file,
 {
 	struct bpf_map_info __user *uinfo = u64_to_user_ptr(attr->info.info);
 	struct bpf_map_info info;
-	u32 info_len = attr->info.info_len;
+	u32 info_len = attr->info.info_len, len;
 	int err;
 
-	err = bpf_check_uarg_tail_zero(USER_BPFPTR(uinfo), sizeof(info), info_len);
+	len = offsetofend(struct bpf_map_info, hash_size);
+	err = bpf_check_uarg_tail_zero(USER_BPFPTR(uinfo), len, info_len);
 	if (err)
 		return err;
 	info_len = min_t(u32, sizeof(info), info_len);
diff --git a/tools/include/uapi/linux/bpf.h b/tools/include/uapi/linux/bpf.h
index 677be9a4734768..4b3fecb01852ef 100644
--- a/tools/include/uapi/linux/bpf.h
+++ b/tools/include/uapi/linux/bpf.h
@@ -6719,6 +6719,7 @@ struct bpf_map_info {
 	__u64 map_extra;
 	__aligned_u64 hash;
 	__u32 hash_size;
+	__u32 :32;
 } __attribute__((aligned(8)));
 
 struct bpf_btf_info {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0513/2077] bpf: Check tail zero of bpf_prog_info
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (511 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0512/2077] bpf: Check tail zero of bpf_map_info Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0514/2077] bpf: Update transport_header when encapsulating UDP tunnel in lwt Greg Kroah-Hartman
                   ` (484 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mykyta Yatsenko, Leon Hwang,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leon Hwang <leon.hwang@linux.dev>

[ Upstream commit 786be2b05980a5828e67fc564ad7517e2adbe9bd ]

Since there're 4 bytes padding at the end of struct bpf_prog_info, they
won't be checked by bpf_check_uarg_tail_zero().

pahole -C bpf_prog_info ./vmlinux
struct bpf_prog_info {
	...
	__u32                      attach_btf_obj_id;    /*   220     4 */
	__u32                      attach_btf_id;        /*   224     4 */

	/* size: 232, cachelines: 4, members: 38 */
	/* sum members: 224 */
	/* sum bitfield members: 1 bits, bit holes: 1, sum bit holes: 31 bits */
	/* padding: 4 */
	/* forced alignments: 9 */
	/* last cacheline: 40 bytes */
} __attribute__((__aligned__(8)));

If a future kernel extension adds a new 4-byte field, older userspace
programs allocating this structure on the stack might inadvertently pass
uninitialized stack garbage into the new field, permanently breaking
backward compatibility. -- sashiko [1]

Fix it by changing sizeof(info) to
offsetofend(struct bpf_prog_info, attach_btf_id).

And, add "__u32 :32" to the tail of struct bpf_prog_info.

[1] https://lore.kernel.org/bpf/20260513224823.6494FC19425@smtp.kernel.org/

Fixes: aba64c7da983 ("bpf: Add verified_insns to bpf_prog_info and fdinfo")
Acked-by: Mykyta Yatsenko <yatsenko@meta.com>
Signed-off-by: Leon Hwang <leon.hwang@linux.dev>
Link: https://lore.kernel.org/r/20260605155249.20772-3-leon.hwang@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/uapi/linux/bpf.h       | 1 +
 kernel/bpf/syscall.c           | 5 +++--
 tools/include/uapi/linux/bpf.h | 1 +
 3 files changed, 5 insertions(+), 2 deletions(-)

diff --git a/include/uapi/linux/bpf.h b/include/uapi/linux/bpf.h
index 93778d60c760e9..daf7a1d3c18572 100644
--- a/include/uapi/linux/bpf.h
+++ b/include/uapi/linux/bpf.h
@@ -6698,6 +6698,7 @@ struct bpf_prog_info {
 	__u32 verified_insns;
 	__u32 attach_btf_obj_id;
 	__u32 attach_btf_id;
+	__u32 :32;
 } __attribute__((aligned(8)));
 
 struct bpf_map_info {
diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
index 0be81c6437c24f..bd1250a6c1e1fd 100644
--- a/kernel/bpf/syscall.c
+++ b/kernel/bpf/syscall.c
@@ -5052,10 +5052,11 @@ static int bpf_prog_get_info_by_fd(struct file *file,
 	u32 info_len = attr->info.info_len;
 	struct bpf_prog_kstats stats;
 	char __user *uinsns;
-	u32 ulen;
+	u32 ulen, len;
 	int err;
 
-	err = bpf_check_uarg_tail_zero(USER_BPFPTR(uinfo), sizeof(info), info_len);
+	len = offsetofend(struct bpf_prog_info, attach_btf_id);
+	err = bpf_check_uarg_tail_zero(USER_BPFPTR(uinfo), len, info_len);
 	if (err)
 		return err;
 	info_len = min_t(u32, sizeof(info), info_len);
diff --git a/tools/include/uapi/linux/bpf.h b/tools/include/uapi/linux/bpf.h
index 4b3fecb01852ef..9bbf35d5f141f9 100644
--- a/tools/include/uapi/linux/bpf.h
+++ b/tools/include/uapi/linux/bpf.h
@@ -6698,6 +6698,7 @@ struct bpf_prog_info {
 	__u32 verified_insns;
 	__u32 attach_btf_obj_id;
 	__u32 attach_btf_id;
+	__u32 :32;
 } __attribute__((aligned(8)));
 
 struct bpf_map_info {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0514/2077] bpf: Update transport_header when encapsulating UDP tunnel in lwt
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (512 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0513/2077] bpf: Check tail zero of bpf_prog_info Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0515/2077] kernfs: fix xattr race condition with multiple superblocks Greg Kroah-Hartman
                   ` (483 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Leon Hwang, Leon Hwang,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leon Hwang <leon.hwang@linux.dev>

[ Upstream commit 82d7d0adbc678064543e9d254864f6b4ea4a388c ]

Currently, bpf_lwt_push_ip_encap() does not update skb->transport_header.
When a driver, e.g. ice, reuses the stale skb->transport_header to
offload checksum computation to NIC hardware, VxLAN packets encapsulated
by bpf_lwt_push_encap() helper may be dropped due to incorrect checksum.

Update skb->transport_header in bpf_lwt_push_ip_encap() whenever the
encapsulated packet uses UDP, so checksum offload works correctly.

Fixes: 52f278774e79 ("bpf: implement BPF_LWT_ENCAP_IP mode in bpf_lwt_push_encap")
Cc: Leon Hwang <leon.huangfu@shopee.com>
Signed-off-by: Leon Hwang <leon.hwang@linux.dev>
Link: https://lore.kernel.org/r/20260602150931.49629-2-leon.hwang@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/core/lwt_bpf.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/net/core/lwt_bpf.c b/net/core/lwt_bpf.c
index f71ef82a5f3d36..bf588f508b79e6 100644
--- a/net/core/lwt_bpf.c
+++ b/net/core/lwt_bpf.c
@@ -599,6 +599,7 @@ static int handle_gso_encap(struct sk_buff *skb, bool ipv4, int encap_len)
 
 int bpf_lwt_push_ip_encap(struct sk_buff *skb, void *hdr, u32 len, bool ingress)
 {
+	bool is_udp_tunnel;
 	struct iphdr *iph;
 	bool ipv4;
 	int err;
@@ -612,10 +613,16 @@ int bpf_lwt_push_ip_encap(struct sk_buff *skb, void *hdr, u32 len, bool ingress)
 		ipv4 = true;
 		if (unlikely(len < iph->ihl * 4))
 			return -EINVAL;
+		is_udp_tunnel = iph->protocol == IPPROTO_UDP;
+		if (unlikely(is_udp_tunnel && len < iph->ihl * 4 + sizeof(struct udphdr)))
+			return -EINVAL;
 	} else if (iph->version == 6) {
 		ipv4 = false;
 		if (unlikely(len < sizeof(struct ipv6hdr)))
 			return -EINVAL;
+		is_udp_tunnel = ((struct ipv6hdr *)iph)->nexthdr == NEXTHDR_UDP;
+		if (unlikely(is_udp_tunnel && len < sizeof(struct ipv6hdr) + sizeof(struct udphdr)))
+			return -EINVAL;
 	} else {
 		return -EINVAL;
 	}
@@ -637,6 +644,11 @@ int bpf_lwt_push_ip_encap(struct sk_buff *skb, void *hdr, u32 len, bool ingress)
 	if (ingress)
 		skb_postpush_rcsum(skb, iph, len);
 	skb_reset_network_header(skb);
+	if (is_udp_tunnel) {
+		size_t iph_sz = ipv4 ? iph->ihl * 4 : sizeof(struct ipv6hdr);
+
+		skb_set_transport_header(skb, skb_network_offset(skb) + iph_sz);
+	}
 	memcpy(skb_network_header(skb), hdr, len);
 	bpf_compute_data_pointers(skb);
 	skb_clear_hash(skb);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0515/2077] kernfs: fix xattr race condition with multiple superblocks
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (513 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0514/2077] bpf: Update transport_header when encapsulating UDP tunnel in lwt Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0516/2077] tmpfs: simplify constructing "security.foo" xattr names Greg Kroah-Hartman
                   ` (482 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Miklos Szeredi,
	Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Miklos Szeredi <mszeredi@redhat.com>

[ Upstream commit 6a07814ff643b5c8e1353d8c6229f52fde205cde ]

Multiple superblocks with different namespaces can share the same
kernfs_node when kernfs_test_super() finds a matching root but
different namespace. This means multiple inodes from different
superblocks can reference the same kernfs_node->iattr->xattrs
structure.

The VFS layer only holds per-inode locks during xattr operations,
which is insufficient to serialize concurrent xattr modifications on
the shared kernfs_node. This can lead to race conditions in
simple_xattr_set() where the lookup->replace/remove sequence is not
atomic with respect to operations from other superblocks.

Fix this by protecting xattr operations with the existing hashed
kernfs_locks->open_file_mutex[] array, which is already used to
protect per-node open file data. The hashed mutex array provides
scalable per-node serialization (scaled by CPU count, up to 1024 locks
on 32+ CPU systems) with zero memory overhead.

Changes:
- Rename open_file_mutex[] to node_mutex[] to reflect dual purpose
- Add kernfs_node_lock_ptr() and kernfs_node_lock() helpers
- Protect simple_xattr_set() calls in kernfs_xattr_set() and
  kernfs_vfs_user_xattr_set() with the hashed mutex
- Update file.c to use new helpers via compatibility wrappers
- Update documentation to explain the extended lock usage

Fixes: b32c4a213698 ("xattr: add rhashtable-based simple_xattr infrastructure")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260601162454.2116375-1-mszeredi%40redhat.com
Assisted-by: Claude:claude-sonnet-4-5
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Link: https://patch.msgid.link/20260605135322.2632068-2-mszeredi@redhat.com
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/kernfs/file.c            | 13 +++----------
 fs/kernfs/inode.c           | 12 ++++++++++++
 fs/kernfs/kernfs-internal.h | 20 ++++++++++++++++++++
 fs/kernfs/mount.c           |  2 +-
 include/linux/kernfs.h      | 11 ++++++++---
 5 files changed, 44 insertions(+), 14 deletions(-)

diff --git a/fs/kernfs/file.c b/fs/kernfs/file.c
index 1163aa76973849..8e0e90c933720b 100644
--- a/fs/kernfs/file.c
+++ b/fs/kernfs/file.c
@@ -40,22 +40,15 @@ struct kernfs_open_node {
 static DEFINE_SPINLOCK(kernfs_notify_lock);
 static struct kernfs_node *kernfs_notify_list = KERNFS_NOTIFY_EOL;
 
+/* Compatibility wrappers - use the common hashed node lock */
 static inline struct mutex *kernfs_open_file_mutex_ptr(struct kernfs_node *kn)
 {
-	int idx = hash_ptr(kn, NR_KERNFS_LOCK_BITS);
-
-	return &kernfs_locks->open_file_mutex[idx];
+	return kernfs_node_lock_ptr(kn);
 }
 
 static inline struct mutex *kernfs_open_file_mutex_lock(struct kernfs_node *kn)
 {
-	struct mutex *lock;
-
-	lock = kernfs_open_file_mutex_ptr(kn);
-
-	mutex_lock(lock);
-
-	return lock;
+	return kernfs_node_lock(kn);
 }
 
 /**
diff --git a/fs/kernfs/inode.c b/fs/kernfs/inode.c
index 38b28aa7cd023f..e676737d9531a7 100644
--- a/fs/kernfs/inode.c
+++ b/fs/kernfs/inode.c
@@ -320,6 +320,15 @@ int kernfs_xattr_set(struct kernfs_node *kn, const char *name,
 	if (!attrs)
 		return -ENOMEM;
 
+	/*
+	 * Protect xattr modifications with the hashed per-node mutex.
+	 * Multiple superblocks (with different namespaces) can share the same
+	 * kernfs_node, so inode locking alone is insufficient. The hashed mutex
+	 * ensures serialization of concurrent xattr operations on the same node,
+	 * including the lazy allocation of the xattrs structure itself.
+	 */
+	CLASS(kernfs_node_lock, lock)(kn);
+
 	xattrs = simple_xattrs_lazy_alloc(&attrs->xattrs, value, flags);
 	if (IS_ERR_OR_NULL(xattrs))
 		return PTR_ERR(xattrs);
@@ -372,6 +381,9 @@ static int kernfs_vfs_user_xattr_set(const struct xattr_handler *handler,
 	if (!attrs)
 		return -ENOMEM;
 
+	/* See comment in kernfs_xattr_set() about locking. */
+	CLASS(kernfs_node_lock, lock)(kn);
+
 	xattrs = simple_xattrs_lazy_alloc(&attrs->xattrs, value, flags);
 	if (IS_ERR_OR_NULL(xattrs))
 		return PTR_ERR(xattrs);
diff --git a/fs/kernfs/kernfs-internal.h b/fs/kernfs/kernfs-internal.h
index 8d8912f50b054d..1dc6663553d1a5 100644
--- a/fs/kernfs/kernfs-internal.h
+++ b/fs/kernfs/kernfs-internal.h
@@ -211,4 +211,24 @@ extern const struct inode_operations kernfs_symlink_iops;
  * kernfs locks
  */
 extern struct kernfs_global_locks *kernfs_locks;
+
+/* Hashed mutex helpers - protect per-node data structures */
+static inline struct mutex *kernfs_node_lock_ptr(struct kernfs_node *kn)
+{
+	int idx = hash_ptr(kn, NR_KERNFS_LOCK_BITS);
+
+	return &kernfs_locks->node_mutex[idx];
+}
+
+static inline struct mutex *kernfs_node_lock(struct kernfs_node *kn)
+{
+	struct mutex *lock = kernfs_node_lock_ptr(kn);
+
+	mutex_lock(lock);
+	return lock;
+}
+
+DEFINE_CLASS(kernfs_node_lock, struct mutex *,
+	     mutex_unlock(_T), kernfs_node_lock(kn), struct kernfs_node *kn)
+
 #endif	/* __KERNFS_INTERNAL_H */
diff --git a/fs/kernfs/mount.c b/fs/kernfs/mount.c
index 6e3217b6e4811a..f183a96778b9a2 100644
--- a/fs/kernfs/mount.c
+++ b/fs/kernfs/mount.c
@@ -446,7 +446,7 @@ static void __init kernfs_mutex_init(void)
 	int count;
 
 	for (count = 0; count < NR_KERNFS_LOCKS; count++)
-		mutex_init(&kernfs_locks->open_file_mutex[count]);
+		mutex_init(&kernfs_locks->node_mutex[count]);
 }
 
 static void __init kernfs_lock_init(void)
diff --git a/include/linux/kernfs.h b/include/linux/kernfs.h
index e21b2f7f4159fe..351a5101c86287 100644
--- a/include/linux/kernfs.h
+++ b/include/linux/kernfs.h
@@ -76,20 +76,25 @@ struct kernfs_iattrs;
  * kernfs_open_file.
  *
  * kernfs_open_files are chained at kernfs_open_node->files, which is
- * protected by kernfs_global_locks.open_file_mutex[i].
+ * protected by kernfs_global_locks.node_mutex[i].
  *
  * To reduce possible contention in sysfs access, arising due to single
- * locks, use an array of locks (e.g. open_file_mutex) and use kernfs_node
+ * locks, use an array of locks (e.g. node_mutex) and use kernfs_node
  * object address as hash keys to get the index of these locks.
  *
  * Hashed mutexes are safe to use here because operations using these don't
  * rely on global exclusion.
  *
+ * The hashed mutex array protects per-node data: the kernfs_open_node for
+ * open file management, and kernfs_node xattr operations (necessary because
+ * multiple superblocks with different namespaces can share the same
+ * kernfs_node, making per-inode locking insufficient).
+ *
  * In future we intend to replace other global locks with hashed ones as well.
  * kernfs_global_locks acts as a holder for all such hash tables.
  */
 struct kernfs_global_locks {
-	struct mutex open_file_mutex[NR_KERNFS_LOCKS];
+	struct mutex node_mutex[NR_KERNFS_LOCKS];
 };
 
 enum kernfs_node_type {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0516/2077] tmpfs: simplify constructing "security.foo" xattr names
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (514 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0515/2077] kernfs: fix xattr race condition with multiple superblocks Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0517/2077] simple_xattr: change interface to pass struct simple_xattrs ** Greg Kroah-Hartman
                   ` (481 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Miklos Szeredi, Calum Mackay,
	Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Miklos Szeredi <mszeredi@redhat.com>

[ Upstream commit 832f4de4c8ba4f19e5df1d016a09917204b17834 ]

Use kasprintf() instead of doing it with kmalloc() + 2 x memcpy().

Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Link: https://patch.msgid.link/20260605135322.2632068-3-mszeredi@redhat.com
Tested-by: Calum Mackay <calum.mackay@oracle.com>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Stable-dep-of: 1e7cd8a53b72 ("simpe_xattr: use per-sb cache")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 mm/shmem.c | 11 ++---------
 1 file changed, 2 insertions(+), 9 deletions(-)

diff --git a/mm/shmem.c b/mm/shmem.c
index 3b5dc21b323c2f..c7897570fc9f9d 100644
--- a/mm/shmem.c
+++ b/mm/shmem.c
@@ -4232,7 +4232,6 @@ static int shmem_initxattrs(struct inode *inode,
 	struct shmem_sb_info *sbinfo = SHMEM_SB(inode->i_sb);
 	const struct xattr *xattr;
 	size_t ispace = 0;
-	size_t len;
 
 	CLASS(simple_xattrs, xattrs)();
 	if (IS_ERR(xattrs))
@@ -4260,17 +4259,11 @@ static int shmem_initxattrs(struct inode *inode,
 		if (IS_ERR(new_xattr))
 			break;
 
-		len = strlen(xattr->name) + 1;
-		new_xattr->name = kmalloc(XATTR_SECURITY_PREFIX_LEN + len,
-					  GFP_KERNEL_ACCOUNT);
+		new_xattr->name = kasprintf(GFP_KERNEL_ACCOUNT,
+					XATTR_SECURITY_PREFIX "%s", xattr->name);
 		if (!new_xattr->name)
 			break;
 
-		memcpy(new_xattr->name, XATTR_SECURITY_PREFIX,
-		       XATTR_SECURITY_PREFIX_LEN);
-		memcpy(new_xattr->name + XATTR_SECURITY_PREFIX_LEN,
-		       xattr->name, len);
-
 		if (simple_xattr_add(xattrs, new_xattr))
 			break;
 		retain_and_null_ptr(new_xattr);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0517/2077] simple_xattr: change interface to pass struct simple_xattrs **
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (515 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0516/2077] tmpfs: simplify constructing "security.foo" xattr names Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0518/2077] simpe_xattr: use per-sb cache Greg Kroah-Hartman
                   ` (480 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Miklos Szeredi,
	Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Miklos Szeredi <mszeredi@redhat.com>

[ Upstream commit 076e5cef28e27febfc09b5f72544d2b857c75201 ]

Change the simple_xattr API to accept pointer-to-pointer (struct
simple_xattrs **) instead of pointer.  This allows the functions to handle
lazy allocation internally without requiring callers to use
simple_xattrs_lazy_alloc().

The simple_xattr_set(), simple_xattr_set_limited() and simple_xattr_add()
functions now handle allocation when xattrs is NULL.  simple_xattrs_free()
now also frees the xattrs structure itself and sets the pointer to NULL.

This simplifies callers and removes the need for most callers to explicitly
manage xattrs allocation and lifetime.

In shmem_initxattrs(), the total required space for all initial xattrs
(ispace) is pre-calculated and deducted from sbinfo->free_ispace.

Since this patch modifies the function to add new xattrs directly to the
inode's &info->xattrs list rather than using a local temporary variable, a
failure means that the partially populated info->xattrs list remains
attached to the inode.

When the VFS caller handles the -ENOMEM error, it drops the newly created
inode via iput(), shmem_free_inode() adds freed to sbinfo->free_ispace a
second time, permanently inflating the tmpfs free space quota.

Fix by substracting already added xattrs from ispace.

Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Link: https://patch.msgid.link/20260605135322.2632068-4-mszeredi@redhat.com
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Stable-dep-of: 1e7cd8a53b72 ("simpe_xattr: use per-sb cache")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/kernfs/dir.c       | 12 +++--------
 fs/kernfs/inode.c     | 24 ++++------------------
 fs/pidfs.c            | 37 ++++++----------------------------
 fs/xattr.c            | 46 ++++++++++++++++++++++++++++++++++---------
 include/linux/xattr.h | 21 ++++++--------------
 mm/shmem.c            | 34 ++++++++++----------------------
 net/socket.c          | 24 +++++-----------------
 7 files changed, 71 insertions(+), 127 deletions(-)

diff --git a/fs/kernfs/dir.c b/fs/kernfs/dir.c
index e88b71607f1e51..cf6fc2bfa58024 100644
--- a/fs/kernfs/dir.c
+++ b/fs/kernfs/dir.c
@@ -608,11 +608,8 @@ void kernfs_put(struct kernfs_node *kn)
 	if (kernfs_type(kn) == KERNFS_LINK)
 		kernfs_put(kn->symlink.target_kn);
 
-	if (kn->iattr && kn->iattr->xattrs) {
-		simple_xattrs_free(kn->iattr->xattrs, NULL);
-		kfree(kn->iattr->xattrs);
-		kn->iattr->xattrs = NULL;
-	}
+	if (kn->iattr)
+		simple_xattrs_free(&kn->iattr->xattrs, NULL);
 
 	spin_lock(&root->kernfs_idr_lock);
 	idr_remove(&root->ino_idr, (u32)kernfs_ino(kn));
@@ -712,10 +709,7 @@ static struct kernfs_node *__kernfs_new_node(struct kernfs_root *root,
 
  err_out4:
 	if (kn->iattr) {
-		if (kn->iattr->xattrs) {
-			simple_xattrs_free(kn->iattr->xattrs, NULL);
-			kfree(kn->iattr->xattrs);
-		}
+		simple_xattrs_free(&kn->iattr->xattrs, NULL);
 		kmem_cache_free(kernfs_iattrs_cache, kn->iattr);
 	}
  err_out3:
diff --git a/fs/kernfs/inode.c b/fs/kernfs/inode.c
index e676737d9531a7..f2298de6bc6f8e 100644
--- a/fs/kernfs/inode.c
+++ b/fs/kernfs/inode.c
@@ -144,8 +144,7 @@ ssize_t kernfs_iop_listxattr(struct dentry *dentry, char *buf, size_t size)
 	if (!attrs)
 		return -ENOMEM;
 
-	return simple_xattr_list(d_inode(dentry), READ_ONCE(attrs->xattrs),
-				 buf, size);
+	return simple_xattr_list(d_inode(dentry), &attrs->xattrs, buf, size);
 }
 
 static inline void set_default_inode_attr(struct inode *inode, umode_t mode)
@@ -297,23 +296,17 @@ int kernfs_xattr_get(struct kernfs_node *kn, const char *name,
 		     void *value, size_t size)
 {
 	struct kernfs_iattrs *attrs = kernfs_iattrs_noalloc(kn);
-	struct simple_xattrs *xattrs;
 
 	if (!attrs)
 		return -ENODATA;
 
-	xattrs = READ_ONCE(attrs->xattrs);
-	if (!xattrs)
-		return -ENODATA;
-
-	return simple_xattr_get(xattrs, name, value, size);
+	return simple_xattr_get(&attrs->xattrs, name, value, size);
 }
 
 int kernfs_xattr_set(struct kernfs_node *kn, const char *name,
 		     const void *value, size_t size, int flags)
 {
 	struct simple_xattr *old_xattr;
-	struct simple_xattrs *xattrs;
 	struct kernfs_iattrs *attrs;
 
 	attrs = kernfs_iattrs(kn);
@@ -329,11 +322,7 @@ int kernfs_xattr_set(struct kernfs_node *kn, const char *name,
 	 */
 	CLASS(kernfs_node_lock, lock)(kn);
 
-	xattrs = simple_xattrs_lazy_alloc(&attrs->xattrs, value, flags);
-	if (IS_ERR_OR_NULL(xattrs))
-		return PTR_ERR(xattrs);
-
-	old_xattr = simple_xattr_set(xattrs, name, value, size, flags);
+	old_xattr = simple_xattr_set(&attrs->xattrs, name, value, size, flags);
 	if (IS_ERR(old_xattr))
 		return PTR_ERR(old_xattr);
 
@@ -371,7 +360,6 @@ static int kernfs_vfs_user_xattr_set(const struct xattr_handler *handler,
 {
 	const char *full_name = xattr_full_name(handler, suffix);
 	struct kernfs_node *kn = inode->i_private;
-	struct simple_xattrs *xattrs;
 	struct kernfs_iattrs *attrs;
 
 	if (!(kernfs_root(kn)->flags & KERNFS_ROOT_SUPPORT_USER_XATTR))
@@ -384,11 +372,7 @@ static int kernfs_vfs_user_xattr_set(const struct xattr_handler *handler,
 	/* See comment in kernfs_xattr_set() about locking. */
 	CLASS(kernfs_node_lock, lock)(kn);
 
-	xattrs = simple_xattrs_lazy_alloc(&attrs->xattrs, value, flags);
-	if (IS_ERR_OR_NULL(xattrs))
-		return PTR_ERR(xattrs);
-
-	return simple_xattr_set_limited(xattrs, &attrs->xattr_limits,
+	return simple_xattr_set_limited(&attrs->xattrs, &attrs->xattr_limits,
 					full_name, value, size, flags);
 }
 
diff --git a/fs/pidfs.c b/fs/pidfs.c
index 1cce4f34a05128..eb5105bddecaf0 100644
--- a/fs/pidfs.c
+++ b/fs/pidfs.c
@@ -196,12 +196,7 @@ static void pidfs_free_attr_work(struct work_struct *work)
 
 	head = llist_del_all(&pidfs_free_list);
 	llist_for_each_entry_safe(attr, next, head, pidfs_llist) {
-		struct simple_xattrs *xattrs = attr->xattrs;
-
-		if (xattrs) {
-			simple_xattrs_free(xattrs, NULL);
-			kfree(xattrs);
-		}
+		simple_xattrs_free(&attr->xattrs, NULL);
 		kfree(attr);
 	}
 }
@@ -815,14 +810,8 @@ static ssize_t pidfs_listxattr(struct dentry *dentry, char *buf, size_t size)
 {
 	struct inode *inode = d_inode(dentry);
 	struct pid *pid = inode->i_private;
-	struct pidfs_attr *attr = pid->attr;
-	struct simple_xattrs *xattrs;
-
-	xattrs = READ_ONCE(attr->xattrs);
-	if (!xattrs)
-		return 0;
 
-	return simple_xattr_list(inode, xattrs, buf, size);
+	return simple_xattr_list(inode, &pid->attr->xattrs, buf, size);
 }
 
 static const struct inode_operations pidfs_inode_operations = {
@@ -1057,16 +1046,9 @@ static int pidfs_xattr_get(const struct xattr_handler *handler,
 			   const char *suffix, void *value, size_t size)
 {
 	struct pid *pid = inode->i_private;
-	struct pidfs_attr *attr = pid->attr;
-	const char *name;
-	struct simple_xattrs *xattrs;
-
-	xattrs = READ_ONCE(attr->xattrs);
-	if (!xattrs)
-		return -ENODATA;
+	const char *name = xattr_full_name(handler, suffix);
 
-	name = xattr_full_name(handler, suffix);
-	return simple_xattr_get(xattrs, name, value, size);
+	return simple_xattr_get(&pid->attr->xattrs, name, value, size);
 }
 
 static int pidfs_xattr_set(const struct xattr_handler *handler,
@@ -1075,20 +1057,13 @@ static int pidfs_xattr_set(const struct xattr_handler *handler,
 			   const void *value, size_t size, int flags)
 {
 	struct pid *pid = inode->i_private;
-	struct pidfs_attr *attr = pid->attr;
-	const char *name;
-	struct simple_xattrs *xattrs;
+	const char *name = xattr_full_name(handler, suffix);
 	struct simple_xattr *old_xattr;
 
 	/* Ensure we're the only one to set @attr->xattrs. */
 	WARN_ON_ONCE(!inode_is_locked(inode));
 
-	xattrs = simple_xattrs_lazy_alloc(&attr->xattrs, value, flags);
-	if (IS_ERR_OR_NULL(xattrs))
-		return PTR_ERR(xattrs);
-
-	name = xattr_full_name(handler, suffix);
-	old_xattr = simple_xattr_set(xattrs, name, value, size, flags);
+	old_xattr = simple_xattr_set(&pid->attr->xattrs, name, value, size, flags);
 	if (IS_ERR(old_xattr))
 		return PTR_ERR(old_xattr);
 
diff --git a/fs/xattr.c b/fs/xattr.c
index 09ecbaaa16608a..9ef7ad8a8f3218 100644
--- a/fs/xattr.c
+++ b/fs/xattr.c
@@ -1311,12 +1311,17 @@ static const struct rhashtable_params simple_xattr_params = {
  * Return: On success the length of the xattr value is returned. On error a
  * negative error code is returned.
  */
-int simple_xattr_get(struct simple_xattrs *xattrs, const char *name,
+int simple_xattr_get(struct simple_xattrs **xattrsp, const char *name,
 		     void *buffer, size_t size)
 {
+	struct simple_xattrs *xattrs;
 	struct simple_xattr *xattr;
 	int ret = -ENODATA;
 
+	xattrs = READ_ONCE(*xattrsp);
+	if (!xattrs)
+		return -ENODATA;
+
 	guard(rcu)();
 	xattr = rhashtable_lookup(&xattrs->ht, name, simple_xattr_params);
 	if (xattr) {
@@ -1331,6 +1336,9 @@ int simple_xattr_get(struct simple_xattrs *xattrs, const char *name,
 	return ret;
 }
 
+static struct simple_xattrs *simple_xattrs_lazy_alloc(struct simple_xattrs **xattrsp,
+						      const void *value, int flags);
+
 /**
  * simple_xattr_set - set an xattr object
  * @xattrs: the header of the xattr object
@@ -1362,13 +1370,18 @@ int simple_xattr_get(struct simple_xattrs *xattrs, const char *name,
  * Return: On success, the removed or replaced xattr is returned, to be freed
  * by the caller; or NULL if none. On failure a negative error code is returned.
  */
-struct simple_xattr *simple_xattr_set(struct simple_xattrs *xattrs,
+struct simple_xattr *simple_xattr_set(struct simple_xattrs **xattrsp,
 				      const char *name, const void *value,
 				      size_t size, int flags)
 {
+	struct simple_xattrs *xattrs;
 	struct simple_xattr *old_xattr = NULL;
 	int err;
 
+	xattrs = simple_xattrs_lazy_alloc(xattrsp, value, flags);
+	if (IS_ERR_OR_NULL(xattrs))
+		return ERR_CAST(xattrs);
+
 	CLASS(simple_xattr, new_xattr)(value, size);
 	if (IS_ERR(new_xattr))
 		return new_xattr;
@@ -1467,7 +1480,7 @@ static inline int simple_xattr_limits_inc(struct simple_xattr_limits *limits,
  * Return: On success zero is returned. On failure a negative error code is
  * returned.
  */
-int simple_xattr_set_limited(struct simple_xattrs *xattrs,
+int simple_xattr_set_limited(struct simple_xattrs **xattrs,
 			     struct simple_xattr_limits *limits,
 			     const char *name, const void *value,
 			     size_t size, int flags)
@@ -1527,10 +1540,11 @@ static bool xattr_is_maclabel(const char *name)
  * Return: On success the required size or the size of the copied xattrs is
  * returned. On error a negative error code is returned.
  */
-ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs *xattrs,
+ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs **xattrsp,
 			  char *buffer, size_t size)
 {
 	bool trusted = ns_capable_noaudit(&init_user_ns, CAP_SYS_ADMIN);
+	struct simple_xattrs *xattrs;
 	struct rhashtable_iter iter;
 	struct simple_xattr *xattr;
 	ssize_t remaining_size = size;
@@ -1552,6 +1566,7 @@ ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs *xattrs,
 	remaining_size -= err;
 	err = 0;
 
+	xattrs = READ_ONCE(*xattrsp);
 	if (!xattrs)
 		return size - remaining_size;
 
@@ -1597,9 +1612,15 @@ ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs *xattrs,
  * Return: On success zero is returned. On failure a negative error code is
  * returned.
  */
-int simple_xattr_add(struct simple_xattrs *xattrs,
+int simple_xattr_add(struct simple_xattrs **xattrsp,
 		     struct simple_xattr *new_xattr)
 {
+	struct simple_xattrs *xattrs;
+
+	xattrs = simple_xattrs_lazy_alloc(xattrsp, new_xattr->value, 0);
+	if (IS_ERR(xattrs))
+		return PTR_ERR(xattrs);
+
 	return rhashtable_insert_fast(&xattrs->ht, &new_xattr->hash_node,
 				      simple_xattr_params);
 }
@@ -1629,7 +1650,7 @@ int simple_xattrs_init(struct simple_xattrs *xattrs)
  * Return: On success a new simple_xattrs is returned. On failure an
  * ERR_PTR is returned.
  */
-struct simple_xattrs *simple_xattrs_alloc(void)
+static struct simple_xattrs *simple_xattrs_alloc(void)
 {
 	struct simple_xattrs *xattrs __free(kfree) = NULL;
 	int ret;
@@ -1661,8 +1682,8 @@ struct simple_xattrs *simple_xattrs_alloc(void)
  * check with IS_ERR_OR_NULL() and propagate with PTR_ERR() which
  * correctly returns 0 for the NULL no-op case.
  */
-struct simple_xattrs *simple_xattrs_lazy_alloc(struct simple_xattrs **xattrsp,
-					       const void *value, int flags)
+static struct simple_xattrs *simple_xattrs_lazy_alloc(struct simple_xattrs **xattrsp,
+						      const void *value, int flags)
 {
 	struct simple_xattrs *xattrs;
 
@@ -1697,12 +1718,19 @@ static void simple_xattr_ht_free(void *ptr, void *arg)
  * Destroy all xattrs in @xattr. When this is called no one can hold a
  * reference to any of the xattrs anymore.
  */
-void simple_xattrs_free(struct simple_xattrs *xattrs, size_t *freed_space)
+void simple_xattrs_free(struct simple_xattrs **xattrsp, size_t *freed_space)
 {
+	struct simple_xattrs *xattrs = *xattrsp;
+
 	might_sleep();
 
+	if (!xattrs)
+		return;
+
 	if (freed_space)
 		*freed_space = 0;
 	rhashtable_free_and_destroy(&xattrs->ht, simple_xattr_ht_free,
 				    freed_space);
+	kfree(xattrs);
+	*xattrsp = NULL;
 }
diff --git a/include/linux/xattr.h b/include/linux/xattr.h
index 8b6601367eae8e..ded446c1ef81fc 100644
--- a/include/linux/xattr.h
+++ b/include/linux/xattr.h
@@ -133,26 +133,23 @@ static inline void simple_xattr_limits_init(struct simple_xattr_limits *limits)
 }
 
 int simple_xattrs_init(struct simple_xattrs *xattrs);
-struct simple_xattrs *simple_xattrs_alloc(void);
-struct simple_xattrs *simple_xattrs_lazy_alloc(struct simple_xattrs **xattrsp,
-					       const void *value, int flags);
-void simple_xattrs_free(struct simple_xattrs *xattrs, size_t *freed_space);
+void simple_xattrs_free(struct simple_xattrs **xattrs, size_t *freed_space);
 size_t simple_xattr_space(const char *name, size_t size);
 struct simple_xattr *simple_xattr_alloc(const void *value, size_t size);
 void simple_xattr_free(struct simple_xattr *xattr);
 void simple_xattr_free_rcu(struct simple_xattr *xattr);
-int simple_xattr_get(struct simple_xattrs *xattrs, const char *name,
+int simple_xattr_get(struct simple_xattrs **xattrs, const char *name,
 		     void *buffer, size_t size);
-struct simple_xattr *simple_xattr_set(struct simple_xattrs *xattrs,
+struct simple_xattr *simple_xattr_set(struct simple_xattrs **xattrs,
 				      const char *name, const void *value,
 				      size_t size, int flags);
-int simple_xattr_set_limited(struct simple_xattrs *xattrs,
+int simple_xattr_set_limited(struct simple_xattrs **xattrs,
 			     struct simple_xattr_limits *limits,
 			     const char *name, const void *value,
 			     size_t size, int flags);
-ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs *xattrs,
+ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs **xattrs,
 			  char *buffer, size_t size);
-int simple_xattr_add(struct simple_xattrs *xattrs,
+int simple_xattr_add(struct simple_xattrs **xattrs,
 		     struct simple_xattr *new_xattr);
 int xattr_list_one(char **buffer, ssize_t *remaining_size, const char *name);
 
@@ -162,10 +159,4 @@ DEFINE_CLASS(simple_xattr,
 	     simple_xattr_alloc(value, size),
 	     const void *value, size_t size)
 
-DEFINE_CLASS(simple_xattrs,
-            struct simple_xattrs *,
-            if (!IS_ERR_OR_NULL(_T)) { simple_xattrs_free(_T, NULL); kfree(_T); },
-            simple_xattrs_alloc(),
-            void)
-
 #endif	/* _LINUX_XATTR_H */
diff --git a/mm/shmem.c b/mm/shmem.c
index c7897570fc9f9d..cf4ee9f4119115 100644
--- a/mm/shmem.c
+++ b/mm/shmem.c
@@ -1425,10 +1425,8 @@ static void shmem_evict_inode(struct inode *inode)
 		}
 	}
 
-	if (info->xattrs) {
-		simple_xattrs_free(info->xattrs, sbinfo->max_inodes ? &freed : NULL);
-		kfree(info->xattrs);
-	}
+	simple_xattrs_free(&info->xattrs, sbinfo->max_inodes ? &freed : NULL);
+
 	shmem_free_inode(inode->i_sb, freed);
 	WARN_ON(inode->i_blocks);
 	clear_inode(inode);
@@ -4233,10 +4231,6 @@ static int shmem_initxattrs(struct inode *inode,
 	const struct xattr *xattr;
 	size_t ispace = 0;
 
-	CLASS(simple_xattrs, xattrs)();
-	if (IS_ERR(xattrs))
-		return PTR_ERR(xattrs);
-
 	if (sbinfo->max_inodes) {
 		for (xattr = xattr_array; xattr->name != NULL; xattr++) {
 			ispace += simple_xattr_space(xattr->name,
@@ -4264,8 +4258,11 @@ static int shmem_initxattrs(struct inode *inode,
 		if (!new_xattr->name)
 			break;
 
-		if (simple_xattr_add(xattrs, new_xattr))
+		if (simple_xattr_add(&info->xattrs, new_xattr))
 			break;
+
+		if (sbinfo->max_inodes)
+			ispace -= simple_xattr_space(new_xattr->name, new_xattr->size);
 		retain_and_null_ptr(new_xattr);
 	}
 
@@ -4277,8 +4274,8 @@ static int shmem_initxattrs(struct inode *inode,
 		}
 		return -ENOMEM;
 	}
+	WARN_ON(ispace);
 
-	smp_store_release(&info->xattrs, no_free_ptr(xattrs));
 	return 0;
 }
 
@@ -4287,14 +4284,9 @@ static int shmem_xattr_handler_get(const struct xattr_handler *handler,
 				   const char *name, void *buffer, size_t size)
 {
 	struct shmem_inode_info *info = SHMEM_I(inode);
-	struct simple_xattrs *xattrs;
-
-	xattrs = READ_ONCE(info->xattrs);
-	if (!xattrs)
-		return -ENODATA;
 
 	name = xattr_full_name(handler, name);
-	return simple_xattr_get(xattrs, name, buffer, size);
+	return simple_xattr_get(&info->xattrs, name, buffer, size);
 }
 
 static int shmem_xattr_handler_set(const struct xattr_handler *handler,
@@ -4305,16 +4297,11 @@ static int shmem_xattr_handler_set(const struct xattr_handler *handler,
 {
 	struct shmem_inode_info *info = SHMEM_I(inode);
 	struct shmem_sb_info *sbinfo = SHMEM_SB(inode->i_sb);
-	struct simple_xattrs *xattrs;
 	struct simple_xattr *old_xattr;
 	size_t ispace = 0;
 
 	name = xattr_full_name(handler, name);
 
-	xattrs = simple_xattrs_lazy_alloc(&info->xattrs, value, flags);
-	if (IS_ERR_OR_NULL(xattrs))
-		return PTR_ERR(xattrs);
-
 	if (value && sbinfo->max_inodes) {
 		ispace = simple_xattr_space(name, size);
 		raw_spin_lock(&sbinfo->stat_lock);
@@ -4327,7 +4314,7 @@ static int shmem_xattr_handler_set(const struct xattr_handler *handler,
 			return -ENOSPC;
 	}
 
-	old_xattr = simple_xattr_set(xattrs, name, value, size, flags);
+	old_xattr = simple_xattr_set(&info->xattrs, name, value, size, flags);
 	if (!IS_ERR(old_xattr)) {
 		ispace = 0;
 		if (old_xattr && sbinfo->max_inodes)
@@ -4375,8 +4362,7 @@ static ssize_t shmem_listxattr(struct dentry *dentry, char *buffer, size_t size)
 {
 	struct shmem_inode_info *info = SHMEM_I(d_inode(dentry));
 
-	return simple_xattr_list(d_inode(dentry), READ_ONCE(info->xattrs),
-				 buffer, size);
+	return simple_xattr_list(d_inode(dentry), &info->xattrs, buffer, size);
 }
 #endif /* CONFIG_TMPFS_XATTR */
 
diff --git a/net/socket.c b/net/socket.c
index c2698a1441a7dd..c59aa002d3e355 100644
--- a/net/socket.c
+++ b/net/socket.c
@@ -347,12 +347,8 @@ static struct inode *sock_alloc_inode(struct super_block *sb)
 static void sock_evict_inode(struct inode *inode)
 {
 	struct sockfs_inode *si = SOCKFS_I(inode);
-	struct simple_xattrs *xattrs = si->xattrs;
 
-	if (xattrs) {
-		simple_xattrs_free(xattrs, NULL);
-		kfree(xattrs);
-	}
+	simple_xattrs_free(&si->xattrs, NULL);
 	clear_inode(inode);
 }
 
@@ -443,13 +439,9 @@ static int sockfs_user_xattr_get(const struct xattr_handler *handler,
 				 const char *suffix, void *value, size_t size)
 {
 	const char *name = xattr_full_name(handler, suffix);
-	struct simple_xattrs *xattrs;
-
-	xattrs = READ_ONCE(SOCKFS_I(inode)->xattrs);
-	if (!xattrs)
-		return -ENODATA;
+	struct sockfs_inode *si = SOCKFS_I(inode);
 
-	return simple_xattr_get(xattrs, name, value, size);
+	return simple_xattr_get(&si->xattrs, name, value, size);
 }
 
 static int sockfs_user_xattr_set(const struct xattr_handler *handler,
@@ -460,13 +452,8 @@ static int sockfs_user_xattr_set(const struct xattr_handler *handler,
 {
 	const char *name = xattr_full_name(handler, suffix);
 	struct sockfs_inode *si = SOCKFS_I(inode);
-	struct simple_xattrs *xattrs;
-
-	xattrs = simple_xattrs_lazy_alloc(&si->xattrs, value, flags);
-	if (IS_ERR_OR_NULL(xattrs))
-		return PTR_ERR(xattrs);
 
-	return simple_xattr_set_limited(xattrs, &si->xattr_limits,
+	return simple_xattr_set_limited(&si->xattrs, &si->xattr_limits,
 					name, value, size, flags);
 }
 
@@ -635,8 +622,7 @@ static ssize_t sockfs_listxattr(struct dentry *dentry, char *buffer,
 	struct sockfs_inode *si = SOCKFS_I(d_inode(dentry));
 	ssize_t len, used;
 
-	len = simple_xattr_list(d_inode(dentry), READ_ONCE(si->xattrs),
-				buffer, size);
+	len = simple_xattr_list(d_inode(dentry), &si->xattrs, buffer, size);
 	if (len < 0)
 		return len;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0518/2077] simpe_xattr: use per-sb cache
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (516 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0517/2077] simple_xattr: change interface to pass struct simple_xattrs ** Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0519/2077] kernfs: link kn to its parent before the LSM init hook Greg Kroah-Hartman
                   ` (479 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Miklos Szeredi,
	Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Miklos Szeredi <mszeredi@redhat.com>

[ Upstream commit 1e7cd8a53b72a58a44c4d282aed95f6ce0e76db0 ]

Move the hash table to the super block to remove excessive overhead in case
of small number of xattrs per inode.

Add linked list to the inode, used for listxattr and eviction.  Listxattr
uses rcu protection to iterate the list of xattrs.

Before being made per-sb, lazy allocation was protected by inode lock.  Now
inode lock no longer provides sufficient exclusion, so use cmpxchg() to
ensure atomicity.

Though I haven't found a description of this pattern, after some research
it seems that cmpxchg_release() and READ_ONCE() should provide the
necessary memory barriers.

Use simple_xattr_free_rcu() in simple_xattrs_free(). This is needed because
the hash table is now shared between inodes and lookup on a different inode
might be running the compare function on the just freed element within the
RCU grace period.

Following stats are based on slabinfo diff, after creating 100k empty
files, then adding a "user.test=foo" xattr to each:

v7.0 (no rhashtable):
  File creation: 993.40 bytes/file
  Xattr addition: 79.99 bytes/file

v7.1-rc2 (per-inode rhashtable):
  File creation: 939.73 bytes/file
  Xattr addition: 1296.08 bytes/file

v7.1-rc2 + this patch (per-sb rhashtable)
  File creation: 946.84 bytes/file
  Xattr addition: 111.86 bytes/file

The overhead of a single xattr is reduced to nearly v7.0 levels.  The per
xattr overhead is slightly larger due to the addition of three pointers to
struct simple_xattr.

Fixes: b32c4a213698 ("xattr: add rhashtable-based simple_xattr infrastructure")
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Link: https://patch.msgid.link/20260605135322.2632068-5-mszeredi@redhat.com
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/kernfs/dir.c             |   5 +-
 fs/kernfs/inode.c           |  10 +-
 fs/kernfs/kernfs-internal.h |   4 +-
 fs/pidfs.c                  |  14 +-
 fs/xattr.c                  | 283 +++++++++++++++++-------------------
 include/linux/shmem_fs.h    |   3 +-
 include/linux/xattr.h       |  26 ++--
 mm/shmem.c                  |  13 +-
 net/socket.c                |  12 +-
 9 files changed, 192 insertions(+), 178 deletions(-)

diff --git a/fs/kernfs/dir.c b/fs/kernfs/dir.c
index cf6fc2bfa58024..78812cf1256b95 100644
--- a/fs/kernfs/dir.c
+++ b/fs/kernfs/dir.c
@@ -609,7 +609,7 @@ void kernfs_put(struct kernfs_node *kn)
 		kernfs_put(kn->symlink.target_kn);
 
 	if (kn->iattr)
-		simple_xattrs_free(&kn->iattr->xattrs, NULL);
+		simple_xattrs_free(&root->xa_cache, &kn->iattr->xattrs, NULL);
 
 	spin_lock(&root->kernfs_idr_lock);
 	idr_remove(&root->ino_idr, (u32)kernfs_ino(kn));
@@ -624,6 +624,7 @@ void kernfs_put(struct kernfs_node *kn)
 	} else {
 		/* just released the root kn, free @root too */
 		idr_destroy(&root->ino_idr);
+		simple_xattr_cache_cleanup(&root->xa_cache);
 		kfree_rcu(root, rcu);
 	}
 }
@@ -709,7 +710,7 @@ static struct kernfs_node *__kernfs_new_node(struct kernfs_root *root,
 
  err_out4:
 	if (kn->iattr) {
-		simple_xattrs_free(&kn->iattr->xattrs, NULL);
+		simple_xattrs_free(&root->xa_cache, &kn->iattr->xattrs, NULL);
 		kmem_cache_free(kernfs_iattrs_cache, kn->iattr);
 	}
  err_out3:
diff --git a/fs/kernfs/inode.c b/fs/kernfs/inode.c
index f2298de6bc6f8e..2cb20294aaf58a 100644
--- a/fs/kernfs/inode.c
+++ b/fs/kernfs/inode.c
@@ -37,6 +37,7 @@ static struct kernfs_iattrs *__kernfs_iattrs(struct kernfs_node *kn, bool alloc)
 	if (!ret)
 		return NULL;
 
+	INIT_LIST_HEAD_RCU(&ret->xattrs);
 	/* assign default attributes */
 	ret->ia_uid = GLOBAL_ROOT_UID;
 	ret->ia_gid = GLOBAL_ROOT_GID;
@@ -296,11 +297,12 @@ int kernfs_xattr_get(struct kernfs_node *kn, const char *name,
 		     void *value, size_t size)
 {
 	struct kernfs_iattrs *attrs = kernfs_iattrs_noalloc(kn);
+	struct simple_xattr_cache *cache = &kernfs_root(kn)->xa_cache;
 
 	if (!attrs)
 		return -ENODATA;
 
-	return simple_xattr_get(&attrs->xattrs, name, value, size);
+	return simple_xattr_get(cache, &attrs->xattrs, name, value, size);
 }
 
 int kernfs_xattr_set(struct kernfs_node *kn, const char *name,
@@ -308,6 +310,7 @@ int kernfs_xattr_set(struct kernfs_node *kn, const char *name,
 {
 	struct simple_xattr *old_xattr;
 	struct kernfs_iattrs *attrs;
+	struct simple_xattr_cache *cache = &kernfs_root(kn)->xa_cache;
 
 	attrs = kernfs_iattrs(kn);
 	if (!attrs)
@@ -322,7 +325,7 @@ int kernfs_xattr_set(struct kernfs_node *kn, const char *name,
 	 */
 	CLASS(kernfs_node_lock, lock)(kn);
 
-	old_xattr = simple_xattr_set(&attrs->xattrs, name, value, size, flags);
+	old_xattr = simple_xattr_set(cache, &attrs->xattrs, name, value, size, flags);
 	if (IS_ERR(old_xattr))
 		return PTR_ERR(old_xattr);
 
@@ -372,7 +375,8 @@ static int kernfs_vfs_user_xattr_set(const struct xattr_handler *handler,
 	/* See comment in kernfs_xattr_set() about locking. */
 	CLASS(kernfs_node_lock, lock)(kn);
 
-	return simple_xattr_set_limited(&attrs->xattrs, &attrs->xattr_limits,
+	return simple_xattr_set_limited(&kernfs_root(kn)->xa_cache,
+					&attrs->xattrs, &attrs->xattr_limits,
 					full_name, value, size, flags);
 }
 
diff --git a/fs/kernfs/kernfs-internal.h b/fs/kernfs/kernfs-internal.h
index 1dc6663553d1a5..aa784b540b3616 100644
--- a/fs/kernfs/kernfs-internal.h
+++ b/fs/kernfs/kernfs-internal.h
@@ -26,7 +26,7 @@ struct kernfs_iattrs {
 	struct timespec64	ia_mtime;
 	struct timespec64	ia_ctime;
 
-	struct simple_xattrs	*xattrs;
+	struct list_head	xattrs;
 	struct simple_xattr_limits xattr_limits;
 };
 
@@ -54,6 +54,8 @@ struct kernfs_root {
 	rwlock_t		kernfs_rename_lock;
 
 	struct rcu_head		rcu;
+
+	struct simple_xattr_cache xa_cache;
 };
 
 /* +1 to avoid triggering overflow warning when negating it */
diff --git a/fs/pidfs.c b/fs/pidfs.c
index eb5105bddecaf0..143d0aec16af10 100644
--- a/fs/pidfs.c
+++ b/fs/pidfs.c
@@ -37,6 +37,8 @@ static struct kmem_cache *pidfs_attr_cachep __ro_after_init;
 
 static struct path pidfs_root_path = {};
 
+static struct simple_xattr_cache pidfs_xa_cache;
+
 void pidfs_get_root(struct path *path)
 {
 	*path = pidfs_root_path;
@@ -96,7 +98,7 @@ static const struct rhashtable_params pidfs_ino_ht_params = {
  * use file handles.
  */
 struct pidfs_attr {
-	struct simple_xattrs *xattrs;
+	struct list_head xattrs;
 	union {
 		struct pidfs_anon_attr;
 		struct llist_node pidfs_llist;
@@ -196,7 +198,7 @@ static void pidfs_free_attr_work(struct work_struct *work)
 
 	head = llist_del_all(&pidfs_free_list);
 	llist_for_each_entry_safe(attr, next, head, pidfs_llist) {
-		simple_xattrs_free(&attr->xattrs, NULL);
+		simple_xattrs_free(&pidfs_xa_cache, &attr->xattrs, NULL);
 		kfree(attr);
 	}
 }
@@ -224,7 +226,7 @@ void pidfs_free_pid(struct pid *pid)
 	if (IS_ERR(attr))
 		return;
 
-	if (likely(!attr->xattrs))
+	if (likely(list_empty(&attr->xattrs)))
 		kfree(attr);
 	else if (llist_add(&attr->pidfs_llist, &pidfs_free_list))
 		schedule_work(&pidfs_free_work);
@@ -1007,6 +1009,8 @@ int pidfs_register_pid(struct pid *pid)
 	if (!new_attr)
 		return -ENOMEM;
 
+	INIT_LIST_HEAD_RCU(&new_attr->xattrs);
+
 	/* Synchronize with pidfs_exit(). */
 	guard(spinlock_irq)(&pid->wait_pidfd.lock);
 
@@ -1048,7 +1052,7 @@ static int pidfs_xattr_get(const struct xattr_handler *handler,
 	struct pid *pid = inode->i_private;
 	const char *name = xattr_full_name(handler, suffix);
 
-	return simple_xattr_get(&pid->attr->xattrs, name, value, size);
+	return simple_xattr_get(&pidfs_xa_cache, &pid->attr->xattrs, name, value, size);
 }
 
 static int pidfs_xattr_set(const struct xattr_handler *handler,
@@ -1063,7 +1067,7 @@ static int pidfs_xattr_set(const struct xattr_handler *handler,
 	/* Ensure we're the only one to set @attr->xattrs. */
 	WARN_ON_ONCE(!inode_is_locked(inode));
 
-	old_xattr = simple_xattr_set(&pid->attr->xattrs, name, value, size, flags);
+	old_xattr = simple_xattr_set(&pidfs_xa_cache, &pid->attr->xattrs, name, value, size, flags);
 	if (IS_ERR(old_xattr))
 		return PTR_ERR(old_xattr);
 
diff --git a/fs/xattr.c b/fs/xattr.c
index 9ef7ad8a8f3218..89374cd9029a77 100644
--- a/fs/xattr.c
+++ b/fs/xattr.c
@@ -28,6 +28,11 @@
 
 #include "internal.h"
 
+struct sx_key {
+	const struct list_head *parent;
+	const char *name;
+};
+
 static const char *
 strcmp_prefix(const char *a, const char *a_prefix)
 {
@@ -1269,23 +1274,32 @@ struct simple_xattr *simple_xattr_alloc(const void *value, size_t size)
 	return new_xattr;
 }
 
+static u32 sx_hashfn(const char *name, const struct list_head *parent, u32 seed)
+{
+	return jhash(name, strlen(name), jhash(&parent, sizeof(parent), seed));
+}
+
 static u32 simple_xattr_hashfn(const void *data, u32 len, u32 seed)
 {
-	const char *name = data;
-	return jhash(name, strlen(name), seed);
+	const struct sx_key *key = data;
+
+	return sx_hashfn(key->name, key->parent, seed);
 }
 
 static u32 simple_xattr_obj_hashfn(const void *obj, u32 len, u32 seed)
 {
 	const struct simple_xattr *xattr = obj;
-	return jhash(xattr->name, strlen(xattr->name), seed);
+
+	return sx_hashfn(xattr->name, xattr->parent, seed);
 }
 
 static int simple_xattr_obj_cmpfn(struct rhashtable_compare_arg *arg,
 				   const void *obj)
 {
 	const struct simple_xattr *xattr = obj;
-	return strcmp(xattr->name, arg->key);
+	const struct sx_key *key = arg->key;
+
+	return xattr->parent != key->parent || strcmp(xattr->name, key->name);
 }
 
 static const struct rhashtable_params simple_xattr_params = {
@@ -1298,6 +1312,7 @@ static const struct rhashtable_params simple_xattr_params = {
 
 /**
  * simple_xattr_get - get an xattr object
+ * @cache: anchor for the hash table
  * @xattrs: the header of the xattr object
  * @name: the name of the xattr to retrieve
  * @buffer: the buffer to store the value into
@@ -1311,19 +1326,19 @@ static const struct rhashtable_params simple_xattr_params = {
  * Return: On success the length of the xattr value is returned. On error a
  * negative error code is returned.
  */
-int simple_xattr_get(struct simple_xattrs **xattrsp, const char *name,
-		     void *buffer, size_t size)
+int simple_xattr_get(struct simple_xattr_cache *cache, struct list_head *xattrs,
+		     const char *name, void *buffer, size_t size)
 {
-	struct simple_xattrs *xattrs;
 	struct simple_xattr *xattr;
+	struct sx_key key = { .parent = xattrs, .name = name };
+	struct rhashtable *ht = READ_ONCE(cache->ht);
 	int ret = -ENODATA;
 
-	xattrs = READ_ONCE(*xattrsp);
-	if (!xattrs)
-		return -ENODATA;
+	if (!ht)
+		return ret;
 
 	guard(rcu)();
-	xattr = rhashtable_lookup(&xattrs->ht, name, simple_xattr_params);
+	xattr = rhashtable_lookup(ht, &key, simple_xattr_params);
 	if (xattr) {
 		ret = xattr->size;
 		if (buffer) {
@@ -1336,11 +1351,45 @@ int simple_xattr_get(struct simple_xattrs **xattrsp, const char *name,
 	return ret;
 }
 
-static struct simple_xattrs *simple_xattrs_lazy_alloc(struct simple_xattrs **xattrsp,
-						      const void *value, int flags);
+static struct rhashtable *simple_xattrs_lazy_alloc(struct simple_xattr_cache *cache,
+						   const void *value, int flags)
+{
+	struct rhashtable *oldht, *ht = READ_ONCE(cache->ht);
+	int err;
+
+	if (unlikely(!ht)) {
+		if (!value)
+			return (flags & XATTR_REPLACE) ? ERR_PTR(-ENODATA) : NULL;
+
+		ht = kzalloc_obj(*ht);
+		if (!ht)
+			return ERR_PTR(-ENOMEM);
+
+		err = rhashtable_init(ht, &simple_xattr_params);
+		if (err) {
+			kfree(ht);
+			return ERR_PTR(err);
+		}
+
+		/*
+		 * Provides release semantics on success, so that use of a
+		 * non-NULL READ_ONCE(cache->ht) will be ordered relative to the
+		 * above initialization, due to implicit address dependency.
+		 */
+		oldht = cmpxchg_release(&cache->ht, NULL, ht);
+		if (oldht) {
+			/* Race lost */
+			rhashtable_destroy(ht);
+			kfree(ht);
+			ht = oldht;
+		}
+	}
+	return ht;
+}
 
 /**
  * simple_xattr_set - set an xattr object
+ * @cache: anchor for the hash table
  * @xattrs: the header of the xattr object
  * @name: the name of the xattr to retrieve
  * @value: the value to store along the xattr
@@ -1370,50 +1419,58 @@ static struct simple_xattrs *simple_xattrs_lazy_alloc(struct simple_xattrs **xat
  * Return: On success, the removed or replaced xattr is returned, to be freed
  * by the caller; or NULL if none. On failure a negative error code is returned.
  */
-struct simple_xattr *simple_xattr_set(struct simple_xattrs **xattrsp,
+struct simple_xattr *simple_xattr_set(struct simple_xattr_cache *cache, struct list_head *xattrs,
 				      const char *name, const void *value,
 				      size_t size, int flags)
 {
-	struct simple_xattrs *xattrs;
+	struct sx_key key = { .parent = xattrs, .name = name };
 	struct simple_xattr *old_xattr = NULL;
+	struct rhashtable *ht;
 	int err;
 
-	xattrs = simple_xattrs_lazy_alloc(xattrsp, value, flags);
-	if (IS_ERR_OR_NULL(xattrs))
-		return ERR_CAST(xattrs);
+	ht = simple_xattrs_lazy_alloc(cache, value, flags);
+	if (IS_ERR_OR_NULL(ht))
+		return ERR_CAST(ht);
 
 	CLASS(simple_xattr, new_xattr)(value, size);
 	if (IS_ERR(new_xattr))
 		return new_xattr;
 
 	if (new_xattr) {
+		new_xattr->parent = xattrs;
 		new_xattr->name = kstrdup(name, GFP_KERNEL_ACCOUNT);
 		if (!new_xattr->name)
 			return ERR_PTR(-ENOMEM);
 	}
 
-	/* Lookup is safe without RCU here since writes are serialized. */
-	old_xattr = rhashtable_lookup_fast(&xattrs->ht, name,
-					   simple_xattr_params);
-
+	/*
+	 * Hash table lookup/replace/remove will grab RCU read lock themselves.
+	 * This makes sure that hash table lookup is safe against concurrent
+	 * modification on another inode.
+	 */
+	old_xattr = rhashtable_lookup_fast(ht, &key, simple_xattr_params);
 	if (old_xattr) {
 		/* Fail if XATTR_CREATE is requested and the xattr exists. */
 		if (flags & XATTR_CREATE)
 			return ERR_PTR(-EEXIST);
 
 		if (new_xattr) {
-			err = rhashtable_replace_fast(&xattrs->ht,
+			err = rhashtable_replace_fast(ht,
 						      &old_xattr->hash_node,
 						      &new_xattr->hash_node,
 						      simple_xattr_params);
 			if (err)
 				return ERR_PTR(err);
+
+			list_replace_rcu(&old_xattr->node, &new_xattr->node);
 		} else {
-			err = rhashtable_remove_fast(&xattrs->ht,
+			err = rhashtable_remove_fast(ht,
 						     &old_xattr->hash_node,
 						     simple_xattr_params);
 			if (err)
 				return ERR_PTR(err);
+
+			list_del_rcu(&old_xattr->node);
 		}
 	} else {
 		/* Fail if XATTR_REPLACE is requested but no xattr is found. */
@@ -1425,11 +1482,13 @@ struct simple_xattr *simple_xattr_set(struct simple_xattrs **xattrsp,
 		 * new value simply insert it.
 		 */
 		if (new_xattr) {
-			err = rhashtable_insert_fast(&xattrs->ht,
+			err = rhashtable_insert_fast(ht,
 						     &new_xattr->hash_node,
 						     simple_xattr_params);
 			if (err)
 				return ERR_PTR(err);
+
+			list_add_tail_rcu(&new_xattr->node, xattrs);
 		}
 
 		/*
@@ -1466,6 +1525,7 @@ static inline int simple_xattr_limits_inc(struct simple_xattr_limits *limits,
 
 /**
  * simple_xattr_set_limited - set an xattr with per-inode user.* limits
+ * @cache: anchor for the hash table
  * @xattrs: the header of the xattr object
  * @limits: per-inode limit counters for user.* xattrs
  * @name: the name of the xattr to set or remove
@@ -1480,7 +1540,7 @@ static inline int simple_xattr_limits_inc(struct simple_xattr_limits *limits,
  * Return: On success zero is returned. On failure a negative error code is
  * returned.
  */
-int simple_xattr_set_limited(struct simple_xattrs **xattrs,
+int simple_xattr_set_limited(struct simple_xattr_cache *cache, struct list_head *xattrs,
 			     struct simple_xattr_limits *limits,
 			     const char *name, const void *value,
 			     size_t size, int flags)
@@ -1494,7 +1554,7 @@ int simple_xattr_set_limited(struct simple_xattrs **xattrs,
 			return ret;
 	}
 
-	old_xattr = simple_xattr_set(xattrs, name, value, size, flags);
+	old_xattr = simple_xattr_set(cache, xattrs, name, value, size, flags);
 	if (IS_ERR(old_xattr)) {
 		if (value)
 			simple_xattr_limits_dec(limits, size);
@@ -1540,12 +1600,10 @@ static bool xattr_is_maclabel(const char *name)
  * Return: On success the required size or the size of the copied xattrs is
  * returned. On error a negative error code is returned.
  */
-ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs **xattrsp,
+ssize_t simple_xattr_list(struct inode *inode, struct list_head *xattrs,
 			  char *buffer, size_t size)
 {
 	bool trusted = ns_capable_noaudit(&init_user_ns, CAP_SYS_ADMIN);
-	struct simple_xattrs *xattrs;
-	struct rhashtable_iter iter;
 	struct simple_xattr *xattr;
 	ssize_t remaining_size = size;
 	int err = 0;
@@ -1566,21 +1624,11 @@ ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs **xattrsp,
 	remaining_size -= err;
 	err = 0;
 
-	xattrs = READ_ONCE(*xattrsp);
 	if (!xattrs)
 		return size - remaining_size;
 
-	rhashtable_walk_enter(&xattrs->ht, &iter);
-	rhashtable_walk_start(&iter);
-
-	while ((xattr = rhashtable_walk_next(&iter)) != NULL) {
-		if (IS_ERR(xattr)) {
-			if (PTR_ERR(xattr) == -EAGAIN)
-				continue;
-			err = PTR_ERR(xattr);
-			break;
-		}
-
+	rcu_read_lock();
+	list_for_each_entry_rcu(xattr, xattrs, node) {
 		/* skip "trusted." attributes for unprivileged callers */
 		if (!trusted && xattr_is_trusted(xattr->name))
 			continue;
@@ -1593,15 +1641,14 @@ ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs **xattrsp,
 		if (err)
 			break;
 	}
-
-	rhashtable_walk_stop(&iter);
-	rhashtable_walk_exit(&iter);
+	rcu_read_unlock();
 
 	return err ? err : size - remaining_size;
 }
 
 /**
  * simple_xattr_add - add xattr objects
+ * @cache: anchor for the hash table
  * @xattrs: the header of the xattr object
  * @new_xattr: the xattr object to add
  *
@@ -1612,125 +1659,67 @@ ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs **xattrsp,
  * Return: On success zero is returned. On failure a negative error code is
  * returned.
  */
-int simple_xattr_add(struct simple_xattrs **xattrsp,
+int simple_xattr_add(struct simple_xattr_cache *cache, struct list_head *xattrs,
 		     struct simple_xattr *new_xattr)
 {
-	struct simple_xattrs *xattrs;
-
-	xattrs = simple_xattrs_lazy_alloc(xattrsp, new_xattr->value, 0);
-	if (IS_ERR(xattrs))
-		return PTR_ERR(xattrs);
-
-	return rhashtable_insert_fast(&xattrs->ht, &new_xattr->hash_node,
-				      simple_xattr_params);
-}
-
-/**
- * simple_xattrs_init - initialize new xattr header
- * @xattrs: header to initialize
- *
- * Initialize the rhashtable used to store xattr objects.
- *
- * Return: On success zero is returned. On failure a negative error code is
- * returned.
- */
-int simple_xattrs_init(struct simple_xattrs *xattrs)
-{
-	return rhashtable_init(&xattrs->ht, &simple_xattr_params);
-}
-
-/**
- * simple_xattrs_alloc - allocate and initialize a new xattr header
- *
- * Dynamically allocate a simple_xattrs header and initialize the
- * underlying rhashtable. This is intended for consumers that want
- * to lazily allocate xattr storage only when the first xattr is set,
- * avoiding the per-inode rhashtable overhead when no xattrs are used.
- *
- * Return: On success a new simple_xattrs is returned. On failure an
- * ERR_PTR is returned.
- */
-static struct simple_xattrs *simple_xattrs_alloc(void)
-{
-	struct simple_xattrs *xattrs __free(kfree) = NULL;
-	int ret;
+	struct rhashtable *ht;
+	int err;
 
-	xattrs = kzalloc(sizeof(*xattrs), GFP_KERNEL);
-	if (!xattrs)
-		return ERR_PTR(-ENOMEM);
+	ht = simple_xattrs_lazy_alloc(cache, new_xattr->value, 0);
+	if (IS_ERR(ht))
+		return PTR_ERR(ht);
 
-	ret = simple_xattrs_init(xattrs);
-	if (ret)
-		return ERR_PTR(ret);
+	new_xattr->parent = xattrs;
+	err = rhashtable_insert_fast(ht, &new_xattr->hash_node, simple_xattr_params);
+	if (err)
+		return err;
 
-	return no_free_ptr(xattrs);
+	list_add_tail_rcu(&new_xattr->node, xattrs);
+	return 0;
 }
 
 /**
- * simple_xattrs_lazy_alloc - get or allocate xattrs for a set operation
- * @xattrsp: pointer to the xattrs pointer (may point to NULL)
- * @value: value being set (NULL means remove)
- * @flags: xattr set flags
- *
- * For lazily-allocated xattrs on the write path. If no xattrs exist yet
- * and this is a remove operation, returns the appropriate result without
- * allocating. Otherwise ensures xattrs is allocated and published with
- * store-release semantics.
+ * simple_xattrs_free - free xattrs
+ * @cache: anchor for the hash table
+ * @xattrs: xattr header whose xattrs to destroy
+ * @freed_space: approximate number of bytes of memory freed from @xattrs
  *
- * Return: On success a valid pointer to the xattrs is returned. On
- * failure or early-exit an ERR_PTR or NULL is returned. Callers should
- * check with IS_ERR_OR_NULL() and propagate with PTR_ERR() which
- * correctly returns 0 for the NULL no-op case.
+ * Destroy all xattrs in @xattrs. When this is called no one can hold a
+ * reference to any of the xattrs anymore.
  */
-static struct simple_xattrs *simple_xattrs_lazy_alloc(struct simple_xattrs **xattrsp,
-						      const void *value, int flags)
+void simple_xattrs_free(struct simple_xattr_cache *cache, struct list_head *xattrs,
+			size_t *freed_space)
 {
-	struct simple_xattrs *xattrs;
-
-	xattrs = READ_ONCE(*xattrsp);
-	if (xattrs)
-		return xattrs;
-
-	if (!value)
-		return (flags & XATTR_REPLACE) ? ERR_PTR(-ENODATA) : NULL;
-
-	xattrs = simple_xattrs_alloc();
-	if (!IS_ERR(xattrs))
-		smp_store_release(xattrsp, xattrs);
-	return xattrs;
-}
+	if (freed_space)
+		*freed_space = 0;
 
-static void simple_xattr_ht_free(void *ptr, void *arg)
-{
-	struct simple_xattr *xattr = ptr;
-	size_t *freed_space = arg;
+	while (!list_empty(xattrs)) {
+		struct simple_xattr *xattr = list_first_entry(xattrs, typeof(*xattr), node);
 
-	if (freed_space)
-		*freed_space += simple_xattr_space(xattr->name, xattr->size);
-	simple_xattr_free(xattr);
+		rhashtable_remove_fast(cache->ht, &xattr->hash_node, simple_xattr_params);
+		list_del(&xattr->node);
+		if (freed_space)
+			*freed_space += simple_xattr_space(xattr->name, xattr->size);
+		/*
+		 * Free with RCU, since the xattr might still get accessed by
+		 * the hash compare function
+		 */
+		simple_xattr_free_rcu(xattr);
+	}
 }
 
 /**
- * simple_xattrs_free - free xattrs
- * @xattrs: xattr header whose xattrs to destroy
- * @freed_space: approximate number of bytes of memory freed from @xattrs
+ * simple_xattr_cache_cleanup - free the cache
+ * @cache: anchor for the hash table
  *
- * Destroy all xattrs in @xattr. When this is called no one can hold a
- * reference to any of the xattrs anymore.
+ * Destroy the cache table, which was lazily allocated on adding the first xattr.
  */
-void simple_xattrs_free(struct simple_xattrs **xattrsp, size_t *freed_space)
+void simple_xattr_cache_cleanup(struct simple_xattr_cache *cache)
 {
-	struct simple_xattrs *xattrs = *xattrsp;
-
-	might_sleep();
-
-	if (!xattrs)
-		return;
-
-	if (freed_space)
-		*freed_space = 0;
-	rhashtable_free_and_destroy(&xattrs->ht, simple_xattr_ht_free,
-				    freed_space);
-	kfree(xattrs);
-	*xattrsp = NULL;
+	if (cache->ht) {
+		WARN_ON(atomic_read(&cache->ht->nelems));
+		rhashtable_destroy(cache->ht);
+		kfree(cache->ht);
+		cache->ht = NULL;
+	}
 }
diff --git a/include/linux/shmem_fs.h b/include/linux/shmem_fs.h
index 93a0ba872ebe04..69b0177da15648 100644
--- a/include/linux/shmem_fs.h
+++ b/include/linux/shmem_fs.h
@@ -48,7 +48,7 @@ struct shmem_inode_info {
 	};
 	struct timespec64	i_crtime;	/* file creation time */
 	struct shared_policy	policy;		/* NUMA memory alloc policy */
-	struct simple_xattrs	*xattrs;	/* list of xattrs */
+	struct list_head        xattrs;		/* list of xattrs */
 	pgoff_t			fallocend;	/* highest fallocate endindex */
 	unsigned int		fsflags;	/* for FS_IOC_[SG]ETFLAGS */
 	atomic_t		stop_eviction;	/* hold when working on inode */
@@ -89,6 +89,7 @@ struct shmem_sb_info {
 	struct list_head shrinklist;  /* List of shinkable inodes */
 	unsigned long shrinklist_len; /* Length of shrinklist */
 	struct shmem_quota_limits qlimits; /* Default quota limits */
+	struct simple_xattr_cache xa_cache;
 };
 
 static inline struct shmem_inode_info *SHMEM_I(struct inode *inode)
diff --git a/include/linux/xattr.h b/include/linux/xattr.h
index ded446c1ef81fc..7aaaf4f8aff5be 100644
--- a/include/linux/xattr.h
+++ b/include/linux/xattr.h
@@ -106,12 +106,14 @@ static inline const char *xattr_prefix(const struct xattr_handler *handler)
 	return handler->prefix ?: handler->name;
 }
 
-struct simple_xattrs {
-	struct rhashtable ht;
+struct simple_xattr_cache {
+	struct rhashtable *ht;
 };
 
 struct simple_xattr {
 	struct rhash_head hash_node;
+	struct list_head *parent;
+	struct list_head node;
 	struct rcu_head rcu;
 	char *name;
 	size_t size;
@@ -132,27 +134,31 @@ static inline void simple_xattr_limits_init(struct simple_xattr_limits *limits)
 	atomic_set(&limits->xattr_size, 0);
 }
 
-int simple_xattrs_init(struct simple_xattrs *xattrs);
-void simple_xattrs_free(struct simple_xattrs **xattrs, size_t *freed_space);
+void simple_xattrs_free(struct simple_xattr_cache *cache, struct list_head *xattrs,
+			size_t *freed_space);
 size_t simple_xattr_space(const char *name, size_t size);
 struct simple_xattr *simple_xattr_alloc(const void *value, size_t size);
 void simple_xattr_free(struct simple_xattr *xattr);
 void simple_xattr_free_rcu(struct simple_xattr *xattr);
-int simple_xattr_get(struct simple_xattrs **xattrs, const char *name,
-		     void *buffer, size_t size);
-struct simple_xattr *simple_xattr_set(struct simple_xattrs **xattrs,
+int simple_xattr_get(struct simple_xattr_cache *cache, struct list_head *xattrs,
+		     const char *name, void *buffer, size_t size);
+struct simple_xattr *simple_xattr_set(struct simple_xattr_cache *cache,
+				      struct list_head *xattrs,
 				      const char *name, const void *value,
 				      size_t size, int flags);
-int simple_xattr_set_limited(struct simple_xattrs **xattrs,
+int simple_xattr_set_limited(struct simple_xattr_cache *cache,
+			     struct list_head *xattrs,
 			     struct simple_xattr_limits *limits,
 			     const char *name, const void *value,
 			     size_t size, int flags);
-ssize_t simple_xattr_list(struct inode *inode, struct simple_xattrs **xattrs,
+ssize_t simple_xattr_list(struct inode *inode, struct list_head *xattrs,
 			  char *buffer, size_t size);
-int simple_xattr_add(struct simple_xattrs **xattrs,
+int simple_xattr_add(struct simple_xattr_cache *cache, struct list_head *xattrs,
 		     struct simple_xattr *new_xattr);
 int xattr_list_one(char **buffer, ssize_t *remaining_size, const char *name);
 
+void simple_xattr_cache_cleanup(struct simple_xattr_cache *cache);
+
 DEFINE_CLASS(simple_xattr,
 	     struct simple_xattr *,
 	     if (!IS_ERR_OR_NULL(_T)) simple_xattr_free(_T),
diff --git a/mm/shmem.c b/mm/shmem.c
index cf4ee9f4119115..7b1ea9fb598f4a 100644
--- a/mm/shmem.c
+++ b/mm/shmem.c
@@ -1425,7 +1425,7 @@ static void shmem_evict_inode(struct inode *inode)
 		}
 	}
 
-	simple_xattrs_free(&info->xattrs, sbinfo->max_inodes ? &freed : NULL);
+	simple_xattrs_free(&sbinfo->xa_cache, &info->xattrs, sbinfo->max_inodes ? &freed : NULL);
 
 	shmem_free_inode(inode->i_sb, freed);
 	WARN_ON(inode->i_blocks);
@@ -3084,6 +3084,7 @@ static struct inode *__shmem_get_inode(struct mnt_idmap *idmap,
 	inode->i_generation = get_random_u32();
 	info = SHMEM_I(inode);
 	memset(info, 0, (char *)inode - (char *)info);
+	INIT_LIST_HEAD_RCU(&info->xattrs);
 	spin_lock_init(&info->lock);
 	atomic_set(&info->stop_eviction, 0);
 	info->seals = F_SEAL_SEAL;
@@ -4258,7 +4259,7 @@ static int shmem_initxattrs(struct inode *inode,
 		if (!new_xattr->name)
 			break;
 
-		if (simple_xattr_add(&info->xattrs, new_xattr))
+		if (simple_xattr_add(&sbinfo->xa_cache, &info->xattrs, new_xattr))
 			break;
 
 		if (sbinfo->max_inodes)
@@ -4283,10 +4284,11 @@ static int shmem_xattr_handler_get(const struct xattr_handler *handler,
 				   struct dentry *unused, struct inode *inode,
 				   const char *name, void *buffer, size_t size)
 {
+	struct shmem_sb_info *sbinfo = SHMEM_SB(inode->i_sb);
 	struct shmem_inode_info *info = SHMEM_I(inode);
 
 	name = xattr_full_name(handler, name);
-	return simple_xattr_get(&info->xattrs, name, buffer, size);
+	return simple_xattr_get(&sbinfo->xa_cache, &info->xattrs, name, buffer, size);
 }
 
 static int shmem_xattr_handler_set(const struct xattr_handler *handler,
@@ -4314,7 +4316,7 @@ static int shmem_xattr_handler_set(const struct xattr_handler *handler,
 			return -ENOSPC;
 	}
 
-	old_xattr = simple_xattr_set(&info->xattrs, name, value, size, flags);
+	old_xattr = simple_xattr_set(&sbinfo->xa_cache, &info->xattrs, name, value, size, flags);
 	if (!IS_ERR(old_xattr)) {
 		ispace = 0;
 		if (old_xattr && sbinfo->max_inodes)
@@ -4963,6 +4965,9 @@ static void shmem_put_super(struct super_block *sb)
 	free_percpu(sbinfo->ino_batch);
 	percpu_counter_destroy(&sbinfo->used_blocks);
 	mpol_put(sbinfo->mpol);
+#ifdef CONFIG_TMPFS_XATTR
+	simple_xattr_cache_cleanup(&sbinfo->xa_cache);
+#endif
 	kfree(sbinfo);
 	sb->s_fs_info = NULL;
 }
diff --git a/net/socket.c b/net/socket.c
index c59aa002d3e355..f51bdcbaa43f7e 100644
--- a/net/socket.c
+++ b/net/socket.c
@@ -310,8 +310,10 @@ static int move_addr_to_user(struct sockaddr_storage *kaddr, int klen,
 
 static struct kmem_cache *sock_inode_cachep __ro_after_init;
 
+static struct simple_xattr_cache sockfs_xa_cache;
+
 struct sockfs_inode {
-	struct simple_xattrs *xattrs;
+	struct list_head xattrs;
 	struct simple_xattr_limits xattr_limits;
 	struct socket_alloc;
 };
@@ -328,7 +330,7 @@ static struct inode *sock_alloc_inode(struct super_block *sb)
 	si = alloc_inode_sb(sb, sock_inode_cachep, GFP_KERNEL);
 	if (!si)
 		return NULL;
-	si->xattrs = NULL;
+	INIT_LIST_HEAD_RCU(&si->xattrs);
 	simple_xattr_limits_init(&si->xattr_limits);
 
 	init_waitqueue_head(&si->socket.wq.wait);
@@ -348,7 +350,7 @@ static void sock_evict_inode(struct inode *inode)
 {
 	struct sockfs_inode *si = SOCKFS_I(inode);
 
-	simple_xattrs_free(&si->xattrs, NULL);
+	simple_xattrs_free(&sockfs_xa_cache, &si->xattrs, NULL);
 	clear_inode(inode);
 }
 
@@ -441,7 +443,7 @@ static int sockfs_user_xattr_get(const struct xattr_handler *handler,
 	const char *name = xattr_full_name(handler, suffix);
 	struct sockfs_inode *si = SOCKFS_I(inode);
 
-	return simple_xattr_get(&si->xattrs, name, value, size);
+	return simple_xattr_get(&sockfs_xa_cache, &si->xattrs, name, value, size);
 }
 
 static int sockfs_user_xattr_set(const struct xattr_handler *handler,
@@ -453,7 +455,7 @@ static int sockfs_user_xattr_set(const struct xattr_handler *handler,
 	const char *name = xattr_full_name(handler, suffix);
 	struct sockfs_inode *si = SOCKFS_I(inode);
 
-	return simple_xattr_set_limited(&si->xattrs, &si->xattr_limits,
+	return simple_xattr_set_limited(&sockfs_xa_cache, &si->xattrs, &si->xattr_limits,
 					name, value, size, flags);
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0519/2077] kernfs: link kn to its parent before the LSM init hook
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (517 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0518/2077] simpe_xattr: use per-sb cache Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0520/2077] wifi: wcn36xx: fix heap overflow from oversized firmware HAL response Greg Kroah-Hartman
                   ` (478 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Calum Mackay,
	Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Brauner <brauner@kernel.org>

[ Upstream commit 6cccc49b027c7551ffc1d2532f2ef1922661f3da ]

After commit 12e9e3cd03b5 ("simpe_xattr: use per-sb cache"),
kernfs_xattr_set() and kernfs_xattr_get() compute the cache via
kernfs_root(kn) before any other check.  kernfs_root(kn) walks
kn->__parent first and falls back to kn->dir.root, both of which are
NULL on a freshly kmem_cache_zalloc()'d kn. kn->__parent was being set
in kernfs_new_node() after __kernfs_new_node() returned, and kn->dir.root
is set even later by kernfs_create_dir_ns() / kernfs_create_empty_dir().

The LSM kernfs_init_security hook is invoked from inside
__kernfs_new_node(), before either field has been initialized.
selinux_kernfs_init_security() ends with kernfs_xattr_set(kn,
XATTR_NAME_SELINUX, ...).  kernfs_root(kn) then returns NULL, and
&((struct kernfs_root *)NULL)->xa_cache evaluates to
offsetof(struct kernfs_root, xa_cache) which faults:

  BUG: kernel NULL pointer dereference, address: 00000000000000e0
  RIP: 0010:simple_xattr_set+0x27/0x8b0
  Call Trace:
   kernfs_xattr_set+0x63/0xb0
   selinux_kernfs_init_security+0x13b/0x270
   security_kernfs_init_security+0x36/0xc0
   __kernfs_new_node+0x182/0x290
   kernfs_new_node+0x80/0xc0
   kernfs_create_dir_ns+0x2b/0xa0
   cgroup_create+0x116/0x380
   cgroup_mkdir+0x7c/0x1a0

Reproduces deterministically at PID 1 (systemd) on an SELinux-enabled
distro. The first cgroup mkdir under /sys/fs/cgroup with a labelled
parent panics the kernel.

The LSM hook's contract is that the kn_dir argument is the parent of
the new kn, so kn->__parent should already point at kn_dir when the
hook runs.  Move kernfs_get(parent) and rcu_assign_pointer of
kn->__parent from kernfs_new_node() into __kernfs_new_node() right
before the security hook, and unwind the parent reference on the
err_out4 path.  kernfs_root(kn) then takes its parent branch during
the hook and returns parent->dir.root, which is the correct root.

This also closes the same-shape latent bug in kernfs_xattr_get() (which
today is hidden only by kernfs_iattrs_noalloc() returning NULL on a
fresh kn).

Fixes: 12e9e3cd03b5 ("simpe_xattr: use per-sb cache")
Reported-by: Calum Mackay <calum.mackay@oracle.com>
Closes: https://lore.kernel.org/all/5386153f-9112-4971-98fc-de90d7aae2c6@oracle.com/
Link: https://patch.msgid.link/20260526-ablief-demut-wehen-aef8446ef5c9@brauner
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/kernfs/dir.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/fs/kernfs/dir.c b/fs/kernfs/dir.c
index 78812cf1256b95..97d9d227b66d9d 100644
--- a/fs/kernfs/dir.c
+++ b/fs/kernfs/dir.c
@@ -701,6 +701,9 @@ static struct kernfs_node *__kernfs_new_node(struct kernfs_root *root,
 	}
 
 	if (parent) {
+		kernfs_get(parent);
+		rcu_assign_pointer(kn->__parent, parent);
+
 		ret = security_kernfs_init_security(parent, kn);
 		if (ret)
 			goto err_out4;
@@ -709,6 +712,8 @@ static struct kernfs_node *__kernfs_new_node(struct kernfs_root *root,
 	return kn;
 
  err_out4:
+	RCU_INIT_POINTER(kn->__parent, NULL);
+	kernfs_put(parent);
 	if (kn->iattr) {
 		simple_xattrs_free(&root->xa_cache, &kn->iattr->xattrs, NULL);
 		kmem_cache_free(kernfs_iattrs_cache, kn->iattr);
@@ -745,10 +750,6 @@ struct kernfs_node *kernfs_new_node(struct kernfs_node *parent,
 
 	kn = __kernfs_new_node(kernfs_root(parent), parent,
 			       name, mode, uid, gid, flags);
-	if (kn) {
-		kernfs_get(parent);
-		rcu_assign_pointer(kn->__parent, parent);
-	}
 	return kn;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0520/2077] wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (518 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0519/2077] kernfs: link kn to its parent before the LSM init hook Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0521/2077] wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication Greg Kroah-Hartman
                   ` (477 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tristan Madani, Loic Poulain,
	Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tristan Madani <tristan@talencesecurity.com>

[ Upstream commit 88a240d86d3d64521f9194abe185ac71cc74d0bd ]

The firmware response dispatcher copies all synchronous HAL responses
into the 4096-byte hal_buf without validating the response length. A
response exceeding WCN36XX_HAL_BUF_SIZE causes a heap buffer overflow
with firmware-controlled content.

Add a bounds check on the response length.

Fixes: 8e84c2582169 ("wcn36xx: mac80211 driver for Qualcomm WCN3660/WCN3680 hardware")
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Link: https://patch.msgid.link/20260421135018.352774-2-tristmd@gmail.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/wcn36xx/smd.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/net/wireless/ath/wcn36xx/smd.c b/drivers/net/wireless/ath/wcn36xx/smd.c
index 813553edcb7899..f65328329f4f08 100644
--- a/drivers/net/wireless/ath/wcn36xx/smd.c
+++ b/drivers/net/wireless/ath/wcn36xx/smd.c
@@ -3293,6 +3293,10 @@ int wcn36xx_smd_rsp_process(struct rpmsg_device *rpdev,
 	case WCN36XX_HAL_EXIT_IMPS_RSP:
 	case WCN36XX_HAL_UPDATE_CHANNEL_LIST_RSP:
 	case WCN36XX_HAL_ADD_BCN_FILTER_RSP:
+		if (len > WCN36XX_HAL_BUF_SIZE) {
+			wcn36xx_warn("HAL response too large: %d\n", len);
+			break;
+		}
 		memcpy(wcn->hal_buf, buf, len);
 		wcn->hal_rsp_len = len;
 		complete(&wcn->hal_rsp_compl);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0521/2077] wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (519 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0520/2077] wifi: wcn36xx: fix heap overflow from oversized firmware HAL response Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0522/2077] wifi: wcn36xx: fix OOB read from short trigger BA firmware response Greg Kroah-Hartman
                   ` (476 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tristan Madani, Loic Poulain,
	Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tristan Madani <tristan@talencesecurity.com>

[ Upstream commit df2187acfca6c6cca372c5d35f42394d9c270b09 ]

The firmware-controlled rsp->count field is used as the loop bound for
indexing into the flexible rsp->regs[] array without validation against
the message length. A count exceeding the actual data causes out-of-
bounds reads from the heap-allocated message buffer.

Add a check that count fits within the received message.

Fixes: 43efa3c0f241 ("wcn36xx: Implement print_reg indication")
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Link: https://patch.msgid.link/20260421135018.352774-3-tristmd@gmail.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/wcn36xx/smd.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/net/wireless/ath/wcn36xx/smd.c b/drivers/net/wireless/ath/wcn36xx/smd.c
index f65328329f4f08..2a0c946d810950 100644
--- a/drivers/net/wireless/ath/wcn36xx/smd.c
+++ b/drivers/net/wireless/ath/wcn36xx/smd.c
@@ -2805,6 +2805,12 @@ static int wcn36xx_smd_print_reg_info_ind(struct wcn36xx *wcn,
 		return -EIO;
 	}
 
+	if (rsp->count > (len - sizeof(*rsp)) / sizeof(rsp->regs[0])) {
+		wcn36xx_warn("Truncated print reg info indication: count %u, len %zu\n",
+			     rsp->count, len);
+		return -EIO;
+	}
+
 	wcn36xx_dbg(WCN36XX_DBG_HAL,
 		    "reginfo indication, scenario: 0x%x reason: 0x%x\n",
 		    rsp->scenario, rsp->reason);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0522/2077] wifi: wcn36xx: fix OOB read from short trigger BA firmware response
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (520 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0521/2077] wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0523/2077] ALSA: seq: Fix partial userptr event expansion Greg Kroah-Hartman
                   ` (475 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tristan Madani, Loic Poulain,
	Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tristan Madani <tristan@talencesecurity.com>

[ Upstream commit b5e6f21923ca89d90256e7346301056f6502691e ]

The firmware response length is only checked against sizeof(*rsp) (20
bytes), but when candidate_cnt >= 1, a 22-byte candidate struct is read
at buf + 20 without verifying the response contains it. This causes an
out-of-bounds read of stale heap data, corrupting the BA session state.

Add validation that the response includes the candidate data.

Fixes: 16be1ac55944 ("wcn36xx: Parse trigger_ba response properly")
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Link: https://patch.msgid.link/20260421135018.352774-4-tristmd@gmail.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/wcn36xx/smd.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/net/wireless/ath/wcn36xx/smd.c b/drivers/net/wireless/ath/wcn36xx/smd.c
index 2a0c946d810950..c0b477345832b8 100644
--- a/drivers/net/wireless/ath/wcn36xx/smd.c
+++ b/drivers/net/wireless/ath/wcn36xx/smd.c
@@ -2599,6 +2599,9 @@ static int wcn36xx_smd_trigger_ba_rsp(void *buf, int len, struct add_ba_info *ba
 	if (rsp->candidate_cnt < 1)
 		return rsp->status ? rsp->status : -EINVAL;
 
+	if (len < sizeof(*rsp) + sizeof(*candidate))
+		return -EINVAL;
+
 	candidate = (struct wcn36xx_hal_trigger_ba_rsp_candidate *)(buf + sizeof(*rsp));
 
 	for (i = 0; i < STACFG_MAX_TC; i++) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0523/2077] ALSA: seq: Fix partial userptr event expansion
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (521 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0522/2077] wifi: wcn36xx: fix OOB read from short trigger BA firmware response Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0524/2077] ALSA: pcm: Fix unlocked runtime state reads in xfer ioctls Greg Kroah-Hartman
                   ` (474 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Takashi Iwai,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: HyeongJun An <sammiee5311@gmail.com>

[ Upstream commit 2b7bd6f548292aec92a386deebe62324d21d62a9 ]

snd_seq_expand_var_event_at() clamps the number of bytes to copy to the
remaining variable-event length, but passes the original buffer size to
expand_var_event().

For SNDRV_SEQ_EXT_USRPTR events, expand_var_event() copies exactly the
size argument from userspace.  On the final chunk, when the remaining
event data is shorter than the caller's buffer, this can read past the
declared event data and can spuriously fail with -EFAULT if the extra
bytes cross an unmapped page.

Pass the clamped length instead.  The chained and kernel-backed paths
already reclamp in dump_var_event(), but the user-pointer path handles
the size directly.

Fixes: ea46f79709b6 ("ALSA: seq: Add snd_seq_expand_var_event_at() helper")
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Link: https://patch.msgid.link/20260606040913.230213-1-sammiee5311@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/core/seq/seq_memory.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/core/seq/seq_memory.c b/sound/core/seq/seq_memory.c
index 670f6599e002da..209b08c2a94088 100644
--- a/sound/core/seq/seq_memory.c
+++ b/sound/core/seq/seq_memory.c
@@ -211,7 +211,7 @@ int snd_seq_expand_var_event_at(const struct snd_seq_event *event, int count,
 	len -= offset;
 	if (len > count)
 		len = count;
-	err = expand_var_event(event, offset, count, buf, true);
+	err = expand_var_event(event, offset, len, buf, true);
 	if (err < 0)
 		return err;
 	return len;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0524/2077] ALSA: pcm: Fix unlocked runtime state reads in xfer ioctls
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (522 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0523/2077] ALSA: seq: Fix partial userptr event expansion Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0525/2077] riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool Greg Kroah-Hartman
                   ` (473 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Takashi Iwai,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cássio Gabriel <cassiogabrielcontato@gmail.com>

[ Upstream commit 98fe3988a2efe89a1a1ded213a0561e6543e94e2 ]

The recent runtime state locking cleanup converted several PCM ioctl state
checks to snd_pcm_get_state(), including snd_pcm_pre_prepare(),
snd_pcm_drain() and snd_pcm_kernel_ioctl(). The native and compat xfer
ioctl paths still sample runtime->state directly before dispatching to the
PCM transfer helpers, and snd_pcm_common_ioctl() still samples the
DISCONNECTED state directly in its common precheck.

Use snd_pcm_get_state() for those ioctl-side prechecks as well. This keeps
the externally visible ioctl entry checks consistent with the stream-locked
state access used by the recent PCM state-read cleanup.

Fixes: 032322b44c02 ("ALSA: pcm: oss: use proper stream lock for runtime->state access")
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260605-alsa-pcm-xfer-state-helper-v1-1-eba97cecf820@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/core/pcm_compat.c | 4 ++--
 sound/core/pcm_native.c | 7 +++----
 2 files changed, 5 insertions(+), 6 deletions(-)

diff --git a/sound/core/pcm_compat.c b/sound/core/pcm_compat.c
index 5313f50f17da5e..55ecf87586c4dd 100644
--- a/sound/core/pcm_compat.c
+++ b/sound/core/pcm_compat.c
@@ -293,7 +293,7 @@ static int snd_pcm_ioctl_xferi_compat(struct snd_pcm_substream *substream,
 		return -ENOTTY;
 	if (substream->stream != dir)
 		return -EINVAL;
-	if (substream->runtime->state == SNDRV_PCM_STATE_OPEN)
+	if (snd_pcm_get_state(substream) == SNDRV_PCM_STATE_OPEN)
 		return -EBADFD;
 
 	if (get_user(buf, &data32->buf) ||
@@ -338,7 +338,7 @@ static int snd_pcm_ioctl_xfern_compat(struct snd_pcm_substream *substream,
 		return -ENOTTY;
 	if (substream->stream != dir)
 		return -EINVAL;
-	if (substream->runtime->state == SNDRV_PCM_STATE_OPEN)
+	if (snd_pcm_get_state(substream) == SNDRV_PCM_STATE_OPEN)
 		return -EBADFD;
 
 	ch = substream->runtime->channels;
diff --git a/sound/core/pcm_native.c b/sound/core/pcm_native.c
index 302643c1c1921e..aa334416968557 100644
--- a/sound/core/pcm_native.c
+++ b/sound/core/pcm_native.c
@@ -3303,10 +3303,9 @@ static int snd_pcm_xferi_frames_ioctl(struct snd_pcm_substream *substream,
 				      struct snd_xferi __user *_xferi)
 {
 	struct snd_xferi xferi;
-	struct snd_pcm_runtime *runtime = substream->runtime;
 	snd_pcm_sframes_t result;
 
-	if (runtime->state == SNDRV_PCM_STATE_OPEN)
+	if (snd_pcm_get_state(substream) == SNDRV_PCM_STATE_OPEN)
 		return -EBADFD;
 	if (put_user(0, &_xferi->result))
 		return -EFAULT;
@@ -3329,7 +3328,7 @@ static int snd_pcm_xfern_frames_ioctl(struct snd_pcm_substream *substream,
 	void *bufs __free(kfree) = NULL;
 	snd_pcm_sframes_t result;
 
-	if (runtime->state == SNDRV_PCM_STATE_OPEN)
+	if (snd_pcm_get_state(substream) == SNDRV_PCM_STATE_OPEN)
 		return -EBADFD;
 	if (runtime->channels > 128)
 		return -EINVAL;
@@ -3392,7 +3391,7 @@ static int snd_pcm_common_ioctl(struct file *file,
 	if (PCM_RUNTIME_CHECK(substream))
 		return -ENXIO;
 
-	if (substream->runtime->state == SNDRV_PCM_STATE_DISCONNECTED)
+	if (snd_pcm_get_state(substream) == SNDRV_PCM_STATE_DISCONNECTED)
 		return -EBADFD;
 
 	res = snd_power_wait(substream->pcm->card);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0525/2077] riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (523 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0524/2077] ALSA: pcm: Fix unlocked runtime state reads in xfer ioctls Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0526/2077] riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe Greg Kroah-Hartman
                   ` (472 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Hui Wang, Paul Walmsley, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hui Wang <hui.wang@canonical.com>

[ Upstream commit 2b2b207e1162e577cd6208e184d3d3a0fcfa9cca ]

In the original sbi_cpu_is_stopped(), if rc doesn't equal to the
SBI_HSM_STATE_STOPPED, it will return rc to the caller directly. But
there is a hidden problem, the rc could be SBI_HSM_STATE_STARTED, if
so, this function will report cpu stopped while the cpu isn't really
stopped.

Furthermore, from the name of cpu_is_stopped(), it gives a sense the
return value is a bool type, true means the cpu is stopped, conversely
false means the cpu is not stopped.

Here change the return value type to bool and change the callers
accordingly. This could fix the above two issues.

Fixes: f1e58583b9c7c ("RISC-V: Support cpu hotplug")
Signed-off-by: Hui Wang <hui.wang@canonical.com>
Link: https://patch.msgid.link/20260413123515.48423-1-hui.wang@canonical.com
[pjw@kernel.org: cleaned up some of the pr_warn() messages]
Signed-off-by: Paul Walmsley <pjw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/include/asm/cpu_ops.h |  2 +-
 arch/riscv/kernel/cpu-hotplug.c  |  4 ++--
 arch/riscv/kernel/cpu_ops_sbi.c  | 11 +++++++----
 3 files changed, 10 insertions(+), 7 deletions(-)

diff --git a/arch/riscv/include/asm/cpu_ops.h b/arch/riscv/include/asm/cpu_ops.h
index 176b570ef98276..065811fca594d9 100644
--- a/arch/riscv/include/asm/cpu_ops.h
+++ b/arch/riscv/include/asm/cpu_ops.h
@@ -24,7 +24,7 @@ struct cpu_operations {
 				     struct task_struct *tidle);
 #ifdef CONFIG_HOTPLUG_CPU
 	void		(*cpu_stop)(void);
-	int		(*cpu_is_stopped)(unsigned int cpu);
+	bool		(*cpu_is_stopped)(unsigned int cpu);
 #endif
 };
 
diff --git a/arch/riscv/kernel/cpu-hotplug.c b/arch/riscv/kernel/cpu-hotplug.c
index a0ee426f6d938a..0bc56d8381b6bf 100644
--- a/arch/riscv/kernel/cpu-hotplug.c
+++ b/arch/riscv/kernel/cpu-hotplug.c
@@ -57,8 +57,8 @@ void arch_cpuhp_cleanup_dead_cpu(unsigned int cpu)
 	/* Verify from the firmware if the cpu is really stopped*/
 	if (cpu_ops->cpu_is_stopped)
 		ret = cpu_ops->cpu_is_stopped(cpu);
-	if (ret)
-		pr_warn("CPU%u may not have stopped: %d\n", cpu, ret);
+	if (!ret)
+		pr_warn("CPU%u may not have stopped\n", cpu);
 }
 
 /*
diff --git a/arch/riscv/kernel/cpu_ops_sbi.c b/arch/riscv/kernel/cpu_ops_sbi.c
index 00aff669f5f2f5..146ceab1011fee 100644
--- a/arch/riscv/kernel/cpu_ops_sbi.c
+++ b/arch/riscv/kernel/cpu_ops_sbi.c
@@ -88,16 +88,19 @@ static void sbi_cpu_stop(void)
 	pr_crit("Unable to stop the cpu %d (%d)\n", smp_processor_id(), ret);
 }
 
-static int sbi_cpu_is_stopped(unsigned int cpuid)
+static bool sbi_cpu_is_stopped(unsigned int cpuid)
 {
 	int rc;
 	unsigned long hartid = cpuid_to_hartid_map(cpuid);
 
 	rc = sbi_hsm_hart_get_status(hartid);
 
-	if (rc == SBI_HSM_STATE_STOPPED)
-		return 0;
-	return rc;
+	if (rc != SBI_HSM_STATE_STOPPED) {
+		pr_warn("HART%lu isn't stopped; status %d\n", hartid, rc);
+		return false;
+	}
+
+	return true;
 }
 #endif
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0526/2077] riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (524 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0525/2077] riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0527/2077] ALSA: seq: Clear variable event pointer on read Greg Kroah-Hartman
                   ` (471 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Rui Qi, Paul Walmsley, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rui Qi <qirui.001@bytedance.com>

[ Upstream commit 8ac35bac70e7e581d673b76878f7691cdadc33b8 ]

In the non-frame-pointer version of walk_stackframe, each value read
from the stack is treated as a potential return address and has 0x4
subtracted before being used as the program counter. This was intended
to convert the return address (the instruction after a call) back to
the call site, but it is incorrect:

1. RISC-V has variable-length instructions due to the RVC (compressed
   instruction) extension. A call instruction can be either 4 bytes
   (regular) or 2 bytes (compressed, e.g. c.jal). Subtracting a fixed
   0x4 assumes all call instructions are 4 bytes, which is wrong for
   compressed instructions.

2. Stack traces conventionally report return addresses, not call sites.
   Other architectures (ARM64, x86, ARM) do not subtract instruction
   size from return addresses in their stack unwinding code.

3. The frame-pointer version of walk_stackframe already dropped the
   -0x4 offset. Commit b785ec129bd9 ("riscv/ftrace: Add
   HAVE_FUNCTION_GRAPH_RET_ADDR_PTR support") replaced "pc =
   frame->ra - 0x4" with ftrace_graph_ret_addr(), and the commit
   message explicitly noted that "the original calculation, pc =
   frame->ra - 4, is buggy when the instruction at the return address
   happened to be a compressed inst." The non-FP version was simply
   overlooked.

Remove the bogus -0x4 offset to match the FP version and the
conventions used by other architectures.

Fixes: 5d8544e2d007 ("RISC-V: Generic library routines and assembly")
Signed-off-by: Rui Qi <qirui.001@bytedance.com>
Link: https://patch.msgid.link/20260603115329.791603-2-qirui.001@bytedance.com
Signed-off-by: Paul Walmsley <pjw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/kernel/stacktrace.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/riscv/kernel/stacktrace.c b/arch/riscv/kernel/stacktrace.c
index b41b6255751cb1..31fd3abb57d329 100644
--- a/arch/riscv/kernel/stacktrace.c
+++ b/arch/riscv/kernel/stacktrace.c
@@ -129,7 +129,7 @@ void notrace walk_stackframe(struct task_struct *task,
 	while (!kstack_end(ksp)) {
 		if (__kernel_text_address(pc) && unlikely(!fn(arg, pc)))
 			break;
-		pc = READ_ONCE_NOCHECK(*ksp++) - 0x4;
+		pc = READ_ONCE_NOCHECK(*ksp++);
 	}
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0527/2077] ALSA: seq: Clear variable event pointer on read
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (525 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0526/2077] riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0528/2077] riscv: alternative: Use IS_ENABLED() over ifdeffery for apply_vdso_alternatives() Greg Kroah-Hartman
                   ` (470 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Kyle Zeng, Takashi Iwai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kyle Zeng <kylebot@openai.com>

[ Upstream commit 705dd6dcbc0ea87351c660c1a6443f85f1001c76 ]

snd_seq_read() copies a queued variable-length event header to userspace
before expanding the payload. Queued variable-length events use
SNDRV_SEQ_EXT_CHAINED internally, and data.ext.ptr points at the first
extension cell.

The read side strips SNDRV_SEQ_EXT_* bits from data.ext.len before the
copy, but it leaves data.ext.ptr untouched. A userspace sequencer client
can therefore write a direct variable event to itself and read back the
extension-cell kernel address from the returned header.

Clear the temporary header pointer before copy_to_user(). The original
queued event remains unchanged and is still passed to
snd_seq_expand_var_event(), so payload expansion keeps using the
internal chain.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Kyle Zeng <kylebot@openai.com>
Link: https://patch.msgid.link/20260607004129.61345-1-kylebot@openai.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/core/seq/seq_clientmgr.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/core/seq/seq_clientmgr.c b/sound/core/seq/seq_clientmgr.c
index 5719637575a911..ce0dd53399bfac 100644
--- a/sound/core/seq/seq_clientmgr.c
+++ b/sound/core/seq/seq_clientmgr.c
@@ -441,6 +441,7 @@ static ssize_t snd_seq_read(struct file *file, char __user *buf, size_t count,
 
 			memcpy(&tmpev, &cell->event, aligned_size);
 			tmpev.data.ext.len &= ~SNDRV_SEQ_EXT_MASK;
+			tmpev.data.ext.ptr = NULL;
 			if (copy_to_user(buf, &tmpev, aligned_size)) {
 				err = -EFAULT;
 				break;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0528/2077] riscv: alternative: Use IS_ENABLED() over ifdeffery for apply_vdso_alternatives()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (526 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0527/2077] ALSA: seq: Clear variable event pointer on read Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0529/2077] riscv: alternative: Pass vDSO start as parameter to apply_vdso_alternatives() Greg Kroah-Hartman
                   ` (469 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Weißschuh, Paul Walmsley,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Weißschuh <thomas.weissschuh@linutronix.de>

[ Upstream commit 4fd6505f189d447abbed1f1f6fe6b82649f27a46 ]

IS_ENABLED() allows better compilation coverage while still optimizing
away all the dead code. Also it will make some upcoming changes easier.

Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Link: https://patch.msgid.link/20260504-riscv-cfi-vdso-alternative-v1-2-bcdf3d37f62e@linutronix.de
Signed-off-by: Paul Walmsley <pjw@kernel.org>
Stable-dep-of: d3e0634787a2 ("riscv: alternative: Also patch the CFI vDSO")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/kernel/alternative.c | 7 ++-----
 1 file changed, 2 insertions(+), 5 deletions(-)

diff --git a/arch/riscv/kernel/alternative.c b/arch/riscv/kernel/alternative.c
index 7642704c7f1841..59991922a5dca5 100644
--- a/arch/riscv/kernel/alternative.c
+++ b/arch/riscv/kernel/alternative.c
@@ -173,7 +173,6 @@ static void __init_or_module _apply_alternatives(struct alt_entry *begin,
 				stage);
 }
 
-#ifdef CONFIG_MMU
 static void __init apply_vdso_alternatives(void)
 {
 	const Elf_Ehdr *hdr;
@@ -194,9 +193,6 @@ static void __init apply_vdso_alternatives(void)
 			    (struct alt_entry *)end,
 			    RISCV_ALTERNATIVES_BOOT);
 }
-#else
-static void __init apply_vdso_alternatives(void) { }
-#endif
 
 void __init apply_boot_alternatives(void)
 {
@@ -207,7 +203,8 @@ void __init apply_boot_alternatives(void)
 			    (struct alt_entry *)__alt_end,
 			    RISCV_ALTERNATIVES_BOOT);
 
-	apply_vdso_alternatives();
+	if (IS_ENABLED(CONFIG_MMU))
+		apply_vdso_alternatives();
 }
 
 /*
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0529/2077] riscv: alternative: Pass vDSO start as parameter to apply_vdso_alternatives()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (527 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0528/2077] riscv: alternative: Use IS_ENABLED() over ifdeffery for apply_vdso_alternatives() Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0530/2077] riscv: alternative: Also patch the CFI vDSO Greg Kroah-Hartman
                   ` (468 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Weißschuh, Paul Walmsley,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Weißschuh <thomas.weissschuh@linutronix.de>

[ Upstream commit 6386161abb02880ace2cc965e73f7857b351706c ]

The dedicated vDSO with CFI should also be patched in the same way.
To prepare for that move the currently hardcoded vDSO start symbol
into a parameter.

Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Link: https://patch.msgid.link/20260504-riscv-cfi-vdso-alternative-v1-3-bcdf3d37f62e@linutronix.de
Signed-off-by: Paul Walmsley <pjw@kernel.org>
Stable-dep-of: d3e0634787a2 ("riscv: alternative: Also patch the CFI vDSO")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/kernel/alternative.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/arch/riscv/kernel/alternative.c b/arch/riscv/kernel/alternative.c
index 59991922a5dca5..89c283a5cec7ff 100644
--- a/arch/riscv/kernel/alternative.c
+++ b/arch/riscv/kernel/alternative.c
@@ -173,14 +173,14 @@ static void __init_or_module _apply_alternatives(struct alt_entry *begin,
 				stage);
 }
 
-static void __init apply_vdso_alternatives(void)
+static void __init apply_vdso_alternatives(void *start)
 {
 	const Elf_Ehdr *hdr;
 	const Elf_Shdr *shdr;
 	const Elf_Shdr *alt;
 	struct alt_entry *begin, *end;
 
-	hdr = (Elf_Ehdr *)vdso_start;
+	hdr = (Elf_Ehdr *)start;
 	shdr = (void *)hdr + hdr->e_shoff;
 	alt = find_section(hdr, shdr, ".alternative");
 	if (!alt)
@@ -204,7 +204,7 @@ void __init apply_boot_alternatives(void)
 			    RISCV_ALTERNATIVES_BOOT);
 
 	if (IS_ENABLED(CONFIG_MMU))
-		apply_vdso_alternatives();
+		apply_vdso_alternatives(vdso_start);
 }
 
 /*
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0530/2077] riscv: alternative: Also patch the CFI vDSO
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (528 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0529/2077] riscv: alternative: Pass vDSO start as parameter to apply_vdso_alternatives() Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0531/2077] bpf: Verifier support for sleepable tracepoint programs Greg Kroah-Hartman
                   ` (467 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Weißschuh, Paul Walmsley,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Weißschuh <thomas.weissschuh@linutronix.de>

[ Upstream commit d3e0634787a234b40a740b9c398fd320a68db81c ]

The dedicated vDSO for CFI-enabled userspace can also contain
alternative entries.

Patch those, too.

Fixes: ccad8c1336b6 ("arch/riscv: add dual vdso creation logic and select vdso based on hw")
Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Link: https://patch.msgid.link/20260504-riscv-cfi-vdso-alternative-v1-4-bcdf3d37f62e@linutronix.de
Signed-off-by: Paul Walmsley <pjw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/riscv/kernel/alternative.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/arch/riscv/kernel/alternative.c b/arch/riscv/kernel/alternative.c
index 89c283a5cec7ff..104dc0862c5c2e 100644
--- a/arch/riscv/kernel/alternative.c
+++ b/arch/riscv/kernel/alternative.c
@@ -205,6 +205,9 @@ void __init apply_boot_alternatives(void)
 
 	if (IS_ENABLED(CONFIG_MMU))
 		apply_vdso_alternatives(vdso_start);
+
+	if (IS_ENABLED(CONFIG_RISCV_USER_CFI))
+		apply_vdso_alternatives(vdso_cfi_start);
 }
 
 /*
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0531/2077] bpf: Verifier support for sleepable tracepoint programs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (529 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0530/2077] riscv: alternative: Also patch the CFI vDSO Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0532/2077] bpf: Reject sleepable BPF_LSM_CGROUP programs at load time Greg Kroah-Hartman
                   ` (466 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mykyta Yatsenko,
	Kumar Kartikeya Dwivedi, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mykyta Yatsenko <yatsenko@meta.com>

[ Upstream commit 8cfb77d3092052b52582e804e644202e2b10167a ]

Allow BPF_PROG_TYPE_RAW_TRACEPOINT, BPF_PROG_TYPE_TRACEPOINT, and
BPF_TRACE_RAW_TP (tp_btf) programs to be sleepable by adding them
to can_be_sleepable().

For BTF-based raw tracepoints (tp_btf), add a load-time check in
bpf_check_attach_target() that rejects sleepable programs attaching
to non-faultable tracepoints with a descriptive error message.

For raw tracepoints (raw_tp), add an attach-time check in
bpf_raw_tp_link_attach() that rejects sleepable programs on
non-faultable tracepoints. The attach-time check is needed because
the tracepoint name is not known at load time for raw_tp.

The attach-time check for classic tracepoints (tp) in
__perf_event_set_bpf_prog() was added in the previous patch.

Replace the verbose error message that enumerates allowed program
types with a generic "Program of this type cannot be sleepable"
message, since the list of sleepable-capable types keeps growing.

Signed-off-by: Mykyta Yatsenko <yatsenko@meta.com>
Acked-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Link: https://lore.kernel.org/bpf/20260422-sleepable_tracepoints-v13-4-99005dff21ef@meta.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Stable-dep-of: 5b038319be44 ("bpf: Reject sleepable BPF_LSM_CGROUP programs at load time")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/bpf/syscall.c  |  5 +++++
 kernel/bpf/verifier.c | 13 +++++++++++--
 2 files changed, 16 insertions(+), 2 deletions(-)

diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
index bd1250a6c1e1fd..d3667970885580 100644
--- a/kernel/bpf/syscall.c
+++ b/kernel/bpf/syscall.c
@@ -4288,6 +4288,11 @@ static int bpf_raw_tp_link_attach(struct bpf_prog *prog,
 	if (!btp)
 		return -ENOENT;
 
+	if (prog->sleepable && !tracepoint_is_faultable(btp->tp)) {
+		bpf_put_raw_tracepoint(btp);
+		return -EINVAL;
+	}
+
 	link = kzalloc_obj(*link, GFP_USER);
 	if (!link) {
 		err = -ENOMEM;
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index ff9b1f68ceca44..16da9f76804aad 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -19317,6 +19317,12 @@ int bpf_check_attach_target(struct bpf_verifier_log *log,
 		btp = bpf_get_raw_tracepoint(tname);
 		if (!btp)
 			return -EINVAL;
+		if (prog->sleepable && !tracepoint_is_faultable(btp->tp)) {
+			bpf_log(log, "Sleepable program cannot attach to non-faultable tracepoint %s\n",
+				tname);
+			bpf_put_raw_tracepoint(btp);
+			return -EINVAL;
+		}
 		fname = kallsyms_lookup((unsigned long)btp->bpf_func, NULL, NULL, NULL,
 					trace_symbol);
 		bpf_put_raw_tracepoint(btp);
@@ -19533,6 +19539,7 @@ static bool can_be_sleepable(struct bpf_prog *prog)
 		case BPF_MODIFY_RETURN:
 		case BPF_TRACE_ITER:
 		case BPF_TRACE_FSESSION:
+		case BPF_TRACE_RAW_TP:
 			return true;
 		default:
 			return false;
@@ -19540,7 +19547,9 @@ static bool can_be_sleepable(struct bpf_prog *prog)
 	}
 	return prog->type == BPF_PROG_TYPE_LSM ||
 	       prog->type == BPF_PROG_TYPE_KPROBE /* only for uprobes */ ||
-	       prog->type == BPF_PROG_TYPE_STRUCT_OPS;
+	       prog->type == BPF_PROG_TYPE_STRUCT_OPS ||
+	       prog->type == BPF_PROG_TYPE_RAW_TRACEPOINT ||
+	       prog->type == BPF_PROG_TYPE_TRACEPOINT;
 }
 
 static int check_attach_btf_id(struct bpf_verifier_env *env)
@@ -19562,7 +19571,7 @@ static int check_attach_btf_id(struct bpf_verifier_env *env)
 	}
 
 	if (prog->sleepable && !can_be_sleepable(prog)) {
-		verbose(env, "Only fentry/fexit/fsession/fmod_ret, lsm, iter, uprobe, and struct_ops programs can be sleepable\n");
+		verbose(env, "Program of this type cannot be sleepable\n");
 		return -EINVAL;
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0532/2077] bpf: Reject sleepable BPF_LSM_CGROUP programs at load time
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (530 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0531/2077] bpf: Verifier support for sleepable tracepoint programs Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0533/2077] netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag Greg Kroah-Hartman
                   ` (465 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Windsor, Yonghong Song,
	Song Liu, Kumar Kartikeya Dwivedi, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Windsor <dwindsor@gmail.com>

[ Upstream commit 5b038319be442c620f774e6fc9e9283deeca1c75 ]

The cgroup shim runs under rcu_read_lock_dont_migrate(), so we should
not attach any sleepable BPF programs there. Add support to the verifier
to explicitly reject attempts to load sleepable BPF programs destined
for LSM cgroup attachment.

Without this, we get the following splat from a BPF_LSM_CGROUP
program marked BPF_F_SLEEPABLE attached to file_open when it calls
bpf_get_dentry_xattr():

  BUG: sleeping function called from invalid context at kernel/locking/rwsem.c:1567
  in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 34317, name: load
  preempt_count: 0, expected: 0
  RCU nest depth: 2, expected: 0
  Call Trace:
   down_read+0x76/0x480
   ext4_xattr_get+0x11f/0x700
   __vfs_getxattr+0xf0/0x150
   bpf_get_dentry_xattr+0xbb/0xf0
   bpf_prog_e76a298dac9218c6_test_open+0x6a/0x85
   __cgroup_bpf_run_lsm_current+0x326/0x840
   bpf_trampoline_6442534646+0x62/0x14d
   security_file_open+0x34/0x60
   do_dentry_open+0x340/0x1260
   vfs_open+0x7a/0x440
   path_openat+0x1bac/0x30a0

libbpf provides a .s named section variant for every sleepable
program type except lsm_cgroup, reflecting that per-cgroup LSM programs
are intended to only run in a non-sleepable context.

The above splat was obtained by bypassing libbpf by using bpf(2)
directly.

Fixes: 69fd337a975c ("bpf: per-cgroup lsm flavor")
Signed-off-by: David Windsor <dwindsor@gmail.com>
Acked-by: Yonghong Song <yonghong.song@linux.dev>
Acked-by: Song Liu <song@kernel.org>
Link: https://lore.kernel.org/bpf/20260605145707.608579-1-dwindsor@gmail.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/bpf/verifier.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 16da9f76804aad..c34bf4169d5c9c 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -19545,8 +19545,10 @@ static bool can_be_sleepable(struct bpf_prog *prog)
 			return false;
 		}
 	}
-	return prog->type == BPF_PROG_TYPE_LSM ||
-	       prog->type == BPF_PROG_TYPE_KPROBE /* only for uprobes */ ||
+	if (prog->type == BPF_PROG_TYPE_LSM)
+		return prog->expected_attach_type != BPF_LSM_CGROUP;
+
+	return prog->type == BPF_PROG_TYPE_KPROBE /* only for uprobes */ ||
 	       prog->type == BPF_PROG_TYPE_STRUCT_OPS ||
 	       prog->type == BPF_PROG_TYPE_RAW_TRACEPOINT ||
 	       prog->type == BPF_PROG_TYPE_TRACEPOINT;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0533/2077] netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (531 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0532/2077] bpf: Reject sleepable BPF_LSM_CGROUP programs at load time Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0534/2077] filelock: fix break_lease() stub signature for CONFIG_FILE_LOCKING=n Greg Kroah-Hartman
                   ` (464 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Carlier,
	Fernando Fernandez Mancera, Pablo Neira Ayuso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Carlier <devnexen@gmail.com>

[ Upstream commit e052f920773b73be49eb4d8702a9f85de7464363 ]

The DEV_PATH_BR_VLAN_UNTAG case post-decrements info->num_encaps
inside WARN_ON_ONCE(). num_encaps is u8, so if it's already 0 the
decrement still happens and wraps it to 255. The break only leaves
the inner switch -- a later path entry can set info->indev back to
a real device, and we end up returning with num_encaps == 255.

nft_dev_forward_path() then walks info.encap[] (size 2) up to
num_encaps, which means an OOB stack read and a bogus count copied
into the route descriptor.

Should only happen on a malformed bridge path stack, hence the WARN,
but worth handling sanely. Move the decrement out of the WARN.

[ While at this, remove the WARN_ON_ONCE since this can only happen
  with a buggy bridge path stack --pablo ].

Fixes: e990cef6516d ("netfilter: flowtable: add bridge vlan filtering support")
Signed-off-by: David Carlier <devnexen@gmail.com>
Reviewed-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/netfilter/nf_flow_table_path.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/net/netfilter/nf_flow_table_path.c b/net/netfilter/nf_flow_table_path.c
index 9e88ea6a2eef78..a3e6b82f2f8e95 100644
--- a/net/netfilter/nf_flow_table_path.c
+++ b/net/netfilter/nf_flow_table_path.c
@@ -163,10 +163,11 @@ static void nft_dev_path_info(const struct net_device_path_stack *stack,
 				info->num_encaps++;
 				break;
 			case DEV_PATH_BR_VLAN_UNTAG:
-				if (WARN_ON_ONCE(info->num_encaps-- == 0)) {
+				if (info->num_encaps == 0) {
 					info->indev = NULL;
 					break;
 				}
+				info->num_encaps--;
 				break;
 			case DEV_PATH_BR_VLAN_KEEP:
 				break;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0534/2077] filelock: fix break_lease() stub signature for CONFIG_FILE_LOCKING=n
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (532 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0533/2077] netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0535/2077] bpf: Fix NMI/tracepoint re-entry deadlock on lru locks Greg Kroah-Hartman
                   ` (463 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, kernel test robot,
	Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Brauner <brauner@kernel.org>

[ Upstream commit 4bbcff264b678859cc404669bd145bcd6819804b ]

The CONFIG_FILE_LOCKING=n stub for break_lease() takes a 'bool wait'
argument, whereas the CONFIG_FILE_LOCKING=y version and every caller pass
an openmode as an 'unsigned int mode'. The mismatch was introduced when
__break_lease() was reworked to use flags: only the stub was switched to
'bool wait', a stray leftover from the neighbouring break_layout()
helper. The real prototype kept 'unsigned int mode'.

This was harmless until O_WRONLY changed from the octal literal 00000001
to (1 << 0). clang's -Wtautological-constant-compare then fires on the
implicit shift-to-bool conversion at the first FILE_LOCKING=n caller:

  fs/open.c:112:29: warning: converting the result of '<<' to a boolean
                    always evaluates to true [-Wtautological-constant-compare]
    112 | error = break_lease(inode, O_WRONLY);

Restore the stub's parameter to 'unsigned int mode' so it matches the
real prototype and every caller. The stub still just returns 0, so there
is no functional change; it removes the type inconsistency and silences
the warning.

Root cause diagnosed by Nathan Chancellor.

Fixes: 4be9f3cc582a ("filelock: rework the __break_lease API to use flags")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202606071029.DKCs8WOs-lkp@intel.com/
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/filelock.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/linux/filelock.h b/include/linux/filelock.h
index 5f0a2fb3145060..77e1cc4afbaa89 100644
--- a/include/linux/filelock.h
+++ b/include/linux/filelock.h
@@ -564,7 +564,7 @@ static inline bool is_delegated(struct delegated_inode *di)
 	return false;
 }
 
-static inline int break_lease(struct inode *inode, bool wait)
+static inline int break_lease(struct inode *inode, unsigned int mode)
 {
 	return 0;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0535/2077] bpf: Fix NMI/tracepoint re-entry deadlock on lru locks
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (533 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0534/2077] filelock: fix break_lease() stub signature for CONFIG_FILE_LOCKING=n Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0536/2077] kunit:tool: Dont write to stdout when it should be disabled Greg Kroah-Hartman
                   ` (462 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+c69a0a2c816716f1e0d5,
	syzbot+18b26edb69b2e19f3b33, Mykyta Yatsenko, Alexei Starovoitov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mykyta Yatsenko <yatsenko@meta.com>

[ Upstream commit 89edbdfc5d0308cef57b71359331de5c4ddbf763 ]

NMI and tracepoint BPF programs can re-enter the per-CPU or global
LRU lock that bpf_lru_pop_free()/push_free() already hold on the
same CPU, AA-deadlocking. Lockdep reports "inconsistent
{INITIAL USE} -> {IN-NMI}" on &l->lock (syzbot c69a0a2c816716f1e0d5)
and "possible recursive locking detected" on &loc_l->lock (syzbot
18b26edb69b2e19f3b33).

Prior trylock and rqspinlock based fixes (see links) were nacked
because compromised on reliability.

This patch converts every LRU lock site to rqspinlock_t and adds a
recovery path for some failure windows to avoid node leaks.

Failure recovery:

 - *_pop_free top-level: return NULL; prealloc_lru_pop() already
   treats that as no-free-element (-ENOMEM).

 - Cross-CPU steal: skip the victim's locked loc_l, try next CPU.

 - Post-steal local lock fail: publish stolen node to lockless
   per-CPU free_llist; next pop on this CPU picks it up.

 - push_free fail: mark node pending_free=1. __local_list_flush(),
   __local_list_pop_pending() reclaim the node from pending_list.
   __bpf_lru_list_shrink_inactive() reclaims the node from inactive
   list. Nodes from active list are reclaimed by __bpf_lru_list_shrink()
   or after __bpf_lru_list_rotate_active() demotes it to the inactive.

Fixes: 3a08c2fd7634 ("bpf: LRU List")
Reported-by: syzbot+c69a0a2c816716f1e0d5@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c69a0a2c816716f1e0d5
Reported-by: syzbot+18b26edb69b2e19f3b33@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=18b26edb69b2e19f3b33
Link: https://lore.kernel.org/bpf/CAPPBnEYO4R+m+SpVc2gNj_x31R6fo1uJvj2bK2YS1P09GWT6kQ@mail.gmail.com/
Link: https://lore.kernel.org/bpf/CAPPBnEZmFA3ab8Uc=PEm0bdojZy=7T_F5_+eyZSHyZR3MBG4Vw@mail.gmail.com/
Link: https://lore.kernel.org/bpf/20251030030010.95352-1-dongml2@chinatelecom.cn/
Link: https://lore.kernel.org/bpf/20260119142120.28170-1-leon.hwang@linux.dev/
Signed-off-by: Mykyta Yatsenko <yatsenko@meta.com>
Link: https://lore.kernel.org/r/20260607-lru_map_spin-v3-1-bcd9332e911b@meta.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/bpf/bpf_lru_list.c | 165 +++++++++++++++++++++++---------------
 kernel/bpf/bpf_lru_list.h |  25 ++++--
 2 files changed, 119 insertions(+), 71 deletions(-)

diff --git a/kernel/bpf/bpf_lru_list.c b/kernel/bpf/bpf_lru_list.c
index e7a2fc60523f6c..5ed7cb4b98c006 100644
--- a/kernel/bpf/bpf_lru_list.c
+++ b/kernel/bpf/bpf_lru_list.c
@@ -13,23 +13,8 @@
 #define PERCPU_FREE_TARGET		(4)
 #define PERCPU_NR_SCANS			PERCPU_FREE_TARGET
 
-/* Helpers to get the local list index */
-#define LOCAL_LIST_IDX(t)	((t) - BPF_LOCAL_LIST_T_OFFSET)
-#define LOCAL_FREE_LIST_IDX	LOCAL_LIST_IDX(BPF_LRU_LOCAL_LIST_T_FREE)
-#define LOCAL_PENDING_LIST_IDX	LOCAL_LIST_IDX(BPF_LRU_LOCAL_LIST_T_PENDING)
 #define IS_LOCAL_LIST_TYPE(t)	((t) >= BPF_LOCAL_LIST_T_OFFSET)
 
-/* Local list helpers */
-static struct list_head *local_free_list(struct bpf_lru_locallist *loc_l)
-{
-	return &loc_l->lists[LOCAL_FREE_LIST_IDX];
-}
-
-static struct list_head *local_pending_list(struct bpf_lru_locallist *loc_l)
-{
-	return &loc_l->lists[LOCAL_PENDING_LIST_IDX];
-}
-
 /* bpf_lru_node helpers */
 static bool bpf_lru_node_is_ref(const struct bpf_lru_node *node)
 {
@@ -72,6 +57,7 @@ static void __bpf_lru_node_move_to_free(struct bpf_lru_list *l,
 	bpf_lru_list_count_dec(l, node->type);
 
 	node->type = tgt_free_type;
+	WRITE_ONCE(node->pending_free, 0);
 	list_move(&node->list, free_list);
 }
 
@@ -87,6 +73,9 @@ static void __bpf_lru_node_move_in(struct bpf_lru_list *l,
 	bpf_lru_list_count_inc(l, tgt_type);
 	node->type = tgt_type;
 	bpf_lru_node_clear_ref(node);
+	/* Reset pending_free only when moving to the free list */
+	if (tgt_type == BPF_LRU_LIST_T_FREE)
+		WRITE_ONCE(node->pending_free, 0);
 	list_move(&node->list, &l->lists[tgt_type]);
 }
 
@@ -212,9 +201,11 @@ __bpf_lru_list_shrink_inactive(struct bpf_lru *lru,
 	unsigned int i = 0;
 
 	list_for_each_entry_safe_reverse(node, tmp_node, inactive, list) {
-		if (bpf_lru_node_is_ref(node)) {
+		if (bpf_lru_node_is_ref(node) &&
+		    !READ_ONCE(node->pending_free)) {
 			__bpf_lru_node_move(l, node, BPF_LRU_LIST_T_ACTIVE);
-		} else if (lru->del_from_htab(lru->del_arg, node)) {
+		} else if (READ_ONCE(node->pending_free) ||
+			   lru->del_from_htab(lru->del_arg, node)) {
 			__bpf_lru_node_move_to_free(l, node, free_list,
 						    tgt_free_type);
 			if (++nshrinked == tgt_nshrink)
@@ -273,7 +264,8 @@ static unsigned int __bpf_lru_list_shrink(struct bpf_lru *lru,
 
 	list_for_each_entry_safe_reverse(node, tmp_node, force_shrink_list,
 					 list) {
-		if (lru->del_from_htab(lru->del_arg, node)) {
+		if (READ_ONCE(node->pending_free) ||
+		    lru->del_from_htab(lru->del_arg, node)) {
 			__bpf_lru_node_move_to_free(l, node, free_list,
 						    tgt_free_type);
 			return 1;
@@ -290,8 +282,10 @@ static void __local_list_flush(struct bpf_lru_list *l,
 	struct bpf_lru_node *node, *tmp_node;
 
 	list_for_each_entry_safe_reverse(node, tmp_node,
-					 local_pending_list(loc_l), list) {
-		if (bpf_lru_node_is_ref(node))
+					 &loc_l->pending_list, list) {
+		if (READ_ONCE(node->pending_free))
+			__bpf_lru_node_move_in(l, node, BPF_LRU_LIST_T_FREE);
+		else if (bpf_lru_node_is_ref(node))
 			__bpf_lru_node_move_in(l, node, BPF_LRU_LIST_T_ACTIVE);
 		else
 			__bpf_lru_node_move_in(l, node,
@@ -307,9 +301,12 @@ static void bpf_lru_list_push_free(struct bpf_lru_list *l,
 	if (WARN_ON_ONCE(IS_LOCAL_LIST_TYPE(node->type)))
 		return;
 
-	raw_spin_lock_irqsave(&l->lock, flags);
+	if (raw_res_spin_lock_irqsave(&l->lock, flags)) {
+		WRITE_ONCE(node->pending_free, 1);
+		return;
+	}
 	__bpf_lru_node_move(l, node, BPF_LRU_LIST_T_FREE);
-	raw_spin_unlock_irqrestore(&l->lock, flags);
+	raw_res_spin_unlock_irqrestore(&l->lock, flags);
 }
 
 static void bpf_lru_list_pop_free_to_local(struct bpf_lru *lru,
@@ -318,8 +315,10 @@ static void bpf_lru_list_pop_free_to_local(struct bpf_lru *lru,
 	struct bpf_lru_list *l = &lru->common_lru.lru_list;
 	struct bpf_lru_node *node, *tmp_node;
 	unsigned int nfree = 0;
+	LIST_HEAD(tmp_free);
 
-	raw_spin_lock(&l->lock);
+	if (raw_res_spin_lock(&l->lock))
+		return;
 
 	__local_list_flush(l, loc_l);
 
@@ -327,7 +326,7 @@ static void bpf_lru_list_pop_free_to_local(struct bpf_lru *lru,
 
 	list_for_each_entry_safe(node, tmp_node, &l->lists[BPF_LRU_LIST_T_FREE],
 				 list) {
-		__bpf_lru_node_move_to_free(l, node, local_free_list(loc_l),
+		__bpf_lru_node_move_to_free(l, node, &tmp_free,
 					    BPF_LRU_LOCAL_LIST_T_FREE);
 		if (++nfree == lru->target_free)
 			break;
@@ -335,10 +334,19 @@ static void bpf_lru_list_pop_free_to_local(struct bpf_lru *lru,
 
 	if (nfree < lru->target_free)
 		__bpf_lru_list_shrink(lru, l, lru->target_free - nfree,
-				      local_free_list(loc_l),
+				      &tmp_free,
 				      BPF_LRU_LOCAL_LIST_T_FREE);
 
-	raw_spin_unlock(&l->lock);
+	raw_res_spin_unlock(&l->lock);
+
+	/*
+	 * Transfer the harvested nodes from the temporary list_head into
+	 * the lockless per-CPU free llist.
+	 */
+	list_for_each_entry_safe(node, tmp_node, &tmp_free, list) {
+		list_del(&node->list);
+		llist_add(&node->llist, &loc_l->free_llist);
+	}
 }
 
 static void __local_list_add_pending(struct bpf_lru *lru,
@@ -350,22 +358,21 @@ static void __local_list_add_pending(struct bpf_lru *lru,
 	*(u32 *)((void *)node + lru->hash_offset) = hash;
 	node->cpu = cpu;
 	node->type = BPF_LRU_LOCAL_LIST_T_PENDING;
+	WRITE_ONCE(node->pending_free, 0);
 	bpf_lru_node_clear_ref(node);
-	list_add(&node->list, local_pending_list(loc_l));
+	list_add(&node->list, &loc_l->pending_list);
 }
 
 static struct bpf_lru_node *
 __local_list_pop_free(struct bpf_lru_locallist *loc_l)
 {
-	struct bpf_lru_node *node;
+	struct llist_node *llnode;
 
-	node = list_first_entry_or_null(local_free_list(loc_l),
-					struct bpf_lru_node,
-					list);
-	if (node)
-		list_del(&node->list);
+	llnode = llist_del_first(&loc_l->free_llist);
+	if (!llnode)
+		return NULL;
 
-	return node;
+	return container_of(llnode, struct bpf_lru_node, llist);
 }
 
 static struct bpf_lru_node *
@@ -376,10 +383,10 @@ __local_list_pop_pending(struct bpf_lru *lru, struct bpf_lru_locallist *loc_l)
 
 ignore_ref:
 	/* Get from the tail (i.e. older element) of the pending list. */
-	list_for_each_entry_reverse(node, local_pending_list(loc_l),
-				    list) {
+	list_for_each_entry_reverse(node, &loc_l->pending_list, list) {
 		if ((!bpf_lru_node_is_ref(node) || force) &&
-		    lru->del_from_htab(lru->del_arg, node)) {
+		    (READ_ONCE(node->pending_free) ||
+		     lru->del_from_htab(lru->del_arg, node))) {
 			list_del(&node->list);
 			return node;
 		}
@@ -404,7 +411,8 @@ static struct bpf_lru_node *bpf_percpu_lru_pop_free(struct bpf_lru *lru,
 
 	l = per_cpu_ptr(lru->percpu_lru, cpu);
 
-	raw_spin_lock_irqsave(&l->lock, flags);
+	if (raw_res_spin_lock_irqsave(&l->lock, flags))
+		return NULL;
 
 	__bpf_lru_list_rotate(lru, l);
 
@@ -420,7 +428,7 @@ static struct bpf_lru_node *bpf_percpu_lru_pop_free(struct bpf_lru *lru,
 		__bpf_lru_node_move(l, node, BPF_LRU_LIST_T_INACTIVE);
 	}
 
-	raw_spin_unlock_irqrestore(&l->lock, flags);
+	raw_res_spin_unlock_irqrestore(&l->lock, flags);
 
 	return node;
 }
@@ -437,7 +445,8 @@ static struct bpf_lru_node *bpf_common_lru_pop_free(struct bpf_lru *lru,
 
 	loc_l = per_cpu_ptr(clru->local_list, cpu);
 
-	raw_spin_lock_irqsave(&loc_l->lock, flags);
+	if (raw_res_spin_lock_irqsave(&loc_l->lock, flags))
+		return NULL;
 
 	node = __local_list_pop_free(loc_l);
 	if (!node) {
@@ -448,17 +457,22 @@ static struct bpf_lru_node *bpf_common_lru_pop_free(struct bpf_lru *lru,
 	if (node)
 		__local_list_add_pending(lru, loc_l, cpu, node, hash);
 
-	raw_spin_unlock_irqrestore(&loc_l->lock, flags);
+	raw_res_spin_unlock_irqrestore(&loc_l->lock, flags);
 
 	if (node)
 		return node;
 
-	/* No free nodes found from the local free list and
+	/*
+	 * No free nodes found from the local free list and
 	 * the global LRU list.
 	 *
 	 * Steal from the local free/pending list of the
 	 * current CPU and remote CPU in RR.  It starts
 	 * with the loc_l->next_steal CPU.
+	 *
+	 * Acquire the victim's lock before touching either list. On
+	 * acquisition failure (rqspinlock AA or timeout) skip the victim
+	 * and try the next CPU.
 	 */
 
 	first_steal = loc_l->next_steal;
@@ -466,24 +480,36 @@ static struct bpf_lru_node *bpf_common_lru_pop_free(struct bpf_lru *lru,
 	do {
 		steal_loc_l = per_cpu_ptr(clru->local_list, steal);
 
-		raw_spin_lock_irqsave(&steal_loc_l->lock, flags);
-
-		node = __local_list_pop_free(steal_loc_l);
-		if (!node)
-			node = __local_list_pop_pending(lru, steal_loc_l);
-
-		raw_spin_unlock_irqrestore(&steal_loc_l->lock, flags);
+		if (!raw_res_spin_lock_irqsave(&steal_loc_l->lock, flags)) {
+			node = __local_list_pop_free(steal_loc_l);
+			if (!node)
+				node = __local_list_pop_pending(lru, steal_loc_l);
+			raw_res_spin_unlock_irqrestore(&steal_loc_l->lock, flags);
+		}
 
 		steal = cpumask_next_wrap(steal, cpu_possible_mask);
 	} while (!node && steal != first_steal);
 
 	loc_l->next_steal = steal;
 
-	if (node) {
-		raw_spin_lock_irqsave(&loc_l->lock, flags);
-		__local_list_add_pending(lru, loc_l, cpu, node, hash);
-		raw_spin_unlock_irqrestore(&loc_l->lock, flags);
+	if (!node)
+		return NULL;
+
+	if (raw_res_spin_lock_irqsave(&loc_l->lock, flags)) {
+		/*
+		 * The local pending lock can't be acquired (rqspinlock AA
+		 * or timeout). Return the stolen node to the per-CPU
+		 * free_llist instead of orphaning it; the next pop_free on
+		 * this CPU will pick it up.
+		 */
+		node->type = BPF_LRU_LOCAL_LIST_T_FREE;
+		bpf_lru_node_clear_ref(node);
+		WRITE_ONCE(node->pending_free, 0);
+		llist_add(&node->llist, &loc_l->free_llist);
+		return NULL;
 	}
+	__local_list_add_pending(lru, loc_l, cpu, node, hash);
+	raw_res_spin_unlock_irqrestore(&loc_l->lock, flags);
 
 	return node;
 }
@@ -511,18 +537,24 @@ static void bpf_common_lru_push_free(struct bpf_lru *lru,
 
 		loc_l = per_cpu_ptr(lru->common_lru.local_list, node->cpu);
 
-		raw_spin_lock_irqsave(&loc_l->lock, flags);
+		if (raw_res_spin_lock_irqsave(&loc_l->lock, flags)) {
+			WRITE_ONCE(node->pending_free, 1);
+			return;
+		}
 
 		if (unlikely(node->type != BPF_LRU_LOCAL_LIST_T_PENDING)) {
-			raw_spin_unlock_irqrestore(&loc_l->lock, flags);
+			raw_res_spin_unlock_irqrestore(&loc_l->lock,
+						       flags);
 			goto check_lru_list;
 		}
 
 		node->type = BPF_LRU_LOCAL_LIST_T_FREE;
 		bpf_lru_node_clear_ref(node);
-		list_move(&node->list, local_free_list(loc_l));
+		list_del(&node->list);
+
+		raw_res_spin_unlock_irqrestore(&loc_l->lock, flags);
 
-		raw_spin_unlock_irqrestore(&loc_l->lock, flags);
+		llist_add(&node->llist, &loc_l->free_llist);
 		return;
 	}
 
@@ -538,11 +570,14 @@ static void bpf_percpu_lru_push_free(struct bpf_lru *lru,
 
 	l = per_cpu_ptr(lru->percpu_lru, node->cpu);
 
-	raw_spin_lock_irqsave(&l->lock, flags);
+	if (raw_res_spin_lock_irqsave(&l->lock, flags)) {
+		WRITE_ONCE(node->pending_free, 1);
+		return;
+	}
 
 	__bpf_lru_node_move(l, node, BPF_LRU_LIST_T_FREE);
 
-	raw_spin_unlock_irqrestore(&l->lock, flags);
+	raw_res_spin_unlock_irqrestore(&l->lock, flags);
 }
 
 void bpf_lru_push_free(struct bpf_lru *lru, struct bpf_lru_node *node)
@@ -565,6 +600,7 @@ static void bpf_common_lru_populate(struct bpf_lru *lru, void *buf,
 
 		node = (struct bpf_lru_node *)(buf + node_offset);
 		node->type = BPF_LRU_LIST_T_FREE;
+		node->pending_free = 0;
 		bpf_lru_node_clear_ref(node);
 		list_add(&node->list, &l->lists[BPF_LRU_LIST_T_FREE]);
 		buf += elem_size;
@@ -594,6 +630,7 @@ static void bpf_percpu_lru_populate(struct bpf_lru *lru, void *buf,
 		node = (struct bpf_lru_node *)(buf + node_offset);
 		node->cpu = cpu;
 		node->type = BPF_LRU_LIST_T_FREE;
+		node->pending_free = 0;
 		bpf_lru_node_clear_ref(node);
 		list_add(&node->list, &l->lists[BPF_LRU_LIST_T_FREE]);
 		i++;
@@ -618,14 +655,12 @@ void bpf_lru_populate(struct bpf_lru *lru, void *buf, u32 node_offset,
 
 static void bpf_lru_locallist_init(struct bpf_lru_locallist *loc_l, int cpu)
 {
-	int i;
-
-	for (i = 0; i < NR_BPF_LRU_LOCAL_LIST_T; i++)
-		INIT_LIST_HEAD(&loc_l->lists[i]);
+	INIT_LIST_HEAD(&loc_l->pending_list);
+	init_llist_head(&loc_l->free_llist);
 
 	loc_l->next_steal = cpu;
 
-	raw_spin_lock_init(&loc_l->lock);
+	raw_res_spin_lock_init(&loc_l->lock);
 }
 
 static void bpf_lru_list_init(struct bpf_lru_list *l)
@@ -640,7 +675,7 @@ static void bpf_lru_list_init(struct bpf_lru_list *l)
 
 	l->next_inactive_rotation = &l->lists[BPF_LRU_LIST_T_INACTIVE];
 
-	raw_spin_lock_init(&l->lock);
+	raw_res_spin_lock_init(&l->lock);
 }
 
 int bpf_lru_init(struct bpf_lru *lru, bool percpu, u32 hash_offset,
diff --git a/kernel/bpf/bpf_lru_list.h b/kernel/bpf/bpf_lru_list.h
index fe2661a58ea94a..8d0ee61622af0c 100644
--- a/kernel/bpf/bpf_lru_list.h
+++ b/kernel/bpf/bpf_lru_list.h
@@ -6,11 +6,11 @@
 
 #include <linux/cache.h>
 #include <linux/list.h>
-#include <linux/spinlock_types.h>
+#include <linux/llist.h>
+#include <asm/rqspinlock.h>
 
 #define NR_BPF_LRU_LIST_T	(3)
 #define NR_BPF_LRU_LIST_COUNT	(2)
-#define NR_BPF_LRU_LOCAL_LIST_T (2)
 #define BPF_LOCAL_LIST_T_OFFSET NR_BPF_LRU_LIST_T
 
 enum bpf_lru_list_type {
@@ -22,10 +22,22 @@ enum bpf_lru_list_type {
 };
 
 struct bpf_lru_node {
-	struct list_head list;
+	/*
+	 * A node is in at most one list at a time. The free path on the
+	 * per-CPU locallist uses an llist, so share storage via a union.
+	 */
+	union {
+		struct list_head list;
+		struct llist_node llist;
+	};
 	u16 cpu;
 	u8 type;
 	u8 ref;
+	/*
+	 * Marks nodes whose *_push_free() lock acquire failed; reclaimed
+	 * by flush/shrink which honor the flag instead of del_from_htab().
+	 */
+	u8 pending_free;
 };
 
 struct bpf_lru_list {
@@ -34,13 +46,14 @@ struct bpf_lru_list {
 	/* The next inactive list rotation starts from here */
 	struct list_head *next_inactive_rotation;
 
-	raw_spinlock_t lock ____cacheline_aligned_in_smp;
+	rqspinlock_t lock ____cacheline_aligned_in_smp;
 };
 
 struct bpf_lru_locallist {
-	struct list_head lists[NR_BPF_LRU_LOCAL_LIST_T];
+	struct list_head pending_list;
+	struct llist_head free_llist;
 	u16 next_steal;
-	raw_spinlock_t lock;
+	rqspinlock_t lock;
 };
 
 struct bpf_common_lru {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0536/2077] kunit:tool: Dont write to stdout when it should be disabled
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (534 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0535/2077] bpf: Fix NMI/tracepoint re-entry deadlock on lru locks Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0537/2077] wifi: mac80211: bound S1G TIM PVB walk to the TIM element Greg Kroah-Hartman
                   ` (461 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, David Gow, Shuah Khan, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Gow <david@davidgow.net>

[ Upstream commit 29afed142d64e181749214072315c976f8510bd7 ]

The kunit_parser module accepts a 'printer' object which is used as a
destination for all output. This is typically set to stdout, so that the
parsed results are visible, but can be set to a special 'null_printer' to
implement options where not all results are always printed.

However, there are a few places where use of stdout is hardcoded, notably
in handling crashed tests and in outputting the colour escape sequences.

Properly use the specified printer for all output. This is okay for the
colour handling (as this is already gated behind isatty() anyway), and also
for the crash handling, as cases where printer != stdout are separately
printed afterwards.

Link: https://lore.kernel.org/r/20260606020317.264178-1-david@davidgow.net
Fixes: 062a9dd9bad7 ("kunit: tool: Only print the summary")
Signed-off-by: David Gow <david@davidgow.net>
Signed-off-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/kunit/kunit_parser.py | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/tools/testing/kunit/kunit_parser.py b/tools/testing/kunit/kunit_parser.py
index 1c61a0ed740d4b..266c9dd953512e 100644
--- a/tools/testing/kunit/kunit_parser.py
+++ b/tools/testing/kunit/kunit_parser.py
@@ -17,7 +17,7 @@ import textwrap
 from enum import Enum, auto
 from typing import Iterable, Iterator, List, Optional, Tuple
 
-from kunit_printer import Printer, stdout
+from kunit_printer import Printer
 
 class Test:
 	"""
@@ -57,7 +57,7 @@ class Test:
 	def add_error(self, printer: Printer, error_message: str) -> None:
 		"""Records an error that occurred while parsing this test."""
 		self.counts.errors += 1
-		printer.print_with_timestamp(stdout.red('[ERROR]') + f' Test: {self.name}: {error_message}')
+		printer.print_with_timestamp(printer.red('[ERROR]') + f' Test: {self.name}: {error_message}')
 
 	def ok_status(self) -> bool:
 		"""Returns true if the status was ok, i.e. passed or skipped."""
@@ -544,7 +544,7 @@ def format_test_result(test: Test, printer: Printer) -> str:
 		return printer.yellow('[NO TESTS RUN] ') + test.name
 	if test.status == TestStatus.TEST_CRASHED:
 		print_log(test.log, printer)
-		return stdout.red('[CRASHED] ') + test.name
+		return printer.red('[CRASHED] ') + test.name
 	print_log(test.log, printer)
 	return printer.red('[FAILED] ') + test.name
 
@@ -651,11 +651,11 @@ def print_summary_line(test: Test, printer: Printer) -> None:
 	printer - Printer object to output results
 	"""
 	if test.status == TestStatus.SUCCESS:
-		color = stdout.green
+		color = printer.green
 	elif test.status in (TestStatus.SKIPPED, TestStatus.NO_TESTS):
-		color = stdout.yellow
+		color = printer.yellow
 	else:
-		color = stdout.red
+		color = printer.red
 	printer.print_with_timestamp(color(f'Testing complete. {test.counts}'))
 
 	# Summarize failures that might have gone off-screen since we had a lot
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0537/2077] wifi: mac80211: bound S1G TIM PVB walk to the TIM element
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (535 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0536/2077] kunit:tool: Dont write to stdout when it should be disabled Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0538/2077] powerpc/8xx: implement get_direction() in cpm1 Greg Kroah-Hartman
                   ` (460 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Johannes Berg,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bryam Vargas <hexlabsecurity@proton.me>

[ Upstream commit b224d18b1e5d1cddfc67f63f41d80023b2ec8889 ]

ieee80211_s1g_check_tim() parses the S1G Partial Virtual Bitmap (PVB) of a
received TIM element. The TIM is handed in as the element payload:
ieee802_11_parse_elems_full() stores elems->tim = elem->data and
elems->tim_len = elem->datalen (net/mac80211/parse.c), so the valid bytes
are [tim, tim + tim_len).

When walking the encoded blocks the function passes the walker an end
sentinel of (const u8 *)tim + tim_len + 2, i.e. two bytes past the end of
the element. ieee80211_s1g_find_target_block() loops while (ptr + 1 <= end)
and dereferences ptr (and the per-mode ieee80211_s1g_len_*() helpers read
*ptr), so it can read up to two bytes beyond the TIM element -- an
out-of-bounds read of adjacent skb/heap data when the TIM is the last
element in the frame. The +2 appears to account for the element id/len
header, but tim already points past that header at the element payload, so
the addend is wrong.

Pass the correct element end, (const u8 *)tim + tim_len.

Fixes: e0c47c6229c2 ("wifi: mac80211: support parsing S1G TIM PVB")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Link: https://patch.msgid.link/20260606074341.49135-1-hexlabsecurity@proton.me
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/ieee80211-s1g.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/linux/ieee80211-s1g.h b/include/linux/ieee80211-s1g.h
index 22dde4cbc1b05a..3f9626ad3d97c7 100644
--- a/include/linux/ieee80211-s1g.h
+++ b/include/linux/ieee80211-s1g.h
@@ -556,7 +556,7 @@ static inline bool ieee80211_s1g_check_tim(const struct ieee80211_tim_ie *tim,
 	 */
 	err = ieee80211_s1g_find_target_block(&enc_blk, &target_aid,
 					      tim->virtual_map,
-					      (const u8 *)tim + tim_len + 2);
+					      (const u8 *)tim + tim_len);
 	if (err)
 		return false;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0538/2077] powerpc/8xx: implement get_direction() in cpm1
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (536 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0537/2077] wifi: mac80211: bound S1G TIM PVB walk to the TIM element Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0539/2077] bpf: Fix NULL pointer dereference in bpf_task_from_vpid() Greg Kroah-Hartman
                   ` (459 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christophe Leroy,
	Bartosz Golaszewski, Linus Walleij, Madhavan Srinivasan,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>

[ Upstream commit 052f67a1ae6ffa6e43c82193bf2e6c0dfd2e6d8f ]

The lack of get_direction() callbacks in this driver causes GPIOLIB to
emit a warning. Implement them for 16- and 32-bit variants.

Reported-by: Christophe Leroy <chleroy@kernel.org>
Closes: https://lore.kernel.org/all/63487206f6e5a93eaf9f41784317fe99d394312f.1780399750.git.chleroy@kernel.org/
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Fixes: e623c4303ed1 ("gpiolib: sanitize the return value of gpio_chip::get_direction()")
Tested-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
[Maddy: Fixed the Fixes tag]
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260603-powerpc-8xx-cpm1-get-dir-v1-1-2ae1c9a5b992@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/powerpc/platforms/8xx/cpm1.c | 26 ++++++++++++++++++++++++++
 1 file changed, 26 insertions(+)

diff --git a/arch/powerpc/platforms/8xx/cpm1.c b/arch/powerpc/platforms/8xx/cpm1.c
index f00734f0590cf7..b31376bf677880 100644
--- a/arch/powerpc/platforms/8xx/cpm1.c
+++ b/arch/powerpc/platforms/8xx/cpm1.c
@@ -472,6 +472,18 @@ static int cpm1_gpio16_dir_in(struct gpio_chip *gc, unsigned int gpio)
 	return 0;
 }
 
+static int cpm1_gpio16_get_direction(struct gpio_chip *gc, unsigned int gpio)
+{
+	struct cpm1_gpio16_chip *cpm1_gc = gpiochip_get_data(gc);
+	struct cpm_ioport16 __iomem *iop = cpm1_gc->regs;
+	u16 pin_mask = 1 << (15 - gpio);
+
+	if (in_be16(&iop->dir) & pin_mask)
+		return GPIO_LINE_DIRECTION_OUT;
+
+	return GPIO_LINE_DIRECTION_IN;
+}
+
 int cpm1_gpiochip_add16(struct device *dev)
 {
 	struct device_node *np = dev->of_node;
@@ -498,6 +510,7 @@ int cpm1_gpiochip_add16(struct device *dev)
 	gc->ngpio = 16;
 	gc->direction_input = cpm1_gpio16_dir_in;
 	gc->direction_output = cpm1_gpio16_dir_out;
+	gc->get_direction = cpm1_gpio16_get_direction;
 	gc->get = cpm1_gpio16_get;
 	gc->set = cpm1_gpio16_set;
 	gc->to_irq = cpm1_gpio16_to_irq;
@@ -604,6 +617,18 @@ static int cpm1_gpio32_dir_in(struct gpio_chip *gc, unsigned int gpio)
 	return 0;
 }
 
+static int cpm1_gpio32_get_direction(struct gpio_chip *gc, unsigned int gpio)
+{
+	struct cpm1_gpio32_chip *cpm1_gc = gpiochip_get_data(gc);
+	struct cpm_ioport32b __iomem *iop = cpm1_gc->regs;
+	u32 pin_mask = 1 << (31 - gpio);
+
+	if (in_be32(&iop->dir) & pin_mask)
+		return GPIO_LINE_DIRECTION_OUT;
+
+	return GPIO_LINE_DIRECTION_IN;
+}
+
 int cpm1_gpiochip_add32(struct device *dev)
 {
 	struct device_node *np = dev->of_node;
@@ -621,6 +646,7 @@ int cpm1_gpiochip_add32(struct device *dev)
 	gc->ngpio = 32;
 	gc->direction_input = cpm1_gpio32_dir_in;
 	gc->direction_output = cpm1_gpio32_dir_out;
+	gc->get_direction = cpm1_gpio32_get_direction;
 	gc->get = cpm1_gpio32_get;
 	gc->set = cpm1_gpio32_set;
 	gc->parent = dev;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0539/2077] bpf: Fix NULL pointer dereference in bpf_task_from_vpid()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (537 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0538/2077] powerpc/8xx: implement get_direction() in cpm1 Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0540/2077] ACPI: IPMI: Fix message kref handling on dead device Greg Kroah-Hartman
                   ` (458 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sechang Lim, Leon Hwang,
	Kumar Kartikeya Dwivedi, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sechang Lim <rhkrqnwk98@gmail.com>

[ Upstream commit 50dff00615522f3ec03449680ca23beb4cfc549c ]

bpf_task_from_vpid() looks up a task in the pid namespace of the
current task, via find_task_by_vpid():

  find_task_by_vpid(vpid)
    find_task_by_pid_ns(vpid, task_active_pid_ns(current))
      find_pid_ns(nr, ns) -> idr_find(&ns->idr, nr)

cgroup_skb programs run in softirq, which may interrupt a task that is
itself in do_exit(). Once that task has passed
exit_notify() -> release_task() -> __unhash_process(), its thread_pid is
cleared, so task_active_pid_ns(current) returns NULL and find_pid_ns()
dereferences &NULL->idr:

  BUG: kernel NULL pointer dereference, address: 0000000000000050
  RIP: 0010:idr_find+0x11/0x30 lib/idr.c:176
  Call Trace:
   <IRQ>
   find_pid_ns kernel/pid.c:370 [inline]
   find_task_by_pid_ns+0x3b/0xe0 kernel/pid.c:485
   bpf_task_from_vpid+0x5b/0x200 kernel/bpf/helpers.c:2916
   bpf_prog_run_array_cg+0x17e/0x530 kernel/bpf/cgroup.c:81
   __cgroup_bpf_run_filter_skb+0x12b/0x250 kernel/bpf/cgroup.c:1612
   sk_filter_trim_cap+0x1dc/0x4c0 net/core/filter.c:148
   tcp_v4_rcv+0x18d1/0x2200 net/ipv4/tcp_ipv4.c:2223
   </IRQ>
   <TASK>
   do_exit+0xa63/0x1270 kernel/exit.c:1010
   get_signal+0x141c/0x1530 kernel/signal.c:3037

Bail out when current has no pid namespace.

Fixes: 675c3596ff32 ("bpf: Add bpf_task_from_vpid() kfunc")
Signed-off-by: Sechang Lim <rhkrqnwk98@gmail.com>
Acked-by: Leon Hwang <leon.hwang@linux.dev>
Link: https://lore.kernel.org/bpf/20260608050001.2545245-1-rhkrqnwk98@gmail.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/bpf/helpers.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/kernel/bpf/helpers.c b/kernel/bpf/helpers.c
index 5c1e5c8812b12b..c2032af98e0836 100644
--- a/kernel/bpf/helpers.c
+++ b/kernel/bpf/helpers.c
@@ -2919,11 +2919,13 @@ __bpf_kfunc struct task_struct *bpf_task_from_vpid(s32 vpid)
 {
 	struct task_struct *p;
 
-	rcu_read_lock();
+	guard(rcu)();
+	if (!task_active_pid_ns(current))
+		return NULL;
+
 	p = find_task_by_vpid(vpid);
 	if (p)
 		p = bpf_task_acquire(p);
-	rcu_read_unlock();
 
 	return p;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0540/2077] ACPI: IPMI: Fix message kref handling on dead device
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (538 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0539/2077] bpf: Fix NULL pointer dereference in bpf_task_from_vpid() Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0541/2077] ACPI: processor: Add cpuidle driver check in acpi_processor_register_idle_driver() Greg Kroah-Hartman
                   ` (457 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuho Choi, Rafael J. Wysocki,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yuho Choi <dbgh9129@gmail.com>

[ Upstream commit 63320db6a5d84ec3fed8b3d36ba5244d07ddd108 ]

acpi_ipmi_space_handler() takes an extra reference on tx_msg before
checking whether the selected IPMI device is dead. The reference
belongs to the tx_msg_list entry and is normally dropped by
ipmi_cancel_tx_msg() or ipmi_flush_tx_msg() after the message is removed
from the list.

On the dead-device path, the message has not been queued yet, but the
error path still calls ipmi_msg_release() directly. That bypasses
kref_put() and frees tx_msg while the queued-message reference is still
recorded in the kref count.

Take the queued-message reference only after the dead-device check
succeeds, immediately before adding tx_msg to the list.

Fixes: 7b9844772237 ("ACPI / IPMI: Add reference counting for ACPI IPMI transfers")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Link: https://patch.msgid.link/20260603163108.2149359-1-dbgh9129@gmail.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/acpi/acpi_ipmi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/acpi/acpi_ipmi.c b/drivers/acpi/acpi_ipmi.c
index 8f1aeae8b72ed7..79ce6e72bf295a 100644
--- a/drivers/acpi/acpi_ipmi.c
+++ b/drivers/acpi/acpi_ipmi.c
@@ -550,7 +550,6 @@ acpi_ipmi_space_handler(u32 function, acpi_physical_address address,
 		return AE_TYPE;
 	}
 
-	acpi_ipmi_msg_get(tx_msg);
 	mutex_lock(&driver_data.ipmi_lock);
 	/* Do not add a tx_msg that can not be flushed. */
 	if (ipmi_device->dead) {
@@ -558,6 +557,7 @@ acpi_ipmi_space_handler(u32 function, acpi_physical_address address,
 		ipmi_msg_release(tx_msg);
 		return AE_NOT_EXIST;
 	}
+	acpi_ipmi_msg_get(tx_msg);
 	spin_lock_irqsave(&ipmi_device->tx_msg_lock, flags);
 	list_add_tail(&tx_msg->head, &ipmi_device->tx_msg_list);
 	spin_unlock_irqrestore(&ipmi_device->tx_msg_lock, flags);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0541/2077] ACPI: processor: Add cpuidle driver check in acpi_processor_register_idle_driver()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (539 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0540/2077] ACPI: IPMI: Fix message kref handling on dead device Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0542/2077] cpufreq: Documentation: fix conservative governor freq_step description Greg Kroah-Hartman
                   ` (456 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tony W Wang-oc, Rafael J. Wysocki,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tony W Wang-oc <TonyWWang-oc@zhaoxin.com>

[ Upstream commit 66c62e6773c54ce5233eb21c6d48999c3747bd13 ]

Commit 7a8c994cbb2d ("ACPI: processor: idle: Optimize ACPI idle
driver registration") moved the ACPI idle driver registration to
acpi_processor_driver_init(), but it didn't check whether a cpuidle
driver was already registered.

For example, on Intel platforms, if the intel_idle driver is already
loaded, the code would still evaluate the _CST object in the ACPI
table and attempt to register the acpi_idle driver. This registration
would fail with -EBUSY due to the existing check in cpuidle_register_driver.

Add a check at the beginning of acpi_processor_register_idle_driver()
to avoid unnecessary _CST evaluate and potential registration failures.

Fixes: 7a8c994cbb2d ("ACPI: processor: idle: Optimize ACPI idle driver registration")
Signed-off-by: Tony W Wang-oc <TonyWWang-oc@zhaoxin.com>
Link: https://patch.msgid.link/20260608190359.3254-1-TonyWWang-oc@zhaoxin.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/acpi/processor_idle.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/drivers/acpi/processor_idle.c b/drivers/acpi/processor_idle.c
index ee5facccbe10c5..390ab5f1d31378 100644
--- a/drivers/acpi/processor_idle.c
+++ b/drivers/acpi/processor_idle.c
@@ -1355,6 +1355,15 @@ void acpi_processor_register_idle_driver(void)
 	int ret = -ENODEV;
 	int cpu;
 
+	/*
+	 * If a cpuidle driver is already registered, there is no need to
+	 * evaluate _CST or attempt to register the ACPI idle driver.
+	 */
+	if (cpuidle_get_driver()) {
+		pr_debug("cpuidle driver %pS already registered.\n", cpuidle_get_driver());
+		return;
+	}
+
 	acpi_processor_update_max_cstate();
 
 	/*
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0542/2077] cpufreq: Documentation: fix conservative governor freq_step description
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (540 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0541/2077] ACPI: processor: Add cpuidle driver check in acpi_processor_register_idle_driver() Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0543/2077] thermal: testing: reject missing command arguments Greg Kroah-Hartman
                   ` (455 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Pengjie Zhang, Zhongqiu Han,
	Rafael J. Wysocki, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pengjie Zhang <zhangpengjie2@huawei.com>

[ Upstream commit 03120e1425262c7d11f93362a88e579a1720390b ]

The conservative governor documentation incorrectly states that setting
freq_step to 0 will use the default 5% frequency step. In reality, since
at least commit 8e677ce83bf4 ("[CPUFREQ] conservative: fixup governor to
function more like ondemand logic"), freq_step=0 has always caused the
governor to skip frequency updates entirely.

Correct the documentation to reflect the actual behavior: freq_step=0
disables frequency changes by the governor entirely.

Fixes: 2a0e49279850 ("cpufreq: User/admin documentation update and consolidation")
Signed-off-by: Pengjie Zhang <zhangpengjie2@huawei.com>
Reviewed-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
[ rjw: Subject adjustment ]
Link: https://patch.msgid.link/20260603055635.1549943-1-zhangpengjie2@huawei.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/admin-guide/pm/cpufreq.rst | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/Documentation/admin-guide/pm/cpufreq.rst b/Documentation/admin-guide/pm/cpufreq.rst
index fdca59c955dcc9..8831cface58552 100644
--- a/Documentation/admin-guide/pm/cpufreq.rst
+++ b/Documentation/admin-guide/pm/cpufreq.rst
@@ -586,8 +586,8 @@ This governor exposes the following tunables:
 	100 (5 by default).
 
 	This is how much the frequency is allowed to change in one go.  Setting
-	it to 0 will cause the default frequency step (5 percent) to be used
-	and setting it to 100 effectively causes the governor to periodically
+	it to 0 disables frequency changes by the governor entirely and setting
+	it to 100 effectively causes the governor to periodically
 	switch the frequency between the ``scaling_min_freq`` and
 	``scaling_max_freq`` policy limits.
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0543/2077] thermal: testing: reject missing command arguments
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (541 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0542/2077] cpufreq: Documentation: fix conservative governor freq_step description Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0544/2077] btrfs: dont force DIO writes to be serialized Greg Kroah-Hartman
                   ` (454 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Samuel Moelius, Rafael J. Wysocki,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Samuel Moelius <sam.moelius@trailofbits.com>

[ Upstream commit ef3e98b0aa4b348f44065d7130251273c83bd204 ]

The thermal testing debugfs command parser splits commands at ':' and
passes the right-hand side to the command implementation. Commands such
as deltz, tzaddtrip, tzreg, and tzunreg require a zone id, but writing
one of those command names without ':' leaves the argument pointer NULL.

The command implementations parse the id with sscanf(arg, "%d", ...), so
the missing-argument form dereferences a NULL pointer from the debugfs
write path.

Reject missing arguments in tt_command_exec() before calling handlers
that require an id.

Fixes: f6a034f2df42 ("thermal: Introduce a debugfs-based testing facility")
Assisted-by: Codex:gpt-5.5-cyber-preview
Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com>
Link: https://patch.msgid.link/20260605185212.2491144-1-sam.moelius@trailofbits.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/thermal/testing/command.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/drivers/thermal/testing/command.c b/drivers/thermal/testing/command.c
index 1159ecea57e7cf..fbf7ab9729b5a5 100644
--- a/drivers/thermal/testing/command.c
+++ b/drivers/thermal/testing/command.c
@@ -116,18 +116,30 @@ static int tt_command_exec(int index, const char *arg)
 		break;
 
 	case TT_CMD_DELTZ:
+		if (!arg || !*arg)
+			return -EINVAL;
+
 		ret = tt_del_tz(arg);
 		break;
 
 	case TT_CMD_TZADDTRIP:
+		if (!arg || !*arg)
+			return -EINVAL;
+
 		ret = tt_zone_add_trip(arg);
 		break;
 
 	case TT_CMD_TZREG:
+		if (!arg || !*arg)
+			return -EINVAL;
+
 		ret = tt_zone_reg(arg);
 		break;
 
 	case TT_CMD_TZUNREG:
+		if (!arg || !*arg)
+			return -EINVAL;
+
 		ret = tt_zone_unreg(arg);
 		break;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0544/2077] btrfs: dont force DIO writes to be serialized
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (542 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0543/2077] thermal: testing: reject missing command arguments Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0545/2077] ntfs: validate resident attribute lists and harden the validator Greg Kroah-Hartman
                   ` (453 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mark Harmstone, David Sterba,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mark Harmstone <mark@harmstone.com>

[ Upstream commit 14f9161e872072075284b8afa4c3f929e199a0f6 ]

Before btrfs switched to the new mount API in 2023, we were setting
SB_NOSEC in btrfs_mount_root(). This flag tells the VFS that the
filesystem may have files which don't have security xattrs, enabling it
to do some optimizations.

Unfortunately this was missed in the transition, meaning that IS_NOSEC
will always return false for a btrfs inode. This means that
btrfs_direct_write() calls will always get the inode lock exclusively,
meaning that DIO writes to the same file will be serialized.

On my machine, this one-line change results in a ~59% improvement in DIO
throughput:

Before patch:

  test: (g=0): rw=randwrite, bs=(R) 4096B-4096B, (W) 4096B-4096B, (T) 4096B-4096B, ioengine=io_uring, iodepth=64
  ...
  fio-3.39
  Starting 32 processes
  test: Laying out IO file (1 file / 1024MiB)
  Jobs: 32 (f=32): [w(32)][100.0%][w=764MiB/s][w=195k IOPS][eta 00m:00s]
  test: (groupid=0, jobs=32): err= 0: pid=586: Wed Apr 22 13:03:04 2026
    write: IOPS=202k, BW=787MiB/s (826MB/s)(46.1GiB/60012msec); 0 zone resets
     bw (  KiB/s): min=498714, max=1199892, per=100.00%, avg=806659.03, stdev=4229.94, samples=3808
     iops        : min=124677, max=299971, avg=201661.82, stdev=1057.49, samples=3808
    cpu          : usr=0.32%, sys=1.27%, ctx=8329204, majf=0, minf=1163
    IO depths    : 1=0.0%, 2=0.0%, 4=0.0%, 8=0.0%, 16=0.0%, 32=0.0%, >=64=100.0%
       submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
       complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
       issued rwts: total=0,12094328,0,0 short=0,0,0,0 dropped=0,0,0,0
       latency   : target=0, window=0, percentile=100.00%, depth=64

  Run status group 0 (all jobs):
    WRITE: bw=787MiB/s (826MB/s), 787MiB/s-787MiB/s (826MB/s-826MB/s), io=46.1GiB (49.5GB), run=60012-60012msec

After patch:

  test: (g=0): rw=randwrite, bs=(R) 4096B-4096B, (W) 4096B-4096B, (T) 4096B-4096B, ioengine=io_uring, iodepth=64
  ...
  fio-3.39
  Starting 32 processes
  test: Laying out IO file (1 file / 1024MiB)
  Jobs: 32 (f=32): [w(32)][100.0%][w=1255MiB/s][w=321k IOPS][eta 00m:00s]
  test: (groupid=0, jobs=32): err= 0: pid=572: Wed Apr 22 13:13:46 2026
    write: IOPS=320k, BW=1250MiB/s (1311MB/s)(73.3GiB/60003msec); 0 zone resets
     bw (  MiB/s): min=  619, max= 2289, per=100.00%, avg=1251.28, stdev= 9.64, samples=3808
     iops        : min=158538, max=586025, avg=320320.80, stdev=2468.97, samples=3808
    cpu          : usr=0.35%, sys=11.50%, ctx=1584847, majf=0, minf=1160
    IO depths    : 1=0.0%, 2=0.0%, 4=0.0%, 8=0.0%, 16=0.0%, 32=0.0%, >=64=100.0%
       submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
       complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
       issued rwts: total=0,19203309,0,0 short=0,0,0,0 dropped=0,0,0,0
       latency   : target=0, window=0, percentile=100.00%, depth=64

  Run status group 0 (all jobs):
    WRITE: bw=1250MiB/s (1311MB/s), 1250MiB/s-1250MiB/s (1311MB/s-1311MB/s), io=73.3GiB (78.7GB), run=60003-60003msec

The script to reproduce that:

  #!/bin/bash
  mkfs.btrfs -f /dev/nvme0n1
  mount /dev/nvme0n1 /mnt/test
  mkdir /mnt/test/nocow
  chattr +C /mnt/test/nocow
  fio /root/test.fio

  # cat /root/test.fio
  [global]
  rw=randwrite
  ioengine=io_uring
  iodepth=64
  size=1g
  direct=1
  startdelay=20
  force_async=4
  ramp_time=5
  runtime=60
  group_reporting=1
  numjobs=32
  time_based
  disk_util=0
  clat_percentiles=0
  disable_lat=1
  disable_clat=1
  disable_slat=1
  filename=/mnt/test/nocow/fiofile
  [test]
  name=test
  bs=4k
  stonewall

This was on a VM with 8 cores and 8GB of RAM, with a real NVMe exposed
through PCI passthrough. The figures for XFS and ext4 in comparison are
both about ~3GB/s.

Fixes: ad21f15b0f79 ("btrfs: switch to the new mount API")
Signed-off-by: Mark Harmstone <mark@harmstone.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/btrfs/super.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/fs/btrfs/super.c b/fs/btrfs/super.c
index b26aa9169e8388..64514d600eec71 100644
--- a/fs/btrfs/super.c
+++ b/fs/btrfs/super.c
@@ -1873,6 +1873,7 @@ static int btrfs_get_tree_super(struct fs_context *fc)
 	fs_info->fs_devices = fs_devices;
 	mutex_unlock(&uuid_mutex);
 
+	fc->sb_flags |= SB_NOSEC;
 
 	sb = sget_fc(fc, btrfs_fc_test_super, set_anon_super_fc);
 	if (IS_ERR(sb)) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0545/2077] ntfs: validate resident attribute lists and harden the validator
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (543 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0544/2077] btrfs: dont force DIO writes to be serialized Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0546/2077] ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() Greg Kroah-Hartman
                   ` (452 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Hyunchul Lee,
	Namjae Jeon, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bryam Vargas <hexlabsecurity@proton.me>

[ Upstream commit 7d19e1ffee084c4f7d321a360c14ba43404f7cc8 ]

A base inode's $ATTRIBUTE_LIST is sanity-checked by load_attribute_list()
only on the non-resident path; ntfs_read_locked_inode() copies a *resident*
attribute list into ni->attr_list with a plain memcpy() and no validation
at all. Every subsequent walk of ni->attr_list --
ntfs_external_attr_find(), ntfs_inode_attach_all_extents() and
ntfs_attrlist_need() -- then trusts the entries are well-formed and reads
attr_list_entry fixed-header fields
(lowest_vcn at offset 8, mft_reference at offset 16, and the name) with
bounds that assume validation already happened. A crafted resident
attribute list therefore reaches those walks unvalidated and can drive
out-of-bounds reads of the attribute-list buffer.

load_attribute_list() itself reads ale->name_offset (offset 7),
ale->mft_reference (offset 16) and the name length under only an
"al < al_start + size" bound, so its own validation loop can over-read the
fixed header of a truncated trailing entry by a few bytes.

Factor the per-entry validation into ntfs_attr_list_entry_is_valid(),
which requires each entry's fixed header (offsetof(struct
attr_list_entry, name)) to be in range before any field is dereferenced,
that ale->length is a multiple of 8 covering the fixed header plus the
name, and that the entry is in use and carries a live MFT reference.
ntfs_attr_list_is_valid() walks the buffer with it and checks the entries
tile it exactly. Use the list validator in load_attribute_list()
(replacing the open-coded loop, closing its own over-read) and on the
resident path in ntfs_read_locked_inode() (which previously skipped
validation entirely); patches 2/3 reuse the per-entry helper at the other
two attribute-list walks.

Fixes: 1e9ea7e04472 ("Revert "fs: Remove NTFS classic"")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs/attrib.c | 78 ++++++++++++++++++++++++++++++++++++++----------
 fs/ntfs/attrib.h |  4 +++
 fs/ntfs/inode.c  |  6 ++++
 3 files changed, 73 insertions(+), 15 deletions(-)

diff --git a/fs/ntfs/attrib.c b/fs/ntfs/attrib.c
index 421c6cdcbb5307..abc0add6f0c446 100644
--- a/fs/ntfs/attrib.c
+++ b/fs/ntfs/attrib.c
@@ -843,11 +843,71 @@ char *ntfs_attr_name_get(const struct ntfs_volume *vol, const __le16 *uname,
 	return NULL;
 }
 
+/*
+ * ntfs_attr_list_entry_is_valid - sanity check one $ATTRIBUTE_LIST entry
+ * @ale:	the attribute-list entry to check
+ * @al_end:	end of the attribute-list buffer @ale lives in
+ *
+ * Verify that @ale is a well-formed attr_list_entry wholly contained in
+ * [.., @al_end): its fixed header must lie in range before any field is
+ * dereferenced, its length must be a multiple of 8 that covers the fixed
+ * header plus the name, the name must lie within the buffer, the entry must
+ * be in use and carry a live MFT reference.  Return true if valid.
+ */
+bool ntfs_attr_list_entry_is_valid(const struct attr_list_entry *ale,
+				   const u8 *al_end)
+{
+	const u8 *al = (const u8 *)ale;
+	u16 ale_len;
+
+	/* The fixed header must be in bounds before it is parsed. */
+	if (al + offsetof(struct attr_list_entry, name) > al_end)
+		return false;
+	ale_len = le16_to_cpu(ale->length);
+	/* On-disk entries are 8-byte aligned (see struct attr_list_entry). */
+	if (ale_len & 7)
+		return false;
+	if (ale->name_offset != sizeof(struct attr_list_entry))
+		return false;
+	if ((u32)ale->name_offset +
+	    (u32)ale->name_length * sizeof(__le16) > ale_len ||
+	    al + ale_len > al_end)
+		return false;
+	if (ale->type == AT_UNUSED)
+		return false;
+	if (MSEQNO_LE(ale->mft_reference) == 0)
+		return false;
+	return true;
+}
+
+/*
+ * ntfs_attr_list_is_valid - sanity check an in-memory $ATTRIBUTE_LIST
+ * @al_start:	start of the attribute list buffer
+ * @size:	length of the attribute list in bytes
+ *
+ * Verify that [@al_start, @al_start + @size) is a sequence of valid
+ * attr_list_entry records (see ntfs_attr_list_entry_is_valid()) that tile the
+ * buffer exactly.  Return true if valid, false otherwise.
+ */
+bool ntfs_attr_list_is_valid(const u8 *al_start, s64 size)
+{
+	const u8 *al = al_start;
+	const u8 *al_end = al_start + size;
+
+	while (al < al_end) {
+		const struct attr_list_entry *ale =
+				(const struct attr_list_entry *)al;
+
+		if (!ntfs_attr_list_entry_is_valid(ale, al_end))
+			return false;
+		al += le16_to_cpu(ale->length);
+	}
+	return al == al_end;
+}
+
 int load_attribute_list(struct ntfs_inode *base_ni, u8 *al_start, const s64 size)
 {
 	struct inode *attr_vi = NULL;
-	u8 *al;
-	struct attr_list_entry *ale;
 
 	if (!al_start || size <= 0)
 		return -EINVAL;
@@ -869,19 +929,7 @@ int load_attribute_list(struct ntfs_inode *base_ni, u8 *al_start, const s64 size
 	}
 	iput(attr_vi);
 
-	for (al = al_start; al < al_start + size; al += le16_to_cpu(ale->length)) {
-		ale = (struct attr_list_entry *)al;
-		if (ale->name_offset != sizeof(struct attr_list_entry))
-			break;
-		if (le16_to_cpu(ale->length) <= ale->name_offset + ale->name_length ||
-		    al + le16_to_cpu(ale->length) > al_start + size)
-			break;
-		if (ale->type == AT_UNUSED)
-			break;
-		if (MSEQNO_LE(ale->mft_reference) == 0)
-			break;
-	}
-	if (al != al_start + size) {
+	if (!ntfs_attr_list_is_valid(al_start, size)) {
 		ntfs_error(base_ni->vol->sb, "Corrupt attribute list, mft = %llu",
 			   base_ni->mft_no);
 		return -EIO;
diff --git a/fs/ntfs/attrib.h b/fs/ntfs/attrib.h
index f7acc7986b090d..e2224fbfaabe95 100644
--- a/fs/ntfs/attrib.h
+++ b/fs/ntfs/attrib.h
@@ -71,6 +71,10 @@ int ntfs_attr_lookup(const __le32 type, const __le16 *name,
 		const u32 name_len, const u32 ic,
 		const s64 lowest_vcn, const u8 *val, const u32 val_len,
 		struct ntfs_attr_search_ctx *ctx);
+bool ntfs_attr_list_entry_is_valid(const struct attr_list_entry *ale,
+				   const u8 *al_end);
+bool ntfs_attr_list_is_valid(const u8 *al_start, s64 size);
+
 int load_attribute_list(struct ntfs_inode *base_ni,
 			       u8 *al_start, const s64 size);
 
diff --git a/fs/ntfs/inode.c b/fs/ntfs/inode.c
index 360bebd1ee3fe6..a5f7400fd19dc4 100644
--- a/fs/ntfs/inode.c
+++ b/fs/ntfs/inode.c
@@ -848,6 +848,12 @@ static int ntfs_read_locked_inode(struct inode *vi)
 					a->data.resident.value_offset),
 					le32_to_cpu(
 					a->data.resident.value_length));
+			/* A resident list is not validated on load; check it now. */
+			if (!ntfs_attr_list_is_valid(ni->attr_list,
+						     ni->attr_list_size)) {
+				ntfs_error(vi->i_sb, "Corrupt attribute list.");
+				goto unm_err_out;
+			}
 		}
 	}
 skip_attr_list_load:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0546/2077] ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (544 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0545/2077] ntfs: validate resident attribute lists and harden the validator Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0547/2077] ntfs: bound the attribute-list entry in ntfs_read_inode_mount() Greg Kroah-Hartman
                   ` (451 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Hyunchul Lee,
	Namjae Jeon, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bryam Vargas <hexlabsecurity@proton.me>

[ Upstream commit 344b18f389f9934d59c7b0cf3d20541ea2e0da58 ]

When resolving an attribute lookup with a non-zero @lowest_vcn,
ntfs_external_attr_find() peeks at the next $ATTRIBUTE_LIST entry to
decide whether to keep searching, but bounds that not-yet-validated
entry only with "(u8 *)next_al_entry + 6 < al_end" (which proves just
bytes 0..6 are in range) and "(u8 *)next_al_entry + length <= al_end"
with an attacker-controlled, non-8-aligned length. It then reads
next_al_entry->lowest_vcn (an __le64 at offset 8) and the name at
next_al_entry->name_offset, both of which can lie past al_end -- the
exact end of the kvmalloc'd attribute-list buffer (allocated at the
on-disk attr_list_size, no rounding). A crafted on-disk $ATTRIBUTE_LIST
whose last entry sits a few bytes before al_end therefore yields a slab
out-of-bounds read when the inode is read.

Validate the look-ahead entry with ntfs_attr_list_entry_is_valid() (added
in patch 1/3) before dereferencing lowest_vcn and the name, so the same
fixed-header, length and name bounds the main attribute-list walk uses now
guard this read too.

Fixes: 1e9ea7e04472 ("Revert "fs: Remove NTFS classic"")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs/attrib.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/fs/ntfs/attrib.c b/fs/ntfs/attrib.c
index abc0add6f0c446..e425c8d074c58a 100644
--- a/fs/ntfs/attrib.c
+++ b/fs/ntfs/attrib.c
@@ -1185,9 +1185,8 @@ static int ntfs_external_attr_find(const __le32 type,
 		 * we have reached the right one or the search has failed.
 		 */
 		if (lowest_vcn && (u8 *)next_al_entry >= al_start &&
-				(u8 *)next_al_entry + 6 < al_end &&
-				(u8 *)next_al_entry + le16_to_cpu(
-					next_al_entry->length) <= al_end &&
+				ntfs_attr_list_entry_is_valid(next_al_entry,
+							      al_end) &&
 				le64_to_cpu(next_al_entry->lowest_vcn) <=
 					lowest_vcn &&
 				next_al_entry->type == al_entry->type &&
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0547/2077] ntfs: bound the attribute-list entry in ntfs_read_inode_mount()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (545 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0546/2077] ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0548/2077] ntfs: fix u16 truncation of restart-area length check Greg Kroah-Hartman
                   ` (450 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Hyunchul Lee,
	Namjae Jeon, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bryam Vargas <hexlabsecurity@proton.me>

[ Upstream commit 98634df5b1cb56c26299b7409227025ddb0167d8 ]

The $MFT attribute-list walk in ntfs_read_inode_mount() validates each
entry only with "(u8 *)al_entry + 6 > al_end" and
"(u8 *)al_entry + le16_to_cpu(al_entry->length) > al_end", but then reads
al_entry->lowest_vcn (an __le64 at offset 8) and al_entry->mft_reference
(offset 16) -- fields beyond the 6 bytes proven in range. al_entry->length
is attacker-controlled and only required non-zero, so a short entry (e.g.
length 8) placed at the tail passes both checks while the lowest_vcn /
mft_reference reads fall past al_end.

al_end is ni->attr_list + attr_list_size (the on-disk size); the buffer is
kvzalloc(round_up(attr_list_size, SECTOR_SIZE)), so the sector rounding
usually absorbs the over-read -- but when attr_list_size is a multiple of
SECTOR_SIZE there is no slack and a crafted $MFT attribute list produces an
out-of-bounds read at mount time.

Validate the entry with ntfs_attr_list_entry_is_valid() (added in patch
1/3) before dereferencing it, matching the bound the other attribute-list
walks now use. The validator already requires the length to cover the fixed
header, which makes the separate "!al_entry->length" check redundant, so
drop it too.

Fixes: 1e9ea7e04472 ("Revert "fs: Remove NTFS classic"")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs/inode.c | 5 +----
 1 file changed, 1 insertion(+), 4 deletions(-)

diff --git a/fs/ntfs/inode.c b/fs/ntfs/inode.c
index a5f7400fd19dc4..c4fa6aa11c9e8d 100644
--- a/fs/ntfs/inode.c
+++ b/fs/ntfs/inode.c
@@ -2000,10 +2000,7 @@ int ntfs_read_inode_mount(struct inode *vi)
 			/* Catch the end of the attribute list. */
 			if ((u8 *)al_entry == al_end)
 				goto em_put_err_out;
-			if (!al_entry->length)
-				goto em_put_err_out;
-			if ((u8 *)al_entry + 6 > al_end ||
-			    (u8 *)al_entry + le16_to_cpu(al_entry->length) > al_end)
+			if (!ntfs_attr_list_entry_is_valid(al_entry, al_end))
 				goto em_put_err_out;
 			next_al_entry = (struct attr_list_entry *)((u8 *)al_entry +
 					le16_to_cpu(al_entry->length));
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0548/2077] ntfs: fix u16 truncation of restart-area length check
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (546 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0547/2077] ntfs: bound the attribute-list entry in ntfs_read_inode_mount() Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0549/2077] IB/mlx5: Dont take the rereg_mr fallback without a new translation Greg Kroah-Hartman
                   ` (449 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Namjae Jeon,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bryam Vargas <hexlabsecurity@proton.me>

[ Upstream commit 390936fb15053d8d8991ca3a22776e251a5a7f2f ]

ntfs_check_restart_area() validates that the $LogFile restart area and
its trailing log client record array fit within the system page size:

        u16 ra_ofs, ra_len, ca_ofs;
        ...
        ra_len = ca_ofs + le16_to_cpu(ra->log_clients) *
                        sizeof(struct log_client_record);
        if (ra_ofs + ra_len > le32_to_cpu(rp->system_page_size) || ...)
                return false;

ra_len is u16, but the right-hand side is computed in size_t
(sizeof(struct log_client_record) == 160). Both ca_ofs and log_clients
come straight from the on-disk restart area. With an on-disk
log_clients of 410 the product 410 * 160 = 65600; adding ca_ofs and
storing into the u16 ra_len truncates modulo 65536 (e.g. ca_ofs 64
gives ra_len 128), so the "fits in the page" check passes even though
the client array described by log_clients extends far beyond the page.

ntfs_check_log_client_array() then walks the array bounded only by the
on-disk log_clients count:

        cr = ca + idx;
        if (cr->prev_client != LOGFILE_NO_CLIENT) ...

For log_clients 410 it dereferences records up to ca + 409 * 160,
~64 KiB past the kvzalloc(system_page_size) restart-page buffer -- an
out-of-bounds read of attacker-controlled extent, reachable when a
crafted NTFS image is mounted (load_and_check_logfile() at mount time).
This is the in-kernel analogue of CVE-2022-30789, fixed in the ntfs-3g
userspace driver but never in this revived classic driver.

Compute the restart-area length in a u32 so the existing bounds check
rejects an over-large client array instead of being defeated by the
truncation. Widen ra_ofs and ca_ofs to u32 as well: both are loaded
from __le16 on-disk fields and every comparison already promotes to
int/size_t, so this changes no result and keeps the declaration uniform.

Fixes: 1e9ea7e04472 ("Revert "fs: Remove NTFS classic"")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs/logfile.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/ntfs/logfile.c b/fs/ntfs/logfile.c
index d3f25d8e29f9d2..9bc34572908efe 100644
--- a/fs/ntfs/logfile.c
+++ b/fs/ntfs/logfile.c
@@ -132,7 +132,7 @@ static bool ntfs_check_restart_area(struct inode *vi, struct restart_page_header
 {
 	u64 file_size;
 	struct restart_area *ra;
-	u16 ra_ofs, ra_len, ca_ofs;
+	u32 ra_ofs, ra_len, ca_ofs;
 	u8 fs_bits;
 
 	ntfs_debug("Entering.");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0549/2077] IB/mlx5: Dont take the rereg_mr fallback without a new translation
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (547 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0548/2077] ntfs: fix u16 truncation of restart-area length check Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0550/2077] IB/mlx5: Properly support implicit ODP rereg_mr Greg Kroah-Hartman
                   ` (448 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jason Gunthorpe <jgg@nvidia.com>

[ Upstream commit 55d339d200c908de83a408d023cfb7be779b0dd7 ]

Jumping to mlx5_ib_reg_user_mr() without IB_MR_REREG_TRANS set will use
garbage values for start, length, and iova. Recovering the original mr
parameters for ODP and DMABUF to properly recreate it is too hard in this
flow, so just fail it.

Fixes: ef3642c4f54d ("RDMA/mlx5: Fix error unwinds for rereg_mr")
Link: https://patch.msgid.link/r/1-v1-29ebd2c229b5+fd5-ib_mr_pd_jgg@nvidia.com
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/mr.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/mlx5/mr.c b/drivers/infiniband/hw/mlx5/mr.c
index fb40b44496f47a..d70d3e3dbd1a95 100644
--- a/drivers/infiniband/hw/mlx5/mr.c
+++ b/drivers/infiniband/hw/mlx5/mr.c
@@ -1202,7 +1202,7 @@ struct ib_mr *mlx5_ib_rereg_user_mr(struct ib_mr *ib_mr, int flags, u64 start,
 		}
 		/* DM or ODP MR's don't have a normal umem so we can't re-use it */
 		if (!mr->umem || is_odp_mr(mr) || is_dmabuf_mr(mr))
-			goto recreate;
+			return ERR_PTR(-EOPNOTSUPP);
 
 		/*
 		 * Only one active MR can refer to a umem at one time, revoke
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0550/2077] IB/mlx5: Properly support implicit ODP rereg_mr
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (548 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0549/2077] IB/mlx5: Dont take the rereg_mr fallback without a new translation Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0551/2077] RDMA/nldev: Fix locking when accessing mr->pd Greg Kroah-Hartman
                   ` (447 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jason Gunthorpe <jgg@nvidia.com>

[ Upstream commit ee7a8335069150c3f1893a697ab30bbeca00d796 ]

Due to all the child mkeys in the implicit ODP configuration we cannot
change anything in place for the parent mkey. Instead the whole thing
needs to be rebuilt if any change is requested. If the user does not
specify a translation then force the implicit values which will then fall
through the logic into mlx5_ib_reg_user_mr() to allocate a completely new
MR.

Since implicit children were also touching the mr->pd, this removes
another case where the access was racy.

Fixes: ef3642c4f54d ("RDMA/mlx5: Fix error unwinds for rereg_mr")
Link: https://sashiko.dev/#/patchset/20260427-security-bug-fixes-v3-0-4621fa52de0e%40nvidia.com?part=4
Link: https://patch.msgid.link/r/3-v1-29ebd2c229b5+fd5-ib_mr_pd_jgg@nvidia.com
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/mr.c | 15 +++++++++++++++
 1 file changed, 15 insertions(+)

diff --git a/drivers/infiniband/hw/mlx5/mr.c b/drivers/infiniband/hw/mlx5/mr.c
index d70d3e3dbd1a95..f3884faf1a117c 100644
--- a/drivers/infiniband/hw/mlx5/mr.c
+++ b/drivers/infiniband/hw/mlx5/mr.c
@@ -1188,6 +1188,21 @@ struct ib_mr *mlx5_ib_rereg_user_mr(struct ib_mr *ib_mr, int flags, u64 start,
 	if (!(flags & IB_MR_REREG_PD))
 		new_pd = ib_mr->pd;
 
+	if (mr->is_odp_implicit && !(flags & IB_MR_REREG_TRANS)) {
+		if (!(new_access_flags & IB_ACCESS_ON_DEMAND))
+			return ERR_PTR(-EOPNOTSUPP);
+
+		/*
+		 * Due to all the child mkeys we cannot actually change an
+		 * implicit MR in place. If the user did not specify a new
+		 * translation then force the fixed implicit MR values.
+		 */
+		start = 0;
+		iova = 0;
+		length = U64_MAX;
+		flags |= IB_MR_REREG_TRANS;
+	}
+
 	if (!(flags & IB_MR_REREG_TRANS)) {
 		struct ib_umem *umem;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0551/2077] RDMA/nldev: Fix locking when accessing mr->pd
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (549 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0550/2077] IB/mlx5: Properly support implicit ODP rereg_mr Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0552/2077] IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift() Greg Kroah-Hartman
                   ` (446 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jason Gunthorpe <jgg@nvidia.com>

[ Upstream commit 50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3 ]

Sashiko points out that, due to rereg_mr, the PD is actually variable and
all the touches in nldev are racy.

Use mr->device instead of mr->pd->device.

Getting the PD restrack ID is more tricky. To avoid disturbing all the
happy paths, add an rdma_restrack_sync() operation which is sort of like
flush_workqueue() or synchronize_irq(): after it returns, all the old
nldev touches to the mr are gone and everything sees the new PD. This
makes it safe to reach into the PD pointer.

Fixes: da5c85078215 ("RDMA/nldev: add driver-specific resource tracking")
Link: https://patch.msgid.link/r/4-v1-29ebd2c229b5+fd5-ib_mr_pd_jgg@nvidia.com
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/core/nldev.c      | 15 +++++----
 drivers/infiniband/core/restrack.c   | 49 ++++++++++++++++++++++++++++
 drivers/infiniband/core/restrack.h   |  1 +
 drivers/infiniband/core/uverbs_cmd.c | 10 ++++--
 include/rdma/ib_verbs.h              |  5 +++
 5 files changed, 72 insertions(+), 8 deletions(-)

diff --git a/drivers/infiniband/core/nldev.c b/drivers/infiniband/core/nldev.c
index 5aaba2b9746ba6..02a0a9c0a4a6ad 100644
--- a/drivers/infiniband/core/nldev.c
+++ b/drivers/infiniband/core/nldev.c
@@ -695,7 +695,7 @@ static int fill_res_mr_entry(struct sk_buff *msg, bool has_cap_net_admin,
 			     struct rdma_restrack_entry *res, uint32_t port)
 {
 	struct ib_mr *mr = container_of(res, struct ib_mr, res);
-	struct ib_device *dev = mr->pd->device;
+	struct ib_device *dev = mr->device;
 
 	if (has_cap_net_admin) {
 		if (nla_put_u32(msg, RDMA_NLDEV_ATTR_RES_RKEY, mr->rkey))
@@ -711,9 +711,12 @@ static int fill_res_mr_entry(struct sk_buff *msg, bool has_cap_net_admin,
 	if (nla_put_u32(msg, RDMA_NLDEV_ATTR_RES_MRN, res->id))
 		return -EMSGSIZE;
 
-	if (!rdma_is_kernel_res(res) &&
-	    nla_put_u32(msg, RDMA_NLDEV_ATTR_RES_PDN, mr->pd->res.id))
-		return -EMSGSIZE;
+	if (!rdma_is_kernel_res(res)) {
+		struct ib_pd *pd = READ_ONCE(mr->pd);
+
+		if (nla_put_u32(msg, RDMA_NLDEV_ATTR_RES_PDN, pd->res.id))
+			return -EMSGSIZE;
+	}
 
 	if (fill_res_name_pid(msg, res))
 		return -EMSGSIZE;
@@ -727,7 +730,7 @@ static int fill_res_mr_raw_entry(struct sk_buff *msg, bool has_cap_net_admin,
 				 struct rdma_restrack_entry *res, uint32_t port)
 {
 	struct ib_mr *mr = container_of(res, struct ib_mr, res);
-	struct ib_device *dev = mr->pd->device;
+	struct ib_device *dev = mr->device;
 
 	if (!dev->ops.fill_res_mr_entry_raw)
 		return -EINVAL;
@@ -1017,7 +1020,7 @@ static int fill_stat_mr_entry(struct sk_buff *msg, bool has_cap_net_admin,
 			      struct rdma_restrack_entry *res, uint32_t port)
 {
 	struct ib_mr *mr = container_of(res, struct ib_mr, res);
-	struct ib_device *dev = mr->pd->device;
+	struct ib_device *dev = mr->device;
 
 	if (nla_put_u32(msg, RDMA_NLDEV_ATTR_RES_MRN, res->id))
 		goto err;
diff --git a/drivers/infiniband/core/restrack.c b/drivers/infiniband/core/restrack.c
index ac3688952cabbf..cfee2071586c16 100644
--- a/drivers/infiniband/core/restrack.c
+++ b/drivers/infiniband/core/restrack.c
@@ -71,6 +71,8 @@ int rdma_restrack_count(struct ib_device *dev, enum rdma_restrack_type type,
 
 	xa_lock(&rt->xa);
 	xas_for_each(&xas, e, U32_MAX) {
+		if (xa_is_zero(e))
+			continue;
 		if (xa_get_mark(&rt->xa, e->id, RESTRACK_DD) && !show_details)
 			continue;
 		cnt++;
@@ -276,6 +278,53 @@ int rdma_restrack_put(struct rdma_restrack_entry *res)
 }
 EXPORT_SYMBOL(rdma_restrack_put);
 
+/**
+ * rdma_restrack_sync() - Fence concurrent netlink dumps on an entry
+ * @res:  resource entry
+ *
+ * After this returns any concurrent netlink dump threads will see the current
+ * value of the object. This is useful if the object has to be changed and there
+ * is not locking to protect the nl side. Eg for mr->pd. This effectively
+ * destroys the object from a kref/xarray perspective and then immediately
+ * restores it. The kref is acting like a lock to barrier concurrent nl threads.
+ * Callers must ensure rdma_restrack_del() is not concurrently called.
+ */
+void rdma_restrack_sync(struct rdma_restrack_entry *res)
+{
+	struct rdma_restrack_entry *old;
+	struct rdma_restrack_root *rt;
+	struct task_struct *task;
+	struct ib_device *dev;
+
+	if (!res->valid || res->no_track)
+		return;
+
+	dev = res_to_dev(res);
+	if (WARN_ON(!dev))
+		return;
+
+	rt = &dev->res[res->type];
+	if (WARN_ON(xa_get_mark(&rt->xa, res->id, RESTRACK_DD)))
+		return;
+
+	old = xa_cmpxchg(&rt->xa, res->id, res, XA_ZERO_ENTRY, GFP_KERNEL);
+	if (WARN_ON(old != res))
+		return;
+
+	task = res->task;
+	if (task)
+		get_task_struct(task);
+	rdma_restrack_put(res);
+	wait_for_completion(&res->comp);
+	reinit_completion(&res->comp);
+	if (task)
+		res->task = task;
+	kref_init(&res->kref);
+
+	xa_cmpxchg(&rt->xa, res->id, XA_ZERO_ENTRY, res, GFP_KERNEL);
+}
+EXPORT_SYMBOL(rdma_restrack_sync);
+
 /**
  * rdma_restrack_del() - delete object from the resource tracking database
  * @res:  resource entry
diff --git a/drivers/infiniband/core/restrack.h b/drivers/infiniband/core/restrack.h
index 6a04fc41f73801..75b8d1005a984b 100644
--- a/drivers/infiniband/core/restrack.h
+++ b/drivers/infiniband/core/restrack.h
@@ -27,6 +27,7 @@ int rdma_restrack_init(struct ib_device *dev);
 void rdma_restrack_clean(struct ib_device *dev);
 void rdma_restrack_add(struct rdma_restrack_entry *res);
 void rdma_restrack_del(struct rdma_restrack_entry *res);
+void rdma_restrack_sync(struct rdma_restrack_entry *res);
 void rdma_restrack_new(struct rdma_restrack_entry *res,
 		       enum rdma_restrack_type type);
 void rdma_restrack_set_name(struct rdma_restrack_entry *res,
diff --git a/drivers/infiniband/core/uverbs_cmd.c b/drivers/infiniband/core/uverbs_cmd.c
index 91a62d2ade4dd0..22793e4b1895e4 100644
--- a/drivers/infiniband/core/uverbs_cmd.c
+++ b/drivers/infiniband/core/uverbs_cmd.c
@@ -47,6 +47,7 @@
 
 #include "uverbs.h"
 #include "core_priv.h"
+#include "restrack.h"
 
 /*
  * Copy a response to userspace. If the provided 'resp' is larger than the
@@ -819,6 +820,10 @@ static int ib_uverbs_rereg_mr(struct uverbs_attr_bundle *attrs)
 			ret = PTR_ERR(new_pd);
 			goto put_uobjs;
 		}
+		if (new_pd == orig_pd) {
+			uobj_put_obj_read(new_pd);
+			cmd.flags &= ~IB_MR_REREG_PD;
+		}
 	} else {
 		new_pd = mr->pd;
 	}
@@ -866,9 +871,10 @@ static int ib_uverbs_rereg_mr(struct uverbs_attr_bundle *attrs)
 		mr = new_mr;
 	} else {
 		if (cmd.flags & IB_MR_REREG_PD) {
-			atomic_dec(&orig_pd->usecnt);
-			mr->pd = new_pd;
 			atomic_inc(&new_pd->usecnt);
+			WRITE_ONCE(mr->pd, new_pd);
+			rdma_restrack_sync(&mr->res);
+			atomic_dec(&orig_pd->usecnt);
 		}
 		if (cmd.flags & IB_MR_REREG_TRANS) {
 			mr->iova = cmd.hca_va;
diff --git a/include/rdma/ib_verbs.h b/include/rdma/ib_verbs.h
index 9dd76f489a0ba4..46568a5221f403 100644
--- a/include/rdma/ib_verbs.h
+++ b/include/rdma/ib_verbs.h
@@ -1977,6 +1977,11 @@ struct ib_dmah {
 
 struct ib_mr {
 	struct ib_device  *device;
+	/*
+	 * Due to IB_MR_REREG_PD pd is not a fixed pointer and can change. For a
+	 * user MR, this value should only be read from a system call that holds
+	 * the uobject lock, or the driver should disable in-place REREG_PD.
+	 */
 	struct ib_pd	  *pd;
 	u32		   lkey;
 	u32		   rkey;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0552/2077] IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (550 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0551/2077] RDMA/nldev: Fix locking when accessing mr->pd Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0553/2077] IB/mlx5: Pull the pdn out of the depths of the umr machinery Greg Kroah-Hartman
                   ` (445 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jason Gunthorpe <jgg@nvidia.com>

[ Upstream commit 4910483bd7ee2b40d0cc8ebd537fa33c95562029 ]

The HW only processes mkc fields selected by mkey_mask.
pd, qpn and mkey_7_0 are never selected so they can be left as zero.

This removes a racy read of mr->pd.

Fixes: e73242aa14d2 ("RDMA/mlx5: Optimize DMABUF mkey page size")
Link: https://patch.msgid.link/r/5-v1-29ebd2c229b5+fd5-ib_mr_pd_jgg@nvidia.com
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/umr.c | 16 +++-------------
 drivers/infiniband/hw/mlx5/umr.h |  3 +--
 2 files changed, 4 insertions(+), 15 deletions(-)

diff --git a/drivers/infiniband/hw/mlx5/umr.c b/drivers/infiniband/hw/mlx5/umr.c
index 688d5246f284e8..f0ba8d91f81d16 100644
--- a/drivers/infiniband/hw/mlx5/umr.c
+++ b/drivers/infiniband/hw/mlx5/umr.c
@@ -937,8 +937,7 @@ int mlx5r_umr_update_xlt(struct mlx5_ib_mr *mr, u64 idx, int npages,
  * pinned and the HW can switch from 4K to huge-page alignment).
  */
 int mlx5r_umr_update_mr_page_shift(struct mlx5_ib_mr *mr,
-				   unsigned int page_shift,
-				   bool dd)
+				   unsigned int page_shift)
 {
 	struct mlx5_ib_dev *dev = mr_to_mdev(mr);
 	struct mlx5r_umr_wqe wqe = {};
@@ -953,16 +952,8 @@ int mlx5r_umr_update_mr_page_shift(struct mlx5_ib_mr *mr,
 	/* Fill mkey segment with the new page size, keep the rest unchanged */
 	MLX5_SET(mkc, &wqe.mkey_seg, log_page_size, page_shift);
 
-	if (dd)
-		MLX5_SET(mkc, &wqe.mkey_seg, pd, dev->ddr.pdn);
-	else
-		MLX5_SET(mkc, &wqe.mkey_seg, pd, to_mpd(mr->ibmr.pd)->pdn);
-
 	MLX5_SET64(mkc, &wqe.mkey_seg, start_addr, mr->ibmr.iova);
 	MLX5_SET64(mkc, &wqe.mkey_seg, len, mr->ibmr.length);
-	MLX5_SET(mkc, &wqe.mkey_seg, qpn, 0xffffff);
-	MLX5_SET(mkc, &wqe.mkey_seg, mkey_7_0,
-		 mlx5_mkey_variant(mr->mmkey.key));
 
 	err = mlx5r_umr_post_send_wait(dev, mr->mmkey.key, &wqe, false);
 	if (!err)
@@ -1049,7 +1040,7 @@ static int _mlx5r_umr_zap_mkey(struct mlx5_ib_mr *mr,
 	 * non-present.
 	 */
 	if (*nblocks) {
-		err = mlx5r_umr_update_mr_page_shift(mr, max_page_shift, dd);
+		err = mlx5r_umr_update_mr_page_shift(mr, max_page_shift);
 		if (err) {
 			mr->page_shift = old_page_shift;
 			return err;
@@ -1114,8 +1105,7 @@ int mlx5r_umr_dmabuf_update_pgsz(struct mlx5_ib_mr *mr, u32 xlt_flags,
 			goto err;
 	}
 
-	err = mlx5r_umr_update_mr_page_shift(mr, mr->page_shift,
-					     mr->data_direct);
+	err = mlx5r_umr_update_mr_page_shift(mr, mr->page_shift);
 	if (err)
 		goto err;
 	err = _mlx5r_dmabuf_umr_update_pas(mr, xlt_flags, 0, zapped_blocks,
diff --git a/drivers/infiniband/hw/mlx5/umr.h b/drivers/infiniband/hw/mlx5/umr.h
index 7eeaf6a94c9743..59809d4d7d7297 100644
--- a/drivers/infiniband/hw/mlx5/umr.h
+++ b/drivers/infiniband/hw/mlx5/umr.h
@@ -106,8 +106,7 @@ int mlx5r_umr_update_mr_pas(struct mlx5_ib_mr *mr, unsigned int flags);
 int mlx5r_umr_update_xlt(struct mlx5_ib_mr *mr, u64 idx, int npages,
 			 int page_shift, int flags);
 int mlx5r_umr_update_mr_page_shift(struct mlx5_ib_mr *mr,
-				   unsigned int page_shift,
-				   bool dd);
+				   unsigned int page_shift);
 int mlx5r_umr_dmabuf_update_pgsz(struct mlx5_ib_mr *mr, u32 xlt_flags,
 				 unsigned int page_shift);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0553/2077] IB/mlx5: Pull the pdn out of the depths of the umr machinery
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (551 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0552/2077] IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift() Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0554/2077] IB/mlx5: Dont mangle the mr->pd inside the rereg callback Greg Kroah-Hartman
                   ` (444 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jason Gunthorpe <jgg@nvidia.com>

[ Upstream commit f387a9f06ea4f05e607a91b161963c0b19436652 ]

Instead of getting the pdn deep inside the umr code, pass it in from the
top. to_mpd(mr->ibmr.pd)->pdn is not safe due to the rereg races, so all
the call sites need some revision to obtain the pdn in a safe way.

Mark them with mlx5_mr_pdn(); following patches will go through and remove
these.

Cases where the XLT flags are known and do not require the PDN can pass 0,
such as for mlx5_ib_dmabuf_invalidate_cb().

Also extract the DMABUF data_direct special case from inside the UMR code
and into the only place that needs it, pagefault_dmabuf_mr(). The actual
mr was created directly without using the UMR flow. Ultimately this will
be moved into mlx5_ib_init_dmabuf_mr().

Link: https://patch.msgid.link/r/6-v1-29ebd2c229b5+fd5-ib_mr_pd_jgg@nvidia.com
Assisted-by: Codex:gpt-5-5
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Stable-dep-of: 8e0a02a989c1 ("IB/mlx5: Don't mangle the mr->pd inside the rereg callback")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/mlx5_ib.h |  9 ++++
 drivers/infiniband/hw/mlx5/mr.c      |  8 +--
 drivers/infiniband/hw/mlx5/odp.c     | 12 +++--
 drivers/infiniband/hw/mlx5/umr.c     | 75 ++++++++++++++--------------
 drivers/infiniband/hw/mlx5/umr.h     |  6 +--
 5 files changed, 64 insertions(+), 46 deletions(-)

diff --git a/drivers/infiniband/hw/mlx5/mlx5_ib.h b/drivers/infiniband/hw/mlx5/mlx5_ib.h
index e156dc4d752996..0a2b8ede0d818a 100644
--- a/drivers/infiniband/hw/mlx5/mlx5_ib.h
+++ b/drivers/infiniband/hw/mlx5/mlx5_ib.h
@@ -331,6 +331,10 @@ struct mlx5_ib_flow_db {
 #define MLX5_IB_QPT_DCT		IB_QPT_RESERVED4
 #define MLX5_IB_WR_UMR		IB_WR_RESERVED1
 
+/*
+ * A valid pdn is required when flags include MLX5_IB_UPD_XLT_ENABLE,
+ * MLX5_IB_UPD_XLT_PD or MLX5_IB_UPD_XLT_ACCESS.
+ */
 #define MLX5_IB_UPD_XLT_ZAP	      BIT(0)
 #define MLX5_IB_UPD_XLT_ENABLE	      BIT(1)
 #define MLX5_IB_UPD_XLT_ATOMIC	      BIT(2)
@@ -1209,6 +1213,11 @@ static inline struct mlx5_ib_pd *to_mpd(struct ib_pd *ibpd)
 	return container_of(ibpd, struct mlx5_ib_pd, ibpd);
 }
 
+static inline u32 mlx5_mr_pdn(struct mlx5_ib_mr *mr)
+{
+	return to_mpd(mr->ibmr.pd)->pdn;
+}
+
 static inline struct mlx5_ib_srq *to_msrq(struct ib_srq *ibsrq)
 {
 	return container_of(ibsrq, struct mlx5_ib_srq, ibsrq);
diff --git a/drivers/infiniband/hw/mlx5/mr.c b/drivers/infiniband/hw/mlx5/mr.c
index f3884faf1a117c..e29f5e628312b3 100644
--- a/drivers/infiniband/hw/mlx5/mr.c
+++ b/drivers/infiniband/hw/mlx5/mr.c
@@ -781,7 +781,8 @@ static struct ib_mr *create_real_mr(struct ib_pd *pd, struct ib_umem *umem,
 		 * configured properly but left disabled. It is safe to go ahead
 		 * and configure it again via UMR while enabling it.
 		 */
-		err = mlx5r_umr_update_mr_pas(mr, MLX5_IB_UPD_XLT_ENABLE);
+		err = mlx5r_umr_update_mr_pas(mr, MLX5_IB_UPD_XLT_ENABLE,
+					      to_mpd(pd)->pdn);
 		if (err) {
 			mlx5_ib_dereg_mr(&mr->ibmr, NULL);
 			return ERR_PTR(err);
@@ -890,7 +891,8 @@ static void mlx5_ib_dmabuf_invalidate_cb(struct dma_buf_attachment *attach)
 	if (!umem_dmabuf->sgt || !mr)
 		return;
 
-	mlx5r_umr_update_mr_pas(mr, MLX5_IB_UPD_XLT_ZAP);
+	/* MLX5_IB_UPD_XLT_ZAP does not change the pdn */
+	mlx5r_umr_update_mr_pas(mr, MLX5_IB_UPD_XLT_ZAP, 0);
 	ib_umem_dmabuf_unmap_pages(umem_dmabuf);
 }
 
@@ -1141,7 +1143,7 @@ static int umr_rereg_pas(struct mlx5_ib_mr *mr, struct ib_pd *pd,
 	mr->ibmr.length = new_umem->length;
 	mr->page_shift = order_base_2(page_size);
 	mr->umem = new_umem;
-	err = mlx5r_umr_update_mr_pas(mr, upd_flags);
+	err = mlx5r_umr_update_mr_pas(mr, upd_flags, mlx5_mr_pdn(mr));
 	if (err) {
 		/*
 		 * The MR is revoked at this point so there is no issue to free
diff --git a/drivers/infiniband/hw/mlx5/odp.c b/drivers/infiniband/hw/mlx5/odp.c
index 1119ce163ea783..42235b9dd6ab18 100644
--- a/drivers/infiniband/hw/mlx5/odp.c
+++ b/drivers/infiniband/hw/mlx5/odp.c
@@ -833,12 +833,14 @@ static int pagefault_dmabuf_mr(struct mlx5_ib_mr *mr, size_t bcnt,
 			       u32 *bytes_mapped, u32 flags)
 {
 	struct ib_umem_dmabuf *umem_dmabuf = to_ib_umem_dmabuf(mr->umem);
+	struct mlx5_ib_dev *dev = mr_to_mdev(mr);
 	int access_mode = mr->data_direct ? MLX5_MKC_ACCESS_MODE_KSM :
 					    MLX5_MKC_ACCESS_MODE_MTT;
 	unsigned int old_page_shift = mr->page_shift;
 	unsigned int page_shift;
 	unsigned long page_size;
 	u32 xlt_flags = 0;
+	u32 pdn = 0;
 	int err;
 
 	if (flags & MLX5_PF_FLAGS_ENABLE)
@@ -857,8 +859,12 @@ static int pagefault_dmabuf_mr(struct mlx5_ib_mr *mr, size_t bcnt,
 		err = -EINVAL;
 	} else {
 		page_shift = order_base_2(page_size);
+		if (mr->data_direct)
+			pdn = dev->ddr.pdn;
+		else
+			pdn = mlx5_mr_pdn(mr);
 		if (page_shift != mr->page_shift && mr->dmabuf_faulted) {
-			err = mlx5r_umr_dmabuf_update_pgsz(mr, xlt_flags,
+			err = mlx5r_umr_dmabuf_update_pgsz(mr, xlt_flags, pdn,
 							   page_shift);
 		} else {
 			mr->page_shift = page_shift;
@@ -866,8 +872,8 @@ static int pagefault_dmabuf_mr(struct mlx5_ib_mr *mr, size_t bcnt,
 				err = mlx5r_umr_update_data_direct_ksm_pas(
 					mr, xlt_flags);
 			else
-				err = mlx5r_umr_update_mr_pas(mr,
-							      xlt_flags);
+				err = mlx5r_umr_update_mr_pas(mr, xlt_flags,
+							      pdn);
 		}
 	}
 	dma_resv_unlock(umem_dmabuf->attach->dmabuf->resv);
diff --git a/drivers/infiniband/hw/mlx5/umr.c b/drivers/infiniband/hw/mlx5/umr.c
index f0ba8d91f81d16..f3f428f5e1b663 100644
--- a/drivers/infiniband/hw/mlx5/umr.c
+++ b/drivers/infiniband/hw/mlx5/umr.c
@@ -603,11 +603,11 @@ mlx5r_umr_set_update_xlt_ctrl_seg(struct mlx5_wqe_umr_ctrl_seg *ctrl_seg,
 
 static void mlx5r_umr_set_update_xlt_mkey_seg(struct mlx5_ib_dev *dev,
 					      struct mlx5_mkey_seg *mkey_seg,
-					      struct mlx5_ib_mr *mr,
+					      struct mlx5_ib_mr *mr, u32 pdn,
 					      unsigned int page_shift)
 {
 	mlx5r_umr_set_access_flags(dev, mkey_seg, mr->access_flags);
-	MLX5_SET(mkc, mkey_seg, pd, to_mpd(mr->ibmr.pd)->pdn);
+	MLX5_SET(mkc, mkey_seg, pd, pdn);
 	MLX5_SET64(mkc, mkey_seg, start_addr, mr->ibmr.iova);
 	MLX5_SET64(mkc, mkey_seg, len, mr->ibmr.length);
 	MLX5_SET(mkc, mkey_seg, log_page_size, page_shift);
@@ -670,23 +670,22 @@ static void mlx5r_umr_final_update_xlt(struct mlx5_ib_dev *dev,
 	wqe->data_seg.byte_count = cpu_to_be32(sg->length);
 }
 
-static void
-_mlx5r_umr_init_wqe(struct mlx5_ib_mr *mr, struct mlx5r_umr_wqe *wqe,
-		    struct ib_sge *sg, unsigned int flags,
-		    unsigned int page_shift, bool dd)
+static void _mlx5r_umr_init_wqe(struct mlx5_ib_mr *mr,
+				struct mlx5r_umr_wqe *wqe, struct ib_sge *sg,
+				unsigned int flags, u32 pdn,
+				unsigned int page_shift)
 {
 	struct mlx5_ib_dev *dev = mr_to_mdev(mr);
 
 	mlx5r_umr_set_update_xlt_ctrl_seg(&wqe->ctrl_seg, flags, sg);
-	mlx5r_umr_set_update_xlt_mkey_seg(dev, &wqe->mkey_seg, mr, page_shift);
-	if (dd) /* Use the data direct internal kernel PD */
-		MLX5_SET(mkc, &wqe->mkey_seg, pd, dev->ddr.pdn);
+	mlx5r_umr_set_update_xlt_mkey_seg(dev, &wqe->mkey_seg, mr, pdn,
+					  page_shift);
 	mlx5r_umr_set_update_xlt_data_seg(&wqe->data_seg, sg);
 }
 
-static int
-_mlx5r_umr_update_mr_pas(struct mlx5_ib_mr *mr, unsigned int flags, bool dd,
-			 size_t start_block, size_t nblocks)
+static int _mlx5r_umr_update_mr_pas(struct mlx5_ib_mr *mr, unsigned int flags,
+				    u32 pdn, bool dd, size_t start_block,
+				    size_t nblocks)
 {
 	size_t ent_size = dd ? sizeof(struct mlx5_ksm) : sizeof(struct mlx5_mtt);
 	struct mlx5_ib_dev *dev = mr_to_mdev(mr);
@@ -720,7 +719,7 @@ _mlx5r_umr_update_mr_pas(struct mlx5_ib_mr *mr, unsigned int flags, bool dd,
 
 	orig_sg_length = sg.length;
 
-	_mlx5r_umr_init_wqe(mr, &wqe, &sg, flags, mr->page_shift, dd);
+	_mlx5r_umr_init_wqe(mr, &wqe, &sg, flags, pdn, mr->page_shift);
 
 	/* Set initial translation offset to start_block */
 	offset = (u64)start_block * ent_size;
@@ -811,7 +810,8 @@ int mlx5r_umr_update_data_direct_ksm_pas_range(struct mlx5_ib_mr *mr,
 	    !(flags & MLX5_IB_UPD_XLT_KEEP_PGSZ)))
 		return -EINVAL;
 
-	return _mlx5r_umr_update_mr_pas(mr, flags, true, start_block, nblocks);
+	return _mlx5r_umr_update_mr_pas(mr, flags, mr_to_mdev(mr)->ddr.pdn,
+					true, start_block, nblocks);
 }
 
 int mlx5r_umr_update_data_direct_ksm_pas(struct mlx5_ib_mr *mr,
@@ -821,12 +821,13 @@ int mlx5r_umr_update_data_direct_ksm_pas(struct mlx5_ib_mr *mr,
 }
 
 int mlx5r_umr_update_mr_pas_range(struct mlx5_ib_mr *mr, unsigned int flags,
-				  size_t start_block, size_t nblocks)
+				  u32 pdn, size_t start_block, size_t nblocks)
 {
 	if (WARN_ON(mr->umem->is_odp))
 		return -EINVAL;
 
-	return _mlx5r_umr_update_mr_pas(mr, flags, false, start_block, nblocks);
+	return _mlx5r_umr_update_mr_pas(mr, flags, pdn, false, start_block,
+					nblocks);
 }
 
 /*
@@ -834,9 +835,9 @@ int mlx5r_umr_update_mr_pas_range(struct mlx5_ib_mr *mr, unsigned int flags,
  * Dmabuf MR is handled in a similar way, except that the MLX5_IB_UPD_XLT_ZAP
  * flag may be used.
  */
-int mlx5r_umr_update_mr_pas(struct mlx5_ib_mr *mr, unsigned int flags)
+int mlx5r_umr_update_mr_pas(struct mlx5_ib_mr *mr, unsigned int flags, u32 pdn)
 {
-	return mlx5r_umr_update_mr_pas_range(mr, flags, 0, 0);
+	return mlx5r_umr_update_mr_pas_range(mr, flags, pdn, 0, 0);
 }
 
 static bool umr_can_use_indirect_mkey(struct mlx5_ib_dev *dev)
@@ -861,6 +862,7 @@ int mlx5r_umr_update_xlt(struct mlx5_ib_mr *mr, u64 idx, int npages,
 	size_t orig_sg_length;
 	size_t pages_iter;
 	struct ib_sge sg;
+	u32 pdn = mlx5_mr_pdn(mr);
 	int err = 0;
 	void *xlt;
 
@@ -895,7 +897,8 @@ int mlx5r_umr_update_xlt(struct mlx5_ib_mr *mr, u64 idx, int npages,
 	}
 
 	mlx5r_umr_set_update_xlt_ctrl_seg(&wqe.ctrl_seg, flags, &sg);
-	mlx5r_umr_set_update_xlt_mkey_seg(dev, &wqe.mkey_seg, mr, page_shift);
+	mlx5r_umr_set_update_xlt_mkey_seg(dev, &wqe.mkey_seg, mr, pdn,
+					  page_shift);
 	mlx5r_umr_set_update_xlt_data_seg(&wqe.data_seg, &sg);
 
 	for (pages_mapped = 0;
@@ -962,17 +965,18 @@ int mlx5r_umr_update_mr_page_shift(struct mlx5_ib_mr *mr,
 	return err;
 }
 
-static inline int
-_mlx5r_dmabuf_umr_update_pas(struct mlx5_ib_mr *mr, unsigned int flags,
-			     size_t start_block, size_t nblocks, bool dd)
+static inline int _mlx5r_dmabuf_umr_update_pas(struct mlx5_ib_mr *mr,
+					       unsigned int flags, u32 pdn,
+					       size_t start_block,
+					       size_t nblocks, bool dd)
 {
 	if (dd)
 		return mlx5r_umr_update_data_direct_ksm_pas_range(mr, flags,
 								  start_block,
 								  nblocks);
 	else
-		return mlx5r_umr_update_mr_pas_range(mr, flags, start_block,
-						     nblocks);
+		return mlx5r_umr_update_mr_pas_range(mr, flags, pdn,
+						     start_block, nblocks);
 }
 
 /**
@@ -986,11 +990,9 @@ _mlx5r_dmabuf_umr_update_pas(struct mlx5_ib_mr *mr, unsigned int flags,
  * Return: On success, returns the number of entries that were zapped.
  *         On error, returns a negative error code.
  */
-static int _mlx5r_umr_zap_mkey(struct mlx5_ib_mr *mr,
-			       unsigned int flags,
-			       unsigned int page_shift,
-			       size_t *nblocks,
-			       bool dd)
+static int _mlx5r_umr_zap_mkey(struct mlx5_ib_mr *mr, unsigned int flags,
+			       unsigned int page_shift, size_t *nblocks,
+			       u32 pdn, bool dd)
 {
 	unsigned int old_page_shift = mr->page_shift;
 	struct mlx5_ib_dev *dev = mr_to_mdev(mr);
@@ -1030,7 +1032,7 @@ static int _mlx5r_umr_zap_mkey(struct mlx5_ib_mr *mr,
 	 */
 	if (*nblocks)
 		mr->page_shift = max_page_shift;
-	err = _mlx5r_dmabuf_umr_update_pas(mr, flags, 0, *nblocks, dd);
+	err = _mlx5r_dmabuf_umr_update_pas(mr, flags, pdn, 0, *nblocks, dd);
 	if (err) {
 		mr->page_shift = old_page_shift;
 		return err;
@@ -1055,6 +1057,7 @@ static int _mlx5r_umr_zap_mkey(struct mlx5_ib_mr *mr,
  * entries accordingly
  * @mr:        The memory region to update
  * @xlt_flags: Translation table update flags
+ * @pdn:       Protection domain number
  * @page_shift: The new (optimized) page shift to use
  *
  * This function updates the page size and mkey translation entries for a DMABUF
@@ -1074,7 +1077,7 @@ static int _mlx5r_umr_zap_mkey(struct mlx5_ib_mr *mr,
  *
  * Returns 0 on success or a negative error code on failure.
  */
-int mlx5r_umr_dmabuf_update_pgsz(struct mlx5_ib_mr *mr, u32 xlt_flags,
+int mlx5r_umr_dmabuf_update_pgsz(struct mlx5_ib_mr *mr, u32 xlt_flags, u32 pdn,
 				 unsigned int page_shift)
 {
 	unsigned int old_page_shift = mr->page_shift;
@@ -1083,7 +1086,7 @@ int mlx5r_umr_dmabuf_update_pgsz(struct mlx5_ib_mr *mr, u32 xlt_flags,
 	int err;
 
 	err = _mlx5r_umr_zap_mkey(mr, xlt_flags, page_shift, &zapped_blocks,
-				  mr->data_direct);
+				  pdn, mr->data_direct);
 	if (err)
 		return err;
 
@@ -1096,10 +1099,8 @@ int mlx5r_umr_dmabuf_update_pgsz(struct mlx5_ib_mr *mr, u32 xlt_flags,
 		 * the page size in the mkey yet.
 		 */
 		err = _mlx5r_dmabuf_umr_update_pas(
-			mr,
-			xlt_flags | MLX5_IB_UPD_XLT_KEEP_PGSZ,
-			zapped_blocks,
-			total_blocks - zapped_blocks,
+			mr, xlt_flags | MLX5_IB_UPD_XLT_KEEP_PGSZ, pdn,
+			zapped_blocks, total_blocks - zapped_blocks,
 			mr->data_direct);
 		if (err)
 			goto err;
@@ -1108,7 +1109,7 @@ int mlx5r_umr_dmabuf_update_pgsz(struct mlx5_ib_mr *mr, u32 xlt_flags,
 	err = mlx5r_umr_update_mr_page_shift(mr, mr->page_shift);
 	if (err)
 		goto err;
-	err = _mlx5r_dmabuf_umr_update_pas(mr, xlt_flags, 0, zapped_blocks,
+	err = _mlx5r_dmabuf_umr_update_pas(mr, xlt_flags, pdn, 0, zapped_blocks,
 					   mr->data_direct);
 	if (err)
 		goto err;
diff --git a/drivers/infiniband/hw/mlx5/umr.h b/drivers/infiniband/hw/mlx5/umr.h
index 59809d4d7d7297..99192ec67957c7 100644
--- a/drivers/infiniband/hw/mlx5/umr.h
+++ b/drivers/infiniband/hw/mlx5/umr.h
@@ -101,13 +101,13 @@ int mlx5r_umr_update_data_direct_ksm_pas_range(struct mlx5_ib_mr *mr,
 					       size_t nblocks);
 int mlx5r_umr_update_data_direct_ksm_pas(struct mlx5_ib_mr *mr, unsigned int flags);
 int mlx5r_umr_update_mr_pas_range(struct mlx5_ib_mr *mr, unsigned int flags,
-				  size_t start_block, size_t nblocks);
-int mlx5r_umr_update_mr_pas(struct mlx5_ib_mr *mr, unsigned int flags);
+				  u32 pdn, size_t start_block, size_t nblocks);
+int mlx5r_umr_update_mr_pas(struct mlx5_ib_mr *mr, unsigned int flags, u32 pdn);
 int mlx5r_umr_update_xlt(struct mlx5_ib_mr *mr, u64 idx, int npages,
 			 int page_shift, int flags);
 int mlx5r_umr_update_mr_page_shift(struct mlx5_ib_mr *mr,
 				   unsigned int page_shift);
-int mlx5r_umr_dmabuf_update_pgsz(struct mlx5_ib_mr *mr, u32 xlt_flags,
+int mlx5r_umr_dmabuf_update_pgsz(struct mlx5_ib_mr *mr, u32 xlt_flags, u32 pdn,
 				 unsigned int page_shift);
 
 #endif /* _MLX5_IB_UMR_H */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0554/2077] IB/mlx5: Dont mangle the mr->pd inside the rereg callback
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (552 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0553/2077] IB/mlx5: Pull the pdn out of the depths of the umr machinery Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0555/2077] spi: ep93xx: fix double-free of zeropage on DMA setup failure Greg Kroah-Hartman
                   ` (443 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jason Gunthorpe <jgg@nvidia.com>

[ Upstream commit 8e0a02a989c156ce17f06a645d5f075277e06b95 ]

The rereg protocol expects the core code to change mr->pd and synchronize
that change with the atomics and syncs. The driver should not touch it.

mlx5 needed to update it in umr_rereg_pas() because
mlx5r_umr_update_mr_pas() required the updated mr->pd to build the
UMR.

Simply switch mlx5r_umr_update_mr_pas() to use the pdn directly from
the new pd and remove the mr->pd update.

Fixes: 56e11d628c5d ("IB/mlx5: Added support for re-registration of MRs")
Link: https://patch.msgid.link/r/7-v1-29ebd2c229b5+fd5-ib_mr_pd_jgg@nvidia.com
Assisted-by: Codex:gpt-5-5
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/mr.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

diff --git a/drivers/infiniband/hw/mlx5/mr.c b/drivers/infiniband/hw/mlx5/mr.c
index e29f5e628312b3..41ca3b1a6db079 100644
--- a/drivers/infiniband/hw/mlx5/mr.c
+++ b/drivers/infiniband/hw/mlx5/mr.c
@@ -1130,10 +1130,8 @@ static int umr_rereg_pas(struct mlx5_ib_mr *mr, struct ib_pd *pd,
 	if (err)
 		return err;
 
-	if (flags & IB_MR_REREG_PD) {
-		mr->ibmr.pd = pd;
+	if (flags & IB_MR_REREG_PD)
 		upd_flags |= MLX5_IB_UPD_XLT_PD;
-	}
 	if (flags & IB_MR_REREG_ACCESS) {
 		mr->access_flags = access_flags;
 		upd_flags |= MLX5_IB_UPD_XLT_ACCESS;
@@ -1143,7 +1141,7 @@ static int umr_rereg_pas(struct mlx5_ib_mr *mr, struct ib_pd *pd,
 	mr->ibmr.length = new_umem->length;
 	mr->page_shift = order_base_2(page_size);
 	mr->umem = new_umem;
-	err = mlx5r_umr_update_mr_pas(mr, upd_flags, mlx5_mr_pdn(mr));
+	err = mlx5r_umr_update_mr_pas(mr, upd_flags, to_mpd(pd)->pdn);
 	if (err) {
 		/*
 		 * The MR is revoked at this point so there is no issue to free
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0555/2077] spi: ep93xx: fix double-free of zeropage on DMA setup failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (553 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0554/2077] IB/mlx5: Dont mangle the mr->pd inside the rereg callback Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0556/2077] ASoC: amd: acp-sdw-legacy: Bound DAI link iteration Greg Kroah-Hartman
                   ` (442 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit 7886054b06f762f62054957a8f6de0f14e6b7541 ]

If DMA setup fails after allocating the zeropage, the error path frees
the page but leaves espi->zeropage dangling. A subsequent call to
ep93xx_spi_release_dma() sees the non-NULL pointer and frees the page
again.

Clear the pointer after freeing in the error path of
ep93xx_spi_setup_dma().

Fixes: 626a96db1169 ("spi/ep93xx: add DMA support")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Link: https://patch.msgid.link/20260529-ep93xx-v1-1-9185070ca1fc@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/spi/spi-ep93xx.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/spi/spi-ep93xx.c b/drivers/spi/spi-ep93xx.c
index f716c9607be4af..4cab0d97a68afc 100644
--- a/drivers/spi/spi-ep93xx.c
+++ b/drivers/spi/spi-ep93xx.c
@@ -600,6 +600,7 @@ static int ep93xx_spi_setup_dma(struct device *dev, struct ep93xx_spi *espi)
 	espi->dma_rx = NULL;
 fail_free_page:
 	free_page((unsigned long)espi->zeropage);
+	espi->zeropage = NULL;
 
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0556/2077] ASoC: amd: acp-sdw-legacy: Bound DAI link iteration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (554 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0555/2077] spi: ep93xx: fix double-free of zeropage on DMA setup failure Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0557/2077] ASoC: amd: acp-sdw-sof: " Greg Kroah-Hartman
                   ` (441 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Aaron Ma, Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aaron Ma <aaron.ma@canonical.com>

[ Upstream commit d49ecdf327cc91062d2f80996a163cf65fda1e60 ]

create_sdw_dailinks() walks soc_dais until it finds an entry with
initialised cleared, but soc_dais is allocated with exactly num_ends
entries. If all entries are initialised, the loop reads past the end of
the array.

This was reported by KASAN:

  BUG: KASAN: slab-out-of-bounds in mc_probe+0x26b3/0x2774 [snd_acp_sdw_legacy_mach]
  Read of size 1

Pass the allocated entry count to create_sdw_dailinks() and stop before
reading past the array.

Fixes: 2981d9b0789c ("ASoC: amd: acp: add soundwire machine driver for legacy stack")
Signed-off-by: Aaron Ma <aaron.ma@canonical.com>
Link: https://patch.msgid.link/20260528082110.915549-1-aaron.ma@canonical.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/amd/acp/acp-sdw-legacy-mach.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/sound/soc/amd/acp/acp-sdw-legacy-mach.c b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
index 09b475c83c4966..e8b6819cc4b459 100644
--- a/sound/soc/amd/acp/acp-sdw-legacy-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
@@ -303,13 +303,14 @@ static int create_sdw_dailink(struct snd_soc_card *card,
 
 static int create_sdw_dailinks(struct snd_soc_card *card,
 			       struct snd_soc_dai_link **dai_links, int *be_id,
-			       struct asoc_sdw_dailink *soc_dais,
+			       struct asoc_sdw_dailink *soc_dais, int num_dais,
 			       struct snd_soc_codec_conf **codec_conf)
 {
 	struct device *dev = card->dev;
 	struct asoc_sdw_mc_private *ctx = snd_soc_card_get_drvdata(card);
 	struct amd_mc_ctx *amd_ctx = (struct amd_mc_ctx *)ctx->private;
 	struct snd_soc_dai_link_component *sdw_platform_component;
+	int i;
 	int ret;
 
 	sdw_platform_component = devm_kzalloc(dev, sizeof(struct snd_soc_dai_link_component),
@@ -329,7 +330,7 @@ static int create_sdw_dailinks(struct snd_soc_card *card,
 	}
 
 	/* generate DAI links by each sdw link */
-	while (soc_dais->initialised) {
+	for (i = 0; i < num_dais && soc_dais->initialised; i++) {
 		int current_be_id = 0;
 
 		ret = create_sdw_dailink(card, soc_dais, dai_links,
@@ -463,7 +464,7 @@ static int soc_card_dai_links_create(struct snd_soc_card *card)
 	/* SDW */
 	if (sdw_be_num) {
 		ret = create_sdw_dailinks(card, &dai_links, &be_id,
-					  soc_dais, &codec_conf);
+					  soc_dais, num_ends, &codec_conf);
 		if (ret)
 			return ret;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0557/2077] ASoC: amd: acp-sdw-sof: Bound DAI link iteration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (555 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0556/2077] ASoC: amd: acp-sdw-legacy: Bound DAI link iteration Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0558/2077] firmware_loader: Fix recursive lock in device_cache_fw_images() Greg Kroah-Hartman
                   ` (440 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Aaron Ma, Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aaron Ma <aaron.ma@canonical.com>

[ Upstream commit 4d992e63f52d58f52b724606c60ae7b37a1c582f ]

create_sdw_dailinks() walks sof_dais until it finds an entry with
initialised cleared, but sof_dais is allocated with exactly num_ends
entries. If all entries are initialised, the loop reads past the end of
the array.

Pass the allocated entry count to create_sdw_dailinks() and stop before
reading past the array.

Fixes: 6d8348ddc56e ("ASoC: amd: acp: refactor SoundWire machine driver code")
Signed-off-by: Aaron Ma <aaron.ma@canonical.com>
Link: https://patch.msgid.link/20260528082110.915549-2-aaron.ma@canonical.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/amd/acp/acp-sdw-sof-mach.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/sound/soc/amd/acp/acp-sdw-sof-mach.c b/sound/soc/amd/acp/acp-sdw-sof-mach.c
index a0fd8a6f997088..a423853f3a97d8 100644
--- a/sound/soc/amd/acp/acp-sdw-sof-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-sof-mach.c
@@ -220,13 +220,14 @@ static int create_sdw_dailink(struct snd_soc_card *card,
 
 static int create_sdw_dailinks(struct snd_soc_card *card,
 			       struct snd_soc_dai_link **dai_links, int *be_id,
-			       struct asoc_sdw_dailink *sof_dais,
+			       struct asoc_sdw_dailink *sof_dais, int num_dais,
 			       struct snd_soc_codec_conf **codec_conf)
 {
+	int i;
 	int ret;
 
 	/* generate DAI links by each sdw link */
-	while (sof_dais->initialised) {
+	for (i = 0; i < num_dais && sof_dais->initialised; i++) {
 		int current_be_id = 0;
 
 		ret = create_sdw_dailink(card, sof_dais, dai_links,
@@ -334,7 +335,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
 	/* SDW */
 	if (sdw_be_num) {
 		ret = create_sdw_dailinks(card, &dai_links, &be_id,
-					  sof_dais, &codec_conf);
+					  sof_dais, num_ends, &codec_conf);
 		if (ret)
 			return ret;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0558/2077] firmware_loader: Fix recursive lock in device_cache_fw_images()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (556 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0557/2077] ASoC: amd: acp-sdw-sof: " Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0559/2077] configfs: fix lockless traversals of ->s_children Greg Kroah-Hartman
                   ` (439 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+e70e4c6f6eee43357ba7,
	Dmitry Vyukov, Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dmitry Vyukov <dvyukov@google.com>

[ Upstream commit d3ec78f8f8d48a04a9fac38d47275c34645e5103 ]

A recursive locking deadlock can occur in the firmware loader's power
management notification handler.

During system suspend or hibernation preparation, fw_pm_notify() calls
device_cache_fw_images(). This function acquires fw_lock to set the
firmware cache state to FW_LOADER_START_CACHE and then iterates over all
devices using dpm_for_each_dev() while still holding the lock.

For each device, dev_cache_fw_image() schedules asynchronous work to cache
the firmware. If memory allocation for the async work entry fails (e.g., in
out-of-memory conditions), async_schedule_node_domain() falls back to
executing the work function synchronously in the current thread.

The synchronous execution path (__async_dev_cache_fw_image() ->
cache_firmware() -> request_firmware() -> assign_fw()) attempts to acquire
fw_lock again. Since the current thread already holds fw_lock, this results
in a recursive locking deadlock.

Fix this by releasing fw_lock immediately after updating the cache state
and before calling dpm_for_each_dev(). The lock is only needed to protect
the state update. Concurrent firmware requests will correctly see the
FW_LOADER_START_CACHE state and use the piggyback mechanism, which is
independently protected by its own fwc->name_lock.

Fixes: ac39b3ea73aa ("firmware loader: let caching firmware piggyback on loading firmware")
Assisted-by: Gemini:gemini-3.1-pro-preview Gemini:gemini-3-flash-preview syzbot
Reported-by: syzbot+e70e4c6f6eee43357ba7@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=e70e4c6f6eee43357ba7
Link: https://syzkaller.appspot.com/ai_job?id=8b4af9fd-24af-423f-8acb-1159fd34c1a5
Signed-off-by: Dmitry Vyukov <dvyukov@google.com>
Link: https://patch.msgid.link/48b092a5-f49d-48a4-95f4-f65bebfc6bc3@mail.kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/base/firmware_loader/main.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/base/firmware_loader/main.c b/drivers/base/firmware_loader/main.c
index a11b30dda23be5..c96312ac2be7bf 100644
--- a/drivers/base/firmware_loader/main.c
+++ b/drivers/base/firmware_loader/main.c
@@ -1503,9 +1503,10 @@ static void device_cache_fw_images(void)
 
 	mutex_lock(&fw_lock);
 	fwc->state = FW_LOADER_START_CACHE;
-	dpm_for_each_dev(NULL, dev_cache_fw_image);
 	mutex_unlock(&fw_lock);
 
+	dpm_for_each_dev(NULL, dev_cache_fw_image);
+
 	/* wait for completion of caching firmware for all devices */
 	async_synchronize_full_domain(&fw_cache_domain);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0559/2077] configfs: fix lockless traversals of ->s_children
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (557 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0558/2077] firmware_loader: Fix recursive lock in device_cache_fw_images() Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0560/2077] watchdog: unregister PM notifier on watchdog unregister Greg Kroah-Hartman
                   ` (438 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jan Kara, Al Viro, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Al Viro <viro@zeniv.linux.org.uk>

[ Upstream commit 9b9e8bb81c41fd27e7b57a1c936fde140548535f ]

Having the parent directory locked protects entries from removal
by another thread, but it does *not* protect cursors from being
moved around by lseek() - or freed, for that matter.

Fixes: 6f6107640625 ("configfs: Introduce configfs_dirent_lock")
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/configfs/dir.c | 54 +++++++++++++++++++++++++++++++++++------------
 1 file changed, 41 insertions(+), 13 deletions(-)

diff --git a/fs/configfs/dir.c b/fs/configfs/dir.c
index e84483a0836d8e..eb991b2a9c341f 100644
--- a/fs/configfs/dir.c
+++ b/fs/configfs/dir.c
@@ -235,15 +235,16 @@ static int configfs_dirent_exists(struct dentry *dentry)
 	const unsigned char *new = dentry->d_name.name;
 	struct configfs_dirent *sd;
 
+	spin_lock(&configfs_dirent_lock);
 	list_for_each_entry(sd, &parent_sd->s_children, s_sibling) {
 		if (sd->s_element) {
-			const unsigned char *existing = configfs_get_name(sd);
-			if (strcmp(existing, new))
-				continue;
-			else
+			if (strcmp(configfs_get_name(sd), new) == 0) {
+				spin_unlock(&configfs_dirent_lock);
 				return -EEXIST;
+			}
 		}
 	}
+	spin_unlock(&configfs_dirent_lock);
 
 	return 0;
 }
@@ -575,11 +576,28 @@ static void configfs_detach_rollback(struct dentry *dentry)
 			configfs_detach_rollback(sd->s_dentry);
 }
 
+/*
+ * Find the next non-cursor.  configfs_dirent_lock held by caller.
+ */
+static struct configfs_dirent *next_dirent(struct configfs_dirent *parent,
+					   struct configfs_dirent *last)
+{
+	struct configfs_dirent *s;
+
+	s = list_prepare_entry(last, &parent->s_children, s_sibling);
+
+	list_for_each_entry_continue(s, &parent->s_children, s_sibling) {
+		if (s->s_element)
+			return s;
+	}
+	return NULL;
+}
+
 static void detach_attrs(struct config_item * item)
 {
 	struct dentry * dentry = dget(item->ci_dentry);
-	struct configfs_dirent * parent_sd;
-	struct configfs_dirent * sd, * tmp;
+	struct configfs_dirent *parent_sd;
+	struct configfs_dirent *sd, *next;
 
 	if (!dentry)
 		return;
@@ -588,15 +606,19 @@ static void detach_attrs(struct config_item * item)
 		 dentry->d_name.name);
 
 	parent_sd = dentry->d_fsdata;
-	list_for_each_entry_safe(sd, tmp, &parent_sd->s_children, s_sibling) {
-		if (!sd->s_element || !(sd->s_type & CONFIGFS_NOT_PINNED))
+
+	spin_lock(&configfs_dirent_lock);
+	for (sd = next_dirent(parent_sd, NULL); sd; sd = next) {
+		next = next_dirent(parent_sd, sd);
+		if (!(sd->s_type & CONFIGFS_NOT_PINNED))
 			continue;
-		spin_lock(&configfs_dirent_lock);
 		list_del_init(&sd->s_sibling);
 		spin_unlock(&configfs_dirent_lock);
 		configfs_drop_dentry(sd, dentry);
 		configfs_put(sd);
+		spin_lock(&configfs_dirent_lock);
 	}
+	spin_unlock(&configfs_dirent_lock);
 
 	/**
 	 * Drop reference from dget() on entrance.
@@ -655,18 +677,20 @@ static void detach_groups(struct config_group *group)
 	struct dentry * dentry = dget(group->cg_item.ci_dentry);
 	struct dentry *child;
 	struct configfs_dirent *parent_sd;
-	struct configfs_dirent *sd, *tmp;
+	struct configfs_dirent *sd, *next;
 
 	if (!dentry)
 		return;
 
 	parent_sd = dentry->d_fsdata;
-	list_for_each_entry_safe(sd, tmp, &parent_sd->s_children, s_sibling) {
-		if (!sd->s_element ||
-		    !(sd->s_type & CONFIGFS_USET_DEFAULT))
+	spin_lock(&configfs_dirent_lock);
+	for (sd = next_dirent(parent_sd, NULL); sd; sd = next) {
+		next = next_dirent(parent_sd, sd);
+		if (!(sd->s_type & CONFIGFS_USET_DEFAULT))
 			continue;
 
 		child = sd->s_dentry;
+		spin_unlock(&configfs_dirent_lock);
 
 		inode_lock(d_inode(child));
 
@@ -678,7 +702,9 @@ static void detach_groups(struct config_group *group)
 
 		d_delete(child);
 		dput(child);
+		spin_lock(&configfs_dirent_lock);
 	}
+	spin_unlock(&configfs_dirent_lock);
 
 	/**
 	 * Drop reference from dget() on entrance.
@@ -1130,6 +1156,7 @@ configfs_find_subsys_dentry(struct configfs_dirent *root_sd,
 	struct configfs_dirent *p;
 	struct configfs_dirent *ret = NULL;
 
+	spin_lock(&configfs_dirent_lock);
 	list_for_each_entry(p, &root_sd->s_children, s_sibling) {
 		if (p->s_type & CONFIGFS_DIR &&
 		    p->s_element == subsys_item) {
@@ -1137,6 +1164,7 @@ configfs_find_subsys_dentry(struct configfs_dirent *root_sd,
 			break;
 		}
 	}
+	spin_unlock(&configfs_dirent_lock);
 
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0560/2077] watchdog: unregister PM notifier on watchdog unregister
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (558 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0559/2077] configfs: fix lockless traversals of ->s_children Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0561/2077] pinctrl: qcom: Fix resolving register base address from device node Greg Kroah-Hartman
                   ` (437 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Guenter Roeck,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yuho Choi <dbgh9129@gmail.com>

[ Upstream commit a298c7302ee9584a7a1ac1e8acbede8d98ab51a4 ]

watchdog_register_device() registers wdd->pm_nb when
WDOG_NO_PING_ON_SUSPEND is set, but watchdog_unregister_device() does not
remove it. This leaves an embedded notifier block on the PM notifier chain
after the watchdog device has been unregistered.

A later suspend/resume notification can then call watchdog_pm_notifier()
with a stale watchdog_device pointer, or at minimum after wdd->wd_data has
been cleared by watchdog_dev_unregister().

Unregister the PM notifier before tearing down the watchdog device.

Fixes: 60bcd91aafd2 ("watchdog: introduce watchdog_dev_suspend/resume")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Link: https://lore.kernel.org/r/20260601192005.1970805-1-dbgh9129@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/watchdog/watchdog_core.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/watchdog/watchdog_core.c b/drivers/watchdog/watchdog_core.c
index 8300520688d079..6c087b4ef5dd52 100644
--- a/drivers/watchdog/watchdog_core.c
+++ b/drivers/watchdog/watchdog_core.c
@@ -391,6 +391,9 @@ static void __watchdog_unregister_device(struct watchdog_device *wdd)
 	if (test_bit(WDOG_STOP_ON_REBOOT, &wdd->status))
 		unregister_reboot_notifier(&wdd->reboot_nb);
 
+	if (test_bit(WDOG_NO_PING_ON_SUSPEND, &wdd->status))
+		unregister_pm_notifier(&wdd->pm_nb);
+
 	watchdog_dev_unregister(wdd);
 	ida_free(&watchdog_ida, wdd->id);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0561/2077] pinctrl: qcom: Fix resolving register base address from device node
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (559 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0560/2077] watchdog: unregister PM notifier on watchdog unregister Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0562/2077] scsi: target: Fix hexadecimal CHAP_I handling Greg Kroah-Hartman
                   ` (436 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sneh Mankad, Dmitry Baryshkov,
	Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sneh Mankad <sneh.mankad@oss.qualcomm.com>

[ Upstream commit 4e31ab47997540d0ff4c9de801741bed03c1ab3f ]

Commit 56ffb63749f4 ("pinctrl: qcom: add multi TLMM region option parameter")
added reg-names property based register reading. However multiple platforms
are not using the reg-names as they have only single TLMM register region.

Commit tried to handle this using the default_region module parameter,
however this condition is unreachable as the error return precedes it by
just checking if reg-names property exists or not, making it impossible
to use tlmm-test for the SoCs (x1e80100) which don't have reg-names
property in TLMM device.

Fix this by moving the default_region check at the start of the
tlmm_reg_base().

Fixes: 56ffb63749f4 ("pinctrl: qcom: add multi TLMM region option parameter")
Signed-off-by: Sneh Mankad <sneh.mankad@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/qcom/tlmm-test.c | 19 +++++++++----------
 1 file changed, 9 insertions(+), 10 deletions(-)

diff --git a/drivers/pinctrl/qcom/tlmm-test.c b/drivers/pinctrl/qcom/tlmm-test.c
index 7d7fff538755a2..4ac96538a417fc 100644
--- a/drivers/pinctrl/qcom/tlmm-test.c
+++ b/drivers/pinctrl/qcom/tlmm-test.c
@@ -581,6 +581,9 @@ static int tlmm_reg_base(struct device_node *tlmm, struct resource *res)
 	int ret;
 	int i;
 
+	if (!strcmp(tlmm_reg_name, "default_region"))
+		return of_address_to_resource(tlmm, 0, res);
+
 	count = of_property_count_strings(tlmm, "reg-names");
 	if (count <= 0) {
 		pr_err("failed to find tlmm reg name\n");
@@ -597,18 +600,14 @@ static int tlmm_reg_base(struct device_node *tlmm, struct resource *res)
 		return -EINVAL;
 	}
 
-	if (!strcmp(tlmm_reg_name, "default_region")) {
-		ret = of_address_to_resource(tlmm, 0, res);
-	} else {
-		for (i = 0; i < count; i++) {
-			if (!strcmp(reg_names[i], tlmm_reg_name)) {
-				ret = of_address_to_resource(tlmm, i, res);
-				break;
-			}
+	for (i = 0; i < count; i++) {
+		if (!strcmp(reg_names[i], tlmm_reg_name)) {
+			ret = of_address_to_resource(tlmm, i, res);
+			break;
 		}
-		if (i == count)
-			ret = -EINVAL;
 	}
+	if (i == count)
+		ret = -EINVAL;
 
 	kfree(reg_names);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0562/2077] scsi: target: Fix hexadecimal CHAP_I handling
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (560 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0561/2077] pinctrl: qcom: Fix resolving register base address from device node Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0563/2077] scsi: ufs: core: Handle PM commands timeout before SCSI EH Greg Kroah-Hartman
                   ` (435 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Disseldorp, Lee Duncan,
	John Garry, Martin K. Petersen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Disseldorp <ddiss@suse.de>

[ Upstream commit 7e161211f1dd5288b4ea802b30e70ef919ebc3da ]

A mutual CHAP handshake requires target processing of an initiator-sent
CHAP_I identifier. The RFC 3720 specification states:

  11.1.4.  Challenge Handshake Authentication Protocol (CHAP)
  ...
  CHAP_A=<A> CHAP_I=<I> CHAP_C=<C>
  ...
  Where N, (A,A1,A2), I, C, and R are (correspondingly) the Name,
  Algorithm, Identifier, Challenge, and Response as defined in
  [RFC1994], N is a text string, A,A1,A2, and I are numbers

CHAP_I parsing currently calls extract_param(), which returns the
@identifier string (stripped of any 0b/0B or 0x/0X prefix) and a @type
which indicates DECIMAL, HEX, or BASE64 encoding (based on any stripped
prefix).

Any HEX encoded CHAP_I string is further processed via:

  ret = kstrtoul(&identifier[2], 0, &id);

This is incorrect for two reasons:

 * The @identifier string has already been stripped of the 0x/0X prefix,
   so skipping the first two bytes omits part of the number.

 * The kstrtoul() call specifies a base of 0, which will see
   &identifier[2] parsed as a decimal, unless a '0x' or (octal) '0' is
   erroneously present at that offset.

Fix this by passing the (zero-offset) identifier string to kstrtoul()
along with a base=16 parameter. Also add an explicit error handler for
BASE64 encoding.

Hex-encoded CHAP_I handling can be testing using the libiscsi EncodedI
test linked below.

Reported-by: Sashiko (gemini/gemini-3.1-pro-preview)
Link: https://sashiko.dev/#/patchset/20260521151121.808477-1-hossu.alexandru%40gmail.com
Link: https://github.com/sahlberg/libiscsi/pull/473
Fixes: 85db7391310b ("scsi: target: iscsi: Validate CHAP_R length before base64 decode")
Signed-off-by: David Disseldorp <ddiss@suse.de>
Reviewed-by: Lee Duncan <lduncan@suse.com>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260605122019.24146-2-ddiss@suse.de
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/target/iscsi/iscsi_target_auth.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/target/iscsi/iscsi_target_auth.c b/drivers/target/iscsi/iscsi_target_auth.c
index a3ad2d244dbee1..5858cc3089796e 100644
--- a/drivers/target/iscsi/iscsi_target_auth.c
+++ b/drivers/target/iscsi/iscsi_target_auth.c
@@ -438,9 +438,11 @@ static int chap_server_compute_hash(
 	}
 
 	if (type == HEX)
-		ret = kstrtoul(&identifier[2], 0, &id);
+		ret = kstrtoul(identifier, 16, &id);
+	else if (type == DECIMAL)
+		ret = kstrtoul(identifier, 10, &id);
 	else
-		ret = kstrtoul(identifier, 0, &id);
+		ret = -EINVAL;
 
 	if (ret < 0) {
 		pr_err("kstrtoul() failed for CHAP identifier: %d\n", ret);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0563/2077] scsi: ufs: core: Handle PM commands timeout before SCSI EH
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (561 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0562/2077] scsi: target: Fix hexadecimal CHAP_I handling Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0564/2077] scsi: target: Remove tcm_loop target reset handling Greg Kroah-Hartman
                   ` (434 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hongjie Fang, Bart Van Assche,
	Peter Wang, Martin K. Petersen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hongjie Fang <hongjiefang@asrmicro.com>

[ Upstream commit 01d5e237b33931b970dd190dd6a19c5ef32c105d ]

A PM START STOP sent from the UFS well-known LU resume path can race
with SCSI EH:

The "wl resume" task flow is:
  __ufshcd_wl_resume()
    ufshcd_set_dev_pwr_mode(UFS_ACTIVE_PWR_MODE)
      ufshcd_execute_start_stop()
        scsi_execute_cmd()
          blk_execute_rq           <-- wait
          scsi_check_passthrough() <-- may retry START STOP

If the first START STOP time out, SCSI EH may already recover the link and
reset the device before scsi_execute_cmd() returns:

  scsi_timeout()
    scsi_eh_scmd_add()
      scsi_error_handler()
        scsi_unjam_host()
          scsi_eh_ready_devs()
            scsi_eh_host_reset()
              ufshcd_eh_host_reset_handler()
                if (hba->pm_op_in_progress)
                  ufshcd_link_recovery()
                    ufshcd_device_reset()
                    ufshcd_host_reset_and_restore()
          ...
          scsi_eh_flush_done_q()   <-- wakeup "wl resume" task
        ...                        <-- host still in SHOST_RECOVERY
        scsi_restart_operations()

A later passthrough retry can then run while the host is still in
SHOST_RECOVERY and hit the SCMD_FAIL_IF_RECOVERING path:

  scsi_queue_rq()
    if (scsi_host_in_recovery(shost) &&
        cmd->flags & SCMD_FAIL_IF_RECOVERING)
      return BLK_STS_OFFLINE

That retry completes with DID_ERROR or DID_NO_CONNECT even though EH may
already have restored the device to an operational ACTIVE state.

Handle these PM timeouts directly from ufshcd_eh_timed_out() instead.
After ufshcd_link_recovery(), complete the timed-out command immediately
if it has not been completed already.

For regular SCSI commands, complete them with DID_REQUEUE to match the
existing MCQ force-completion semantics and allow scsi_execute_cmd() to
retry if needed. For reserved internal device-management commands,
finish the request with DID_TIME_OUT without calling
ufshcd_release_scsi_cmd() since those commands use different resource
lifetime rules.

The system_suspending flag is no longer needed because PM command
timeout handling now uses pm_op_in_progress.

Fixes: b8c3a7bac9b6 ("scsi: ufs: Have midlayer retry start stop errors")
Signed-off-by: Hongjie Fang <hongjiefang@asrmicro.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: Peter Wang <peter.wang@mediatek.com>
Link: https://patch.msgid.link/20260605112034.3802540-1-hongjiefang@asrmicro.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/ufs/core/ufshcd.c | 34 +++++++++++++++++++++++++++-------
 include/ufs/ufshcd.h      |  3 ---
 2 files changed, 27 insertions(+), 10 deletions(-)

diff --git a/drivers/ufs/core/ufshcd.c b/drivers/ufs/core/ufshcd.c
index 385e1a8eec1620..84e32957c332d1 100644
--- a/drivers/ufs/core/ufshcd.c
+++ b/drivers/ufs/core/ufshcd.c
@@ -9466,22 +9466,44 @@ static enum scsi_timeout_action ufshcd_eh_timed_out(struct scsi_cmnd *scmd)
 {
 	struct ufs_hba *hba = shost_priv(scmd->device->host);
 
-	if (!hba->system_suspending) {
+	if (!hba->pm_op_in_progress) {
 		/* Activate the error handler in the SCSI core. */
 		return SCSI_EH_NOT_HANDLED;
 	}
 
 	/*
-	 * If we get here we know that no TMFs are outstanding and also that
-	 * the only pending command is a START STOP UNIT command. Handle the
-	 * timeout of that command directly to prevent a deadlock between
+	 * Handle the timeout directly to prevent a deadlock between
 	 * ufshcd_set_dev_pwr_mode() and ufshcd_err_handler().
 	 */
 	ufshcd_link_recovery(hba);
 	dev_info(hba->dev, "%s() finished; outstanding_tasks = %#lx.\n",
 		 __func__, hba->outstanding_tasks);
 
-	return scsi_host_busy(hba->host) ? SCSI_EH_RESET_TIMER : SCSI_EH_DONE;
+	/*
+	 * ufshcd_link_recovery() may already have completed @scmd, e.g. via
+	 * the existing MCQ force-completion path.
+	 */
+	if (!test_bit(SCMD_STATE_COMPLETE, &scmd->state)) {
+		if (!hba->mcq_enabled) {
+			unsigned long flags;
+			struct request *rq = scsi_cmd_to_rq(scmd);
+
+			spin_lock_irqsave(&hba->outstanding_lock, flags);
+			__clear_bit(rq->tag, &hba->outstanding_reqs);
+			spin_unlock_irqrestore(&hba->outstanding_lock, flags);
+		}
+
+		if (ufshcd_is_scsi_cmd(scmd)) {
+			set_host_byte(scmd, DID_REQUEUE);
+			ufshcd_release_scsi_cmd(hba, scmd);
+		} else {
+			set_host_byte(scmd, DID_TIME_OUT);
+		}
+
+		scsi_done(scmd);
+	}
+
+	return SCSI_EH_DONE;
 }
 
 static const struct attribute_group *ufshcd_driver_groups[] = {
@@ -10518,7 +10540,6 @@ static int ufshcd_wl_suspend(struct device *dev)
 
 	hba = shost_priv(sdev->host);
 	down(&hba->host_sem);
-	hba->system_suspending = true;
 
 	if (pm_runtime_suspended(dev))
 		goto out;
@@ -10560,7 +10581,6 @@ static int ufshcd_wl_resume(struct device *dev)
 		hba->curr_dev_pwr_mode, hba->uic_link_state);
 	if (!ret)
 		hba->is_sys_suspended = false;
-	hba->system_suspending = false;
 	up(&hba->host_sem);
 	return ret;
 }
diff --git a/include/ufs/ufshcd.h b/include/ufs/ufshcd.h
index cfbc75d8df8364..8280a95c00c74d 100644
--- a/include/ufs/ufshcd.h
+++ b/include/ufs/ufshcd.h
@@ -1020,8 +1020,6 @@ enum ufshcd_mcq_opr {
  * @caps: bitmask with information about UFS controller capabilities
  * @devfreq: frequency scaling information owned by the devfreq core
  * @clk_scaling: frequency scaling information owned by the UFS driver
- * @system_suspending: system suspend has been started and system resume has
- *	not yet finished.
  * @is_sys_suspended: UFS device has been suspended because of system suspend
  * @urgent_bkops_lvl: keeps track of urgent bkops level for device
  * @is_urgent_bkops_lvl_checked: keeps track if the urgent bkops level for
@@ -1197,7 +1195,6 @@ struct ufs_hba {
 
 	struct devfreq *devfreq;
 	struct ufs_clk_scaling clk_scaling;
-	bool system_suspending;
 	bool is_sys_suspended;
 
 	enum bkops_status urgent_bkops_lvl;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0564/2077] scsi: target: Remove tcm_loop target reset handling
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (562 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0563/2077] scsi: ufs: core: Handle PM commands timeout before SCSI EH Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0565/2077] pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 Greg Kroah-Hartman
                   ` (433 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mike Christie, Hannes Reinecke,
	Martin K. Petersen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mike Christie <michael.christie@oracle.com>

[ Upstream commit 7c08d430835a90414cd962e3a9602e5b002dee3b ]

tcm_loop_target_reset is supposed to handle all the LUNs on a target but
it's only doing a TMR_LUN_RESET so only that one LUN is handled.  This
will cause us to return early while IOs to other LUNs are still hung in
lower layers. This just removes the target reset handler for the driver
because LIO doesn't support target resets and for the common case where
this is run from the scsi-ml error hamdler we have already tried an
abort and lun reset so waiting again is most likely useless.

Fixes: 1333eee56cdf ("scsi: target: tcm_loop: Drain commands in target_reset handler")
Signed-off-by: Mike Christie <michael.christie@oracle.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260530052349.5134-1-michael.christie@oracle.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/target/loopback/tcm_loop.c | 64 ------------------------------
 1 file changed, 64 deletions(-)

diff --git a/drivers/target/loopback/tcm_loop.c b/drivers/target/loopback/tcm_loop.c
index 11029734575134..d29830b951f753 100644
--- a/drivers/target/loopback/tcm_loop.c
+++ b/drivers/target/loopback/tcm_loop.c
@@ -270,69 +270,6 @@ static int tcm_loop_device_reset(struct scsi_cmnd *sc)
 	return (ret == TMR_FUNCTION_COMPLETE) ? SUCCESS : FAILED;
 }
 
-static bool tcm_loop_flush_work_iter(struct request *rq, void *data)
-{
-	struct scsi_cmnd *sc = blk_mq_rq_to_pdu(rq);
-	struct tcm_loop_cmd *tl_cmd = scsi_cmd_priv(sc);
-	struct se_cmd *se_cmd = &tl_cmd->tl_se_cmd;
-
-	flush_work(&se_cmd->work);
-	return true;
-}
-
-static int tcm_loop_target_reset(struct scsi_cmnd *sc)
-{
-	struct tcm_loop_hba *tl_hba;
-	struct tcm_loop_tpg *tl_tpg;
-	struct Scsi_Host *sh = sc->device->host;
-	int ret;
-
-	/*
-	 * Locate the tcm_loop_hba_t pointer
-	 */
-	tl_hba = *(struct tcm_loop_hba **)shost_priv(sh);
-	if (!tl_hba) {
-		pr_err("Unable to perform device reset without active I_T Nexus\n");
-		return FAILED;
-	}
-	/*
-	 * Locate the tl_tpg pointer from TargetID in sc->device->id
-	 */
-	tl_tpg = &tl_hba->tl_hba_tpgs[sc->device->id];
-	if (!tl_tpg)
-		return FAILED;
-
-	/*
-	 * Issue a LUN_RESET to drain all commands that the target core
-	 * knows about.  This handles commands not yet marked CMD_T_COMPLETE.
-	 */
-	ret = tcm_loop_issue_tmr(tl_tpg, sc->device->lun, 0, TMR_LUN_RESET);
-	if (ret != TMR_FUNCTION_COMPLETE)
-		return FAILED;
-
-	/*
-	 * Flush any deferred target core completion work that may still be
-	 * queued.  Commands that already had CMD_T_COMPLETE set before the TMR
-	 * are skipped by the TMR drain, but their async completion work
-	 * (transport_lun_remove_cmd → percpu_ref_put, release_cmd → scsi_done)
-	 * may still be pending in target_completion_wq.
-	 *
-	 * The SCSI EH will reuse in-flight scsi_cmnd structures for recovery
-	 * commands (e.g. TUR) immediately after this handler returns SUCCESS —
-	 * if deferred work is still pending, the memset in queuecommand would
-	 * zero the se_cmd while the work accesses it, leaking the LUN
-	 * percpu_ref and hanging configfs unlink forever.
-	 *
-	 * Use blk_mq_tagset_busy_iter() to find all started requests and
-	 * flush_work() on each — the same pattern used by mpi3mr, scsi_debug,
-	 * and other SCSI drivers to drain outstanding commands during reset.
-	 */
-	blk_mq_tagset_busy_iter(&sh->tag_set, tcm_loop_flush_work_iter, NULL);
-
-	tl_tpg->tl_transport_status = TCM_TRANSPORT_ONLINE;
-	return SUCCESS;
-}
-
 static const struct scsi_host_template tcm_loop_driver_template = {
 	.show_info		= tcm_loop_show_info,
 	.proc_name		= "tcm_loopback",
@@ -341,7 +278,6 @@ static const struct scsi_host_template tcm_loop_driver_template = {
 	.change_queue_depth	= scsi_change_queue_depth,
 	.eh_abort_handler = tcm_loop_abort_task,
 	.eh_device_reset_handler = tcm_loop_device_reset,
-	.eh_target_reset_handler = tcm_loop_target_reset,
 	.this_id		= -1,
 	.sg_tablesize		= 256,
 	.max_sectors		= 0xFFFF,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0565/2077] pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (563 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0564/2077] scsi: target: Remove tcm_loop target reset handling Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:03 ` [PATCH 7.1 0566/2077] pinctrl: mediatek: mt8167: " Greg Kroah-Hartman
                   ` (432 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Luca Leonardo Scorcia, Linus Walleij,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Luca Leonardo Scorcia <l.scorcia@gmail.com>

[ Upstream commit 1c3044cab23a056ea28da47da1cdd667a39df0b8 ]

The correct Schmitt trigger register offset for pins 34-39 is 0xA00.

Signed-off-by: Luca Leonardo Scorcia <l.scorcia@gmail.com>
Fixes: 264667112ef0 ("pinctrl: mediatek: Add MT8516 Pinctrl driver")
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-mt8516.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pinctrl/mediatek/pinctrl-mt8516.c b/drivers/pinctrl/mediatek/pinctrl-mt8516.c
index abda75d4354e28..68d6638e7f4b18 100644
--- a/drivers/pinctrl/mediatek/pinctrl-mt8516.c
+++ b/drivers/pinctrl/mediatek/pinctrl-mt8516.c
@@ -244,7 +244,7 @@ static const struct mtk_pin_ies_smt_set mt8516_smt_set[] = {
 	MTK_PIN_IES_SMT_SPEC(24, 25, 0xA00, 12),
 	MTK_PIN_IES_SMT_SPEC(26, 30, 0xA00, 0),
 	MTK_PIN_IES_SMT_SPEC(31, 33, 0xA00, 1),
-	MTK_PIN_IES_SMT_SPEC(34, 39, 0xA900, 2),
+	MTK_PIN_IES_SMT_SPEC(34, 39, 0xA00, 2),
 	MTK_PIN_IES_SMT_SPEC(40, 40, 0xA10, 11),
 	MTK_PIN_IES_SMT_SPEC(41, 43, 0xA00, 10),
 	MTK_PIN_IES_SMT_SPEC(44, 47, 0xA00, 11),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0566/2077] pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (564 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0565/2077] pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 Greg Kroah-Hartman
@ 2026-07-21 15:03 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0567/2077] dt-bindings: pinctrl: realtek,rtd1625: Fix input voltage property name Greg Kroah-Hartman
                   ` (431 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:03 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Luca Leonardo Scorcia, Linus Walleij,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Luca Leonardo Scorcia <l.scorcia@gmail.com>

[ Upstream commit 439bc91d20188901dac698bed4921caac76d9074 ]

The correct Schmitt trigger register offset for pins 34-39 is 0xA00. Value
was verified with SoC data sheet.

Signed-off-by: Luca Leonardo Scorcia <l.scorcia@gmail.com>
Fixes: 82d70627e94a ("pinctrl: mediatek: Add MT8167 Pinctrl driver")
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-mt8167.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pinctrl/mediatek/pinctrl-mt8167.c b/drivers/pinctrl/mediatek/pinctrl-mt8167.c
index 143c2662227252..c812d614e9d453 100644
--- a/drivers/pinctrl/mediatek/pinctrl-mt8167.c
+++ b/drivers/pinctrl/mediatek/pinctrl-mt8167.c
@@ -244,7 +244,7 @@ static const struct mtk_pin_ies_smt_set mt8167_smt_set[] = {
 	MTK_PIN_IES_SMT_SPEC(24, 25, 0xA00, 12),
 	MTK_PIN_IES_SMT_SPEC(26, 30, 0xA00, 0),
 	MTK_PIN_IES_SMT_SPEC(31, 33, 0xA00, 1),
-	MTK_PIN_IES_SMT_SPEC(34, 39, 0xA900, 2),
+	MTK_PIN_IES_SMT_SPEC(34, 39, 0xA00, 2),
 	MTK_PIN_IES_SMT_SPEC(40, 40, 0xA10, 11),
 	MTK_PIN_IES_SMT_SPEC(41, 43, 0xA00, 10),
 	MTK_PIN_IES_SMT_SPEC(44, 47, 0xA00, 11),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0567/2077] dt-bindings: pinctrl: realtek,rtd1625: Fix input voltage property name
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (565 preceding siblings ...)
  2026-07-21 15:03 ` [PATCH 7.1 0566/2077] pinctrl: mediatek: mt8167: " Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0568/2077] pinctrl: PINCTRL_STMFX should depend on CONFIG_OF Greg Kroah-Hartman
                   ` (430 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yu-Chun Lin, Conor Dooley,
	Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yu-Chun Lin <eleanor.lin@realtek.com>

[ Upstream commit 388d2fe16283d68e4be8c5317809a4a218ebeace ]

The property 'input-voltage-microvolt' is a typo. Rename it to
'input-threshold-voltage-microvolt' to align with the standard pin
configuration defined in pincfg-node.yaml and parsed by pinconf-generic.c.

Fixes: f6ea7004e926 ("dt-bindings: pinctrl: realtek: Add RTD1625 pinctrl binding")
Signed-off-by: Yu-Chun Lin <eleanor.lin@realtek.com>
Acked-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../devicetree/bindings/pinctrl/realtek,rtd1625-pinctrl.yaml    | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/Documentation/devicetree/bindings/pinctrl/realtek,rtd1625-pinctrl.yaml b/Documentation/devicetree/bindings/pinctrl/realtek,rtd1625-pinctrl.yaml
index 9562a043707ee2..adc5955a2047c2 100644
--- a/Documentation/devicetree/bindings/pinctrl/realtek,rtd1625-pinctrl.yaml
+++ b/Documentation/devicetree/bindings/pinctrl/realtek,rtd1625-pinctrl.yaml
@@ -110,7 +110,7 @@ patternProperties:
 
       input-schmitt-disable: true
 
-      input-voltage-microvolt:
+      input-threshold-voltage-microvolt:
         description: |
           Select the input receiver voltage domain for the pin.
           Valid arguments are:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0568/2077] pinctrl: PINCTRL_STMFX should depend on CONFIG_OF
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (566 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0567/2077] dt-bindings: pinctrl: realtek,rtd1625: Fix input voltage property name Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0569/2077] iommufd: Take dma_resv lock before dma_buf_unpin() in release path Greg Kroah-Hartman
                   ` (429 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Timur Tabi, Linus Walleij,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Timur Tabi <ttabi@nvidia.com>

[ Upstream commit fd9490bdd4536a8e0911578f62164176b9000552 ]

Commit e785c990adcc ("pinctrl: Kconfig: drop unneeded dependencies
on OF_GPIO") removed a redundant dependecy on CONFIG_OF_GPIO for
several pinctrl drivers, but this change also removed a dependency
on CONFIG_OF for some of those drivers.

Normally, this wouldn't be a problem, but PINCTRL_STMFX also selected
MFD_STMFX, which does depend on CONFIG_OF.  This conflict allows
MFD_STMFX to be enabled even if CONFIG_OF is disabled.

Fix this by also having PINCTRL_STMFX depend on CONFIG_OF.  This is
okay because the pinctrl-stmfx driver actually does depend on CONFIG_OF
functions.

Fixes: e785c990adcc ("pinctrl: Kconfig: drop unneeded dependencies on OF_GPIO")
Signed-off-by: Timur Tabi <ttabi@nvidia.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/Kconfig | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/pinctrl/Kconfig b/drivers/pinctrl/Kconfig
index 03f2e3ee065f42..75131b6e6eeac9 100644
--- a/drivers/pinctrl/Kconfig
+++ b/drivers/pinctrl/Kconfig
@@ -548,6 +548,7 @@ config PINCTRL_ST
 
 config PINCTRL_STMFX
 	tristate "STMicroelectronics STMFX GPIO expander pinctrl driver"
+	depends on OF
 	depends on I2C
 	depends on HAS_IOMEM
 	select GENERIC_PINCONF
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0569/2077] iommufd: Take dma_resv lock before dma_buf_unpin() in release path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (567 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0568/2077] pinctrl: PINCTRL_STMFX should depend on CONFIG_OF Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0570/2077] iommufd: Destroy the pages content after detaching from dmabuf Greg Kroah-Hartman
                   ` (428 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ankit Soni, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ankit Soni <Ankit.Soni@amd.com>

[ Upstream commit e745cd2c749e557c14a15ac931761c3f58c24489 ]

dma_buf_unpin() requires the caller to hold the exporter's dma_resv
lock:

  void dma_buf_unpin(struct dma_buf_attachment *attach)
  {
          ...
          dma_resv_assert_held(dmabuf->resv);
          ...
  }

iopt_release_pages() calls dma_buf_unpin() without taking that lock,
so every iommufd_ioas_destroy()/iommufd_ioas_unmap() that releases
the last reference on a DMABUF-backed iopt_pages triggers a WARN.
This was hit while running tools/testing/selftests/iommu/iommufd:

  WARNING: drivers/dma-buf/dma-buf.c:1137 at dma_buf_unpin+0x62/0x70
  RIP: 0010:dma_buf_unpin+0x62/0x70
  Call Trace:
   <TASK>
   dma_buf_unpin+0x62/0x70
   iopt_release_pages+0xe4/0x190
   iopt_unmap_iova_range+0x1c7/0x290
   iopt_unmap_all+0x1a/0x30
   iommufd_ioas_destroy+0x1d/0x50
   iommufd_fops_release+0x93/0x150
   __fput+0xfc/0x2c0
   __x64_sys_close+0x3d/0x80
   do_syscall_64+0x65/0x180
   </TASK>

Take the dma_resv lock around dma_buf_unpin() in iopt_release_pages(),
matching the iopt_map_dmabuf() convention. dma_buf_detach() acquires the
reservation lock internally, so it must remain outside the locked region.

Fixes: 8c5f9645c389 ("iommufd: Add dma_buf_pin()")
Link: https://patch.msgid.link/r/20260526111034.4079-1-Ankit.Soni@amd.com
Reported-by: Ankit Soni <Ankit.Soni@amd.com>
Signed-off-by: Ankit Soni <Ankit.Soni@amd.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iommu/iommufd/pages.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/iommu/iommufd/pages.c b/drivers/iommu/iommufd/pages.c
index 9bdb2945afe1eb..7b64002e54b9a2 100644
--- a/drivers/iommu/iommufd/pages.c
+++ b/drivers/iommu/iommufd/pages.c
@@ -1663,7 +1663,9 @@ void iopt_release_pages(struct kref *kref)
 	if (iopt_is_dmabuf(pages) && pages->dmabuf.attach) {
 		struct dma_buf *dmabuf = pages->dmabuf.attach->dmabuf;
 
+		dma_resv_lock(dmabuf->resv, NULL);
 		dma_buf_unpin(pages->dmabuf.attach);
+		dma_resv_unlock(dmabuf->resv);
 		dma_buf_detach(dmabuf, pages->dmabuf.attach);
 		dma_buf_put(dmabuf);
 		WARN_ON(!list_empty(&pages->dmabuf.tracker));
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0570/2077] iommufd: Destroy the pages content after detaching from dmabuf
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (568 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0569/2077] iommufd: Take dma_resv lock before dma_buf_unpin() in release path Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0571/2077] lib/test_hmm: fix memory leak in dmirror_migrate_to_system() Greg Kroah-Hartman
                   ` (427 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jason Gunthorpe <jgg@nvidia.com>

[ Upstream commit f2d70dbd3dcefa8e3c380beff9c31f5f033a4221 ]

Sashiko points out this has gotten out of order, the mutex could still be
in use through the dmabuf invalidation callbacks. Don't destroy any of the
pages content until the dmabuf is fully detached.

Fixes: 71db84a092c3 ("iommufd: Add DMABUF to iopt_pages")
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iommu/iommufd/pages.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/iommu/iommufd/pages.c b/drivers/iommu/iommufd/pages.c
index 7b64002e54b9a2..03c8379bbc347e 100644
--- a/drivers/iommu/iommufd/pages.c
+++ b/drivers/iommu/iommufd/pages.c
@@ -1656,10 +1656,6 @@ void iopt_release_pages(struct kref *kref)
 	WARN_ON(!RB_EMPTY_ROOT(&pages->domains_itree.rb_root));
 	WARN_ON(pages->npinned);
 	WARN_ON(!xa_empty(&pages->pinned_pfns));
-	mmdrop(pages->source_mm);
-	mutex_destroy(&pages->mutex);
-	put_task_struct(pages->source_task);
-	free_uid(pages->source_user);
 	if (iopt_is_dmabuf(pages) && pages->dmabuf.attach) {
 		struct dma_buf *dmabuf = pages->dmabuf.attach->dmabuf;
 
@@ -1672,6 +1668,10 @@ void iopt_release_pages(struct kref *kref)
 	} else if (pages->type == IOPT_ADDRESS_FILE) {
 		fput(pages->file);
 	}
+	mmdrop(pages->source_mm);
+	mutex_destroy(&pages->mutex);
+	put_task_struct(pages->source_task);
+	free_uid(pages->source_user);
 	kfree(pages);
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0571/2077] lib/test_hmm: fix memory leak in dmirror_migrate_to_system()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (569 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0570/2077] iommufd: Destroy the pages content after detaching from dmabuf Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0572/2077] vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() Greg Kroah-Hartman
                   ` (426 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hao Ge, Alistair Popple, Sashiko,
	Balbir Singh, Jason Gunthorpe, Leon Romanovsky, Andrew Morton,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hao Ge <hao.ge@linux.dev>

[ Upstream commit 8f7275c174bc5bcc8fc1bec8024e2b3e6fe17f46 ]

Move the kvcalloc() calls after the early return checks to avoid leaking
src_pfns and dst_pfns when end < start or mmget_not_zero() fails.

Link: https://lore.kernel.org/20260528011336.20797-1-hao.ge@linux.dev
Fixes: 775465fd26a3 ("lib/test_hmm: add zone device private THP test infrastructure")
Signed-off-by: Hao Ge <hao.ge@linux.dev>
Reviewed-by: Alistair Popple <apopple@nvidia.com>
Reported-by: Sashiko <sashiko-bot@kernel.org>
Reviewed-by: Balbir Singh <balbirs@nvidia.com>
Cc: Jason Gunthorpe <jgg@ziepe.ca>
Cc: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 lib/test_hmm.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/lib/test_hmm.c b/lib/test_hmm.c
index 38996c4baa4080..1e2b76e79c74e9 100644
--- a/lib/test_hmm.c
+++ b/lib/test_hmm.c
@@ -1111,9 +1111,6 @@ static int dmirror_migrate_to_system(struct dmirror *dmirror,
 	unsigned long *src_pfns;
 	unsigned long *dst_pfns;
 
-	src_pfns = kvcalloc(PTRS_PER_PTE, sizeof(*src_pfns), GFP_KERNEL | __GFP_NOFAIL);
-	dst_pfns = kvcalloc(PTRS_PER_PTE, sizeof(*dst_pfns), GFP_KERNEL | __GFP_NOFAIL);
-
 	start = cmd->addr;
 	end = start + size;
 	if (end < start)
@@ -1123,6 +1120,9 @@ static int dmirror_migrate_to_system(struct dmirror *dmirror,
 	if (!mmget_not_zero(mm))
 		return -EINVAL;
 
+	src_pfns = kvcalloc(PTRS_PER_PTE, sizeof(*src_pfns), GFP_KERNEL | __GFP_NOFAIL);
+	dst_pfns = kvcalloc(PTRS_PER_PTE, sizeof(*dst_pfns), GFP_KERNEL | __GFP_NOFAIL);
+
 	cmd->cpages = 0;
 	mmap_read_lock(mm);
 	for (addr = start; addr < end; addr = next) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0572/2077] vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (570 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0571/2077] lib/test_hmm: fix memory leak in dmirror_migrate_to_system() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0573/2077] rust: kbuild: show the right `quiet_cmd_rustc_procmacrolibrary` Greg Kroah-Hartman
                   ` (425 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hui Zhu, Dev Jain,
	Uladzislau Rezki (Sony), Nicholas Piggin, Andrew Morton,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hui Zhu <zhuhui@kylinos.cn>

[ Upstream commit c55dd3b46c1208d6d2ea737a8aefef4aa4c70cb8 ]

find_vm_area() can return NULL if the given address is not a valid vmalloc
area.  Check the return value before dereferencing it to avoid a kernel
crash.

Link: https://lore.kernel.org/20260529014130.671291-1-hui.zhu@linux.dev
Fixes: 121e6f3258fe ("mm/vmalloc: hugepage vmalloc mappings")
Signed-off-by: Hui Zhu <zhuhui@kylinos.cn>
Reviewed-by: Dev Jain <dev.jain@arm.com>
Reviewed-by: Uladzislau Rezki (Sony) <urezki@gmail.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/vmalloc.h | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/include/linux/vmalloc.h b/include/linux/vmalloc.h
index 3b02c0c6b37187..d87dc7f77f4e8a 100644
--- a/include/linux/vmalloc.h
+++ b/include/linux/vmalloc.h
@@ -265,7 +265,9 @@ static inline bool is_vm_area_hugepages(const void *addr)
 	 * allocated in the vmalloc layer.
 	 */
 #ifdef CONFIG_HAVE_ARCH_HUGE_VMALLOC
-	return find_vm_area(addr)->page_order > 0;
+	struct vm_struct *area = find_vm_area(addr);
+
+	return area && area->page_order > 0;
 #else
 	return false;
 #endif
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0573/2077] rust: kbuild: show the right `quiet_cmd_rustc_procmacrolibrary`
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (571 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0572/2077] vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0574/2077] remoteproc: qcom_q6v5_wcss: drop redundant wcss_q6_bcr_reset Greg Kroah-Hartman
                   ` (424 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nicolas Schier, Miguel Ojeda,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Miguel Ojeda <ojeda@kernel.org>

[ Upstream commit 70a8d5ada9fabf4a34732b718f9c992195eed2ea ]

When Clippy is skipped, `RUSTC` should be shown in `quiet` instead of
`CLIPPY` to be accurate and to avoid confusion.

Thus do so, matching what we do in `quiet_cmd_rustc_library`.

Fixes: 7dbe46c0b11d ("rust: kbuild: add proc macro library support")
Reviewed-by: Nicolas Schier <nsc@kernel.org>
Link: https://patch.msgid.link/20260608141439.182634-3-ojeda@kernel.org
Signed-off-by: Miguel Ojeda <ojeda@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 rust/Makefile | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/rust/Makefile b/rust/Makefile
index b9e9f512cec314..bec9726f256ce9 100644
--- a/rust/Makefile
+++ b/rust/Makefile
@@ -517,7 +517,7 @@ $(obj)/exports_bindings_generated.h: $(obj)/bindings.o FORCE
 $(obj)/exports_kernel_generated.h: $(obj)/kernel.o FORCE
 	$(call if_changed,exports)
 
-quiet_cmd_rustc_procmacrolibrary = $(RUSTC_OR_CLIPPY_QUIET) PL $@
+quiet_cmd_rustc_procmacrolibrary = $(if $(skip_clippy),RUSTC,$(RUSTC_OR_CLIPPY_QUIET)) PL $@
       cmd_rustc_procmacrolibrary = \
 	$(if $(skip_clippy),$(RUSTC),$(RUSTC_OR_CLIPPY)) \
 		$(filter-out $(skip_flags),$(rust_common_flags) $(rustc_target_flags)) \
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0574/2077] remoteproc: qcom_q6v5_wcss: drop redundant wcss_q6_bcr_reset
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (572 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0573/2077] rust: kbuild: show the right `quiet_cmd_rustc_procmacrolibrary` Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0575/2077] hwspinlock: qcom: avoid uninitialized struct members Greg Kroah-Hartman
                   ` (423 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Alexandru Gagniuc,
	Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexandru Gagniuc <mr.nuke.me@gmail.com>

[ Upstream commit 6ad61d0acd41044a949e84f96a5f8e02284d350f ]

The wcss_q6_bcr_reset used on QCS404, and wcss_q6_reset used on IPQ
are the same. "BCR reset" is redundant, and likely a mistake. Use the
documented "wcss_q6_reset" instead. Drop ".wcss_q6_reset_required"
from the descriptor, since all targets now need it.

This changes the bindings expectations, however, it actually fixes the
driver to consume the intended ones (qcom,q6v5.txt), which lists
"wcss_q6_reset" and *not* "wcss_q6_bcr_reset"

Fixes: 0af65b9b915e ("remoteproc: qcom: wcss: Add non pas wcss Q6 support for QCS404")

Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Alexandru Gagniuc <mr.nuke.me@gmail.com>
Link: https://lore.kernel.org/r/20251208223315.3540680-1-mr.nuke.me@gmail.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/remoteproc/qcom_q6v5_wcss.c | 23 +++++------------------
 1 file changed, 5 insertions(+), 18 deletions(-)

diff --git a/drivers/remoteproc/qcom_q6v5_wcss.c b/drivers/remoteproc/qcom_q6v5_wcss.c
index c27200159a88a2..b391724cfd08e1 100644
--- a/drivers/remoteproc/qcom_q6v5_wcss.c
+++ b/drivers/remoteproc/qcom_q6v5_wcss.c
@@ -96,7 +96,6 @@ struct wcss_data {
 	unsigned int crash_reason_smem;
 	u32 version;
 	bool aon_reset_required;
-	bool wcss_q6_reset_required;
 	const char *ssr_name;
 	const char *sysmon_name;
 	int ssctl_id;
@@ -134,7 +133,6 @@ struct q6v5_wcss {
 	struct reset_control *wcss_aon_reset;
 	struct reset_control *wcss_reset;
 	struct reset_control *wcss_q6_reset;
-	struct reset_control *wcss_q6_bcr_reset;
 
 	struct qcom_q6v5 q6v5;
 
@@ -309,7 +307,7 @@ static int q6v5_wcss_qcs404_power_on(struct q6v5_wcss *wcss)
 		return ret;
 
 	/* Remove reset to the WCNSS QDSP6SS */
-	reset_control_deassert(wcss->wcss_q6_bcr_reset);
+	reset_control_deassert(wcss->wcss_q6_reset);
 
 	/* Enable Q6SSTOP_AHBFABRIC_CBCR clock */
 	ret = clk_prepare_enable(wcss->ahbfabric_cbcr_clk);
@@ -803,19 +801,10 @@ static int q6v5_wcss_init_reset(struct q6v5_wcss *wcss,
 		return PTR_ERR(wcss->wcss_reset);
 	}
 
-	if (desc->wcss_q6_reset_required) {
-		wcss->wcss_q6_reset = devm_reset_control_get_exclusive(dev, "wcss_q6_reset");
-		if (IS_ERR(wcss->wcss_q6_reset)) {
-			dev_err(wcss->dev, "unable to acquire wcss_q6_reset\n");
-			return PTR_ERR(wcss->wcss_q6_reset);
-		}
-	}
-
-	wcss->wcss_q6_bcr_reset = devm_reset_control_get_optional_exclusive(dev,
-							"wcss_q6_bcr_reset");
-	if (IS_ERR(wcss->wcss_q6_bcr_reset)) {
-		dev_err(wcss->dev, "unable to acquire wcss_q6_bcr_reset\n");
-		return PTR_ERR(wcss->wcss_q6_bcr_reset);
+	wcss->wcss_q6_reset = devm_reset_control_get_exclusive(dev, "wcss_q6_reset");
+	if (IS_ERR(wcss->wcss_q6_reset)) {
+		dev_err(wcss->dev, "unable to acquire wcss_q6_reset\n");
+		return PTR_ERR(wcss->wcss_q6_reset);
 	}
 
 	return 0;
@@ -1062,7 +1051,6 @@ static const struct wcss_data wcss_ipq8074_res_init = {
 	.firmware_name = "IPQ8074/q6_fw.mdt",
 	.crash_reason_smem = WCSS_CRASH_REASON,
 	.aon_reset_required = true,
-	.wcss_q6_reset_required = true,
 	.ops = &q6v5_wcss_ipq8074_ops,
 	.requires_force_stop = true,
 };
@@ -1072,7 +1060,6 @@ static const struct wcss_data wcss_qcs404_res_init = {
 	.firmware_name = "wcnss.mdt",
 	.version = WCSS_QCS404,
 	.aon_reset_required = false,
-	.wcss_q6_reset_required = false,
 	.ssr_name = "mpss",
 	.sysmon_name = "wcnss",
 	.ssctl_id = 0x12,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0575/2077] hwspinlock: qcom: avoid uninitialized struct members
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (573 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0574/2077] remoteproc: qcom_q6v5_wcss: drop redundant wcss_q6_bcr_reset Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0576/2077] sched/fair: Fix cpu_util runnable_avg arithmetic Greg Kroah-Hartman
                   ` (422 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wolfram Sang, Konrad Dybcio,
	Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wolfram Sang <wsa+renesas@sang-engineering.com>

[ Upstream commit 8752c396ce3b2136b3d4c906fe103f6efb6782d9 ]

The reg_field is allocated on stack, so using the REG_FIELD macro will
ensure that unused members do not have uninitialized values.

Fixes: 19a0f61224d2 ("hwspinlock: qcom: Add support for Qualcomm HW Mutex block")
Link: https://sashiko.dev/#/patchset/20260319105947.6237-1-wsa%2Brenesas%40sang-engineering.com
Signed-off-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260512091339.31085-2-wsa+renesas@sang-engineering.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwspinlock/qcom_hwspinlock.c | 5 +----
 1 file changed, 1 insertion(+), 4 deletions(-)

diff --git a/drivers/hwspinlock/qcom_hwspinlock.c b/drivers/hwspinlock/qcom_hwspinlock.c
index 0390979fd765d0..712003a4640cc1 100644
--- a/drivers/hwspinlock/qcom_hwspinlock.c
+++ b/drivers/hwspinlock/qcom_hwspinlock.c
@@ -202,7 +202,6 @@ static struct regmap *qcom_hwspinlock_probe_mmio(struct platform_device *pdev,
 static int qcom_hwspinlock_probe(struct platform_device *pdev)
 {
 	struct hwspinlock_device *bank;
-	struct reg_field field;
 	struct regmap *regmap;
 	size_t array_size;
 	u32 stride;
@@ -224,9 +223,7 @@ static int qcom_hwspinlock_probe(struct platform_device *pdev)
 	platform_set_drvdata(pdev, bank);
 
 	for (i = 0; i < QCOM_MUTEX_NUM_LOCKS; i++) {
-		field.reg = base + i * stride;
-		field.lsb = 0;
-		field.msb = 31;
+		struct reg_field field = REG_FIELD(base + i * stride, 0, 31);
 
 		bank->lock[i].priv = devm_regmap_field_alloc(&pdev->dev,
 							     regmap, field);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0576/2077] sched/fair: Fix cpu_util runnable_avg arithmetic
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (574 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0575/2077] hwspinlock: qcom: avoid uninitialized struct members Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0577/2077] ARM: configs: Drop duplicated CONFIG_EXT4_FS Greg Kroah-Hartman
                   ` (421 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hongyan Xia, Peter Zijlstra (Intel),
	Vincent Guittot, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hongyan Xia <hongyan.xia@transsion.com>

[ Upstream commit 29922fdfc2a4008d66418bedd0ebf5038fc54efa ]

If we take runnable_avg in max(runnable_avg, util_avg) in cpu_util(), we
should then add or subtract task runnable_avg, but the arithmetic below
is still with task util_avg. This mixes runnable_avg with util_avg which
is incorrect.

Fix by always doing arithmetic with runnable_avg and only take
max(runnable_avg, util_avg) at the last step.

Fixes: 7d0583cf9ec7 ("sched/fair, cpufreq: Introduce 'runnable boosting'")
Signed-off-by: Hongyan Xia <hongyan.xia@transsion.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Vincent Guittot <vincent.guittot@linaro.org>
Link: https://patch.msgid.link/20260605094318.37931-1-hongyan.xia@transsion.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/sched/fair.c | 23 +++++++++++++++--------
 1 file changed, 15 insertions(+), 8 deletions(-)

diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c
index bcc984e462272d..abb76775aa7287 100644
--- a/kernel/sched/fair.c
+++ b/kernel/sched/fair.c
@@ -8256,25 +8256,32 @@ static int select_idle_sibling(struct task_struct *p, int prev, int target)
 static unsigned long
 cpu_util(int cpu, struct task_struct *p, int dst_cpu, int boost)
 {
+	bool add_task = p && task_cpu(p) != cpu && dst_cpu == cpu;
+	bool sub_task = p && task_cpu(p) == cpu && dst_cpu != cpu;
 	struct cfs_rq *cfs_rq = &cpu_rq(cpu)->cfs;
 	unsigned long util = READ_ONCE(cfs_rq->avg.util_avg);
 	unsigned long runnable;
 
-	if (boost) {
-		runnable = READ_ONCE(cfs_rq->avg.runnable_avg);
-		util = max(util, runnable);
-	}
-
 	/*
 	 * If @dst_cpu is -1 or @p migrates from @cpu to @dst_cpu remove its
 	 * contribution. If @p migrates from another CPU to @cpu add its
 	 * contribution. In all the other cases @cpu is not impacted by the
 	 * migration so its util_avg is already correct.
 	 */
-	if (p && task_cpu(p) == cpu && dst_cpu != cpu)
-		lsub_positive(&util, task_util(p));
-	else if (p && task_cpu(p) != cpu && dst_cpu == cpu)
+	if (add_task)
 		util += task_util(p);
+	else if (sub_task)
+		lsub_positive(&util, task_util(p));
+
+	if (boost) {
+		runnable = READ_ONCE(cfs_rq->avg.runnable_avg);
+		if (add_task)
+			runnable += READ_ONCE(p->se.avg.runnable_avg);
+		else if (sub_task)
+			lsub_positive(&runnable,
+				      READ_ONCE(p->se.avg.runnable_avg));
+		util = max(util, runnable);
+	}
 
 	if (sched_feat(UTIL_EST)) {
 		unsigned long util_est;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0577/2077] ARM: configs: Drop duplicated CONFIG_EXT4_FS
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (575 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0576/2077] sched/fair: Fix cpu_util runnable_avg arithmetic Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0578/2077] wifi: mt76: mt7925: clean up DMA on probe failure Greg Kroah-Hartman
                   ` (420 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Richard Cheng,
	Arnd Bergmann, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

[ Upstream commit ae371a58117d30a496e3be27cce8d9d13acdd740 ]

Remove redundant, duplicated CONFIG_EXT4_FS to fix warnings like:

  axm55xx_defconfig:198:warning: override: reassigning to symbol EXT4_FS

Fixes: c065b6046b34 ("Use CONFIG_EXT4_FS instead of CONFIG_EXT3_FS in all of the defconfigs")
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Richard Cheng <icheng@nvidia.com>
Link: https://lore.kernel.org/r/20260603072726.19404-2-krzysztof.kozlowski@oss.qualcomm.com
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm/configs/axm55xx_defconfig | 1 -
 arch/arm/configs/dove_defconfig    | 1 -
 arch/arm/configs/ep93xx_defconfig  | 1 -
 arch/arm/configs/mmp2_defconfig    | 1 -
 arch/arm/configs/mv78xx0_defconfig | 1 -
 5 files changed, 5 deletions(-)

diff --git a/arch/arm/configs/axm55xx_defconfig b/arch/arm/configs/axm55xx_defconfig
index 22b189090e15f4..0952e5e94c5e7f 100644
--- a/arch/arm/configs/axm55xx_defconfig
+++ b/arch/arm/configs/axm55xx_defconfig
@@ -195,7 +195,6 @@ CONFIG_PL320_MBOX=y
 # CONFIG_IOMMU_SUPPORT is not set
 CONFIG_EXT2_FS=y
 CONFIG_EXT4_FS=y
-CONFIG_EXT4_FS=y
 CONFIG_AUTOFS_FS=y
 CONFIG_FUSE_FS=y
 CONFIG_CUSE=y
diff --git a/arch/arm/configs/dove_defconfig b/arch/arm/configs/dove_defconfig
index e98c35df675e65..3d978ce34b54f0 100644
--- a/arch/arm/configs/dove_defconfig
+++ b/arch/arm/configs/dove_defconfig
@@ -97,7 +97,6 @@ CONFIG_MV_XOR=y
 CONFIG_EXT2_FS=y
 CONFIG_EXT4_FS=y
 # CONFIG_EXT4_FS_XATTR is not set
-CONFIG_EXT4_FS=y
 CONFIG_ISO9660_FS=y
 CONFIG_JOLIET=y
 CONFIG_UDF_FS=m
diff --git a/arch/arm/configs/ep93xx_defconfig b/arch/arm/configs/ep93xx_defconfig
index 9f3c7324d1cf48..ce41dc8c435cb5 100644
--- a/arch/arm/configs/ep93xx_defconfig
+++ b/arch/arm/configs/ep93xx_defconfig
@@ -105,7 +105,6 @@ CONFIG_EP93XX_DMA=y
 CONFIG_EXT2_FS=y
 CONFIG_EXT4_FS=y
 # CONFIG_EXT4_FS_XATTR is not set
-CONFIG_EXT4_FS=y
 CONFIG_VFAT_FS=y
 CONFIG_TMPFS=y
 CONFIG_JFFS2_FS=y
diff --git a/arch/arm/configs/mmp2_defconfig b/arch/arm/configs/mmp2_defconfig
index a9a212abfd69ad..0ea608c75f2263 100644
--- a/arch/arm/configs/mmp2_defconfig
+++ b/arch/arm/configs/mmp2_defconfig
@@ -54,7 +54,6 @@ CONFIG_RTC_DRV_MAX8925=y
 # CONFIG_RESET_CONTROLLER is not set
 CONFIG_EXT2_FS=y
 CONFIG_EXT4_FS=y
-CONFIG_EXT4_FS=y
 # CONFIG_DNOTIFY is not set
 CONFIG_MSDOS_FS=y
 CONFIG_FAT_DEFAULT_CODEPAGE=437
diff --git a/arch/arm/configs/mv78xx0_defconfig b/arch/arm/configs/mv78xx0_defconfig
index d3a26efe766c4c..c6b46141cb697f 100644
--- a/arch/arm/configs/mv78xx0_defconfig
+++ b/arch/arm/configs/mv78xx0_defconfig
@@ -93,7 +93,6 @@ CONFIG_RTC_DRV_M41T80=y
 CONFIG_EXT2_FS=y
 CONFIG_EXT4_FS=y
 # CONFIG_EXT4_FS_XATTR is not set
-CONFIG_EXT4_FS=m
 CONFIG_ISO9660_FS=m
 CONFIG_JOLIET=y
 CONFIG_UDF_FS=m
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0578/2077] wifi: mt76: mt7925: clean up DMA on probe failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (576 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0577/2077] ARM: configs: Drop duplicated CONFIG_EXT4_FS Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0579/2077] wifi: mt76: mt7921: fix resource leak in probe error path Greg Kroah-Hartman
                   ` (419 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak,
	Felix Fietkau, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Myeonghun Pak <mhun512@gmail.com>

[ Upstream commit 9629f31f505d74e76ac0d7a9492fd06c0316fc5d ]

mt7925_pci_probe() initializes DMA before registering the device. If
mt7925_register_device() fails, probe returns through err_free_irq without
tearing down DMA state.

That leaves the TX NAPI instance enabled and skips the DMA queue cleanup
that the normal remove path performs through mt7925e_unregister_device().
Add a dedicated unwind label for failures after mt7925_dma_init() succeeds.

Fixes: c948b5da6bbe ("wifi: mt76: mt7925: add Mediatek Wi-Fi7 driver for mt7925 chips")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Link: https://patch.msgid.link/20260426143728.41534-1-pakmyeonghun@bagmyeonghun-ui-MacBookPro.local
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7925/pci.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/pci.c b/drivers/net/wireless/mediatek/mt76/mt7925/pci.c
index c4161754c01df1..48837723024d7c 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/pci.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/pci.c
@@ -415,10 +415,12 @@ static int mt7925_pci_probe(struct pci_dev *pdev,
 
 	ret = mt7925_register_device(dev);
 	if (ret)
-		goto err_free_irq;
+		goto err_free_dma;
 
 	return 0;
 
+err_free_dma:
+	mt792x_dma_cleanup(dev);
 err_free_irq:
 	devm_free_irq(&pdev->dev, pdev->irq, dev);
 err_free_dev:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0579/2077] wifi: mt76: mt7921: fix resource leak in probe error path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (577 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0578/2077] wifi: mt76: mt7925: clean up DMA on probe failure Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0580/2077] wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link Greg Kroah-Hartman
                   ` (418 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hongling Zeng, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hongling Zeng <zenghongling@kylinos.cn>

[ Upstream commit 346dac35b1384af9338b34b6835e82e634ea4d2c ]

When pcim_iomap_region() or devm_kmemdup() fail, the code returns
directly without cleaning up previously allocated resources:
  - mt76_device allocated by mt76_alloc_device()
  - pci irq vectors allocated by pci_alloc_irq_vectors()
Fix this by jumping to the existing error cleanup path instead of
returning directly.

Fixes: ee5bb35d2b83 ("wifi: mt76: mt7921: Replace deprecated PCI function")
Fixes: 222606f43b58 ("wifi: mt76: mt7921: handle MT7902 irq_map quirk with mutable copy")
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Link: https://patch.msgid.link/20260512065245.46496-1-zenghongling@kylinos.cn
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7921/pci.c | 15 ++++++++++-----
 1 file changed, 10 insertions(+), 5 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7921/pci.c b/drivers/net/wireless/mediatek/mt76/mt7921/pci.c
index 7a790ddf43bb69..49a37185f0564e 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7921/pci.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7921/pci.c
@@ -343,11 +343,14 @@ static int mt7921_pci_probe(struct pci_dev *pdev,
 
 	pci_set_drvdata(pdev, mdev);
 
+	dev = container_of(mdev, struct mt792x_dev, mt76);
+
 	regs =  pcim_iomap_region(pdev, 0, pci_name(pdev));
-	if (IS_ERR(regs))
-		return PTR_ERR(regs);
+	if (IS_ERR(regs)) {
+		ret = PTR_ERR(regs);
+		goto err_free_dev;
+	}
 
-	dev = container_of(mdev, struct mt792x_dev, mt76);
 	dev->fw_features = features;
 	dev->hif_ops = &mt7921_pcie_ops;
 	dev->irq_map = &irq_map;
@@ -359,8 +362,10 @@ static int mt7921_pci_probe(struct pci_dev *pdev,
 		/* MT7902 needs a mutable copy because wm2_complete_mask differs */
 		map = devm_kmemdup(&pdev->dev, &irq_map,
 				   sizeof(irq_map), GFP_KERNEL);
-		if (!map)
-			return -ENOMEM;
+		if (!map) {
+			ret = -ENOMEM;
+			goto err_free_dev;
+		}
 
 		map->rx.wm2_complete_mask = 0;
 		dev->irq_map = map;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0580/2077] wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (578 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0579/2077] wifi: mt76: mt7921: fix resource leak in probe error path Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0581/2077] wifi: mt76: mt7996: add missing max_remain_on_channel_duration Greg Kroah-Hartman
                   ` (417 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Rajat Gupta, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rajat Gupta <rajat.gupta@oss.qualcomm.com>

[ Upstream commit 7fae097aa9a56c30febf539d72ef3773165d3aa3 ]

mt76_put_vif_phy_link() frees the offchannel mlink with plain kfree()
after rcu_assign_pointer(NULL). However, rcu_assign_pointer only prevents
future RCU readers from obtaining the pointer -- it does not wait for
existing readers that already hold it via rcu_dereference.

The TX datapath (e.g. mt7996_mac_write_txwi) dereferences mlink->wcid
and mlink->idx under rcu_read_lock. If a TX softirq obtained the pointer
via rcu_dereference just before the NULL assignment, it will dereference
freed memory after the kfree.

struct mt76_vif_link already contains an rcu_head field that is unused at
this free site -- a developer oversight, since the adjacent
kfree_rcu_mightsleep call for rx_sc in the same function shows the
pattern was understood.

Replace kfree(mlink) with kfree_rcu(mlink, rcu_head).

Fixes: a8f424c1287c ("wifi: mt76: add multi-radio remain_on_channel functions")
Signed-off-by: Rajat Gupta <rajat.gupta@oss.qualcomm.com>
Link: https://patch.msgid.link/20260507043531.492-1-rajat.gupta@oss.qualcomm.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/channel.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wireless/mediatek/mt76/channel.c b/drivers/net/wireless/mediatek/mt76/channel.c
index 05eee64706ea87..6edcb3b8f2798e 100644
--- a/drivers/net/wireless/mediatek/mt76/channel.c
+++ b/drivers/net/wireless/mediatek/mt76/channel.c
@@ -307,7 +307,7 @@ void mt76_put_vif_phy_link(struct mt76_phy *phy, struct ieee80211_vif *vif,
 
 	rcu_assign_pointer(mvif->offchannel_link, NULL);
 	dev->drv->vif_link_remove(phy, vif, &vif->bss_conf, mlink);
-	kfree(mlink);
+	kfree_rcu(mlink, rcu_head);
 }
 
 void mt76_roc_complete(struct mt76_phy *phy)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0581/2077] wifi: mt76: mt7996: add missing max_remain_on_channel_duration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (579 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0580/2077] wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0582/2077] wifi: mt76: mt7996: Fix NULL pointer dereference in mt7996_init_tx_queues() Greg Kroah-Hartman
                   ` (416 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Fietkau <nbd@nbd.name>

[ Upstream commit ac41612e0044fa29cf9bc45b6808dda6d87ac2da ]

Having this unset breaks remain-on-channel and mgmt TX.
Move setting it to mt76 core to keep it in one place.

Fixes: 69d54ce7491d0 ("wifi: mt76: mt7996: switch to single multi-radio wiphy")
Link: https://patch.msgid.link/20260324154904.2555603-2-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mac80211.c    | 2 ++
 drivers/net/wireless/mediatek/mt76/mt7615/init.c | 1 -
 drivers/net/wireless/mediatek/mt76/mt792x_core.c | 1 -
 3 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mac80211.c b/drivers/net/wireless/mediatek/mt76/mac80211.c
index b78b4cd206e064..dd09ef1bd0c25a 100644
--- a/drivers/net/wireless/mediatek/mt76/mac80211.c
+++ b/drivers/net/wireless/mediatek/mt76/mac80211.c
@@ -449,6 +449,8 @@ mt76_phy_init(struct mt76_phy *phy, struct ieee80211_hw *hw)
 	wiphy_ext_feature_set(wiphy, NL80211_EXT_FEATURE_AIRTIME_FAIRNESS);
 	wiphy_ext_feature_set(wiphy, NL80211_EXT_FEATURE_AQL);
 
+	if (!wiphy->max_remain_on_channel_duration)
+		wiphy->max_remain_on_channel_duration = 5000;
 	if (!wiphy->available_antennas_tx)
 		wiphy->available_antennas_tx = phy->antenna_mask;
 	if (!wiphy->available_antennas_rx)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7615/init.c b/drivers/net/wireless/mediatek/mt76/mt7615/init.c
index 42e11ba1206ee8..e437e088b2e913 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7615/init.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7615/init.c
@@ -195,7 +195,6 @@ mt7615_check_offload_capability(struct mt7615_dev *dev)
 		ieee80211_hw_set(hw, SUPPORTS_DYNAMIC_PS);
 
 		wiphy->flags &= ~WIPHY_FLAG_4ADDR_STATION;
-		wiphy->max_remain_on_channel_duration = 5000;
 		wiphy->features |= NL80211_FEATURE_SCHED_SCAN_RANDOM_MAC_ADDR |
 				   NL80211_FEATURE_SCAN_RANDOM_MAC_ADDR |
 				   WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL |
diff --git a/drivers/net/wireless/mediatek/mt76/mt792x_core.c b/drivers/net/wireless/mediatek/mt76/mt792x_core.c
index 152cfcca2f908a..5a5d7534830bba 100644
--- a/drivers/net/wireless/mediatek/mt76/mt792x_core.c
+++ b/drivers/net/wireless/mediatek/mt76/mt792x_core.c
@@ -657,7 +657,6 @@ int mt792x_init_wiphy(struct ieee80211_hw *hw)
 				 BIT(NL80211_IFTYPE_P2P_CLIENT) |
 				 BIT(NL80211_IFTYPE_P2P_GO) |
 				 BIT(NL80211_IFTYPE_P2P_DEVICE);
-	wiphy->max_remain_on_channel_duration = 5000;
 	wiphy->max_scan_ie_len = MT76_CONNAC_SCAN_IE_LEN;
 	wiphy->max_scan_ssids = 4;
 	wiphy->max_sched_scan_plan_interval =
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0582/2077] wifi: mt76: mt7996: Fix NULL pointer dereference in mt7996_init_tx_queues()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (580 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0581/2077] wifi: mt76: mt7996: add missing max_remain_on_channel_duration Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0583/2077] wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links Greg Kroah-Hartman
                   ` (415 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lorenzo Bianconi <lorenzo@kernel.org>

[ Upstream commit 6794edb55b5f5ef834e03b0b241b1a8b725f82c0 ]

When MT76_NPU and CONFIG_NET_MEDIATEK_SOC_WED are enabled and
mt76 detects properly the Airoha NPU SoC, mt7996_init_tx_queues() will
dereference a NULL WED pointer.
Fix the issue by always passing the WED pointer from mt7996_dma_init().

Fixes: cd7951f242a7 ("wifi: mt76: mt7996: Integrate MT7990 dma configuration for NPU")
Signed-off-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/20260418-mt7996-dma-init-npu-fix-v1-1-6b8dcffbcb57@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7996/dma.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/dma.c b/drivers/net/wireless/mediatek/mt76/mt7996/dma.c
index 8f5d297dafce23..3d9353811a02eb 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/dma.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/dma.c
@@ -683,7 +683,7 @@ int mt7996_dma_init(struct mt7996_dev *dev)
 		ret = mt7996_init_tx_queues(&dev->phy, MT_TXQ_ID(0),
 					    MT7996_NPU_TX_RING_SIZE,
 					    MT_TXQ_RING_BASE(0) + hif1_ofs,
-					    NULL);
+					    wed);
 	else
 		ret = mt7996_init_tx_queues(&dev->phy,
 					    MT_TXQ_ID(dev->mphy.band_idx),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0583/2077] wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (581 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0582/2077] wifi: mt76: mt7996: Fix NULL pointer dereference in mt7996_init_tx_queues() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0584/2077] wifi: mt76: mt7925: keep TX BA state in the primary WCID Greg Kroah-Hartman
                   ` (414 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Marcin FM, Cristian-Florin Radoi,
	George Salukvadze, Evgeny Kapusta, Samu Toljamo, Ariel Rosenfeld,
	Chapuis Dario, Thibaut François, 张旭涵,
	Sean Wang, Javier Tia, Felix Fietkau, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Javier Tia <floss@jetm.me>

[ Upstream commit 9f1accf3069a0cd42c14ca6c7d44d5b17cc48a80 ]

In the error path of mt7925_change_vif_links(), the free: label iterates
over link_ids to clean up, but compares against `mconf` and `mlink`
which hold stale values from the last loop iteration rather than the
current link_id being freed.

Use array-indexed access (mconfs[link_id] / mlinks[link_id]) to compare
against the correct per-link pointers.

Fixes: 69acd6d910b0 ("wifi: mt76: mt7925: add mt7925_change_vif_links")
Tested-by: Marcin FM <marcin@lgic.pl>
Tested-by: Cristian-Florin Radoi <radoi.chris@gmail.com>
Tested-by: George Salukvadze <giosal90@gmail.com>
Tested-by: Evgeny Kapusta <3193631@gmail.com>
Tested-by: Samu Toljamo <samu.toljamo@gmail.com>
Tested-by: Ariel Rosenfeld <ariel.rosenfeld.750@gmail.com>
Tested-by: Chapuis Dario <chapuisdario4@gmail.com>
Tested-by: Thibaut François <tibo@humeurlibre.fr>
Tested-by: 张旭涵 <Loong.0x00@gmail.com>
Reviewed-by: Sean Wang <sean.wang@mediatek.com>
Signed-off-by: Javier Tia <floss@jetm.me>
Link: https://patch.msgid.link/20260425195011.790265-2-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7925/main.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/main.c b/drivers/net/wireless/mediatek/mt76/mt7925/main.c
index 9dc5ee51eb9f96..8765121b916a26 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/main.c
@@ -2182,9 +2182,9 @@ mt7925_change_vif_links(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
 		rcu_assign_pointer(mvif->link_conf[link_id], NULL);
 		rcu_assign_pointer(mvif->sta.link[link_id], NULL);
 
-		if (mconf != &mvif->bss_conf)
+		if (mconfs[link_id] != &mvif->bss_conf)
 			devm_kfree(dev->mt76.dev, mconfs[link_id]);
-		if (mlink != &mvif->sta.deflink)
+		if (mlinks[link_id] != &mvif->sta.deflink)
 			devm_kfree(dev->mt76.dev, mlinks[link_id]);
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0584/2077] wifi: mt76: mt7925: keep TX BA state in the primary WCID
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (582 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0583/2077] wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0585/2077] wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX Greg Kroah-Hartman
                   ` (413 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yao Ting Hsieh, Sean Wang,
	Felix Fietkau, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Wang <sean.wang@mediatek.com>

[ Upstream commit d3c854068bad22a25db6515f12784f64c663fed2 ]

For MLO, the same TID can run over different links. Keeping TX BA state in
a link WCID makes the state depend on which link starts aggregation first.

Store it in the primary WCID instead, so the BA state stays stable across
links.

Fixes: 44eb173bdd4f ("wifi: mt76: mt7925: add link handling in mt7925_txwi_free")
Tested-by: Yao Ting Hsieh <yao-ting.hsieh@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260425154721.738101-1-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7925/mac.c | 15 +++++++--------
 1 file changed, 7 insertions(+), 8 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/mac.c b/drivers/net/wireless/mediatek/mt76/mt7925/mac.c
index c47bd812b66b9c..f025c0efeda217 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/mac.c
@@ -841,7 +841,6 @@ static void mt7925_tx_check_aggr(struct ieee80211_sta *sta, struct sk_buff *skb,
 {
 	struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
 	struct ieee80211_link_sta *link_sta;
-	struct mt792x_link_sta *mlink;
 	struct mt792x_sta *msta;
 	bool is_8023;
 	u16 fc, tid;
@@ -880,14 +879,14 @@ static void mt7925_tx_check_aggr(struct ieee80211_sta *sta, struct sk_buff *skb,
 
 	msta = (struct mt792x_sta *)sta->drv_priv;
 
-	if (sta->mlo && msta->deflink_id != IEEE80211_LINK_UNSPECIFIED)
-		mlink = rcu_dereference(msta->link[msta->deflink_id]);
-	else
-		mlink = &msta->deflink;
-
-	if (!test_and_set_bit(tid, &mlink->wcid.ampdu_state)) {
+	/* Packets belonging to the same TID can be transmitted over multiple
+	 * links. Keep the TX BA session state in the primary link so all links
+	 * share the same AMPDU bookkeeping.
+	 */
+	if (!test_and_set_bit(tid, &msta->deflink.wcid.ampdu_state)) {
 		if (ieee80211_start_tx_ba_session(sta, tid, 0))
-			clear_bit(tid, &mlink->wcid.ampdu_state);
+			clear_bit(tid, &msta->deflink.wcid.ampdu_state);
+
 	}
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0585/2077] wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (583 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0584/2077] wifi: mt76: mt7925: keep TX BA state in the primary WCID Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0586/2077] wifi: mt76: mt7925: validate skb length in testmode query Greg Kroah-Hartman
                   ` (412 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sean Wang, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Wang <sean.wang@mediatek.com>

[ Upstream commit a1152244702bb31b64650e5ca8308142286c0e4a ]

mt792x_tx() rewrites addr1/addr2/addr3 by treating skb->data as
an 802.11 header for MLD traffic.

That is only valid for native 802.11 frames. Direct 802.3 TX can also
reach this path with IEEE80211_TX_CTL_HW_80211_ENCAP set, where
skb->data is not an 802.11 header.

Skip the MLD header rewrite for HW-encap packets to avoid corrupting
802.3 frame contents.

Fixes: ebb1406813c6 ("wifi: mt76: mt7925: add link handling to txwi")
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260425144648.734030-1-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt792x_core.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt792x_core.c b/drivers/net/wireless/mediatek/mt76/mt792x_core.c
index 5a5d7534830bba..dc63400c1b996b 100644
--- a/drivers/net/wireless/mediatek/mt76/mt792x_core.c
+++ b/drivers/net/wireless/mediatek/mt76/mt792x_core.c
@@ -105,7 +105,8 @@ void mt792x_tx(struct ieee80211_hw *hw, struct ieee80211_tx_control *control,
 		wcid = &mvif->sta.deflink.wcid;
 	}
 
-	if (vif && control->sta && ieee80211_vif_is_mld(vif)) {
+	if (vif && control->sta && ieee80211_vif_is_mld(vif) &&
+	    !(info->flags & IEEE80211_TX_CTL_HW_80211_ENCAP)) {
 		struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
 		struct ieee80211_link_sta *link_sta;
 		struct ieee80211_bss_conf *conf;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0586/2077] wifi: mt76: mt7925: validate skb length in testmode query
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (584 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0585/2077] wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0587/2077] wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb() Greg Kroah-Hartman
                   ` (411 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Aviel Zohar, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aviel Zohar <avielzohar123@gmail.com>

[ Upstream commit c7369a00860a0704461d440e7c3bf9b49bfdbaee ]

In mt7925_tm_query(), the response skb from mt76_mcu_send_and_get_msg()
is used in a memcpy without validating its length:

  memcpy(evt_resp, skb->data + 8, MT7925_EVT_RSP_LEN);

where MT7925_EVT_RSP_LEN is 512. If the firmware returns a response
shorter than 520 bytes (8 + 512), this reads beyond the skb data
buffer. The over-read data is then returned to userspace via nla_put()
in mt7925_testmode_dump().

Add a length check before the memcpy to ensure the skb contains
sufficient data.

Fixes: c948b5da6bbe ("wifi: mt76: mt7925: add Mediatek Wi-Fi7 driver for mt7925 chips")
Signed-off-by: Aviel Zohar <avielzohar123@gmail.com>
Link: https://patch.msgid.link/20260413033136.5417-2-avielzohar123@gmail.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7925/testmode.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/testmode.c b/drivers/net/wireless/mediatek/mt76/mt7925/testmode.c
index 3d40aacfc011f5..22a8f1ddc321da 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/testmode.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/testmode.c
@@ -105,6 +105,11 @@ mt7925_tm_query(struct mt792x_dev *dev, struct mt7925_tm_cmd *req,
 	if (ret)
 		goto out;
 
+	if (skb->len < MT7925_EVT_RSP_LEN + 8) {
+		ret = -EINVAL;
+		goto out;
+	}
+
 	memcpy((char *)evt_resp, (char *)skb->data + 8, MT7925_EVT_RSP_LEN);
 
 out:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0587/2077] wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (585 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0586/2077] wifi: mt76: mt7925: validate skb length in testmode query Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0588/2077] wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211() Greg Kroah-Hartman
                   ` (410 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lorenzo Bianconi <lorenzo@kernel.org>

[ Upstream commit 831074096d0450308357271fc0ffd3f600a2487e ]

If link_conf or link_sta lookup fails in mt7996_tx_prepare_skb routine,
mt7996 driver leaks an already allocated tx token. Fix the issue
releasing the token in case of error.

Fixes: 7ef0c7ad735b0 ("wifi: mt76: mt7996: Implement MLD address translation for EAPOL")
Signed-off-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/20260531-mt7996_tx_prepare_skb-token-leack-v1-1-2b9c9f59ceb1@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7996/mac.c | 8 ++++++--
 drivers/net/wireless/mediatek/mt76/tx.c         | 2 +-
 2 files changed, 7 insertions(+), 3 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index e2a83da3a09c0a..09df505ee5a77e 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -1067,11 +1067,11 @@ int mt7996_tx_prepare_skb(struct mt76_dev *mdev, void *txwi_ptr,
 
 		link_conf = rcu_dereference(vif->link_conf[wcid->link_id]);
 		if (!link_conf)
-			return -EINVAL;
+			goto error_release_token;
 
 		link_sta = rcu_dereference(sta->link[wcid->link_id]);
 		if (!link_sta)
-			return -EINVAL;
+			goto error_release_token;
 
 		dma_sync_single_for_cpu(mdev->dma_dev, tx_info->buf[1].addr,
 					tx_info->buf[1].len, DMA_TO_DEVICE);
@@ -1176,6 +1176,10 @@ int mt7996_tx_prepare_skb(struct mt76_dev *mdev, void *txwi_ptr,
 	tx_info->nbuf = MT_CT_DMA_BUF_NUM;
 
 	return 0;
+
+error_release_token:
+	mt76_token_release(mdev, id, NULL);
+	return -EINVAL;
 }
 
 u32 mt7996_wed_init_buf(void *ptr, dma_addr_t phys, int token_id)
diff --git a/drivers/net/wireless/mediatek/mt76/tx.c b/drivers/net/wireless/mediatek/mt76/tx.c
index 22f9690634c942..f96d9c47185354 100644
--- a/drivers/net/wireless/mediatek/mt76/tx.c
+++ b/drivers/net/wireless/mediatek/mt76/tx.c
@@ -933,7 +933,7 @@ mt76_token_release(struct mt76_dev *dev, int token, bool *wake)
 #endif
 	}
 
-	if (dev->token_count < dev->token_size - MT76_TOKEN_FREE_THR &&
+	if (wake && dev->token_count < dev->token_size - MT76_TOKEN_FREE_THR &&
 	    dev->phy.q_tx[0]->blocked)
 		*wake = true;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0588/2077] wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (586 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0587/2077] wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0589/2077] wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add() Greg Kroah-Hartman
                   ` (409 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lorenzo Bianconi <lorenzo@kernel.org>

[ Upstream commit 61370e6674b5253de5686813ceeceebc35a7d3e5 ]

For injected frames (e.g. via radiotap), mac80211 can pass
info->control.vif = NULL, as explicitly noted in struct ieee80211_tx_info.
Check vif pointer before executing ieee80211_vif_is_mld() in
mt7996_mac_write_txwi_80211 routine in order to avoid a possible NULL
pointer dereference.

Fixes: f0b0b239b8f36 ("wifi: mt76: mt7996: rework mt7996_mac_write_txwi() for MLO support")
Signed-off-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/20260531-mt7996_mac_write_txwi_80211-null-ptr-deref-v1-1-6dd38e1d3422@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7996/mac.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index 09df505ee5a77e..7533146b772b35 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -757,6 +757,7 @@ mt7996_mac_write_txwi_80211(struct mt7996_dev *dev, __le32 *txwi,
 	bool multicast = is_multicast_ether_addr(hdr->addr1);
 	u8 tid = skb->priority & IEEE80211_QOS_CTL_TID_MASK;
 	__le16 fc = hdr->frame_control, sc = hdr->seq_ctrl;
+	struct ieee80211_vif *vif = info->control.vif;
 	u16 seqno = le16_to_cpu(sc);
 	bool hw_bigtk = false;
 	u8 fc_type, fc_stype;
@@ -819,7 +820,7 @@ mt7996_mac_write_txwi_80211(struct mt7996_dev *dev, __le32 *txwi,
 		txwi[3] |= cpu_to_le32(MT_TXD3_REM_TX_COUNT);
 	}
 
-	if (multicast && ieee80211_vif_is_mld(info->control.vif)) {
+	if (multicast && vif && ieee80211_vif_is_mld(vif)) {
 		val = MT_TXD3_SN_VALID |
 		      FIELD_PREP(MT_TXD3_SEQ, IEEE80211_SEQ_TO_SN(seqno));
 		txwi[3] |= cpu_to_le32(val);
@@ -839,12 +840,12 @@ mt7996_mac_write_txwi_80211(struct mt7996_dev *dev, __le32 *txwi,
 		txwi[3] &= ~cpu_to_le32(MT_TXD3_HW_AMSDU);
 	}
 
-	if (ieee80211_vif_is_mld(info->control.vif) &&
+	if (vif && ieee80211_vif_is_mld(vif) &&
 	    (multicast || unlikely(skb->protocol == cpu_to_be16(ETH_P_PAE))))
 		txwi[5] |= cpu_to_le32(MT_TXD5_FL);
 
 	if (ieee80211_is_nullfunc(fc) && ieee80211_has_a4(fc) &&
-	    ieee80211_vif_is_mld(info->control.vif)) {
+	    vif && ieee80211_vif_is_mld(vif)) {
 		txwi[5] |= cpu_to_le32(MT_TXD5_FL);
 		txwi[6] |= cpu_to_le32(MT_TXD6_DIS_MAT);
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0589/2077] wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (587 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0588/2077] wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0590/2077] wifi: mt76: mt7996: remove redundant pdev->bus check in probe Greg Kroah-Hartman
                   ` (408 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lorenzo Bianconi <lorenzo@kernel.org>

[ Upstream commit 729c83a3330c0a56662cd0d8e40db96d41c00a54 ]

mt76_tx_status_skb_add() zeroes the mt76_tx_cb struct stored at
info->status.status_driver_data via memset(). Since info->control and
info->status are members of the same union in ieee80211_tx_info,
this overwrites info->control.flags.
In mt7996_tx_prepare_skb(), mt76_tx_status_skb_add() is called before
mt7996_mac_write_txwi(), which re-reads info->control.flags to extract
IEEE80211_TX_CTRL_MLO_LINK. Because the field has been zeroed, the
link_id always resolves to 0 for frames using global_wcid, leading to
incorrect TXWI configuration.
Fix this by passing link_id as an explicit parameter to
mt7996_mac_write_txwi(). In mt7996_tx_prepare_skb(), the link_id is
already extracted from info->control.flags before the destructive
mt76_tx_status_skb_add() call. For the beacon and inband discovery
callers in mcu.c, use link_conf->link_id directly.

Fixes: f0b0b239b8f36 ("wifi: mt76: mt7996: rework mt7996_mac_write_txwi() for MLO support")
Signed-off-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/20260531-mt76_tx_status_skb_add-overwrite-fix-v2-1-b73c4b4a9798@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7996/mac.c    | 14 ++++----------
 drivers/net/wireless/mediatek/mt76/mt7996/mcu.c    |  5 +++--
 drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h |  3 ++-
 3 files changed, 9 insertions(+), 13 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index 7533146b772b35..ffa15f32c250c9 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -857,7 +857,8 @@ mt7996_mac_write_txwi_80211(struct mt7996_dev *dev, __le32 *txwi,
 void mt7996_mac_write_txwi(struct mt7996_dev *dev, __le32 *txwi,
 			   struct sk_buff *skb, struct mt76_wcid *wcid,
 			   struct ieee80211_key_conf *key, int pid,
-			   enum mt76_txq_id qid, u32 changed)
+			   enum mt76_txq_id qid, u32 changed,
+			   unsigned int link_id)
 {
 	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
 	struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
@@ -867,7 +868,6 @@ void mt7996_mac_write_txwi(struct mt7996_dev *dev, __le32 *txwi,
 	bool is_8023 = info->flags & IEEE80211_TX_CTL_HW_80211_ENCAP;
 	struct mt76_vif_link *mlink = NULL;
 	struct mt7996_vif *mvif;
-	unsigned int link_id;
 	u16 tx_count = 15;
 	u32 val;
 	bool inband_disc = !!(changed & (BSS_CHANGED_UNSOL_BCAST_PROBE_RESP |
@@ -875,17 +875,11 @@ void mt7996_mac_write_txwi(struct mt7996_dev *dev, __le32 *txwi,
 	bool beacon = !!(changed & (BSS_CHANGED_BEACON |
 				    BSS_CHANGED_BEACON_ENABLED)) && (!inband_disc);
 
-	if (wcid != &dev->mt76.global_wcid)
-		link_id = wcid->link_id;
-	else
-		link_id = u32_get_bits(info->control.flags,
-				       IEEE80211_TX_CTRL_MLO_LINK);
-
 	mvif = vif ? (struct mt7996_vif *)vif->drv_priv : NULL;
 	if (mvif) {
 		if (wcid->offchannel)
 			mlink = rcu_dereference(mvif->mt76.offchannel_link);
-		if (!mlink)
+		if (!mlink && link_id != IEEE80211_LINK_UNSPECIFIED)
 			mlink = rcu_dereference(mvif->mt76.link[link_id]);
 	}
 
@@ -1097,7 +1091,7 @@ int mt7996_tx_prepare_skb(struct mt76_dev *mdev, void *txwi_ptr,
 	/* Transmit non qos data by 802.11 header and need to fill txd by host*/
 	if (!is_8023 || pid >= MT_PACKET_ID_FIRST)
 		mt7996_mac_write_txwi(dev, txwi_ptr, tx_info->skb, wcid, key,
-				      pid, qid, 0);
+				      pid, qid, 0, link_id);
 
 	/* MT7996 and MT7992 require driver to provide the MAC TXP for AddBA
 	 * req
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
index 16420375112d1e..2748bfeb479744 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
@@ -3098,7 +3098,7 @@ mt7996_mcu_beacon_cont(struct mt7996_dev *dev,
 
 	buf = (u8 *)bcn + sizeof(*bcn);
 	mt7996_mac_write_txwi(dev, (__le32 *)buf, skb, wcid, NULL, 0, 0,
-			      BSS_CHANGED_BEACON);
+			      BSS_CHANGED_BEACON, link_conf->link_id);
 
 	memcpy(buf + MT_TXD_SIZE, skb->data, skb->len);
 }
@@ -3244,7 +3244,8 @@ int mt7996_mcu_beacon_inband_discov(struct mt7996_dev *dev,
 
 	buf = (u8 *)tlv + sizeof(*discov);
 
-	mt7996_mac_write_txwi(dev, (__le32 *)buf, skb, wcid, NULL, 0, 0, changed);
+	mt7996_mac_write_txwi(dev, (__le32 *)buf, skb, wcid, NULL, 0, 0,
+			      changed, link_conf->link_id);
 
 	memcpy(buf + MT_TXD_SIZE, skb->data, skb->len);
 
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h b/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
index bdcf7245795497..5f39a583bd3725 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
@@ -855,7 +855,8 @@ void mt7996_mac_enable_nf(struct mt7996_dev *dev, u8 band);
 void mt7996_mac_write_txwi(struct mt7996_dev *dev, __le32 *txwi,
 			   struct sk_buff *skb, struct mt76_wcid *wcid,
 			   struct ieee80211_key_conf *key, int pid,
-			   enum mt76_txq_id qid, u32 changed);
+			   enum mt76_txq_id qid, u32 changed,
+			   unsigned int link_id);
 void mt7996_mac_update_beacons(struct mt7996_phy *phy);
 void mt7996_mac_set_coverage_class(struct mt7996_phy *phy);
 void mt7996_mac_work(struct work_struct *work);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0590/2077] wifi: mt76: mt7996: remove redundant pdev->bus check in probe
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (588 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0589/2077] wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0591/2077] wifi: mt76: mt7996: limit work in set_bitrate_mask Greg Kroah-Hartman
                   ` (407 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lorenzo Bianconi <lorenzo@kernel.org>

[ Upstream commit 6b294950eaac246e6b0f42d74aa643ff36384c6e ]

Drop the unnecessary pdev->bus NULL check in mt7996_pci_probe() since
the pointer is already dereferenced earlier in mt76_pci_disable_aspm(),
making the check dead code. Silences the related Smatch warning.

Fixes: 377aa17d2aed ("wifi: mt76: mt7996: Add NPU offload support to MT7996 driver")
Signed-off-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/20260522-mt7996-pdev-bus-fix-v1-1-c91716484365@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7996/pci.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/pci.c b/drivers/net/wireless/mediatek/mt76/mt7996/pci.c
index 12523ddba63041..b7d9193e042f48 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/pci.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/pci.c
@@ -141,7 +141,7 @@ static int mt7996_pci_probe(struct pci_dev *pdev,
 	dev->hif2 = hif2;
 
 	mt76_npu_init(mdev, pci_resource_start(pdev, 0),
-		      pdev->bus && pci_domain_nr(pdev->bus) ? 3 : 2);
+		      pci_domain_nr(pdev->bus) ? 3 : 2);
 
 	ret = mt7996_mmio_wed_init(dev, pdev, false, &irq);
 	if (ret < 0)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0591/2077] wifi: mt76: mt7996: limit work in set_bitrate_mask
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (589 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0590/2077] wifi: mt76: mt7996: remove redundant pdev->bus check in probe Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0592/2077] wifi: mt76: fix argument to ieee80211_is_first_frag() Greg Kroah-Hartman
                   ` (406 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dylan Eskew, Lorenzo Bianconi,
	Felix Fietkau, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dylan Eskew <dylan.eskew@candelatech.com>

[ Upstream commit 5fd3385505600934f5faa9635e5b30fa38e548b9 ]

Calls to mt7996_set_bitrate_mask() would propagate work for all stations
on the ieee80211_hw regardless of the vif specified in the call. To
prevent unnecessary work in FW, limit setting the sta_rate to only the
specified vif in mt7996_sta_rate_ctrl_update().

Fixes: afff4325548f0 ("wifi: mt76: mt7996: Use proper link_id in link_sta_rc_update callback")
Signed-off-by: Dylan Eskew <dylan.eskew@candelatech.com>
Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/20260408145057.2356878-2-dylan.eskew@candelatech.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7996/main.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/main.c b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
index a8a6552d49f69a..26b8c91db0a81e 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
@@ -1959,7 +1959,11 @@ static void mt7996_sta_rate_ctrl_update(void *data, struct ieee80211_sta *sta)
 {
 	struct mt7996_sta *msta = (struct mt7996_sta *)sta->drv_priv;
 	struct mt7996_sta_link *msta_link;
-	u32 *changed = data;
+	struct mt7996_vif *mvif = data;
+	u32 changed = IEEE80211_RC_SUPP_RATES_CHANGED;
+
+	if (msta->vif != mvif)
+		return;
 
 	msta_link = rcu_dereference(msta->link[msta->deflink_id]);
 	if (msta_link)
@@ -1972,7 +1976,6 @@ mt7996_set_bitrate_mask(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
 {
 	struct mt7996_dev *dev = mt7996_hw_dev(hw);
 	struct mt7996_vif *mvif = (struct mt7996_vif *)vif->drv_priv;
-	u32 changed = IEEE80211_RC_SUPP_RATES_CHANGED;
 
 	mvif->deflink.bitrate_mask = *mask;
 
@@ -1985,7 +1988,7 @@ mt7996_set_bitrate_mask(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
 	 * then multiple MCS setting (MCS 4,5,6) is not supported.
 	 */
 	ieee80211_iterate_stations_atomic(hw, mt7996_sta_rate_ctrl_update,
-					  &changed);
+					  mvif);
 	ieee80211_queue_work(hw, &dev->rc_work);
 
 	return 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0592/2077] wifi: mt76: fix argument to ieee80211_is_first_frag()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (590 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0591/2077] wifi: mt76: mt7996: limit work in set_bitrate_mask Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0593/2077] wifi: mt76: mt7915: fix potential tx_retries underflow Greg Kroah-Hartman
                   ` (405 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bjoern A. Zeeb, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bjoern A. Zeeb <bz@FreeBSD.org>

[ Upstream commit 5832743279da8c6ae72f715bad2f7141eca6f4b8 ]

ieee80211_is_first_frag() operates on the seq_ctrl not the frame_control
header field. Pass the correct one in; otherwise the results may vary.

Sponsored by: The FreeBSD Foundation
Fixes: 30ce7f4456ae4 ("mt76: validate rx CCMP PN")
Link: https://cgit.freebsd.org/src/commit/sys/contrib/dev/mediatek/mt76/mac80211.c?id=c67fd35e58c6ee1e19877a7fe5998885683abedc
Signed-off-by: Bjoern A. Zeeb <bz@FreeBSD.org>
Link: https://patch.msgid.link/83s4psnr-popo-8789-757o-npr2n9n7rs2o@SerrOFQ.bet
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mac80211.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mac80211.c b/drivers/net/wireless/mediatek/mt76/mac80211.c
index dd09ef1bd0c25a..13c4e8abe28191 100644
--- a/drivers/net/wireless/mediatek/mt76/mac80211.c
+++ b/drivers/net/wireless/mediatek/mt76/mac80211.c
@@ -1323,7 +1323,7 @@ mt76_check_ccmp_pn(struct sk_buff *skb)
 		 * All further fragments will be validated by mac80211 only.
 		 */
 		if (ieee80211_is_frag(hdr) &&
-		    !ieee80211_is_first_frag(hdr->frame_control))
+		    !ieee80211_is_first_frag(hdr->seq_ctrl))
 			return;
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0593/2077] wifi: mt76: mt7915: fix potential tx_retries underflow
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (591 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0592/2077] wifi: mt76: fix argument to ieee80211_is_first_frag() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0594/2077] wifi: mt76: mt7921: " Greg Kroah-Hartman
                   ` (404 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ryder Lee, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ryder Lee <ryder.lee@mediatek.com>

[ Upstream commit 05e72b6167970043348bfbe8f72a3b67a38a9f1c ]

When FIELD_GET returns 0 for the retry count, subtracting 1 causes
an unsigned integer underflow, resulting in tx_retries becoming a
very large value (0xFFFFFFFF for u32).

Fix by checking if count is non-zero before subtracting 1.

Fixes: 943e4fb96e6f ("wifi: mt76: mt7915: report tx retries/failed counts for non-WED path")
Signed-off-by: Ryder Lee <ryder.lee@mediatek.com>
Link: https://patch.msgid.link/20260605113306.3485554-1-ryder.lee@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7915/mac.c | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/mac.c b/drivers/net/wireless/mediatek/mt76/mt7915/mac.c
index cec2c4208255fd..334c19ab2b22ca 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/mac.c
@@ -912,16 +912,16 @@ mt7915_mac_tx_free(struct mt7915_dev *dev, void *data, int len)
 		}
 
 		if (!mtk_wed_device_active(&mdev->mmio.wed) && wcid) {
-			u32 tx_retries = 0, tx_failed = 0;
+			u32 tx_retries = 0, tx_failed = 0, count;
 
 			if (v3 && (info & MT_TX_FREE_MPDU_HEADER_V3)) {
-				tx_retries =
-					FIELD_GET(MT_TX_FREE_COUNT_V3, info) - 1;
+				count = FIELD_GET(MT_TX_FREE_COUNT_V3, info);
+				tx_retries = count ? count - 1 : 0;
 				tx_failed = tx_retries +
 					!!FIELD_GET(MT_TX_FREE_STAT_V3, info);
 			} else if (!v3 && (info & MT_TX_FREE_MPDU_HEADER)) {
-				tx_retries =
-					FIELD_GET(MT_TX_FREE_COUNT, info) - 1;
+				count = FIELD_GET(MT_TX_FREE_COUNT, info);
+				tx_retries = count ? count - 1 : 0;
 				tx_failed = tx_retries +
 					!!FIELD_GET(MT_TX_FREE_STAT, info);
 			}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0594/2077] wifi: mt76: mt7921: fix potential tx_retries underflow
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (592 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0593/2077] wifi: mt76: mt7915: fix potential tx_retries underflow Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0595/2077] wifi: mt76: mt7925: " Greg Kroah-Hartman
                   ` (403 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ryder Lee, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ryder Lee <ryder.lee@mediatek.com>

[ Upstream commit 3c5671ed81b1fff97fa868dae771690599db94f7 ]

When FIELD_GET returns 0 for the retry count, subtracting 1 causes
an unsigned integer underflow, resulting in tx_retries becoming a
very large value (0xFFFFFFFF for u32).

Fix by checking if count is non-zero before subtracting 1.

Fixes: 9aecfa754c7f ("wifi: mt76: mt7921e: report tx retries/failed counts in tx free event")
Signed-off-by: Ryder Lee <ryder.lee@mediatek.com>
Link: https://patch.msgid.link/20260605113306.3485554-2-ryder.lee@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7921/mac.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7921/mac.c b/drivers/net/wireless/mediatek/mt76/mt7921/mac.c
index 03b4960db73f0b..668bfa19538078 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7921/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7921/mac.c
@@ -530,8 +530,9 @@ static void mt7921_mac_tx_free(struct mt792x_dev *dev, void *data, int len)
 		stat = FIELD_GET(MT_TX_FREE_STATUS, info);
 
 		if (wcid) {
-			wcid->stats.tx_retries +=
-				FIELD_GET(MT_TX_FREE_COUNT, info) - 1;
+			u32 count = FIELD_GET(MT_TX_FREE_COUNT, info);
+
+			wcid->stats.tx_retries += count ? count - 1 : 0;
 			wcid->stats.tx_failed += !!stat;
 		}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0595/2077] wifi: mt76: mt7925: fix potential tx_retries underflow
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (593 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0594/2077] wifi: mt76: mt7921: " Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0596/2077] wifi: mt76: mt7996: " Greg Kroah-Hartman
                   ` (402 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ryder Lee, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ryder Lee <ryder.lee@mediatek.com>

[ Upstream commit 1e1fd84571e62a2961cea44c053340ec5c99b2cb ]

When FIELD_GET returns 0 for the retry count, subtracting 1 causes
an unsigned integer underflow, resulting in tx_retries becoming a
very large value (0xFFFFFFFF for u32).

Fix by checking if count is non-zero before subtracting 1.

Fixes: c948b5da6bbe ("wifi: mt76: mt7925: add Mediatek Wi-Fi7 driver for mt7925 chips")
Signed-off-by: Ryder Lee <ryder.lee@mediatek.com>
Link: https://patch.msgid.link/20260605113306.3485554-3-ryder.lee@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7925/mac.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/mac.c b/drivers/net/wireless/mediatek/mt76/mt7925/mac.c
index f025c0efeda217..50034d7c04f0cf 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/mac.c
@@ -1140,8 +1140,9 @@ mt7925_mac_tx_free(struct mt792x_dev *dev, void *data, int len)
 
 		if (info & MT_TXFREE_INFO_HEADER) {
 			if (wcid) {
-				wcid->stats.tx_retries +=
-					FIELD_GET(MT_TXFREE_INFO_COUNT, info) - 1;
+				u32 count = FIELD_GET(MT_TXFREE_INFO_COUNT, info);
+
+				wcid->stats.tx_retries += count ? count - 1 : 0;
 				wcid->stats.tx_failed +=
 					!!FIELD_GET(MT_TXFREE_INFO_STAT, info);
 			}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0596/2077] wifi: mt76: mt7996: fix potential tx_retries underflow
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (594 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0595/2077] wifi: mt76: mt7925: " Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0597/2077] btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() Greg Kroah-Hartman
                   ` (401 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ryder Lee, Felix Fietkau,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ryder Lee <ryder.lee@mediatek.com>

[ Upstream commit 4d8bba99d645bcb46a442b18eb42402610cba03a ]

When FIELD_GET returns 0 for the retry count, subtracting 1 causes
an unsigned integer underflow, resulting in tx_retries becoming a
very large value (0xFFFFFFFF for u32).

Fix by checking if count is non-zero before subtracting 1.

Fixes: 2461599f835e ("wifi: mt76: mt7996: get tx_retries and tx_failed from txfree")
Signed-off-by: Ryder Lee <ryder.lee@mediatek.com>
Link: https://patch.msgid.link/20260605113306.3485554-4-ryder.lee@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/mediatek/mt76/mt7996/mac.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index ffa15f32c250c9..2a0511b2e4d29e 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -1359,13 +1359,13 @@ mt7996_mac_tx_free(struct mt7996_dev *dev, void *data, int len)
 				cur_info++;
 			continue;
 		} else if (info & MT_TXFREE_INFO_HEADER) {
-			u32 tx_retries = 0, tx_failed = 0;
+			u32 tx_retries = 0, tx_failed = 0, count;
 
 			if (!wcid)
 				continue;
 
-			tx_retries =
-				FIELD_GET(MT_TXFREE_INFO_COUNT, info) - 1;
+			count = FIELD_GET(MT_TXFREE_INFO_COUNT, info);
+			tx_retries = count ? count - 1 : 0;
 			tx_failed = tx_retries +
 				!!FIELD_GET(MT_TXFREE_INFO_STAT, info);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0597/2077] btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (595 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0596/2077] wifi: mt76: mt7996: " Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0598/2077] ALSA: aloop: Drop superfluous break Greg Kroah-Hartman
                   ` (400 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Boris Burkov,
	Qu Wenruo, Filipe Manana, David Sterba, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Filipe Manana <fdmanana@suse.com>

[ Upstream commit 486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae ]

In the beginning of the loop, we try to obtain a locked delayed ref head,
if 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(),
which can return an error pointer. If the error pointer is -EAGAIN we do
a continue and go back to the beginning of the loop, which will not try
again to call btrfs_select_ref_head() since 'locked_ref' is no longer
NULL but it's ERR_PTR(-EAGAIN), and then we do:

   spin_lock(&locked_ref->lock);

against a ERR_PTR(-EAGAIN) value, generating an invalid pointer
dereference.

Fix this by ensuring that 'locked_ref' is set to NULL when
btrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count'
as well, to prevent infinite looping. We do this by doing a goto to the
bottom of the loop that already sets 'locked_ref' to NULL and does a
cond_resched(), with an increment to 'count' right before the goto.
These measures were in place before the refactoring in commit 0110a4c43451
("btrfs: refactor __btrfs_run_delayed_refs loop") but were unintentionally
lost afterwards.

Reported-by: Dan Carpenter <error27@gmail.com>
Link: https://lore.kernel.org/linux-btrfs/ag8ARRwykv8bpJ87@stanley.mountain/
Fixes: 0110a4c43451 ("btrfs: refactor __btrfs_run_delayed_refs loop")
Reviewed-by: Boris Burkov <boris@bur.io>
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/btrfs/extent-tree.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/fs/btrfs/extent-tree.c b/fs/btrfs/extent-tree.c
index a8c77f31ff7843..70d1f7ead160fc 100644
--- a/fs/btrfs/extent-tree.c
+++ b/fs/btrfs/extent-tree.c
@@ -2108,7 +2108,8 @@ static noinline int __btrfs_run_delayed_refs(struct btrfs_trans_handle *trans,
 			locked_ref = btrfs_select_ref_head(fs_info, delayed_refs);
 			if (IS_ERR_OR_NULL(locked_ref)) {
 				if (PTR_ERR(locked_ref) == -EAGAIN) {
-					continue;
+					count++;
+					goto again;
 				} else {
 					break;
 				}
@@ -2156,7 +2157,7 @@ static noinline int __btrfs_run_delayed_refs(struct btrfs_trans_handle *trans,
 		 * Either success case or btrfs_run_delayed_refs_for_head
 		 * returned -EAGAIN, meaning we need to select another head
 		 */
-
+again:
 		locked_ref = NULL;
 		cond_resched();
 	} while ((min_bytes != U64_MAX && bytes_processed < min_bytes) ||
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0598/2077] ALSA: aloop: Drop superfluous break
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (596 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0597/2077] btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0599/2077] gpio: mt7621: fix interrupt banks mapping on gpio chips Greg Kroah-Hartman
                   ` (399 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Takashi Iwai <tiwai@suse.de>

[ Upstream commit 123fd13f35ccaf7d2b98f5a8cc6c8a3de378568d ]

At converting the spinlock to guard(), a break statement was put in
the scoped_guard block in loopback_jiffies_timer_function(), but it's
obviously superfluous (although it's harmless).  Better to drop it for
avoiding confusion.

Fixes: 1ef2cb6b29c2 ("ALSA: aloop: Use guard() for spin locks")
Link: https://patch.msgid.link/20260609074907.726593-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/drivers/aloop.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/sound/drivers/aloop.c b/sound/drivers/aloop.c
index a37a1695f51c7d..3f8488716a0827 100644
--- a/sound/drivers/aloop.c
+++ b/sound/drivers/aloop.c
@@ -728,7 +728,6 @@ static void loopback_jiffies_timer_function(struct timer_list *t)
 			if (dpcm->period_update_pending) {
 				dpcm->period_update_pending = 0;
 				period_elapsed = true;
-				break;
 			}
 		}
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0599/2077] gpio: mt7621: fix interrupt banks mapping on gpio chips
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (597 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0598/2077] ALSA: aloop: Drop superfluous break Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0600/2077] wifi: ath12k: fix EAPOL TX failure caused by stale tcl_metadata bits Greg Kroah-Hartman
                   ` (398 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Vicente Bergas, Sergio Paracuellos,
	Bartosz Golaszewski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sergio Paracuellos <sergio.paracuellos@gmail.com>

[ Upstream commit a46f2e5720f5670feda145709d1f0d20be5c7263 ]

The GPIO controller's registers are organized as sets of eight 32-bit
registers with each set controlling a bank of up to 32 pins. A single
interrupt is shared for all of the banks handled by the controller.
The driver implements this using three gpio chip instances every one
with its own irq chip. Every single pin can generate interrupts having
a total of 96 possible interrupts here. It looks like there is a problem
with interrupts being properly mapped to the gpio bank using this solution.
This problem report is in the following lore's link [0].

Device tree is using two cells for this, so only the interrupt pin and the
interrupt type are described there. Changing to have three cells to setup
also the bank and implement 'of_node_instance_match()' would also work but
this would be an ABI breakage and also a bit incoherent since gpios itself
are also using two cells and properly mapped in desired bank using through
its pin number on 'of_xlate()'.

That said, register a linear IRQ domain of the total of 96 interrupts shared
with the three gpio chip instances so the bank and the interrupt is properly
decoded and devices using gpio IRQs properly work.

[0]: https://lore.kernel.org/linux-gpio/CAAMcf8C_A9dJ_v4QRKtb9eGNOpJ7BZNOGsFP4i2WFOZxOVBPnQ@mail.gmail.com/T/#u

Fixes: 4ba9c3afda41 ("gpio: mt7621: Add a driver for MT7621")
Co-developed-by: Vicente Bergas <vicencb@gmail.com>
Signed-off-by: Vicente Bergas <vicencb@gmail.com>
Tested-by: Vicente Bergas <vicencb@gmail.com>
Signed-off-by: Sergio Paracuellos <sergio.paracuellos@gmail.com>
Link: https://patch.msgid.link/20260609031118.2275735-1-sergio.paracuellos@gmail.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpio/gpio-mt7621.c | 282 ++++++++++++++++++++++++++++---------
 1 file changed, 216 insertions(+), 66 deletions(-)

diff --git a/drivers/gpio/gpio-mt7621.c b/drivers/gpio/gpio-mt7621.c
index 91230be5158790..a814885ccd5d11 100644
--- a/drivers/gpio/gpio-mt7621.c
+++ b/drivers/gpio/gpio-mt7621.c
@@ -29,8 +29,8 @@
 #define GPIO_REG_EDGE		0xA0
 
 struct mtk_gc {
-	struct irq_chip irq_chip;
 	struct gpio_generic_chip chip;
+	struct mtk *parent_priv;
 	int bank;
 	u32 rising;
 	u32 falling;
@@ -41,20 +41,32 @@ struct mtk_gc {
 /**
  * struct mtk - state container for
  * data of the platform driver. It is 3
- * separate gpio-chip each one with its
- * own irq_chip.
- * @dev: device instance
+ * separate gpio-chip having an IRQ
+ * linear domain shared for all of them
+ * @pdev: platform device instance
  * @base: memory base address
+ * @irq_domain: IRQ linear domain shared across the three gpio chips
  * @gpio_irq: irq number from the device tree
+ * @num_gpios: total number of gpio pins on the three gpio chips
  * @gc_map: array of the gpio chips
  */
 struct mtk {
-	struct device *dev;
+	struct platform_device *pdev;
 	void __iomem *base;
+	struct irq_domain *irq_domain;
 	int gpio_irq;
+	int num_gpios;
 	struct mtk_gc gc_map[MTK_BANK_CNT];
 };
 
+static inline struct mtk *
+mt7621_gpio_gc_to_priv(struct gpio_chip *gc)
+{
+	struct mtk_gc *bank = gpiochip_get_data(gc);
+
+	return bank->parent_priv;
+}
+
 static inline struct mtk_gc *
 to_mediatek_gpio(struct gpio_chip *chip)
 {
@@ -67,7 +79,7 @@ static inline void
 mtk_gpio_w32(struct mtk_gc *rg, u32 offset, u32 val)
 {
 	struct gpio_chip *gc = &rg->chip.gc;
-	struct mtk *mtk = gpiochip_get_data(gc);
+	struct mtk *mtk = mt7621_gpio_gc_to_priv(gc);
 
 	offset = (rg->bank * GPIO_BANK_STRIDE) + offset;
 	gpio_generic_write_reg(&rg->chip, mtk->base + offset, val);
@@ -77,41 +89,62 @@ static inline u32
 mtk_gpio_r32(struct mtk_gc *rg, u32 offset)
 {
 	struct gpio_chip *gc = &rg->chip.gc;
-	struct mtk *mtk = gpiochip_get_data(gc);
+	struct mtk *mtk = mt7621_gpio_gc_to_priv(gc);
 
 	offset = (rg->bank * GPIO_BANK_STRIDE) + offset;
 	return gpio_generic_read_reg(&rg->chip, mtk->base + offset);
 }
 
-static irqreturn_t
-mediatek_gpio_irq_handler(int irq, void *data)
+static void
+mt7621_gpio_irq_bank_handler(struct mtk_gc *bank)
 {
-	struct gpio_chip *gc = data;
-	struct mtk_gc *rg = to_mediatek_gpio(gc);
-	irqreturn_t ret = IRQ_NONE;
+	struct mtk *priv = bank->parent_priv;
+	struct irq_domain *domain = priv->irq_domain;
+	int hwbase = bank->chip.gc.offset;
 	unsigned long pending;
-	int bit;
+	unsigned int offset;
+
+	pending = mtk_gpio_r32(bank, GPIO_REG_STAT);
+	if (!pending)
+		return;
+
+	mtk_gpio_w32(bank, GPIO_REG_STAT, pending);
+
+	for_each_set_bit(offset, &pending, MTK_BANK_WIDTH)
+		generic_handle_domain_irq(domain, hwbase + offset);
+}
+
+static void
+mt7621_gpio_irq_handler(struct irq_desc *desc)
+{
+	struct mtk *priv = irq_desc_get_handler_data(desc);
+	struct irq_chip *chip = irq_desc_get_chip(desc);
+	int i;
 
-	pending = mtk_gpio_r32(rg, GPIO_REG_STAT);
+	chained_irq_enter(chip, desc);
+	for (i = 0; i < MTK_BANK_CNT; i++) {
+		struct mtk_gc *bank = &priv->gc_map[i];
 
-	for_each_set_bit(bit, &pending, MTK_BANK_WIDTH) {
-		generic_handle_domain_irq(gc->irq.domain, bit);
-		mtk_gpio_w32(rg, GPIO_REG_STAT, BIT(bit));
-		ret |= IRQ_HANDLED;
+		mt7621_gpio_irq_bank_handler(bank);
 	}
+	chained_irq_exit(chip, desc);
+}
 
-	return ret;
+static int
+mt7621_gpio_hwirq_to_offset(irq_hw_number_t hwirq, struct mtk_gc *bank)
+{
+	return hwirq - bank->chip.gc.offset;
 }
 
 static void
 mediatek_gpio_irq_unmask(struct irq_data *d)
 {
 	struct gpio_chip *gc = irq_data_get_irq_chip_data(d);
-	struct mtk_gc *rg = to_mediatek_gpio(gc);
-	int pin = d->hwirq;
+	struct mtk_gc *rg = gpiochip_get_data(gc);
+	u32 mask = mt7621_gpio_hwirq_to_offset(d->hwirq, rg);
 	u32 rise, fall, high, low;
 
-	gpiochip_enable_irq(gc, d->hwirq);
+	gpiochip_enable_irq(gc, mask);
 
 	guard(gpio_generic_lock_irqsave)(&rg->chip);
 
@@ -119,18 +152,18 @@ mediatek_gpio_irq_unmask(struct irq_data *d)
 	fall = mtk_gpio_r32(rg, GPIO_REG_FEDGE);
 	high = mtk_gpio_r32(rg, GPIO_REG_HLVL);
 	low = mtk_gpio_r32(rg, GPIO_REG_LLVL);
-	mtk_gpio_w32(rg, GPIO_REG_REDGE, rise | (BIT(pin) & rg->rising));
-	mtk_gpio_w32(rg, GPIO_REG_FEDGE, fall | (BIT(pin) & rg->falling));
-	mtk_gpio_w32(rg, GPIO_REG_HLVL, high | (BIT(pin) & rg->hlevel));
-	mtk_gpio_w32(rg, GPIO_REG_LLVL, low | (BIT(pin) & rg->llevel));
+	mtk_gpio_w32(rg, GPIO_REG_REDGE, rise | (BIT(mask) & rg->rising));
+	mtk_gpio_w32(rg, GPIO_REG_FEDGE, fall | (BIT(mask) & rg->falling));
+	mtk_gpio_w32(rg, GPIO_REG_HLVL, high | (BIT(mask) & rg->hlevel));
+	mtk_gpio_w32(rg, GPIO_REG_LLVL, low | (BIT(mask) & rg->llevel));
 }
 
 static void
 mediatek_gpio_irq_mask(struct irq_data *d)
 {
 	struct gpio_chip *gc = irq_data_get_irq_chip_data(d);
-	struct mtk_gc *rg = to_mediatek_gpio(gc);
-	int pin = d->hwirq;
+	struct mtk_gc *rg = gpiochip_get_data(gc);
+	u32 mask = mt7621_gpio_hwirq_to_offset(d->hwirq, rg);
 	u32 rise, fall, high, low;
 
 	scoped_guard(gpio_generic_lock_irqsave, &rg->chip) {
@@ -138,22 +171,21 @@ mediatek_gpio_irq_mask(struct irq_data *d)
 		fall = mtk_gpio_r32(rg, GPIO_REG_FEDGE);
 		high = mtk_gpio_r32(rg, GPIO_REG_HLVL);
 		low = mtk_gpio_r32(rg, GPIO_REG_LLVL);
-		mtk_gpio_w32(rg, GPIO_REG_FEDGE, fall & ~BIT(pin));
-		mtk_gpio_w32(rg, GPIO_REG_REDGE, rise & ~BIT(pin));
-		mtk_gpio_w32(rg, GPIO_REG_HLVL, high & ~BIT(pin));
-		mtk_gpio_w32(rg, GPIO_REG_LLVL, low & ~BIT(pin));
+		mtk_gpio_w32(rg, GPIO_REG_FEDGE, fall & ~BIT(mask));
+		mtk_gpio_w32(rg, GPIO_REG_REDGE, rise & ~BIT(mask));
+		mtk_gpio_w32(rg, GPIO_REG_HLVL, high & ~BIT(mask));
+		mtk_gpio_w32(rg, GPIO_REG_LLVL, low & ~BIT(mask));
 	}
 
-	gpiochip_disable_irq(gc, d->hwirq);
+	gpiochip_disable_irq(gc, mask);
 }
 
 static int
 mediatek_gpio_irq_type(struct irq_data *d, unsigned int type)
 {
 	struct gpio_chip *gc = irq_data_get_irq_chip_data(d);
-	struct mtk_gc *rg = to_mediatek_gpio(gc);
-	int pin = d->hwirq;
-	u32 mask = BIT(pin);
+	struct mtk_gc *rg = gpiochip_get_data(gc);
+	u32 mask = BIT(mt7621_gpio_hwirq_to_offset(d->hwirq, rg));
 
 	if (type == IRQ_TYPE_PROBE) {
 		if ((rg->rising | rg->falling |
@@ -190,6 +222,26 @@ mediatek_gpio_irq_type(struct irq_data *d, unsigned int type)
 	return 0;
 }
 
+static int
+mt7621_gpio_irq_reqres(struct irq_data *d)
+{
+	struct gpio_chip *gc = irq_data_get_irq_chip_data(d);
+	struct mtk_gc *rg = gpiochip_get_data(gc);
+	unsigned int irq = mt7621_gpio_hwirq_to_offset(d->hwirq, rg);
+
+	return gpiochip_reqres_irq(gc, irq);
+}
+
+static void
+mt7621_gpio_irq_relres(struct irq_data *d)
+{
+	struct gpio_chip *gc = irq_data_get_irq_chip_data(d);
+	struct mtk_gc *rg = gpiochip_get_data(gc);
+	unsigned int irq = mt7621_gpio_hwirq_to_offset(d->hwirq, rg);
+
+	gpiochip_relres_irq(gc, irq);
+}
+
 static int
 mediatek_gpio_xlate(struct gpio_chip *chip,
 		    const struct of_phandle_args *spec, u32 *flags)
@@ -208,14 +260,123 @@ mediatek_gpio_xlate(struct gpio_chip *chip,
 
 static const struct irq_chip mt7621_irq_chip = {
 	.name		= "mt7621-gpio",
+	.irq_request_resources = mt7621_gpio_irq_reqres,
+	.irq_release_resources = mt7621_gpio_irq_relres,
 	.irq_mask_ack	= mediatek_gpio_irq_mask,
 	.irq_mask	= mediatek_gpio_irq_mask,
 	.irq_unmask	= mediatek_gpio_irq_unmask,
 	.irq_set_type	= mediatek_gpio_irq_type,
 	.flags		= IRQCHIP_IMMUTABLE,
-	GPIOCHIP_IRQ_RESOURCE_HELPERS,
+};
+
+static void
+mt7621_gpio_remove(struct platform_device *pdev)
+{
+	struct mtk *priv = platform_get_drvdata(pdev);
+	int offset, virq;
+
+	if (priv->gpio_irq > 0)
+		irq_set_chained_handler_and_data(priv->gpio_irq, NULL, NULL);
+
+	/* Remove all IRQ mappings and delete the domain */
+	if (priv->irq_domain) {
+		for (offset = 0; offset < priv->num_gpios; offset++) {
+			virq = irq_find_mapping(priv->irq_domain, offset);
+			irq_dispose_mapping(virq);
+		}
+		irq_domain_remove(priv->irq_domain);
+	}
+}
+
+static struct mtk_gc *
+mt7621_gpio_hwirq_to_bank(struct mtk *priv, irq_hw_number_t hwirq)
+{
+	int i;
+
+	for (i = 0; i < MTK_BANK_CNT; i++) {
+		struct mtk_gc *bank = &priv->gc_map[i];
+
+		if (hwirq >= bank->chip.gc.offset &&
+		    hwirq < (bank->chip.gc.offset + bank->chip.gc.ngpio))
+			return bank;
+	}
+
+	return NULL;
+}
+
+static int
+mt7621_gpio_irq_map(struct irq_domain *d, unsigned int irq,
+		    irq_hw_number_t hwirq)
+{
+	struct mtk *priv = d->host_data;
+	struct mtk_gc *bank = mt7621_gpio_hwirq_to_bank(priv, hwirq);
+	struct platform_device *pdev = priv->pdev;
+	int ret;
+
+	if (!bank)
+		return -EINVAL;
+
+	dev_dbg(&pdev->dev, "Mapping irq %d for gpio line %d (bank %d)\n",
+		irq, (int)hwirq, bank->bank);
+
+	ret = irq_set_chip_data(irq, &bank->chip.gc);
+	if (ret < 0)
+		return ret;
+
+	irq_set_chip_and_handler(irq, &mt7621_irq_chip, handle_simple_irq);
+	irq_set_noprobe(irq);
+
+	return 0;
+}
+
+static void
+mt7621_gpio_irq_unmap(struct irq_domain *d, unsigned int irq)
+{
+	irq_set_chip_and_handler(irq, NULL, NULL);
+	irq_set_chip_data(irq, NULL);
+}
+
+static const struct irq_domain_ops mt7621_gpio_irq_domain_ops = {
+	.map = mt7621_gpio_irq_map,
+	.unmap = mt7621_gpio_irq_unmap,
+	.xlate = irq_domain_xlate_twocell,
 };
 
+static int
+mt7621_gpio_irq_setup(struct platform_device *pdev,
+		      struct mtk *priv)
+{
+	struct device *dev = &pdev->dev;
+
+	priv->irq_domain = irq_domain_create_linear(dev_fwnode(dev),
+						    priv->num_gpios,
+						    &mt7621_gpio_irq_domain_ops,
+						    priv);
+	if (!priv->irq_domain) {
+		dev_err(dev, "Couldn't allocate IRQ domain\n");
+		return -ENXIO;
+	}
+
+	irq_set_chained_handler_and_data(priv->gpio_irq,
+					 mt7621_gpio_irq_handler, priv);
+	irq_set_status_flags(priv->gpio_irq, IRQ_DISABLE_UNLAZY);
+
+	return 0;
+}
+
+static int
+mt7621_gpio_to_irq(struct gpio_chip *gc, unsigned int offset)
+{
+	struct mtk *priv = mt7621_gpio_gc_to_priv(gc);
+	/* gc_offset is relative to this gpio_chip; want real offset */
+	int hwirq = offset + gc->offset;
+
+	if (hwirq >= priv->num_gpios)
+		return -ENXIO;
+
+	return irq_create_mapping(priv->irq_domain, hwirq);
+}
+
 static int
 mediatek_gpio_bank_probe(struct device *dev, int bank)
 {
@@ -228,6 +389,7 @@ mediatek_gpio_bank_probe(struct device *dev, int bank)
 	rg = &mtk->gc_map[bank];
 	memset(rg, 0, sizeof(*rg));
 
+	rg->parent_priv = mtk;
 	rg->bank = bank;
 
 	dat = mtk->base + GPIO_REG_DATA + (rg->bank * GPIO_BANK_STRIDE);
@@ -253,41 +415,17 @@ mediatek_gpio_bank_probe(struct device *dev, int bank)
 
 	rg->chip.gc.of_gpio_n_cells = 2;
 	rg->chip.gc.of_xlate = mediatek_gpio_xlate;
+	rg->chip.gc.ngpio = MTK_BANK_WIDTH;
 	rg->chip.gc.label = devm_kasprintf(dev, GFP_KERNEL, "%s-bank%d",
 					dev_name(dev), bank);
 	if (!rg->chip.gc.label)
 		return -ENOMEM;
 
 	rg->chip.gc.offset = bank * MTK_BANK_WIDTH;
+	if (mtk->gpio_irq > 0)
+		rg->chip.gc.to_irq = mt7621_gpio_to_irq;
 
-	if (mtk->gpio_irq) {
-		struct gpio_irq_chip *girq;
-
-		/*
-		 * Directly request the irq here instead of passing
-		 * a flow-handler because the irq is shared.
-		 */
-		ret = devm_request_irq(dev, mtk->gpio_irq,
-				       mediatek_gpio_irq_handler, IRQF_SHARED,
-				       rg->chip.gc.label, &rg->chip.gc);
-
-		if (ret) {
-			dev_err(dev, "Error requesting IRQ %d: %d\n",
-				mtk->gpio_irq, ret);
-			return ret;
-		}
-
-		girq = &rg->chip.gc.irq;
-		gpio_irq_chip_set_chip(girq, &mt7621_irq_chip);
-		/* This will let us handle the parent IRQ in the driver */
-		girq->parent_handler = NULL;
-		girq->num_parents = 0;
-		girq->parents = NULL;
-		girq->default_type = IRQ_TYPE_NONE;
-		girq->handler = handle_simple_irq;
-	}
-
-	ret = devm_gpiochip_add_data(dev, &rg->chip.gc, mtk);
+	ret = devm_gpiochip_add_data(dev, &rg->chip.gc, rg);
 	if (ret < 0) {
 		dev_err(dev, "Could not register gpio %d, ret=%d\n",
 			rg->chip.gc.ngpio, ret);
@@ -322,7 +460,8 @@ mediatek_gpio_probe(struct platform_device *pdev)
 	if (mtk->gpio_irq < 0)
 		return mtk->gpio_irq;
 
-	mtk->dev = dev;
+	mtk->pdev = pdev;
+	mtk->num_gpios = MTK_BANK_WIDTH * MTK_BANK_CNT;
 	platform_set_drvdata(pdev, mtk);
 
 	for (i = 0; i < MTK_BANK_CNT; i++) {
@@ -331,7 +470,17 @@ mediatek_gpio_probe(struct platform_device *pdev)
 			return ret;
 	}
 
+	if (mtk->gpio_irq > 0) {
+		ret = mt7621_gpio_irq_setup(pdev, mtk);
+		if (ret)
+			goto fail;
+	}
+
 	return 0;
+
+fail:
+	mt7621_gpio_remove(pdev);
+	return ret;
 }
 
 static const struct of_device_id mediatek_gpio_match[] = {
@@ -342,6 +491,7 @@ MODULE_DEVICE_TABLE(of, mediatek_gpio_match);
 
 static struct platform_driver mediatek_gpio_driver = {
 	.probe = mediatek_gpio_probe,
+	.remove = mt7621_gpio_remove,
 	.driver = {
 		.name = "mt7621_gpio",
 		.of_match_table = mediatek_gpio_match,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0600/2077] wifi: ath12k: fix EAPOL TX failure caused by stale tcl_metadata bits
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (598 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0599/2077] gpio: mt7621: fix interrupt banks mapping on gpio chips Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0601/2077] wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is reported Greg Kroah-Hartman
                   ` (397 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Baochen Qiang, Rameshkumar Sundaram,
	Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Baochen Qiang <baochen.qiang@oss.qualcomm.com>

[ Upstream commit fdea4d44e4b9c3f7021c85f8cd766e84e224472d ]

On WCN7850, after the following sequence:

  1. load ath12k and connect to a non-MLO AP
  2. disconnect and connect to an MLO AP
  3. disconnect and reconnect to the non-MLO AP

the third connection always fails with a 4-Way handshake timeout. The
supplicant transmits message 2 of 4 four times in response to AP
retries of message 1, but the AP never sees any of them.

ath12k_dp_vdev_tx_attach() composes dp_link_vif->tcl_metadata using |=,
but dp_link_vif is embedded in struct ath12k_dp_vif and its slots are
reused across vif/peer teardown and setup. Since tcl_metadata is never
cleared on detach, vdev_id bits from a previous attach remain set when
the same link slot is reused with a different vdev_id. In this specific
issue, the same link slot is used for vdev_id 0, then vdev_id 1, then
vdev_id 0 again, the OR yields tcl_metadata == 0x9, which encodes
vdev_id 1 in the HTT_TCL_META_DATA_VDEV_ID field even though
ti.vdev_id is 0. Firmware then routes the EAPOL frame to the wrong
vdev and the AP never receives message 2.

Use plain assignment instead of |= so the field is fully recomputed
from the current arvif on every attach.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3

Fixes: af66c7640cf9 ("wifi: ath12k: Refactor ath12k_vif structure")
Signed-off-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Link: https://patch.msgid.link/20260609-ath12k-fix-eapol-tcl-metadata-v1-1-d47e6f90d4ee@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/ath12k/dp.c | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

diff --git a/drivers/net/wireless/ath/ath12k/dp.c b/drivers/net/wireless/ath/ath12k/dp.c
index 90802ed1aa59f9..af5f11fc1d84ab 100644
--- a/drivers/net/wireless/ath/ath12k/dp.c
+++ b/drivers/net/wireless/ath/ath12k/dp.c
@@ -943,11 +943,11 @@ void ath12k_dp_vdev_tx_attach(struct ath12k *ar, struct ath12k_link_vif *arvif)
 
 	dp_link_vif = ath12k_dp_vif_to_dp_link_vif(&ahvif->dp_vif, link_id);
 
-	dp_link_vif->tcl_metadata |= u32_encode_bits(1, HTT_TCL_META_DATA_TYPE) |
-				     u32_encode_bits(arvif->vdev_id,
-						     HTT_TCL_META_DATA_VDEV_ID) |
-				     u32_encode_bits(ar->pdev->pdev_id,
-						     HTT_TCL_META_DATA_PDEV_ID);
+	dp_link_vif->tcl_metadata = u32_encode_bits(1, HTT_TCL_META_DATA_TYPE) |
+				    u32_encode_bits(arvif->vdev_id,
+						    HTT_TCL_META_DATA_VDEV_ID) |
+				    u32_encode_bits(ar->pdev->pdev_id,
+						    HTT_TCL_META_DATA_PDEV_ID);
 
 	/* set HTT extension valid bit to 0 by default */
 	dp_link_vif->tcl_metadata &= ~HTT_TCL_META_DATA_VALID_HTT;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0601/2077] wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is reported
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (599 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0600/2077] wifi: ath12k: fix EAPOL TX failure caused by stale tcl_metadata bits Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0602/2077] fbdev/arm: Export acorndata_8x8 font symbol for bootloader Greg Kroah-Hartman
                   ` (396 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wen Gong, Maharaja Kennadyrajan,
	Rameshkumar Sundaram, Jeff Johnson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wen Gong <quic_wgong@quicinc.com>

[ Upstream commit 63abe299b12b317dfee5bcd09037da4668a4431a ]

When firmware reports NSS ratio support, SUPPORTS_VHT_EXT_NSS_BW is enabled in
ath12k. However, IEEE80211_VHT_EXT_NSS_BW_CAPABLE must also be set to make the
advertisement valid.

According to IEEE Std 802.11-2024, Subclause 9.4.2.156.3 (Supported VHT-MCS and
NSS Set subfields), the VHT Extended NSS BW Capable bit indicates whether a STA
is capable of interpreting the Extended NSS BW Support subfield of the VHT
capabilities information field. Advertising extended NSS BW support without
setting this capability bit is therefore invalid.

Without this change, mac80211 detects the inconsistency and logs:

  ieee80211 phy0: copying sband (band 1) due to VHT EXT NSS BW flag

This indicates that mac80211 implicitly aligns IEEE80211_VHT_EXT_NSS_BW_CAPABLE
during ieee80211_register_hw(). Explicitly setting the bit in ath12k avoids this
fixup and ensures capabilities are advertised correctly by the driver.

This change follows the same approach as the existing ath11k fix.
https://lore.kernel.org/all/20211013073704.15888-1-wgong@codeaurora.org/

Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.5-01651-QCAHKSWPL_SILICONZ-1

Fixes: 18ab9d038fad ("wifi: ath12k: add support for 160 MHz bandwidth")
Signed-off-by: Wen Gong <quic_wgong@quicinc.com>
Signed-off-by: Maharaja Kennadyrajan <maharaja.kennadyrajan@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Link: https://patch.msgid.link/20260604095831.2674298-1-maharaja.kennadyrajan@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wireless/ath/ath12k/mac.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/net/wireless/ath/ath12k/mac.c b/drivers/net/wireless/ath/ath12k/mac.c
index 74af291350241d..7190aafd3ae693 100644
--- a/drivers/net/wireless/ath/ath12k/mac.c
+++ b/drivers/net/wireless/ath/ath12k/mac.c
@@ -8399,6 +8399,10 @@ ath12k_create_vht_cap(struct ath12k *ar, u32 rate_cap_tx_chainmask,
 	vht_cap.vht_supported = 1;
 	vht_cap.cap = ar->pdev->cap.vht_cap;
 
+	if (ar->pdev->cap.nss_ratio_enabled)
+		vht_cap.vht_mcs.tx_highest |=
+			cpu_to_le16(IEEE80211_VHT_EXT_NSS_BW_CAPABLE);
+
 	ath12k_set_vht_txbf_cap(ar, &vht_cap.cap);
 
 	/* 80P80 is not supported */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0602/2077] fbdev/arm: Export acorndata_8x8 font symbol for bootloader
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (600 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0601/2077] wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is reported Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0603/2077] fbdev: sm501fb: Fix buffer errors in OF binding code Greg Kroah-Hartman
                   ` (395 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ethan Nelson-Moore,
	Thomas Zimmermann, linux-arm-kernel, Russell King, Helge Deller,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Helge Deller <deller@gmx.de>

[ Upstream commit 470ea955a18c76eeb10ca11ffcb2fe923bfc5515 ]

The text display code used in the Risc PC kernel image decompression
code uses arch/arm/boot/compressed/font.c, which includes
lib/fonts/font_acorn_8x8.c, which further includes <linux/font.h>.

Since commit 97df8960240a ("lib/fonts: Provide helpers for calculating
glyph pitch and size") <linux/font.h> contains inline functions that
require __do_div64, which is not linked into the ARM kernel
decompressor. This makes Risc PC zImages fail to build.

Resolve this issue by defining the BOOTLOADER symbol and use it to avoid
a static declaration of the acorndata_8x8 symbol. That way it can be
referenced by the arm bootloader, and other static math functions and
symbols (like __do_div64) stay static and don't get unneccesary included
in the ARM kernel bootloader decompressor object file.

Fixes: 97df8960240a ("lib/fonts: Provide helpers for calculating glyph pitch and size")
Reported-by: Ethan Nelson-Moore <enelsonmoore@gmail.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Cc: linux-arm-kernel@lists.infradead.org
Cc: Russell King <linux@armlinux.org.uk>
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm/boot/compressed/Makefile | 2 +-
 lib/fonts/font_acorn_8x8.c        | 5 +++++
 2 files changed, 6 insertions(+), 1 deletion(-)

diff --git a/arch/arm/boot/compressed/Makefile b/arch/arm/boot/compressed/Makefile
index a159120d1e42e2..e3f550d6285786 100644
--- a/arch/arm/boot/compressed/Makefile
+++ b/arch/arm/boot/compressed/Makefile
@@ -157,4 +157,4 @@ $(obj)/piggy_data: $(obj)/../Image FORCE
 
 $(obj)/piggy.o: $(obj)/piggy_data
 
-CFLAGS_font.o := -Dstatic=
+CFLAGS_font.o := -DBOOTLOADER
diff --git a/lib/fonts/font_acorn_8x8.c b/lib/fonts/font_acorn_8x8.c
index 36c51016769d41..4ff52c79f8c4d6 100644
--- a/lib/fonts/font_acorn_8x8.c
+++ b/lib/fonts/font_acorn_8x8.c
@@ -5,7 +5,12 @@
 
 #define FONTDATAMAX 2048
 
+#ifdef BOOTLOADER
+/* The acorndata_8x8 symbol is needed by the ARM bootloader too. */
+const struct font_data acorndata_8x8 = {
+#else
 static const struct font_data acorndata_8x8 = {
+#endif
 { 0, 0, FONTDATAMAX, 0 }, {
 /* 00 */  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ^@ */
 /* 01 */  0x7e, 0x81, 0xa5, 0x81, 0xbd, 0x99, 0x81, 0x7e, /* ^A */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0603/2077] fbdev: sm501fb: Fix buffer errors in OF binding code
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (601 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0602/2077] fbdev/arm: Export acorndata_8x8 font symbol for bootloader Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0604/2077] memory: tegra186-emc: stop borrowing MC aggregate hook for EMC Greg Kroah-Hartman
                   ` (394 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, David Laight, Helge Deller,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Laight <david.laight.linux@gmail.com>

[ Upstream commit d8421e09382cfe0bd2a044c8b0a822f64855dd4e ]

The code that gets the frame buffer mode from OF has 'use after free',
'buffer overrun' and memory leaks.

info->edid_data isn't free if the probe functions fail or if
pd->def_mode is set.

If both the CRT and PANEL are enabled info->edid_data is used after
being freed and is freed twice.

The string returned by of_get_property(np, "mode", &len) is just
written over either the static "640x480-16@60" or the module parameter
string without any regard for the length (which is most likely longer).

Use kstrump() for the OF mode and free everything before freeing 'info.

Fixes: 4295f9bf74a88 ("video, sm501: add OF binding to support SM501")
Signed-off-by: David Laight <david.laight.linux@gmail.com>
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/video/fbdev/sm501fb.c | 16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

diff --git a/drivers/video/fbdev/sm501fb.c b/drivers/video/fbdev/sm501fb.c
index fee4b9f84592f7..ea5375ed4ea6f3 100644
--- a/drivers/video/fbdev/sm501fb.c
+++ b/drivers/video/fbdev/sm501fb.c
@@ -96,6 +96,7 @@ struct sm501fb_info {
 	void __iomem		*fbmem;		/* remapped framebuffer */
 	size_t			 fbmem_len;	/* length of remapped region */
 	u8 *edid_data;
+	char *fb_mode;
 };
 
 /* per-framebuffer private data */
@@ -1793,12 +1794,11 @@ static int sm501fb_init_fb(struct fb_info *fb, enum sm501_controller head,
 			fb->var.yres_virtual = fb->var.yres;
 		} else {
 			if (info->edid_data) {
-				ret = fb_find_mode(&fb->var, fb, fb_mode,
+				ret = fb_find_mode(&fb->var, fb,
+					info->fb_mode ?: fb_mode,
 					fb->monspecs.modedb,
 					fb->monspecs.modedb_len,
 					&sm501_default_mode, default_bpp);
-				/* edid_data is no longer needed, free it */
-				kfree(info->edid_data);
 			} else {
 				ret = fb_find_mode(&fb->var, fb,
 					   NULL, NULL, 0, NULL, 8);
@@ -1974,7 +1974,7 @@ static int sm501fb_probe(struct platform_device *pdev)
 			/* Get EDID */
 			cp = of_get_property(np, "mode", &len);
 			if (cp)
-				strcpy(fb_mode, cp);
+				info->fb_mode = kstrdup(cp, GFP_KERNEL);
 			prop = of_get_property(np, "edid", &len);
 			if (prop && len == EDID_LENGTH) {
 				info->edid_data = kmemdup(prop, EDID_LENGTH,
@@ -2031,6 +2031,12 @@ static int sm501fb_probe(struct platform_device *pdev)
 		goto err_started_crt;
 	}
 
+	/* These aren't needed any more */
+	kfree(info->edid_data);
+	kfree(info->fb_mode);
+	info->edid_data = NULL;
+	info->fb_mode = NULL;
+
 	/* we registered, return ok */
 	return 0;
 
@@ -2048,6 +2054,8 @@ static int sm501fb_probe(struct platform_device *pdev)
 	framebuffer_release(info->fb[HEAD_CRT]);
 
 err_alloc:
+	kfree(info->edid_data);
+	kfree(info->fb_mode);
 	kfree(info);
 
 	return ret;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0604/2077] memory: tegra186-emc: stop borrowing MC aggregate hook for EMC
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (602 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0603/2077] fbdev: sm501fb: Fix buffer errors in OF binding code Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0605/2077] vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS Greg Kroah-Hartman
                   ` (393 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jon Hunter, Sumit Gupta,
	Krzysztof Kozlowski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sumit Gupta <sumitg@nvidia.com>

[ Upstream commit 2e05f3d6005d9aa3e2e423d2471f290d9ccbe3d2 ]

tegra186_emc_interconnect_init() copies the MC's ICC aggregate hook
into the EMC provider.  That hook (tegra234_mc_icc_aggregate /
tegra264_mc_icc_aggregate) uses container_of() to recover 'mc',
which is only valid when the icc_provider is embedded in struct
tegra_mc.  For an EMC node the provider is embedded in struct
tegra186_emc, so 'mc' points into unrelated memory.

This stayed harmless until commit faafd6ca7e6e ("memory: tegra:
make icc_set_bw return zero if BWMGR not supported") added an
unconditional read of mc->bwmgr_mrq_supported at the top of the
hook.  UBSAN catches the stray load on every EMC aggregation:

  UBSAN: invalid-load in drivers/memory/tegra/tegra234.c:1104:9
  load of value 112 is not a valid value for type '_Bool'

No functional impact in practice, since the hook's only other mc
dereference (mc->num_channels) sits inside a
TEGRA_ICC_MC_CPU_CLUSTER* branch that EMC nodes never enter.

Fix this by setting the EMC provider's aggregate hook to
icc_std_aggregate, instead of borrowing the MC's hook.  The MC
providers continue using their own aggregate hooks, where
container_of() correctly resolves to struct tegra_mc.

Reported-by: Jon Hunter <jonathanh@nvidia.com>
Fixes: 9a38cb27668e ("memory: tegra: Add interconnect support for DRAM scaling in Tegra234")
Signed-off-by: Sumit Gupta <sumitg@nvidia.com>
Reviewed-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Link: https://patch.msgid.link/20260527140127.49172-2-sumitg@nvidia.com
Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/memory/tegra/tegra186-emc.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/drivers/memory/tegra/tegra186-emc.c b/drivers/memory/tegra/tegra186-emc.c
index 03ebab6fbe68fe..f71265b303b976 100644
--- a/drivers/memory/tegra/tegra186-emc.c
+++ b/drivers/memory/tegra/tegra186-emc.c
@@ -258,15 +258,13 @@ static int tegra186_emc_icc_get_init_bw(struct icc_node *node, u32 *avg, u32 *pe
 
 static int tegra186_emc_interconnect_init(struct tegra186_emc *emc)
 {
-	struct tegra_mc *mc = dev_get_drvdata(emc->dev->parent);
-	const struct tegra_mc_soc *soc = mc->soc;
 	struct icc_node *node;
 	int err;
 
 	emc->provider.dev = emc->dev;
 	emc->provider.set = tegra186_emc_icc_set_bw;
 	emc->provider.data = &emc->provider;
-	emc->provider.aggregate = soc->icc_ops->aggregate;
+	emc->provider.aggregate = icc_std_aggregate;
 	emc->provider.xlate = tegra186_emc_of_icc_xlate;
 	emc->provider.get_bw = tegra186_emc_icc_get_init_bw;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0605/2077] vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (603 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0604/2077] memory: tegra186-emc: stop borrowing MC aggregate hook for EMC Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0606/2077] hwmon: (it87) Clamp negative values to zero in set_fan() Greg Kroah-Hartman
                   ` (392 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jeff Layton, Anna Schumaker,
	Alexander Mikhalitsyn, Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jeff Layton <jlayton@kernel.org>

[ Upstream commit c5d6cac28646b0d5d81ef632be748ae93c1f36c7 ]

Commit e1c5ae59c0f2 ("fs: don't allow non-init s_user_ns for filesystems
without FS_USERNS_MOUNT") prevents the mount of any filesystem inside a
container that doesn't have FS_USERNS_MOUNT set.

This broke NFS mounts in our containerized environment. We have a daemon
somewhat like systemd-mountfsd running in the init_ns. A process does a
fsopen() inside the container and passes it to the daemon via unix
socket.

The daemon then vets that the request is for an allowed NFS server and
performs the mount. This now fails because the fc->user_ns is set to the
value in the container and NFS doesn't set FS_USERNS_MOUNT.  We don't
want to add FS_USERNS_MOUNT to NFS since that would allow the container
to mount any NFS server (even malicious ones).

Add a new FS_USERNS_DELEGATABLE flag, and enable it on NFS.

Fixes: e1c5ae59c0f2 ("fs: don't allow non-init s_user_ns for filesystems without FS_USERNS_MOUNT")
Signed-off-by: Jeff Layton <jlayton@kernel.org>
Link: https://patch.msgid.link/20260129-twmount-v1-1-4874ed2a15c4@kernel.org
Acked-by: Anna Schumaker <anna.schumaker@oracle.com>
Reviewed-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/nfs/fs_context.c |  8 ++++++--
 fs/super.c          | 11 ++++++-----
 include/linux/fs.h  |  1 +
 3 files changed, 13 insertions(+), 7 deletions(-)

diff --git a/fs/nfs/fs_context.c b/fs/nfs/fs_context.c
index c105882edd16e7..1967de7d1dff97 100644
--- a/fs/nfs/fs_context.c
+++ b/fs/nfs/fs_context.c
@@ -1769,7 +1769,9 @@ struct file_system_type nfs_fs_type = {
 	.init_fs_context	= nfs_init_fs_context,
 	.parameters		= nfs_fs_parameters,
 	.kill_sb		= nfs_kill_super,
-	.fs_flags		= FS_RENAME_DOES_D_MOVE|FS_BINARY_MOUNTDATA,
+	.fs_flags		= FS_RENAME_DOES_D_MOVE	|
+				  FS_BINARY_MOUNTDATA	|
+				  FS_USERNS_DELEGATABLE,
 };
 MODULE_ALIAS_FS("nfs");
 EXPORT_SYMBOL_GPL(nfs_fs_type);
@@ -1781,7 +1783,9 @@ struct file_system_type nfs4_fs_type = {
 	.init_fs_context	= nfs_init_fs_context,
 	.parameters		= nfs_fs_parameters,
 	.kill_sb		= nfs_kill_super,
-	.fs_flags		= FS_RENAME_DOES_D_MOVE|FS_BINARY_MOUNTDATA,
+	.fs_flags		= FS_RENAME_DOES_D_MOVE	|
+				  FS_BINARY_MOUNTDATA	|
+				  FS_USERNS_DELEGATABLE,
 };
 MODULE_ALIAS_FS("nfs4");
 MODULE_ALIAS("nfs4");
diff --git a/fs/super.c b/fs/super.c
index 378e81efe643bd..97df9e574d8bf5 100644
--- a/fs/super.c
+++ b/fs/super.c
@@ -741,12 +741,13 @@ struct super_block *sget_fc(struct fs_context *fc,
 	int err;
 
 	/*
-	 * Never allow s_user_ns != &init_user_ns when FS_USERNS_MOUNT is
-	 * not set, as the filesystem is likely unprepared to handle it.
-	 * This can happen when fsconfig() is called from init_user_ns with
-	 * an fs_fd opened in another user namespace.
+	 * Never allow s_user_ns != &init_user_ns when FS_USERNS_MOUNT or
+	 * FS_USERNS_DELEGATABLE is not set, as the filesystem is likely
+	 * unprepared to handle it. This can happen when fsconfig() is called
+	 * from init_user_ns with an fs_fd opened in another user namespace.
 	 */
-	if (user_ns != &init_user_ns && !(fc->fs_type->fs_flags & FS_USERNS_MOUNT)) {
+	if (user_ns != &init_user_ns &&
+	    !(fc->fs_type->fs_flags & (FS_USERNS_MOUNT | FS_USERNS_DELEGATABLE))) {
 		errorfc(fc, "VFS: Mounting from non-initial user namespace is not allowed");
 		return ERR_PTR(-EPERM);
 	}
diff --git a/include/linux/fs.h b/include/linux/fs.h
index f93b216149cc92..0f5f022e6e7bc7 100644
--- a/include/linux/fs.h
+++ b/include/linux/fs.h
@@ -2281,6 +2281,7 @@ struct file_system_type {
 #define FS_MGTIME		64	/* FS uses multigrain timestamps */
 #define FS_LBS			128	/* FS supports LBS */
 #define FS_POWER_FREEZE		256	/* Always freeze on suspend/hibernate */
+#define FS_USERNS_DELEGATABLE	1024	/* Can be mounted inside userns from outside */
 #define FS_RENAME_DOES_D_MOVE	32768	/* FS will handle d_move() during rename() internally. */
 	int (*init_fs_context)(struct fs_context *);
 	const struct fs_parameter_spec *parameters;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0606/2077] hwmon: (it87) Clamp negative values to zero in set_fan()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (604 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0605/2077] vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0607/2077] PM: QoS: Fix misc device registration unwind Greg Kroah-Hartman
                   ` (391 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nikita Zhandarovich, Guenter Roeck,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nikita Zhandarovich <n.zhandarovich@fintech.ru>

[ Upstream commit 7f8581c70a3bd50a932d3d2d253e99c5ec3eda74 ]

set_fan() parses user input with kstrtol() and passes the resulting
value to FAN16_TO_REG() on chips with 16-bit fan support.

Negative fan speeds are not meaningful and should be rejected before
conversion. Worst scenario, one may be able to abuse undefined
behaviour of signed overflow to possibly induce rpm * 2 == 0 in
FAN16_TO_REG(), thus causing a division by zero.

Instead, clamp val < 0 to zero and keep the conversion in its valid
input domain, avoiding unsafe arithmetic in the register conversion
path.

Found by Linux Verification Center (linuxtesting.org) with static
analysis tool SVACE.

Fixes: 17d648bf5786 ("it87: Add support for the IT8716F")
Signed-off-by: Nikita Zhandarovich <n.zhandarovich@fintech.ru>
Link: https://lore.kernel.org/r/20260529141839.1639287-1-n.zhandarovich@fintech.ru
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwmon/it87.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/hwmon/it87.c b/drivers/hwmon/it87.c
index 5fd310662ee432..87edb1b6048bb5 100644
--- a/drivers/hwmon/it87.c
+++ b/drivers/hwmon/it87.c
@@ -1412,6 +1412,9 @@ static ssize_t set_fan(struct device *dev, struct device_attribute *attr,
 	if (kstrtol(buf, 10, &val) < 0)
 		return -EINVAL;
 
+	if (val < 0)
+		val = 0;
+
 	err = it87_lock(data);
 	if (err)
 		return err;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0607/2077] PM: QoS: Fix misc device registration unwind
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (605 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0606/2077] hwmon: (it87) Clamp negative values to zero in set_fan() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0608/2077] btrfs: zoned: dont account data relocation space-info in statfs free space Greg Kroah-Hartman
                   ` (390 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuho Choi, Rafael J. Wysocki,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yuho Choi <dbgh9129@gmail.com>

[ Upstream commit 51a7c560cffdd3653ac2b930d01410569b23b23e ]

cpu_latency_qos_init() registers cpu_dma_latency first and, when
CONFIG_PM_QOS_CPU_SYSTEM_WAKEUP is enabled, registers cpu_wakeup_latency
afterwards. The second registration overwrites the first return value.

As a result, a failure to register cpu_dma_latency can be masked if the
second registration succeeds. Conversely, if cpu_dma_latency succeeds and
cpu_wakeup_latency fails, the function returns an error while leaving the
first misc device registered.

Return immediately on the first registration failure and deregister
cpu_dma_latency if the second registration fails.

Fixes: a4e6512a79d8 ("PM: QoS: Introduce a CPU system wakeup QoS limit")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Link: https://patch.msgid.link/20260608170748.82273-1-dbgh9129@gmail.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/power/qos.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

diff --git a/kernel/power/qos.c b/kernel/power/qos.c
index 398b994b73aabf..1944dbeb0d4c95 100644
--- a/kernel/power/qos.c
+++ b/kernel/power/qos.c
@@ -519,18 +519,23 @@ static int __init cpu_latency_qos_init(void)
 	int ret;
 
 	ret = misc_register(&cpu_latency_qos_miscdev);
-	if (ret < 0)
+	if (ret < 0) {
 		pr_err("%s: %s setup failed\n", __func__,
 		       cpu_latency_qos_miscdev.name);
+		return ret;
+	}
 
 #ifdef CONFIG_PM_QOS_CPU_SYSTEM_WAKEUP
 	ret = misc_register(&cpu_wakeup_latency_qos_miscdev);
-	if (ret < 0)
+	if (ret < 0) {
 		pr_err("%s: %s setup failed\n", __func__,
 		       cpu_wakeup_latency_qos_miscdev.name);
+		misc_deregister(&cpu_latency_qos_miscdev);
+		return ret;
+	}
 #endif
 
-	return ret;
+	return 0;
 }
 late_initcall(cpu_latency_qos_init);
 #endif /* CONFIG_CPU_IDLE */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0608/2077] btrfs: zoned: dont account data relocation space-info in statfs free space
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (606 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0607/2077] PM: QoS: Fix misc device registration unwind Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0609/2077] btrfs: zoned: fix deadlock waiting for ticket during data relocation Greg Kroah-Hartman
                   ` (389 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Boris Burkov, Naohiro Aota,
	Johannes Thumshirn, David Sterba, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johannes Thumshirn <johannes.thumshirn@wdc.com>

[ Upstream commit 52416a27aabc43eab3792fd0ca9f5dabeab58f31 ]

Don't account the free space in a data relocation space-info sub-group as
usable free space in statfs.

This is misleading as no user allocations can be made in this space-info
sub-group. It is only a target for relocation.

Fixes: f92ee31e031c ("btrfs: introduce btrfs_space_info sub-group")
Reviewed-by: Boris Burkov <boris@bur.io>
Reviewed-by: Naohiro Aota <naohiro.aota@wdc.com>
Signed-off-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/btrfs/super.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/fs/btrfs/super.c b/fs/btrfs/super.c
index 64514d600eec71..ba70d727622e84 100644
--- a/fs/btrfs/super.c
+++ b/fs/btrfs/super.c
@@ -1740,7 +1740,8 @@ static int btrfs_statfs(struct dentry *dentry, struct kstatfs *buf)
 	int mixed = 0;
 
 	list_for_each_entry(found, &fs_info->space_info, list) {
-		if (found->flags & BTRFS_BLOCK_GROUP_DATA) {
+		if (found->flags & BTRFS_BLOCK_GROUP_DATA &&
+		    found->subgroup_id != BTRFS_SUB_GROUP_DATA_RELOC) {
 			int i;
 
 			total_free_data += found->disk_total - found->disk_used;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0609/2077] btrfs: zoned: fix deadlock waiting for ticket during data relocation
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (607 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0608/2077] btrfs: zoned: dont account data relocation space-info in statfs free space Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0610/2077] Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()" Greg Kroah-Hartman
                   ` (388 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Boris Burkov, Naohiro Aota,
	Johannes Thumshirn, David Sterba, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johannes Thumshirn <johannes.thumshirn@wdc.com>

[ Upstream commit 814c3b4ea357297c507158bceb07bcdc5fbe9808 ]

When performing data relocation on a zoned filesystem, BTRFS can deadlock
in handle_reserve_tickets(). The relocation process is waiting on a space
reservation ticket that can never be fulfilled, because the relocation
itself is the operation responsible for freeing up that space.

Fix this by introducing a new flush state,
BTRFS_RESERVE_FLUSH_ZONED_RELOCATION, specifically for data chunk
allocation during zoned relocation. Like
BTRFS_RESERVE_FLUSH_FREE_SPACE_INODE, this state uses
priority_reclaim_data_space() instead of the normal flushing path, which
avoids re-entering the relocation code and breaking the deadlock cycle.

In btrfs_alloc_data_chunk_ondemand(), select this new flush state when the
inode belongs to a data relocation root on a zoned filesystem.

Fixes: e2a7fd22378f ("btrfs: zoned: add zone reclaim flush state for DATA space_info")
Reviewed-by: Boris Burkov <boris@bur.io>
Reviewed-by: Naohiro Aota <naohiro.aota@wdc.com>
Signed-off-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/btrfs/delalloc-space.c |  2 ++
 fs/btrfs/space-info.c     |  2 ++
 fs/btrfs/space-info.h     | 11 +++++++++++
 3 files changed, 15 insertions(+)

diff --git a/fs/btrfs/delalloc-space.c b/fs/btrfs/delalloc-space.c
index 0970799d0aa443..4293a63834337f 100644
--- a/fs/btrfs/delalloc-space.c
+++ b/fs/btrfs/delalloc-space.c
@@ -134,6 +134,8 @@ int btrfs_alloc_data_chunk_ondemand(const struct btrfs_inode *inode, u64 bytes)
 
 	if (btrfs_is_free_space_inode(inode))
 		flush = BTRFS_RESERVE_FLUSH_FREE_SPACE_INODE;
+	else if (btrfs_is_zoned(fs_info) && btrfs_is_data_reloc_root(root))
+		flush = BTRFS_RESERVE_FLUSH_ZONED_RELOCATION;
 
 	return btrfs_reserve_data_bytes(data_sinfo_for_inode(inode), bytes, flush);
 }
diff --git a/fs/btrfs/space-info.c b/fs/btrfs/space-info.c
index f0436eea15445b..e7a5cf50caa4be 100644
--- a/fs/btrfs/space-info.c
+++ b/fs/btrfs/space-info.c
@@ -1698,6 +1698,7 @@ static int handle_reserve_ticket(struct btrfs_space_info *space_info,
 						ARRAY_SIZE(evict_flush_states));
 		break;
 	case BTRFS_RESERVE_FLUSH_FREE_SPACE_INODE:
+	case BTRFS_RESERVE_FLUSH_ZONED_RELOCATION:
 		priority_reclaim_data_space(space_info, ticket);
 		break;
 	default:
@@ -1961,6 +1962,7 @@ int btrfs_reserve_data_bytes(struct btrfs_space_info *space_info, u64 bytes,
 
 	ASSERT(flush == BTRFS_RESERVE_FLUSH_DATA ||
 	       flush == BTRFS_RESERVE_FLUSH_FREE_SPACE_INODE ||
+	       flush == BTRFS_RESERVE_FLUSH_ZONED_RELOCATION ||
 	       flush == BTRFS_RESERVE_NO_FLUSH, "flush=%d", flush);
 	ASSERT(!current->journal_info || flush != BTRFS_RESERVE_FLUSH_DATA,
 	       "current->journal_info=0x%lx flush=%d",
diff --git a/fs/btrfs/space-info.h b/fs/btrfs/space-info.h
index 24f45072ca4b1d..aa836e8a9d4a6f 100644
--- a/fs/btrfs/space-info.h
+++ b/fs/btrfs/space-info.h
@@ -77,6 +77,17 @@ enum btrfs_reserve_flush_enum {
 	 */
 	BTRFS_RESERVE_FLUSH_ALL_STEAL,
 
+	/*
+	 * This is for relocation on zoned filesystems only. We need to use
+	 * priority flushing for this, because otherwise we can deadlock on
+	 * waiting for a ticket, that cannot be granted, because we cannot do
+	 * any allocations.
+	 *
+	 * Apart from being specific to zoned relocation, it is equal to
+	 * BTRFS_FLUSH_FREE_SPACE_INODE.
+	 */
+	BTRFS_RESERVE_FLUSH_ZONED_RELOCATION,
+
 	/*
 	 * This is for btrfs_use_block_rsv only.  We have exhausted our block
 	 * rsv and our global block rsv.  This can happen for things like
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0610/2077] Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()"
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (608 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0609/2077] btrfs: zoned: fix deadlock waiting for ticket during data relocation Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0611/2077] btrfs: zoned: always set max_active_zones for zoned devices Greg Kroah-Hartman
                   ` (387 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Matthew Wilcox (Oracle), Qu Wenruo,
	Boris Burkov, David Sterba, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matthew Wilcox (Oracle) <willy@infradead.org>

[ Upstream commit 0279bed34c22dd5ebff12e5af8ef940de93c5523 ]

It seems that af566bdaff54 was tested against a tree which did not
contain commit 12851bd921d4 ("fs: Turn page_offset() into a wrapper
around folio_pos()).  Unfortunately it has a bug of its own; on 32-bit
systems, shifting by PAGE_SHIFT will overflow on files larger than 4GiB.
Since page_offset() is now fixed, just revert af566bdaff54.

Fixes: af566bdaff54 (btrfs: fix the file offset calculation inside btrfs_decompress_buf2page())
Signed-off-by: Matthew Wilcox (Oracle) <willy@infradead.org>
Reviewed-by: Qu Wenruo <wqu@suse.com>
Reviewed-by: Boris Burkov <boris@bur.io>
Tested-by: Boris Burkov <boris@bur.io>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/btrfs/compression.c | 18 +-----------------
 1 file changed, 1 insertion(+), 17 deletions(-)

diff --git a/fs/btrfs/compression.c b/fs/btrfs/compression.c
index a02b62e0a8f33e..2ceb5661e0718a 100644
--- a/fs/btrfs/compression.c
+++ b/fs/btrfs/compression.c
@@ -1191,22 +1191,6 @@ void __cold btrfs_exit_compress(void)
 	bioset_exit(&btrfs_compressed_bioset);
 }
 
-/*
- * The bvec is a single page bvec from a bio that contains folios from a filemap.
- *
- * Since the folio may be a large one, and if the bv_page is not a head page of
- * a large folio, then page->index is unreliable.
- *
- * Thus we need this helper to grab the proper file offset.
- */
-static u64 file_offset_from_bvec(const struct bio_vec *bvec)
-{
-	const struct page *page = bvec->bv_page;
-	const struct folio *folio = page_folio(page);
-
-	return (page_pgoff(folio, page) << PAGE_SHIFT) + bvec->bv_offset;
-}
-
 /*
  * Copy decompressed data from working buffer to pages.
  *
@@ -1259,7 +1243,7 @@ int btrfs_decompress_buf2page(const char *buf, u32 buf_len,
 		 * cb->start may underflow, but subtracting that value can still
 		 * give us correct offset inside the full decompressed extent.
 		 */
-		bvec_offset = file_offset_from_bvec(&bvec) - cb->start;
+		bvec_offset = page_offset(bvec.bv_page) + bvec.bv_offset - cb->start;
 
 		/* Haven't reached the bvec range, exit */
 		if (decompressed + buf_len <= bvec_offset)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0611/2077] btrfs: zoned: always set max_active_zones for zoned devices
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (609 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0610/2077] Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()" Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0612/2077] btrfs: annotate lockless read of defrag_bytes in should_nocow() Greg Kroah-Hartman
                   ` (386 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Damien Le Moal, Johannes Thumshirn,
	David Sterba, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johannes Thumshirn <johannes.thumshirn@wdc.com>

[ Upstream commit 21a3533b99b8a53a026cc9f5041b10795c1f3ae8 ]

When a block device does not report a maximum number of open or active
zones,  currently assign BTRFS_DEFAULT_MAX_ACTIVE_ZONES (128) to
the internal limit, if the device has more than
BTRFS_DEFAULT_MAX_ACTIVE_ZONES zones.

But if the device has less than BTRFS_DEFAULT_MAX_ACTIVE_ZONES the
internal max_active_zones limit will stay at 0, even if the device has
zone resource limits. Furthermore, if the device has a total number of
zones that is less than BTRFS_DEFAULT_MAX_ACTIVE_ZONE, max_active_zones
should be set to at most the number of zones.

Also move the max_active_zone calculation and setting into a dedicated
helper, to shrink btrfs_get_dev_zone_info().

Fixes: 04147d8394e8 ("btrfs: zoned: limit active zones to max_open_zones")
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/btrfs/zoned.c | 64 +++++++++++++++++++++++++++++-------------------
 1 file changed, 39 insertions(+), 25 deletions(-)

diff --git a/fs/btrfs/zoned.c b/fs/btrfs/zoned.c
index 16dd87aa06f20c..0d590e81f3259b 100644
--- a/fs/btrfs/zoned.c
+++ b/fs/btrfs/zoned.c
@@ -354,12 +354,33 @@ int btrfs_get_dev_zone_info_all_devices(struct btrfs_fs_info *fs_info)
 	return ret;
 }
 
+static int btrfs_get_max_active_zones(struct btrfs_device *device,
+				      struct btrfs_zoned_device_info *zone_info)
+{
+	struct block_device *bdev = device->bdev;
+	int max_active_zones;
+
+	if (unlikely(zone_info->nr_zones < BTRFS_MIN_ACTIVE_ZONES)) {
+		btrfs_err(device->fs_info, "zoned: not enough zones to mount filesystem: %u < %d",
+			  zone_info->nr_zones, BTRFS_MIN_ACTIVE_ZONES);
+		return -EINVAL;
+	}
+
+	max_active_zones = min_not_zero(bdev_max_active_zones(bdev),
+					bdev_max_open_zones(bdev));
+	if (max_active_zones == 0)
+		max_active_zones = min(zone_info->nr_zones / 4,
+				       BTRFS_DEFAULT_MAX_ACTIVE_ZONES);
+
+	zone_info->max_active_zones = max(max_active_zones, BTRFS_MIN_ACTIVE_ZONES);
+	return 0;
+}
+
 int btrfs_get_dev_zone_info(struct btrfs_device *device, bool populate_cache)
 {
 	struct btrfs_fs_info *fs_info = device->fs_info;
 	struct btrfs_zoned_device_info *zone_info = NULL;
 	struct block_device *bdev = device->bdev;
-	unsigned int max_active_zones;
 	unsigned int nactive;
 	sector_t nr_sectors;
 	sector_t sector = 0;
@@ -424,19 +445,9 @@ int btrfs_get_dev_zone_info(struct btrfs_device *device, bool populate_cache)
 	if (!IS_ALIGNED(nr_sectors, zone_sectors))
 		zone_info->nr_zones++;
 
-	max_active_zones = min_not_zero(bdev_max_active_zones(bdev),
-					bdev_max_open_zones(bdev));
-	if (!max_active_zones && zone_info->nr_zones > BTRFS_DEFAULT_MAX_ACTIVE_ZONES)
-		max_active_zones = BTRFS_DEFAULT_MAX_ACTIVE_ZONES;
-	if (max_active_zones && max_active_zones < BTRFS_MIN_ACTIVE_ZONES) {
-		btrfs_err(fs_info,
-"zoned: %s: max active zones %u is too small, need at least %u active zones",
-				 rcu_dereference(device->name), max_active_zones,
-				 BTRFS_MIN_ACTIVE_ZONES);
-		ret = -EINVAL;
+	ret = btrfs_get_max_active_zones(device, zone_info);
+	if (ret)
 		goto out;
-	}
-	zone_info->max_active_zones = max_active_zones;
 
 	zone_info->seq_zones = bitmap_zalloc(zone_info->nr_zones, GFP_KERNEL);
 	if (!zone_info->seq_zones) {
@@ -517,26 +528,29 @@ int btrfs_get_dev_zone_info(struct btrfs_device *device, bool populate_cache)
 		goto out;
 	}
 
-	if (max_active_zones) {
-		if (unlikely(nactive > max_active_zones)) {
-			if (bdev_max_active_zones(bdev) == 0) {
-				max_active_zones = 0;
-				zone_info->max_active_zones = 0;
-				goto validate;
-			}
+	if (unlikely(nactive > zone_info->max_active_zones)) {
+		if (bdev_max_active_zones(bdev) > 0) {
 			btrfs_err(device->fs_info,
-			"zoned: %u active zones on %s exceeds max_active_zones %u",
-					 nactive, rcu_dereference(device->name),
-					 max_active_zones);
+					"zoned: %u active zones on %s exceeds max_active_zones %u",
+					nactive, rcu_dereference(device->name),
+					zone_info->max_active_zones);
 			ret = -EIO;
 			goto out;
 		}
+
+		/*
+		 * This is for backward compatibility with old filesystems that
+		 * have a lot of active zones because the device doesn't report
+		 * a maximum number of zones and we previously didn't care for
+		 * the limit.
+		 */
+		zone_info->max_active_zones = 0;
+	} else {
 		atomic_set(&zone_info->active_zones_left,
-			   max_active_zones - nactive);
+				zone_info->max_active_zones - nactive);
 		set_bit(BTRFS_FS_ACTIVE_ZONE_TRACKING, &fs_info->flags);
 	}
 
-validate:
 	/* Validate superblock log */
 	nr_zones = BTRFS_NR_SB_LOG_ZONES;
 	for (i = 0; i < BTRFS_SUPER_MIRROR_MAX; i++) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0612/2077] btrfs: annotate lockless read of defrag_bytes in should_nocow()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (610 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0611/2077] btrfs: zoned: always set max_active_zones for zoned devices Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0613/2077] btrfs: fix deadlock cloning inline extent when using flushoncommit Greg Kroah-Hartman
                   ` (385 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Cen Zhang, David Sterba, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cen Zhang <zzzccc427@gmail.com>

[ Upstream commit 89c0dc3de7a73e8aba5e9bfef543eee047a3d0d2 ]

should_nocow() reads inode->defrag_bytes without holding inode->lock,
while btrfs_set_delalloc_extent() and btrfs_clear_delalloc_extent()
update it under that spinlock.

This is a data race.  The read is a quick check used to decide whether
to fall back to COW for a NOCOW inode: if defrag_bytes is non-zero and
the range is tagged EXTENT_DEFRAG, we force COW so that defragmentation
can rewrite the extent.  Reading a stale value is harmless because:

  - A missed increment may skip COW once, but the defrag pass will
    redo the extent later.
  - A stale non-zero may force an unnecessary COW, which is a minor
    efficiency loss, not a correctness issue.

On 64-bit platforms an aligned u64 load is naturally atomic so tearing
cannot happen.  On 32-bit platforms u64 may tear, but we only test for
zero vs non-zero, so the heuristic stays correct regardless.  Use
data_race() annotation.

Fixes: 47059d930f0e ("Btrfs: make defragment work with nodatacow option")
Signed-off-by: Cen Zhang <zzzccc427@gmail.com>
[ Use data_race() instead of READ_ONCXE() ]
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/btrfs/inode.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/btrfs/inode.c b/fs/btrfs/inode.c
index f1f7ac8684735d..dc5148f176e77c 100644
--- a/fs/btrfs/inode.c
+++ b/fs/btrfs/inode.c
@@ -2317,7 +2317,7 @@ static noinline int run_delalloc_nocow(struct btrfs_inode *inode,
 static bool should_nocow(struct btrfs_inode *inode, u64 start, u64 end)
 {
 	if (inode->flags & (BTRFS_INODE_NODATACOW | BTRFS_INODE_PREALLOC)) {
-		if (inode->defrag_bytes &&
+		if (data_race(inode->defrag_bytes) &&
 		    btrfs_test_range_bit_exists(&inode->io_tree, start, end, EXTENT_DEFRAG))
 			return false;
 		return true;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0613/2077] btrfs: fix deadlock cloning inline extent when using flushoncommit
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (611 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0612/2077] btrfs: annotate lockless read of defrag_bytes in should_nocow() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0614/2077] btrfs: lzo: reject compressed segment that overflows the compressed input Greg Kroah-Hartman
                   ` (384 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+c7443384724bb0f9e913,
	Boris Burkov, Filipe Manana, David Sterba, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Filipe Manana <fdmanana@suse.com>

[ Upstream commit 532085d00eb54c074bdeae648b194765239f4d11 ]

In commit b48c980b6a7e ("btrfs: fix deadlock between reflink and
transaction commit when using flushoncommit") a deadlock was fixed
between reflinks and transaction commits when the fs is mounted with the
flushoncommit option. This happened when we had to copy an inline extent's
data to the destination file. However the issue was fixed only for the
case where the destination offset is 0, it missed the case when the offset
is greater than zero.

Fix this by ensuring we get i_size update whenever we copied an inline
extent's data into the destination file.

Syzbot reported this with the following trace:

   INFO: task kworker/u8:3:57 blocked for more than 143 seconds.
         Not tainted syzkaller #0
   "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
   task:kworker/u8:3    state:D stack:21600 pid:57    tgid:57    ppid:2      task_flags:0x4208160 flags:0x00080000
   Workqueue: writeback wb_workfn (flush-btrfs-129)
   Call Trace:
    <TASK>
    context_switch kernel/sched/core.c:5402 [inline]
    __schedule+0x16f9/0x5500 kernel/sched/core.c:7204
    __schedule_loop kernel/sched/core.c:7283 [inline]
    schedule+0x164/0x360 kernel/sched/core.c:7298
    wait_extent_bit fs/btrfs/extent-io-tree.c:905 [inline]
    btrfs_lock_extent_bits+0x59c/0x700 fs/btrfs/extent-io-tree.c:2008
    btrfs_lock_extent fs/btrfs/extent-io-tree.h:152 [inline]
    btrfs_invalidate_folio+0x440/0xc00 fs/btrfs/inode.c:7718
    extent_writepage fs/btrfs/extent_io.c:1848 [inline]
    extent_write_cache_pages fs/btrfs/extent_io.c:2552 [inline]
    btrfs_writepages+0x12f3/0x2410 fs/btrfs/extent_io.c:2684
    do_writepages+0x32e/0x550 mm/page-writeback.c:2571
    __writeback_single_inode+0x133/0x10e0 fs/fs-writeback.c:1764
    writeback_sb_inodes+0x97f/0x1980 fs/fs-writeback.c:2056
    wb_writeback+0x445/0xb00 fs/fs-writeback.c:2241
    wb_do_writeback fs/fs-writeback.c:2388 [inline]
    wb_workfn+0x3fd/0xf20 fs/fs-writeback.c:2428
    process_one_work+0x98b/0x1630 kernel/workqueue.c:3318
    process_scheduled_works kernel/workqueue.c:3401 [inline]
    worker_thread+0xb49/0x1140 kernel/workqueue.c:3482
    kthread+0x388/0x470 kernel/kthread.c:436
    ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
    ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
    </TASK>
   INFO: task syz.0.145:8523 blocked for more than 143 seconds.
         Not tainted syzkaller #0
   "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
   task:syz.0.145       state:D stack:22752 pid:8523  tgid:8522  ppid:5850   task_flags:0x400140 flags:0x00080002
   Call Trace:
    <TASK>
    context_switch kernel/sched/core.c:5402 [inline]
    __schedule+0x16f9/0x5500 kernel/sched/core.c:7204
    __schedule_loop kernel/sched/core.c:7283 [inline]
    schedule+0x164/0x360 kernel/sched/core.c:7298
    wb_wait_for_completion+0x3e8/0x790 fs/fs-writeback.c:227
    __writeback_inodes_sb_nr+0x24c/0x2d0 fs/fs-writeback.c:2847
    try_to_writeback_inodes_sb+0x9a/0xc0 fs/fs-writeback.c:2895
    btrfs_start_delalloc_flush fs/btrfs/transaction.c:2182 [inline]
    btrfs_commit_transaction+0x813/0x2fc0 fs/btrfs/transaction.c:2371
    btrfs_sync_file+0xdf4/0x1230 fs/btrfs/file.c:1822
    generic_write_sync include/linux/fs.h:2663 [inline]
    btrfs_do_write_iter+0x6a9/0x840 fs/btrfs/file.c:1473
    new_sync_write fs/read_write.c:595 [inline]
    vfs_write+0x629/0xba0 fs/read_write.c:688
    ksys_write+0x156/0x270 fs/read_write.c:740
    do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
    do_syscall_64+0x15f/0x560 arch/x86/entry/syscall_64.c:94
    entry_SYSCALL_64_after_hwframe+0x77/0x7f
   RIP: 0033:0x7f5a0bdece59
   RSP: 002b:00007f5a0b446028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
   RAX: ffffffffffffffda RBX: 00007f5a0c065fa0 RCX: 00007f5a0bdece59
   RDX: 000000000000029f RSI: 0000200000000200 RDI: 0000000000000004
   RBP: 00007f5a0be82d6f R08: 0000000000000000 R09: 0000000000000000
   R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
   R13: 00007f5a0c066038 R14: 00007f5a0c065fa0 R15: 00007ffe149206b8
    </TASK>
   INFO: task syz.0.145:8539 blocked for more than 143 seconds.
         Not tainted syzkaller #0
   "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
   task:syz.0.145       state:D stack:23704 pid:8539  tgid:8522  ppid:5850   task_flags:0x400140 flags:0x00080002
   Call Trace:
    <TASK>
    context_switch kernel/sched/core.c:5402 [inline]
    __schedule+0x16f9/0x5500 kernel/sched/core.c:7204
    __schedule_loop kernel/sched/core.c:7283 [inline]
    schedule+0x164/0x360 kernel/sched/core.c:7298
    wait_current_trans+0x39f/0x590 fs/btrfs/transaction.c:536
    start_transaction+0xbd8/0x1820 fs/btrfs/transaction.c:716
    clone_copy_inline_extent fs/btrfs/reflink.c:299 [inline]
    btrfs_clone+0x1316/0x2540 fs/btrfs/reflink.c:574
    btrfs_clone_files+0x271/0x3f0 fs/btrfs/reflink.c:795
    btrfs_remap_file_range+0x76b/0x1320 fs/btrfs/reflink.c:948
    vfs_clone_file_range+0x435/0x7b0 fs/remap_range.c:403
    ioctl_file_clone fs/ioctl.c:239 [inline]
    ioctl_file_clone_range fs/ioctl.c:257 [inline]
    do_vfs_ioctl+0xe15/0x1540 fs/ioctl.c:544
    __do_sys_ioctl fs/ioctl.c:595 [inline]
    __se_sys_ioctl+0x82/0x170 fs/ioctl.c:583
    do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
    do_syscall_64+0x15f/0x560 arch/x86/entry/syscall_64.c:94
    entry_SYSCALL_64_after_hwframe+0x77/0x7f
   RIP: 0033:0x7f5a0bdece59
   RSP: 002b:00007f5a0b425028 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
   RAX: ffffffffffffffda RBX: 00007f5a0c066090 RCX: 00007f5a0bdece59
   RDX: 00002000000000c0 RSI: 000000004020940d RDI: 0000000000000004
   RBP: 00007f5a0be82d6f R08: 0000000000000000 R09: 0000000000000000
   R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
   R13: 00007f5a0c066128 R14: 00007f5a0c066090 R15: 00007ffe149206b8
    </TASK>

Reported-by: syzbot+c7443384724bb0f9e913@syzkaller.appspotmail.com
Link: https://lore.kernel.org/linux-btrfs/6a150a09.820a0220.e7972.0006.GAE@google.com/
Fixes: 05a5a7621ce6 ("Btrfs: implement full reflink support for inline extents")
Reviewed-by: Boris Burkov <boris@bur.io>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/btrfs/reflink.c | 101 +++++++++++++++++++++++++--------------------
 1 file changed, 57 insertions(+), 44 deletions(-)

diff --git a/fs/btrfs/reflink.c b/fs/btrfs/reflink.c
index 76a7b56f6cdeef..951824b033b78a 100644
--- a/fs/btrfs/reflink.c
+++ b/fs/btrfs/reflink.c
@@ -179,10 +179,12 @@ static int clone_copy_inline_extent(struct btrfs_inode *inode,
 	struct btrfs_drop_extents_args drop_args = { 0 };
 	int ret;
 	struct btrfs_key key;
+	bool copied_inline_to_page = false;
 
 	if (new_key->offset > 0) {
 		ret = copy_inline_to_page(inode, new_key->offset,
 					  inline_data, size, datal, comp_type);
+		copied_inline_to_page = (ret == 0);
 		goto out;
 	}
 
@@ -288,6 +290,60 @@ static int clone_copy_inline_extent(struct btrfs_inode *inode,
 		btrfs_abort_transaction(trans, ret);
 out:
 	if (!ret && !trans) {
+		if (copied_inline_to_page &&
+		    new_key->offset + datal > i_size_read(&inode->vfs_inode)) {
+			/*
+			 * If we copied the inline extent data to a page/folio
+			 * beyond the i_size of the destination inode, then we
+			 * need to increase the i_size before we start a
+			 * transaction to update the inode item. This is to
+			 * prevent a deadlock when the flushoncommit mount
+			 * option is used, which happens like this:
+			 *
+			 * 1) Task A clones an inline extent from inode X to an
+			 *    offset of inode Y that is beyond Y's current
+			 *    i_size. This means we copied the inline extent's
+			 *    data to a folio of inode Y that is beyond its EOF,
+			 *    using the call above to copy_inline_to_page();
+			 *
+			 * 2) Task B starts a transaction commit and calls
+			 *    btrfs_start_delalloc_flush() to flush delalloc;
+			 *
+			 * 3) The delalloc flushing sees the new dirty folio of
+			 *    inode Y and when it attempts to flush it, it ends
+			 *    up at extent_writepage() and sees that the offset
+			 *    of the folio is beyond the i_size of inode Y, so
+			 *    it attempts to invalidate the folio by calling
+			 *    folio_invalidate(), which ends up at btrfs' folio
+			 *    invalidate callback - btrfs_invalidate_folio().
+			 *    There it tries to lock the folio's range in inode
+			 *    Y's extent io tree, but it blocks since it's
+			 *    currently locked by task A - during reflink we
+			 *    lock the inodes and the source and destination
+			 *    ranges after flushing all delalloc and waiting for
+			 *    ordered extent completion - after that we don't
+			 *    expect to have dirty folios in the ranges, the
+			 *    exception is if we have to copy an inline extent's
+			 *    data (because the destination offset is not zero);
+			 *
+			 * 4) Task A then does the 'goto out' below and attempts
+			 *    to start a transaction to update the inode item,
+			 *    and then it's blocked since the current
+			 *    transaction is in the TRANS_STATE_COMMIT_START
+			 *    state. Therefore task A has to wait for the
+			 *    current transaction to become unblocked (its
+			 *    state >= TRANS_STATE_UNBLOCKED).
+			 *
+			 * This leads to a deadlock - the task committing the
+			 * transaction waiting for the delalloc flushing which
+			 * is blocked during folio invalidation on the inode's
+			 * extent lock and the reflink task waiting for the
+			 * current transaction to be unblocked so that it can
+			 * start a new one to update the inode item (while
+			 * holding the extent lock).
+			 */
+			i_size_write(&inode->vfs_inode, new_key->offset + datal);
+		}
 		/*
 		 * No transaction here means we copied the inline extent into a
 		 * page of the destination inode.
@@ -320,50 +376,7 @@ static int clone_copy_inline_extent(struct btrfs_inode *inode,
 
 	ret = copy_inline_to_page(inode, new_key->offset,
 				  inline_data, size, datal, comp_type);
-
-	/*
-	 * If we copied the inline extent data to a page/folio beyond the i_size
-	 * of the destination inode, then we need to increase the i_size before
-	 * we start a transaction to update the inode item. This is to prevent a
-	 * deadlock when the flushoncommit mount option is used, which happens
-	 * like this:
-	 *
-	 * 1) Task A clones an inline extent from inode X to an offset of inode
-	 *    Y that is beyond Y's current i_size. This means we copied the
-	 *    inline extent's data to a folio of inode Y that is beyond its EOF,
-	 *    using the call above to copy_inline_to_page();
-	 *
-	 * 2) Task B starts a transaction commit and calls
-	 *    btrfs_start_delalloc_flush() to flush delalloc;
-	 *
-	 * 3) The delalloc flushing sees the new dirty folio of inode Y and when
-	 *    it attempts to flush it, it ends up at extent_writepage() and sees
-	 *    that the offset of the folio is beyond the i_size of inode Y, so
-	 *    it attempts to invalidate the folio by calling folio_invalidate(),
-	 *    which ends up at btrfs' folio invalidate callback -
-	 *    btrfs_invalidate_folio(). There it tries to lock the folio's range
-	 *    in inode Y's extent io tree, but it blocks since it's currently
-	 *    locked by task A - during reflink we lock the inodes and the
-	 *    source and destination ranges after flushing all delalloc and
-	 *    waiting for ordered extent completion - after that we don't expect
-	 *    to have dirty folios in the ranges, the exception is if we have to
-	 *    copy an inline extent's data (because the destination offset is
-	 *    not zero);
-	 *
-	 * 4) Task A then does the 'goto out' below and attempts to start a
-	 *    transaction to update the inode item, and then it's blocked since
-	 *    the current transaction is in the TRANS_STATE_COMMIT_START state.
-	 *    Therefore task A has to wait for the current transaction to become
-	 *    unblocked (its state >= TRANS_STATE_UNBLOCKED).
-	 *
-	 * This leads to a deadlock - the task committing the transaction
-	 * waiting for the delalloc flushing which is blocked during folio
-	 * invalidation on the inode's extent lock and the reflink task waiting
-	 * for the current transaction to be unblocked so that it can start a
-	 * a new one to update the inode item (while holding the extent lock).
-	 */
-	if (ret == 0 && new_key->offset + datal > i_size_read(&inode->vfs_inode))
-		i_size_write(&inode->vfs_inode, new_key->offset + datal);
+	copied_inline_to_page = (ret == 0);
 
 	goto out;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0614/2077] btrfs: lzo: reject compressed segment that overflows the compressed input
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (612 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0613/2077] btrfs: fix deadlock cloning inline extent when using flushoncommit Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0615/2077] ixgbe: do not configure xps for XDP queues Greg Kroah-Hartman
                   ` (383 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Xiang Mei, Qu Wenruo, Weiming Shi,
	David Sterba, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Weiming Shi <bestswngs@gmail.com>

[ Upstream commit b0d27d43791b7a3057c3c4aedf9b4aa033d37c46 ]

lzo_decompress_bio() validates each on-disk segment length seg_len only
against the workspace cbuf size, not against the compressed input size
(compressed_len, the total folio bytes of the bio).  A crafted extent can
carry a segment whose seg_len passes the cbuf check but runs past the end
of the bio, so copy_compressed_segment() walks off the last folio:
get_current_folio() then returns the NULL folio from bio_next_folio(), and
with CONFIG_BTRFS_ASSERT disabled (default) folio_size(NULL) faults.

 BUG: KASAN: null-ptr-deref in lzo_decompress_bio (fs/btrfs/lzo.c:383)
 Read of size 8 at addr 0000000000000000 by task kworker/u8:1/29
 Workqueue: btrfs-endio simple_end_io_work
  kasan_report (mm/kasan/report.c:590)
  lzo_decompress_bio (fs/btrfs/lzo.c:383)
  end_bbio_compressed_read (fs/btrfs/compression.c:1065)
  btrfs_bio_end_io (fs/btrfs/bio.c:135)
  btrfs_check_read_bio (fs/btrfs/bio.c:180 fs/btrfs/bio.c:285)
  simple_end_io_work
  process_one_work
  worker_thread

Reject any segment whose payload would extend beyond compressed_len before
copying it, treating it as corruption like the other on-disk validation
failures in this function.

Reported-by: Xiang Mei <xmei5@asu.edu>
Fixes: a6e66e6f8c1b ("btrfs: rework lzo_decompress_bio() to make it subpage compatible")
Assisted-by: Claude:claude-opus-4-8
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/btrfs/lzo.c | 11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/fs/btrfs/lzo.c b/fs/btrfs/lzo.c
index 2de18c7b563afd..6e4aa22853aba2 100644
--- a/fs/btrfs/lzo.c
+++ b/fs/btrfs/lzo.c
@@ -491,6 +491,17 @@ int lzo_decompress_bio(struct list_head *ws, struct compressed_bio *cb)
 			return -EIO;
 		}
 
+		/* The segment must not extend beyond the compressed input. */
+		if (unlikely(cur_in + seg_len > compressed_len)) {
+			struct btrfs_inode *inode = cb->bbio.inode;
+
+			btrfs_err(fs_info,
+			"lzo segment overflows compressed input, root %llu inode %llu offset %llu cur_in %u len %u compressed len %u",
+				  btrfs_root_id(inode->root), btrfs_ino(inode),
+				  cb->start, cur_in, seg_len, compressed_len);
+			return -EUCLEAN;
+		}
+
 		/* Copy the compressed segment payload into workspace */
 		copy_compressed_segment(cb, &fi, &cur_folio_index, workspace->cbuf,
 					seg_len, &cur_in);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0615/2077] ixgbe: do not configure xps for XDP queues
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (613 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0614/2077] btrfs: lzo: reject compressed segment that overflows the compressed input Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0616/2077] igc: skip RX timestamp header for frame preemption verification Greg Kroah-Hartman
                   ` (382 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alexander Lobakin,
	Aleksandr Loktionov, Larysa Zaremba, Simon Horman, Patryk Holda,
	Tony Nguyen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Larysa Zaremba <larysa.zaremba@intel.com>

[ Upstream commit 7bd4355272de34c2e90e34b72c5613736d03c32b ]

netif_set_xps_queue() should not be called for an XDP Tx queue, since such
queues are not netdev-exposed. On systems with number of CPUs >=64, on E610
adapter, netdev is configured with maximum number queue pairs being 63
(due to MSI-X assignment), but configuring XDP results in 64 XDP queues.

So, during XDP program load, when netif_set_xps_queue() is called for the
last XDP queue, we get a WARNING with a call trace and KASAN report
afterwards (if enabled).

[ 2012.699800] WARNING: net/core/dev.c:2854 at __netif_set_xps_queue+0x116a/0x1e40, CPU#36: xdpsock/103668
[...]
[ 2012.700029] RIP: 0010:__netif_set_xps_queue+0x116a/0x1e40
[ 2012.700035] Code: b6 34 06 48 89 f8 83 e0 07 83 c0 01 40 38 f0 7c 09 40 84 f6 0f 85 03 0a 00 00 0f b7 44 24 40 66 43 89 44 6a 18 e9 01 fb ff ff <0f> 0b e9 f2 ee ff ff 44 8b 44 24 44 45 85 c0 74 50 4d 85 e4 0f 84
[ 2012.700040] RSP: 0018:ffff8882369aeb28 EFLAGS: 00010246
[ 2012.700046] RAX: 0000000000000000 RBX: 000000000000003f RCX: 0000000000000000
[ 2012.700050] RDX: 1ffff1111da3d891 RSI: ffff888120e34250 RDI: ffff8888ed1ec488
[ 2012.700054] RBP: ffff888913281560 R08: 0000000000000000 R09: ffff8888ed1ec000
[ 2012.700058] R10: ffff8888a2e83180 R11: 0000000000000000 R12: 0000000000007fa8
[ 2012.700061] R13: 000000000000003f R14: ffff888120e34854 R15: ffff8889132817c8
[ 2012.700065] FS:  00007fc8ea9ff740(0000) GS:ffff88884cefe000(0000) knlGS:0000000000000000
[ 2012.700069] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 2012.700073] CR2: 00007f81c8000020 CR3: 00000002299f8006 CR4: 00000000007726f0
[ 2012.700077] PKRU: 55555554
[ 2012.700080] Call Trace:
[ 2012.700084]  <TASK>
[ 2012.700087]  ? ktime_get+0x61/0x150
[ 2012.700097]  ? usleep_range_state+0x133/0x1b0
[ 2012.700108]  ? __pfx_usleep_range_state+0x10/0x10
[ 2012.700114]  netif_set_xps_queue+0x31/0x50
[ 2012.700119]  ixgbe_configure_tx_ring+0x472/0x920 [ixgbe]
[...]
[ 2012.700486]  ixgbe_xdp+0x38f/0x750 [ixgbe]

[...]

[ 2012.701094] BUG: KASAN: slab-out-of-bounds in __netif_set_xps_queue+0x1ac5/0x1e40
[ 2012.701100] Write of size 4 at addr ffff88888d43cff8 by task xdpsock/103668

Skip XPS configuration for XDP Tx queues.

Fixes: 33fdc82f0883 ("ixgbe: add support for XDP_TX action")
Reviewed-by: Alexander Lobakin <aleksander.lobakin@intel.com>
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Signed-off-by: Larysa Zaremba <larysa.zaremba@intel.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Tested-by: Patryk Holda <patryk.holda@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/intel/ixgbe/ixgbe_main.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c b/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c
index 2646ee6f295f02..9ec250c262842f 100644
--- a/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c
+++ b/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c
@@ -3958,7 +3958,8 @@ void ixgbe_configure_tx_ring(struct ixgbe_adapter *adapter,
 	}
 
 	/* initialize XPS */
-	if (!test_and_set_bit(__IXGBE_TX_XPS_INIT_DONE, ring->state)) {
+	if (!ring_is_xdp(ring) &&
+	    !test_and_set_bit(__IXGBE_TX_XPS_INIT_DONE, ring->state)) {
 		struct ixgbe_q_vector *q_vector = ring->q_vector;
 
 		if (q_vector)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0616/2077] igc: skip RX timestamp header for frame preemption verification
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (614 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0615/2077] ixgbe: do not configure xps for XDP queues Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0617/2077] ASoC: sma1307: Fix uevent string leaks in fault worker Greg Kroah-Hartman
                   ` (381 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Faizal Rahim, KhaiWenTan,
	Aleksandr Loktionov, Tony Nguyen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: KhaiWenTan <khai.wen.tan@linux.intel.com>

[ Upstream commit 38b7a274cf84af9b1f4b602b8e2741565b81947b ]

When RX hardware timestamping is enabled, a 16-byte inline timestamp header
is added to the start of the packet buffer, causing FPE handshake
verification to fail.

Because an incorrect packet buffer is passed to igc_fpe_handle_mpacket(),
the mem_is_zero() check inspects the timestamp metadata instead of the
actual mPacket payload. As a result, valid Verify/Response mPackets can be
missed when inline RX timestamps are present.

Pass pktbuf + pkt_offset to igc_fpe_handle_mpacket() so it inspects the
actual mPacket payload instead of the timestamp header.

Fixes: 5422570c0010 ("igc: add support for frame preemption verification")
Co-developed-by: Faizal Rahim <faizal.abdul.rahim@linux.intel.com>
Signed-off-by: Faizal Rahim <faizal.abdul.rahim@linux.intel.com>
Signed-off-by: KhaiWenTan <khai.wen.tan@linux.intel.com>
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/intel/igc/igc_main.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/intel/igc/igc_main.c b/drivers/net/ethernet/intel/igc/igc_main.c
index 8ac16808023cc6..c470d2354ce8ff 100644
--- a/drivers/net/ethernet/intel/igc/igc_main.c
+++ b/drivers/net/ethernet/intel/igc/igc_main.c
@@ -2649,7 +2649,7 @@ static int igc_clean_rx_irq(struct igc_q_vector *q_vector, const int budget)
 		}
 
 		if (igc_fpe_is_pmac_enabled(adapter) &&
-		    igc_fpe_handle_mpacket(adapter, rx_desc, size, pktbuf)) {
+		    igc_fpe_handle_mpacket(adapter, rx_desc, size, pktbuf + pkt_offset)) {
 			/* Advance the ring next-to-clean */
 			igc_is_non_eop(rx_ring, rx_desc);
 			cleaned_count++;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0617/2077] ASoC: sma1307: Fix uevent string leaks in fault worker
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (615 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0616/2077] igc: skip RX timestamp header for frame preemption verification Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0618/2077] IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified Greg Kroah-Hartman
                   ` (380 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cássio Gabriel <cassiogabrielcontato@gmail.com>

[ Upstream commit a750ca72af72dde9744468fdca6eda0b698a1cfc ]

sma1307_check_fault_worker() stores dynamically allocated uevent strings in
envp[0]. Several fault conditions are checked in sequence, so a later fault
can overwrite envp[0] before the final kfree() and leak the previous
allocation.

The same flow can leave an OT1 volume entry in envp[1] while envp[0]
has been overwritten by a later non-OT1 fault, causing an inconsistent
uevent payload.

Use static STATUS strings and a stack buffer for the optional VOLUME entry.
This removes the allocations from the worker and keeps VOLUME tied only
to the OT1 events that produce it.

Fixes: 576c57e6b4c1 ("ASoC: sma1307: Add driver for Iron Device SMA1307")
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260609-asoc-sma1307-uevent-leak-v1-1-cd7f5b062ab7@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/codecs/sma1307.c | 35 +++++++++++++++++++++--------------
 1 file changed, 21 insertions(+), 14 deletions(-)

diff --git a/sound/soc/codecs/sma1307.c b/sound/soc/codecs/sma1307.c
index 5850bf6e71cade..5cc0834873f00b 100644
--- a/sound/soc/codecs/sma1307.c
+++ b/sound/soc/codecs/sma1307.c
@@ -1592,6 +1592,7 @@ static void sma1307_check_fault_worker(struct work_struct *work)
 	struct sma1307_priv *sma1307 =
 	    container_of(work, struct sma1307_priv, check_fault_work.work);
 	unsigned int status1_val, status2_val;
+	char volume[sizeof("VOLUME=0x12345678")];
 	char *envp[3] = { NULL, NULL, NULL };
 
 	if (sma1307->tsdw_cnt)
@@ -1607,7 +1608,7 @@ static void sma1307_check_fault_worker(struct work_struct *work)
 	if (~status1_val & SMA1307_OT1_OK_STATUS) {
 		dev_crit(sma1307->dev,
 			 "%s: OT1(Over Temperature Level 1)\n", __func__);
-		envp[0] = kasprintf(GFP_KERNEL, "STATUS=OT1");
+		envp[0] = "STATUS=OT1";
 		if (sma1307->sw_ot1_prot) {
 			/* Volume control (Current Volume -3dB) */
 			if ((sma1307->cur_vol + 6) <= 0xFA) {
@@ -1615,8 +1616,9 @@ static void sma1307_check_fault_worker(struct work_struct *work)
 				regmap_write(sma1307->regmap,
 						     SMA1307_0A_SPK_VOL,
 						     sma1307->cur_vol);
-				envp[1] = kasprintf(GFP_KERNEL,
-					"VOLUME=0x%02X", sma1307->cur_vol);
+				snprintf(volume, sizeof(volume),
+					 "VOLUME=0x%02X", sma1307->cur_vol);
+				envp[1] = volume;
 			}
 		}
 		sma1307->tsdw_cnt++;
@@ -1625,48 +1627,53 @@ static void sma1307_check_fault_worker(struct work_struct *work)
 				     SMA1307_0A_SPK_VOL, sma1307->init_vol);
 		sma1307->tsdw_cnt = 0;
 		sma1307->cur_vol = sma1307->init_vol;
-		envp[0] = kasprintf(GFP_KERNEL, "STATUS=OT1_CLEAR");
-		envp[1] = kasprintf(GFP_KERNEL,
-				"VOLUME=0x%02X", sma1307->cur_vol);
+		envp[0] = "STATUS=OT1_CLEAR";
+		snprintf(volume, sizeof(volume), "VOLUME=0x%02X",
+			 sma1307->cur_vol);
+		envp[1] = volume;
 	}
 
 	if (~status1_val & SMA1307_OT2_OK_STATUS) {
 		dev_crit(sma1307->dev,
 			 "%s: OT2(Over Temperature Level 2)\n", __func__);
-		envp[0] = kasprintf(GFP_KERNEL, "STATUS=OT2");
+		envp[0] = "STATUS=OT2";
+		envp[1] = NULL;
 	}
 	if (status1_val & SMA1307_UVLO_STATUS) {
 		dev_crit(sma1307->dev,
 			 "%s: UVLO(Under Voltage Lock Out)\n", __func__);
-		envp[0] = kasprintf(GFP_KERNEL, "STATUS=UVLO");
+		envp[0] = "STATUS=UVLO";
+		envp[1] = NULL;
 	}
 	if (status1_val & SMA1307_OVP_BST_STATUS) {
 		dev_crit(sma1307->dev,
 			 "%s: OVP_BST(Over Voltage Protection)\n", __func__);
-		envp[0] = kasprintf(GFP_KERNEL, "STATUS=OVP_BST");
+		envp[0] = "STATUS=OVP_BST";
+		envp[1] = NULL;
 	}
 	if (status2_val & SMA1307_OCP_SPK_STATUS) {
 		dev_crit(sma1307->dev,
 			 "%s: OCP_SPK(Over Current Protect SPK)\n", __func__);
-		envp[0] = kasprintf(GFP_KERNEL, "STATUS=OCP_SPK");
+		envp[0] = "STATUS=OCP_SPK";
+		envp[1] = NULL;
 	}
 	if (status2_val & SMA1307_OCP_BST_STATUS) {
 		dev_crit(sma1307->dev,
 			 "%s: OCP_BST(Over Current Protect Boost)\n", __func__);
-		envp[0] = kasprintf(GFP_KERNEL, "STATUS=OCP_BST");
+		envp[0] = "STATUS=OCP_BST";
+		envp[1] = NULL;
 	}
 	if (status2_val & SMA1307_CLK_MON_STATUS) {
 		dev_crit(sma1307->dev,
 			 "%s: CLK_FAULT(No clock input)\n", __func__);
-		envp[0] = kasprintf(GFP_KERNEL, "STATUS=CLK_FAULT");
+		envp[0] = "STATUS=CLK_FAULT";
+		envp[1] = NULL;
 	}
 
 	if (envp[0] != NULL) {
 		if (kobject_uevent_env(sma1307->kobj, KOBJ_CHANGE, envp))
 			dev_err(sma1307->dev,
 				"%s: Error sending uevent\n", __func__);
-		kfree(envp[0]);
-		kfree(envp[1]);
 	}
 
 	if (sma1307->check_fault_status) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0618/2077] IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (616 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0617/2077] ASoC: sma1307: Fix uevent string leaks in fault worker Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0619/2077] NFSD: Handle layout stid in nfsd4_drop_revoked_stid() Greg Kroah-Hartman
                   ` (379 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jason Gunthorpe <jgg@nvidia.com>

[ Upstream commit bade9a3150d44ed20b8c6484c4c8a943b7289abb ]

Sashiko noticed mlx4 was using whatever random access flags were provided
when IB_MR_REREG_ACCESS is not used. Since IB_MR_REREG_TRANS needs
access_flags it used the random ones which means it doesn't work sensibly
if userspace provides only IB_MR_REREG_TRANS.

Keep track of the current access_flag of the MR and use it if the user
does not specify one.

Also fixup a little confusion around mmr.access, it is the HW access flags
so the convert_access() was missing. But nothing reads this by the time
rereg_mr can happen.

Fixes: 9376932d0c26 ("IB/mlx4_ib: Add support for user MR re-registration")
Link: https://patch.msgid.link/r/0-v1-29ca7a402625+ddd6-mlx4_rereg_flags_jgg@nvidia.com
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx4/mlx4_ib.h | 1 +
 drivers/infiniband/hw/mlx4/mr.c      | 9 +++++++--
 2 files changed, 8 insertions(+), 2 deletions(-)

diff --git a/drivers/infiniband/hw/mlx4/mlx4_ib.h b/drivers/infiniband/hw/mlx4/mlx4_ib.h
index 5a799d6df93ebc..898c8363422abb 100644
--- a/drivers/infiniband/hw/mlx4/mlx4_ib.h
+++ b/drivers/infiniband/hw/mlx4/mlx4_ib.h
@@ -135,6 +135,7 @@ struct mlx4_ib_mr {
 	dma_addr_t		page_map;
 	u32			npages;
 	u32			max_pages;
+	int			access_flags;
 	struct mlx4_mr		mmr;
 	struct ib_umem	       *umem;
 	size_t			page_map_size;
diff --git a/drivers/infiniband/hw/mlx4/mr.c b/drivers/infiniband/hw/mlx4/mr.c
index 6747bca3067770..67b0e8954b5e5e 100644
--- a/drivers/infiniband/hw/mlx4/mr.c
+++ b/drivers/infiniband/hw/mlx4/mr.c
@@ -181,6 +181,7 @@ struct ib_mr *mlx4_ib_reg_user_mr(struct ib_pd *pd, u64 start, u64 length,
 	if (err)
 		goto err_mr;
 
+	mr->access_flags = access_flags;
 	mr->ibmr.rkey = mr->ibmr.lkey = mr->mmr.key;
 	mr->ibmr.page_size = 1U << shift;
 
@@ -241,6 +242,8 @@ struct ib_mr *mlx4_ib_rereg_user_mr(struct ib_mr *mr, int flags, u64 start,
 
 		if (err)
 			goto release_mpt_entry;
+	} else {
+		mr_access_flags = mmr->access_flags;
 	}
 
 	if (flags & IB_MR_REREG_TRANS) {
@@ -282,8 +285,10 @@ struct ib_mr *mlx4_ib_rereg_user_mr(struct ib_mr *mr, int flags, u64 start,
 	 * return a failure. But dereg_mr will free the resources.
 	 */
 	err = mlx4_mr_hw_write_mpt(dev->dev, &mmr->mmr, pmpt_entry);
-	if (!err && flags & IB_MR_REREG_ACCESS)
-		mmr->mmr.access = mr_access_flags;
+	if (!err && flags & IB_MR_REREG_ACCESS) {
+		mmr->access_flags = mr_access_flags;
+		mmr->mmr.access = convert_access(mr_access_flags);
+	}
 
 release_mpt_entry:
 	mlx4_mr_hw_put_mpt(dev->dev, pmpt_entry);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0619/2077] NFSD: Handle layout stid in nfsd4_drop_revoked_stid()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (617 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0618/2077] IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0620/2077] lockd: Stop warning on nlm__int__drop_reply in !V4 cast_status Greg Kroah-Hartman
                   ` (378 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jeff Layton, Dai Ngo, Chuck Lever,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 86b9898920a6d02b4149f4fef9efd77b8aa3b9ca ]

nfsd4_drop_revoked_stid() has no SC_TYPE_LAYOUT case, so when a
client sends FREE_STATEID for an admin-revoked layout stid, the
default branch releases cl_lock and returns without unhashing or
releasing the stid.  The stid remains in the IDR and on the
per-client list until the client is destroyed.

Remove the layout stid from the per-client list and call
nfs4_put_stid() to drop the creation reference.  When the
refcount reaches zero, nfsd4_free_layout_stateid() handles the
remaining cleanup: cancelling the fence worker, removing from
the per-file list, and freeing the slab object.

Fixes: 1e33e1414bec ("nfsd: allow layout state to be admin-revoked.")
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Tested-by: Dai Ngo <dai.ngo@oracle.com>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/nfsd/nfs4state.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/fs/nfsd/nfs4state.c b/fs/nfsd/nfs4state.c
index 2696a9fef0291c..523db702464c17 100644
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -5056,6 +5056,7 @@ static void nfsd4_drop_revoked_stid(struct nfs4_stid *s)
 {
 	struct nfs4_client *cl = s->sc_client;
 	LIST_HEAD(reaplist);
+	struct nfs4_layout_stateid *ls;
 	struct nfs4_ol_stateid *stp;
 	struct nfs4_delegation *dp;
 	bool unhashed;
@@ -5081,6 +5082,12 @@ static void nfsd4_drop_revoked_stid(struct nfs4_stid *s)
 		spin_unlock(&cl->cl_lock);
 		nfs4_put_stid(s);
 		break;
+	case SC_TYPE_LAYOUT:
+		ls = layoutstateid(s);
+		list_del_init(&ls->ls_perclnt);
+		spin_unlock(&cl->cl_lock);
+		nfs4_put_stid(s);
+		break;
 	default:
 		spin_unlock(&cl->cl_lock);
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0620/2077] lockd: Stop warning on nlm__int__drop_reply in !V4 cast_status
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (618 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0619/2077] NFSD: Handle layout stid in nfsd4_drop_revoked_stid() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0621/2077] lockd: Translate nlm__int__deadlock in __nlm4svc_proc_lock_msg() Greg Kroah-Hartman
                   ` (377 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jeff Layton, Chuck Lever,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 5cca6056f2bae9be14566e0f7f6e351103a6aef3 ]

cast_status folds internal lock-daemon sentinels into NLMv1/v3
wire status codes.  The !CONFIG_LOCKD_V4 variant warns when an
unrecognized status falls into the internal-sentinel range,
gated by be32_to_cpu(status) >= 30000.

nlm__int__drop_reply is defined as cpu_to_be32(30000), so it
sits at the lower edge of that range and trips pr_warn_once
("lockd: unhandled internal status %u").  The status is
returned unchanged so the reply is still dropped, but every
dropped reply on a !CONFIG_LOCKD_V4 build emits a spurious
warning.

Compare against nlm__int__drop_reply directly so the warning
still catches the genuinely unexpected sentinels deadlock,
stale_fh, and failed (30001 through 30003) but excludes the
legitimate dropped-reply marker.

Fixes: d343fce148a4 ("[PATCH] knfsd: Allow lockd to drop replies as appropriate")
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/lockd/svcproc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/lockd/svcproc.c b/fs/lockd/svcproc.c
index c0a3487719e283..110e186802b6cd 100644
--- a/fs/lockd/svcproc.c
+++ b/fs/lockd/svcproc.c
@@ -49,7 +49,7 @@ static inline __be32 cast_status(__be32 status)
 		status = nlm_lck_denied_nolocks;
 		break;
 	default:
-		if (be32_to_cpu(status) >= 30000)
+		if (be32_to_cpu(status) > be32_to_cpu(nlm__int__drop_reply))
 			pr_warn_once("lockd: unhandled internal status %u\n",
 				     be32_to_cpu(status));
 		break;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0621/2077] lockd: Translate nlm__int__deadlock in __nlm4svc_proc_lock_msg()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (619 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0620/2077] lockd: Stop warning on nlm__int__drop_reply in !V4 cast_status Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0622/2077] lockd: Do not monitor when looking up the LOCK_MSG callback host Greg Kroah-Hartman
                   ` (376 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jeff Layton, Chuck Lever,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 2175ca75882e346c9d8741a2196693d70f635340 ]

When nlmsvc_lock() detects a deadlock it returns the internal
sentinel nlm__int__deadlock (30001), which version-specific
handlers must translate to a wire-valid status before the reply
is encoded.  The xdrgen LOCK_MSG handler stores the sentinel
unmodified in resp->status; the LOCK_RES callback then places
30001 on the v4 wire, where the client rejects the reply.

Commit 9e0d0c619407 ("lockd: Introduce nlm__int__deadlock")
established the translation boundary and updated the synchronous
v4 path nlm4svc_do_lock(), but the xdrgen LOCK_MSG handler added
later in commit b2be4e28c23a ("lockd: Use xdrgen XDR functions
for the NLMv4 LOCK_MSG procedure") missed the corresponding
remap.  Apply the same translation in __nlm4svc_proc_lock_msg()
so deadlock results are reported as nlm4_deadlock on LOCK_RES.

Fixes: b2be4e28c23a ("lockd: Use xdrgen XDR functions for the NLMv4 LOCK_MSG procedure")
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/lockd/svc4proc.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/fs/lockd/svc4proc.c b/fs/lockd/svc4proc.c
index 41cab858de5782..74070e33cb3e2d 100644
--- a/fs/lockd/svc4proc.c
+++ b/fs/lockd/svc4proc.c
@@ -669,6 +669,8 @@ __nlm4svc_proc_lock_msg(struct svc_rqst *rqstp, struct nlm_res *resp)
 	resp->status = nlmsvc_lock(rqstp, file, host, &argp->lock,
 				   argp->xdrgen.block, &resp->cookie,
 				   argp->xdrgen.reclaim);
+	if (resp->status == nlm__int__deadlock)
+		resp->status = nlm4_deadlock;
 	nlmsvc_release_lockowner(&argp->lock);
 
 out:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0622/2077] lockd: Do not monitor when looking up the LOCK_MSG callback host
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (620 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0621/2077] lockd: Translate nlm__int__deadlock in __nlm4svc_proc_lock_msg() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0623/2077] lockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file() Greg Kroah-Hartman
                   ` (375 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jeff Layton, Chuck Lever,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit b3d200166a35305ac77941845dcab99bb6badd76 ]

A LOCK_MSG handler that fails to obtain a host returns
rpc_system_err, which causes the dispatcher to send an RPC-level
error rather than an NLM LOCK_RES denial. Before the xdrgen
conversion, the outer host lookup was unmonitored, so an NSM
upcall failure was reported back to the client through LOCK_RES
with status nlm_lck_denied_nolocks generated by the inner helper.

The xdrgen conversion replaced the unmonitored lookup with
nlm4svc_lookup_host(..., true). When nsm_monitor() fails, the
outer lookup now returns NULL, so the procedure short-circuits to
rpc_system_err and __nlm4svc_proc_lock_msg() never runs. The
client therefore receives no LOCK_RES, regressing the legacy
behavior.

The inner helper still performs a monitored lookup while building
the LOCK_RES, so the outer call only needs an unmonitored host
reference for the callback path. Pass false here to restore the
previous semantics.

Fixes: b2be4e28c23a ("lockd: Use xdrgen XDR functions for the NLMv4 LOCK_MSG procedure")
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/lockd/svc4proc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/lockd/svc4proc.c b/fs/lockd/svc4proc.c
index 74070e33cb3e2d..ca1d165e0d8606 100644
--- a/fs/lockd/svc4proc.c
+++ b/fs/lockd/svc4proc.c
@@ -699,7 +699,7 @@ static __be32 nlm4svc_proc_lock_msg(struct svc_rqst *rqstp)
 	struct nlm4_lockargs_wrapper *argp = rqstp->rq_argp;
 	struct nlm_host *host;
 
-	host = nlm4svc_lookup_host(rqstp, argp->xdrgen.alock.caller_name, true);
+	host = nlm4svc_lookup_host(rqstp, argp->xdrgen.alock.caller_name, false);
 	if (!host)
 		return rpc_system_err;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0623/2077] lockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (621 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0622/2077] lockd: Do not monitor when looking up the LOCK_MSG callback host Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0624/2077] spi: meson-spifc: fix runtime PM leak on remove Greg Kroah-Hartman
                   ` (374 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jeff Layton, Chuck Lever,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 6e4c62caecf792e8a15ad9bc7f371e57c17e3302 ]

file_hash() digests the first LOCKD_FH_HASH_SIZE bytes of
nfs_fh.data when bucketing nlm_files[], independent of fh.size.
Commit 3de744ee4e45 ("lockd: Use xdrgen XDR functions for the
NLMv4 TEST procedure") set .pc_argzero to zero for the converted
procedures and moved file-handle population into
nlm4svc_lookup_file(), which copies only xdr_lock->fh.len bytes
into lock->fh.data.

When an NLMv4 client presents a file handle shorter than
LOCKD_FH_HASH_SIZE, bytes fh.len..31 retain whatever the argument
buffer held from an earlier request.  The same wire handle then
hashes to different buckets across calls; nlm_lookup_file() misses
the existing nlm_file entry, and lock-state lookups fail.

Zero only the tail bytes that file_hash() would otherwise consume.
Handles of LOCKD_FH_HASH_SIZE or larger already populate every byte
that file_hash() reads.

Reported-by: Jeff Layton <jlayton@kernel.org>
Closes: https://lore.kernel.org/r/5229a9746d723a3f830120c0b966510f75badfc2.camel@kernel.org
Fixes: 3de744ee4e45 ("lockd: Use xdrgen XDR functions for the NLMv4 TEST procedure")
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/lockd/lockd.h    | 8 ++++++++
 fs/lockd/svc4proc.c | 3 +++
 fs/lockd/svcsubs.c  | 3 +--
 3 files changed, 12 insertions(+), 2 deletions(-)

diff --git a/fs/lockd/lockd.h b/fs/lockd/lockd.h
index 1db6cb3525425d..9aa6acb43f9a4d 100644
--- a/fs/lockd/lockd.h
+++ b/fs/lockd/lockd.h
@@ -52,6 +52,14 @@
  */
 #define LOCKD_DFLT_TIMEO	10
 
+/*
+ * Number of leading bytes of nfs_fh.data that file_hash()
+ * digests when bucketing nlm_files[]. Sized for historical
+ * NFSv2 handles; nfs_fh.data must be initialized at least
+ * this far before lookup, regardless of fh.size.
+ */
+#define LOCKD_FH_HASH_SIZE	32
+
 /* error codes new to NLMv4 */
 #define	nlm4_deadlock		cpu_to_be32(NLM_DEADLCK)
 #define	nlm4_rofs		cpu_to_be32(NLM_ROFS)
diff --git a/fs/lockd/svc4proc.c b/fs/lockd/svc4proc.c
index ca1d165e0d8606..3bf6cccae56858 100644
--- a/fs/lockd/svc4proc.c
+++ b/fs/lockd/svc4proc.c
@@ -157,6 +157,9 @@ nlm4svc_lookup_file(struct svc_rqst *rqstp, struct nlm_host *host,
 		return nlm_lck_denied_nolocks;
 	lock->fh.size = xdr_lock->fh.len;
 	memcpy(lock->fh.data, xdr_lock->fh.data, xdr_lock->fh.len);
+	if (xdr_lock->fh.len < LOCKD_FH_HASH_SIZE)
+		memset(lock->fh.data + xdr_lock->fh.len, 0,
+		       LOCKD_FH_HASH_SIZE - xdr_lock->fh.len);
 
 	lock->oh.len = xdr_lock->oh.len;
 	lock->oh.data = xdr_lock->oh.data;
diff --git a/fs/lockd/svcsubs.c b/fs/lockd/svcsubs.c
index 9da9d6e0b42e25..95a499940daf2f 100644
--- a/fs/lockd/svcsubs.c
+++ b/fs/lockd/svcsubs.c
@@ -17,7 +17,6 @@
 #include <linux/sunrpc/addr.h>
 #include <linux/module.h>
 #include <linux/mount.h>
-#include <uapi/linux/nfs2.h>
 
 #include "lockd.h"
 #include "share.h"
@@ -67,7 +66,7 @@ static inline unsigned int file_hash(struct nfs_fh *f)
 {
 	unsigned int tmp=0;
 	int i;
-	for (i=0; i<NFS2_FHSIZE;i++)
+	for (i = 0; i < LOCKD_FH_HASH_SIZE; i++)
 		tmp += f->data[i];
 	return tmp & (FILE_NRHASH - 1);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0624/2077] spi: meson-spifc: fix runtime PM leak on remove
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (622 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0623/2077] lockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file() Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0625/2077] ASoC: codecs: aw88261: fix incorrect masks for boost regs Greg Kroah-Hartman
                   ` (373 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ruoyu Wang <ruoyuw560@gmail.com>

[ Upstream commit 606c0826bd90384a54571c0c5475ca41f50164ea ]

pm_runtime_get_sync() increments the runtime PM usage counter even when it
returns an error. meson_spifc_remove() uses it to resume the controller
before disabling runtime PM, but never drops the usage counter again.

Balance the get with pm_runtime_put_noidle() after disabling runtime PM,
matching the teardown pattern used by other SPI controller drivers.

Found by static analysis. I do not have hardware to test this.

Fixes: c3e4bc5434d2 ("spi: meson: Add support for Amlogic Meson SPIFC")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Link: https://patch.msgid.link/20260609052647.5-1-ruoyuw560@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/spi/spi-meson-spifc.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/spi/spi-meson-spifc.c b/drivers/spi/spi-meson-spifc.c
index b818950a8cb7d1..e2d19c3873f712 100644
--- a/drivers/spi/spi-meson-spifc.c
+++ b/drivers/spi/spi-meson-spifc.c
@@ -351,6 +351,7 @@ static void meson_spifc_remove(struct platform_device *pdev)
 {
 	pm_runtime_get_sync(&pdev->dev);
 	pm_runtime_disable(&pdev->dev);
+	pm_runtime_put_noidle(&pdev->dev);
 }
 
 #ifdef CONFIG_PM_SLEEP
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0625/2077] ASoC: codecs: aw88261: fix incorrect masks for boost regs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (623 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0624/2077] spi: meson-spifc: fix runtime PM leak on remove Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:04 ` [PATCH 7.1 0626/2077] bpf: Cancel special fields on map value recycle Greg Kroah-Hartman
                   ` (372 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Val Packett, Luca Weiss, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Val Packett <val@packett.cool>

[ Upstream commit 79c053a1ff9d3ab31cefbc791e8d7816ba830491 ]

The boost-related register fields used in aw88261_reg_force_set use the
exact same definitions as the rest of the fields, where the mask must be
inverted when passing it to regmap_update_bits, but they weren't
inverted here.

Fixes: 028a2ae25691 ("ASoC: codecs: Add aw88261 amplifier driver")
Signed-off-by: Val Packett <val@packett.cool>
Tested-by: Luca Weiss <luca.weiss@fairphone.com>
Link: https://patch.msgid.link/20260529200550.529719-7-val@packett.cool
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/codecs/aw88261.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/sound/soc/codecs/aw88261.c b/sound/soc/codecs/aw88261.c
index a6805d5405cd10..a6545f5a8ed0df 100644
--- a/sound/soc/codecs/aw88261.c
+++ b/sound/soc/codecs/aw88261.c
@@ -284,22 +284,22 @@ static void aw88261_reg_force_set(struct aw88261 *aw88261)
 	if (aw88261->frcset_en == AW88261_FRCSET_ENABLE) {
 		/* set FORCE_PWM */
 		regmap_update_bits(aw88261->regmap, AW88261_BSTCTRL3_REG,
-				AW88261_FORCE_PWM_MASK, AW88261_FORCE_PWM_FORCEMINUS_PWM_VALUE);
+				~AW88261_FORCE_PWM_MASK, AW88261_FORCE_PWM_FORCEMINUS_PWM_VALUE);
 		/* set BOOST_OS_WIDTH */
 		regmap_update_bits(aw88261->regmap, AW88261_BSTCTRL5_REG,
-				AW88261_BST_OS_WIDTH_MASK, AW88261_BST_OS_WIDTH_50NS_VALUE);
+				~AW88261_BST_OS_WIDTH_MASK, AW88261_BST_OS_WIDTH_50NS_VALUE);
 		/* set BURST_LOOPR */
 		regmap_update_bits(aw88261->regmap, AW88261_BSTCTRL6_REG,
-				AW88261_BST_LOOPR_MASK, AW88261_BST_LOOPR_340K_VALUE);
+				~AW88261_BST_LOOPR_MASK, AW88261_BST_LOOPR_340K_VALUE);
 		/* set RSQN_DLY */
 		regmap_update_bits(aw88261->regmap, AW88261_BSTCTRL7_REG,
-				AW88261_RSQN_DLY_MASK, AW88261_RSQN_DLY_35NS_VALUE);
+				~AW88261_RSQN_DLY_MASK, AW88261_RSQN_DLY_35NS_VALUE);
 		/* set BURST_SSMODE */
 		regmap_update_bits(aw88261->regmap, AW88261_BSTCTRL8_REG,
-				AW88261_BURST_SSMODE_MASK, AW88261_BURST_SSMODE_FAST_VALUE);
+				~AW88261_BURST_SSMODE_MASK, AW88261_BURST_SSMODE_FAST_VALUE);
 		/* set BST_BURST */
 		regmap_update_bits(aw88261->regmap, AW88261_BSTCTRL9_REG,
-				AW88261_BST_BURST_MASK, AW88261_BST_BURST_30MA_VALUE);
+				~AW88261_BST_BURST_MASK, AW88261_BST_BURST_30MA_VALUE);
 	} else {
 		dev_dbg(aw88261->aw_pa->dev, "needn't set reg value");
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0626/2077] bpf: Cancel special fields on map value recycle
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (624 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0625/2077] ASoC: codecs: aw88261: fix incorrect masks for boost regs Greg Kroah-Hartman
@ 2026-07-21 15:04 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0627/2077] clocksource: move NXP timer selection to drivers/clocksource Greg Kroah-Hartman
                   ` (371 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:04 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Justin Suess,
	Kumar Kartikeya Dwivedi, Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Justin Suess <utilityemal77@gmail.com>

[ Upstream commit a3a81d247651218e47153f2d2afd7aee236726fd ]

Map update and delete paths currently call bpf_obj_free_fields() when a
value is being replaced or recycled. That makes field destruction depend
on the context of the update/delete operation. For tracing programs this
can include NMI context, where referenced kptr destructors, uptr
unpinning, and graph root destruction are not generally safe.

Introduce bpf_obj_cancel_fields() for the reusable-value path. It only
performs NMI-safe cleanup for timer, workqueue, and task_work fields.
Fields that need full destruction are left attached to the recycled value
and are destroyed by the final cleanup path instead.

Switch array and hashtab update/delete/recycle paths to this cancel
helper. Keep bpf_obj_free_fields() for final map destruction and for
bpf_mem_alloc destructors. Preallocated hashtabs do not have allocator
destructors, so teardown continues to walk the normal and extra elements
and fully destroy their fields.

This deliberately relaxes the eager-free semantics of map update/delete
for special fields. Programs that relied on a recycled map slot becoming
empty immediately after update/delete were relying on behavior that
cannot be implemented safely from every BPF execution context without
offloading arbitrary destructors.

There is a chance this change breaks programs making assumptions
regarding the eager freeing of fields. If so, we can relax semantics to
cancellation only when irqs_disabled() is true in the future. However,
theoretically, map values that get reused eagerly already have weaker
guarantees as parallel users can recreate freed fields before the new
element becomes visible again.

Fixes: 14a324f6a67e ("bpf: Wire up freeing of referenced kptr")
Signed-off-by: Justin Suess <utilityemal77@gmail.com>
Co-developed-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Link: https://lore.kernel.org/r/20260609202548.3571690-3-memxor@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/bpf.h                           |  1 +
 kernel/bpf/arraymap.c                         |  8 +--
 kernel/bpf/hashtab.c                          | 32 +++++----
 kernel/bpf/syscall.c                          |  5 ++
 .../selftests/bpf/prog_tests/htab_update.c    |  4 +-
 .../selftests/bpf/prog_tests/linked_list.c    | 33 ++++-----
 .../selftests/bpf/prog_tests/map_kptr.c       | 10 +--
 .../bpf/prog_tests/refcounted_kptr.c          |  8 ++-
 .../testing/selftests/bpf/progs/htab_update.c |  4 +-
 .../testing/selftests/bpf/progs/linked_list.c | 71 +++++++++++++++++++
 .../selftests/bpf/progs/refcounted_kptr.c     | 20 +++++-
 11 files changed, 146 insertions(+), 50 deletions(-)

diff --git a/include/linux/bpf.h b/include/linux/bpf.h
index 487f4653d8a669..a2cf24d1688020 100644
--- a/include/linux/bpf.h
+++ b/include/linux/bpf.h
@@ -2596,6 +2596,7 @@ bool btf_record_equal(const struct btf_record *rec_a, const struct btf_record *r
 void bpf_obj_free_timer(const struct btf_record *rec, void *obj);
 void bpf_obj_free_workqueue(const struct btf_record *rec, void *obj);
 void bpf_obj_free_task_work(const struct btf_record *rec, void *obj);
+void bpf_obj_cancel_fields(struct bpf_map *map, void *obj);
 void bpf_obj_free_fields(const struct btf_record *rec, void *obj);
 void __bpf_obj_drop_impl(void *p, const struct btf_record *rec, bool percpu);
 
diff --git a/kernel/bpf/arraymap.c b/kernel/bpf/arraymap.c
index dfb2110ab73357..4b68d7a2b90ea7 100644
--- a/kernel/bpf/arraymap.c
+++ b/kernel/bpf/arraymap.c
@@ -386,7 +386,7 @@ static long array_map_update_elem(struct bpf_map *map, void *key, void *value,
 	if (array->map.map_type == BPF_MAP_TYPE_PERCPU_ARRAY) {
 		val = this_cpu_ptr(array->pptrs[index & array->index_mask]);
 		copy_map_value(map, val, value);
-		bpf_obj_free_fields(array->map.record, val);
+		bpf_obj_cancel_fields(map, val);
 	} else {
 		val = array->value +
 			(u64)array->elem_size * (index & array->index_mask);
@@ -394,7 +394,7 @@ static long array_map_update_elem(struct bpf_map *map, void *key, void *value,
 			copy_map_value_locked(map, val, value, false);
 		else
 			copy_map_value(map, val, value);
-		bpf_obj_free_fields(array->map.record, val);
+		bpf_obj_cancel_fields(map, val);
 	}
 	return 0;
 }
@@ -434,14 +434,14 @@ int bpf_percpu_array_update(struct bpf_map *map, void *key, void *value,
 		cpu = map_flags >> 32;
 		ptr = per_cpu_ptr(pptr, cpu);
 		copy_map_value(map, ptr, value);
-		bpf_obj_free_fields(array->map.record, ptr);
+		bpf_obj_cancel_fields(map, ptr);
 		goto unlock;
 	}
 	for_each_possible_cpu(cpu) {
 		ptr = per_cpu_ptr(pptr, cpu);
 		val = (map_flags & BPF_F_ALL_CPUS) ? value : value + size * cpu;
 		copy_map_value(map, ptr, val);
-		bpf_obj_free_fields(array->map.record, ptr);
+		bpf_obj_cancel_fields(map, ptr);
 	}
 unlock:
 	rcu_read_unlock();
diff --git a/kernel/bpf/hashtab.c b/kernel/bpf/hashtab.c
index 3dd9b4924ae4fb..74c5ced74032bb 100644
--- a/kernel/bpf/hashtab.c
+++ b/kernel/bpf/hashtab.c
@@ -242,6 +242,10 @@ static void htab_free_prealloced_fields(struct bpf_htab *htab)
 
 	if (IS_ERR_OR_NULL(htab->map.record))
 		return;
+	/*
+	 * Preallocated maps do not have a bpf_mem_alloc destructor, so fully
+	 * destroy every element, including the extra elements.
+	 */
 	if (htab_has_extra_elems(htab))
 		num_entries += num_possible_cpus();
 	for (i = 0; i < num_entries; i++) {
@@ -834,8 +838,8 @@ static int htab_lru_map_gen_lookup(struct bpf_map *map,
 	return insn - insn_buf;
 }
 
-static void check_and_free_fields(struct bpf_htab *htab,
-				  struct htab_elem *elem)
+static void check_and_cancel_fields(struct bpf_htab *htab,
+				    struct htab_elem *elem)
 {
 	if (IS_ERR_OR_NULL(htab->map.record))
 		return;
@@ -845,11 +849,11 @@ static void check_and_free_fields(struct bpf_htab *htab,
 		int cpu;
 
 		for_each_possible_cpu(cpu)
-			bpf_obj_free_fields(htab->map.record, per_cpu_ptr(pptr, cpu));
+			bpf_obj_cancel_fields(&htab->map, per_cpu_ptr(pptr, cpu));
 	} else {
 		void *map_value = htab_elem_value(elem, htab->map.key_size);
 
-		bpf_obj_free_fields(htab->map.record, map_value);
+		bpf_obj_cancel_fields(&htab->map, map_value);
 	}
 }
 
@@ -884,7 +888,7 @@ static bool htab_lru_map_delete_node(void *arg, struct bpf_lru_node *node)
 	htab_unlock_bucket(b, flags);
 
 	if (l == tgt_l)
-		check_and_free_fields(htab, l);
+		check_and_cancel_fields(htab, l);
 	return l == tgt_l;
 }
 
@@ -949,7 +953,7 @@ static int htab_map_get_next_key(struct bpf_map *map, void *key, void *next_key)
 
 static void htab_elem_free(struct bpf_htab *htab, struct htab_elem *l)
 {
-	check_and_free_fields(htab, l);
+	check_and_cancel_fields(htab, l);
 
 	if (htab->map.map_type == BPF_MAP_TYPE_PERCPU_HASH)
 		bpf_mem_cache_free(&htab->pcpu_ma, l->ptr_to_pptr);
@@ -1002,7 +1006,7 @@ static void free_htab_elem(struct bpf_htab *htab, struct htab_elem *l)
 
 	if (htab_is_prealloc(htab)) {
 		bpf_map_dec_elem_count(&htab->map);
-		check_and_free_fields(htab, l);
+		check_and_cancel_fields(htab, l);
 		pcpu_freelist_push(&htab->freelist, &l->fnode);
 	} else {
 		dec_elem_count(htab);
@@ -1019,7 +1023,7 @@ static void pcpu_copy_value(struct bpf_htab *htab, void __percpu *pptr,
 		/* copy true value_size bytes */
 		ptr = this_cpu_ptr(pptr);
 		copy_map_value(&htab->map, ptr, value);
-		bpf_obj_free_fields(htab->map.record, ptr);
+		bpf_obj_cancel_fields(&htab->map, ptr);
 	} else {
 		u32 size = round_up(htab->map.value_size, 8);
 		void *val;
@@ -1029,7 +1033,7 @@ static void pcpu_copy_value(struct bpf_htab *htab, void __percpu *pptr,
 			cpu = map_flags >> 32;
 			ptr = per_cpu_ptr(pptr, cpu);
 			copy_map_value(&htab->map, ptr, value);
-			bpf_obj_free_fields(htab->map.record, ptr);
+			bpf_obj_cancel_fields(&htab->map, ptr);
 			return;
 		}
 
@@ -1037,7 +1041,7 @@ static void pcpu_copy_value(struct bpf_htab *htab, void __percpu *pptr,
 			ptr = per_cpu_ptr(pptr, cpu);
 			val = (map_flags & BPF_F_ALL_CPUS) ? value : value + size * cpu;
 			copy_map_value(&htab->map, ptr, val);
-			bpf_obj_free_fields(htab->map.record, ptr);
+			bpf_obj_cancel_fields(&htab->map, ptr);
 		}
 	}
 }
@@ -1253,11 +1257,11 @@ static long htab_map_update_elem(struct bpf_map *map, void *key, void *value,
 	if (l_old) {
 		hlist_nulls_del_rcu(&l_old->hash_node);
 
-		/* l_old has already been stashed in htab->extra_elems, free
-		 * its special fields before it is available for reuse.
+		/* l_old has already been stashed in htab->extra_elems, cancel
+		 * its reusable special fields before it is available for reuse.
 		 */
 		if (htab_is_prealloc(htab))
-			check_and_free_fields(htab, l_old);
+			check_and_cancel_fields(htab, l_old);
 	}
 	htab_unlock_bucket(b, flags);
 	if (l_old && !htab_is_prealloc(htab))
@@ -1270,7 +1274,7 @@ static long htab_map_update_elem(struct bpf_map *map, void *key, void *value,
 
 static void htab_lru_push_free(struct bpf_htab *htab, struct htab_elem *elem)
 {
-	check_and_free_fields(htab, elem);
+	check_and_cancel_fields(htab, elem);
 	bpf_map_dec_elem_count(&htab->map);
 	bpf_lru_push_free(&htab->lru, &elem->lru_node);
 }
diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
index d3667970885580..ddf0571f476bf1 100644
--- a/kernel/bpf/syscall.c
+++ b/kernel/bpf/syscall.c
@@ -807,6 +807,11 @@ void bpf_obj_free_task_work(const struct btf_record *rec, void *obj)
 	bpf_task_work_cancel_and_free(obj + rec->task_work_off);
 }
 
+void bpf_obj_cancel_fields(struct bpf_map *map, void *obj)
+{
+	bpf_map_free_internal_structs(map, obj);
+}
+
 void bpf_obj_free_fields(const struct btf_record *rec, void *obj)
 {
 	const struct btf_field *fields;
diff --git a/tools/testing/selftests/bpf/prog_tests/htab_update.c b/tools/testing/selftests/bpf/prog_tests/htab_update.c
index ea1a6766fbe987..0a28d434692404 100644
--- a/tools/testing/selftests/bpf/prog_tests/htab_update.c
+++ b/tools/testing/selftests/bpf/prog_tests/htab_update.c
@@ -23,7 +23,7 @@ static void test_reenter_update(void)
 	if (!ASSERT_OK_PTR(skel, "htab_update__open"))
 		return;
 
-	bpf_program__set_autoload(skel->progs.bpf_obj_free_fields, true);
+	bpf_program__set_autoload(skel->progs.bpf_obj_cancel_fields, true);
 	err = htab_update__load(skel);
 	if (!ASSERT_TRUE(!err, "htab_update__load") || err)
 		goto out;
@@ -50,7 +50,7 @@ static void test_reenter_update(void)
 	/*
 	 * Second update: replace existing element with same key and trigger
 	 * the reentrancy of bpf_map_update_elem().
-	 * check_and_free_fields() calls bpf_obj_free_fields() on the old
+	 * check_and_cancel_fields() calls bpf_obj_cancel_fields() on the old
 	 * value, which is where fentry program runs and performs a nested
 	 * bpf_map_update_elem(), triggering -EDEADLK.
 	 */
diff --git a/tools/testing/selftests/bpf/prog_tests/linked_list.c b/tools/testing/selftests/bpf/prog_tests/linked_list.c
index 6f25b5f39a79cd..62d974a1987fff 100644
--- a/tools/testing/selftests/bpf/prog_tests/linked_list.c
+++ b/tools/testing/selftests/bpf/prog_tests/linked_list.c
@@ -131,13 +131,14 @@ static void test_linked_list_fail_prog(const char *prog_name, const char *err_ms
 	linked_list_fail__destroy(skel);
 }
 
-static void clear_fields(struct bpf_map *map)
+static void clear_fields(struct bpf_program *prog)
 {
-	char buf[24];
-	int key = 0;
+	LIBBPF_OPTS(bpf_test_run_opts, opts);
+	int ret;
 
-	memset(buf, 0xff, sizeof(buf));
-	ASSERT_OK(bpf_map__update_elem(map, &key, sizeof(key), buf, sizeof(buf), 0), "check_and_free_fields");
+	ret = bpf_prog_test_run_opts(bpf_program__fd(prog), &opts);
+	ASSERT_OK(ret, "clear_fields");
+	ASSERT_OK(opts.retval, "clear_fields retval");
 }
 
 enum {
@@ -170,31 +171,31 @@ static void test_linked_list_success(int mode, bool leave_in_map)
 	ASSERT_OK(ret, "map_list_push_pop");
 	ASSERT_OK(opts.retval, "map_list_push_pop retval");
 	if (!leave_in_map)
-		clear_fields(skel->maps.array_map);
+		clear_fields(skel->progs.clear_map_list);
 
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.inner_map_list_push_pop), &opts);
 	ASSERT_OK(ret, "inner_map_list_push_pop");
 	ASSERT_OK(opts.retval, "inner_map_list_push_pop retval");
 	if (!leave_in_map)
-		clear_fields(skel->maps.inner_map);
+		clear_fields(skel->progs.clear_inner_map_list);
 
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.global_list_push_pop), &opts);
 	ASSERT_OK(ret, "global_list_push_pop");
 	ASSERT_OK(opts.retval, "global_list_push_pop retval");
 	if (!leave_in_map)
-		clear_fields(skel->maps.bss_A);
+		clear_fields(skel->progs.clear_global_list);
 
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.global_list_push_pop_nested), &opts);
 	ASSERT_OK(ret, "global_list_push_pop_nested");
 	ASSERT_OK(opts.retval, "global_list_push_pop_nested retval");
 	if (!leave_in_map)
-		clear_fields(skel->maps.bss_A);
+		clear_fields(skel->progs.clear_global_nested_list);
 
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.global_list_array_push_pop), &opts);
 	ASSERT_OK(ret, "global_list_array_push_pop");
 	ASSERT_OK(opts.retval, "global_list_array_push_pop retval");
 	if (!leave_in_map)
-		clear_fields(skel->maps.bss_A);
+		clear_fields(skel->progs.clear_global_array_list);
 
 	if (mode == PUSH_POP)
 		goto end;
@@ -204,19 +205,19 @@ static void test_linked_list_success(int mode, bool leave_in_map)
 	ASSERT_OK(ret, "map_list_push_pop_multiple");
 	ASSERT_OK(opts.retval, "map_list_push_pop_multiple retval");
 	if (!leave_in_map)
-		clear_fields(skel->maps.array_map);
+		clear_fields(skel->progs.clear_map_list);
 
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.inner_map_list_push_pop_multiple), &opts);
 	ASSERT_OK(ret, "inner_map_list_push_pop_multiple");
 	ASSERT_OK(opts.retval, "inner_map_list_push_pop_multiple retval");
 	if (!leave_in_map)
-		clear_fields(skel->maps.inner_map);
+		clear_fields(skel->progs.clear_inner_map_list);
 
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.global_list_push_pop_multiple), &opts);
 	ASSERT_OK(ret, "global_list_push_pop_multiple");
 	ASSERT_OK(opts.retval, "global_list_push_pop_multiple retval");
 	if (!leave_in_map)
-		clear_fields(skel->maps.bss_A);
+		clear_fields(skel->progs.clear_global_list);
 
 	if (mode == PUSH_POP_MULT)
 		goto end;
@@ -226,19 +227,19 @@ static void test_linked_list_success(int mode, bool leave_in_map)
 	ASSERT_OK(ret, "map_list_in_list");
 	ASSERT_OK(opts.retval, "map_list_in_list retval");
 	if (!leave_in_map)
-		clear_fields(skel->maps.array_map);
+		clear_fields(skel->progs.clear_map_list);
 
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.inner_map_list_in_list), &opts);
 	ASSERT_OK(ret, "inner_map_list_in_list");
 	ASSERT_OK(opts.retval, "inner_map_list_in_list retval");
 	if (!leave_in_map)
-		clear_fields(skel->maps.inner_map);
+		clear_fields(skel->progs.clear_inner_map_list);
 
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.global_list_in_list), &opts);
 	ASSERT_OK(ret, "global_list_in_list");
 	ASSERT_OK(opts.retval, "global_list_in_list retval");
 	if (!leave_in_map)
-		clear_fields(skel->maps.bss_A);
+		clear_fields(skel->progs.clear_global_list);
 end:
 	linked_list__destroy(skel);
 }
diff --git a/tools/testing/selftests/bpf/prog_tests/map_kptr.c b/tools/testing/selftests/bpf/prog_tests/map_kptr.c
index 03b46f17cf5375..ec6f2f2e830896 100644
--- a/tools/testing/selftests/bpf/prog_tests/map_kptr.c
+++ b/tools/testing/selftests/bpf/prog_tests/map_kptr.c
@@ -51,7 +51,6 @@ static void test_map_kptr_success(bool test_run)
 	ret = bpf_map__update_elem(skel->maps.array_map,
 				   &key, sizeof(key), buf, sizeof(buf), 0);
 	ASSERT_OK(ret, "array_map update");
-	skel->data->ref--;
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.test_map_kptr_ref3), &opts);
 	ASSERT_OK(ret, "test_map_kptr_ref3 refcount");
 	ASSERT_OK(opts.retval, "test_map_kptr_ref3 retval");
@@ -59,49 +58,42 @@ static void test_map_kptr_success(bool test_run)
 	ret = bpf_map__update_elem(skel->maps.pcpu_array_map,
 				   &key, sizeof(key), pbuf, cpu * sizeof(buf), 0);
 	ASSERT_OK(ret, "pcpu_array_map update");
-	skel->data->ref--;
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.test_map_kptr_ref3), &opts);
 	ASSERT_OK(ret, "test_map_kptr_ref3 refcount");
 	ASSERT_OK(opts.retval, "test_map_kptr_ref3 retval");
 
 	ret = bpf_map__delete_elem(skel->maps.hash_map, &key, sizeof(key), 0);
 	ASSERT_OK(ret, "hash_map delete");
-	skel->data->ref--;
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.test_map_kptr_ref3), &opts);
 	ASSERT_OK(ret, "test_map_kptr_ref3 refcount");
 	ASSERT_OK(opts.retval, "test_map_kptr_ref3 retval");
 
 	ret = bpf_map__delete_elem(skel->maps.pcpu_hash_map, &key, sizeof(key), 0);
 	ASSERT_OK(ret, "pcpu_hash_map delete");
-	skel->data->ref--;
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.test_map_kptr_ref3), &opts);
 	ASSERT_OK(ret, "test_map_kptr_ref3 refcount");
 	ASSERT_OK(opts.retval, "test_map_kptr_ref3 retval");
 
 	ret = bpf_map__delete_elem(skel->maps.hash_malloc_map, &key, sizeof(key), 0);
 	ASSERT_OK(ret, "hash_malloc_map delete");
-	skel->data->ref--;
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.test_map_kptr_ref3), &opts);
 	ASSERT_OK(ret, "test_map_kptr_ref3 refcount");
 	ASSERT_OK(opts.retval, "test_map_kptr_ref3 retval");
 
 	ret = bpf_map__delete_elem(skel->maps.pcpu_hash_malloc_map, &key, sizeof(key), 0);
 	ASSERT_OK(ret, "pcpu_hash_malloc_map delete");
-	skel->data->ref--;
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.test_map_kptr_ref3), &opts);
 	ASSERT_OK(ret, "test_map_kptr_ref3 refcount");
 	ASSERT_OK(opts.retval, "test_map_kptr_ref3 retval");
 
 	ret = bpf_map__delete_elem(skel->maps.lru_hash_map, &key, sizeof(key), 0);
 	ASSERT_OK(ret, "lru_hash_map delete");
-	skel->data->ref--;
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.test_map_kptr_ref3), &opts);
 	ASSERT_OK(ret, "test_map_kptr_ref3 refcount");
 	ASSERT_OK(opts.retval, "test_map_kptr_ref3 retval");
 
 	ret = bpf_map__delete_elem(skel->maps.lru_pcpu_hash_map, &key, sizeof(key), 0);
 	ASSERT_OK(ret, "lru_pcpu_hash_map delete");
-	skel->data->ref--;
 	ret = bpf_prog_test_run_opts(bpf_program__fd(skel->progs.test_map_kptr_ref3), &opts);
 	ASSERT_OK(ret, "test_map_kptr_ref3 refcount");
 	ASSERT_OK(opts.retval, "test_map_kptr_ref3 retval");
@@ -175,7 +167,7 @@ void serial_test_map_kptr(void)
 		ASSERT_OK(kern_sync_rcu(), "sync rcu");
 		wait_for_map_release();
 
-		/* Observe refcount dropping to 1 on synchronous delete elem */
+		/* Observe refcount dropping to 1 on map release. */
 		test_map_kptr_success(true);
 	}
 
diff --git a/tools/testing/selftests/bpf/prog_tests/refcounted_kptr.c b/tools/testing/selftests/bpf/prog_tests/refcounted_kptr.c
index d2c0542716a848..1737eba3432343 100644
--- a/tools/testing/selftests/bpf/prog_tests/refcounted_kptr.c
+++ b/tools/testing/selftests/bpf/prog_tests/refcounted_kptr.c
@@ -57,6 +57,7 @@ void test_percpu_hash_refcounted_kptr_refcount_leak(void)
 		    .data_size_in = sizeof(pkt_v4),
 		    .repeat = 1,
 	);
+	LIBBPF_OPTS(bpf_test_run_opts, syscall_opts);
 
 	cpu_nr = libbpf_num_possible_cpus();
 	if (!ASSERT_GT(cpu_nr, 0, "libbpf_num_possible_cpus"))
@@ -87,8 +88,11 @@ void test_percpu_hash_refcounted_kptr_refcount_leak(void)
 	if (!ASSERT_EQ(opts.retval, 2, "opts.retval"))
 		goto out;
 
-	err = bpf_map__update_elem(map, &key, sizeof(key), values, values_sz, 0);
-	if (!ASSERT_OK(err, "bpf_map__update_elem"))
+	fd = bpf_program__fd(skel->progs.clear_percpu_hash_kptr);
+	err = bpf_prog_test_run_opts(fd, &syscall_opts);
+	if (!ASSERT_OK(err, "bpf_prog_test_run_opts"))
+		goto out;
+	if (!ASSERT_EQ(syscall_opts.retval, 1, "syscall_opts.retval"))
 		goto out;
 
 	fd = bpf_program__fd(skel->progs.check_percpu_hash_refcount);
diff --git a/tools/testing/selftests/bpf/progs/htab_update.c b/tools/testing/selftests/bpf/progs/htab_update.c
index 195d3b2fba00c5..62c1b1325ec27b 100644
--- a/tools/testing/selftests/bpf/progs/htab_update.c
+++ b/tools/testing/selftests/bpf/progs/htab_update.c
@@ -22,8 +22,8 @@ struct {
 int pid = 0;
 int update_err = 0;
 
-SEC("?fentry/bpf_obj_free_fields")
-int bpf_obj_free_fields(void *ctx)
+SEC("?fentry/bpf_obj_cancel_fields")
+int bpf_obj_cancel_fields(void *ctx)
 {
 	__u32 key = 0;
 	struct val value = { .payload = 1 };
diff --git a/tools/testing/selftests/bpf/progs/linked_list.c b/tools/testing/selftests/bpf/progs/linked_list.c
index 421f40835acd75..fa97faa5358bca 100644
--- a/tools/testing/selftests/bpf/progs/linked_list.c
+++ b/tools/testing/selftests/bpf/progs/linked_list.c
@@ -290,6 +290,77 @@ int test_list_in_list(struct bpf_spin_lock *lock, struct bpf_list_head *head)
 	return list_in_list(lock, head, true);
 }
 
+#define MAX_LIST_CLEAR_NODES 256
+
+static __always_inline
+int clear_list(struct bpf_spin_lock *lock, struct bpf_list_head *head)
+{
+	struct bpf_list_node *n;
+	int i;
+
+	for (i = 0; i < MAX_LIST_CLEAR_NODES; i++) {
+		bpf_spin_lock(lock);
+		n = bpf_list_pop_front(head);
+		bpf_spin_unlock(lock);
+		if (!n)
+			return 0;
+		bpf_obj_drop(container_of(n, struct foo, node2));
+	}
+	return 1;
+}
+
+SEC("syscall")
+int clear_map_list(void *ctx)
+{
+	struct map_value *v;
+
+	v = bpf_map_lookup_elem(&array_map, &(int){0});
+	if (!v)
+		return 1;
+	return clear_list(&v->lock, &v->head);
+}
+
+SEC("syscall")
+int clear_inner_map_list(void *ctx)
+{
+	struct map_value *v;
+	void *map;
+
+	map = bpf_map_lookup_elem(&map_of_maps, &(int){0});
+	if (!map)
+		return 1;
+	v = bpf_map_lookup_elem(map, &(int){0});
+	if (!v)
+		return 1;
+	return clear_list(&v->lock, &v->head);
+}
+
+SEC("syscall")
+int clear_global_list(void *ctx)
+{
+	return clear_list(&glock, &ghead);
+}
+
+SEC("syscall")
+int clear_global_nested_list(void *ctx)
+{
+	return clear_list(&ghead_nested.inner.lock, &ghead_nested.inner.head);
+}
+
+SEC("syscall")
+int clear_global_array_list(void *ctx)
+{
+	int ret;
+
+	ret = clear_list(&glock_c, &ghead_array[0]);
+	if (ret)
+		return ret;
+	ret = clear_list(&glock_c, &ghead_array[1]);
+	if (ret)
+		return ret;
+	return clear_list(&glock_c, &ghead_array_one[0]);
+}
+
 SEC("tc")
 int map_list_push_pop(void *ctx)
 {
diff --git a/tools/testing/selftests/bpf/progs/refcounted_kptr.c b/tools/testing/selftests/bpf/progs/refcounted_kptr.c
index c847398837ccd7..9837dccfc141c6 100644
--- a/tools/testing/selftests/bpf/progs/refcounted_kptr.c
+++ b/tools/testing/selftests/bpf/progs/refcounted_kptr.c
@@ -615,13 +615,31 @@ int percpu_hash_refcount_leak(void *ctx)
 	struct map_value *v;
 	int key = 0;
 
-	v = bpf_map_lookup_elem(&percpu_hash, &key);
+	v = bpf_map_lookup_percpu_elem(&percpu_hash, &key, 0);
 	if (!v)
 		return 0;
 
 	return __insert_in_list(&head, &lock, &v->node);
 }
 
+SEC("syscall")
+int clear_percpu_hash_kptr(void *ctx)
+{
+	struct node_data *n;
+	struct map_value *v;
+	int key = 0;
+
+	v = bpf_map_lookup_percpu_elem(&percpu_hash, &key, 0);
+	if (!v)
+		return 0;
+
+	n = bpf_kptr_xchg(&v->node, NULL);
+	if (!n)
+		return 0;
+	bpf_obj_drop(n);
+	return probe_read_refcount();
+}
+
 SEC("tc")
 int check_percpu_hash_refcount(void *ctx)
 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0627/2077] clocksource: move NXP timer selection to drivers/clocksource
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (625 preceding siblings ...)
  2026-07-21 15:04 ` [PATCH 7.1 0626/2077] bpf: Cancel special fields on map value recycle Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0628/2077] vduse: hold vduse_lock across IDR lookup in open path Greg Kroah-Hartman
                   ` (370 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Enric Balletbo i Serra,
	Daniel Lezcano, Frank Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Enric Balletbo i Serra <eballetb@redhat.com>

[ Upstream commit a9ac745bc320cbdc2ed3c851eb78f91f22ff975b ]

The Kconfig logic for selecting the scheduler clocksource on
NXP Vybrid (VF610) uses a `choice` block restricted to 32-bit ARM. This
prevents 64-bit architectures, such as the NXP S32 family, from enabling
the NXP Periodic Interrupt Timer (PIT) driver (CONFIG_NXP_PIT_TIMER).

Relocate the NXP clocksource selection from arch/arm/mach-imx/Kconfig to
drivers/clocksource/Kconfig. This allows the configuration to be shared
across different architectures.

Update the selection to include support for ARCH_S32 and add a "None"
option restricted to ARCH_S32, since Vybrid lacks the ARM Architected
Timer. The Vybrid Global Timer option is restricted to ARCH_MULTI_V7
SOC_VF610 platforms to prevent it from being visible on Cortex-M4 builds,
which lack the ARM Global Timer hardware.

Fixes: bee33f22d7c3 ("clocksource/drivers/nxp-pit: Add NXP Automotive s32g2 / s32g3 support")
Signed-off-by: Enric Balletbo i Serra <eballetb@redhat.com>
Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260514-fix-nxp-timer-v3-1-a3e68fdb505e@redhat.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm/mach-imx/Kconfig   | 21 ---------------------
 drivers/clocksource/Kconfig | 31 +++++++++++++++++++++++++++++++
 2 files changed, 31 insertions(+), 21 deletions(-)

diff --git a/arch/arm/mach-imx/Kconfig b/arch/arm/mach-imx/Kconfig
index 6ea1bd55acf8de..a361840d7a0478 100644
--- a/arch/arm/mach-imx/Kconfig
+++ b/arch/arm/mach-imx/Kconfig
@@ -227,27 +227,6 @@ config SOC_VF610
 	help
 	  This enables support for Freescale Vybrid VF610 processor.
 
-choice
-	prompt "Clocksource for scheduler clock"
-	depends on SOC_VF610
-	default VF_USE_ARM_GLOBAL_TIMER
-
-	config VF_USE_ARM_GLOBAL_TIMER
-		bool "Use ARM Global Timer"
-		depends on ARCH_MULTI_V7
-		select ARM_GLOBAL_TIMER
-		select CLKSRC_ARM_GLOBAL_TIMER_SCHED_CLOCK
-		help
-		  Use the ARM Global Timer as clocksource
-
-	config VF_USE_PIT_TIMER
-		bool "Use PIT timer"
-		select NXP_PIT_TIMER
-		help
-		  Use SoC Periodic Interrupt Timer (PIT) as clocksource
-
-endchoice
-
 endif
 
 endif
diff --git a/drivers/clocksource/Kconfig b/drivers/clocksource/Kconfig
index d1a33a231a44c3..d9c76dd443f8ac 100644
--- a/drivers/clocksource/Kconfig
+++ b/drivers/clocksource/Kconfig
@@ -793,4 +793,35 @@ config RTK_SYSTIMER
 	  this option only when building for a Realtek platform or for compilation
 	  testing.
 
+choice
+	prompt "NXP clocksource for scheduler clock"
+	depends on SOC_VF610 || ARCH_S32
+	# Default to Global Timer for Vybrid (32-bit)
+	default VF_USE_ARM_GLOBAL_TIMER if SOC_VF610
+	# Default to None for S32 (64-bit)
+	default VF_TIMER_NONE if ARCH_S32
+
+	config VF_USE_ARM_GLOBAL_TIMER
+		bool "Use NXP Vybrid Global Timer"
+		depends on ARCH_MULTI_V7 && SOC_VF610
+		select ARM_GLOBAL_TIMER
+		select CLKSRC_ARM_GLOBAL_TIMER_SCHED_CLOCK
+		help
+		  Use the NXP Vybrid Global Timer as clocksource.
+
+	config VF_USE_PIT_TIMER
+		bool "Use NXP PIT timer"
+		select NXP_PIT_TIMER
+		help
+		  Use NXP Periodic Interrupt Timer (PIT) as clocksource.
+
+	config VF_TIMER_NONE
+		bool "None (Use standard Arch Timer)"
+		depends on ARCH_S32
+		help
+		  Do not use any specific NXP timer driver. Use the standard
+		  ARM Architected Timer instead.
+
+endchoice
+
 endmenu
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0628/2077] vduse: hold vduse_lock across IDR lookup in open path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (626 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0627/2077] clocksource: move NXP timer selection to drivers/clocksource Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0629/2077] vhost/vdpa: validate virtqueue index in mmap and fault paths Greg Kroah-Hartman
                   ` (369 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Qihang Tang, Michael S. Tsirkin,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Qihang Tang <q.h.hack.winter@gmail.com>

[ Upstream commit e440e077748939839d9f76e24383b76b785f80ce ]

vduse_dev_open() looks up struct vduse_dev through the IDR and then
acquires dev->lock only after vduse_lock has been dropped.

This leaves a window where a concurrent VDUSE_DESTROY_DEV can remove the
same object from the IDR and free it before the open path locks the
device, leading to a use-after-free.

Close this race by keeping vduse_lock held until dev->lock has been
acquired in the open path, matching the lock ordering already used by
the destroy path.

Fixes: c8a6153b6c59 ("vduse: Introduce VDUSE - vDPA Device in Userspace")
Signed-off-by: Qihang Tang <q.h.hack.winter@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260508094659.94647-1-q.h.hack.winter@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/vdpa/vdpa_user/vduse_dev.c | 21 +++++++--------------
 1 file changed, 7 insertions(+), 14 deletions(-)

diff --git a/drivers/vdpa/vdpa_user/vduse_dev.c b/drivers/vdpa/vdpa_user/vduse_dev.c
index 6202f6902fcdf1..d5c34260ed68dc 100644
--- a/drivers/vdpa/vdpa_user/vduse_dev.c
+++ b/drivers/vdpa/vdpa_user/vduse_dev.c
@@ -1637,26 +1637,18 @@ static int vduse_dev_release(struct inode *inode, struct file *file)
 	return 0;
 }
 
-static struct vduse_dev *vduse_dev_get_from_minor(int minor)
+static int vduse_dev_open(struct inode *inode, struct file *file)
 {
+	int ret = -EBUSY;
 	struct vduse_dev *dev;
 
 	mutex_lock(&vduse_lock);
-	dev = idr_find(&vduse_idr, minor);
-	mutex_unlock(&vduse_lock);
-
-	return dev;
-}
-
-static int vduse_dev_open(struct inode *inode, struct file *file)
-{
-	int ret;
-	struct vduse_dev *dev = vduse_dev_get_from_minor(iminor(inode));
-
-	if (!dev)
+	dev = idr_find(&vduse_idr, iminor(inode));
+	if (!dev) {
+		mutex_unlock(&vduse_lock);
 		return -ENODEV;
+	}
 
-	ret = -EBUSY;
 	mutex_lock(&dev->lock);
 	if (dev->connected)
 		goto unlock;
@@ -1666,6 +1658,7 @@ static int vduse_dev_open(struct inode *inode, struct file *file)
 	file->private_data = dev;
 unlock:
 	mutex_unlock(&dev->lock);
+	mutex_unlock(&vduse_lock);
 
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0629/2077] vhost/vdpa: validate virtqueue index in mmap and fault paths
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (627 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0628/2077] vduse: hold vduse_lock across IDR lookup in open path Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0630/2077] virtio: rtc: tear down old virtqueues before restore Greg Kroah-Hartman
                   ` (368 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eugenio Pérez,
	Michael S. Tsirkin, Qihang Tang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Qihang Tang <q.h.hack.winter@gmail.com>

[ Upstream commit 929e4f044621c8cc30b612fb74e1410bef09e41b ]

vhost_vdpa_mmap() and vhost_vdpa_fault() use vma->vm_pgoff as a
virtqueue index for get_vq_notification(), but they do not validate
that the index is smaller than v->nvqs.

The ioctl path already performs both a bounds check and
array_index_nospec(), but the mmap/fault path only checks that the
index fits in u16. This allows an out-of-range queue index to reach
driver-specific get_vq_notification() callbacks.

Fix this by extracting a unified vhost_vdpa_get_vq_notification()
helper that validates the queue index against v->nvqs and applies
array_index_nospec() before calling the driver callback. Both the
mmap and fault paths use this helper, and the bounds checking is
consolidated into a single location.

>From source inspection, the most defensible impact is out-of-bounds
access in the callback path, potentially leading to invalid PFN
remaps and crash/DoS.

Fixes: ddd89d0a059d ("vhost_vdpa: support doorbell mapping via mmap")
Acked-by: Eugenio Pérez <eperezma@redhat.com>
Acked-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Qihang Tang <q.h.hack.winter@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260508075821.92656-1-q.h.hack.winter@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/vhost/vdpa.c | 29 ++++++++++++++++++++++-------
 1 file changed, 22 insertions(+), 7 deletions(-)

diff --git a/drivers/vhost/vdpa.c b/drivers/vhost/vdpa.c
index 692564b1bcbbe5..ac55275fa0d0ae 100644
--- a/drivers/vhost/vdpa.c
+++ b/drivers/vhost/vdpa.c
@@ -1482,16 +1482,32 @@ static int vhost_vdpa_release(struct inode *inode, struct file *filep)
 }
 
 #ifdef CONFIG_MMU
-static vm_fault_t vhost_vdpa_fault(struct vm_fault *vmf)
+static int
+vhost_vdpa_get_vq_notification(struct vhost_vdpa *v, unsigned long index,
+			       struct vdpa_notification_area *notify)
 {
-	struct vhost_vdpa *v = vmf->vma->vm_file->private_data;
 	struct vdpa_device *vdpa = v->vdpa;
 	const struct vdpa_config_ops *ops = vdpa->config;
+
+	if (index > 65535 || index >= v->nvqs)
+		return -EINVAL;
+
+	index = array_index_nospec(index, v->nvqs);
+
+	*notify = ops->get_vq_notification(vdpa, index);
+
+	return 0;
+}
+
+static vm_fault_t vhost_vdpa_fault(struct vm_fault *vmf)
+{
+	struct vhost_vdpa *v = vmf->vma->vm_file->private_data;
 	struct vdpa_notification_area notify;
 	struct vm_area_struct *vma = vmf->vma;
-	u16 index = vma->vm_pgoff;
+	unsigned long index = vma->vm_pgoff;
 
-	notify = ops->get_vq_notification(vdpa, index);
+	if (vhost_vdpa_get_vq_notification(v, index, &notify))
+		return VM_FAULT_SIGBUS;
 
 	return vmf_insert_pfn(vma, vmf->address & PAGE_MASK, PFN_DOWN(notify.addr));
 }
@@ -1514,8 +1530,6 @@ static int vhost_vdpa_mmap(struct file *file, struct vm_area_struct *vma)
 		return -EINVAL;
 	if (vma->vm_flags & VM_READ)
 		return -EINVAL;
-	if (index > 65535)
-		return -EINVAL;
 	if (!ops->get_vq_notification)
 		return -ENOTSUPP;
 
@@ -1523,7 +1537,8 @@ static int vhost_vdpa_mmap(struct file *file, struct vm_area_struct *vma)
 	 * support the doorbell which sits on the page boundary and
 	 * does not share the page with other registers.
 	 */
-	notify = ops->get_vq_notification(vdpa, index);
+	if (vhost_vdpa_get_vq_notification(v, index, &notify))
+		return -EINVAL;
 	if (notify.addr & (PAGE_SIZE - 1))
 		return -EINVAL;
 	if (vma->vm_end - vma->vm_start != notify.size)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0630/2077] virtio: rtc: tear down old virtqueues before restore
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (628 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0629/2077] vhost/vdpa: validate virtqueue index in mmap and fault paths Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0631/2077] virtio_console: read size from config space during device init Greg Kroah-Hartman
                   ` (367 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jia Jia, Peter Hilber,
	Michael S. Tsirkin, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jia Jia <physicalmtea@gmail.com>

[ Upstream commit 548d2208455f14e6121404c6e30e997bfe0cd264 ]

virtio_device_restore() resets the device and restores the negotiated
features before calling ->restore(). viortc_freeze() intentionally
leaves the existing virtqueues in place so the alarm queue can still
wake the system, but viortc_restore() immediately calls
viortc_init_vqs() without first deleting those old queues.

If virtqueue reinitialization fails on virtio-pci, the transport error
path can run vp_del_vqs() against a newly allocated vp_dev->vqs array
while vdev->vqs still contains the old virtqueues. vp_del_vqs() then
looks up queue state through the new array and can dereference a NULL
info pointer in vp_del_vq(), crashing the guest kernel during restore.

This can also happen during a non-faulty reinitialization, when one of
the vp_find_vqs_msix() attempts is unsuccessful before a later attempt
would succeed.

Delete the stale virtqueues before rebuilding them. If restore fails
before virtio_device_ready(), reuse the remove path to stop the device.
Once the device is ready, return errors directly instead of deleting the
virtqueues again.

Fixes: 0623c7592768 ("virtio_rtc: Add module and driver core")
Signed-off-by: Jia Jia <physicalmtea@gmail.com>
Reviewed-by: Peter Hilber <peter.hilber@oss.qualcomm.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260507120801.3677552-1-physicalmtea@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/virtio/virtio_rtc_driver.c | 28 ++++++++++++++++++++--------
 1 file changed, 20 insertions(+), 8 deletions(-)

diff --git a/drivers/virtio/virtio_rtc_driver.c b/drivers/virtio/virtio_rtc_driver.c
index a57d5e06e19d2d..4419735b0f0dcf 100644
--- a/drivers/virtio/virtio_rtc_driver.c
+++ b/drivers/virtio/virtio_rtc_driver.c
@@ -1257,6 +1257,15 @@ static int viortc_init_vqs(struct viortc_dev *viortc)
 	return 0;
 }
 
+static void __viortc_remove(struct viortc_dev *viortc)
+{
+	struct virtio_device *vdev = viortc->vdev;
+
+	viortc_clocks_deinit(viortc);
+	virtio_reset_device(vdev);
+	vdev->config->del_vqs(vdev);
+}
+
 /**
  * viortc_probe() - probe a virtio_rtc virtio device
  * @vdev: virtio device
@@ -1282,7 +1291,7 @@ static int viortc_probe(struct virtio_device *vdev)
 
 	ret = viortc_init_vqs(viortc);
 	if (ret)
-		return ret;
+		goto err_reset_vdev;
 
 	virtio_device_ready(vdev);
 
@@ -1329,10 +1338,7 @@ static void viortc_remove(struct virtio_device *vdev)
 {
 	struct viortc_dev *viortc = vdev->priv;
 
-	viortc_clocks_deinit(viortc);
-
-	virtio_reset_device(vdev);
-	vdev->config->del_vqs(vdev);
+	__viortc_remove(viortc);
 }
 
 static int viortc_freeze(struct virtio_device *dev)
@@ -1353,9 +1359,11 @@ static int viortc_restore(struct virtio_device *dev)
 	bool notify = false;
 	int ret;
 
+	dev->config->del_vqs(dev);
+
 	ret = viortc_init_vqs(viortc);
 	if (ret)
-		return ret;
+		goto err_remove;
 
 	alarm_viortc_vq = &viortc->vqs[VIORTC_ALARMQ];
 	alarm_vq = alarm_viortc_vq->vq;
@@ -1364,7 +1372,7 @@ static int viortc_restore(struct virtio_device *dev)
 		ret = viortc_populate_vq(viortc, alarm_viortc_vq,
 					 VIORTC_ALARMQ_BUF_CAP, false);
 		if (ret)
-			return ret;
+			goto err_remove;
 
 		notify = virtqueue_kick_prepare(alarm_vq);
 	}
@@ -1372,8 +1380,12 @@ static int viortc_restore(struct virtio_device *dev)
 	virtio_device_ready(dev);
 
 	if (notify && !virtqueue_notify(alarm_vq))
-		ret = -EIO;
+		return -EIO;
+
+	return 0;
 
+err_remove:
+	__viortc_remove(viortc);
 	return ret;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0631/2077] virtio_console: read size from config space during device init
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (629 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0630/2077] virtio: rtc: tear down old virtqueues before restore Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0632/2077] vduse: Requeue failed read to send_list head Greg Kroah-Hartman
                   ` (366 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Filip Hejsek, Michael S. Tsirkin,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Filip Hejsek <filip.hejsek@gmail.com>

[ Upstream commit b3592a32b34f37874dc94aa1a0d15c4334ed86ca ]

Previously, the size was only read upon receiving the config interrupt.
This interrupt is sent when the size changes. However, we also need to
read the initial size.

Also make sure to only read the size from config if F_SIZE is enabled.

Fixes: 9778829cffd4 ("virtio: console: Store each console's size in the console structure")
Signed-off-by: Filip Hejsek <filip.hejsek@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260223-virtio-console-fix-v1-1-0cf08303b428@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/char/virtio_console.c | 52 +++++++++++++++++++++--------------
 1 file changed, 31 insertions(+), 21 deletions(-)

diff --git a/drivers/char/virtio_console.c b/drivers/char/virtio_console.c
index 9a33217c68d9d8..198b9731416803 100644
--- a/drivers/char/virtio_console.c
+++ b/drivers/char/virtio_console.c
@@ -1771,32 +1771,40 @@ static void config_intr(struct virtio_device *vdev)
 		schedule_work(&portdev->config_work);
 }
 
-static void config_work_handler(struct work_struct *work)
+static void update_size_from_config(struct ports_device *portdev)
 {
-	struct ports_device *portdev;
+	struct virtio_device *vdev;
+	struct port *port;
+	u16 rows, cols;
 
-	portdev = container_of(work, struct ports_device, config_work);
-	if (!use_multiport(portdev)) {
-		struct virtio_device *vdev;
-		struct port *port;
-		u16 rows, cols;
+	vdev = portdev->vdev;
 
-		vdev = portdev->vdev;
-		virtio_cread(vdev, struct virtio_console_config, cols, &cols);
-		virtio_cread(vdev, struct virtio_console_config, rows, &rows);
+	/*
+	 * We'll use this way of resizing only for legacy support.
+	 * For multiport devices, use control messages to indicate
+	 * console size changes so that it can be done per-port.
+	 *
+	 * Don't test F_SIZE at all if we're rproc: not a valid feature.
+	 */
+	if (is_rproc_serial(vdev) ||
+	    use_multiport(portdev) ||
+	    !virtio_has_feature(vdev, VIRTIO_CONSOLE_F_SIZE))
+		return;
 
-		port = find_port_by_id(portdev, 0);
-		set_console_size(port, rows, cols);
+	virtio_cread(vdev, struct virtio_console_config, cols, &cols);
+	virtio_cread(vdev, struct virtio_console_config, rows, &rows);
 
-		/*
-		 * We'll use this way of resizing only for legacy
-		 * support.  For newer userspace
-		 * (VIRTIO_CONSOLE_F_MULTPORT+), use control messages
-		 * to indicate console size changes so that it can be
-		 * done per-port.
-		 */
-		resize_console(port);
-	}
+	port = find_port_by_id(portdev, 0);
+	set_console_size(port, rows, cols);
+	resize_console(port);
+}
+
+static void config_work_handler(struct work_struct *work)
+{
+	struct ports_device *portdev;
+
+	portdev = container_of(work, struct ports_device, config_work);
+	update_size_from_config(portdev);
 }
 
 static int init_vqs(struct ports_device *portdev)
@@ -2052,6 +2060,8 @@ static int virtcons_probe(struct virtio_device *vdev)
 	__send_control_msg(portdev, VIRTIO_CONSOLE_BAD_ID,
 			   VIRTIO_CONSOLE_DEVICE_READY, 1);
 
+	update_size_from_config(portdev);
+
 	return 0;
 
 free_chrdev:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0632/2077] vduse: Requeue failed read to send_list head
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (630 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0631/2077] virtio_console: read size from config space during device init Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0633/2077] vhost/net: complete zerocopy ubufs only once Greg Kroah-Hartman
                   ` (365 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael S. Tsirkin, Xie Yongji,
	Zhang Tianci, Jason Wang, Eugenio Pérez, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhang Tianci <zhangtianci.1997@bytedance.com>

[ Upstream commit 373ec43ded742b2f3aecf14731ffe1a57f438f38 ]

When copy_to_iter() fails in vduse_dev_read_iter(), put the message back
at the head of send_list to preserve FIFO ordering and retry the oldest
pending request first.

Fixes: c8a6153b6c59 ("vduse: Introduce VDUSE - vDPA Device in Userspace")
Reported-by: Michael S. Tsirkin <mst@redhat.com>
Suggested-by: Xie Yongji <xieyongji@bytedance.com>
Signed-off-by: Zhang Tianci <zhangtianci.1997@bytedance.com>
Reviewed-by: Xie Yongji <xieyongji@bytedance.com>
Acked-by: Jason Wang <jasowang@redhat.com>
Acked-by: Eugenio Pérez <eperezma@redhat.com>
Acked-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260226115550.1814-2-zhangtianci.1997@bytedance.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/vdpa/vdpa_user/vduse_dev.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/drivers/vdpa/vdpa_user/vduse_dev.c b/drivers/vdpa/vdpa_user/vduse_dev.c
index d5c34260ed68dc..a479fef535ac61 100644
--- a/drivers/vdpa/vdpa_user/vduse_dev.c
+++ b/drivers/vdpa/vdpa_user/vduse_dev.c
@@ -221,6 +221,12 @@ static void vduse_enqueue_msg(struct list_head *head,
 	list_add_tail(&msg->list, head);
 }
 
+static void vduse_enqueue_msg_head(struct list_head *head,
+				   struct vduse_dev_msg *msg)
+{
+	list_add(&msg->list, head);
+}
+
 static void vduse_dev_broken(struct vduse_dev *dev)
 {
 	struct vduse_dev_msg *msg, *tmp;
@@ -387,7 +393,7 @@ static ssize_t vduse_dev_read_iter(struct kiocb *iocb, struct iov_iter *to)
 	spin_lock(&dev->msg_lock);
 	if (ret != size) {
 		ret = -EFAULT;
-		vduse_enqueue_msg(&dev->send_list, msg);
+		vduse_enqueue_msg_head(&dev->send_list, msg);
 		goto unlock;
 	}
 	vduse_enqueue_msg(&dev->recv_list, msg);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0633/2077] vhost/net: complete zerocopy ubufs only once
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (631 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0632/2077] vduse: Requeue failed read to send_list head Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0634/2077] tools/virtio: check mmap return value in vringh_test Greg Kroah-Hartman
                   ` (364 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Qing Ming, Michael S. Tsirkin,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Qing Ming <a0yami@mailbox.org>

[ Upstream commit 8f6898fe80794f2d7c3d38c1158c806e4074a1c4 ]

vhost-net initializes one ubuf_info per outstanding zerocopy TX
descriptor and hands it to the backend socket.  The networking stack may
then clone a zerocopy skb before all skb references are released.  For
example, batman-adv fragmentation reaches skb_split(), which calls
skb_zerocopy_clone() and increments the same ubuf_info refcount.

vhost_zerocopy_complete() currently treats every ubuf callback as a
completed vhost descriptor.  It dereferences ubuf->ctx, writes the
descriptor completion state, and drops the vhost_net_ubuf_ref even when
the callback only releases a cloned skb reference.  A backend reset can
therefore wait for and free the vhost_net_ubuf_ref while another cloned
skb still carries the same ubuf_info.  A later completion then
dereferences the freed ubufs pointer.

KASAN reports the stale completion as:

  BUG: KASAN: slab-use-after-free in vhost_zerocopy_complete+0x1d7/0x1f0
  BUG: KASAN: slab-use-after-free in vhost_zerocopy_complete+0x101/0x1f0
  vhost_zerocopy_complete
  skb_copy_ubufs
  __dev_forward_skb2
  veth_xmit

The freed object was allocated from vhost_net_ioctl() while setting the
backend and freed through kfree_rcu()/kvfree_rcu_bulk after backend
removal, while delayed skb completion still reached
vhost_zerocopy_complete().

Honor the generic ubuf_info refcount before touching vhost state, and run
the vhost descriptor completion only for the final ubuf reference.  This
matches the msg_zerocopy_complete() ownership rule for cloned zerocopy
skbs.

Fixes: bab632d69ee4 ("vhost: vhost TX zero-copy support")
Signed-off-by: Qing Ming <a0yami@mailbox.org>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260601104300.197210-1-a0yami@mailbox.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/vhost/net.c | 15 +++++++++++----
 1 file changed, 11 insertions(+), 4 deletions(-)

diff --git a/drivers/vhost/net.c b/drivers/vhost/net.c
index c6536cad9c4f94..b9af63fb630602 100644
--- a/drivers/vhost/net.c
+++ b/drivers/vhost/net.c
@@ -390,13 +390,20 @@ static void vhost_zerocopy_signal_used(struct vhost_net *net,
 static void vhost_zerocopy_complete(struct sk_buff *skb,
 				    struct ubuf_info *ubuf_base, bool success)
 {
-	struct ubuf_info_msgzc *ubuf = uarg_to_msgzc(ubuf_base);
-	struct vhost_net_ubuf_ref *ubufs = ubuf->ctx;
-	struct vhost_virtqueue *vq = ubufs->vq;
+	struct ubuf_info_msgzc *ubuf;
+	struct vhost_net_ubuf_ref *ubufs;
+	struct vhost_virtqueue *vq;
 	int cnt;
 
-	rcu_read_lock_bh();
+	/* Only the final cloned skb reference completes the vhost descriptor. */
+	if (!refcount_dec_and_test(&ubuf_base->refcnt))
+		return;
+
+	ubuf = uarg_to_msgzc(ubuf_base);
+	ubufs = ubuf->ctx;
+	vq = ubufs->vq;
 
+	rcu_read_lock_bh();
 	/* set len to mark this desc buffers done DMA */
 	vq->heads[ubuf->desc].len = success ?
 		VHOST_DMA_DONE_LEN : VHOST_DMA_FAILED_LEN;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0634/2077] tools/virtio: check mmap return value in vringh_test
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (632 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0633/2077] vhost/net: complete zerocopy ubufs only once Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0635/2077] vduse: fix compat handling for VDUSE_IOTLB_GET_FD/VDUSE_VQ_GET_INFO Greg Kroah-Hartman
                   ` (363 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, longlong yan, Michael S. Tsirkin,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: longlong yan <yanlonglong@kylinos.cn>

[ Upstream commit ec6177dfe98b9be1c3ede6c0dfe4394ea2a76959 ]

In parallel_test(), the return values of mmap() for both host_map and
guest_map are not checked against MAP_FAILED. If mmap() fails, the
subsequent code will dereference the invalid pointer, leading to a
segmentation fault.

Add MAP_FAILED checks after both mmap() calls, using err() to report
the error and exit, consistent with the existing error handling style
in this file (e.g., the open() call on line 149).

Fixes: 1515c5ce26ae ("tools/virtio: add vring_test.")
Signed-off-by: longlong yan <yanlonglong@kylinos.cn>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260605021446.1611-1-yanlonglong@kylinos.cn>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/virtio/vringh_test.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/tools/virtio/vringh_test.c b/tools/virtio/vringh_test.c
index b9591223437a64..5ea6d29bc992d2 100644
--- a/tools/virtio/vringh_test.c
+++ b/tools/virtio/vringh_test.c
@@ -159,7 +159,12 @@ static int parallel_test(u64 features,
 
 	/* Parent and child use separate addresses, to check our mapping logic! */
 	host_map = mmap(NULL, mapsize, PROT_READ|PROT_WRITE, MAP_SHARED, fd, 0);
+	if (host_map == MAP_FAILED)
+		err(1, "mmap host_map");
+
 	guest_map = mmap(NULL, mapsize, PROT_READ|PROT_WRITE, MAP_SHARED, fd, 0);
+	if (guest_map == MAP_FAILED)
+		err(1, "mmap guest_map");
 
 	pipe_ret = pipe(to_guest);
 	assert(!pipe_ret);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0635/2077] vduse: fix compat handling for VDUSE_IOTLB_GET_FD/VDUSE_VQ_GET_INFO
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (633 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0634/2077] tools/virtio: check mmap return value in vringh_test Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0636/2077] vdpa/octeon_ep: Fix PF->VF mailbox data address calculation Greg Kroah-Hartman
                   ` (362 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eugenio Pérez, Arnd Bergmann,
	Michael S. Tsirkin, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

[ Upstream commit 455a2a1af92651764e9eb42cec0d95ac142afc28 ]

These two ioctls are incompatible on 32-bit x86 userspace, because
the data structures are shorter than they are on 64-bit.

Add a proper .compat_ioctl handler for x86 that reads the structures
with the smaller padding before calling the internal handlers. On
all other architectures, CONFIG_COMPAT_FOR_U64_ALIGNMENT is disabled
and no special handling is required.

Fixes: ad146355bfad ("vduse: Support querying information of IOVA regions")
Fixes: c8a6153b6c59 ("vduse: Introduce VDUSE - vDPA Device in Userspace")
Acked-by: Eugenio Pérez <eperezma@redhat.com>
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260213154051.4172275-1-arnd@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/vdpa/vdpa_user/vduse_dev.c | 123 ++++++++++++++++++++++++++++-
 1 file changed, 122 insertions(+), 1 deletion(-)

diff --git a/drivers/vdpa/vdpa_user/vduse_dev.c b/drivers/vdpa/vdpa_user/vduse_dev.c
index a479fef535ac61..1367d14e5105e6 100644
--- a/drivers/vdpa/vdpa_user/vduse_dev.c
+++ b/drivers/vdpa/vdpa_user/vduse_dev.c
@@ -1624,6 +1624,127 @@ static long vduse_dev_ioctl(struct file *file, unsigned int cmd,
 	return ret;
 }
 
+#ifdef CONFIG_COMPAT_FOR_U64_ALIGNMENT
+/*
+ * i386 has different alignment constraints than x86_64,
+ * so there are only 3 bytes of padding instead of 7.
+ */
+struct compat_vduse_iotlb_entry {
+	compat_u64 offset;
+	compat_u64 start;
+	compat_u64 last;
+	__u8 perm;
+	__u8 padding[3];
+};
+#define COMPAT_VDUSE_IOTLB_GET_FD	_IOWR(VDUSE_BASE, 0x10, struct compat_vduse_iotlb_entry)
+
+struct compat_vduse_vq_info {
+	__u32 index;
+	__u32 num;
+	compat_u64 desc_addr;
+	compat_u64 driver_addr;
+	compat_u64 device_addr;
+	union {
+		struct vduse_vq_state_split split;
+		struct vduse_vq_state_packed packed;
+	};
+	__u8 ready;
+	__u8 padding[3];
+};
+#define COMPAT_VDUSE_VQ_GET_INFO	_IOWR(VDUSE_BASE, 0x15, struct compat_vduse_vq_info)
+
+static long vduse_dev_compat_ioctl(struct file *file, unsigned int cmd,
+				   unsigned long arg)
+{
+	struct vduse_dev *dev = file->private_data;
+	void __user *argp = (void __user *)arg;
+	int ret;
+
+	if (unlikely(dev->broken))
+		return -EPERM;
+
+	switch (cmd) {
+	case COMPAT_VDUSE_IOTLB_GET_FD: {
+		struct vduse_iotlb_entry_v2 entry = {0};
+		struct file *f = NULL;
+
+		ret = -EFAULT;
+		if (copy_from_user(&entry, argp, _IOC_SIZE(cmd)))
+			break;
+
+		ret = vduse_dev_iotlb_entry(dev, &entry, &f, NULL);
+		if (ret)
+			break;
+
+		ret = -EINVAL;
+		if (!f)
+			break;
+
+		ret = copy_to_user(argp, &entry, _IOC_SIZE(cmd));
+		if (ret) {
+			ret = -EFAULT;
+			fput(f);
+			break;
+		}
+		ret = receive_fd(f, NULL, perm_to_file_flags(entry.perm));
+		fput(f);
+		break;
+	}
+	case COMPAT_VDUSE_VQ_GET_INFO: {
+		struct vduse_vq_info vq_info = {};
+		struct vduse_virtqueue *vq;
+		u32 index;
+
+		ret = -EFAULT;
+		if (copy_from_user(&vq_info, argp,
+				   sizeof(struct compat_vduse_vq_info)))
+			break;
+
+		ret = -EINVAL;
+		if (vq_info.index >= dev->vq_num)
+			break;
+
+		index = array_index_nospec(vq_info.index, dev->vq_num);
+		vq = dev->vqs[index];
+		vq_info.desc_addr = vq->desc_addr;
+		vq_info.driver_addr = vq->driver_addr;
+		vq_info.device_addr = vq->device_addr;
+		vq_info.num = vq->num;
+
+		if (dev->driver_features & BIT_ULL(VIRTIO_F_RING_PACKED)) {
+			vq_info.packed.last_avail_counter =
+				vq->state.packed.last_avail_counter;
+			vq_info.packed.last_avail_idx =
+				vq->state.packed.last_avail_idx;
+			vq_info.packed.last_used_counter =
+				vq->state.packed.last_used_counter;
+			vq_info.packed.last_used_idx =
+				vq->state.packed.last_used_idx;
+		} else
+			vq_info.split.avail_index =
+				vq->state.split.avail_index;
+
+		vq_info.ready = vq->ready;
+
+		ret = -EFAULT;
+		if (copy_to_user(argp, &vq_info,
+		    sizeof(struct compat_vduse_vq_info)))
+			break;
+
+		ret = 0;
+		break;
+	}
+	default:
+		ret = -ENOIOCTLCMD;
+		break;
+	}
+
+	return vduse_dev_ioctl(file, cmd, (unsigned long)compat_ptr(arg));
+}
+#else
+#define vduse_dev_compat_ioctl compat_ptr_ioctl
+#endif
+
 static int vduse_dev_release(struct inode *inode, struct file *file)
 {
 	struct vduse_dev *dev = file->private_data;
@@ -1677,7 +1798,7 @@ static const struct file_operations vduse_dev_fops = {
 	.write_iter	= vduse_dev_write_iter,
 	.poll		= vduse_dev_poll,
 	.unlocked_ioctl	= vduse_dev_ioctl,
-	.compat_ioctl	= compat_ptr_ioctl,
+	.compat_ioctl	= vduse_dev_compat_ioctl,
 	.llseek		= noop_llseek,
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0636/2077] vdpa/octeon_ep: Fix PF->VF mailbox data address calculation
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (634 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0635/2077] vduse: fix compat handling for VDUSE_IOTLB_GET_FD/VDUSE_VQ_GET_INFO Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0637/2077] vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler Greg Kroah-Hartman
                   ` (361 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Srujana Challa, Michael S. Tsirkin,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Srujana Challa <schalla@marvell.com>

[ Upstream commit 74dc530f4c505d61f0f3620e59fe56c325ae3437 ]

The mailbox address was computed assuming 1 ring per VF. Read the
actual rings-per-VF from OCTEP_EPF_RINFO and use it when calculating
OCTEP_PF_MBOX_DATA offsets, fixing VF initialization when rings
per VF > 1.

Fixes: 8b6c724cdab8 ("virtio: vdpa: vDPA driver for Marvell OCTEON DPU devices")
Signed-off-by: Srujana Challa <schalla@marvell.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260224095226.1001151-2-schalla@marvell.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/vdpa/octeon_ep/octep_vdpa_main.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/vdpa/octeon_ep/octep_vdpa_main.c b/drivers/vdpa/octeon_ep/octep_vdpa_main.c
index 31a02e7fd7f279..9946480ee70460 100644
--- a/drivers/vdpa/octeon_ep/octep_vdpa_main.c
+++ b/drivers/vdpa/octeon_ep/octep_vdpa_main.c
@@ -1,6 +1,7 @@
 // SPDX-License-Identifier: GPL-2.0-only
 /* Copyright (C) 2024 Marvell. */
 
+#include <linux/bitfield.h>
 #include <linux/interrupt.h>
 #include <linux/io-64-nonatomic-lo-hi.h>
 #include <linux/module.h>
@@ -722,6 +723,8 @@ static int octep_sriov_enable(struct pci_dev *pdev, int num_vfs)
 	bool done = false;
 	int index = 0;
 	int ret, i;
+	u8 rpvf;
+	u64 val;
 
 	ret = pci_enable_sriov(pdev, num_vfs);
 	if (ret)
@@ -741,9 +744,11 @@ static int octep_sriov_enable(struct pci_dev *pdev, int num_vfs)
 		}
 	}
 
+	val = readq(addr + OCTEP_EPF_RINFO(0));
+	rpvf = FIELD_GET(GENMASK_ULL(35, 32), val);
 	if (done) {
 		for (i = 0; i < pf->enabled_vfs; i++)
-			writeq(OCTEP_DEV_READY_SIGNATURE, addr + OCTEP_PF_MBOX_DATA(i));
+			writeq(OCTEP_DEV_READY_SIGNATURE, addr + OCTEP_PF_MBOX_DATA(i * rpvf));
 	}
 
 	return num_vfs;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0637/2077] vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (635 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0636/2077] vdpa/octeon_ep: Fix PF->VF mailbox data address calculation Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0638/2077] iomap: pass the correct len to fserror_report_io in __iomap_write_begin Greg Kroah-Hartman
                   ` (360 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Srujana Challa, Michael S. Tsirkin,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Srujana Challa <schalla@marvell.com>

[ Upstream commit 0d21a1d6375a05274291e32c1ab7cd57dbb69513 ]

Look up the IRQ index in oct_hw->irqs instead of assuming
irq - irqs[0]. This supports non-contiguous IRQ numbers and
avoids incorrect ring indexing when irqs[0] is not the base.

Fixes: 26f8ce06af64 ("vdpa/octeon_ep: enable support for multiple interrupts per device")
Signed-off-by: Srujana Challa <schalla@marvell.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260224095226.1001151-5-schalla@marvell.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/vdpa/octeon_ep/octep_vdpa_main.c | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/drivers/vdpa/octeon_ep/octep_vdpa_main.c b/drivers/vdpa/octeon_ep/octep_vdpa_main.c
index 9946480ee70460..df8af6c1454cce 100644
--- a/drivers/vdpa/octeon_ep/octep_vdpa_main.c
+++ b/drivers/vdpa/octeon_ep/octep_vdpa_main.c
@@ -48,7 +48,7 @@ static struct octep_hw *vdpa_to_octep_hw(struct vdpa_device *vdpa_dev)
 static irqreturn_t octep_vdpa_intr_handler(int irq, void *data)
 {
 	struct octep_hw *oct_hw = data;
-	int i;
+	int i, start_ring_idx = -1;
 
 	/* Each device has multiple interrupts (nb_irqs) shared among rings
 	 * (nr_vring). Device interrupts are mapped to the rings in a
@@ -61,7 +61,16 @@ static irqreturn_t octep_vdpa_intr_handler(int irq, void *data)
 	 * 7 -> 7, 15, 23, 31, 39, 47, 55, 63;
 	 */
 
-	for (i = irq - oct_hw->irqs[0]; i < oct_hw->nr_vring; i += oct_hw->nb_irqs) {
+	for (i = 0; i < oct_hw->nb_irqs; i++) {
+		if (oct_hw->irqs[i] == irq) {
+			start_ring_idx = i;
+			break;
+		}
+	}
+	if (start_ring_idx == -1)
+		return IRQ_NONE;
+
+	for (i = start_ring_idx; i < oct_hw->nr_vring; i += oct_hw->nb_irqs) {
 		if (ioread8(oct_hw->vqs[i].cb_notify_addr)) {
 			/* Acknowledge the per ring notification to the device */
 			iowrite8(0, oct_hw->vqs[i].cb_notify_addr);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0638/2077] iomap: pass the correct len to fserror_report_io in __iomap_write_begin
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (636 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0637/2077] vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0639/2077] ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() Greg Kroah-Hartman
                   ` (359 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Darrick J. Wong,
	Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christoph Hellwig <hch@lst.de>

[ Upstream commit de654d66ff30e75d9308fd4d4f1627addef7923e ]

len is size of the (larger) write request, plen is the range for which
the read failed here.

Fixes: a9d573ee88af ("iomap: report file I/O errors to the VFS")
Signed-off-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260610050642.1906695-1-hch@lst.de
Reviewed-by: "Darrick J. Wong" <djwong@kernel.org>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/iomap/buffered-io.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/iomap/buffered-io.c b/fs/iomap/buffered-io.c
index d55b936e698628..5fa9a2c7e30eb8 100644
--- a/fs/iomap/buffered-io.c
+++ b/fs/iomap/buffered-io.c
@@ -850,7 +850,7 @@ static int __iomap_write_begin(const struct iomap_iter *iter,
 			if (status < 0)
 				fserror_report_io(iter->inode,
 						  FSERR_BUFFERED_READ, pos,
-						  len, status, GFP_NOFS);
+						  plen, status, GFP_NOFS);
 			if (status)
 				return status;
 		}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0639/2077] ASoC: cs35l56: Fix missing calls to wm_adsp2_remove()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (637 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0638/2077] iomap: pass the correct len to fserror_report_io in __iomap_write_begin Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0640/2077] ASoC: cs35l56: Prevent double-free of debugfs Greg Kroah-Hartman
                   ` (358 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Fitzgerald <rf@opensource.cirrus.com>

[ Upstream commit 85f7bf03632bfcdd6cedfb3945b7e387d9487d73 ]

Call wm_adsp2_remove() in cs35l56_remove() and the error path of
cs35l56_common_probe().

Depends on commit 7d3fb78b5503 ("ASoC: wm_adsp: Fix NULL dereference
when removing firmware controls").

The call to wm_halo_init() during driver probe should be paired with
a call to wm_adsp2_remove() but this was missing. The consequence
would be a memory leak of the control lists in the cs_dsp driver.

Fixes: e49611252900 ("ASoC: cs35l56: Add driver for Cirrus Logic CS35L56")
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260610093432.557375-2-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/codecs/cs35l56.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/sound/soc/codecs/cs35l56.c b/sound/soc/codecs/cs35l56.c
index 4fbbdcc8715162..3ab5395f15bb25 100644
--- a/sound/soc/codecs/cs35l56.c
+++ b/sound/soc/codecs/cs35l56.c
@@ -1964,11 +1964,14 @@ int cs35l56_common_probe(struct cs35l56_private *cs35l56)
 					 cs35l56_dai, ARRAY_SIZE(cs35l56_dai));
 	if (ret < 0) {
 		dev_err_probe(cs35l56->base.dev, ret, "Register codec failed\n");
-		goto err;
+		goto err_remove_wm_adsp;
 	}
 
 	return 0;
 
+err_remove_wm_adsp:
+	wm_adsp2_remove(&cs35l56->dsp);
+
 err:
 	gpiod_set_value_cansleep(cs35l56->base.reset_gpio, 0);
 	regulator_bulk_disable(ARRAY_SIZE(cs35l56->supplies), cs35l56->supplies);
@@ -2076,6 +2079,8 @@ void cs35l56_remove(struct cs35l56_private *cs35l56)
 
 	destroy_workqueue(cs35l56->dsp_wq);
 
+	wm_adsp2_remove(&cs35l56->dsp);
+
 	pm_runtime_dont_use_autosuspend(cs35l56->base.dev);
 	pm_runtime_suspend(cs35l56->base.dev);
 	pm_runtime_disable(cs35l56->base.dev);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0640/2077] ASoC: cs35l56: Prevent double-free of debugfs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (638 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0639/2077] ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0641/2077] ASoC: cs35l56: Cleanup if component_probe fails Greg Kroah-Hartman
                   ` (357 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko, Richard Fitzgerald,
	Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Fitzgerald <rf@opensource.cirrus.com>

[ Upstream commit 344a12ca7ba6e10f9779476780afe9d977d47322 ]

Invalidate the debugfs pointer after debugfs_remove_recursive() in
cs35l56_remove_cal_debugfs(). This prevents a double-free situation when
a future commit adds proper failure cleanup in cs35l56_component_probe().

As described by Sashiko (including the future cs35l56_component_probe()
cleanup commit):

During a normal component unbind, cs35l56_component_remove() calls
cs35l56_remove_cal_debugfs() which removes the directory but leaves
a dangling pointer.

If the component is later bound again, but _cs35l56_component_probe()
fails early (for example, if the init_completion times out), this new
error path will call cs35l56_component_remove(). This causes
cs35l56_remove_cal_debugfs() to be called again with the dangling
cs35l56_base->debugfs pointer from the previous lifecycle, resulting in
a use-after-free in debugfs_remove_recursive().

Fixes: f7097161e94c ("ASoC: cs35l56: Add common code for factory calibration")
Reported-by: sashiko <sashiko@sashiko.dev>
Link: https://sashiko.dev/#/patchset/20260609120738.284770-1-rf%40opensource.cirrus.com
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260610093432.557375-3-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/codecs/cs35l56-shared.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/soc/codecs/cs35l56-shared.c b/sound/soc/codecs/cs35l56-shared.c
index 795e2764d67ec8..e04b114a32b7f2 100644
--- a/sound/soc/codecs/cs35l56-shared.c
+++ b/sound/soc/codecs/cs35l56-shared.c
@@ -1293,6 +1293,7 @@ EXPORT_SYMBOL_NS_GPL(cs35l56_create_cal_debugfs, "SND_SOC_CS35L56_SHARED");
 void cs35l56_remove_cal_debugfs(struct cs35l56_base *cs35l56_base)
 {
 	debugfs_remove_recursive(cs35l56_base->debugfs);
+	cs35l56_base->debugfs = ERR_PTR(-ENOENT);
 }
 EXPORT_SYMBOL_NS_GPL(cs35l56_remove_cal_debugfs, "SND_SOC_CS35L56_SHARED");
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0641/2077] ASoC: cs35l56: Cleanup if component_probe fails
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (639 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0640/2077] ASoC: cs35l56: Prevent double-free of debugfs Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0642/2077] ASoC: cs35l56: Dont leave parent IRQ disabled if system_suspend fails Greg Kroah-Hartman
                   ` (356 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Fitzgerald <rf@opensource.cirrus.com>

[ Upstream commit a0df7522dfb098d56b42560247082d6f5a8581dd ]

If cs35l56_component_probe() fails, call cs35l56_component_remove() to
clean up.

All the cleanup in cs35l56_component_remove() is the same cleanup that
would need to be done (at least partially) if cs35l56_component_probe()
fails. So calling cs35l56_component_remove() avoids convoluted cleanup
gotos and duplicated code in cs35l56_component_probe().

The only action in cs35l56_component_remove() that is nominally
dependent on having completed the component_probe() action is the call
to wm_adsp2_component_remove(). Though it is currently safe to call that
even if wm_adsp2_component_probe() was not called. However,
wm_adsp2_component_probe() has been trivially updated to check itself
whether it needs to cleanup.

Fixes: e49611252900 ("ASoC: cs35l56: Add driver for Cirrus Logic CS35L56")
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260610093432.557375-4-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/codecs/cs35l56.c | 13 ++++++++++++-
 sound/soc/codecs/wm_adsp.c |  7 +++++++
 2 files changed, 19 insertions(+), 1 deletion(-)

diff --git a/sound/soc/codecs/cs35l56.c b/sound/soc/codecs/cs35l56.c
index 3ab5395f15bb25..3641ac1378c7c2 100644
--- a/sound/soc/codecs/cs35l56.c
+++ b/sound/soc/codecs/cs35l56.c
@@ -1326,7 +1326,7 @@ VISIBLE_IF_KUNIT int cs35l56_set_fw_name(struct snd_soc_component *component)
 }
 EXPORT_SYMBOL_IF_KUNIT(cs35l56_set_fw_name);
 
-static int cs35l56_component_probe(struct snd_soc_component *component)
+static int _cs35l56_component_probe(struct snd_soc_component *component)
 {
 	struct snd_soc_dapm_context *dapm = snd_soc_component_to_dapm(component);
 	struct cs35l56_private *cs35l56 = snd_soc_component_get_drvdata(component);
@@ -1426,6 +1426,17 @@ static void cs35l56_component_remove(struct snd_soc_component *component)
 	cs35l56->component = NULL;
 }
 
+static int cs35l56_component_probe(struct snd_soc_component *component)
+{
+	int ret;
+
+	ret = _cs35l56_component_probe(component);
+	if (ret < 0)
+		cs35l56_component_remove(component);
+
+	return ret;
+}
+
 static int cs35l56_set_bias_level(struct snd_soc_component *component,
 				  enum snd_soc_bias_level level)
 {
diff --git a/sound/soc/codecs/wm_adsp.c b/sound/soc/codecs/wm_adsp.c
index ca630c9948e49a..baa75e7ff53ba9 100644
--- a/sound/soc/codecs/wm_adsp.c
+++ b/sound/soc/codecs/wm_adsp.c
@@ -1170,7 +1170,14 @@ EXPORT_SYMBOL_GPL(wm_adsp2_component_probe);
 
 int wm_adsp2_component_remove(struct wm_adsp *dsp, struct snd_soc_component *component)
 {
+	if (!dsp)
+		return 0;
+
+	if (!dsp->component)
+		return 0;
+
 	cs_dsp_cleanup_debugfs(&dsp->cs_dsp);
+	dsp->component = NULL;
 
 	return 0;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0642/2077] ASoC: cs35l56: Dont leave parent IRQ disabled if system_suspend fails
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (640 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0641/2077] ASoC: cs35l56: Cleanup if component_probe fails Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0643/2077] hwmon: (gpd-fan): drop global driver data and use per-device allocation Greg Kroah-Hartman
                   ` (355 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Fitzgerald <rf@opensource.cirrus.com>

[ Upstream commit 53cebeb017164254cde5e31c94d8deef9e4fff97 ]

In cs35l56_system_suspend() re-enable the parent IRQ if the call to
pm_runtime_force_suspend() returns an error.

Fixes: f9dc6b875ec0 ("ASoC: cs35l56: Add basic system suspend handling")
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260610105556.612830-1-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/codecs/cs35l56.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/sound/soc/codecs/cs35l56.c b/sound/soc/codecs/cs35l56.c
index 3641ac1378c7c2..033028a4734b50 100644
--- a/sound/soc/codecs/cs35l56.c
+++ b/sound/soc/codecs/cs35l56.c
@@ -1491,6 +1491,7 @@ static int __maybe_unused cs35l56_runtime_resume_i2c_spi(struct device *dev)
 int cs35l56_system_suspend(struct device *dev)
 {
 	struct cs35l56_private *cs35l56 = dev_get_drvdata(dev);
+	int ret;
 
 	dev_dbg(dev, "system_suspend\n");
 
@@ -1506,7 +1507,11 @@ int cs35l56_system_suspend(struct device *dev)
 	if (cs35l56->base.irq)
 		disable_irq(cs35l56->base.irq);
 
-	return pm_runtime_force_suspend(dev);
+	ret = pm_runtime_force_suspend(dev);
+	if ((ret < 0) && cs35l56->base.irq)
+		enable_irq(cs35l56->base.irq);
+
+	return ret;
 }
 EXPORT_SYMBOL_GPL(cs35l56_system_suspend);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0643/2077] hwmon: (gpd-fan): drop global driver data and use per-device allocation
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (641 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0642/2077] ASoC: cs35l56: Dont leave parent IRQ disabled if system_suspend fails Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0644/2077] hwmon: (gpd-fan): Initialize EC before registering hwmon device Greg Kroah-Hartman
                   ` (354 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pei Xiao, Guenter Roeck, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pei Xiao <xiaopei01@kylinos.cn>

[ Upstream commit 03b4addf8282fa2b63f2d7448d1a9bce9be3f556 ]

replace the global state gpd_driver_priv with per-device private data
(struct gpd_fan_data) allocated in probe. This allows the driver to
support multiple instances in the future and aligns with kernel best
practices.

No functional change intended.

Signed-off-by: Pei Xiao <xiaopei01@kylinos.cn>
Link: https://lore.kernel.org/r/1cd3e13033fdd3d0f9b59322f7c86e350d113b92.1781055639.git.xiaopei01@kylinos.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Stable-dep-of: 1fb4397509bd ("hwmon: (gpd-fan): fix race condition between device removal and sysfs access")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwmon/gpd-fan.c | 209 ++++++++++++++++++++++------------------
 1 file changed, 115 insertions(+), 94 deletions(-)

diff --git a/drivers/hwmon/gpd-fan.c b/drivers/hwmon/gpd-fan.c
index 80de5f20781eb1..7284babd4f5c96 100644
--- a/drivers/hwmon/gpd-fan.c
+++ b/drivers/hwmon/gpd-fan.c
@@ -40,12 +40,11 @@ enum FAN_PWM_ENABLE {
 	AUTOMATIC	= 2,
 };
 
-static struct {
+struct gpd_fan_data {
 	enum FAN_PWM_ENABLE pwm_enable;
 	u8 pwm_value;
-
 	const struct gpd_fan_drvdata *drvdata;
-} gpd_driver_priv;
+};
 
 struct gpd_fan_drvdata {
 	const char *board_name; // Board name for module param comparison
@@ -249,10 +248,10 @@ static const struct gpd_fan_drvdata *gpd_module_drvdata[] = {
 };
 
 // Helper functions to handle EC read/write
-static void gpd_ecram_read(u16 offset, u8 *val)
+static void gpd_ecram_read(const struct gpd_fan_drvdata *drvdata, u16 offset, u8 *val)
 {
-	u16 addr_port = gpd_driver_priv.drvdata->addr_port;
-	u16 data_port = gpd_driver_priv.drvdata->data_port;
+	u16 addr_port = drvdata->addr_port;
+	u16 data_port = drvdata->data_port;
 
 	outb(0x2E, addr_port);
 	outb(0x11, data_port);
@@ -270,10 +269,10 @@ static void gpd_ecram_read(u16 offset, u8 *val)
 	*val = inb(data_port);
 }
 
-static void gpd_ecram_write(u16 offset, u8 value)
+static void gpd_ecram_write(const struct gpd_fan_drvdata *drvdata, u16 offset, u8 value)
 {
-	u16 addr_port = gpd_driver_priv.drvdata->addr_port;
-	u16 data_port = gpd_driver_priv.drvdata->data_port;
+	u16 addr_port = drvdata->addr_port;
+	u16 data_port = drvdata->data_port;
 
 	outb(0x2E, addr_port);
 	outb(0x11, data_port);
@@ -291,198 +290,198 @@ static void gpd_ecram_write(u16 offset, u8 value)
 	outb(value, data_port);
 }
 
-static int gpd_generic_read_rpm(void)
+static int gpd_generic_read_rpm(struct gpd_fan_data *data)
 {
-	const struct gpd_fan_drvdata *const drvdata = gpd_driver_priv.drvdata;
+	const struct gpd_fan_drvdata *drvdata = data->drvdata;
 	u8 high, low;
 
-	gpd_ecram_read(drvdata->rpm_read, &high);
-	gpd_ecram_read(drvdata->rpm_read + 1, &low);
+	gpd_ecram_read(drvdata, drvdata->rpm_read, &high);
+	gpd_ecram_read(drvdata, drvdata->rpm_read + 1, &low);
 
 	return (u16)high << 8 | low;
 }
 
-static int gpd_wm2_read_rpm(void)
+static int gpd_wm2_read_rpm(struct gpd_fan_data *data)
 {
+	const struct gpd_fan_drvdata *drvdata = data->drvdata;
+
 	for (u16 pwm_ctr_offset = GPD_PWM_CTR_OFFSET;
 	     pwm_ctr_offset <= GPD_PWM_CTR_OFFSET + 2; pwm_ctr_offset++) {
 		u8 PWMCTR;
 
-		gpd_ecram_read(pwm_ctr_offset, &PWMCTR);
+		gpd_ecram_read(drvdata, pwm_ctr_offset, &PWMCTR);
 
 		if (PWMCTR != 0xB8)
-			gpd_ecram_write(pwm_ctr_offset, 0xB8);
+			gpd_ecram_write(drvdata, pwm_ctr_offset, 0xB8);
 	}
 
-	return gpd_generic_read_rpm();
+	return gpd_generic_read_rpm(data);
 }
 
 // Read value for fan1_input
-static int gpd_read_rpm(void)
+static int gpd_read_rpm(struct gpd_fan_data *data)
 {
-	switch (gpd_driver_priv.drvdata->board) {
+	switch (data->drvdata->board) {
 	case win4_6800u:
 	case win_mini:
 	case duo:
 	case mpc2:
-		return gpd_generic_read_rpm();
+		return gpd_generic_read_rpm(data);
 	case win_max_2:
-		return gpd_wm2_read_rpm();
+		return gpd_wm2_read_rpm(data);
 	}
 
 	return 0;
 }
 
-static int gpd_wm2_read_pwm(void)
+static int gpd_wm2_read_pwm(struct gpd_fan_data *data)
 {
-	const struct gpd_fan_drvdata *const drvdata = gpd_driver_priv.drvdata;
+	const struct gpd_fan_drvdata *drvdata = data->drvdata;
 	u8 var;
 
-	gpd_ecram_read(drvdata->pwm_write, &var);
+	gpd_ecram_read(drvdata, drvdata->pwm_write, &var);
 
 	// Match gpd_generic_write_pwm(u8) below
 	return DIV_ROUND_CLOSEST((var - 1) * 255, (drvdata->pwm_max - 1));
 }
 
 // Read value for pwm1
-static int gpd_read_pwm(void)
+static int gpd_read_pwm(struct gpd_fan_data *data)
 {
-	switch (gpd_driver_priv.drvdata->board) {
+	switch (data->drvdata->board) {
 	case win_mini:
 	case duo:
 	case win4_6800u:
 	case mpc2:
-		switch (gpd_driver_priv.pwm_enable) {
+		switch (data->pwm_enable) {
 		case DISABLE:
 			return 255;
 		case MANUAL:
-			return gpd_driver_priv.pwm_value;
+			return data->pwm_value;
 		case AUTOMATIC:
 			return -EOPNOTSUPP;
 		}
 		break;
 	case win_max_2:
-		return gpd_wm2_read_pwm();
+		return gpd_wm2_read_pwm(data);
 	}
 	return 0;
 }
 
 // PWM value's range in EC is 1 - pwm_max, cast 0 - 255 to it.
-static inline u8 gpd_cast_pwm_range(u8 val)
+static inline u8 gpd_cast_pwm_range(const struct gpd_fan_drvdata *drvdata, u8 val)
 {
-	const struct gpd_fan_drvdata *const drvdata = gpd_driver_priv.drvdata;
-
 	return DIV_ROUND_CLOSEST(val * (drvdata->pwm_max - 1), 255) + 1;
 }
 
-static void gpd_generic_write_pwm(u8 val)
+static void gpd_generic_write_pwm(struct gpd_fan_data *data, u8 val)
 {
-	const struct gpd_fan_drvdata *const drvdata = gpd_driver_priv.drvdata;
+	const struct gpd_fan_drvdata *drvdata = data->drvdata;
 	u8 pwm_reg;
 
-	pwm_reg = gpd_cast_pwm_range(val);
-	gpd_ecram_write(drvdata->pwm_write, pwm_reg);
+	pwm_reg = gpd_cast_pwm_range(drvdata, val);
+	gpd_ecram_write(drvdata, drvdata->pwm_write, pwm_reg);
 }
 
-static void gpd_duo_write_pwm(u8 val)
+static void gpd_duo_write_pwm(struct gpd_fan_data *data, u8 val)
 {
-	const struct gpd_fan_drvdata *const drvdata = gpd_driver_priv.drvdata;
+	const struct gpd_fan_drvdata *drvdata = data->drvdata;
 	u8 pwm_reg;
 
-	pwm_reg = gpd_cast_pwm_range(val);
-	gpd_ecram_write(drvdata->pwm_write, pwm_reg);
-	gpd_ecram_write(drvdata->pwm_write + 1, pwm_reg);
+	pwm_reg = gpd_cast_pwm_range(drvdata, val);
+	gpd_ecram_write(drvdata, drvdata->pwm_write, pwm_reg);
+	gpd_ecram_write(drvdata, drvdata->pwm_write + 1, pwm_reg);
 }
 
 // Write value for pwm1
-static int gpd_write_pwm(u8 val)
+static int gpd_write_pwm(struct gpd_fan_data *data, u8 val)
 {
-	if (gpd_driver_priv.pwm_enable != MANUAL)
+	if (data->pwm_enable != MANUAL)
 		return -EPERM;
 
-	switch (gpd_driver_priv.drvdata->board) {
+	switch (data->drvdata->board) {
 	case duo:
-		gpd_duo_write_pwm(val);
+		gpd_duo_write_pwm(data, val);
 		break;
 	case win_mini:
 	case win4_6800u:
 	case win_max_2:
 	case mpc2:
-		gpd_generic_write_pwm(val);
+		gpd_generic_write_pwm(data, val);
 		break;
 	}
 
 	return 0;
 }
 
-static void gpd_win_mini_set_pwm_enable(enum FAN_PWM_ENABLE pwm_enable)
+static void gpd_win_mini_set_pwm_enable(struct gpd_fan_data *data, enum FAN_PWM_ENABLE pwm_enable)
 {
 	switch (pwm_enable) {
 	case DISABLE:
-		gpd_generic_write_pwm(255);
+		gpd_generic_write_pwm(data, 255);
 		break;
 	case MANUAL:
-		gpd_generic_write_pwm(gpd_driver_priv.pwm_value);
+		gpd_generic_write_pwm(data, data->pwm_value);
 		break;
 	case AUTOMATIC:
-		gpd_ecram_write(gpd_driver_priv.drvdata->pwm_write, 0);
+		gpd_ecram_write(data->drvdata, data->drvdata->pwm_write, 0);
 		break;
 	}
 }
 
-static void gpd_duo_set_pwm_enable(enum FAN_PWM_ENABLE pwm_enable)
+static void gpd_duo_set_pwm_enable(struct gpd_fan_data *data, enum FAN_PWM_ENABLE pwm_enable)
 {
 	switch (pwm_enable) {
 	case DISABLE:
-		gpd_duo_write_pwm(255);
+		gpd_duo_write_pwm(data, 255);
 		break;
 	case MANUAL:
-		gpd_duo_write_pwm(gpd_driver_priv.pwm_value);
+		gpd_duo_write_pwm(data, data->pwm_value);
 		break;
 	case AUTOMATIC:
-		gpd_ecram_write(gpd_driver_priv.drvdata->pwm_write, 0);
+		gpd_ecram_write(data->drvdata, data->drvdata->pwm_write, 0);
 		break;
 	}
 }
 
-static void gpd_wm2_set_pwm_enable(enum FAN_PWM_ENABLE enable)
+static void gpd_wm2_set_pwm_enable(struct gpd_fan_data *data, enum FAN_PWM_ENABLE enable)
 {
-	const struct gpd_fan_drvdata *const drvdata = gpd_driver_priv.drvdata;
+	const struct gpd_fan_drvdata *drvdata = data->drvdata;
 
 	switch (enable) {
 	case DISABLE:
-		gpd_generic_write_pwm(255);
-		gpd_ecram_write(drvdata->manual_control_enable, 1);
+		gpd_generic_write_pwm(data, 255);
+		gpd_ecram_write(drvdata, drvdata->manual_control_enable, 1);
 		break;
 	case MANUAL:
-		gpd_generic_write_pwm(gpd_driver_priv.pwm_value);
-		gpd_ecram_write(drvdata->manual_control_enable, 1);
+		gpd_generic_write_pwm(data, data->pwm_value);
+		gpd_ecram_write(drvdata, drvdata->manual_control_enable, 1);
 		break;
 	case AUTOMATIC:
-		gpd_ecram_write(drvdata->manual_control_enable, 0);
+		gpd_ecram_write(drvdata, drvdata->manual_control_enable, 0);
 		break;
 	}
 }
 
 // Write value for pwm1_enable
-static void gpd_set_pwm_enable(enum FAN_PWM_ENABLE enable)
+static void gpd_set_pwm_enable(struct gpd_fan_data *data, enum FAN_PWM_ENABLE enable)
 {
 	if (enable == MANUAL)
 		// Set pwm_value to max firstly when switching to manual mode, in
 		// consideration of device safety.
-		gpd_driver_priv.pwm_value = 255;
+		data->pwm_value = 255;
 
-	switch (gpd_driver_priv.drvdata->board) {
+	switch (data->drvdata->board) {
 	case win_mini:
 	case win4_6800u:
 	case mpc2:
-		gpd_win_mini_set_pwm_enable(enable);
+		gpd_win_mini_set_pwm_enable(data, enable);
 		break;
 	case duo:
-		gpd_duo_set_pwm_enable(enable);
+		gpd_duo_set_pwm_enable(data, enable);
 		break;
 	case win_max_2:
-		gpd_wm2_set_pwm_enable(enable);
+		gpd_wm2_set_pwm_enable(data, enable);
 		break;
 	}
 }
@@ -505,15 +504,16 @@ static umode_t gpd_fan_hwmon_is_visible(__always_unused const void *drvdata,
 	return 0;
 }
 
-static int gpd_fan_hwmon_read(__always_unused struct device *dev,
+static int gpd_fan_hwmon_read(struct device *dev,
 			      enum hwmon_sensor_types type, u32 attr,
 			      __always_unused int channel, long *val)
 {
+	struct gpd_fan_data *data = dev_get_drvdata(dev);
 	int ret;
 
 	if (type == hwmon_fan) {
 		if (attr == hwmon_fan_input) {
-			ret = gpd_read_rpm();
+			ret = gpd_read_rpm(data);
 
 			if (ret < 0)
 				return ret;
@@ -524,10 +524,10 @@ static int gpd_fan_hwmon_read(__always_unused struct device *dev,
 	} else if (type == hwmon_pwm) {
 		switch (attr) {
 		case hwmon_pwm_enable:
-			*val = gpd_driver_priv.pwm_enable;
+			*val = data->pwm_enable;
 			return 0;
 		case hwmon_pwm_input:
-			ret = gpd_read_pwm();
+			ret = gpd_read_pwm(data);
 
 			if (ret < 0)
 				return ret;
@@ -540,27 +540,29 @@ static int gpd_fan_hwmon_read(__always_unused struct device *dev,
 	return -EOPNOTSUPP;
 }
 
-static int gpd_fan_hwmon_write(__always_unused struct device *dev,
+static int gpd_fan_hwmon_write(struct device *dev,
 			       enum hwmon_sensor_types type, u32 attr,
 			       __always_unused int channel, long val)
 {
+	struct gpd_fan_data *data = dev_get_drvdata(dev);
+
 	if (type == hwmon_pwm) {
 		switch (attr) {
 		case hwmon_pwm_enable:
 			if (!in_range(val, 0, 3))
 				return -EINVAL;
 
-			gpd_driver_priv.pwm_enable = val;
+			data->pwm_enable = val;
 
-			gpd_set_pwm_enable(gpd_driver_priv.pwm_enable);
+			gpd_set_pwm_enable(data, data->pwm_enable);
 			return 0;
 		case hwmon_pwm_input:
 			if (!in_range(val, 0, 256))
 				return -EINVAL;
 
-			gpd_driver_priv.pwm_value = val;
+			data->pwm_value = val;
 
-			return gpd_write_pwm(val);
+			return gpd_write_pwm(data, val);
 		}
 	}
 
@@ -584,26 +586,27 @@ static struct hwmon_chip_info gpd_fan_chip_info = {
 	.info = gpd_fan_hwmon_channel_info
 };
 
-static void gpd_win4_init_ec(void)
+static void gpd_win4_init_ec(struct gpd_fan_data *data)
 {
+	const struct gpd_fan_drvdata *drvdata = data->drvdata;
 	u8 chip_id, chip_ver;
 
-	gpd_ecram_read(0x2000, &chip_id);
+	gpd_ecram_read(drvdata, 0x2000, &chip_id);
 
 	if (chip_id == 0x55) {
-		gpd_ecram_read(0x1060, &chip_ver);
-		gpd_ecram_write(0x1060, chip_ver | 0x80);
+		gpd_ecram_read(drvdata, 0x1060, &chip_ver);
+		gpd_ecram_write(drvdata, 0x1060, chip_ver | 0x80);
 	}
 }
 
-static void gpd_init_ec(void)
+static void gpd_init_ec(struct gpd_fan_data *data)
 {
 	// The buggy firmware won't initialize EC properly on boot.
 	// Before its initialization, reading RPM will always return 0,
 	// and writing PWM will have no effect.
 	// Initialize it manually on driver load.
-	if (gpd_driver_priv.drvdata->board == win4_6800u)
-		gpd_win4_init_ec();
+	if (data->drvdata->board == win4_6800u)
+		gpd_win4_init_ec(data);
 }
 
 static int gpd_fan_probe(struct platform_device *pdev)
@@ -611,7 +614,9 @@ static int gpd_fan_probe(struct platform_device *pdev)
 	struct device *dev = &pdev->dev;
 	const struct resource *region;
 	const struct resource *res;
-	const struct device *hwdev;
+	struct device *hwdev;
+	struct gpd_fan_data *data;
+	const struct gpd_fan_drvdata *match;
 
 	res = platform_get_resource(pdev, IORESOURCE_IO, 0);
 	if (!res)
@@ -624,24 +629,42 @@ static int gpd_fan_probe(struct platform_device *pdev)
 		return dev_err_probe(dev, -EBUSY,
 				     "Failed to request region\n");
 
+	data = devm_kzalloc(dev, sizeof(*data), GFP_KERNEL);
+	if (!data)
+		return -ENOMEM;
+
+	match = dev_get_platdata(dev);
+	if (!match)
+		return -EINVAL;
+
+	data->drvdata = match;
+	data->pwm_enable = AUTOMATIC;
+	data->pwm_value = 255;
+
+	dev_set_drvdata(dev, data);
+
 	hwdev = devm_hwmon_device_register_with_info(dev,
 						     DRIVER_NAME,
-						     NULL,
+						     data,
 						     &gpd_fan_chip_info,
 						     NULL);
 	if (IS_ERR(hwdev))
 		return dev_err_probe(dev, PTR_ERR(hwdev),
 				     "Failed to register hwmon device\n");
 
-	gpd_init_ec();
+	gpd_init_ec(data);
 
 	return 0;
 }
 
-static void gpd_fan_remove(__always_unused struct platform_device *pdev)
+static void gpd_fan_remove(struct platform_device *pdev)
 {
-	gpd_driver_priv.pwm_enable = AUTOMATIC;
-	gpd_set_pwm_enable(AUTOMATIC);
+	struct gpd_fan_data *data = dev_get_drvdata(&pdev->dev);
+
+	if (data) {
+		data->pwm_enable = AUTOMATIC;
+		gpd_set_pwm_enable(data, AUTOMATIC);
+	}
 }
 
 static struct platform_driver gpd_fan_driver = {
@@ -668,6 +691,7 @@ static int __init gpd_fan_init(void)
 	if (!match) {
 		const struct dmi_system_id *dmi_match =
 			dmi_first_match(dmi_table);
+
 		if (dmi_match)
 			match = dmi_match->driver_data;
 	}
@@ -675,10 +699,6 @@ static int __init gpd_fan_init(void)
 	if (!match)
 		return -ENODEV;
 
-	gpd_driver_priv.pwm_enable = AUTOMATIC;
-	gpd_driver_priv.pwm_value = 255;
-	gpd_driver_priv.drvdata = match;
-
 	struct resource gpd_fan_resources[] = {
 		{
 			.start = match->addr_port,
@@ -690,7 +710,8 @@ static int __init gpd_fan_init(void)
 	gpd_fan_platform_device = platform_create_bundle(&gpd_fan_driver,
 							 gpd_fan_probe,
 							 gpd_fan_resources,
-							 1, NULL, 0);
+							 1,
+							 match, sizeof(*match));
 
 	if (IS_ERR(gpd_fan_platform_device)) {
 		pr_warn("Failed to create platform device\n");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0644/2077] hwmon: (gpd-fan): Initialize EC before registering hwmon device
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (642 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0643/2077] hwmon: (gpd-fan): drop global driver data and use per-device allocation Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0645/2077] hwmon: (gpd-fan): fix race condition between device removal and sysfs access Greg Kroah-Hartman
                   ` (353 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pei Xiao, Guenter Roeck, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pei Xiao <xiaopei01@kylinos.cn>

[ Upstream commit a8a444917fe5d30a9787f41cc179f55fc5f559d3 ]

Move the gpd_init_ec() call to before devm_hwmon_device_register_with_info
in the probe function. With the previous ordering the hwmon device was
registered and exposed to userspace before the EC initialization
completes, creating a window where sysfs reads could return invalid values.

Some buggy firmware won't initialize EC properly on boot. Before its
initialization, reading RPM will always return 0, and writing PWM will have
no effect. So move gpd_init_ec to before hwmon device register.

Fixes: 0ab88e239439 ("hwmon: add GPD devices sensor driver")
Signed-off-by: Pei Xiao <xiaopei01@kylinos.cn>
Link: https://lore.kernel.org/r/4be3734b135c8013157979ab5e80c7ee51243ddd.1781055639.git.xiaopei01@kylinos.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Stable-dep-of: 1fb4397509bd ("hwmon: (gpd-fan): fix race condition between device removal and sysfs access")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwmon/gpd-fan.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/drivers/hwmon/gpd-fan.c b/drivers/hwmon/gpd-fan.c
index 7284babd4f5c96..745b3fb9e3a49d 100644
--- a/drivers/hwmon/gpd-fan.c
+++ b/drivers/hwmon/gpd-fan.c
@@ -643,6 +643,7 @@ static int gpd_fan_probe(struct platform_device *pdev)
 
 	dev_set_drvdata(dev, data);
 
+	gpd_init_ec(data);
 	hwdev = devm_hwmon_device_register_with_info(dev,
 						     DRIVER_NAME,
 						     data,
@@ -651,9 +652,6 @@ static int gpd_fan_probe(struct platform_device *pdev)
 	if (IS_ERR(hwdev))
 		return dev_err_probe(dev, PTR_ERR(hwdev),
 				     "Failed to register hwmon device\n");
-
-	gpd_init_ec(data);
-
 	return 0;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0645/2077] hwmon: (gpd-fan): fix race condition between device removal and sysfs access
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (643 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0644/2077] hwmon: (gpd-fan): Initialize EC before registering hwmon device Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0646/2077] ext4: fix ERR_PTR(0) in ext4_mkdir() Greg Kroah-Hartman
                   ` (352 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pei Xiao, Guenter Roeck, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pei Xiao <xiaopei01@kylinos.cn>

[ Upstream commit 1fb4397509bd8701d323e81ac9a97c2e24ed49eb ]

Replace the manual gpd_fan_remove() callback with a devres-managed
action using devm_add_action_or_reset(). The original remove hook
resets the fan to AUTOMATIC mode, but the hwmon sysfs interface
(registered with devm_hwmon_device_register_with_info()) remains
active until after the remove callback completes. This creates a
race window where a concurrent userspace sysfs access can interleave
with the EC I/O sequence, potentially corrupting EC registers.

Using devm_add_action_or_reset() registers the reset function as a
devres action. Due to the LIFO release order of devres, the hwmon
device is unregistered (sysfs removed) before the reset action
executes, eliminating the race condition.

Fixes: 0ab88e239439 ("hwmon: add GPD devices sensor driver")
Signed-off-by: Pei Xiao <xiaopei01@kylinos.cn>
Link: https://lore.kernel.org/r/4400828422cf3a88adad4db224d9efccdb1049d2.1781055639.git.xiaopei01@kylinos.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwmon/gpd-fan.c | 27 ++++++++++++++++-----------
 1 file changed, 16 insertions(+), 11 deletions(-)

diff --git a/drivers/hwmon/gpd-fan.c b/drivers/hwmon/gpd-fan.c
index 745b3fb9e3a49d..4615f98771ddf9 100644
--- a/drivers/hwmon/gpd-fan.c
+++ b/drivers/hwmon/gpd-fan.c
@@ -609,6 +609,16 @@ static void gpd_init_ec(struct gpd_fan_data *data)
 		gpd_win4_init_ec(data);
 }
 
+static void gpd_fan_reset_hardware(void *pdata)
+{
+	struct gpd_fan_data *data = pdata;
+
+	if (data) {
+		data->pwm_enable = AUTOMATIC;
+		gpd_set_pwm_enable(data, AUTOMATIC);
+	}
+}
+
 static int gpd_fan_probe(struct platform_device *pdev)
 {
 	struct device *dev = &pdev->dev;
@@ -617,6 +627,7 @@ static int gpd_fan_probe(struct platform_device *pdev)
 	struct device *hwdev;
 	struct gpd_fan_data *data;
 	const struct gpd_fan_drvdata *match;
+	int ret;
 
 	res = platform_get_resource(pdev, IORESOURCE_IO, 0);
 	if (!res)
@@ -644,6 +655,11 @@ static int gpd_fan_probe(struct platform_device *pdev)
 	dev_set_drvdata(dev, data);
 
 	gpd_init_ec(data);
+
+	ret = devm_add_action_or_reset(dev, gpd_fan_reset_hardware, data);
+	if (ret)
+		return ret;
+
 	hwdev = devm_hwmon_device_register_with_info(dev,
 						     DRIVER_NAME,
 						     data,
@@ -655,19 +671,8 @@ static int gpd_fan_probe(struct platform_device *pdev)
 	return 0;
 }
 
-static void gpd_fan_remove(struct platform_device *pdev)
-{
-	struct gpd_fan_data *data = dev_get_drvdata(&pdev->dev);
-
-	if (data) {
-		data->pwm_enable = AUTOMATIC;
-		gpd_set_pwm_enable(data, AUTOMATIC);
-	}
-}
-
 static struct platform_driver gpd_fan_driver = {
 	.probe = gpd_fan_probe,
-	.remove = gpd_fan_remove,
 	.driver = {
 		.name = KBUILD_MODNAME,
 	},
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0646/2077] ext4: fix ERR_PTR(0) in ext4_mkdir()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (644 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0645/2077] hwmon: (gpd-fan): fix race condition between device removal and sysfs access Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0647/2077] tools: missed broadcast_neigh if_link uapi header Greg Kroah-Hartman
                   ` (351 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hongling Zeng, Jan Kara, Baokun Li,
	Theodore Tso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hongling Zeng <zenghongling@kylinos.cn>

[ Upstream commit 8e1c43af7cf5091d99db38b7c8129e394d7f45b5 ]

When mkdir succeeds, ext4_mkdir() returns ERR_PTR(0) which is incorrect.
It should return NULL instead for success and ERR_PTR() only with
negative error codes for failure.

Fixes: 88d5baf69082 ("Change inode_operations.mkdir to return struct dentry *")
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Reviewed-by: Jan Kara <jack@suse.cz>
Reviewed-by: Baokun Li <libaokun@linux.alibaba.com>
Link: https://patch.msgid.link/20260604073647.211279-1-zenghongling@kylinos.cn
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ext4/namei.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
index 4a47fbd8dd30ce..8cadaeb15b2bd2 100644
--- a/fs/ext4/namei.c
+++ b/fs/ext4/namei.c
@@ -3054,7 +3054,7 @@ static struct dentry *ext4_mkdir(struct mnt_idmap *idmap, struct inode *dir,
 out_retry:
 	if (err == -ENOSPC && ext4_should_retry_alloc(dir->i_sb, &retries))
 		goto retry;
-	return ERR_PTR(err);
+	return err ? ERR_PTR(err) : NULL;
 }
 
 /*
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0647/2077] tools: missed broadcast_neigh if_link uapi header
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (645 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0646/2077] ext4: fix ERR_PTR(0) in ext4_mkdir() Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0648/2077] netlink: specs: rt-link: missed broadcast-neigh Greg Kroah-Hartman
                   ` (350 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Louis Scalbert, Jay Vosburgh,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Louis Scalbert <louis.scalbert@6wind.com>

[ Upstream commit 0134432215f0e0d4526544ac63dabe20e8a6951e ]

Add missing IFLA_BOND_BROADCAST_NEIGH in if_link uapi header.

Signed-off-by: Louis Scalbert <louis.scalbert@6wind.com>
Acked-by: Jay Vosburgh <jv@jvosburgh.net>
Link: https://patch.msgid.link/20260603150331.1919611-2-louis.scalbert@6wind.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 32b0b8953343 ("bonding: 3ad: add lacp_strict configuration knob")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/include/uapi/linux/if_link.h | 1 +
 1 file changed, 1 insertion(+)

diff --git a/tools/include/uapi/linux/if_link.h b/tools/include/uapi/linux/if_link.h
index 7e46ca4cd31bb5..97a2d4411534ae 100644
--- a/tools/include/uapi/linux/if_link.h
+++ b/tools/include/uapi/linux/if_link.h
@@ -1526,6 +1526,7 @@ enum {
 	IFLA_BOND_MISSED_MAX,
 	IFLA_BOND_NS_IP6_TARGET,
 	IFLA_BOND_COUPLED_CONTROL,
+	IFLA_BOND_BROADCAST_NEIGH,
 	__IFLA_BOND_MAX,
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0648/2077] netlink: specs: rt-link: missed broadcast-neigh
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (646 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0647/2077] tools: missed broadcast_neigh if_link uapi header Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0649/2077] bonding: 3ad: add lacp_strict configuration knob Greg Kroah-Hartman
                   ` (349 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Louis Scalbert, Jay Vosburgh,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Louis Scalbert <louis.scalbert@6wind.com>

[ Upstream commit 363037983cc503eb0b5a5c0ab80bf1434cfd168a ]

Add missed broadcast-neigh.

Signed-off-by: Louis Scalbert <louis.scalbert@6wind.com>
Acked-by: Jay Vosburgh <jv@jvosburgh.net>
Link: https://patch.msgid.link/20260603150331.1919611-3-louis.scalbert@6wind.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 32b0b8953343 ("bonding: 3ad: add lacp_strict configuration knob")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/netlink/specs/rt-link.yaml | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/Documentation/netlink/specs/rt-link.yaml b/Documentation/netlink/specs/rt-link.yaml
index f23aa5f229c500..484e0a97b653a1 100644
--- a/Documentation/netlink/specs/rt-link.yaml
+++ b/Documentation/netlink/specs/rt-link.yaml
@@ -1351,6 +1351,9 @@ attribute-sets:
       -
         name: coupled-control
         type: u8
+      -
+        name: broadcast-neigh
+        type: u8
   -
     name: bond-ad-info-attrs
     name-prefix: ifla-bond-ad-info-
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0649/2077] bonding: 3ad: add lacp_strict configuration knob
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (647 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0648/2077] netlink: specs: rt-link: missed broadcast-neigh Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0650/2077] bonding: 3ad: fix carrier when no usable slaves Greg Kroah-Hartman
                   ` (348 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Louis Scalbert, Jay Vosburgh,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Louis Scalbert <louis.scalbert@6wind.com>

[ Upstream commit 32b0b8953343eaceaa816a9ead3b6bb66355c64e ]

When an 802.3ad (LACP) bonding interface has no slaves in the
collecting/distributing state, the bonding master still reports
carrier as up as long as at least 'min_links' slaves have carrier.

In this situation, only one slave is effectively used for TX/RX,
while traffic received on other slaves is dropped. Upper-layer
daemons therefore consider the interface operational, even though
traffic may be blackholed if the lack of LACP negotiation means
the partner is not ready to deal with traffic.

Introduce a configuration knob to control this behavior. It allows
the bonding master to assert carrier only when at least 'min_links'
slaves are in Collecting_Distributing state.

The default mode preserves the existing behavior. This patch only
introduces the knob; its behavior is implemented in the subsequent
commit.

Fixes: 655f8919d549 ("bonding: add min links parameter to 802.3ad")
Signed-off-by: Louis Scalbert <louis.scalbert@6wind.com>
Acked-by: Jay Vosburgh <jv@jvosburgh.net>
Link: https://patch.msgid.link/20260603150331.1919611-4-louis.scalbert@6wind.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/netlink/specs/rt-link.yaml |  3 +++
 Documentation/networking/bonding.rst     | 23 +++++++++++++++++++++
 drivers/net/bonding/bond_main.c          |  1 +
 drivers/net/bonding/bond_netlink.c       | 16 +++++++++++++++
 drivers/net/bonding/bond_options.c       | 26 ++++++++++++++++++++++++
 include/net/bond_options.h               |  1 +
 include/net/bonding.h                    |  1 +
 include/uapi/linux/if_link.h             |  1 +
 tools/include/uapi/linux/if_link.h       |  1 +
 9 files changed, 73 insertions(+)

diff --git a/Documentation/netlink/specs/rt-link.yaml b/Documentation/netlink/specs/rt-link.yaml
index 484e0a97b653a1..644a8bd7b93c34 100644
--- a/Documentation/netlink/specs/rt-link.yaml
+++ b/Documentation/netlink/specs/rt-link.yaml
@@ -1354,6 +1354,9 @@ attribute-sets:
       -
         name: broadcast-neigh
         type: u8
+      -
+        name: lacp-strict
+        type: u8
   -
     name: bond-ad-info-attrs
     name-prefix: ifla-bond-ad-info-
diff --git a/Documentation/networking/bonding.rst b/Documentation/networking/bonding.rst
index e700bf1d095c35..33ca5afafdf6dd 100644
--- a/Documentation/networking/bonding.rst
+++ b/Documentation/networking/bonding.rst
@@ -619,6 +619,29 @@ min_links
 	aggregator cannot be active without at least one available link,
 	setting this option to 0 or to 1 has the exact same effect.
 
+lacp_strict
+
+	Specifies the fallback behavior of a bonding when LACP negotiation
+	fails on all slave links, i.e. when no slave is in the
+	Collecting_Distributing state, while at least `min_links` link still
+	reports carrier up.
+
+	This option is only applicable to 802.3ad mode (mode 4).
+
+	Valid values are:
+
+	off or 0
+		One interface of the bond is selected to be active, in order to
+		facilitate communication with peer devices that do not implement
+		LACP.
+
+	on or 1
+		Interfaces are only permitted to be made active if they have an
+		active LACP partner and have successfully reached
+		Collecting_Distributing state.
+
+	The default value is 0 (off).
+
 mode
 
 	Specifies one of the bonding policies. The default is
diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c
index 8e75453ce0efd1..cd9b0a6d652174 100644
--- a/drivers/net/bonding/bond_main.c
+++ b/drivers/net/bonding/bond_main.c
@@ -6446,6 +6446,7 @@ static int __init bond_check_params(struct bond_params *params)
 	params->ad_user_port_key = ad_user_port_key;
 	params->coupled_control = 1;
 	params->broadcast_neighbor = 0;
+	params->lacp_strict = 0;
 	if (packets_per_slave > 0) {
 		params->reciprocal_packets_per_slave =
 			reciprocal_value(packets_per_slave);
diff --git a/drivers/net/bonding/bond_netlink.c b/drivers/net/bonding/bond_netlink.c
index 90365d3f7ebff7..4a11572f663d31 100644
--- a/drivers/net/bonding/bond_netlink.c
+++ b/drivers/net/bonding/bond_netlink.c
@@ -143,6 +143,7 @@ static const struct nla_policy bond_policy[IFLA_BOND_MAX + 1] = {
 	[IFLA_BOND_NS_IP6_TARGET]	= { .type = NLA_NESTED },
 	[IFLA_BOND_COUPLED_CONTROL]	= { .type = NLA_U8 },
 	[IFLA_BOND_BROADCAST_NEIGH]	= { .type = NLA_U8 },
+	[IFLA_BOND_LACP_STRICT]		= { .type = NLA_U8 },
 };
 
 static const struct nla_policy bond_slave_policy[IFLA_BOND_SLAVE_MAX + 1] = {
@@ -599,6 +600,16 @@ static int bond_changelink(struct net_device *bond_dev, struct nlattr *tb[],
 			return err;
 	}
 
+	if (data[IFLA_BOND_LACP_STRICT]) {
+		int fallback_mode = nla_get_u8(data[IFLA_BOND_LACP_STRICT]);
+
+		bond_opt_initval(&newval, fallback_mode);
+		err = __bond_opt_set(bond, BOND_OPT_LACP_STRICT, &newval,
+				     data[IFLA_BOND_LACP_STRICT], extack);
+		if (err)
+			return err;
+	}
+
 	return 0;
 }
 
@@ -671,6 +682,7 @@ static size_t bond_get_size(const struct net_device *bond_dev)
 		nla_total_size(sizeof(struct in6_addr)) * BOND_MAX_NS_TARGETS +
 		nla_total_size(sizeof(u8)) +	/* IFLA_BOND_COUPLED_CONTROL */
 		nla_total_size(sizeof(u8)) +	/* IFLA_BOND_BROADCAST_NEIGH */
+		nla_total_size(sizeof(u8)) +	/* IFLA_BOND_LACP_STRICT */
 		0;
 }
 
@@ -838,6 +850,10 @@ static int bond_fill_info(struct sk_buff *skb,
 		       bond->params.broadcast_neighbor))
 		goto nla_put_failure;
 
+	if (nla_put_u8(skb, IFLA_BOND_LACP_STRICT,
+		       bond->params.lacp_strict))
+		goto nla_put_failure;
+
 	if (BOND_MODE(bond) == BOND_MODE_8023AD) {
 		struct ad_info info;
 
diff --git a/drivers/net/bonding/bond_options.c b/drivers/net/bonding/bond_options.c
index 7380cc4ee75a90..d358b831df7730 100644
--- a/drivers/net/bonding/bond_options.c
+++ b/drivers/net/bonding/bond_options.c
@@ -68,6 +68,8 @@ static int bond_option_lacp_active_set(struct bonding *bond,
 				       const struct bond_opt_value *newval);
 static int bond_option_lacp_rate_set(struct bonding *bond,
 				     const struct bond_opt_value *newval);
+static int bond_option_lacp_strict_set(struct bonding *bond,
+				       const struct bond_opt_value *newval);
 static int bond_option_ad_select_set(struct bonding *bond,
 				     const struct bond_opt_value *newval);
 static int bond_option_queue_id_set(struct bonding *bond,
@@ -162,6 +164,12 @@ static const struct bond_opt_value bond_lacp_rate_tbl[] = {
 	{ NULL,   -1,           0},
 };
 
+static const struct bond_opt_value bond_lacp_strict_tbl[] = {
+	{ "off", 0, BOND_VALFLAG_DEFAULT},
+	{ "on",  1, 0},
+	{ NULL, -1, 0 }
+};
+
 static const struct bond_opt_value bond_ad_select_tbl[] = {
 	{ "stable",          BOND_AD_STABLE,    BOND_VALFLAG_DEFAULT},
 	{ "bandwidth",       BOND_AD_BANDWIDTH, 0},
@@ -363,6 +371,14 @@ static const struct bond_option bond_opts[BOND_OPT_LAST] = {
 		.values = bond_lacp_rate_tbl,
 		.set = bond_option_lacp_rate_set
 	},
+	[BOND_OPT_LACP_STRICT] = {
+		.id = BOND_OPT_LACP_STRICT,
+		.name = "lacp_strict",
+		.desc = "Define the LACP fallback mode when no slaves have negotiated",
+		.unsuppmodes = BOND_MODE_ALL_EX(BIT(BOND_MODE_8023AD)),
+		.values = bond_lacp_strict_tbl,
+		.set = bond_option_lacp_strict_set
+	},
 	[BOND_OPT_MINLINKS] = {
 		.id = BOND_OPT_MINLINKS,
 		.name = "min_links",
@@ -1684,6 +1700,16 @@ static int bond_option_lacp_rate_set(struct bonding *bond,
 	return 0;
 }
 
+static int bond_option_lacp_strict_set(struct bonding *bond,
+				       const struct bond_opt_value *newval)
+{
+	netdev_dbg(bond->dev, "Setting LACP fallback to %s (%llu)\n",
+		   newval->string, newval->value);
+	bond->params.lacp_strict = newval->value;
+
+	return 0;
+}
+
 static int bond_option_ad_select_set(struct bonding *bond,
 				     const struct bond_opt_value *newval)
 {
diff --git a/include/net/bond_options.h b/include/net/bond_options.h
index e6eedf23aea1a3..52b966e927938a 100644
--- a/include/net/bond_options.h
+++ b/include/net/bond_options.h
@@ -79,6 +79,7 @@ enum {
 	BOND_OPT_COUPLED_CONTROL,
 	BOND_OPT_BROADCAST_NEIGH,
 	BOND_OPT_ACTOR_PORT_PRIO,
+	BOND_OPT_LACP_STRICT,
 	BOND_OPT_LAST
 };
 
diff --git a/include/net/bonding.h b/include/net/bonding.h
index edd1942dcd736d..2c54a36a8477b9 100644
--- a/include/net/bonding.h
+++ b/include/net/bonding.h
@@ -129,6 +129,7 @@ struct bond_params {
 	int peer_notif_delay;
 	int lacp_active;
 	int lacp_fast;
+	int lacp_strict;
 	unsigned int min_links;
 	int ad_select;
 	char primary[IFNAMSIZ];
diff --git a/include/uapi/linux/if_link.h b/include/uapi/linux/if_link.h
index 79ce4bc24cba6b..9ef5784e78e830 100644
--- a/include/uapi/linux/if_link.h
+++ b/include/uapi/linux/if_link.h
@@ -1584,6 +1584,7 @@ enum {
 	IFLA_BOND_NS_IP6_TARGET,
 	IFLA_BOND_COUPLED_CONTROL,
 	IFLA_BOND_BROADCAST_NEIGH,
+	IFLA_BOND_LACP_STRICT,
 	__IFLA_BOND_MAX,
 };
 
diff --git a/tools/include/uapi/linux/if_link.h b/tools/include/uapi/linux/if_link.h
index 97a2d4411534ae..757ce5e9426e92 100644
--- a/tools/include/uapi/linux/if_link.h
+++ b/tools/include/uapi/linux/if_link.h
@@ -1527,6 +1527,7 @@ enum {
 	IFLA_BOND_NS_IP6_TARGET,
 	IFLA_BOND_COUPLED_CONTROL,
 	IFLA_BOND_BROADCAST_NEIGH,
+	IFLA_BOND_LACP_STRICT,
 	__IFLA_BOND_MAX,
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0650/2077] bonding: 3ad: fix carrier when no usable slaves
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (648 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0649/2077] bonding: 3ad: add lacp_strict configuration knob Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0651/2077] bonding: 3ad: fix mux port state on oper down Greg Kroah-Hartman
                   ` (347 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Louis Scalbert, Jay Vosburgh,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Louis Scalbert <louis.scalbert@6wind.com>

[ Upstream commit 0bd695db23c6262e9cb980017a6273925172ec5b ]

Apply the "lacp_strict" configuration from the previous commit.

"lacp_strict" mode "on" asserts that the bonding master carrier is up
only when at least 'min_links' slaves are in the Collecting_Distributing
state.

Fixes: 655f8919d549 ("bonding: add min links parameter to 802.3ad")
Signed-off-by: Louis Scalbert <louis.scalbert@6wind.com>
Acked-by: Jay Vosburgh <jv@jvosburgh.net>
Link: https://patch.msgid.link/20260603150331.1919611-5-louis.scalbert@6wind.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/bonding/bond_3ad.c     | 26 +++++++++++++++++++++++---
 drivers/net/bonding/bond_options.c |  1 +
 2 files changed, 24 insertions(+), 3 deletions(-)

diff --git a/drivers/net/bonding/bond_3ad.c b/drivers/net/bonding/bond_3ad.c
index 985ef66dc3331e..51d86e3d34db87 100644
--- a/drivers/net/bonding/bond_3ad.c
+++ b/drivers/net/bonding/bond_3ad.c
@@ -745,6 +745,21 @@ static void __set_agg_ports_ready(struct aggregator *aggregator, int val)
 	}
 }
 
+static int __agg_usable_ports(struct aggregator *agg)
+{
+	struct port *port;
+	int valid = 0;
+
+	for (port = agg->lag_ports; port;
+	     port = port->next_port_in_aggregator) {
+		if (port->actor_oper_port_state & LACP_STATE_COLLECTING &&
+		    port->actor_oper_port_state & LACP_STATE_DISTRIBUTING)
+			valid++;
+	}
+
+	return valid;
+}
+
 static int __agg_active_ports(struct aggregator *agg)
 {
 	struct port *port;
@@ -1179,10 +1194,10 @@ static void ad_mux_machine(struct port *port, bool *update_slave_arr)
 		switch (port->sm_mux_state) {
 		case AD_MUX_DETACHED:
 			port->actor_oper_port_state &= ~LACP_STATE_SYNCHRONIZATION;
-			ad_disable_collecting_distributing(port,
-							   update_slave_arr);
 			port->actor_oper_port_state &= ~LACP_STATE_COLLECTING;
 			port->actor_oper_port_state &= ~LACP_STATE_DISTRIBUTING;
+			ad_disable_collecting_distributing(port,
+							   update_slave_arr);
 			port->ntt = true;
 			break;
 		case AD_MUX_WAITING:
@@ -2107,6 +2122,7 @@ static void ad_disable_distributing(struct port *port, bool *update_slave_arr)
 			  port->actor_port_number,
 			  aggregator->aggregator_identifier);
 		__disable_distributing_port(port);
+		bond_3ad_set_carrier(port->slave->bond);
 		/* Slave array needs an update */
 		*update_slave_arr = true;
 	}
@@ -2130,6 +2146,7 @@ static void ad_enable_collecting_distributing(struct port *port,
 			  port->actor_port_number,
 			  aggregator->aggregator_identifier);
 		__enable_port(port);
+		bond_3ad_set_carrier(port->slave->bond);
 		/* Slave array needs update */
 		*update_slave_arr = true;
 		/* Should notify peers if possible */
@@ -2153,6 +2170,7 @@ static void ad_disable_collecting_distributing(struct port *port,
 			  port->actor_port_number,
 			  aggregator->aggregator_identifier);
 		__disable_port(port);
+		bond_3ad_set_carrier(port->slave->bond);
 		/* Slave array needs an update */
 		*update_slave_arr = true;
 	}
@@ -2832,7 +2850,9 @@ int bond_3ad_set_carrier(struct bonding *bond)
 	active = __get_active_agg(&(SLAVE_AD_INFO(first_slave)->aggregator));
 	if (active) {
 		/* are enough slaves available to consider link up? */
-		if (__agg_active_ports(active) < bond->params.min_links) {
+		if ((bond->params.lacp_strict ? __agg_usable_ports(active)
+					: __agg_active_ports(active)) <
+		    bond->params.min_links) {
 			if (netif_carrier_ok(bond->dev)) {
 				netif_carrier_off(bond->dev);
 				goto out;
diff --git a/drivers/net/bonding/bond_options.c b/drivers/net/bonding/bond_options.c
index d358b831df7730..94b7b0851f16ae 100644
--- a/drivers/net/bonding/bond_options.c
+++ b/drivers/net/bonding/bond_options.c
@@ -1706,6 +1706,7 @@ static int bond_option_lacp_strict_set(struct bonding *bond,
 	netdev_dbg(bond->dev, "Setting LACP fallback to %s (%llu)\n",
 		   newval->string, newval->value);
 	bond->params.lacp_strict = newval->value;
+	bond_3ad_set_carrier(bond);
 
 	return 0;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0651/2077] bonding: 3ad: fix mux port state on oper down
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (649 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0650/2077] bonding: 3ad: fix carrier when no usable slaves Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0652/2077] ext4: fix kernel BUG in ext4_write_inline_data_end Greg Kroah-Hartman
                   ` (346 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Louis Scalbert, Jay Vosburgh,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Louis Scalbert <louis.scalbert@6wind.com>

[ Upstream commit 807afc7544b865d4d09068a415fd5b71bf5665cc ]

When the bonding interface has carrier down due to the absence of
usable slaves and a slave transitions from down to up, the bonding
interface briefly goes carrier up, then down again, and finally up
once LACP negotiates collecting and distributing on the port.

When lacp_strict mode is on, the interface should not transition to
carrier up until LACP negotiation is complete.

This happens because the actor and partner port states remain in
Collecting_Distributing when the port goes down. When the port
comes back up, it temporarily remains in this state until LACP
renegotiation occurs.

Previously this was mostly cosmetic, but since the bonding carrier
state may depend on the LACP negotiation state, it causes the
interface to flap.

According to IEEE 802.3ad-2000 and IEEE 802.1ax-2014, Collecting and
Distributing should be reset when a port goes down:
- In the Receive state machine, port_enabled == FALSE causes a
  transition to the PORT_DISABLED state, which is expected to clear
  Partner_Oper_Port_State.Synchronization.
- In the Mux state machine, Partner_Oper_Port_State.Synchronization ==
  FALSE causes a transition to the ATTACHED state, which disables
  Collecting and Distributing.

However, Partner_Oper_Port_State.Synchronization is not cleared in the
PORT_DISABLED state.

Clear Partner_Oper_Port_State.Synchronization in the Receive
PORT_DISABLED state.

Fixes: 655f8919d549 ("bonding: add min links parameter to 802.3ad")
Signed-off-by: Louis Scalbert <louis.scalbert@6wind.com>
Acked-by: Jay Vosburgh <jv@jvosburgh.net>
Link: https://patch.msgid.link/20260603150331.1919611-6-louis.scalbert@6wind.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/bonding/bond_3ad.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/net/bonding/bond_3ad.c b/drivers/net/bonding/bond_3ad.c
index 51d86e3d34db87..acbba08dbdfada 100644
--- a/drivers/net/bonding/bond_3ad.c
+++ b/drivers/net/bonding/bond_3ad.c
@@ -1337,6 +1337,7 @@ static void ad_rx_machine(struct lacpdu *lacpdu, struct port *port)
 			fallthrough;
 		case AD_RX_PORT_DISABLED:
 			port->sm_vars &= ~AD_PORT_MATCHED;
+			port->partner_oper.port_state &= ~LACP_STATE_SYNCHRONIZATION;
 			break;
 		case AD_RX_LACP_DISABLED:
 			port->sm_vars &= ~AD_PORT_SELECTED;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0652/2077] ext4: fix kernel BUG in ext4_write_inline_data_end
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (650 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0651/2077] bonding: 3ad: fix mux port state on oper down Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0653/2077] ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT Greg Kroah-Hartman
                   ` (345 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+0c89d865531d053abb2d,
	Aditya Prakash Srivastava, Jan Kara, Theodore Tso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aditya Prakash Srivastava <aditya.ansh182@gmail.com>

[ Upstream commit ad09aa45965d3fafaf9963bc78109b73c0f9ac8d ]

When the data=journal mount option is used, the ext4_journalled_write_end()
function incorrectly calls ext4_write_inline_data_end() without checking
if the EXT4_STATE_MAY_INLINE_DATA flag is still set on the inode.

If a previous attempt to convert the inline data to an extent failed (e.g.
due to ENOSPC), the EXT4_STATE_MAY_INLINE_DATA flag is cleared, but
the EXT4_INODE_INLINE_DATA flag remains set. In this scenario, the next
call to ext4_write_begin() will not prepare the inline data xattr for
writing, but ext4_journalled_write_end() will incorrectly attempt to write
to it, triggering a BUG_ON(pos + len > EXT4_I(inode)->i_inline_size) in
ext4_write_inline_data() since i_inline_size was not expanded.

Fix this by ensuring that ext4_journalled_write_end() only calls
ext4_write_inline_data_end() if the EXT4_STATE_MAY_INLINE_DATA flag is
set, mirroring the behavior of ext4_write_end() and ext4_da_write_end().

Reported-by: syzbot+0c89d865531d053abb2d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0c89d865531d053abb2d
Fixes: 3fdcfb668fd7 ("ext4: add journalled write support for inline data")
Signed-off-by: Aditya Prakash Srivastava <aditya.ansh182@gmail.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20260608065227.3018-1-aditya.ansh182@gmail.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ext4/inode.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c
index c2c2d6ac7f3d13..4fce9ec176f88a 100644
--- a/fs/ext4/inode.c
+++ b/fs/ext4/inode.c
@@ -1560,7 +1560,8 @@ static int ext4_journalled_write_end(const struct kiocb *iocb,
 
 	BUG_ON(!ext4_handle_valid(handle));
 
-	if (ext4_has_inline_data(inode))
+	if (ext4_has_inline_data(inode) &&
+	    ext4_test_inode_state(inode, EXT4_STATE_MAY_INLINE_DATA))
 		return ext4_write_inline_data_end(inode, pos, len, copied,
 						  folio);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0653/2077] ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (651 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0652/2077] ext4: fix kernel BUG in ext4_write_inline_data_end Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0654/2077] selftests/bpf: Fix bpf_iter/task_vma test Greg Kroah-Hartman
                   ` (344 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+ad6118a7584b607c67f2,
	Yun Zhou, Jan Kara, Andreas Dilger, Theodore Tso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yun Zhou <yun.zhou@windriver.com>

[ Upstream commit c143957520c6c9b5cd72e0de8b52b814f0c576fe ]

Reject the EXT4_IOC_MOVE_EXT ioctl early if the donor file does not
belong to the same superblock as the original file.  Currently, this
validation is performed inside ext4_move_extents() by
mext_check_validity(), but only after lock_two_nondirectories() has
already acquired the inode locks.  When the donor fd refers to a file
on a different filesystem (e.g., overlayfs), this late validation
creates a circular lock dependency:

  CPU0 (overlayfs write)            CPU1 (ext4 ioctl)
  ----                              ----
  inode_lock(ovl_inode)
                                    mnt_want_write_file(filp)
                                      sb_start_write(ext4_sb)   [sb_writers]
    backing_file_write_iter()
      vfs_iter_write(real_file)
        file_start_write(real_file)
          sb_start_write(ext4_sb)   [blocked by freeze]
                                    lock_two_nondirectories()
                                      inode_lock(ovl_inode)     [blocked]

With a concurrent freeze operation holding sb_writers write side, this
forms a deadlock cycle: CPU0 waits for freeze to complete, freeze waits
for CPU1's sb_writers reader to exit, CPU1 waits for CPU0's inode lock.

Since EXT4_IOC_MOVE_EXT exchanges physical extents between two files,
it fundamentally requires both files to reside on the same ext4
filesystem.  Moving the superblock check before any lock acquisition
is both semantically correct and eliminates the circular dependency
by ensuring that cross-filesystem donor fds are rejected before
sb_writers or inode locks are taken.

Fixes: fcf6b1b729bc ("ext4: refactor ext4_move_extents code base")
Reported-by: syzbot+ad6118a7584b607c67f2@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=ad6118a7584b607c67f2
Signed-off-by: Yun Zhou <yun.zhou@windriver.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Reviewed-by: Andreas Dilger <adilger@dilger.ca>
Link: https://patch.msgid.link/20260608152521.1292656-1-yun.zhou@windriver.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ext4/ioctl.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/fs/ext4/ioctl.c b/fs/ext4/ioctl.c
index 110e3fb194ec6b..c8387e6a2c6e90 100644
--- a/fs/ext4/ioctl.c
+++ b/fs/ext4/ioctl.c
@@ -1656,6 +1656,9 @@ static long __ext4_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
 		if (!(fd_file(donor)->f_mode & FMODE_WRITE))
 			return -EBADF;
 
+		if (file_inode(filp)->i_sb != file_inode(fd_file(donor))->i_sb)
+			return -EXDEV;
+
 		err = mnt_want_write_file(filp);
 		if (err)
 			return err;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0654/2077] selftests/bpf: Fix bpf_iter/task_vma test
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (652 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0653/2077] ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0655/2077] cxl/test: Verify cmd->size_in before accessing payload Greg Kroah-Hartman
                   ` (343 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yonghong Song, Leon Hwang,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yonghong Song <yonghong.song@linux.dev>

[ Upstream commit 2e8ad1ff712d2a397e407c9fde60901f68d077dc ]

For selftest bpf_iter/task_vma, I got a failure like below on my qemu run:

test_task_vma_common:FAIL:compare_output unexpected compare_output:
    actual
    '561593546000-561593585000r--p0000000000:241256579534/root/devshare/bpf-next/tools/testing/selftests/bpf/test_progs'
    != expected
    '561593546000-561593585000r--p0000000000:245551546830/root/devshare/bpf-next/tools/testing/selftests/bpf/test_progs'

Further debugging found out file->f_inode->i_ino value may exceed 32bit,
e.g., i_ino = 0x14c2eae35, but the format string is '%u'. This caused
inode mismatch between bpf iter and proc result.

Fix the issue by using format string '%llu' to accommodate 64bit i_ino.

Fixes: e8168840e16c ("selftests/bpf: Add test for bpf_iter_task_vma")
Signed-off-by: Yonghong Song <yonghong.song@linux.dev>
Acked-by: Leon Hwang <leon.hwang@linux.dev>
Link: https://lore.kernel.org/r/20260610051831.1346659-1-yonghong.song@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/bpf/progs/bpf_iter_task_vmas.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/selftests/bpf/progs/bpf_iter_task_vmas.c b/tools/testing/selftests/bpf/progs/bpf_iter_task_vmas.c
index d64ba7ddaed54e..d7fb561ed4fb90 100644
--- a/tools/testing/selftests/bpf/progs/bpf_iter_task_vmas.c
+++ b/tools/testing/selftests/bpf/progs/bpf_iter_task_vmas.c
@@ -52,7 +52,7 @@ SEC("iter/task_vma") int proc_maps(struct bpf_iter__task_vma *ctx)
 		bpf_d_path(&file->f_path, d_path_buf, D_PATH_BUF_SIZE);
 
 		BPF_SEQ_PRINTF(seq, "%08llx ", vma->vm_pgoff << 12);
-		BPF_SEQ_PRINTF(seq, "%02x:%02x %u", MAJOR(dev), MINOR(dev),
+		BPF_SEQ_PRINTF(seq, "%02x:%02x %llu", MAJOR(dev), MINOR(dev),
 			       file->f_inode->i_ino);
 		BPF_SEQ_PRINTF(seq, "\t%s\n", d_path_buf);
 	} else {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0655/2077] cxl/test: Verify cmd->size_in before accessing payload
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (653 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0654/2077] selftests/bpf: Fix bpf_iter/task_vma test Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0656/2077] cxl/test: Fix integer overflow in mock LSA bounds checks Greg Kroah-Hartman
                   ` (342 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alison Schofield, Dave Jiang,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Jiang <dave.jiang@intel.com>

[ Upstream commit 71a1def165267bc0947d4236f7336f490739c379 ]

Several mock mailbox handlers access input payload fields before
verifying that cmd->size_in is large enough for the corresponding
structure.

To ensure invalid commands are rejected before any payload data is
consumed, add missing size checks and move existing checks ahead of
the first payload field access.

[dj: Updated commit log per Alison's comments. ]

Fixes: 7d3eb23c4ccf ("tools/testing/cxl: Introduce a mock memory device + driver")
Fixes: d1dca858f058 ("cxl/test: Add generic mock events")
Fixes: f6448cb5f2f3 ("tools/testing/cxl: add firmware update emulation to CXL memdevs")
Fixes: e77e9c107978 ("cxl/test: Add Get Feature support to cxl_test")
Link: https://lore.kernel.org/linux-cxl/20260605143748.235271F00893@smtp.kernel.org/
Suggested-by: sashiko-bot
Tested-by: Alison Schofield <alison.schofield@intel.com>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/cxl/test/mem.c | 39 +++++++++++++++++++++++++++---------
 1 file changed, 30 insertions(+), 9 deletions(-)

diff --git a/tools/testing/cxl/test/mem.c b/tools/testing/cxl/test/mem.c
index 271c7ad8cc32c9..2e9a5f151e983d 100644
--- a/tools/testing/cxl/test/mem.c
+++ b/tools/testing/cxl/test/mem.c
@@ -312,12 +312,17 @@ static int mock_get_event(struct device *dev, struct cxl_mbox_cmd *cmd)
 
 static int mock_clear_event(struct device *dev, struct cxl_mbox_cmd *cmd)
 {
-	struct cxl_mbox_clear_event_payload *pl = cmd->payload_in;
+	struct cxl_mbox_clear_event_payload *pl;
 	struct mock_event_log *log;
-	u8 log_type = pl->event_log;
+	u8 log_type;
 	u16 handle;
 	int nr;
 
+	if (cmd->size_in < sizeof(*pl))
+		return -EINVAL;
+
+	pl = cmd->payload_in;
+	log_type = pl->event_log;
 	if (log_type >= CXL_EVENT_TYPE_MAX)
 		return -EINVAL;
 
@@ -574,14 +579,19 @@ static int mock_gsl(struct cxl_mbox_cmd *cmd)
 static int mock_get_log(struct cxl_memdev_state *mds, struct cxl_mbox_cmd *cmd)
 {
 	struct cxl_mailbox *cxl_mbox = &mds->cxlds.cxl_mbox;
-	struct cxl_mbox_get_log *gl = cmd->payload_in;
-	u32 offset = le32_to_cpu(gl->offset);
-	u32 length = le32_to_cpu(gl->length);
 	uuid_t uuid = DEFINE_CXL_CEL_UUID;
+	struct cxl_mbox_get_log *gl;
 	void *data = &mock_cel;
+	u32 offset;
+	u32 length;
 
 	if (cmd->size_in < sizeof(*gl))
 		return -EINVAL;
+
+	gl = cmd->payload_in;
+	offset = le32_to_cpu(gl->offset);
+	length = le32_to_cpu(gl->length);
+
 	if (length > cxl_mbox->payload_size)
 		return -EINVAL;
 	if (offset + length > sizeof(mock_cel))
@@ -1336,10 +1346,14 @@ static int mock_fw_info(struct cxl_mockmem_data *mdata,
 static int mock_transfer_fw(struct cxl_mockmem_data *mdata,
 			    struct cxl_mbox_cmd *cmd)
 {
-	struct cxl_mbox_transfer_fw *transfer = cmd->payload_in;
+	struct cxl_mbox_transfer_fw *transfer;
 	void *fw = mdata->fw;
 	size_t offset, length;
 
+	if (cmd->size_in < sizeof(*transfer))
+		return -EINVAL;
+
+	transfer = cmd->payload_in;
 	offset = le32_to_cpu(transfer->offset) * CXL_FW_TRANSFER_ALIGNMENT;
 	length = cmd->size_in - sizeof(*transfer);
 	if (offset + length > FW_SIZE)
@@ -1415,11 +1429,18 @@ static int mock_get_test_feature(struct cxl_mockmem_data *mdata,
 				 struct cxl_mbox_cmd *cmd)
 {
 	struct vendor_test_feat *output = cmd->payload_out;
-	struct cxl_mbox_get_feat_in *input = cmd->payload_in;
-	u16 offset = le16_to_cpu(input->offset);
-	u16 count = le16_to_cpu(input->count);
+	struct cxl_mbox_get_feat_in *input;
+	u16 offset;
+	u16 count;
 	u8 *ptr;
 
+	if (cmd->size_in < sizeof(*input))
+		return -EINVAL;
+
+	input = cmd->payload_in;
+	offset = le16_to_cpu(input->offset);
+	count = le16_to_cpu(input->count);
+
 	if (offset > sizeof(*output)) {
 		cmd->return_code = CXL_MBOX_CMD_RC_INPUT;
 		return -EINVAL;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0656/2077] cxl/test: Fix integer overflow in mock LSA bounds checks
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (654 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0655/2077] cxl/test: Verify cmd->size_in before accessing payload Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0657/2077] cxl/test: Zero out LSA backing memory to avoid leaking to user Greg Kroah-Hartman
                   ` (341 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alison Schofield, Dave Jiang,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Jiang <dave.jiang@intel.com>

[ Upstream commit 81eafcada109b653977c4dfbd2b6a72470025a01 ]

Pre-existing issue discovered by sashiko-bot.

mock_get_lsa() and mock_set_lsa() validate the requested LSA range with
"offset + length > LSA_SIZE". Both offset and length are u32 and, in
mock_get_lsa(), both are taken directly from the user-supplied payload.
The addition is evaluated modulo 2^32, so a large offset combined with a
small length wraps around and passes the check.

Rewrite the checks to first bound offset, then compare length against the
remaining LSA size.

Suggested-by: sashiko-bot
Fixes: 7d3eb23c4ccf ("tools/testing/cxl: Introduce a mock memory device + driver")
Link: https://lore.kernel.org/linux-cxl/20260605143748.235271F00893@smtp.kernel.org/
Assisted-by: Claude:claude-opus-4-8
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/cxl/test/mem.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/tools/testing/cxl/test/mem.c b/tools/testing/cxl/test/mem.c
index 2e9a5f151e983d..9a7cd3f46a1ee5 100644
--- a/tools/testing/cxl/test/mem.c
+++ b/tools/testing/cxl/test/mem.c
@@ -1063,7 +1063,7 @@ static int mock_get_lsa(struct cxl_mockmem_data *mdata,
 		return -EINVAL;
 	offset = le32_to_cpu(get_lsa->offset);
 	length = le32_to_cpu(get_lsa->length);
-	if (offset + length > LSA_SIZE)
+	if (offset > LSA_SIZE || length > LSA_SIZE - offset)
 		return -EINVAL;
 	if (length > cmd->size_out)
 		return -EINVAL;
@@ -1083,7 +1083,7 @@ static int mock_set_lsa(struct cxl_mockmem_data *mdata,
 		return -EINVAL;
 	offset = le32_to_cpu(set_lsa->offset);
 	length = cmd->size_in - sizeof(*set_lsa);
-	if (offset + length > LSA_SIZE)
+	if (offset > LSA_SIZE || length > LSA_SIZE - offset)
 		return -EINVAL;
 
 	memcpy(lsa + offset, &set_lsa->data[0], length);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0657/2077] cxl/test: Zero out LSA backing memory to avoid leaking to user
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (655 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0656/2077] cxl/test: Fix integer overflow in mock LSA bounds checks Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0658/2077] of: cpu: add check in __of_find_n_match_cpu_property() Greg Kroah-Hartman
                   ` (340 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alison Schofield, Dave Jiang,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Jiang <dave.jiang@intel.com>

[ Upstream commit 60f065dbaf46e65830da62a0041761f0c039e086 ]

Memory through vmalloc() is not zeroed out. When this memory is copied
into output payload, it leaks memory content to user. Use vzalloc()
instead to zero out the memory.

Suggested-by: sashiko-bot
Link: https://lore.kernel.org/linux-cxl/20260605173146.2B9A31F00893@smtp.kernel.org/
Fixes: 7d3eb23c4ccf ("tools/testing/cxl: Introduce a mock memory device + driver")
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260605184426.4070913-1-dave.jiang@intel.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/cxl/test/mem.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/cxl/test/mem.c b/tools/testing/cxl/test/mem.c
index 9a7cd3f46a1ee5..739343cd58022a 100644
--- a/tools/testing/cxl/test/mem.c
+++ b/tools/testing/cxl/test/mem.c
@@ -1724,7 +1724,7 @@ static int cxl_mock_mem_probe(struct platform_device *pdev)
 		return -ENOMEM;
 	dev_set_drvdata(dev, mdata);
 
-	mdata->lsa = vmalloc(LSA_SIZE);
+	mdata->lsa = vzalloc(LSA_SIZE);
 	if (!mdata->lsa)
 		return -ENOMEM;
 	mdata->fw = vmalloc(FW_SIZE);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0658/2077] of: cpu: add check in __of_find_n_match_cpu_property()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (656 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0657/2077] cxl/test: Zero out LSA backing memory to avoid leaking to user Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0659/2077] vfio/qat: fix f_pos race in qat_vf_resume_write() Greg Kroah-Hartman
                   ` (339 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sergey Shtylyov, Rob Herring (Arm),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sergey Shtylyov <s.shtylyov@auroraos.dev>

[ Upstream commit 5901eda2ed99ba0d3661da6eb265970559323bb3 ]

In __of_find_n_match_cpu_property(), checking the variable ac for 0 won't
prevent a possible overflow when multiplying it by sizeof(*cell). Besides,
of_read_number() (called in the *for* loop) can't return correct result if
that variable (which equals the #address-cells prop's value) exceeds 2, so
additionally checking for that seems logical...

Found by Linux Verification Center (linuxtesting.org) with the Svace static
analysis tool.

Fixes: f3cea45a77c8 ("of: Fix iteration bug over CPU reg properties")
Signed-off-by: Sergey Shtylyov <s.shtylyov@auroraos.dev>
Link: https://patch.msgid.link/0c7bf7e9-887c-42d5-bcfb-0ba7fe1e70b6@auroraos.dev
Signed-off-by: Rob Herring (Arm) <robh@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/of/cpu.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/of/cpu.c b/drivers/of/cpu.c
index 5214dc3d05ae17..bd0e918d6f290e 100644
--- a/drivers/of/cpu.c
+++ b/drivers/of/cpu.c
@@ -60,7 +60,7 @@ static bool __of_find_n_match_cpu_property(struct device_node *cpun,
 	cell = of_get_property(cpun, prop_name, &prop_len);
 	if (!cell && !ac && arch_match_cpu_phys_id(cpu, 0))
 		return true;
-	if (!cell || !ac)
+	if (!cell || !ac || ac > 2)
 		return false;
 	prop_len /= sizeof(*cell) * ac;
 	for (tid = 0; tid < prop_len; tid++) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0659/2077] vfio/qat: fix f_pos race in qat_vf_resume_write()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (657 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0658/2077] of: cpu: add check in __of_find_n_match_cpu_property() Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0660/2077] bpf: Tighten cgroup storage cookie checks for prog arrays Greg Kroah-Hartman
                   ` (338 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ahsan Atta, Giovanni Cabiddu,
	Alex Williamson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Giovanni Cabiddu <giovanni.cabiddu@intel.com>

[ Upstream commit 4ec5e932e636896e97e4c6a8205b0ac76d52421a ]

qat_vf_resume_write() checks filp->f_pos before taking migf->lock, but
copies into the migration-state buffer after taking the lock and
re-reading the shared file position.

Two concurrent writers could therefore pass the bounds check with the
old offset, then have the second writer copy after the first advanced
f_pos, writing past the end of the migration-state buffer.

Take migf->lock before doing the boundary checks.

Fixes: bb208810b1ab ("vfio/qat: Add vfio_pci driver for Intel QAT SR-IOV VF devices")
Reviewed-by: Ahsan Atta <ahsan.atta@intel.com>
Signed-off-by: Giovanni Cabiddu <giovanni.cabiddu@intel.com>
Link: https://lore.kernel.org/r/20260608151317.136613-1-giovanni.cabiddu@intel.com
Signed-off-by: Alex Williamson <alex@shazbot.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/vfio/pci/qat/main.c | 16 ++++++++++------
 1 file changed, 10 insertions(+), 6 deletions(-)

diff --git a/drivers/vfio/pci/qat/main.c b/drivers/vfio/pci/qat/main.c
index ac9652539d66a1..60ff907b6a67ac 100644
--- a/drivers/vfio/pci/qat/main.c
+++ b/drivers/vfio/pci/qat/main.c
@@ -298,14 +298,18 @@ static ssize_t qat_vf_resume_write(struct file *filp, const char __user *buf,
 		return -ESPIPE;
 	offs = &filp->f_pos;
 
-	if (*offs < 0 ||
-	    check_add_overflow(len, *offs, &end))
-		return -EOVERFLOW;
+	mutex_lock(&migf->lock);
 
-	if (end > mig_dev->state_size)
-		return -ENOMEM;
+	if (*offs < 0 || check_add_overflow(len, *offs, &end)) {
+		done = -EOVERFLOW;
+		goto out_unlock;
+	}
+
+	if (end > mig_dev->state_size) {
+		done = -ENOMEM;
+		goto out_unlock;
+	}
 
-	mutex_lock(&migf->lock);
 	if (migf->disabled) {
 		done = -ENODEV;
 		goto out_unlock;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0660/2077] bpf: Tighten cgroup storage cookie checks for prog arrays
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (658 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0659/2077] vfio/qat: fix f_pos race in qat_vf_resume_write() Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0661/2077] m68k: mcf5441x: fix clocks numbering Greg Kroah-Hartman
                   ` (337 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lin Ma, Daniel Borkmann,
	Yonghong Song, Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

[ Upstream commit 10627ddc0167aab5c1c390a10ef461e9937aba08 ]

The fix in commit abad3d0bad72 ("bpf: Fix oob access in cgroup local
storage") is still incomplete. The prog-array compatibility check
treats a program with no cgroup storage as compatible with any stored
storage cookie. This allows a storage-less program to bridge a tail
call chain between an entry program and a storage-using callee even
though cgroup local storage at runtime still follows the caller's
context, that is, A -> B(no storage) -> C(storage) path.

Requiring exact cookie equality would break the legitimate case of a
storage-less leaf program being tail called from a storage-using one.
Instead, only accept a zero storage cookie if the program cannot
perform tail calls itself. This keeps A -> B(no storage) working
while rejecting the A -> B(no storage) -> C(storage) bridge.

Fixes: abad3d0bad72 ("bpf: Fix oob access in cgroup local storage")
Reported-by: Lin Ma <malin89@huawei.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Yonghong Song <yonghong.song@linux.dev>
Link: https://lore.kernel.org/r/20260610105539.705887-1-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/bpf/core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/bpf/core.c b/kernel/bpf/core.c
index de61e1894452ef..f5d9c27e654d40 100644
--- a/kernel/bpf/core.c
+++ b/kernel/bpf/core.c
@@ -2527,7 +2527,7 @@ static bool __bpf_prog_map_compatible(struct bpf_map *map,
 			cookie = aux->cgroup_storage[i] ?
 				 aux->cgroup_storage[i]->cookie : 0;
 			ret = map->owner->storage_cookie[i] == cookie ||
-			      !cookie;
+			      (!cookie && !aux->tail_call_reachable);
 		}
 		if (ret &&
 		    map->owner->attach_func_proto != aux->attach_func_proto) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0661/2077] m68k: mcf5441x: fix clocks numbering
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (659 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0660/2077] bpf: Tighten cgroup storage cookie checks for prog arrays Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0662/2077] pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag Greg Kroah-Hartman
                   ` (336 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Angelo Dureghello, Greg Ungerer,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Angelo Dureghello <adureghello@baylibre.com>

[ Upstream commit 919afb86694f5a8a9b50bff56cd8199f065b0dbb ]

Fix clocks numbering, set correct values for eport and DAC,
as per RM Rev 5, 05/2018, table 9.5.

Fixes: bea8bcb12da09 ("m68knommu: Add support for the Coldfire m5441x.")
Fixes: 007f84ede6e3e ("m68k: coldfire: remove private clk_get/clk_put")
Signed-off-by: Angelo Dureghello <adureghello@baylibre.com>
Signed-off-by: Greg Ungerer <gerg@linux-m68k.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/m68k/coldfire/m5441x.c | 18 +++++++++---------
 1 file changed, 9 insertions(+), 9 deletions(-)

diff --git a/arch/m68k/coldfire/m5441x.c b/arch/m68k/coldfire/m5441x.c
index 7a25cfc7ac0757..ac9c17d0ee6476 100644
--- a/arch/m68k/coldfire/m5441x.c
+++ b/arch/m68k/coldfire/m5441x.c
@@ -41,9 +41,9 @@ DEFINE_CLK(0, "mcfpit.0", 32, MCF_BUSCLK);
 DEFINE_CLK(0, "mcfpit.1", 33, MCF_BUSCLK);
 DEFINE_CLK(0, "mcfpit.2", 34, MCF_BUSCLK);
 DEFINE_CLK(0, "mcfpit.3", 35, MCF_BUSCLK);
-DEFINE_CLK(0, "mcfeport.0", 37, MCF_CLK);
-DEFINE_CLK(0, "mcfadc.0", 38, MCF_CLK);
-DEFINE_CLK(0, "mcfdac.0", 39, MCF_CLK);
+DEFINE_CLK(0, "mcfeport.0", 36, MCF_CLK);
+DEFINE_CLK(0, "mcfadc.0", 37, MCF_CLK);
+DEFINE_CLK(0, "mcfdac.0", 38, MCF_CLK);
 DEFINE_CLK(0, "mcfrtc.0", 42, MCF_CLK);
 DEFINE_CLK(0, "mcfsim.0", 43, MCF_CLK);
 DEFINE_CLK(0, "mcfusb-otg.0", 44, MCF_CLK);
@@ -103,9 +103,9 @@ static struct clk_lookup m5411x_clk_lookup[] = {
 	CLKDEV_INIT("mcfpit.1", NULL, &__clk_0_33),
 	CLKDEV_INIT("mcfpit.2", NULL, &__clk_0_34),
 	CLKDEV_INIT("mcfpit.3", NULL, &__clk_0_35),
-	CLKDEV_INIT("mcfeport.0", NULL, &__clk_0_37),
-	CLKDEV_INIT("mcfadc.0", NULL, &__clk_0_38),
-	CLKDEV_INIT("mcfdac.0", NULL, &__clk_0_39),
+	CLKDEV_INIT("mcfeport.0", NULL, &__clk_0_36),
+	CLKDEV_INIT("mcfadc.0", NULL, &__clk_0_37),
+	CLKDEV_INIT("mcfdac.0", NULL, &__clk_0_38),
 	CLKDEV_INIT("mcfrtc.0", NULL, &__clk_0_42),
 	CLKDEV_INIT("mcfsim.0", NULL, &__clk_0_43),
 	CLKDEV_INIT("mcfusb-otg.0", NULL, &__clk_0_44),
@@ -156,7 +156,7 @@ static struct clk * const enable_clks[] __initconst = {
 	&__clk_0_27, /* uart3 */
 
 	&__clk_0_33, /* pit.1 */
-	&__clk_0_37, /* eport */
+	&__clk_0_36, /* eport */
 	&__clk_0_48, /* pll */
 	&__clk_0_51, /* esdhc */
 
@@ -174,8 +174,8 @@ static struct clk * const disable_clks[] __initconst = {
 	&__clk_0_32, /* pit.0 */
 	&__clk_0_34, /* pit.2 */
 	&__clk_0_35, /* pit.3 */
-	&__clk_0_38, /* adc */
-	&__clk_0_39, /* dac */
+	&__clk_0_37, /* adc */
+	&__clk_0_38, /* dac.0 */
 	&__clk_0_44, /* usb otg */
 	&__clk_0_45, /* usb host */
 	&__clk_0_47, /* ssi.0 */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0662/2077] pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (660 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0661/2077] m68k: mcf5441x: fix clocks numbering Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0663/2077] pinctrl: airoha: an7581: add missed gpio32 pin group Greg Kroah-Hartman
                   ` (335 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Andre Przywara, Jernej Skrabec,
	Chen-Yu Tsai, Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Andre Przywara <andre.przywara@arm.com>

[ Upstream commit eaf84ff673409fa3dfc390c6afb53b641ee5acba ]

The Allwinner A10 and H3 SoCs cannot read the state of a GPIO line when
that line is muxed for IRQ triggering (muxval 6), but only if it's
explicitly muxed for GPIO input (muxval 0). Other SoCs do not show this
behaviour, so we added a optional workaround, triggered by a quirk bit,
which triggers remuxing the pin when it's configured for IRQ, while we
need to read its value.

For some reasons this quirk flag was copied over to newer SoCs, even
though they don't show this behaviour, and the GPIO data register
reflects the true GPIO state even with a pin muxed to IRQ trigger.

Remove the unneeded quirk from the A523 family, where it's definitely
not needed (confirmed by experiments), and where it actually breaks,
because the workaround is not compatible with the newer generation
pinctrl IP used in that chip.

Together with a DT change this fixes GPIO IRQ operation on the A523
family of SoCs, as for instance used for the SD card detection.

Signed-off-by: Andre Przywara <andre.przywara@arm.com>
Fixes: b8a51e95b376 ("pinctrl: sunxi: Add support for the secondary A523 GPIO ports")
Reviewed-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Acked-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c | 1 -
 drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c   | 1 -
 2 files changed, 2 deletions(-)

diff --git a/drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c b/drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c
index 69cd2b4ebd7d75..462aa1c4a5fa65 100644
--- a/drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c
+++ b/drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c
@@ -26,7 +26,6 @@ static const u8 a523_r_irq_bank_muxes[SUNXI_PINCTRL_MAX_BANKS] =
 static struct sunxi_pinctrl_desc a523_r_pinctrl_data = {
 	.irq_banks = ARRAY_SIZE(a523_r_irq_bank_map),
 	.irq_bank_map = a523_r_irq_bank_map,
-	.irq_read_needs_mux = true,
 	.io_bias_cfg_variant = BIAS_VOLTAGE_PIO_POW_MODE_SEL,
 	.pin_base = PL_BASE,
 };
diff --git a/drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c b/drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c
index 7d2308c37d29e6..b6f78f1f30ac4a 100644
--- a/drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c
+++ b/drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c
@@ -26,7 +26,6 @@ static const u8 a523_irq_bank_muxes[SUNXI_PINCTRL_MAX_BANKS] =
 static struct sunxi_pinctrl_desc a523_pinctrl_data = {
 	.irq_banks = ARRAY_SIZE(a523_irq_bank_map),
 	.irq_bank_map = a523_irq_bank_map,
-	.irq_read_needs_mux = true,
 	.io_bias_cfg_variant = BIAS_VOLTAGE_PIO_POW_MODE_SEL,
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0663/2077] pinctrl: airoha: an7581: add missed gpio32 pin group
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (661 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0662/2077] pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0664/2077] pinctrl: airoha: an7583: " Greg Kroah-Hartman
                   ` (334 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikhail Kshevetskiy,
	Bartosz Golaszewski, Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>

[ Upstream commit bdc95d7e8de3eefa9fc062302625259c0b79136d ]

gpio32 pin group is missed for an7581 SoC. This patch add it.

Fixes: 1c8ace2d0725 ("pinctrl: airoha: Add support for EN7581 SoC")
Signed-off-by: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-airoha.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/pinctrl/mediatek/pinctrl-airoha.c b/drivers/pinctrl/mediatek/pinctrl-airoha.c
index 995ba6175c9504..80516622322875 100644
--- a/drivers/pinctrl/mediatek/pinctrl-airoha.c
+++ b/drivers/pinctrl/mediatek/pinctrl-airoha.c
@@ -539,6 +539,7 @@ static const int en7581_gpio28_pins[] = { 41 };
 static const int en7581_gpio29_pins[] = { 42 };
 static const int en7581_gpio30_pins[] = { 43 };
 static const int en7581_gpio31_pins[] = { 44 };
+static const int en7581_gpio32_pins[] = { 45 };
 static const int en7581_gpio33_pins[] = { 46 };
 static const int en7581_gpio34_pins[] = { 47 };
 static const int en7581_gpio35_pins[] = { 48 };
@@ -623,6 +624,7 @@ static const struct pingroup en7581_pinctrl_groups[] = {
 	PINCTRL_PIN_GROUP("gpio29", en7581_gpio29),
 	PINCTRL_PIN_GROUP("gpio30", en7581_gpio30),
 	PINCTRL_PIN_GROUP("gpio31", en7581_gpio31),
+	PINCTRL_PIN_GROUP("gpio32", en7581_gpio32),
 	PINCTRL_PIN_GROUP("gpio33", en7581_gpio33),
 	PINCTRL_PIN_GROUP("gpio34", en7581_gpio34),
 	PINCTRL_PIN_GROUP("gpio35", en7581_gpio35),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0664/2077] pinctrl: airoha: an7583: add missed gpio32 pin group
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (662 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0663/2077] pinctrl: airoha: an7581: add missed gpio32 pin group Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0665/2077] pinctrl: airoha: an7581: fix misprint in gpio19 pinconf Greg Kroah-Hartman
                   ` (333 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikhail Kshevetskiy,
	Bartosz Golaszewski, Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>

[ Upstream commit 81cc2285cea84e3ed8688d353e1250cf8899c80a ]

gpio32 pin group is missed for an7583 SoC. This patch add it.

Fixes: 3ffeb17a9a27 ("pinctrl: airoha: add support for Airoha AN7583 PINs")
Signed-off-by: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-airoha.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/pinctrl/mediatek/pinctrl-airoha.c b/drivers/pinctrl/mediatek/pinctrl-airoha.c
index 80516622322875..c0aed1b6079208 100644
--- a/drivers/pinctrl/mediatek/pinctrl-airoha.c
+++ b/drivers/pinctrl/mediatek/pinctrl-airoha.c
@@ -758,6 +758,7 @@ static const int an7583_gpio28_pins[] = { 30 };
 static const int an7583_gpio29_pins[] = { 31 };
 static const int an7583_gpio30_pins[] = { 32 };
 static const int an7583_gpio31_pins[] = { 33 };
+static const int an7583_gpio32_pins[] = { 34 };
 static const int an7583_gpio33_pins[] = { 35 };
 static const int an7583_gpio34_pins[] = { 36 };
 static const int an7583_gpio35_pins[] = { 37 };
@@ -836,6 +837,7 @@ static const struct pingroup an7583_pinctrl_groups[] = {
 	PINCTRL_PIN_GROUP("gpio29", an7583_gpio29),
 	PINCTRL_PIN_GROUP("gpio30", an7583_gpio30),
 	PINCTRL_PIN_GROUP("gpio31", an7583_gpio31),
+	PINCTRL_PIN_GROUP("gpio32", an7583_gpio32),
 	PINCTRL_PIN_GROUP("gpio33", an7583_gpio33),
 	PINCTRL_PIN_GROUP("gpio34", an7583_gpio34),
 	PINCTRL_PIN_GROUP("gpio35", an7583_gpio35),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0665/2077] pinctrl: airoha: an7581: fix misprint in gpio19 pinconf
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (663 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0664/2077] pinctrl: airoha: an7583: " Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0666/2077] pinctrl: airoha: an7583: " Greg Kroah-Hartman
                   ` (332 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikhail Kshevetskiy,
	Bartosz Golaszewski, Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>

[ Upstream commit 08a39a0617ff32a7c3962bbc38a9eee41b14659a ]

Pin 32 (gpio19) duplicate pinconf settings of pin 31. Fix it using
a proper bit number in the configuration register.

Fixes: 1c8ace2d0725 ("pinctrl: airoha: Add support for EN7581 SoC")
Signed-off-by: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-airoha.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/pinctrl/mediatek/pinctrl-airoha.c b/drivers/pinctrl/mediatek/pinctrl-airoha.c
index c0aed1b6079208..14b2357277360b 100644
--- a/drivers/pinctrl/mediatek/pinctrl-airoha.c
+++ b/drivers/pinctrl/mediatek/pinctrl-airoha.c
@@ -1798,7 +1798,7 @@ static const struct airoha_pinctrl_conf en7581_pinctrl_pullup_conf[] = {
 	PINCTRL_CONF_DESC(29, REG_GPIO_L_PU, BIT(16)),
 	PINCTRL_CONF_DESC(30, REG_GPIO_L_PU, BIT(17)),
 	PINCTRL_CONF_DESC(31, REG_GPIO_L_PU, BIT(18)),
-	PINCTRL_CONF_DESC(32, REG_GPIO_L_PU, BIT(18)),
+	PINCTRL_CONF_DESC(32, REG_GPIO_L_PU, BIT(19)),
 	PINCTRL_CONF_DESC(33, REG_GPIO_L_PU, BIT(20)),
 	PINCTRL_CONF_DESC(34, REG_GPIO_L_PU, BIT(21)),
 	PINCTRL_CONF_DESC(35, REG_GPIO_L_PU, BIT(22)),
@@ -1915,7 +1915,7 @@ static const struct airoha_pinctrl_conf en7581_pinctrl_pulldown_conf[] = {
 	PINCTRL_CONF_DESC(29, REG_GPIO_L_PD, BIT(16)),
 	PINCTRL_CONF_DESC(30, REG_GPIO_L_PD, BIT(17)),
 	PINCTRL_CONF_DESC(31, REG_GPIO_L_PD, BIT(18)),
-	PINCTRL_CONF_DESC(32, REG_GPIO_L_PD, BIT(18)),
+	PINCTRL_CONF_DESC(32, REG_GPIO_L_PD, BIT(19)),
 	PINCTRL_CONF_DESC(33, REG_GPIO_L_PD, BIT(20)),
 	PINCTRL_CONF_DESC(34, REG_GPIO_L_PD, BIT(21)),
 	PINCTRL_CONF_DESC(35, REG_GPIO_L_PD, BIT(22)),
@@ -2032,7 +2032,7 @@ static const struct airoha_pinctrl_conf en7581_pinctrl_drive_e2_conf[] = {
 	PINCTRL_CONF_DESC(29, REG_GPIO_L_E2, BIT(16)),
 	PINCTRL_CONF_DESC(30, REG_GPIO_L_E2, BIT(17)),
 	PINCTRL_CONF_DESC(31, REG_GPIO_L_E2, BIT(18)),
-	PINCTRL_CONF_DESC(32, REG_GPIO_L_E2, BIT(18)),
+	PINCTRL_CONF_DESC(32, REG_GPIO_L_E2, BIT(19)),
 	PINCTRL_CONF_DESC(33, REG_GPIO_L_E2, BIT(20)),
 	PINCTRL_CONF_DESC(34, REG_GPIO_L_E2, BIT(21)),
 	PINCTRL_CONF_DESC(35, REG_GPIO_L_E2, BIT(22)),
@@ -2149,7 +2149,7 @@ static const struct airoha_pinctrl_conf en7581_pinctrl_drive_e4_conf[] = {
 	PINCTRL_CONF_DESC(29, REG_GPIO_L_E4, BIT(16)),
 	PINCTRL_CONF_DESC(30, REG_GPIO_L_E4, BIT(17)),
 	PINCTRL_CONF_DESC(31, REG_GPIO_L_E4, BIT(18)),
-	PINCTRL_CONF_DESC(32, REG_GPIO_L_E4, BIT(18)),
+	PINCTRL_CONF_DESC(32, REG_GPIO_L_E4, BIT(19)),
 	PINCTRL_CONF_DESC(33, REG_GPIO_L_E4, BIT(20)),
 	PINCTRL_CONF_DESC(34, REG_GPIO_L_E4, BIT(21)),
 	PINCTRL_CONF_DESC(35, REG_GPIO_L_E4, BIT(22)),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0666/2077] pinctrl: airoha: an7583: fix misprint in gpio19 pinconf
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (664 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0665/2077] pinctrl: airoha: an7581: fix misprint in gpio19 pinconf Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0667/2077] pinctrl: airoha: an7581: fix incorrect led mapping in phy4_led1 pin function Greg Kroah-Hartman
                   ` (331 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikhail Kshevetskiy,
	Bartosz Golaszewski, Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>

[ Upstream commit a7f3e2b7730fc1d6c7431af49e0dc1ee97589795 ]

Pin 21 (gpio19) duplicate pinconf settings of pin 20. Fix it using
a proper bit number in the configuration register.

Fixes: 3ffeb17a9a27 ("pinctrl: airoha: add support for Airoha AN7583 PINs")
Signed-off-by: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-airoha.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/pinctrl/mediatek/pinctrl-airoha.c b/drivers/pinctrl/mediatek/pinctrl-airoha.c
index 14b2357277360b..34eef79d058f36 100644
--- a/drivers/pinctrl/mediatek/pinctrl-airoha.c
+++ b/drivers/pinctrl/mediatek/pinctrl-airoha.c
@@ -1851,7 +1851,7 @@ static const struct airoha_pinctrl_conf an7583_pinctrl_pullup_conf[] = {
 	PINCTRL_CONF_DESC(18, REG_GPIO_L_PU, BIT(16)),
 	PINCTRL_CONF_DESC(19, REG_GPIO_L_PU, BIT(17)),
 	PINCTRL_CONF_DESC(20, REG_GPIO_L_PU, BIT(18)),
-	PINCTRL_CONF_DESC(21, REG_GPIO_L_PU, BIT(18)),
+	PINCTRL_CONF_DESC(21, REG_GPIO_L_PU, BIT(19)),
 	PINCTRL_CONF_DESC(22, REG_GPIO_L_PU, BIT(20)),
 	PINCTRL_CONF_DESC(23, REG_GPIO_L_PU, BIT(21)),
 	PINCTRL_CONF_DESC(24, REG_GPIO_L_PU, BIT(22)),
@@ -1968,7 +1968,7 @@ static const struct airoha_pinctrl_conf an7583_pinctrl_pulldown_conf[] = {
 	PINCTRL_CONF_DESC(18, REG_GPIO_L_PD, BIT(16)),
 	PINCTRL_CONF_DESC(19, REG_GPIO_L_PD, BIT(17)),
 	PINCTRL_CONF_DESC(20, REG_GPIO_L_PD, BIT(18)),
-	PINCTRL_CONF_DESC(21, REG_GPIO_L_PD, BIT(18)),
+	PINCTRL_CONF_DESC(21, REG_GPIO_L_PD, BIT(19)),
 	PINCTRL_CONF_DESC(22, REG_GPIO_L_PD, BIT(20)),
 	PINCTRL_CONF_DESC(23, REG_GPIO_L_PD, BIT(21)),
 	PINCTRL_CONF_DESC(24, REG_GPIO_L_PD, BIT(22)),
@@ -2085,7 +2085,7 @@ static const struct airoha_pinctrl_conf an7583_pinctrl_drive_e2_conf[] = {
 	PINCTRL_CONF_DESC(18, REG_GPIO_L_E2, BIT(16)),
 	PINCTRL_CONF_DESC(19, REG_GPIO_L_E2, BIT(17)),
 	PINCTRL_CONF_DESC(20, REG_GPIO_L_E2, BIT(18)),
-	PINCTRL_CONF_DESC(21, REG_GPIO_L_E2, BIT(18)),
+	PINCTRL_CONF_DESC(21, REG_GPIO_L_E2, BIT(19)),
 	PINCTRL_CONF_DESC(22, REG_GPIO_L_E2, BIT(20)),
 	PINCTRL_CONF_DESC(23, REG_GPIO_L_E2, BIT(21)),
 	PINCTRL_CONF_DESC(24, REG_GPIO_L_E2, BIT(22)),
@@ -2202,7 +2202,7 @@ static const struct airoha_pinctrl_conf an7583_pinctrl_drive_e4_conf[] = {
 	PINCTRL_CONF_DESC(18, REG_GPIO_L_E4, BIT(16)),
 	PINCTRL_CONF_DESC(19, REG_GPIO_L_E4, BIT(17)),
 	PINCTRL_CONF_DESC(20, REG_GPIO_L_E4, BIT(18)),
-	PINCTRL_CONF_DESC(21, REG_GPIO_L_E4, BIT(18)),
+	PINCTRL_CONF_DESC(21, REG_GPIO_L_E4, BIT(19)),
 	PINCTRL_CONF_DESC(22, REG_GPIO_L_E4, BIT(20)),
 	PINCTRL_CONF_DESC(23, REG_GPIO_L_E4, BIT(21)),
 	PINCTRL_CONF_DESC(24, REG_GPIO_L_E4, BIT(22)),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0667/2077] pinctrl: airoha: an7581: fix incorrect led mapping in phy4_led1 pin function
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (665 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0666/2077] pinctrl: airoha: an7583: " Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0668/2077] pinctrl: airoha: an7583: " Greg Kroah-Hartman
                   ` (330 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikhail Kshevetskiy,
	Bartosz Golaszewski, Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>

[ Upstream commit e20c85c79cc2f45b87eb3dab38d4c641bbf83ed6 ]

phy4_led1 pin function maps led incorrectly. It uses the same map as
phy3_led1. PHY{X} should map to LAN{N}_PHY_LED_MAP(X-1).

Fixes: 579839c9548c ("pinctrl: airoha: convert PHY LED GPIO to macro")
Signed-off-by: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-airoha.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/pinctrl/mediatek/pinctrl-airoha.c b/drivers/pinctrl/mediatek/pinctrl-airoha.c
index 34eef79d058f36..9497f5110f61b6 100644
--- a/drivers/pinctrl/mediatek/pinctrl-airoha.c
+++ b/drivers/pinctrl/mediatek/pinctrl-airoha.c
@@ -1622,13 +1622,13 @@ static const struct airoha_pinctrl_func_group phy3_led1_func_group[] = {
 
 static const struct airoha_pinctrl_func_group phy4_led1_func_group[] = {
 	AIROHA_PINCTRL_PHY_LED1("gpio43", GPIO_LAN0_LED1_MODE_MASK,
-				LAN0_LED_MAPPING_MASK, LAN0_PHY_LED_MAP(2)),
+				LAN0_LED_MAPPING_MASK, LAN0_PHY_LED_MAP(3)),
 	AIROHA_PINCTRL_PHY_LED1("gpio44", GPIO_LAN1_LED1_MODE_MASK,
-				LAN1_LED_MAPPING_MASK, LAN1_PHY_LED_MAP(2)),
+				LAN1_LED_MAPPING_MASK, LAN1_PHY_LED_MAP(3)),
 	AIROHA_PINCTRL_PHY_LED1("gpio45", GPIO_LAN2_LED1_MODE_MASK,
-				LAN2_LED_MAPPING_MASK, LAN2_PHY_LED_MAP(2)),
+				LAN2_LED_MAPPING_MASK, LAN2_PHY_LED_MAP(3)),
 	AIROHA_PINCTRL_PHY_LED1("gpio46", GPIO_LAN3_LED1_MODE_MASK,
-				LAN3_LED_MAPPING_MASK, LAN3_PHY_LED_MAP(2)),
+				LAN3_LED_MAPPING_MASK, LAN3_PHY_LED_MAP(3)),
 };
 
 static const struct airoha_pinctrl_func_group an7583_phy1_led0_func_group[] = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0668/2077] pinctrl: airoha: an7583: fix incorrect led mapping in phy4_led1 pin function
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (666 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0667/2077] pinctrl: airoha: an7581: fix incorrect led mapping in phy4_led1 pin function Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0669/2077] pinctrl: airoha: fix pwm pin function for an7581 and an7583 Greg Kroah-Hartman
                   ` (329 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikhail Kshevetskiy,
	Bartosz Golaszewski, Linus Walleij, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>

[ Upstream commit a3602577fdfc49c6dc08d67304426d5ef6d7dec6 ]

phy4_led1 pin function maps led incorrectly. It uses the same map as
phy3_led1. PHY{X} should map to LAN{N}_PHY_LED_MAP(X-1).

Fixes: 3ffeb17a9a27 ("pinctrl: airoha: add support for Airoha AN7583 PINs")
Signed-off-by: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-airoha.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/pinctrl/mediatek/pinctrl-airoha.c b/drivers/pinctrl/mediatek/pinctrl-airoha.c
index 9497f5110f61b6..9be759f08b184a 100644
--- a/drivers/pinctrl/mediatek/pinctrl-airoha.c
+++ b/drivers/pinctrl/mediatek/pinctrl-airoha.c
@@ -1710,13 +1710,13 @@ static const struct airoha_pinctrl_func_group an7583_phy3_led1_func_group[] = {
 
 static const struct airoha_pinctrl_func_group an7583_phy4_led1_func_group[] = {
 	AIROHA_PINCTRL_PHY_LED1("gpio8", GPIO_LAN0_LED1_MODE_MASK,
-				LAN0_LED_MAPPING_MASK, LAN0_PHY_LED_MAP(2)),
+				LAN0_LED_MAPPING_MASK, LAN0_PHY_LED_MAP(3)),
 	AIROHA_PINCTRL_PHY_LED1("gpio9", GPIO_LAN1_LED1_MODE_MASK,
-				LAN1_LED_MAPPING_MASK, LAN1_PHY_LED_MAP(2)),
+				LAN1_LED_MAPPING_MASK, LAN1_PHY_LED_MAP(3)),
 	AIROHA_PINCTRL_PHY_LED1("gpio10", GPIO_LAN2_LED1_MODE_MASK,
-				LAN2_LED_MAPPING_MASK, LAN2_PHY_LED_MAP(2)),
+				LAN2_LED_MAPPING_MASK, LAN2_PHY_LED_MAP(3)),
 	AIROHA_PINCTRL_PHY_LED1("gpio11", GPIO_LAN3_LED1_MODE_MASK,
-				LAN3_LED_MAPPING_MASK, LAN3_PHY_LED_MAP(2)),
+				LAN3_LED_MAPPING_MASK, LAN3_PHY_LED_MAP(3)),
 };
 
 static const struct airoha_pinctrl_func en7581_pinctrl_funcs[] = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0669/2077] pinctrl: airoha: fix pwm pin function for an7581 and an7583
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (667 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0668/2077] pinctrl: airoha: an7583: " Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0670/2077] pinctrl: airoha: an7583: fix gpio21 pin group Greg Kroah-Hartman
                   ` (328 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikhail Kshevetskiy, Linus Walleij,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>

[ Upstream commit 08a5af468e613b6d8cd9725d284c9e6be288d364 ]

AN7581 have 47 valid GPIOs only (gpio0-gpio46), so gpio47 is a fiction.
AN7583 have 49 valid GPIOs (gpio0-gpio48), so gpio48 is missed

To fix an issue
 * create AN7583 specific pwm pin function,
 * remove gpio47 from AN7581 pwm pin function.

Fixes: 3ffeb17a9a27 ("pinctrl: airoha: add support for Airoha AN7583 PINs")
Signed-off-by: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-airoha.c | 74 ++++++++++++++++++++++-
 1 file changed, 72 insertions(+), 2 deletions(-)

diff --git a/drivers/pinctrl/mediatek/pinctrl-airoha.c b/drivers/pinctrl/mediatek/pinctrl-airoha.c
index 9be759f08b184a..15a54172434945 100644
--- a/drivers/pinctrl/mediatek/pinctrl-airoha.c
+++ b/drivers/pinctrl/mediatek/pinctrl-airoha.c
@@ -906,7 +906,30 @@ static const char *const pwm_groups[] = { "gpio0", "gpio1",
 					  "gpio40", "gpio41",
 					  "gpio42", "gpio43",
 					  "gpio44", "gpio45",
-					  "gpio46", "gpio47" };
+					  "gpio46" };
+static const char *const an7583_pwm_groups[] = { "gpio0", "gpio1",
+						 "gpio2", "gpio3",
+						 "gpio4", "gpio5",
+						 "gpio6", "gpio7",
+						 "gpio8", "gpio9",
+						 "gpio10", "gpio11",
+						 "gpio12", "gpio13",
+						 "gpio14", "gpio15",
+						 "gpio16", "gpio17",
+						 "gpio18", "gpio19",
+						 "gpio20", "gpio21",
+						 "gpio22", "gpio23",
+						 "gpio24", "gpio25",
+						 "gpio26", "gpio27",
+						 "gpio28", "gpio29",
+						 "gpio30", "gpio31",
+						 "gpio36", "gpio37",
+						 "gpio38", "gpio39",
+						 "gpio40", "gpio41",
+						 "gpio42", "gpio43",
+						 "gpio44", "gpio45",
+						 "gpio46", "gpio47",
+						 "gpio48" };
 static const char *const phy1_led0_groups[] = { "gpio33", "gpio34",
 						"gpio35", "gpio42" };
 static const char *const phy2_led0_groups[] = { "gpio33", "gpio34",
@@ -1504,7 +1527,54 @@ static const struct airoha_pinctrl_func_group pwm_func_group[] = {
 	AIROHA_PINCTRL_PWM_EXT("gpio44", GPIO44_FLASH_MODE_CFG),
 	AIROHA_PINCTRL_PWM_EXT("gpio45", GPIO45_FLASH_MODE_CFG),
 	AIROHA_PINCTRL_PWM_EXT("gpio46", GPIO46_FLASH_MODE_CFG),
+};
+
+static const struct airoha_pinctrl_func_group an7583_pwm_func_group[] = {
+	AIROHA_PINCTRL_PWM("gpio0", GPIO0_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio1", GPIO1_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio2", GPIO2_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio3", GPIO3_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio4", GPIO4_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio5", GPIO5_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio6", GPIO6_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio7", GPIO7_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio8", GPIO8_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio9", GPIO9_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio10", GPIO10_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio11", GPIO11_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio12", GPIO12_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio13", GPIO13_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio14", GPIO14_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM("gpio15", GPIO15_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio16", GPIO16_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio17", GPIO17_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio18", GPIO18_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio19", GPIO19_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio20", GPIO20_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio21", GPIO21_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio22", GPIO22_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio23", GPIO23_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio24", GPIO24_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio25", GPIO25_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio26", GPIO26_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio27", GPIO27_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio28", GPIO28_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio29", GPIO29_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio30", GPIO30_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio31", GPIO31_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio36", GPIO36_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio37", GPIO37_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio38", GPIO38_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio39", GPIO39_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio40", GPIO40_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio41", GPIO41_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio42", GPIO42_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio43", GPIO43_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio44", GPIO44_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio45", GPIO45_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio46", GPIO46_FLASH_MODE_CFG),
 	AIROHA_PINCTRL_PWM_EXT("gpio47", GPIO47_FLASH_MODE_CFG),
+	AIROHA_PINCTRL_PWM_EXT("gpio48", GPIO48_FLASH_MODE_CFG),
 };
 
 #define AIROHA_PINCTRL_PHY_LED0(gpio, mux_val, map_mask, map_val)	\
@@ -1759,7 +1829,7 @@ static const struct airoha_pinctrl_func an7583_pinctrl_funcs[] = {
 	PINCTRL_FUNC_DESC("emmc", emmc),
 	PINCTRL_FUNC_DESC("pnand", pnand),
 	PINCTRL_FUNC_DESC("pcie_reset", an7583_pcie_reset),
-	PINCTRL_FUNC_DESC("pwm", pwm),
+	PINCTRL_FUNC_DESC("pwm", an7583_pwm),
 	PINCTRL_FUNC_DESC("phy1_led0", an7583_phy1_led0),
 	PINCTRL_FUNC_DESC("phy2_led0", an7583_phy2_led0),
 	PINCTRL_FUNC_DESC("phy3_led0", an7583_phy3_led0),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0670/2077] pinctrl: airoha: an7583: fix gpio21 pin group
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (668 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0669/2077] pinctrl: airoha: fix pwm pin function for an7581 and an7583 Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0671/2077] pinctrl: airoha: an7583: add missed gpio22 " Greg Kroah-Hartman
                   ` (327 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikhail Kshevetskiy, Linus Walleij,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>

[ Upstream commit abf92c45cc82e9a01aa581f9fbc790e78250a4d4 ]

gpio21 pin group refers to gpio22 pin, this is wrong.

Fixes: 3ffeb17a9a27 ("pinctrl: airoha: add support for Airoha AN7583 PINs")
Signed-off-by: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-airoha.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pinctrl/mediatek/pinctrl-airoha.c b/drivers/pinctrl/mediatek/pinctrl-airoha.c
index 15a54172434945..9dce3ed6de174e 100644
--- a/drivers/pinctrl/mediatek/pinctrl-airoha.c
+++ b/drivers/pinctrl/mediatek/pinctrl-airoha.c
@@ -748,7 +748,7 @@ static const int an7583_gpio17_pins[] = { 19 };
 static const int an7583_gpio18_pins[] = { 20 };
 static const int an7583_gpio19_pins[] = { 21 };
 static const int an7583_gpio20_pins[] = { 22 };
-static const int an7583_gpio21_pins[] = { 24 };
+static const int an7583_gpio21_pins[] = { 23 };
 static const int an7583_gpio23_pins[] = { 25 };
 static const int an7583_gpio24_pins[] = { 26 };
 static const int an7583_gpio25_pins[] = { 27 };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0671/2077] pinctrl: airoha: an7583: add missed gpio22 pin group
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (669 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0670/2077] pinctrl: airoha: an7583: fix gpio21 pin group Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0672/2077] pinctrl: airoha: an7583: fix phy1_led1 pin function Greg Kroah-Hartman
                   ` (326 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikhail Kshevetskiy, Linus Walleij,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>

[ Upstream commit 9ef86358855d5fd89db019ace33c097d2d752b9d ]

gpio22 pin group is missed, fix it.

Fixes: 3ffeb17a9a27 ("pinctrl: airoha: add support for Airoha AN7583 PINs")
Signed-off-by: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-airoha.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/pinctrl/mediatek/pinctrl-airoha.c b/drivers/pinctrl/mediatek/pinctrl-airoha.c
index 9dce3ed6de174e..e66b608c4803ae 100644
--- a/drivers/pinctrl/mediatek/pinctrl-airoha.c
+++ b/drivers/pinctrl/mediatek/pinctrl-airoha.c
@@ -749,6 +749,7 @@ static const int an7583_gpio18_pins[] = { 20 };
 static const int an7583_gpio19_pins[] = { 21 };
 static const int an7583_gpio20_pins[] = { 22 };
 static const int an7583_gpio21_pins[] = { 23 };
+static const int an7583_gpio22_pins[] = { 24 };
 static const int an7583_gpio23_pins[] = { 25 };
 static const int an7583_gpio24_pins[] = { 26 };
 static const int an7583_gpio25_pins[] = { 27 };
@@ -828,6 +829,7 @@ static const struct pingroup an7583_pinctrl_groups[] = {
 	PINCTRL_PIN_GROUP("gpio19", an7583_gpio19),
 	PINCTRL_PIN_GROUP("gpio20", an7583_gpio20),
 	PINCTRL_PIN_GROUP("gpio21", an7583_gpio21),
+	PINCTRL_PIN_GROUP("gpio22", an7583_gpio22),
 	PINCTRL_PIN_GROUP("gpio23", an7583_gpio23),
 	PINCTRL_PIN_GROUP("gpio24", an7583_gpio24),
 	PINCTRL_PIN_GROUP("gpio25", an7583_gpio25),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0672/2077] pinctrl: airoha: an7583: fix phy1_led1 pin function
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (670 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0671/2077] pinctrl: airoha: an7583: add missed gpio22 " Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0673/2077] pinctrl: airoha: an7583: remove undefined groups from pcm_spi " Greg Kroah-Hartman
                   ` (325 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikhail Kshevetskiy, Linus Walleij,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>

[ Upstream commit dbe28a2a22a3455d1adbf9fd61d3537603ac3072 ]

phy1_led1 pin function wrongly refers to gpio1 instead of gpio11.
Fix it.

Fixes: 3ffeb17a9a27 ("pinctrl: airoha: add support for Airoha AN7583 PINs")
Signed-off-by: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-airoha.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pinctrl/mediatek/pinctrl-airoha.c b/drivers/pinctrl/mediatek/pinctrl-airoha.c
index e66b608c4803ae..b73ab60d006596 100644
--- a/drivers/pinctrl/mediatek/pinctrl-airoha.c
+++ b/drivers/pinctrl/mediatek/pinctrl-airoha.c
@@ -1754,7 +1754,7 @@ static const struct airoha_pinctrl_func_group an7583_phy1_led1_func_group[] = {
 				LAN1_LED_MAPPING_MASK, LAN1_PHY_LED_MAP(0)),
 	AIROHA_PINCTRL_PHY_LED1("gpio10", GPIO_LAN2_LED1_MODE_MASK,
 				LAN2_LED_MAPPING_MASK, LAN2_PHY_LED_MAP(0)),
-	AIROHA_PINCTRL_PHY_LED1("gpio1", GPIO_LAN3_LED1_MODE_MASK,
+	AIROHA_PINCTRL_PHY_LED1("gpio11", GPIO_LAN3_LED1_MODE_MASK,
 				LAN3_LED_MAPPING_MASK, LAN3_PHY_LED_MAP(0)),
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0673/2077] pinctrl: airoha: an7583: remove undefined groups from pcm_spi pin function
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (671 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0672/2077] pinctrl: airoha: an7583: fix phy1_led1 pin function Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0674/2077] arm64: dts: allwinner: a523: Add missing GPIO interrupt Greg Kroah-Hartman
                   ` (324 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mikhail Kshevetskiy, Linus Walleij,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>

[ Upstream commit 7b87a686a5ab138b3f8ca3d7e3489d8371c02695 ]

pcm_spi_int, pcm_spi_cs2, pcm_spi_cs3, pcm_spi_cs4 pin groups are not
defined, so pcm_spi function can't be applied to these groups.

Fixes: 3ffeb17a9a27 ("pinctrl: airoha: add support for Airoha AN7583 PINs")
Signed-off-by: Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pinctrl/mediatek/pinctrl-airoha.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

diff --git a/drivers/pinctrl/mediatek/pinctrl-airoha.c b/drivers/pinctrl/mediatek/pinctrl-airoha.c
index b73ab60d006596..bf5ebb31e6350e 100644
--- a/drivers/pinctrl/mediatek/pinctrl-airoha.c
+++ b/drivers/pinctrl/mediatek/pinctrl-airoha.c
@@ -877,10 +877,8 @@ static const char *const pcm_spi_groups[] = { "pcm_spi", "pcm_spi_int",
 					      "pcm_spi_cs2_p156",
 					      "pcm_spi_cs2_p128",
 					      "pcm_spi_cs3", "pcm_spi_cs4" };
-static const char *const an7583_pcm_spi_groups[] = { "pcm_spi", "pcm_spi_int",
-						     "pcm_spi_rst", "pcm_spi_cs1",
-						     "pcm_spi_cs2", "pcm_spi_cs3",
-						     "pcm_spi_cs4" };
+static const char *const an7583_pcm_spi_groups[] = { "pcm_spi",
+						     "pcm_spi_rst", "pcm_spi_cs1" };
 static const char *const i2s_groups[] = { "i2s" };
 static const char *const emmc_groups[] = { "emmc" };
 static const char *const pnand_groups[] = { "pnand" };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0674/2077] arm64: dts: allwinner: a523: Add missing GPIO interrupt
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (672 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0673/2077] pinctrl: airoha: an7583: remove undefined groups from pcm_spi " Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0675/2077] ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() Greg Kroah-Hartman
                   ` (323 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Andre Przywara, Chen-Yu Tsai,
	Jernej Skrabec, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Andre Przywara <andre.przywara@arm.com>

[ Upstream commit 6b81aa0c8a4f038712fa549e4d44d8279eeb0440 ]

Even though the Allwinner A523 SoC implements 10 GPIO banks, it has
actually registers for 11 IRQ banks, and even an interrupt assigned to
the first, non-implemented IRQ bank.
Add that first interrupt to the list of GPIO interrupts, to correct the
association between IRQs and GPIO banks.

This fixes GPIO IRQ operation on boards with A523 SoCs, as seen by
broken SD card detect functionality, for instance.

Signed-off-by: Andre Przywara <andre.przywara@arm.com>
Fixes: 35ac96f79664 ("arm64: dts: allwinner: Add Allwinner A523 .dtsi file")
Reviewed-by: Chen-Yu Tsai <wens@kernel.org>
Reviewed-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Link: https://patch.msgid.link/20260327113006.3135663-4-andre.przywara@arm.com
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/arm64/boot/dts/allwinner/sun55i-a523.dtsi | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/boot/dts/allwinner/sun55i-a523.dtsi b/arch/arm64/boot/dts/allwinner/sun55i-a523.dtsi
index 5afa8d92acbfbd..b71dc1d78987a6 100644
--- a/arch/arm64/boot/dts/allwinner/sun55i-a523.dtsi
+++ b/arch/arm64/boot/dts/allwinner/sun55i-a523.dtsi
@@ -128,7 +128,8 @@ gpu: gpu@1800000 {
 		pio: pinctrl@2000000 {
 			compatible = "allwinner,sun55i-a523-pinctrl";
 			reg = <0x2000000 0x800>;
-			interrupts = <GIC_SPI 69 IRQ_TYPE_LEVEL_HIGH>,
+			interrupts = <GIC_SPI 67 IRQ_TYPE_LEVEL_HIGH>,
+				     <GIC_SPI 69 IRQ_TYPE_LEVEL_HIGH>,
 				     <GIC_SPI 71 IRQ_TYPE_LEVEL_HIGH>,
 				     <GIC_SPI 73 IRQ_TYPE_LEVEL_HIGH>,
 				     <GIC_SPI 75 IRQ_TYPE_LEVEL_HIGH>,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0675/2077] ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (673 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0674/2077] arm64: dts: allwinner: a523: Add missing GPIO interrupt Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0676/2077] s390/process: Fix kernel thread function pointer type Greg Kroah-Hartman
                   ` (322 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Fitzgerald <rf@opensource.cirrus.com>

[ Upstream commit 007699d278a655871b07d45a1268761260d03124 ]

In cs35l56_spi_system_reset() initialize val to zero before using it in
the read_poll_timeout(). This prevents testing an uninitialized value if
the regmap_read_bypassed() returns an error.

Read errors are intentionally ignored during this loop because the
device is resetting (though SPI can't really detect that so shouldn't
fail because of that, it's safer to ignore errors and keep polling).
Because of this, val must be initialized to something in case the first
read fails. The polling loop is looking for a non-zero value, so
initializing val to 0 will ensure that the loop continues until a valid
state is read from the device or it times out.

Fixes: 769c1b79295c ("ASoC: cs35l56: Prevent races when soft-resetting using SPI control")
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260611132221.1100497-1-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/codecs/cs35l56-shared.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/soc/codecs/cs35l56-shared.c b/sound/soc/codecs/cs35l56-shared.c
index e04b114a32b7f2..5405f70b7119d8 100644
--- a/sound/soc/codecs/cs35l56-shared.c
+++ b/sound/soc/codecs/cs35l56-shared.c
@@ -534,6 +534,7 @@ static void cs35l56_spi_system_reset(struct cs35l56_base *cs35l56_base)
 	 * The regmap must remain in cache-only until the chip has
 	 * booted, so use a bypassed read.
 	 */
+	val = 0;
 	ret = read_poll_timeout(regmap_read_bypassed, read_ret,
 				(val > 0) && (val < 0xffffffff),
 				CS35L56_HALO_STATE_POLL_US,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0676/2077] s390/process: Fix kernel thread function pointer type
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (674 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0675/2077] ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0677/2077] Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device Greg Kroah-Hartman
                   ` (321 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alexander Gordeev, Heiko Carstens,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Heiko Carstens <hca@linux.ibm.com>

[ Upstream commit d0478f5d3cba1095bfdeb43a9b063c10cdebef14 ]

In case of a kernel thread __ret_from_fork() calls the specified function
indirectly. Fix the kernel thread function pointer, since kernel threads
return an int instead of void.

Fixes: 56e62a737028 ("s390: convert to generic entry")
Reviewed-by: Alexander Gordeev <agordeev@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Alexander Gordeev <agordeev@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/s390/kernel/process.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/s390/kernel/process.c b/arch/s390/kernel/process.c
index 0df95dcb210120..e4bd273e31f4e5 100644
--- a/arch/s390/kernel/process.c
+++ b/arch/s390/kernel/process.c
@@ -50,7 +50,7 @@ void ret_from_fork(void) asm("ret_from_fork");
 
 void __ret_from_fork(struct task_struct *prev, struct pt_regs *regs)
 {
-	void (*func)(void *arg);
+	int (*func)(void *arg);
 
 	schedule_tail(prev);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0677/2077] Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (675 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0676/2077] s390/process: Fix kernel thread function pointer type Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0678/2077] Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() " Greg Kroah-Hartman
                   ` (320 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zijun Hu, Luiz Augusto von Dentz,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zijun Hu <zijun.hu@oss.qualcomm.com>

[ Upstream commit 3ec629fee178d429f01ae843e4ea888de93012bf ]

hu->serdev is NULL for hci_uart attached via non-serdev paths, but
qca_setup() unconditionally calls serdev_device_get_drvdata(hu->serdev)
and dereferences the result, causing a NULL pointer dereference.

Fix by guarding the dereference with a NULL check, consistent with the
rest of qca_setup().

Fixes: 22d893eec0d5 ("Bluetooth: hci_qca: Refactor HFP hardware offload capability handling")
Signed-off-by: Zijun Hu <zijun.hu@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/bluetooth/hci_qca.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/drivers/bluetooth/hci_qca.c b/drivers/bluetooth/hci_qca.c
index 34500137df2c10..cc7b34a61fa783 100644
--- a/drivers/bluetooth/hci_qca.c
+++ b/drivers/bluetooth/hci_qca.c
@@ -1916,9 +1916,12 @@ static int qca_setup(struct hci_uart *hu)
 	const char *rampatch_name = qca_get_rampatch_name(hu);
 	int ret;
 	struct qca_btsoc_version ver;
-	struct qca_serdev *qcadev = serdev_device_get_drvdata(hu->serdev);
+	struct qca_serdev *qcadev = NULL;
 	const char *soc_name;
 
+	if (hu->serdev)
+		qcadev = serdev_device_get_drvdata(hu->serdev);
+
 	ret = qca_check_speeds(hu);
 	if (ret)
 		return ret;
@@ -1980,7 +1983,7 @@ static int qca_setup(struct hci_uart *hu)
 	case QCA_WCN6750:
 	case QCA_WCN6855:
 	case QCA_WCN7850:
-		if (qcadev->bdaddr_property_broken)
+		if (qcadev && qcadev->bdaddr_property_broken)
 			hci_set_quirk(hdev, HCI_QUIRK_BDADDR_PROPERTY_BROKEN);
 
 		hci_set_aosp_capable(hdev);
@@ -2073,7 +2076,7 @@ static int qca_setup(struct hci_uart *hu)
 	else
 		hu->hdev->set_bdaddr = qca_set_bdaddr;
 
-	if (qcadev->support_hfp_hw_offload)
+	if (qcadev && qcadev->support_hfp_hw_offload)
 		qca_configure_hfp_offload(hdev);
 
 	qca->fw_version = le16_to_cpu(ver.patch_ver);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0678/2077] Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (676 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0677/2077] Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0679/2077] Bluetooth: eir: Fix stack OOB write when prepending the Flags AD Greg Kroah-Hartman
                   ` (319 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zijun Hu, Luiz Augusto von Dentz,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zijun Hu <zijun.hu@oss.qualcomm.com>

[ Upstream commit 6b8cbcf08de0db62254d1981f83db0f94681ccd9 ]

hu->serdev is NULL for hci_uart attached via non-serdev paths, but
qca_dmp_hdr() unconditionally dereferences hu->serdev->dev.driver->name,
causing a NULL pointer dereference.

Fix by guarding the dereference with a NULL check and falling back to
"hci_ldisc_qca" for the non-serdev case.

Fixes: 06d3fdfcdf5c ("Bluetooth: hci_qca: Add qcom devcoredump support")
Signed-off-by: Zijun Hu <zijun.hu@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/bluetooth/hci_qca.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/bluetooth/hci_qca.c b/drivers/bluetooth/hci_qca.c
index cc7b34a61fa783..2444471956197b 100644
--- a/drivers/bluetooth/hci_qca.c
+++ b/drivers/bluetooth/hci_qca.c
@@ -1028,7 +1028,7 @@ static void qca_dmp_hdr(struct hci_dev *hdev, struct sk_buff *skb)
 	skb_put_data(skb, buf, strlen(buf));
 
 	snprintf(buf, sizeof(buf), "Driver: %s\n",
-		hu->serdev->dev.driver->name);
+		 hu->serdev ? hu->serdev->dev.driver->name : "hci_ldisc_qca");
 	skb_put_data(skb, buf, strlen(buf));
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0679/2077] Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (677 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0678/2077] Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() " Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0680/2077] Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING Greg Kroah-Hartman
                   ` (318 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi,
	Luiz Augusto von Dentz, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Weiming Shi <bestswngs@gmail.com>

[ Upstream commit 6f5fb689fdf80bdd143f22a502f9eb1f3c85e286 ]

eir_create_adv_data() builds the advertising data into a fixed-size
buffer ("size", 31 for the legacy path). It may prepend a 3-byte "Flags"
AD structure (LE_AD_NO_BREDR on an LE-only controller) and then copies
the per-instance data without checking that it still fits:

	memcpy(ptr, adv->adv_data, adv->adv_data_len);

tlv_data_max_len() only reserves those 3 bytes when the user-supplied
flags carry a managed-flags bit, so an instance added with flags == 0 is
accepted with adv_data_len up to the full buffer. At advertise time the
flags are still prepended, and the memcpy() writes 3 + adv_data_len
bytes into the size-byte buffer:

  BUG: KASAN: stack-out-of-bounds in eir_create_adv_data (net/bluetooth/eir.c:301)
  Write of size 31 at addr ffff88800a547bdc by task kworker/u9:0/65
  Workqueue: hci0 hci_cmd_sync_work
   __asan_memcpy (mm/kasan/shadow.c:106)
   eir_create_adv_data (net/bluetooth/eir.c:301)
   hci_update_adv_data_sync (net/bluetooth/hci_sync.c:1310)
   hci_schedule_adv_instance_sync (net/bluetooth/hci_sync.c:1817)
   hci_cmd_sync_work (net/bluetooth/hci_sync.c:332)
  This frame has 1 object:
   [32, 64) 'cp'

The "Flags" structure is added by the kernel, not requested by
userspace, so only prepend it when it fits together with the instance
advertising data; when there is no room for both, drop the flags rather
than the user-provided data.

Reachable by a local user with CAP_NET_ADMIN owning an LE-only
controller on the legacy advertising path.

Fixes: b44133ff03be ("Bluetooth: Support the "discoverable" adv flag")
Reported-by: Xiang Mei <xmei5@asu.edu>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/bluetooth/eir.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/net/bluetooth/eir.c b/net/bluetooth/eir.c
index 3f72111ba651f9..1de5f9df6eec00 100644
--- a/net/bluetooth/eir.c
+++ b/net/bluetooth/eir.c
@@ -283,10 +283,12 @@ u8 eir_create_adv_data(struct hci_dev *hdev, u8 instance, u8 *ptr, u8 size)
 		if (!flags)
 			flags |= mgmt_get_adv_discov_flags(hdev);
 
-		/* If flags would still be empty, then there is no need to
-		 * include the "Flags" AD field".
+		/* Only add the "Flags" if it fits together with the instance
+		 * advertising data; drop it rather than overflow the buffer.
 		 */
-		if (flags && (ad_len + eir_precalc_len(1) <= size)) {
+		if (flags &&
+		    (ad_len + eir_precalc_len(1) +
+		     (adv ? adv->adv_data_len : 0) <= size)) {
 			ptr[0] = 0x02;
 			ptr[1] = EIR_FLAGS;
 			ptr[2] = flags;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0680/2077] Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (678 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0679/2077] Bluetooth: eir: Fix stack OOB write when prepending the Flags AD Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0681/2077] Bluetooth: hci_core: Fix UAF in hci_unregister_dev() Greg Kroah-Hartman
                   ` (317 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jiajia Liu, Luiz Augusto von Dentz,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiajia Liu <liujiajia@kylinos.cn>

[ Upstream commit 96d006ae6445679436b945593950fd465eba7e76 ]

When hci_inquiry_complete_evt is called between le_scan_disable and
le_set_scan_enable_complete and no remote name needs to be resolved,
the interleaved discovery with SIMULTANEOUS quirk gets stuck in
DISCOVERY_FINDING. le_set_scan_enable_complete does not check inquiry
state. No one sets DISCOVERY_STOPPED in this process.

Add state check in le_set_scan_enable_complete and change state if
the state is DISCOVERY_FINDING. Tested with AX201 (8087:0026) in Dell
Vostro 13. Discovering disabled MGMT Event below is reported when
running into the above condition.

 @ MGMT Command: Start Discovery (0x0023)    {0x0001} [hci0] 10885.970873
         Address type: 0x07
           BR/EDR
           LE Public
           LE Random
 ...
 < HCI Command: LE Set Extended Scan Enable    #38205 [hci0] 10886.131438
         Extended scan: Enabled (0x01)
         Filter duplicates: Enabled (0x01)
         Duration: 0 msec (0x0000)
         Period: 0.00 sec (0x0000)
 > HCI Event: Command Complete (0x0e) plen 4   #38206 [hci0] 10886.133295
       LE Set Extended Scan Enable (0x08|0x0042) ncmd 2
         Status: Success (0x00)
 @ MGMT Event: Discovering (0x0013) plen 2   {0x0001} [hci0] 10886.133414
         Address type: 0x07
           BR/EDR
           LE Public
           LE Random
         Discovery: Enabled (0x01)
 < HCI Command: Inquiry (0x01|0x0001) plen 5   #38207 [hci0] 10886.133528
         Access code: 0x9e8b33 (General Inquiry)
         Length: 10.24s (0x08)
         Num responses: 0
 > HCI Event: Command Status (0x0f) plen 4     #38208 [hci0] 10886.141333
       Inquiry (0x01|0x0001) ncmd 2
         Status: Success (0x00)
 ...
 < HCI Command: LE Set Extended Scan Enable    #38242 [hci0] 10896.381802
         Extended scan: Disabled (0x00)
         Filter duplicates: Disabled (0x00)
         Duration: 0 msec (0x0000)
         Period: 0.00 sec (0x0000)
 > HCI Event: Inquiry Complete (0x01) plen 1   #38243 [hci0] 10896.383419
         Status: Success (0x00)
 > HCI Event: Command Complete (0x0e) plen 4   #38244 [hci0] 10896.394378
       LE Set Extended Scan Enable (0x08|0x0042) ncmd 2
         Status: Success (0x00)
 @ MGMT Event: Device Found (0x0012) plen 22 {0x0001} [hci0] 10896.394497
         LE Address: 88:12:AC:92:43:69
         RSSI: -101 dBm (0x9b)
         Flags: 0x00000004
           Not Connectable
         Data length: 8
         Company: Xiaomi Inc. (911)
           Data[0]:
         16-bit Service UUIDs (complete): 1 entry
           Xiaomi Inc. (0xfdaa)
 @ MGMT Event: Discovering (0x0013) plen 2   {0x0001} [hci0] 10896.394506
         Address type: 0x07
           BR/EDR
           LE Public
           LE Random
         Discovery: Disabled (0x00)

Fixes: 8ffde2a73f2c ("Bluetooth: Convert le_scan_disable timeout to hci_sync")
Signed-off-by: Jiajia Liu <liujiajia@kylinos.cn>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/bluetooth/hci_event.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/net/bluetooth/hci_event.c b/net/bluetooth/hci_event.c
index eea2f810aafab3..1cd5f97daafe32 100644
--- a/net/bluetooth/hci_event.c
+++ b/net/bluetooth/hci_event.c
@@ -1769,6 +1769,13 @@ static void le_set_scan_enable_complete(struct hci_dev *hdev, u8 enable)
 
 		hci_dev_clear_flag(hdev, HCI_LE_SCAN);
 
+		if (hdev->discovery.type == DISCOV_TYPE_INTERLEAVED &&
+		    hci_test_quirk(hdev, HCI_QUIRK_SIMULTANEOUS_DISCOVERY) &&
+		    !test_bit(HCI_INQUIRY, &hdev->flags) &&
+		    hdev->discovery.state == DISCOVERY_FINDING) {
+			hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
+		}
+
 		/* The HCI_LE_SCAN_INTERRUPTED flag indicates that we
 		 * interrupted scanning due to a connect request. Mark
 		 * therefore discovery as stopped.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0681/2077] Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (679 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0680/2077] Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0682/2077] Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path Greg Kroah-Hartman
                   ` (316 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jordan Walters,
	Luiz Augusto von Dentz, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jordan Walters <jaggyaur@gmail.com>

[ Upstream commit 5edcc018fa6e80b2c478454a4a8229c23d67c181 ]

hci_unregister_dev() does not disable cmd_timer and ncmd_timer
before the hci_dev structure is freed. If a timeout fires
during device teardown, the callback dereferences freed memory
(including the hdev->reset function pointer), leading to a
use-after-free.

Add disable_delayed_work_sync() calls alongside the existing
disable_work_sync() calls to ensure both timers are fully
quiesced before teardown proceeds.

Fixes: 0d151a103775 ("Bluetooth: hci_core: cancel all works upon hci_unregister_dev()")
Signed-off-by: Jordan Walters <jaggyaur@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/bluetooth/hci_core.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c
index 28d7929dc59377..1cbc666527c57c 100644
--- a/net/bluetooth/hci_core.c
+++ b/net/bluetooth/hci_core.c
@@ -2671,6 +2671,8 @@ void hci_unregister_dev(struct hci_dev *hdev)
 	disable_work_sync(&hdev->tx_work);
 	disable_work_sync(&hdev->power_on);
 	disable_work_sync(&hdev->error_reset);
+	disable_delayed_work_sync(&hdev->cmd_timer);
+	disable_delayed_work_sync(&hdev->ncmd_timer);
 
 	hci_cmd_sync_clear(hdev);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0682/2077] Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (680 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0681/2077] Bluetooth: hci_core: Fix UAF in hci_unregister_dev() Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0683/2077] Bluetooth: btintel_pcie: Load IOSF debug regs by controller variant Greg Kroah-Hartman
                   ` (315 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhao Dongdong,
	Luiz Augusto von Dentz, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhao Dongdong <zhaodongdong@kylinos.cn>

[ Upstream commit f396f4005180928cd9e15e352a6512865d3bc908 ]

When btmtk_isopkt_pad() fails, the previously allocated URB is not freed,
leaking the urb structure. Add usb_free_urb() before returning the error.

Fixes: ceac1cb0259d ("Bluetooth: btusb: mediatek: add ISO data transmission functions")
Signed-off-by: Zhao Dongdong <zhaodongdong@kylinos.cn>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/bluetooth/btmtk.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/bluetooth/btmtk.c b/drivers/bluetooth/btmtk.c
index 8ff66b276af03e..c29e1841b2b3fb 100644
--- a/drivers/bluetooth/btmtk.c
+++ b/drivers/bluetooth/btmtk.c
@@ -1074,8 +1074,10 @@ struct urb *alloc_mtk_intr_urb(struct hci_dev *hdev, struct sk_buff *skb,
 	if (!urb)
 		return ERR_PTR(-ENOMEM);
 
-	if (btmtk_isopkt_pad(hdev, skb))
+	if (btmtk_isopkt_pad(hdev, skb)) {
+		usb_free_urb(urb);
 		return ERR_PTR(-EINVAL);
+	}
 
 	pipe = usb_sndintpipe(btmtk_data->udev,
 			      btmtk_data->isopkt_tx_ep->bEndpointAddress);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0683/2077] Bluetooth: btintel_pcie: Load IOSF debug regs by controller variant
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (681 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0682/2077] Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0684/2077] Bluetooth: hci: validate codec capability element length Greg Kroah-Hartman
                   ` (314 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sai Teja Aluvala, Kiran K,
	Luiz Augusto von Dentz, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sai Teja Aluvala <aluvala.sai.teja@intel.com>

[ Upstream commit e43b33bf8d671c50a45fe5f487819927595bbd50 ]

Load the IOSF DBGC base address based on the controller hardware
variant when reading DRAM buffers during a trace dump. Scorpius
Peak family controllers (SCP/SCP2/SCP2F) use a different DBGC base
address (0xf0d5d500) than Blazar family controllers (BZRI/BZRIW,
0xf3800300).

Fixes: 07e6bddb54b4 ("Bluetooth: btintel_pcie: Add support for device coredump")
Signed-off-by: Sai Teja Aluvala <aluvala.sai.teja@intel.com>
Signed-off-by: Kiran K <kiran.k@intel.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/bluetooth/btintel.h      |  1 +
 drivers/bluetooth/btintel_pcie.c | 30 ++++++++++++++++++++++++------
 drivers/bluetooth/btintel_pcie.h |  4 ++++
 3 files changed, 29 insertions(+), 6 deletions(-)

diff --git a/drivers/bluetooth/btintel.h b/drivers/bluetooth/btintel.h
index 0e9ca99aaaaea2..035ed1ea6ce965 100644
--- a/drivers/bluetooth/btintel.h
+++ b/drivers/bluetooth/btintel.h
@@ -77,6 +77,7 @@ struct intel_tlv {
 #define BTINTEL_HWID_BZRU	0x1d	/* BlazarU - Meteor Lake */
 #define BTINTEL_HWID_SCP	0x1f	/* Scorpius Peak - Panther Lake */
 #define BTINTEL_HWID_SCP2	0x20	/* Scorpius Peak2 - Nova Lake */
+#define BTINTEL_HWID_SCP2F	0x21	/* Scorpius Peak2-F - Nova Lake */
 #define BTINTEL_HWID_BZRIW	0x22	/* BlazarIW - Wildcat Lake */
 
 struct intel_version_tlv {
diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_pcie.c
index 37e0507636330a..d4426ac767fd8c 100644
--- a/drivers/bluetooth/btintel_pcie.c
+++ b/drivers/bluetooth/btintel_pcie.c
@@ -626,9 +626,10 @@ static void *btintel_pcie_copy_tlv(void *dest, enum btintel_pcie_tlv_type type,
 static int btintel_pcie_read_dram_buffers(struct btintel_pcie_data *data)
 {
 	u32 offset, prev_size, wr_ptr_status, dump_size, data_len;
+	u32 status_reg, wrap_reg;
 	struct btintel_pcie_dbgc *dbgc = &data->dbgc;
 	struct hci_dev *hdev = data->hdev;
-	u8 *pdata, *p, buf_idx;
+	u8 *pdata, *p, buf_idx, hw_variant;
 	struct intel_tlv *tlv;
 	struct timespec64 now;
 	struct tm tm_now;
@@ -641,7 +642,28 @@ static int btintel_pcie_read_dram_buffers(struct btintel_pcie_data *data)
 		return -EOPNOTSUPP;
 
 
-	wr_ptr_status = btintel_pcie_rd_dev_mem(data, BTINTEL_PCIE_DBGC_CUR_DBGBUFF_STATUS);
+	hw_variant = INTEL_HW_VARIANT(data->cnvi);
+	switch (hw_variant) {
+	case BTINTEL_HWID_BZRI:
+	case BTINTEL_HWID_BZRIW:
+		status_reg = BTINTEL_PCIE_DBGC_CUR_DBGBUFF_STATUS;
+		wrap_reg = BTINTEL_PCIE_DBGC_DBGBUFF_WRAP_ARND;
+		break;
+	case BTINTEL_HWID_SCP:
+	case BTINTEL_HWID_SCP2:
+	case BTINTEL_HWID_SCP2F:
+		status_reg = BTINTEL_PCIE_DBGC_CUR_DBGBUFF_STATUS_SCP;
+		wrap_reg = BTINTEL_PCIE_DBGC_DBGBUFF_WRAP_ARND_SCP;
+		break;
+	default:
+		bt_dev_err(hdev, "Unsupported Intel hardware variant (0x%2.2x)",
+			   hw_variant);
+		return -EINVAL;
+	}
+
+	wr_ptr_status = btintel_pcie_rd_dev_mem(data, status_reg);
+	data->dmp_hdr.wrap_ctr = btintel_pcie_rd_dev_mem(data, wrap_reg);
+
 	offset = wr_ptr_status & BTINTEL_PCIE_DBG_OFFSET_BIT_MASK;
 
 	buf_idx = BTINTEL_PCIE_DBGC_DBG_BUF_IDX(wr_ptr_status);
@@ -718,10 +740,6 @@ static int btintel_pcie_read_dram_buffers(struct btintel_pcie_data *data)
 				  sizeof(data->dmp_hdr.write_ptr));
 	p = btintel_pcie_copy_tlv(p, BTINTEL_WRAP_CTR, &data->dmp_hdr.wrap_ctr,
 				  sizeof(data->dmp_hdr.wrap_ctr));
-
-	data->dmp_hdr.wrap_ctr = btintel_pcie_rd_dev_mem(data,
-							 BTINTEL_PCIE_DBGC_DBGBUFF_WRAP_ARND);
-
 	p = btintel_pcie_copy_tlv(p, BTINTEL_TRIGGER_REASON, &data->dmp_hdr.trigger_reason,
 				  sizeof(data->dmp_hdr.trigger_reason));
 	p = btintel_pcie_copy_tlv(p, BTINTEL_FW_SHA, &data->dmp_hdr.fw_git_sha1,
diff --git a/drivers/bluetooth/btintel_pcie.h b/drivers/bluetooth/btintel_pcie.h
index 13efef499e4e83..c7db89af49056b 100644
--- a/drivers/bluetooth/btintel_pcie.h
+++ b/drivers/bluetooth/btintel_pcie.h
@@ -68,6 +68,10 @@
 #define BTINTEL_PCIE_DBGC_CUR_DBGBUFF_STATUS		(BTINTEL_PCIE_DBGC_BASE_ADDR + 0x1C)
 #define BTINTEL_PCIE_DBGC_DBGBUFF_WRAP_ARND		(BTINTEL_PCIE_DBGC_BASE_ADDR + 0x2C)
 
+#define BTINTEL_PCIE_DBGC_BASE_ADDR_SCP			(0xf0d5d500)
+#define BTINTEL_PCIE_DBGC_CUR_DBGBUFF_STATUS_SCP	(BTINTEL_PCIE_DBGC_BASE_ADDR_SCP + 0x1C)
+#define BTINTEL_PCIE_DBGC_DBGBUFF_WRAP_ARND_SCP		(BTINTEL_PCIE_DBGC_BASE_ADDR_SCP + 0x2C)
+
 #define BTINTEL_PCIE_DBG_IDX_BIT_MASK		0x0F
 #define BTINTEL_PCIE_DBGC_DBG_BUF_IDX(data)	(((data) >> 24) & BTINTEL_PCIE_DBG_IDX_BIT_MASK)
 #define BTINTEL_PCIE_DBG_OFFSET_BIT_MASK	0xFFFFFF
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0684/2077] Bluetooth: hci: validate codec capability element length
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (682 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0683/2077] Bluetooth: btintel_pcie: Load IOSF debug regs by controller variant Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0685/2077] Bluetooth: vhci: validate devcoredump state before side effects Greg Kroah-Hartman
                   ` (313 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Samuel Moelius,
	Luiz Augusto von Dentz, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Samuel Moelius <sam.moelius@trailofbits.com>

[ Upstream commit c38fbcdc407925c7088f7e5f11c1fff73d2d35a2 ]

Read Local Codec Capabilities returns a sequence of capability elements.
Each element starts with a one-byte length followed by that many payload
bytes.

hci_read_codec_capabilities() checks that the skb contains the length
byte, but then validates only caps->len against the remaining skb
length.  A malformed controller response with one remaining byte and
caps->len set to one passes that check even though the element needs two
bytes.  The parser then records a two-byte capability and copies one
byte beyond the advertised response payload into the codec list.

Validate the full element size, including the length byte, before adding
it to the accumulated capability length.  This preserves all well-formed
capability elements and drops only truncated controller responses.

Fixes: 8961987f3f5f ("Bluetooth: Enumerate local supported codec and cache details")
Assisted-by: Codex:gpt-5.5-cyber-preview
Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/bluetooth/hci_codec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/bluetooth/hci_codec.c b/net/bluetooth/hci_codec.c
index 3cc135bb1d30ca..5bc5003c387c66 100644
--- a/net/bluetooth/hci_codec.c
+++ b/net/bluetooth/hci_codec.c
@@ -100,7 +100,7 @@ static void hci_read_codec_capabilities(struct hci_dev *hdev, __u8 transport,
 				caps = (void *)skb->data;
 				if (skb->len < sizeof(*caps))
 					goto error;
-				if (skb->len < caps->len)
+				if (skb->len < sizeof(caps->len) + caps->len)
 					goto error;
 				len += sizeof(caps->len) + caps->len;
 				skb_pull(skb,  sizeof(caps->len) + caps->len);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0685/2077] Bluetooth: vhci: validate devcoredump state before side effects
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (683 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0684/2077] Bluetooth: hci: validate codec capability element length Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:05 ` [PATCH 7.1 0686/2077] RDMA/mlx5: Fix mkey creation error flow rollback Greg Kroah-Hartman
                   ` (312 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Samuel Moelius,
	Luiz Augusto von Dentz, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Samuel Moelius <sam.moelius@trailofbits.com>

[ Upstream commit 88c2404a3c59c3126453919388dbd5ed98ed01bd ]

The VHCI force_devcoredump debugfs hook accepts a small test record from
userspace. It validates the requested terminal state only after
registering, initializing and appending a Bluetooth devcoredump.

As a result, an invalid state returns -EINVAL but still leaves queued
devcoredump work behind. With a non-zero timeout field, the rejected
write can still emit a devcoredump after the timeout expires.

Reject unsupported states before allocating the skb or changing the HCI
devcoredump state machine.

Fixes: ab4e4380d4e1 ("Bluetooth: Add vhci devcoredump support")
Assisted-by: Codex:gpt-5.5-cyber-preview
Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/bluetooth/hci_vhci.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/drivers/bluetooth/hci_vhci.c b/drivers/bluetooth/hci_vhci.c
index 2762eacf7f20ed..eddb32b30539ff 100644
--- a/drivers/bluetooth/hci_vhci.c
+++ b/drivers/bluetooth/hci_vhci.c
@@ -337,7 +337,17 @@ static ssize_t force_devcd_write(struct file *file, const char __user *user_buf,
 	if (copy_from_user(&dump_data, user_buf, count))
 		return -EFAULT;
 
+	switch (dump_data.state) {
+	case HCI_DEVCOREDUMP_DONE:
+	case HCI_DEVCOREDUMP_ABORT:
+	case HCI_DEVCOREDUMP_TIMEOUT:
+		break;
+	default:
+		return -EINVAL;
+	}
+
 	data_size = count - offsetof(struct devcoredump_test_data, data);
+
 	skb = alloc_skb(data_size, GFP_ATOMIC);
 	if (!skb)
 		return -ENOMEM;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0686/2077] RDMA/mlx5: Fix mkey creation error flow rollback
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (684 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0685/2077] Bluetooth: vhci: validate devcoredump state before side effects Greg Kroah-Hartman
@ 2026-07-21 15:05 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0687/2077] RDMA/mlx5: Fix TPH extraction in FRMR pool key Greg Kroah-Hartman
                   ` (311 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:05 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Guralnik, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Guralnik <michaelgur@nvidia.com>

[ Upstream commit c70fcfa9881207659ad193ae10a3bd56b2ae3f8a ]

Fix the indices of mkeys destroyed in case of an error in batch mkey
creation.

Fixes: 36680ef7bceb ("RDMA/mlx5: Switch from MR cache to FRMR pools")
Link: https://patch.msgid.link/r/20260610000145.820592-2-michaelgur@nvidia.com
Signed-off-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/mr.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/mlx5/mr.c b/drivers/infiniband/hw/mlx5/mr.c
index 41ca3b1a6db079..253545ae39fd53 100644
--- a/drivers/infiniband/hw/mlx5/mr.c
+++ b/drivers/infiniband/hw/mlx5/mr.c
@@ -294,7 +294,7 @@ static int mlx5r_create_mkeys(struct ib_device *device, struct ib_frmr_key *key,
 free_in:
 	kfree(in);
 	if (err)
-		for (; i > 0; i--)
+		for (i--; i >= 0; i--)
 			mlx5_core_destroy_mkey(dev->mdev, handles[i]);
 	return err;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0687/2077] RDMA/mlx5: Fix TPH extraction in FRMR pool key
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (685 preceding siblings ...)
  2026-07-21 15:05 ` [PATCH 7.1 0686/2077] RDMA/mlx5: Fix mkey creation error flow rollback Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0688/2077] RDMA/core: Fix skipped usage for driver built FRMR key Greg Kroah-Hartman
                   ` (310 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Guralnik, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Guralnik <michaelgur@nvidia.com>

[ Upstream commit fe683274fee497834d2e6b54b7342642e1f21892 ]

Fix reading the PH value from the FRMR pool key by shifting the pool key
to the relevant bits.

Fixes: 36680ef7bceb ("RDMA/mlx5: Switch from MR cache to FRMR pools")
Link: https://patch.msgid.link/r/20260610000145.820592-3-michaelgur@nvidia.com
Signed-off-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/mr.c | 16 +++++++++-------
 1 file changed, 9 insertions(+), 7 deletions(-)

diff --git a/drivers/infiniband/hw/mlx5/mr.c b/drivers/infiniband/hw/mlx5/mr.c
index 253545ae39fd53..7fbb01371f1f77 100644
--- a/drivers/infiniband/hw/mlx5/mr.c
+++ b/drivers/infiniband/hw/mlx5/mr.c
@@ -31,6 +31,7 @@
  * SOFTWARE.
  */
 
+#include <linux/bitfield.h>
 #include <linux/kref.h>
 #include <linux/random.h>
 #include <linux/debugfs.h>
@@ -163,9 +164,8 @@ static int get_unchangeable_access_flags(struct mlx5_ib_dev *dev,
 #define MLX5_FRMR_POOLS_KEY_VENDOR_KEY_SUPPORTED \
 	MLX5_FRMR_POOLS_KEY_ACCESS_MODE_KSM_MASK
 
-#define MLX5_FRMR_POOLS_KERNEL_KEY_PH_SHIFT 16
-#define MLX5_FRMR_POOLS_KERNEL_KEY_PH_MASK 0xFF0000
-#define MLX5_FRMR_POOLS_KERNEL_KEY_ST_INDEX_MASK 0xFFFF
+#define MLX5_FRMR_POOLS_KERNEL_KEY_PH_MASK GENMASK_ULL(23, 16)
+#define MLX5_FRMR_POOLS_KERNEL_KEY_ST_INDEX_MASK GENMASK_ULL(15, 0)
 
 static struct mlx5_ib_mr *
 _mlx5_frmr_pool_alloc(struct mlx5_ib_dev *dev, struct ib_umem *umem,
@@ -194,7 +194,8 @@ _mlx5_frmr_pool_alloc(struct mlx5_ib_dev *dev, struct ib_umem *umem,
 		ph ^= MLX5_IB_NO_PH;
 
 	mr->ibmr.frmr.key.kernel_vendor_key =
-		st_index | (ph << MLX5_FRMR_POOLS_KERNEL_KEY_PH_SHIFT);
+		FIELD_PREP(MLX5_FRMR_POOLS_KERNEL_KEY_ST_INDEX_MASK, st_index) |
+		FIELD_PREP(MLX5_FRMR_POOLS_KERNEL_KEY_PH_MASK, ph);
 	err = ib_frmr_pool_pop(&dev->ib_dev, &mr->ibmr);
 	if (err) {
 		kfree(mr);
@@ -271,9 +272,10 @@ static int mlx5r_create_mkeys(struct ib_device *device, struct ib_frmr_key *key,
 		 get_mkc_octo_size(access_mode, key->num_dma_blocks));
 	MLX5_SET(mkc, mkc, log_page_size, PAGE_SHIFT);
 
-	st_index = key->kernel_vendor_key &
-		   MLX5_FRMR_POOLS_KERNEL_KEY_ST_INDEX_MASK;
-	ph = key->kernel_vendor_key & MLX5_FRMR_POOLS_KERNEL_KEY_PH_MASK;
+	st_index = FIELD_GET(MLX5_FRMR_POOLS_KERNEL_KEY_ST_INDEX_MASK,
+			     key->kernel_vendor_key);
+	ph = FIELD_GET(MLX5_FRMR_POOLS_KERNEL_KEY_PH_MASK,
+		       key->kernel_vendor_key);
 	if (ph) {
 		/* Normalize ph: swap MLX5_IB_NO_PH for 0 */
 		if (ph == MLX5_IB_NO_PH)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0688/2077] RDMA/core: Fix skipped usage for driver built FRMR key
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (686 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0687/2077] RDMA/mlx5: Fix TPH extraction in FRMR pool key Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0689/2077] RDMA/core: Fix FRMR aging push to queue error flow Greg Kroah-Hartman
                   ` (309 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Guralnik, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Guralnik <michaelgur@nvidia.com>

[ Upstream commit 3d7fd88aeff73f25ee740b3a65a3b4dd38ad7783 ]

When creating FRMR handles following a netlink command to pin handles,
use the key after driver callback instead of using the key passed directly
from user.

Fixes: 020d189d16a6 ("RDMA/core: Add pinned handles to FRMR pools")
Link: https://patch.msgid.link/r/20260610000145.820592-4-michaelgur@nvidia.com
Signed-off-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/core/frmr_pools.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/core/frmr_pools.c b/drivers/infiniband/core/frmr_pools.c
index 5e992ff3d7cffd..6170466ea9581a 100644
--- a/drivers/infiniband/core/frmr_pools.c
+++ b/drivers/infiniband/core/frmr_pools.c
@@ -426,7 +426,7 @@ int ib_frmr_pools_set_pinned(struct ib_device *device, struct ib_frmr_key *key,
 	if (!handles)
 		return -ENOMEM;
 
-	ret = pools->pool_ops->create_frmrs(device, key, handles,
+	ret = pools->pool_ops->create_frmrs(device, &driver_key, handles,
 					    needed_handles);
 	if (ret) {
 		kfree(handles);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0689/2077] RDMA/core: Fix FRMR aging push to queue error flow
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (687 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0688/2077] RDMA/core: Fix skipped usage for driver built FRMR key Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0690/2077] RDMA/core: Fix FRMR set pinned push error path Greg Kroah-Hartman
                   ` (308 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Guralnik, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Guralnik <michaelgur@nvidia.com>

[ Upstream commit c6936506ed556ce3ccad36ab999baf2764dd7d25 ]

Aging pools with pinned handles requires moving handles from the
active queue to a non-empty inactive queue that might fail on new page
allocation, we are currently not handling the fault and leaking any mkey
that fails the push.

Fix by Introducing push_queue_to_queue_locked() that fills the
destination's partial tail page from the source and then splices the
remaining source pages onto the destination, performing no allocation.

Replace the per-handle move loop in age_pinned_pool() and the
open-coded splice in pool_aging_work() with calls to the helper.
As the helper cannot fail under memory pressure, removing a class of
GFP_ATOMIC allocations under the pool lock and simplifying the error
flow.

Fixes: 020d189d16a6 ("RDMA/core: Add pinned handles to FRMR pools")
Link: https://patch.msgid.link/r/20260610000145.820592-5-michaelgur@nvidia.com
Signed-off-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/core/frmr_pools.c | 53 ++++++++++++++++++++--------
 1 file changed, 38 insertions(+), 15 deletions(-)

diff --git a/drivers/infiniband/core/frmr_pools.c b/drivers/infiniband/core/frmr_pools.c
index 6170466ea9581a..927642c06f3a4c 100644
--- a/drivers/infiniband/core/frmr_pools.c
+++ b/drivers/infiniband/core/frmr_pools.c
@@ -97,13 +97,44 @@ static void destroy_all_handles_in_queue(struct ib_device *device,
 	}
 }
 
+/*
+ * Bulk-move all handles from @src into @dst without allocating new pages.
+ * If @dst has a partial tail page, fill it handle-by-handle from @src first
+ * to preserve the invariant that only the tail page is partial, then splice
+ * the remaining @src pages onto @dst. On return @src is empty.
+ *
+ * Caller must hold the lock protecting both queues.
+ */
+static void splice_frmr_queue_locked(struct frmr_queue *dst,
+				     struct frmr_queue *src)
+{
+	u32 free_in_tail = dst->ci % NUM_HANDLES_PER_PAGE;
+	u32 handle;
+
+	if (free_in_tail) {
+		free_in_tail = NUM_HANDLES_PER_PAGE - free_in_tail;
+		while (free_in_tail && src->ci) {
+			handle = pop_handle_from_queue_locked(src);
+			push_handle_to_queue_locked(dst, handle);
+			free_in_tail--;
+		}
+	}
+
+	if (src->ci > 0) {
+		list_splice_tail_init(&src->pages_list, &dst->pages_list);
+		dst->num_pages += src->num_pages;
+		dst->ci += src->ci;
+		src->num_pages = 0;
+		src->ci = 0;
+	}
+}
+
 static bool age_pinned_pool(struct ib_device *device, struct ib_frmr_pool *pool)
 {
 	struct ib_frmr_pools *pools = device->frmr_pools;
 	u32 total, to_destroy, destroyed = 0;
 	bool has_work = false;
 	u32 *handles;
-	u32 handle;
 
 	spin_lock(&pool->lock);
 	total = pool->queue.ci + pool->inactive_queue.ci + pool->in_use;
@@ -112,7 +143,7 @@ static bool age_pinned_pool(struct ib_device *device, struct ib_frmr_pool *pool)
 		return false;
 	}
 
-	to_destroy = total - pool->pinned_handles;
+	to_destroy = min(total - pool->pinned_handles, pool->inactive_queue.ci);
 
 	handles = kcalloc(to_destroy, sizeof(*handles), GFP_ATOMIC);
 	if (!handles) {
@@ -121,15 +152,13 @@ static bool age_pinned_pool(struct ib_device *device, struct ib_frmr_pool *pool)
 	}
 
 	/* Destroy all excess handles in the inactive queue */
-	while (pool->inactive_queue.ci && destroyed < to_destroy) {
-		handles[destroyed++] = pop_handle_from_queue_locked(
+	for (; destroyed < to_destroy; destroyed++)
+		handles[destroyed] = pop_handle_from_queue_locked(
 			&pool->inactive_queue);
-	}
 
 	/* Move all handles from regular queue to inactive queue */
-	while (pool->queue.ci) {
-		handle = pop_handle_from_queue_locked(&pool->queue);
-		push_handle_to_queue_locked(&pool->inactive_queue, handle);
+	if (pool->queue.ci > 0) {
+		splice_frmr_queue_locked(&pool->inactive_queue, &pool->queue);
 		has_work = true;
 	}
 
@@ -158,13 +187,7 @@ static void pool_aging_work(struct work_struct *work)
 	/* Move all pages from regular queue to inactive queue */
 	spin_lock(&pool->lock);
 	if (pool->queue.ci > 0) {
-		list_splice_tail_init(&pool->queue.pages_list,
-				      &pool->inactive_queue.pages_list);
-		pool->inactive_queue.num_pages = pool->queue.num_pages;
-		pool->inactive_queue.ci = pool->queue.ci;
-
-		pool->queue.num_pages = 0;
-		pool->queue.ci = 0;
+		splice_frmr_queue_locked(&pool->inactive_queue, &pool->queue);
 		has_work = true;
 	}
 	spin_unlock(&pool->lock);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0690/2077] RDMA/core: Fix FRMR set pinned push error path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (688 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0689/2077] RDMA/core: Fix FRMR aging push to queue error flow Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0691/2077] RDMA/core: Avoid NULL dereference on FRMR bad usage Greg Kroah-Hartman
                   ` (307 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Guralnik, Tao Cui,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Guralnik <michaelgur@nvidia.com>

[ Upstream commit 41a707d0275cdec9ac125e826dd6836fa9623cbc ]

Add destruction of FRMR handles in case the push to the pool fails.
This prevents resources leak in case pool page allocation fails.

Fixes: 020d189d16a6 ("RDMA/core: Add pinned handles to FRMR pools")
Link: https://patch.msgid.link/r/20260610000145.820592-6-michaelgur@nvidia.com
Signed-off-by: Michael Guralnik <michaelgur@nvidia.com>
Reviewed-by: Tao Cui <cuitao@kylinos.cn>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/core/frmr_pools.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

diff --git a/drivers/infiniband/core/frmr_pools.c b/drivers/infiniband/core/frmr_pools.c
index 927642c06f3a4c..1cfdddc3fcdaf6 100644
--- a/drivers/infiniband/core/frmr_pools.c
+++ b/drivers/infiniband/core/frmr_pools.c
@@ -461,11 +461,16 @@ int ib_frmr_pools_set_pinned(struct ib_device *device, struct ib_frmr_key *key,
 		ret = push_handle_to_queue_locked(&pool->queue,
 						  handles[i]);
 		if (ret)
-			goto end;
+			break;
 	}
-
-end:
 	spin_unlock(&pool->lock);
+
+	if (ret) {
+		/* Destroy handles created but never pushed to the pool. */
+		pools->pool_ops->destroy_frmrs(device, &handles[i],
+				needed_handles - i);
+	}
+
 	kfree(handles);
 
 schedule_aging:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0691/2077] RDMA/core: Avoid NULL dereference on FRMR bad usage
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (689 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0690/2077] RDMA/core: Fix FRMR set pinned push error path Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0692/2077] RDMA/core: Fix FRMR handle leak on push failure Greg Kroah-Hartman
                   ` (306 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Guralnik, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Guralnik <michaelgur@nvidia.com>

[ Upstream commit 3937243095b5cfed6556bd1ea170790223f3eeb0 ]

In case a driver calls FRMR pop operation without a successful init,
return after triggering a warning to avoid the NULL dereference.

Fixes: ce5df0b891ed ("IB/core: Introduce FRMR pools")
Link: https://patch.msgid.link/r/20260610000145.820592-7-michaelgur@nvidia.com
Signed-off-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/core/frmr_pools.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/infiniband/core/frmr_pools.c b/drivers/infiniband/core/frmr_pools.c
index 1cfdddc3fcdaf6..892aedfe03bed4 100644
--- a/drivers/infiniband/core/frmr_pools.c
+++ b/drivers/infiniband/core/frmr_pools.c
@@ -529,7 +529,9 @@ int ib_frmr_pool_pop(struct ib_device *device, struct ib_mr *mr)
 	struct ib_frmr_pools *pools = device->frmr_pools;
 	struct ib_frmr_pool *pool;
 
-	WARN_ON_ONCE(!device->frmr_pools);
+	if (WARN_ON_ONCE(!pools))
+		return -EINVAL;
+
 	pool = ib_frmr_pool_find(pools, &mr->frmr.key);
 	if (!pool) {
 		pool = create_frmr_pool(device, &mr->frmr.key);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0692/2077] RDMA/core: Fix FRMR handle leak on push failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (690 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0691/2077] RDMA/core: Avoid NULL dereference on FRMR bad usage Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0693/2077] RDMA/core: Add ib_frmr_pool_drop for unrecoverable handles Greg Kroah-Hartman
                   ` (305 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Guralnik, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Guralnik <michaelgur@nvidia.com>

[ Upstream commit 8c76126b866649d8e8acc09a06f2b03b6ff88900 ]

Failure to push a handle to the pool, caused by ENOMEM on queue page
allocation, will trigger missing in_use counter update, skewing pool
state indefinitely.
Fix that by moving the handling of handle destruction in such case
into the FRMR code, ensuring the handle is either pushed to the pool
or destroyed inside the same function.

Adjust mlx5_ib call site accordingly.

Fixes: ce5df0b891ed ("IB/core: Introduce FRMR pools")
Link: https://patch.msgid.link/r/20260610000145.820592-8-michaelgur@nvidia.com
Signed-off-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/core/frmr_pools.c | 19 +++++++++++--------
 drivers/infiniband/hw/mlx5/mr.c      |  5 +++--
 include/rdma/frmr_pools.h            |  2 +-
 3 files changed, 15 insertions(+), 11 deletions(-)

diff --git a/drivers/infiniband/core/frmr_pools.c b/drivers/infiniband/core/frmr_pools.c
index 892aedfe03bed4..e214a8273df844 100644
--- a/drivers/infiniband/core/frmr_pools.c
+++ b/drivers/infiniband/core/frmr_pools.c
@@ -549,9 +549,8 @@ EXPORT_SYMBOL(ib_frmr_pool_pop);
  * @device: The device to push the FRMR handle to.
  * @mr: The MR containing the FRMR handle to push back to the pool.
  *
- * Returns 0 on success, negative error code on failure.
  */
-int ib_frmr_pool_push(struct ib_device *device, struct ib_mr *mr)
+void ib_frmr_pool_push(struct ib_device *device, struct ib_mr *mr)
 {
 	struct ib_frmr_pool *pool = mr->frmr.pool;
 	struct ib_frmr_pools *pools = device->frmr_pools;
@@ -559,19 +558,23 @@ int ib_frmr_pool_push(struct ib_device *device, struct ib_mr *mr)
 	int ret;
 
 	spin_lock(&pool->lock);
+	pool->in_use--;
+	ret = push_handle_to_queue_locked(&pool->queue, mr->frmr.handle);
+
 	/* Schedule aging every time an empty pool becomes non-empty */
-	if (pool->queue.ci == 0)
+	if (!ret && pool->queue.ci == 1)
 		schedule_aging = true;
-	ret = push_handle_to_queue_locked(&pool->queue, mr->frmr.handle);
-	if (ret == 0)
-		pool->in_use--;
 
 	spin_unlock(&pool->lock);
 
-	if (ret == 0 && schedule_aging)
+	if (ret) {
+		pools->pool_ops->destroy_frmrs(device, &mr->frmr.handle, 1);
+		return;
+	}
+
+	if (schedule_aging)
 		queue_delayed_work(pools->aging_wq, &pool->aging_work,
 			secs_to_jiffies(READ_ONCE(pools->aging_period_sec)));
 
-	return ret;
 }
 EXPORT_SYMBOL(ib_frmr_pool_push);
diff --git a/drivers/infiniband/hw/mlx5/mr.c b/drivers/infiniband/hw/mlx5/mr.c
index 7fbb01371f1f77..723594efa094e6 100644
--- a/drivers/infiniband/hw/mlx5/mr.c
+++ b/drivers/infiniband/hw/mlx5/mr.c
@@ -1398,9 +1398,10 @@ static int mlx5r_handle_mkey_cleanup(struct mlx5_ib_mr *mr)
 	bool is_odp = is_odp_mr(mr);
 	int ret;
 
-	if (mr->ibmr.frmr.pool && !mlx5_umr_revoke_mr_with_lock(mr) &&
-	    !ib_frmr_pool_push(mr->ibmr.device, &mr->ibmr))
+	if (mr->ibmr.frmr.pool && !mlx5_umr_revoke_mr_with_lock(mr)) {
+		ib_frmr_pool_push(mr->ibmr.device, &mr->ibmr);
 		return 0;
+	}
 
 	if (is_odp)
 		mutex_lock(&to_ib_umem_odp(mr->umem)->umem_mutex);
diff --git a/include/rdma/frmr_pools.h b/include/rdma/frmr_pools.h
index af1b88801fa469..5b57bafa363669 100644
--- a/include/rdma/frmr_pools.h
+++ b/include/rdma/frmr_pools.h
@@ -34,6 +34,6 @@ int ib_frmr_pools_init(struct ib_device *device,
 		       const struct ib_frmr_pool_ops *pool_ops);
 void ib_frmr_pools_cleanup(struct ib_device *device);
 int ib_frmr_pool_pop(struct ib_device *device, struct ib_mr *mr);
-int ib_frmr_pool_push(struct ib_device *device, struct ib_mr *mr);
+void ib_frmr_pool_push(struct ib_device *device, struct ib_mr *mr);
 
 #endif /* FRMR_POOLS_H */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0693/2077] RDMA/core: Add ib_frmr_pool_drop for unrecoverable handles
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (691 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0692/2077] RDMA/core: Fix FRMR handle leak on push failure Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0694/2077] RDMA/mlx5: Drop FRMR pool handle on UMR revoke failure Greg Kroah-Hartman
                   ` (304 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Guralnik, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Guralnik <michaelgur@nvidia.com>

[ Upstream commit ddbc251be18fb82884ee6e9af634cc9f1171a4d6 ]

A driver that has popped a handle from an FRMR pool can hit failures
that leave the handle in a state where it can't safely be returned
for reuse. The driver destroys the handle itself, but the pool has
no way to learn about it, so the in_use counter drifts upward.

Add ib_frmr_pool_drop to balance the pool's accounting in this case.
Every pop is now balanced by exactly one push or drop.

Fixes: 36680ef7bceb ("RDMA/mlx5: Switch from MR cache to FRMR pools")
Link: https://patch.msgid.link/r/20260610000145.820592-9-michaelgur@nvidia.com
Signed-off-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/core/frmr_pools.c | 15 +++++++++++++++
 include/rdma/frmr_pools.h            |  1 +
 2 files changed, 16 insertions(+)

diff --git a/drivers/infiniband/core/frmr_pools.c b/drivers/infiniband/core/frmr_pools.c
index e214a8273df844..ce8ae4305b9c8f 100644
--- a/drivers/infiniband/core/frmr_pools.c
+++ b/drivers/infiniband/core/frmr_pools.c
@@ -578,3 +578,18 @@ void ib_frmr_pool_push(struct ib_device *device, struct ib_mr *mr)
 
 }
 EXPORT_SYMBOL(ib_frmr_pool_push);
+
+/*
+ * Drop a handle previously popped from the pool without returning it for
+ * reuse. The caller is responsible for destroying the underlying hardware
+ * resource.
+ */
+void ib_frmr_pool_drop(struct ib_mr *mr)
+{
+	struct ib_frmr_pool *pool = mr->frmr.pool;
+
+	spin_lock(&pool->lock);
+	pool->in_use--;
+	spin_unlock(&pool->lock);
+}
+EXPORT_SYMBOL(ib_frmr_pool_drop);
diff --git a/include/rdma/frmr_pools.h b/include/rdma/frmr_pools.h
index 5b57bafa363669..aed4d69d3841c4 100644
--- a/include/rdma/frmr_pools.h
+++ b/include/rdma/frmr_pools.h
@@ -35,5 +35,6 @@ int ib_frmr_pools_init(struct ib_device *device,
 void ib_frmr_pools_cleanup(struct ib_device *device);
 int ib_frmr_pool_pop(struct ib_device *device, struct ib_mr *mr);
 void ib_frmr_pool_push(struct ib_device *device, struct ib_mr *mr);
+void ib_frmr_pool_drop(struct ib_mr *mr);
 
 #endif /* FRMR_POOLS_H */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0694/2077] RDMA/mlx5: Drop FRMR pool handle on UMR revoke failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (692 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0693/2077] RDMA/core: Add ib_frmr_pool_drop for unrecoverable handles Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0695/2077] fs: efs: remove unneeded debug prints Greg Kroah-Hartman
                   ` (303 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Guralnik, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Guralnik <michaelgur@nvidia.com>

[ Upstream commit c37d79dd967d450ea02e0ee2b6438b8534bbd044 ]

When UMR revoke fails during MR cleanup, the handle is left in an
unknown state and cannot be returned to the pool. The driver already
destroys the mkey via the fallback path, but the pool's in_use counter
is never decremented, drifting upward over time.

Call ib_frmr_pool_drop on the revoke-failure path so the pool's
accounting stays consistent with the handles it has handed out.

Fixes: 36680ef7bceb ("RDMA/mlx5: Switch from MR cache to FRMR pools")
Link: https://patch.msgid.link/r/20260610000145.820592-10-michaelgur@nvidia.com
Signed-off-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/mr.c | 12 +++++++++---
 1 file changed, 9 insertions(+), 3 deletions(-)

diff --git a/drivers/infiniband/hw/mlx5/mr.c b/drivers/infiniband/hw/mlx5/mr.c
index 723594efa094e6..4118cd2d15fd55 100644
--- a/drivers/infiniband/hw/mlx5/mr.c
+++ b/drivers/infiniband/hw/mlx5/mr.c
@@ -1398,9 +1398,11 @@ static int mlx5r_handle_mkey_cleanup(struct mlx5_ib_mr *mr)
 	bool is_odp = is_odp_mr(mr);
 	int ret;
 
-	if (mr->ibmr.frmr.pool && !mlx5_umr_revoke_mr_with_lock(mr)) {
-		ib_frmr_pool_push(mr->ibmr.device, &mr->ibmr);
-		return 0;
+	if (mr->ibmr.frmr.pool) {
+		if (!mlx5_umr_revoke_mr_with_lock(mr)) {
+			ib_frmr_pool_push(mr->ibmr.device, &mr->ibmr);
+			return 0;
+		}
 	}
 
 	if (is_odp)
@@ -1422,6 +1424,10 @@ static int mlx5r_handle_mkey_cleanup(struct mlx5_ib_mr *mr)
 		dma_resv_unlock(
 			to_ib_umem_dmabuf(mr->umem)->attach->dmabuf->resv);
 	}
+
+	if (mr->ibmr.frmr.pool && !ret)
+		ib_frmr_pool_drop(&mr->ibmr);
+
 	return ret;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0695/2077] fs: efs: remove unneeded debug prints
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (693 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0694/2077] RDMA/mlx5: Drop FRMR pool handle on UMR revoke failure Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0696/2077] RDMA/mlx5: Remove DCT restrack tracking Greg Kroah-Hartman
                   ` (302 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Maxwell Doose, Andrew Morton,
	Fabian Frederick, Christian Brauner, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Maxwell Doose <m32285159@gmail.com>

[ Upstream commit 89009392c80da5da00876c8334ff20028e6e3eb6 ]

The current code uses debug prints conditionally compiled with #ifdef
DEBUG.  However, that code, when compiled, causes compiler errors due to
incompatible formatters and undefined variables, notably:

fs/efs/file.c: In function `efs_get_block':
fs/efs/file.c:26:35: error: `block' undeclared (first use in this
function); did you mean `iblock'?
  26 |                         __func__, block, inode->i_blocks, inode->i_size);
     |                                   ^~~~~

and:

fs/efs/file.c: In function `efs_bmap':
./include/linux/kern_levels.h:5:25: error: format `%ld' expects
argument of type `long int', but argument 4 has type `blkcnt_t' {aka
`long long unsigned int'} [-Werror=format=]
   5 | #define KERN_SOH        "\001"          /* ASCII Start Of Header */
     |                         ^~~~~~

which also extends to the other formatters.  As this part of the code has
been dead for just about 14 years now, it has not been modernized to stay
compatible with the most recent gcc compilers.  Fix these issues by
removing the debug prints.

Link: https://lore.kernel.org/20260605035251.89305-2-m32285159@gmail.com
Fixes: f403d1dbac6d ("fs/efs: add pr_fmt / use __func__")
Signed-off-by: Maxwell Doose <m32285159@gmail.com>
Suggested-by: Andrew Morton <akpm@linux-foundation.org>
Cc: Fabian Frederick <fabf@skynet.be>
Cc: Christian Brauner <brauner@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/efs/file.c | 21 +++------------------
 1 file changed, 3 insertions(+), 18 deletions(-)

diff --git a/fs/efs/file.c b/fs/efs/file.c
index 9e641da6fab276..9153dfe79bbcc9 100644
--- a/fs/efs/file.c
+++ b/fs/efs/file.c
@@ -18,16 +18,9 @@ int efs_get_block(struct inode *inode, sector_t iblock,
 
 	if (create)
 		return error;
-	if (iblock >= inode->i_blocks) {
-#ifdef DEBUG
-		/*
-		 * i have no idea why this happens as often as it does
-		 */
-		pr_warn("%s(): block %d >= %ld (filesize %ld)\n",
-			__func__, block, inode->i_blocks, inode->i_size);
-#endif
+	if (iblock >= inode->i_blocks)
 		return 0;
-	}
+
 	phys = efs_map_block(inode, iblock);
 	if (phys)
 		map_bh(bh_result, inode->i_sb, phys);
@@ -42,16 +35,8 @@ int efs_bmap(struct inode *inode, efs_block_t block) {
 	}
 
 	/* are we about to read past the end of a file ? */
-	if (!(block < inode->i_blocks)) {
-#ifdef DEBUG
-		/*
-		 * i have no idea why this happens as often as it does
-		 */
-		pr_warn("%s(): block %d >= %ld (filesize %ld)\n",
-			__func__, block, inode->i_blocks, inode->i_size);
-#endif
+	if (!(block < inode->i_blocks))
 		return 0;
-	}
 
 	return efs_map_block(inode, block);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0696/2077] RDMA/mlx5: Remove DCT restrack tracking
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (694 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0695/2077] fs: efs: remove unneeded debug prints Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0697/2077] RDMA/mlx5: Remove raw RSS QP " Greg Kroah-Hartman
                   ` (301 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Patrisious Haddad, Michael Guralnik,
	Edward Srouji, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Patrisious Haddad <phaddad@nvidia.com>

[ Upstream commit b136a7af41f796a48665afc6a55907488a3d5500 ]

DCT restrack tracking wasn't working to begin with as it was only
tracking the first DCT which was added, since at creation the DCT number
isn't yet initialized because the DCT FW object is only created during
modify. The following DCT additions were failing silently.

Since the fix isn't trivial and there were no users that required or
complained about this issue we are dropping this for now instead of fixing.

Fixes: fd3af5e21866 ("RDMA/mlx5: Track DCT, DCI and REG_UMR QPs as diver_detail resources.")
Link: https://patch.msgid.link/r/20260607-restrack-uaf-fix-v1-1-d72e45eb76c2@nvidia.com
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/qp.c       | 1 +
 drivers/infiniband/hw/mlx5/restrack.c | 3 ---
 2 files changed, 1 insertion(+), 3 deletions(-)

diff --git a/drivers/infiniband/hw/mlx5/qp.c b/drivers/infiniband/hw/mlx5/qp.c
index 8fd05532c09cc7..7f8cd69905a42f 100644
--- a/drivers/infiniband/hw/mlx5/qp.c
+++ b/drivers/infiniband/hw/mlx5/qp.c
@@ -3115,6 +3115,7 @@ static int create_qp(struct mlx5_ib_dev *dev, struct ib_pd *pd,
 
 	switch (qp->type) {
 	case MLX5_IB_QPT_DCT:
+		rdma_restrack_no_track(&qp->ibqp.res);
 		err = create_dct(dev, pd, qp, params);
 		break;
 	case MLX5_IB_QPT_DCI:
diff --git a/drivers/infiniband/hw/mlx5/restrack.c b/drivers/infiniband/hw/mlx5/restrack.c
index 67841922c7b877..00a9bcb2603f0b 100644
--- a/drivers/infiniband/hw/mlx5/restrack.c
+++ b/drivers/infiniband/hw/mlx5/restrack.c
@@ -178,9 +178,6 @@ static int fill_res_qp_entry(struct sk_buff *msg, struct ib_qp *ibqp)
 		ret = nla_put_string(msg, RDMA_NLDEV_ATTR_RES_SUBTYPE,
 				     "REG_UMR");
 		break;
-	case MLX5_IB_QPT_DCT:
-		ret = nla_put_string(msg, RDMA_NLDEV_ATTR_RES_SUBTYPE, "DCT");
-		break;
 	case MLX5_IB_QPT_DCI:
 		ret = nla_put_string(msg, RDMA_NLDEV_ATTR_RES_SUBTYPE, "DCI");
 		break;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0697/2077] RDMA/mlx5: Remove raw RSS QP restrack tracking
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (695 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0696/2077] RDMA/mlx5: Remove DCT restrack tracking Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0698/2077] RDMA/mlx5: Fix undefined shift of user RQ WQE size Greg Kroah-Hartman
                   ` (300 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Patrisious Haddad, Michael Guralnik,
	Edward Srouji, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Patrisious Haddad <phaddad@nvidia.com>

[ Upstream commit 666031fed8f0fdfc29b20d125a628c1b0a04cdaf ]

Raw RSS QP restrack tracking wasn't working to begin with as it was
only tracking the first raw RSS QP which was added, since at creation
the raw RSS QP number is reserved so the QP number for this qp type
was always zero.
The following raw RSS QP additions were always failing silently.

Since the fix isn't trivial and there were no users that required or
complained about this issue we are dropping this for now instead of fixing.

Fixes: 968f0b6f9c01 ("RDMA/mlx5: Consolidate into special function all create QP calls")
Link: https://patch.msgid.link/r/20260607-restrack-uaf-fix-v1-2-d72e45eb76c2@nvidia.com
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/qp.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/infiniband/hw/mlx5/qp.c b/drivers/infiniband/hw/mlx5/qp.c
index 7f8cd69905a42f..767444bcbce5d2 100644
--- a/drivers/infiniband/hw/mlx5/qp.c
+++ b/drivers/infiniband/hw/mlx5/qp.c
@@ -3109,6 +3109,7 @@ static int create_qp(struct mlx5_ib_dev *dev, struct ib_pd *pd,
 	int err;
 
 	if (params->is_rss_raw) {
+		rdma_restrack_no_track(&qp->ibqp.res);
 		err = create_rss_raw_qp_tir(dev, pd, qp, params);
 		goto out;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0698/2077] RDMA/mlx5: Fix undefined shift of user RQ WQE size
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (696 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0697/2077] RDMA/mlx5: Remove raw RSS QP " Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0699/2077] RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one Greg Kroah-Hartman
                   ` (299 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Maher Sanalla, Edward Srouji,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Maher Sanalla <msanalla@nvidia.com>

[ Upstream commit d881d60223aac8fdc12b227d89c76e131e92a9cd ]

set_rq_size() computes the RQ WQE size as "1 << rq_wqe_shift" based on
the user-provided rq_wqe_shift, which is only checked to be greater than
32, so shifts of 32 are still accepted. A shift of 31 also overflows a
signed integer, leading to undefined behavior.

Use check_shl_overflow() to compute the RQ WQE size and reject any
invalid values.

Fixes: e126ba97dba9 ("mlx5: Add driver for Mellanox Connect-IB adapters")
Link: https://patch.msgid.link/r/20260611-maher-sec-fixes-v1-1-cd8eb2542869@nvidia.com
Signed-off-by: Maher Sanalla <msanalla@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/qp.c | 11 ++++-------
 1 file changed, 4 insertions(+), 7 deletions(-)

diff --git a/drivers/infiniband/hw/mlx5/qp.c b/drivers/infiniband/hw/mlx5/qp.c
index 767444bcbce5d2..3dc0c85587fffd 100644
--- a/drivers/infiniband/hw/mlx5/qp.c
+++ b/drivers/infiniband/hw/mlx5/qp.c
@@ -451,16 +451,13 @@ static int set_rq_size(struct mlx5_ib_dev *dev, struct ib_qp_cap *cap,
 
 		if (ucmd) {
 			qp->rq.wqe_cnt = ucmd->rq_wqe_count;
-			if (ucmd->rq_wqe_shift > BITS_PER_BYTE * sizeof(ucmd->rq_wqe_shift))
-				return -EINVAL;
 			qp->rq.wqe_shift = ucmd->rq_wqe_shift;
-			if ((1 << qp->rq.wqe_shift) /
-				    sizeof(struct mlx5_wqe_data_seg) <
-			    wq_sig)
+			if (check_shl_overflow(1, qp->rq.wqe_shift, &wqe_size))
+				return -EINVAL;
+			if (wqe_size / sizeof(struct mlx5_wqe_data_seg) < wq_sig)
 				return -EINVAL;
 			qp->rq.max_gs =
-				(1 << qp->rq.wqe_shift) /
-					sizeof(struct mlx5_wqe_data_seg) -
+				wqe_size / sizeof(struct mlx5_wqe_data_seg) -
 				wq_sig;
 			qp->rq.max_post = qp->rq.wqe_cnt;
 		} else {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0699/2077] RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (697 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0698/2077] RDMA/mlx5: Fix undefined shift of user RQ WQE size Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0700/2077] ASoC: cs35l56: Fix wrong error test on simple_write_to_buffer() Greg Kroah-Hartman
                   ` (298 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leon Romanovsky <leonro@nvidia.com>

[ Upstream commit 449ae7927152e46acbe5f19f97eafdae6d3a96b1 ]

Free the UAR index returned by the hardware.

Fixes: 4ed131d0bb15 ("IB/mlx5: Expose dynamic mmap allocation")
Link: https://patch.msgid.link/r/20260611-fix-uar-release-v1-1-f5464d845dbf@nvidia.com
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/mlx5/main.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/mlx5/main.c b/drivers/infiniband/hw/mlx5/main.c
index aa2eb64ecf15e6..1144bfee58048d 100644
--- a/drivers/infiniband/hw/mlx5/main.c
+++ b/drivers/infiniband/hw/mlx5/main.c
@@ -2662,7 +2662,7 @@ static int uar_mmap(struct mlx5_ib_dev *dev, enum mlx5_ib_mmap_cmd cmd,
 	if (!dyn_uar)
 		return err;
 
-	mlx5_cmd_uar_dealloc(dev->mdev, idx, context->devx_uid);
+	mlx5_cmd_uar_dealloc(dev->mdev, uar_index, context->devx_uid);
 
 free_bfreg:
 	mlx5_ib_free_bfreg(dev, bfregi, bfreg_dyn_idx);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0700/2077] ASoC: cs35l56: Fix wrong error test on simple_write_to_buffer()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (698 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0699/2077] RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0701/2077] ASoC: SOF: Intel: select SND_SOC_SDW_UTILS=y from SND_SOC_SOF_HDA_GENERIC=y Greg Kroah-Hartman
                   ` (297 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Richard Fitzgerald,
	Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Fitzgerald <rf@opensource.cirrus.com>

[ Upstream commit 3073eb1f1143deabbda6a043238ab9d99672e7c8 ]

In cs35l56_cal_data_debugfs_write() fix the if statement that checks for
error return to only check for negative values.

Reported by Sashiko:

  simple_write_to_buffer() returns the positive number of bytes copied
  on success. Since the condition returns immediately on any non-zero
  value, is it possible that the written calibration data is discarded
  and cs35l56_stash_calibration() is never called?

Fixes: f7097161e94c ("ASoC: cs35l56: Add common code for factory calibration")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260610093432.557375-1-rf%40opensource.cirrus.com
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260611151234.1111153-1-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/codecs/cs35l56-shared.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/soc/codecs/cs35l56-shared.c b/sound/soc/codecs/cs35l56-shared.c
index 5405f70b7119d8..9928608296d881 100644
--- a/sound/soc/codecs/cs35l56-shared.c
+++ b/sound/soc/codecs/cs35l56-shared.c
@@ -1260,7 +1260,7 @@ ssize_t cs35l56_cal_data_debugfs_write(struct cs35l56_base *cs35l56_base,
 		return -EMSGSIZE;
 
 	ret = simple_write_to_buffer(&cal_data, sizeof(cal_data), ppos, from, count);
-	if (ret)
+	if (ret < 0)
 		return ret;
 
 	ret = cs35l56_stash_calibration(cs35l56_base, &cal_data);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0701/2077] ASoC: SOF: Intel: select SND_SOC_SDW_UTILS=y from SND_SOC_SOF_HDA_GENERIC=y
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (699 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0700/2077] ASoC: cs35l56: Fix wrong error test on simple_write_to_buffer() Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0702/2077] ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly Greg Kroah-Hartman
                   ` (296 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Julian Braha,
	Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

[ Upstream commit 67805f57e5b1a8589f89bd48936c65cbbaeec300 ]

When SND_SOC_SOF_HDA_GENERIC=y but SND_SOC_SOF_INTEL_SOUNDWIRE=m, the
SND_SOC_SDW_UTILS is also set to =m even though there is a direct link
dependency from the hda.c:

aarch64-linux-ld: sound/soc/sof/intel/hda.o: in function `hda_machine_select':
hda.c:(.text+0x21ac): undefined reference to `codec_info_list'
hda.c:(.text+0x241c): undefined reference to `asoc_sdw_get_dai_type'
hda.c:(.text+0x25b4): undefined reference to `asoc_sdw_get_codec_info_list_count'
hda.c:(.text+0x25d8): undefined reference to `asoc_sdw_get_codec_info_list_count'

Change this the same way as the other related 'select' statements
to allow linking against it.

Fixes: 2b4d53eb5cf3 ("ASoC: SOF: Intel: select SND_SOC_SDW_UTILS in SND_SOC_SOF_HDA_GENERIC")
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Tested-by: Julian Braha <julianbraha@gmail.com>
Link: https://patch.msgid.link/20260611132310.137688-1-arnd@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/sof/intel/Kconfig | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/soc/sof/intel/Kconfig b/sound/soc/sof/intel/Kconfig
index e31f4c4061d80e..9ddf14e7946aab 100644
--- a/sound/soc/sof/intel/Kconfig
+++ b/sound/soc/sof/intel/Kconfig
@@ -329,7 +329,7 @@ config SND_SOC_SOF_HDA_GENERIC
 	select SND_INTEL_DSP_CONFIG
 	select SND_SOC_SOF_HDA_LINK_BASELINE
 	select SND_SOC_SOF_HDA_PROBES
-	select SND_SOC_SDW_UTILS if SND_SOC_SOF_INTEL_SOUNDWIRE
+	select SND_SOC_SDW_UTILS if SND_SOC_SOF_INTEL_SOUNDWIRE !=n
 	select SND_SOC_SOF_HDA_MLINK if SND_SOC_SOF_HDA_LINK
 	help
 	  This option is not user-selectable but automagically handled by
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0702/2077] ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (700 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0701/2077] ASoC: SOF: Intel: select SND_SOC_SDW_UTILS=y from SND_SOC_SOF_HDA_GENERIC=y Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0703/2077] ASoC: codecs: hdac_hdmi: Validate written enum value Greg Kroah-Hartman
                   ` (295 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

[ Upstream commit 999ec4c29d73ac85b639a31bbc85ad2ec00eb9d7 ]

When SND_SOC_SOF_INTEL_LNL is set, SND_SOF_SOF_HDA_SDW_BPT must also
be enabled, in order to let the soundwire support call into it.

However, there are configurations with SND_SOF_SOF_HDA_SDW_BPT=m
and SND_SOF_SOF_HDA_SDW_BPT=m but SOUNDWIRE_INTEL=y, which still
lead to a link failure:

aarch64-linux-ld: drivers/soundwire/intel_ace2x.o: in function `intel_ace2x_bpt_wait':
intel_ace2x.c:(.text+0xfc8): undefined reference to `hda_sdw_bpt_wait'
aarch64-linux-ld: drivers/soundwire/intel_ace2x.o: in function `intel_ace2x_bpt_send_async':
intel_ace2x.c:(.text+0x1ff8): undefined reference to `hda_sdw_bpt_get_buf_size_alignment'

Address this by moving the 'select SND_SOF_SOF_HDA_SDW_BPT' into
SND_SOC_SOF_HDA_GENERIC.

Fixes: 614d416dd8ae ("ASoC: SOF: Intel: hda-sdw-bpt: fix SND_SOF_SOF_HDA_SDW_BPT dependencies")
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Link: https://patch.msgid.link/20260611132310.137688-2-arnd@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/sof/intel/Kconfig | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/sound/soc/sof/intel/Kconfig b/sound/soc/sof/intel/Kconfig
index 9ddf14e7946aab..915abbef398d54 100644
--- a/sound/soc/sof/intel/Kconfig
+++ b/sound/soc/sof/intel/Kconfig
@@ -266,10 +266,8 @@ config SND_SOC_SOF_METEORLAKE
 
 config SND_SOC_SOF_INTEL_LNL
 	tristate
-	select SOUNDWIRE_INTEL if SND_SOC_SOF_INTEL_SOUNDWIRE != n
 	select SND_SOC_SOF_HDA_GENERIC
 	select SND_SOC_SOF_INTEL_SOUNDWIRE_LINK_BASELINE
-	select SND_SOF_SOF_HDA_SDW_BPT if SND_SOC_SOF_INTEL_SOUNDWIRE != n
 	select SND_SOC_SOF_IPC4
 	select SND_SOC_SOF_INTEL_MTL
 
@@ -331,6 +329,8 @@ config SND_SOC_SOF_HDA_GENERIC
 	select SND_SOC_SOF_HDA_PROBES
 	select SND_SOC_SDW_UTILS if SND_SOC_SOF_INTEL_SOUNDWIRE !=n
 	select SND_SOC_SOF_HDA_MLINK if SND_SOC_SOF_HDA_LINK
+	select SND_SOF_SOF_HDA_SDW_BPT if SND_SOC_SOF_INTEL_LNL != n && \
+					  SND_SOC_SOF_INTEL_SOUNDWIRE !=n
 	help
 	  This option is not user-selectable but automagically handled by
 	  'select' statements at a higher level.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0703/2077] ASoC: codecs: hdac_hdmi: Validate written enum value
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (701 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0702/2077] ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0704/2077] ASoC: meson: aiu: Validate written enum values Greg Kroah-Hartman
                   ` (294 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: HyeongJun An <sammiee5311@gmail.com>

[ Upstream commit 0b08baeccdcf52fad328ad645f5b4fbee04eea34 ]

hdac_hdmi_set_pin_port_mux() uses the written enum value to index the
texts array before calling snd_soc_dapm_put_enum_double(), which validates
that the value is within the enum item range.

An out-of-range value can therefore make the driver read past the texts
array before the helper rejects the write. Move the lookup after the helper
has accepted the value.

Fixes: 4a3478debf36 ("ASoC: hdac_hdmi: Add jack reporting")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Link: https://patch.msgid.link/20260609124317.38046-2-sammiee5311@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/codecs/hdac_hdmi.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/sound/soc/codecs/hdac_hdmi.c b/sound/soc/codecs/hdac_hdmi.c
index 2652fcf2a3a345..3220f9226e0b26 100644
--- a/sound/soc/codecs/hdac_hdmi.c
+++ b/sound/soc/codecs/hdac_hdmi.c
@@ -911,12 +911,14 @@ static int hdac_hdmi_set_pin_port_mux(struct snd_kcontrol *kcontrol,
 	struct hdac_device *hdev = dev_to_hdac_dev(dev);
 	struct hdac_hdmi_priv *hdmi = hdev_to_hdmi_priv(hdev);
 	struct hdac_hdmi_pcm *pcm;
-	const char *cvt_name =  e->texts[ucontrol->value.enumerated.item[0]];
+	const char *cvt_name;
 
 	ret = snd_soc_dapm_put_enum_double(kcontrol, ucontrol);
 	if (ret < 0)
 		return ret;
 
+	cvt_name = e->texts[ucontrol->value.enumerated.item[0]];
+
 	if (port == NULL)
 		return -EINVAL;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0704/2077] ASoC: meson: aiu: Validate written enum values
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (702 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0703/2077] ASoC: codecs: hdac_hdmi: Validate written enum value Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0705/2077] ASoC: fsl: fsl_audmix: " Greg Kroah-Hartman
                   ` (293 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: HyeongJun An <sammiee5311@gmail.com>

[ Upstream commit d65adf85477247be04ac86886f8edfaa047b5d4a ]

The AIU HDMI and internal codec mux put callbacks use the written enum
value with snd_soc_enum_item_to_val() before checking whether the value is
valid for the enumeration.

Reject out-of-range values before converting the enum item, matching the
validation already done by the G12A HDMI and internal codec mux controls.

Fixes: b82b734c0e9a ("ASoC: meson: aiu: add hdmi codec control support")
Fixes: 65816025d461 ("ASoC: meson: aiu: add internal dac codec control support")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Link: https://patch.msgid.link/20260609124317.38046-3-sammiee5311@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/meson/aiu-acodec-ctrl.c | 3 +++
 sound/soc/meson/aiu-codec-ctrl.c  | 3 +++
 2 files changed, 6 insertions(+)

diff --git a/sound/soc/meson/aiu-acodec-ctrl.c b/sound/soc/meson/aiu-acodec-ctrl.c
index 483772ba69cd7c..94c5d65335233f 100644
--- a/sound/soc/meson/aiu-acodec-ctrl.c
+++ b/sound/soc/meson/aiu-acodec-ctrl.c
@@ -36,6 +36,9 @@ static int aiu_acodec_ctrl_mux_put_enum(struct snd_kcontrol *kcontrol,
 	struct soc_enum *e = (struct soc_enum *)kcontrol->private_value;
 	unsigned int mux, changed;
 
+	if (ucontrol->value.enumerated.item[0] >= e->items)
+		return -EINVAL;
+
 	mux = snd_soc_enum_item_to_val(e, ucontrol->value.enumerated.item[0]);
 	changed = snd_soc_component_test_bits(component, e->reg,
 					      CTRL_DIN_LRCLK_SRC,
diff --git a/sound/soc/meson/aiu-codec-ctrl.c b/sound/soc/meson/aiu-codec-ctrl.c
index 396f815077e291..60bb4cdfee5201 100644
--- a/sound/soc/meson/aiu-codec-ctrl.c
+++ b/sound/soc/meson/aiu-codec-ctrl.c
@@ -28,6 +28,9 @@ static int aiu_codec_ctrl_mux_put_enum(struct snd_kcontrol *kcontrol,
 	struct soc_enum *e = (struct soc_enum *)kcontrol->private_value;
 	unsigned int mux, changed;
 
+	if (ucontrol->value.enumerated.item[0] >= e->items)
+		return -EINVAL;
+
 	mux = snd_soc_enum_item_to_val(e, ucontrol->value.enumerated.item[0]);
 	changed = snd_soc_component_test_bits(component, e->reg,
 					      CTRL_DATA_SEL,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0705/2077] ASoC: fsl: fsl_audmix: Validate written enum values
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (703 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0704/2077] ASoC: meson: aiu: Validate written enum values Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0706/2077] ASoC: tegra: tegra210_ahub: Validate written enum value Greg Kroah-Hartman
                   ` (292 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: HyeongJun An <sammiee5311@gmail.com>

[ Upstream commit 3cd17e4e2871114d5579fa7bc8da66faf7fc1930 ]

fsl_audmix_put_mix_clk_src() and fsl_audmix_put_out_src()
convert the user-provided enum item with snd_soc_enum_item_to_val()
before checking whether the item is within the enum's item count.

The generic snd_soc_put_enum_double() helper performs that
validation, but these callbacks use the converted value first: the
clock-source path tests it with BIT(), and the output-source path
indexes the prms transition table with it.

Reject out-of-range enum items before converting them.

Fixes: be1df61cf06e ("ASoC: fsl: Add Audio Mixer CPU DAI driver")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Link: https://patch.msgid.link/20260609124317.38046-4-sammiee5311@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/fsl/fsl_audmix.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/sound/soc/fsl/fsl_audmix.c b/sound/soc/fsl/fsl_audmix.c
index 40a3b743217442..f819f33ec46b84 100644
--- a/sound/soc/fsl/fsl_audmix.c
+++ b/sound/soc/fsl/fsl_audmix.c
@@ -117,6 +117,9 @@ static int fsl_audmix_put_mix_clk_src(struct snd_kcontrol *kcontrol,
 	unsigned int *item = ucontrol->value.enumerated.item;
 	unsigned int reg_val, val, mix_clk;
 
+	if (item[0] >= e->items)
+		return -EINVAL;
+
 	/* Get current state */
 	reg_val = snd_soc_component_read(comp, FSL_AUDMIX_CTR);
 	mix_clk = ((reg_val & FSL_AUDMIX_CTR_MIXCLK_MASK)
@@ -157,6 +160,9 @@ static int fsl_audmix_put_out_src(struct snd_kcontrol *kcontrol,
 	unsigned int reg_val, val, mask = 0, ctr = 0;
 	int ret;
 
+	if (item[0] >= e->items)
+		return -EINVAL;
+
 	/* Get current state */
 	reg_val = snd_soc_component_read(comp, FSL_AUDMIX_CTR);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0706/2077] ASoC: tegra: tegra210_ahub: Validate written enum value
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (704 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0705/2077] ASoC: fsl: fsl_audmix: " Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0707/2077] ASoC: topology: Check PCM and DAI name strings before use Greg Kroah-Hartman
                   ` (291 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: HyeongJun An <sammiee5311@gmail.com>

[ Upstream commit 1d8aabb413b5638670dfd1162169edc0ba276a2e ]

tegra_ahub_put_value_enum() reads e->values[item[0]] before
checking whether item[0] is within the enum item range. The existing
check therefore happens too late to prevent an out-of-range read of the
values array.

Move the check before the array access.

Fixes: 16e1bcc2caf4 ("ASoC: tegra: Add Tegra210 based AHUB driver")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Link: https://patch.msgid.link/20260609124317.38046-5-sammiee5311@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/tegra/tegra210_ahub.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/sound/soc/tegra/tegra210_ahub.c b/sound/soc/tegra/tegra210_ahub.c
index ece33b7ff190ac..efc8f338866828 100644
--- a/sound/soc/tegra/tegra210_ahub.c
+++ b/sound/soc/tegra/tegra210_ahub.c
@@ -62,13 +62,15 @@ static int tegra_ahub_put_value_enum(struct snd_kcontrol *kctl,
 	struct snd_soc_dapm_update update[TEGRA_XBAR_UPDATE_MAX_REG] = { };
 	int val_bytes = snd_soc_component_regmap_val_bytes(cmpnt);
 	unsigned int *item = uctl->value.enumerated.item;
-	unsigned int value = e->values[item[0]];
+	unsigned int value;
 	unsigned int i, bit_pos, reg_idx = 0, reg_val = 0;
 	int change = 0;
 
 	if (item[0] >= e->items)
 		return -EINVAL;
 
+	value = e->values[item[0]];
+
 	if (value) {
 		/* Get the register index and value to set */
 		reg_idx = (value - 1) / (8 * val_bytes);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0707/2077] ASoC: topology: Check PCM and DAI name strings before use
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (705 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0706/2077] ASoC: tegra: tegra210_ahub: Validate written enum value Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0708/2077] net: dsa: qca8k: fix led devicename when using external mdio bus Greg Kroah-Hartman
                   ` (290 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cássio Gabriel <cassiogabrielcontato@gmail.com>

[ Upstream commit b7e44d1986d6671342c19b82192189ca5db5dab7 ]

Topology objects store several PCM and DAI names in fixed-size UAPI
arrays. Other topology parser paths validate these fields with bounded
strnlen() checks before using them as C strings, but the PCM and DAI
paths still pass some fixed-size arrays directly to strlen(),
devm_kstrdup(), DAI lookup, and diagnostic prints.

A malformed topology blob with a non-NUL-terminated PCM, DAI, or stream
capability name can therefore make the parser read past the end of the
fixed-size field.

Reject unterminated PCM and DAI name fields before consuming them as C
strings.

Fixes: 64527e8a3529 ("ASoC: topology: Add FE DAIs dynamically")
Fixes: acfc7d46cddc ("ASoC: topology: Add FE DAI links dynamically")
Fixes: 0038be9a84dc ("ASoC: topology: Add support for configuring existing BE DAIs")
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260604-asoc-topology-check-pcm-dai-names-v1-1-e1b0f6f7c2ce@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/soc-topology.c | 37 ++++++++++++++++++++++++++++++++++---
 1 file changed, 34 insertions(+), 3 deletions(-)

diff --git a/sound/soc/soc-topology.c b/sound/soc/soc-topology.c
index 85679c8e022999..35cbe29d227589 100644
--- a/sound/soc/soc-topology.c
+++ b/sound/soc/soc-topology.c
@@ -1326,9 +1326,24 @@ static int soc_tplg_dapm_complete(struct soc_tplg *tplg)
 	return ret;
 }
 
+static int soc_tplg_check_name(const char *name)
+{
+	if (strnlen(name, SNDRV_CTL_ELEM_ID_NAME_MAXLEN) ==
+	    SNDRV_CTL_ELEM_ID_NAME_MAXLEN)
+		return -EINVAL;
+
+	return 0;
+}
+
 static int set_stream_info(struct soc_tplg *tplg, struct snd_soc_pcm_stream *stream,
 			   struct snd_soc_tplg_stream_caps *caps)
 {
+	int ret;
+
+	ret = soc_tplg_check_name(caps->name);
+	if (ret)
+		return ret;
+
 	stream->stream_name = devm_kstrdup(tplg->dev, caps->name, GFP_KERNEL);
 	if (!stream->stream_name)
 		return -ENOMEM;
@@ -1380,7 +1395,11 @@ static int soc_tplg_dai_create(struct soc_tplg *tplg,
 	if (dai_drv == NULL)
 		return -ENOMEM;
 
-	if (strlen(pcm->dai_name)) {
+	ret = soc_tplg_check_name(pcm->dai_name);
+	if (ret)
+		goto err;
+
+	if (pcm->dai_name[0]) {
 		dai_drv->name = devm_kstrdup(tplg->dev, pcm->dai_name, GFP_KERNEL);
 		if (!dai_drv->name) {
 			ret = -ENOMEM;
@@ -1486,7 +1505,11 @@ static int soc_tplg_fe_link_create(struct soc_tplg *tplg,
 	if (tplg->ops)
 		link->dobj.unload = tplg->ops->link_unload;
 
-	if (strlen(pcm->pcm_name)) {
+	ret = soc_tplg_check_name(pcm->pcm_name);
+	if (ret)
+		goto err;
+
+	if (pcm->pcm_name[0]) {
 		link->name = devm_kstrdup(tplg->dev, pcm->pcm_name, GFP_KERNEL);
 		link->stream_name = devm_kstrdup(tplg->dev, pcm->pcm_name, GFP_KERNEL);
 		if (!link->name || !link->stream_name) {
@@ -1496,7 +1519,11 @@ static int soc_tplg_fe_link_create(struct soc_tplg *tplg,
 	}
 	link->id = le32_to_cpu(pcm->pcm_id);
 
-	if (strlen(pcm->dai_name)) {
+	ret = soc_tplg_check_name(pcm->dai_name);
+	if (ret)
+		goto err;
+
+	if (pcm->dai_name[0]) {
 		link->cpus->dai_name = devm_kstrdup(tplg->dev, pcm->dai_name, GFP_KERNEL);
 		if (!link->cpus->dai_name) {
 			ret = -ENOMEM;
@@ -1848,6 +1875,10 @@ static int soc_tplg_dai_config(struct soc_tplg *tplg,
 
 	memset(&dai_component, 0, sizeof(dai_component));
 
+	ret = soc_tplg_check_name(d->dai_name);
+	if (ret)
+		return ret;
+
 	dai_component.dai_name = d->dai_name;
 	dai = snd_soc_find_dai(&dai_component);
 	if (!dai) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0708/2077] net: dsa: qca8k: fix led devicename when using external mdio bus
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (706 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0707/2077] ASoC: topology: Check PCM and DAI name strings before use Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0709/2077] net/sched: cls_flow: Dont expose folded kernel pointers Greg Kroah-Hartman
                   ` (289 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, George Moussalem, Andrew Lunn,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: George Moussalem <george.moussalem@outlook.com>

[ Upstream commit 0b7b378ce6cafbb948786cb6f17f406d94016c8c ]

The qca8k dsa switch can use either an external or internal mdio bus.
This depends on whether the mdio node is defined under the switch node
itself. Upon registering the internal mdio bus, the internal_mdio_bus
of the dsa switch is assigned to this bus. When an external mdio bus is
used, the driver still uses the internal_mdio_bus id which is used to
create the device names of the leds.
This leads to the leds being prefixed with '(efault)' as the
internal_mii_bus is null. So let's fix this by adding a null check and
use the devicename of the external bus instead when an external bus is
configured.

Fixes: 1e264f9d2918 ("net: dsa: qca8k: add LEDs basic support")
Signed-off-by: George Moussalem <george.moussalem@outlook.com>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Link: https://patch.msgid.link/20260608-qca8k-leds-fix-v3-1-a915bb2f37ae@outlook.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/dsa/qca/qca8k-leds.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/dsa/qca/qca8k-leds.c b/drivers/net/dsa/qca/qca8k-leds.c
index 43ac68052baf9f..ef496e345a4e7d 100644
--- a/drivers/net/dsa/qca/qca8k-leds.c
+++ b/drivers/net/dsa/qca/qca8k-leds.c
@@ -429,7 +429,8 @@ qca8k_parse_port_leds(struct qca8k_priv *priv, struct fwnode_handle *port, int p
 		init_data.fwnode = led;
 		init_data.devname_mandatory = true;
 		init_data.devicename = kasprintf(GFP_KERNEL, "%s:0%d",
-						 priv->internal_mdio_bus->id,
+						 priv->internal_mdio_bus ?
+						 priv->internal_mdio_bus->id : priv->bus->id,
 						 port_num);
 		if (!init_data.devicename) {
 			fwnode_handle_put(led);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0709/2077] net/sched: cls_flow: Dont expose folded kernel pointers
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (707 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0708/2077] net: dsa: qca8k: fix led devicename when using external mdio bus Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0710/2077] ipv4: fib: Dont dump dying fib_info in fib_leaf_notify() Greg Kroah-Hartman
                   ` (288 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kyle Zeng, Victor Nogueira,
	Jamal Hadi Salim, Eric Dumazet, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jamal Hadi Salim <jhs@mojatatu.com>

[ Upstream commit f294fc71c4a0fa4964f6428a1b4e7929c1d83125 ]

The flow classifier falls back to addr_fold() for fields that are missing
from packet headers. In map mode, userspace controls mask, xor, rshift,
addend and divisor, and can observe the resulting classid through class
statistics. This allows a tc classifier in a user/network namespace to
recover the 32-bit folded value of skb->sk, skb_dst() or skb_nfct().

Align with standard kernel practices for pointer hashing and replace the
XOR folding with a keyed siphash (which is cryptographically secure)

Fixes: e5dfb815181f ("[NET_SCHED]: Add flow classifier")
Reported-by: Kyle Zeng <kylebot@openai.com>
Tested-by: Kyle Zeng <kylebot@openai.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260610101839.14135-1-jhs@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/cls_flow.c | 12 +++++++++---
 1 file changed, 9 insertions(+), 3 deletions(-)

diff --git a/net/sched/cls_flow.c b/net/sched/cls_flow.c
index ab364e4e468624..356c68ebc3895a 100644
--- a/net/sched/cls_flow.c
+++ b/net/sched/cls_flow.c
@@ -21,6 +21,7 @@
 #include <net/inet_sock.h>
 
 #include <net/pkt_cls.h>
+#include <linux/siphash.h>
 #include <net/ip.h>
 #include <net/route.h>
 #include <net/flow_dissector.h>
@@ -57,11 +58,15 @@ struct flow_filter {
 	struct rcu_work		rwork;
 };
 
+static siphash_aligned_key_t flow_keys_secret __read_mostly;
+
 static inline u32 addr_fold(void *addr)
 {
-	unsigned long a = (unsigned long)addr;
-
-	return (a & 0xFFFFFFFF) ^ (BITS_PER_LONG > 32 ? a >> 32 : 0);
+#ifdef CONFIG_64BIT
+	return (u32)siphash_1u64((u64)addr, &flow_keys_secret);
+#else
+	return (u32)siphash_1u32((u32)addr, &flow_keys_secret);
+#endif
 }
 
 static u32 flow_get_src(const struct sk_buff *skb, const struct flow_keys *flow)
@@ -596,6 +601,7 @@ static int flow_init(struct tcf_proto *tp)
 		return -ENOBUFS;
 	INIT_LIST_HEAD(&head->filters);
 	rcu_assign_pointer(tp->root, head);
+	net_get_random_once(&flow_keys_secret, sizeof(flow_keys_secret));
 	return 0;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0710/2077] ipv4: fib: Dont dump dying fib_info in fib_leaf_notify().
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (708 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0709/2077] net/sched: cls_flow: Dont expose folded kernel pointers Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0711/2077] net: fib_rules: Dont dump dying fib_rule in fib_rules_dump() Greg Kroah-Hartman
                   ` (287 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+cb2aa2390ac024e25f5c,
	Kuniyuki Iwashima, Ido Schimmel, David Ahern, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kuniyuki Iwashima <kuniyu@google.com>

[ Upstream commit 06b693d2eb6651a63ad85bad8673de3b7d4edd6d ]

syzbot reported use-after-free in nsim_fib4_prepare_event(). [0]

The problem is that the following functions call fib_info_hold() /
refcount_inc() while dumping fib_info under RCU, which is unsafe.

  * mlxsw_sp_router_fib4_event()
  * rocker_router_fib_event()
  * nsim_fib4_prepare_event()

refcount_inc_not_zero() must be used, but it would be too late
there.

Let's guarantee the lifetime of fib_info in fib_leaf_notify().

Note that IPv6 does not need the corresponding change since
fib6_table_dump() holds fib6_table.tb6_lock.

[0]:
refcount_t: addition on 0; use-after-free.
WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25, CPU#0: kworker/u8:15/3420
Modules linked in:
CPU: 0 UID: 0 PID: 3420 Comm: kworker/u8:15 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026
Workqueue: netns cleanup_net
RIP: 0010:refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25
Code: eb 66 85 db 74 3e 83 fb 01 75 4c e8 1b f1 22 fd 48 8d 3d 84 cb f1 0a 67 48 0f b9 3a eb 4a e8 08 f1 22 fd 48 8d 3d 81 cb f1 0a <67> 48 0f b9 3a eb 37 e8 f5 f0 22 fd 48 8d 3d 7e cb f1 0a 67 48 0f
RSP: 0018:ffffc9000f2c7270 EFLAGS: 00010293
RAX: ffffffff84a18858 RBX: 0000000000000002 RCX: ffff888032ff9ec0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff8f9353e0
RBP: 0000000000000000 R08: ffff888032ff9ec0 R09: 0000000000000005
R10: 0000000000000100 R11: 0000000000000004 R12: ffff8880570cc000
R13: dffffc0000000000 R14: ffff88802b40563c R15: ffff8880570cc000
FS:  0000000000000000(0000) GS:ffff888126173000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fb1f4d5d000 CR3: 000000006072a000 CR4: 00000000003526f0
Call Trace:
 <TASK>
 __refcount_add include/linux/refcount.h:-1 [inline]
 __refcount_inc include/linux/refcount.h:366 [inline]
 refcount_inc include/linux/refcount.h:383 [inline]
 fib_info_hold include/net/ip_fib.h:629 [inline]
 nsim_fib4_prepare_event drivers/net/netdevsim/fib.c:930 [inline]
 nsim_fib_event_schedule_work drivers/net/netdevsim/fib.c:1000 [inline]
 nsim_fib_event_nb+0x1055/0x1240 drivers/net/netdevsim/fib.c:1043
 call_fib_notifier+0x45/0x80 net/core/fib_notifier.c:25
 call_fib_entry_notifier net/ipv4/fib_trie.c:90 [inline]
 fib_leaf_notify net/ipv4/fib_trie.c:2176 [inline]
 fib_table_notify net/ipv4/fib_trie.c:2194 [inline]
 fib_notify+0x36b/0x5e0 net/ipv4/fib_trie.c:2217
 fib_net_dump net/core/fib_notifier.c:70 [inline]
 register_fib_notifier+0x184/0x360 net/core/fib_notifier.c:108
 nsim_fib_create+0x85d/0x9f0 drivers/net/netdevsim/fib.c:1596
 nsim_dev_reload_create drivers/net/netdevsim/dev.c:1604 [inline]
 nsim_dev_reload_up+0x374/0x7c0 drivers/net/netdevsim/dev.c:1058
 devlink_reload+0x501/0x8d0 net/devlink/dev.c:475
 devlink_pernet_pre_exit+0x1ff/0x420 net/devlink/core.c:558
 ops_pre_exit_list net/core/net_namespace.c:161 [inline]
 ops_undo_list+0x187/0x940 net/core/net_namespace.c:234
 cleanup_net+0x56e/0x800 net/core/net_namespace.c:702
 process_one_work kernel/workqueue.c:3314 [inline]
 process_scheduled_works+0xb5d/0x1860 kernel/workqueue.c:3397
 worker_thread+0xa53/0xfc0 kernel/workqueue.c:3478
 kthread+0x388/0x470 kernel/kthread.c:436
 ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
 </TASK>

Fixes: 0ae3eb7b4611 ("netdevsim: fib: Perform the route programming in a non-atomic context")
Fixes: c3852ef7f2f8 ("ipv4: fib: Replay events when registering FIB notifier")
Reported-by: syzbot+cb2aa2390ac024e25f5c@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6a290011.39669fcc.33b062.00b1.GAE@google.com/
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://patch.msgid.link/20260610061744.2030996-2-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/net/ip_fib.h | 5 +++++
 net/ipv4/fib_trie.c  | 4 ++++
 2 files changed, 9 insertions(+)

diff --git a/include/net/ip_fib.h b/include/net/ip_fib.h
index 318593743b6e15..541da2dde6266d 100644
--- a/include/net/ip_fib.h
+++ b/include/net/ip_fib.h
@@ -629,6 +629,11 @@ static inline void fib_info_hold(struct fib_info *fi)
 	refcount_inc(&fi->fib_clntref);
 }
 
+static inline bool fib_info_hold_safe(struct fib_info *fi)
+{
+	return refcount_inc_not_zero(&fi->fib_clntref);
+}
+
 static inline void fib_info_put(struct fib_info *fi)
 {
 	if (refcount_dec_and_test(&fi->fib_clntref))
diff --git a/net/ipv4/fib_trie.c b/net/ipv4/fib_trie.c
index 1308213791f19d..dac543c1d6867a 100644
--- a/net/ipv4/fib_trie.c
+++ b/net/ipv4/fib_trie.c
@@ -2172,10 +2172,14 @@ static int fib_leaf_notify(struct key_vector *l, struct fib_table *tb,
 		if (fa->fa_slen == last_slen)
 			continue;
 
+		if (!fib_info_hold_safe(fa->fa_info))
+			continue;
+
 		last_slen = fa->fa_slen;
 		err = call_fib_entry_notifier(nb, FIB_EVENT_ENTRY_REPLACE,
 					      l->key, KEYLENGTH - fa->fa_slen,
 					      fa, extack);
+		fib_info_put(fa->fa_info);
 		if (err)
 			return err;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0711/2077] net: fib_rules: Dont dump dying fib_rule in fib_rules_dump().
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (709 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0710/2077] ipv4: fib: Dont dump dying fib_info in fib_leaf_notify() Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0712/2077] bridge: cfm: reject invalid CCM interval at configuration time Greg Kroah-Hartman
                   ` (286 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Ido Schimmel,
	David Ahern, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kuniyuki Iwashima <kuniyu@google.com>

[ Upstream commit 2821e85c058f81c9948a2fb1a634f7b47457d51c ]

rocker_router_fib_event() calls fib_rule_get() during RCU dump.

If the fib_rule is dying, refcount_inc() will complain about it.

Let's call refcount_inc_not_zero() in fib_rules_dump().

Fixes: 5d7bfd141924 ("ipv4: fib_rules: Dump FIB rules when registering FIB notifier")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://patch.msgid.link/20260610061744.2030996-3-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/net/fib_rules.h | 5 +++++
 net/core/fib_rules.c    | 6 +++++-
 2 files changed, 10 insertions(+), 1 deletion(-)

diff --git a/include/net/fib_rules.h b/include/net/fib_rules.h
index 6e68e359ad18c2..7dee0ae616e322 100644
--- a/include/net/fib_rules.h
+++ b/include/net/fib_rules.h
@@ -111,6 +111,11 @@ static inline void fib_rule_get(struct fib_rule *rule)
 	refcount_inc(&rule->refcnt);
 }
 
+static inline bool fib_rule_get_safe(struct fib_rule *rule)
+{
+	return refcount_inc_not_zero(&rule->refcnt);
+}
+
 static inline void fib_rule_put(struct fib_rule *rule)
 {
 	if (refcount_dec_and_test(&rule->refcnt))
diff --git a/net/core/fib_rules.c b/net/core/fib_rules.c
index 8ca634964e363c..cf374c20873258 100644
--- a/net/core/fib_rules.c
+++ b/net/core/fib_rules.c
@@ -349,7 +349,7 @@ int fib_rules_lookup(struct fib_rules_ops *ops, struct flowi *fl,
 
 		if (err != -EAGAIN) {
 			if ((arg->flags & FIB_LOOKUP_NOREF) ||
-			    likely(refcount_inc_not_zero(&rule->refcnt))) {
+			    likely(fib_rule_get_safe(rule))) {
 				arg->rule = rule;
 				goto out;
 			}
@@ -410,8 +410,12 @@ int fib_rules_dump(struct net *net, struct notifier_block *nb, int family,
 	if (!ops)
 		return -EAFNOSUPPORT;
 	list_for_each_entry_rcu(rule, &ops->rules_list, list) {
+		if (!fib_rule_get_safe(rule))
+			continue;
+
 		err = call_fib_rule_notifier(nb, FIB_EVENT_RULE_ADD,
 					     rule, family, extack);
+		fib_rule_put(rule);
 		if (err)
 			break;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0712/2077] bridge: cfm: reject invalid CCM interval at configuration time
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (710 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0711/2077] net: fib_rules: Dont dump dying fib_rule in fib_rules_dump() Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0713/2077] sctp: validate embedded address parameter length Greg Kroah-Hartman
                   ` (285 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Weiming Shi, Xiang Mei,
	Nikolay Aleksandrov, Ido Schimmel, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xiang Mei <xmei5@asu.edu>

[ Upstream commit f3e02edd8322b31b8e6517faa6ba053bf29d1e26 ]

ccm_tx_work_expired() re-arms itself via queue_delayed_work() using
the configured exp_interval converted by interval_to_us(). When
exp_interval is BR_CFM_CCM_INTERVAL_NONE or out of range,
interval_to_us() returns 0, causing the worker to fire immediately in
a tight loop that allocates skbs until OOM.

Fix this by validating exp_interval at configuration time:

 - Constrain IFLA_BRIDGE_CFM_CC_CONFIG_EXP_INTERVAL to the valid range
   [BR_CFM_CCM_INTERVAL_3_3_MS, BR_CFM_CCM_INTERVAL_10_MIN] in the
   netlink policy so userspace cannot set an invalid value.

 - Reject starting CCM TX in br_cfm_cc_ccm_tx() when exp_interval has
   not yet been configured (defaults to 0 from kzalloc).

Fixes: 2be665c3940d ("bridge: cfm: Netlink SET configuration Interface.")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260609065116.2818837-1-xmei5@asu.edu
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/bridge/br_cfm.c         | 6 ++++++
 net/bridge/br_cfm_netlink.c | 4 +++-
 2 files changed, 9 insertions(+), 1 deletion(-)

diff --git a/net/bridge/br_cfm.c b/net/bridge/br_cfm.c
index 118c7ea48c351d..dea56fffa1c19f 100644
--- a/net/bridge/br_cfm.c
+++ b/net/bridge/br_cfm.c
@@ -805,6 +805,12 @@ int br_cfm_cc_ccm_tx(struct net_bridge *br, const u32 instance,
 		goto save;
 	}
 
+	if (!interval_to_us(mep->cc_config.exp_interval)) {
+		NL_SET_ERR_MSG_MOD(extack,
+				   "Invalid CCM interval");
+		return -EINVAL;
+	}
+
 	/* Start delayed work to transmit CCM frames. It is done with zero delay
 	 * to send first frame immediately
 	 */
diff --git a/net/bridge/br_cfm_netlink.c b/net/bridge/br_cfm_netlink.c
index 2faab44652e7c0..91b9922dc3f25e 100644
--- a/net/bridge/br_cfm_netlink.c
+++ b/net/bridge/br_cfm_netlink.c
@@ -34,7 +34,9 @@ br_cfm_cc_config_policy[IFLA_BRIDGE_CFM_CC_CONFIG_MAX + 1] = {
 	[IFLA_BRIDGE_CFM_CC_CONFIG_UNSPEC]	 = { .type = NLA_REJECT },
 	[IFLA_BRIDGE_CFM_CC_CONFIG_INSTANCE]	 = { .type = NLA_U32 },
 	[IFLA_BRIDGE_CFM_CC_CONFIG_ENABLE]	 = { .type = NLA_U32 },
-	[IFLA_BRIDGE_CFM_CC_CONFIG_EXP_INTERVAL] = { .type = NLA_U32 },
+	[IFLA_BRIDGE_CFM_CC_CONFIG_EXP_INTERVAL] =
+		NLA_POLICY_RANGE(NLA_U32, BR_CFM_CCM_INTERVAL_3_3_MS,
+				 BR_CFM_CCM_INTERVAL_10_MIN),
 	[IFLA_BRIDGE_CFM_CC_CONFIG_EXP_MAID]	 = {
 	.type = NLA_BINARY, .len = CFM_MAID_LENGTH },
 };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0713/2077] sctp: validate embedded address parameter length
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (711 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0712/2077] bridge: cfm: reject invalid CCM interval at configuration time Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0714/2077] net: pfcp: allocate per-cpu tstats for PFCP netdevs Greg Kroah-Hartman
                   ` (284 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko, Xin Long, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xin Long <lucien.xin@gmail.com>

[ Upstream commit e9361d0ca55c4af12aac09e2572852fa91046229 ]

sctp_verify_asconf() and sctp_verify_param() only validate ADD_IP, DEL_IP,
and SET_PRIMARY parameters against a fixed minimum size of sizeof(struct
sctp_addip_param) + sizeof(struct sctp_paramhdr). This ensures the outer
parameter is large enough to contain an embedded address parameter header,
but does not verify that the embedded address parameter's declared length
fits within the bounds of the outer parameter.

Later, sctp_process_param() and sctp_process_asconf_param() extract the
embedded address parameter and pass it to af->from_addr_param(), which uses
the address parameter length to parse the variable-length address payload.
A malformed peer can therefore advertise an embedded address parameter
length that exceeds the remaining bytes in the enclosing parameter.

Validate that addr_param->p.length does not exceed the space available
after the sctp_addip_param header before processing the embedded address
parameter. Reject malformed parameters when the embedded address length
extends beyond the enclosing parameter bounds.

This prevents out-of-bounds reads when parsing malformed parameters carried
in INIT or ASCONF processing paths.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: sashiko <sashiko-bot@kernel.org>
Signed-off-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/7838b86b69f52add28808fb59034c8f992e97b2d.1781043268.git.lucien.xin@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sctp/sm_make_chunk.c | 10 ++++++++--
 1 file changed, 8 insertions(+), 2 deletions(-)

diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c
index 1741a9f33d8c71..41958b8e59fd53 100644
--- a/net/sctp/sm_make_chunk.c
+++ b/net/sctp/sm_make_chunk.c
@@ -2641,6 +2641,9 @@ static int sctp_process_param(struct sctp_association *asoc,
 			goto fall_through;
 
 		addr_param = param.v + sizeof(struct sctp_addip_param);
+		if (ntohs(addr_param->p.length) >
+		    ntohs(param.p->length) - sizeof(struct sctp_addip_param))
+			break;
 
 		af = sctp_get_af_specific(param_type2af(addr_param->p.type));
 		if (!af)
@@ -3039,13 +3042,16 @@ static __be16 sctp_process_asconf_param(struct sctp_association *asoc,
 	union sctp_addr	addr;
 	struct sctp_af *af;
 
-	addr_param = (void *)asconf_param + sizeof(*asconf_param);
-
 	if (asconf_param->param_hdr.type != SCTP_PARAM_ADD_IP &&
 	    asconf_param->param_hdr.type != SCTP_PARAM_DEL_IP &&
 	    asconf_param->param_hdr.type != SCTP_PARAM_SET_PRIMARY)
 		return SCTP_ERROR_UNKNOWN_PARAM;
 
+	addr_param = (void *)asconf_param + sizeof(*asconf_param);
+	if (ntohs(addr_param->p.length) >
+	    ntohs(asconf_param->param_hdr.length) - sizeof(*asconf_param))
+		return SCTP_ERROR_PROTO_VIOLATION;
+
 	switch (addr_param->p.type) {
 	case SCTP_PARAM_IPV6_ADDRESS:
 		if (!asoc->peer.ipv6_address)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0714/2077] net: pfcp: allocate per-cpu tstats for PFCP netdevs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (712 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0713/2077] sctp: validate embedded address parameter length Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0715/2077] net: Stop leased rxq before uninstalling its memory provider Greg Kroah-Hartman
                   ` (283 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Samuel Moelius, Alexander Lobakin,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Samuel Moelius <sam.moelius@trailofbits.com>

[ Upstream commit 24041543da8cd84eb5d8ae738c534372fff54820 ]

PFCP uses dev_get_tstats64() as its ndo_get_stats64 callback, but
pfcp_link_setup() does not request NETDEV_PCPU_STAT_TSTATS.  The net
core therefore leaves dev->tstats NULL for PFCP devices.

Creating a PFCP rtnetlink device can immediately ask the new netdev for
stats while building the RTM_NEWLINK notification.  That reaches
dev_get_tstats64() and dereferences the NULL dev->tstats pointer.

Set pcpu_stat_type to NETDEV_PCPU_STAT_TSTATS during PFCP link setup so
the net core allocates the storage expected by dev_get_tstats64().

Fixes: 76c8764ef36a ("pfcp: add PFCP module")
Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com>
Reviewed-by: Alexander Lobakin <aleksander.lobakin@intel.com>
Link: https://patch.msgid.link/20260609232244.1602027.c569f6c530f6.pfcp-missing-tstats-link-create-oops@trailofbits.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/pfcp.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/net/pfcp.c b/drivers/net/pfcp.c
index 28e6bc4a1f14c8..a6aa30ae0af762 100644
--- a/drivers/net/pfcp.c
+++ b/drivers/net/pfcp.c
@@ -148,6 +148,7 @@ static void pfcp_link_setup(struct net_device *dev)
 	dev->flags = IFF_POINTOPOINT | IFF_NOARP | IFF_MULTICAST;
 	dev->priv_flags |= IFF_NO_QUEUE;
 
+	dev->pcpu_stat_type = NETDEV_PCPU_STAT_TSTATS;
 	netif_keep_dst(dev);
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0715/2077] net: Stop leased rxq before uninstalling its memory provider
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (713 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0714/2077] net: pfcp: allocate per-cpu tstats for PFCP netdevs Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0716/2077] net/sched: sch_hfsc: Dont make class passive twice Greg Kroah-Hartman
                   ` (282 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ahmed Abdelmoemen, Daniel Borkmann,
	David Wei, Bobby Eshleman, Nikolay Aleksandrov, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Borkmann <daniel@iogearbox.net>

[ Upstream commit 37314c9dbe95b4d924c7b61aaf563cec4f4e4133 ]

netif_rxq_cleanup_unlease() tears down the memory provider that was
installed on a physical RX queue through a netkit queue lease. It
currently revokes the provider's DMA mappings before stopping the
physical queue:

  __netif_mp_uninstall_rxq(virt_rxq, p);            /* DMA unmap */
  __netif_mp_close_rxq(phys_rxq->dev, rxq_idx, p);  /* queue stop */

This inverts the ordering used by the regular teardown paths (normal
device unregister and the io_uring zcrx close path), which stop the
queue before revoking the provider's mappings.

With the physical queue still live, its NAPI can keep consuming
net_iov entries from the page_pool alloc cache after the
__netif_mp_uninstall_rxq() has already cleared their dma_addr,
opening a window for the device to DMA to a stale or zero address.

Fix it by swapping the two calls so the queue is stopped (and its
NAPI quiesced) before the provider is uninstalled. No functional
regression was observed across repeated runs of the nk_qlease.py
HW selftest, which exercises the lease teardown path; this was
tested against fbnic QEMU emulation.

Fixes: 5602ad61ebee ("net: Proxy netif_mp_{open,close}_rxq for leased queues")
Reported-by: Ahmed Abdelmoemen <ahmedabdelmoumen05@gmail.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Cc: David Wei <dw@davidwei.uk>
Reviewed-by: Bobby Eshleman <bobbyeshleman@meta.com>
Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20260609212240.677889-1-daniel@iogearbox.net
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/core/netdev_rx_queue.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/net/core/netdev_rx_queue.c b/net/core/netdev_rx_queue.c
index de4dac4c88b366..00a7011eb4d578 100644
--- a/net/core/netdev_rx_queue.c
+++ b/net/core/netdev_rx_queue.c
@@ -338,12 +338,12 @@ void __netif_mp_uninstall_rxq(struct netdev_rx_queue *rxq,
 void netif_rxq_cleanup_unlease(struct netdev_rx_queue *phys_rxq,
 			       struct netdev_rx_queue *virt_rxq)
 {
-	struct pp_memory_provider_params *p = &phys_rxq->mp_params;
 	unsigned int rxq_idx = get_netdev_rx_queue_index(phys_rxq);
+	struct pp_memory_provider_params p = phys_rxq->mp_params;
 
-	if (!p->mp_ops)
+	if (!p.mp_ops)
 		return;
 
-	__netif_mp_uninstall_rxq(virt_rxq, p);
-	__netif_mp_close_rxq(phys_rxq->dev, rxq_idx, p);
+	__netif_mp_close_rxq(phys_rxq->dev, rxq_idx, &p);
+	__netif_mp_uninstall_rxq(virt_rxq, &p);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0716/2077] net/sched: sch_hfsc: Dont make class passive twice
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (714 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0715/2077] net: Stop leased rxq before uninstalling its memory provider Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0717/2077] tipc: require net admin for TIPCv2 netlink mutators Greg Kroah-Hartman
                   ` (281 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anirudh Gupta, Jamal Hadi Salim,
	Victor Nogueira, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Victor Nogueira <victor@mojatatu.com>

[ Upstream commit 90b662ea25f5e83bb3b8ccec5b93ced810b92fb8 ]

update_vf() is called from two places for the same class during a single
dequeue when the class's child qdisc (e.g. codel/fq_codel) drops its last
packets while dequeuing:

1. The child calls qdisc_tree_reduce_backlog(), which, now that the child
   is empty, invokes hfsc_qlen_notify() -> update_vf(cl, 0, 0) and turns
   the class passive (cl_nactive is decremented up the hierarchy).

2. hfsc_dequeue() then calls update_vf(cl, qdisc_pkt_len(skb), cur_time)
   to charge the dequeued bytes.

On the second call the class is already passive, but its child qdisc is
still empty, so update_vf() arms go_passive again:

      if (cl->qdisc->q.qlen == 0 && cl->cl_flags & HFSC_FSC)
              go_passive = 1;

The leaf is then skipped by the cl_nactive == 0 check inside the loop,
which does not clear go_passive, so the stale go_passive propagates to the
parent and decrements its cl_nactive a second time. A parent that still
has other active children is driven to cl_nactive == 0 and removed from
the vttree, even though those siblings are still backlogged. They are
never dequeued again and the qdisc stalls.

Fix this by only arming go_passive when the class is actually active, so an
already-passive class no longer triggers a second passive transition. The
byte accounting (cl->cl_total += len) still runs for every ancestor, so
dequeued bytes continue to be counted exactly once.

Fixes: 51eb3b65544c ("sch_hfsc: make hfsc_qlen_notify() idempotent")
Reported-by: Anirudh Gupta <anirudhrudr@gmail.com>
Closes: https://lore.kernel.org/netdev/CAN2cbVe79oj0O9==m4+4x3v+O+qzRagA=2=wkrp9i9=CqYvyZA@mail.gmail.com/
Tested-by: Anirudh Gupta <anirudhrudr@gmail.com>
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
Link: https://patch.msgid.link/20260610132824.3027549-1-victor@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/sch_hfsc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/sched/sch_hfsc.c b/net/sched/sch_hfsc.c
index e3dd6de8f1b6e5..50112c8a71e033 100644
--- a/net/sched/sch_hfsc.c
+++ b/net/sched/sch_hfsc.c
@@ -753,7 +753,7 @@ update_vf(struct hfsc_class *cl, unsigned int len, u64 cur_time)
 	u64 f; /* , myf_bound, delta; */
 	int go_passive = 0;
 
-	if (cl->qdisc->q.qlen == 0 && cl->cl_flags & HFSC_FSC)
+	if (cl->qdisc->q.qlen == 0 && cl->cl_flags & HFSC_FSC && cl->cl_nactive)
 		go_passive = 1;
 
 	for (; cl->cl_parent != NULL; cl = cl->cl_parent) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0717/2077] tipc: require net admin for TIPCv2 netlink mutators
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (715 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0716/2077] net/sched: sch_hfsc: Dont make class passive twice Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0718/2077] tipc: prevent snt_unacked underflow on CONN_ACK Greg Kroah-Hartman
                   ` (280 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Tung Nguyen,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Bommarito <michael.bommarito@gmail.com>

[ Upstream commit 86b0c540e2ea397cde021eecd24145f7c16a3d4e ]

TIPCv2 registers mutating generic-netlink operations without admin
permission flags. Generic netlink only checks CAP_NET_ADMIN when an
operation sets GENL_ADMIN_PERM or GENL_UNS_ADMIN_PERM, so a local
unprivileged process can currently change TIPC state through commands
such as TIPC_NL_NET_SET, TIPC_NL_KEY_SET, TIPC_NL_KEY_FLUSH, and
bearer enable/disable.

The legacy TIPC netlink API already checks netlink_net_capable(...,
CAP_NET_ADMIN) for administrative commands. Give the TIPCv2 mutators
the equivalent generic-netlink gate. Use GENL_UNS_ADMIN_PERM, which
maps to the same namespace-aware CAP_NET_ADMIN check that
netlink_net_capable() performs, so the behaviour matches the legacy
path and keeps working for CAP_NET_ADMIN holders in a non-initial user
namespace (containers).

A QEMU/KASAN repro run as uid/gid 65534 with zero effective
capabilities previously succeeded in changing the network id and node
identity, setting and flushing key material, and enabling/disabling a
UDP bearer. With this patch applied the same operations fail with
-EPERM.

Fixes: 0655f6a8635b ("tipc: add bearer disable/enable to new netlink api")
Link: https://lore.kernel.org/all/20260604163102.2658553-1-dominik.czarnota@trailofbits.com/
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20260610124003.3831170-2-michael.bommarito@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/tipc/netlink.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/net/tipc/netlink.c b/net/tipc/netlink.c
index 1a9a5bdaccf4fc..8336a9664703fe 100644
--- a/net/tipc/netlink.c
+++ b/net/tipc/netlink.c
@@ -152,11 +152,13 @@ static const struct genl_ops tipc_genl_v2_ops[] = {
 	{
 		.cmd	= TIPC_NL_BEARER_DISABLE,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit	= tipc_nl_bearer_disable,
 	},
 	{
 		.cmd	= TIPC_NL_BEARER_ENABLE,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit	= tipc_nl_bearer_enable,
 	},
 	{
@@ -168,11 +170,13 @@ static const struct genl_ops tipc_genl_v2_ops[] = {
 	{
 		.cmd	= TIPC_NL_BEARER_ADD,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit	= tipc_nl_bearer_add,
 	},
 	{
 		.cmd	= TIPC_NL_BEARER_SET,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit	= tipc_nl_bearer_set,
 	},
 	{
@@ -197,11 +201,13 @@ static const struct genl_ops tipc_genl_v2_ops[] = {
 	{
 		.cmd	= TIPC_NL_LINK_SET,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit	= tipc_nl_node_set_link,
 	},
 	{
 		.cmd	= TIPC_NL_LINK_RESET_STATS,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit   = tipc_nl_node_reset_link_stats,
 	},
 	{
@@ -213,6 +219,7 @@ static const struct genl_ops tipc_genl_v2_ops[] = {
 	{
 		.cmd	= TIPC_NL_MEDIA_SET,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit	= tipc_nl_media_set,
 	},
 	{
@@ -228,6 +235,7 @@ static const struct genl_ops tipc_genl_v2_ops[] = {
 	{
 		.cmd	= TIPC_NL_NET_SET,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit	= tipc_nl_net_set,
 	},
 	{
@@ -238,6 +246,7 @@ static const struct genl_ops tipc_genl_v2_ops[] = {
 	{
 		.cmd	= TIPC_NL_MON_SET,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit	= tipc_nl_node_set_monitor,
 	},
 	{
@@ -255,6 +264,7 @@ static const struct genl_ops tipc_genl_v2_ops[] = {
 	{
 		.cmd	= TIPC_NL_PEER_REMOVE,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit	= tipc_nl_peer_rm,
 	},
 #ifdef CONFIG_TIPC_MEDIA_UDP
@@ -269,11 +279,13 @@ static const struct genl_ops tipc_genl_v2_ops[] = {
 	{
 		.cmd	= TIPC_NL_KEY_SET,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit	= tipc_nl_node_set_key,
 	},
 	{
 		.cmd	= TIPC_NL_KEY_FLUSH,
 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
+		.flags	= GENL_UNS_ADMIN_PERM,
 		.doit	= tipc_nl_node_flush_key,
 	},
 #endif
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0718/2077] tipc: prevent snt_unacked underflow on CONN_ACK
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (716 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0717/2077] tipc: require net admin for TIPCv2 netlink mutators Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0719/2077] tipc: reject inverted service ranges from peer bindings Greg Kroah-Hartman
                   ` (279 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Tung Nguyen,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Bommarito <michael.bommarito@gmail.com>

[ Upstream commit ab3e10b44ba5411779aac7afd2477917dd77750f ]

tipc_sk_conn_proto_rcv() subtracts the peer-supplied connection ack count
from the unsigned 16-bit send counter snt_unacked without checking that it
does not exceed the number of messages actually outstanding:

	tsk->snt_unacked -= msg_conn_ack(hdr);

msg_conn_ack() is read straight from a received CONN_MANAGER/CONN_ACK
message. If the ack count is larger than snt_unacked, the subtraction
wraps to a near-maximum value, leaving tsk_conn_cong() permanently true
and starving the connection of further transmits.

Validate the ACK count at the start of the CONN_ACK block and drop the
message if it acknowledges more messages than are outstanding. A peer (or,
for a local connection, the connected peer socket) can otherwise wedge a
TIPC connection's send side by sending an oversized connection ack.

Fixes: 10724cc7bb78 ("tipc: redesign connection-level flow control")
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20260610124003.3831170-3-michael.bommarito@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/tipc/socket.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/net/tipc/socket.c b/net/tipc/socket.c
index 9329919fb07f07..f64f7a35b5c910 100644
--- a/net/tipc/socket.c
+++ b/net/tipc/socket.c
@@ -1362,6 +1362,9 @@ static void tipc_sk_conn_proto_rcv(struct tipc_sock *tsk, struct sk_buff *skb,
 			__skb_queue_tail(xmitq, skb);
 		return;
 	} else if (mtyp == CONN_ACK) {
+		if (tsk->snt_unacked < msg_conn_ack(hdr))
+			goto exit;
+
 		was_cong = tsk_conn_cong(tsk);
 		tipc_sk_push_backlog(tsk, msg_nagle_ack(hdr));
 		tsk->snt_unacked -= msg_conn_ack(hdr);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0719/2077] tipc: reject inverted service ranges from peer bindings
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (717 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0718/2077] tipc: prevent snt_unacked underflow on CONN_ACK Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0720/2077] cxl/test: Unregister cxl_acpi in cxl_test_init() error path Greg Kroah-Hartman
                   ` (278 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Tung Nguyen,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Bommarito <michael.bommarito@gmail.com>

[ Upstream commit 2afb648f7b99216c687db1f89739c995e1144153 ]

tipc_update_nametbl() inserts a binding advertised by a peer node using
the lower and upper service-range bounds taken directly from the wire,
without checking that lower <= upper. The local bind path validates the
ordering (tipc_uaddr_valid()), but the name-distribution path does not.

A binding with lower > upper is inserted at the far end of the
service-range rbtree (keyed on lower) where no lookup or withdrawal can
ever match it (service_range_foreach_match() requires sr->lower <= end).
The publication, its service_range node and the augmented rbtree entry
are then leaked for the lifetime of the namespace, and there is no
per-peer cap equivalent to TIPC_MAX_PUBL on locally created bindings.

Reject inverted ranges in the network path as well. A peer node can
otherwise leak unbounded binding-table memory by sending PUBLICATION
items with lower > upper.

Fixes: 37922ea4a310 ("tipc: permit overlapping service ranges in name table")
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20260610124003.3831170-4-michael.bommarito@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/tipc/name_distr.c | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/net/tipc/name_distr.c b/net/tipc/name_distr.c
index 190b49c5cbc3ec..ba4f4906e13b70 100644
--- a/net/tipc/name_distr.c
+++ b/net/tipc/name_distr.c
@@ -280,12 +280,21 @@ static bool tipc_update_nametbl(struct net *net, struct distr_item *i,
 				u32 node, u32 dtype)
 {
 	struct publication *p = NULL;
+	u32 lower = ntohl(i->lower);
+	u32 upper = ntohl(i->upper);
 	struct tipc_socket_addr sk;
-	struct tipc_uaddr ua;
 	u32 key = ntohl(i->key);
+	struct tipc_uaddr ua;
+
+	/* A peer-advertised binding with lower > upper can never be matched
+	 * or withdrawn and would leak the publication; the local bind path
+	 * rejects such ranges, so reject ranges learned from the network too.
+	 */
+	if (lower > upper)
+		return false;
 
 	tipc_uaddr(&ua, TIPC_SERVICE_RANGE, TIPC_CLUSTER_SCOPE,
-		   ntohl(i->type), ntohl(i->lower), ntohl(i->upper));
+		   ntohl(i->type), lower, upper);
 	sk.ref = ntohl(i->port);
 	sk.node = node;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0720/2077] cxl/test: Unregister cxl_acpi in cxl_test_init() error path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (718 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0719/2077] tipc: reject inverted service ranges from peer bindings Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0721/2077] cxl/test: Add check after kzalloc() memory in alloc_mock_res() Greg Kroah-Hartman
                   ` (277 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alison Schofield, Dave Jiang,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Jiang <dave.jiang@intel.com>

[ Upstream commit 50cc34be04a0ea7522b739c9c7a71367cfbc489c ]

In cxl_test_init(), Once cxl_mock_platform_device_add() succeeds, all
error paths after needs to call platform_device_unregister() instead of
platform_device_put() to clean up.

Fixes: 67dcdd4d3b83 ("tools/testing/cxl: Introduce a mocked-up CXL port hierarchy")
Reported-by: sashiko-bot
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260611230355.198912-1-dave.jiang@intel.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/cxl/test/cxl.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/cxl/test/cxl.c b/tools/testing/cxl/test/cxl.c
index 296516eecfd6af..fd6ff00541dced 100644
--- a/tools/testing/cxl/test/cxl.c
+++ b/tools/testing/cxl/test/cxl.c
@@ -1951,7 +1951,7 @@ static __init int cxl_test_init(void)
 err_mem:
 	cxl_mem_exit();
 err_root:
-	platform_device_put(cxl_acpi);
+	platform_device_unregister(cxl_acpi);
 err_rch:
 	cxl_rch_topo_exit();
 err_single:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0721/2077] cxl/test: Add check after kzalloc() memory in alloc_mock_res()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (719 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0720/2077] cxl/test: Unregister cxl_acpi in cxl_test_init() error path Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0722/2077] crypto: marvell/octeontx - fix DMA cleanup using wrong loop index Greg Kroah-Hartman
                   ` (276 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alison Schofield, Dave Jiang,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Jiang <dave.jiang@intel.com>

[ Upstream commit dfe28c8592538152e9611341dae6f7be1735b3f1 ]

alloc_mock_res() calls kzalloc() without checking the return value.
Add scope based resource management to deal with the allocated memory
cleanly.

Reported-by: sashiko-bot
Fixes: 67dcdd4d3b83 ("tools/testing/cxl: Introduce a mocked-up CXL port hierarchy")
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260611230305.197390-1-dave.jiang@intel.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/cxl/test/cxl.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/tools/testing/cxl/test/cxl.c b/tools/testing/cxl/test/cxl.c
index fd6ff00541dced..5733a526f7dcb4 100644
--- a/tools/testing/cxl/test/cxl.c
+++ b/tools/testing/cxl/test/cxl.c
@@ -433,12 +433,16 @@ static void depopulate_all_mock_resources(void)
 
 static struct cxl_mock_res *alloc_mock_res(resource_size_t size, int align)
 {
-	struct cxl_mock_res *res = kzalloc(sizeof(*res), GFP_KERNEL);
 	struct genpool_data_align data = {
 		.align = align,
 	};
 	unsigned long phys;
 
+	struct cxl_mock_res *res __free(kfree) = kzalloc(sizeof(*res),
+							 GFP_KERNEL);
+	if (!res)
+		return NULL;
+
 	INIT_LIST_HEAD(&res->list);
 	phys = gen_pool_alloc_algo(cxl_mock_pool, size,
 				   gen_pool_first_fit_align, &data);
@@ -453,7 +457,7 @@ static struct cxl_mock_res *alloc_mock_res(resource_size_t size, int align)
 	list_add(&res->list, &mock_res);
 	mutex_unlock(&mock_res_lock);
 
-	return res;
+	return no_free_ptr(res);
 }
 
 /* Only update CFMWS0 as this is used by the auto region. */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0722/2077] crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (720 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0721/2077] cxl/test: Add check after kzalloc() memory in alloc_mock_res() Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0723/2077] crypto: cavium/cpt " Greg Kroah-Hartman
                   ` (275 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit 7891c64c0520519782470ba29bac8a5761e295d8 ]

The sg_cleanup path used list[i] instead of list[j] when unmapping DMA
buffers, leaking successfully mapped entries and repeatedly unmapping
the failed one.

Fixes: 10b4f09491bf ("crypto: marvell - add the Virtual Function driver for CPT")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/marvell/octeontx/otx_cptvf_reqmgr.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/crypto/marvell/octeontx/otx_cptvf_reqmgr.c b/drivers/crypto/marvell/octeontx/otx_cptvf_reqmgr.c
index c80baf1ad90b2f..89030e2711ce41 100644
--- a/drivers/crypto/marvell/octeontx/otx_cptvf_reqmgr.c
+++ b/drivers/crypto/marvell/octeontx/otx_cptvf_reqmgr.c
@@ -157,8 +157,8 @@ static inline int setup_sgio_components(struct pci_dev *pdev,
 sg_cleanup:
 	for (j = 0; j < i; j++) {
 		if (list[j].dma_addr) {
-			dma_unmap_single(&pdev->dev, list[i].dma_addr,
-					 list[i].size, DMA_BIDIRECTIONAL);
+			dma_unmap_single(&pdev->dev, list[j].dma_addr,
+					 list[j].size, DMA_BIDIRECTIONAL);
 		}
 
 		list[j].dma_addr = 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0723/2077] crypto: cavium/cpt - fix DMA cleanup using wrong loop index
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (721 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0722/2077] crypto: marvell/octeontx - fix DMA cleanup using wrong loop index Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0724/2077] crypto: rng - Free default RNG on module exit Greg Kroah-Hartman
                   ` (274 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Felix Gu <ustc.gu@gmail.com>

[ Upstream commit 9dbf173bd32d5f81b005008b682bfb50aa093455 ]

The sg_cleanup error path used list[i] instead of list[j] when unmapping
DMA buffers, leaking successfully mapped entries and repeatedly unmapping
the failed one.

Fixes: c694b233295b ("crypto: cavium - Add the Virtual Function driver for CPT")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/crypto/cavium/cpt/cptvf_reqmanager.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/crypto/cavium/cpt/cptvf_reqmanager.c b/drivers/crypto/cavium/cpt/cptvf_reqmanager.c
index e183b60277ff1e..de305cbeccbe0e 100644
--- a/drivers/crypto/cavium/cpt/cptvf_reqmanager.c
+++ b/drivers/crypto/cavium/cpt/cptvf_reqmanager.c
@@ -108,8 +108,8 @@ static int setup_sgio_components(struct cpt_vf *cptvf, struct buf_ptr *list,
 sg_cleanup:
 	for (j = 0; j < i; j++) {
 		if (list[j].dma_addr) {
-			dma_unmap_single(&pdev->dev, list[i].dma_addr,
-					 list[i].size, DMA_BIDIRECTIONAL);
+			dma_unmap_single(&pdev->dev, list[j].dma_addr,
+					 list[j].size, DMA_BIDIRECTIONAL);
 		}
 
 		list[j].dma_addr = 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0724/2077] crypto: rng - Free default RNG on module exit
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (722 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0723/2077] crypto: cavium/cpt " Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0725/2077] ALSA: usb-audio: qcom: Guard sideband endpoint removal Greg Kroah-Hartman
                   ` (273 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Herbert Xu, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Herbert Xu <herbert@gondor.apana.org.au>

[ Upstream commit 606ba888b98e0d26a2c4e5c8dc0542e3ad8f0f3a ]

When the rng module is removed the default RNG will be leaked.
Call crypto_del_default_rng to free it if possible.

Fixes: 7cecadb7cca8 ("crypto: rng - Do not free default RNG when it becomes unused")
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 crypto/rng.c | 11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/crypto/rng.c b/crypto/rng.c
index 1d4b9177bad4d4..a07569ed1e5e0e 100644
--- a/crypto/rng.c
+++ b/crypto/rng.c
@@ -232,5 +232,16 @@ void crypto_unregister_rngs(struct rng_alg *algs, int count)
 }
 EXPORT_SYMBOL_GPL(crypto_unregister_rngs);
 
+static void __exit rng_exit(void)
+{
+	int err;
+
+	err = crypto_del_default_rng();
+	if (err)
+		pr_err("Failed delete default RNG: %d\n", err);
+}
+
+module_exit(rng_exit);
+
 MODULE_LICENSE("GPL");
 MODULE_DESCRIPTION("Random Number Generator");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0725/2077] ALSA: usb-audio: qcom: Guard sideband endpoint removal
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (723 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0724/2077] crypto: rng - Free default RNG on module exit Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0726/2077] ALSA: seq: Fix kernel heap address leak in bounce_error_event() Greg Kroah-Hartman
                   ` (272 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cássio Gabriel, Takashi Iwai,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cássio Gabriel <cassiogabrielcontato@gmail.com>

[ Upstream commit 2773023abb381e36ce02d364022d901f6f7a416d ]

qmi_stop_session() conditionally looks up the cached data and sync
endpoints, but removes each endpoint unconditionally.

The data endpoint is always present for an active offload stream, while
the sync endpoint is optional. When no sync endpoint exists, ep still
refers to the data endpoint and the code attempts to remove that endpoint
a second time. The current sideband implementation rejects the duplicate
removal, but the teardown path should not pass an unrelated endpoint for
an absent sync endpoint.

Only look up and remove an endpoint when its cached pipe exists, check the
lookup result, and clear the cached pipe after handling it. This matches
the normal stream-disable path.

Fixes: 326bbc348298 ("ALSA: usb-audio: qcom: Introduce QC USB SND offloading support")
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260611-alsa-usb-qcom-guard-sideband-endpoint-removal-v1-1-00e73787c156@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/usb/qcom/qc_audio_offload.c | 16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

diff --git a/sound/usb/qcom/qc_audio_offload.c b/sound/usb/qcom/qc_audio_offload.c
index a0009503b2c592..649228421e2f69 100644
--- a/sound/usb/qcom/qc_audio_offload.c
+++ b/sound/usb/qcom/qc_audio_offload.c
@@ -794,15 +794,23 @@ static void qmi_stop_session(void)
 				continue;
 			}
 			/* Release XHCI endpoints */
-			if (info->data_ep_pipe)
+			if (info->data_ep_pipe) {
 				ep = usb_pipe_endpoint(uadev[pcm_card_num].udev,
 						       info->data_ep_pipe);
-			xhci_sideband_remove_endpoint(uadev[pcm_card_num].sb, ep);
+				if (ep)
+					xhci_sideband_remove_endpoint(uadev[pcm_card_num].sb,
+								      ep);
+				info->data_ep_pipe = 0;
+			}
 
-			if (info->sync_ep_pipe)
+			if (info->sync_ep_pipe) {
 				ep = usb_pipe_endpoint(uadev[pcm_card_num].udev,
 						       info->sync_ep_pipe);
-			xhci_sideband_remove_endpoint(uadev[pcm_card_num].sb, ep);
+				if (ep)
+					xhci_sideband_remove_endpoint(uadev[pcm_card_num].sb,
+								      ep);
+				info->sync_ep_pipe = 0;
+			}
 
 			disable_audio_stream(subs);
 		}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0726/2077] ALSA: seq: Fix kernel heap address leak in bounce_error_event()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (724 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0725/2077] ALSA: usb-audio: qcom: Guard sideband endpoint removal Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0727/2077] iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path Greg Kroah-Hartman
                   ` (271 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, HanQuan, Takashi Iwai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: HanQuan <eilaimemedsnaimel@gmail.com>

[ Upstream commit efc86691e4d8083d9e380ea95042c2cf679f65fd ]

The comment above bounce_error_event() documents that user clients
should receive SNDRV_SEQ_EVENT_BOUNCE with the original event embedded
as variable-length data, while kernel clients should receive
SNDRV_SEQ_EVENT_KERNEL_ERROR with a quoted kernel pointer.

However, the implementation unconditionally uses
SNDRV_SEQ_EVENT_KERNEL_ERROR with data.quote.event set to the raw
struct snd_seq_event pointer for all clients.  When a bounce error
event is delivered to a USER_CLIENT via snd_seq_read(), the kernel
heap address in data.quote.event is exposed to userspace through
copy_to_user() in the fixed-length branch.

This is a distinct leak path from the one addressed by commit
705dd6dcbc0e ("ALSA: seq: Clear variable event pointer on read"),
which sanitizes data.ext.ptr in the variable-length branch of
snd_seq_read().  The bounce_error_event() leak uses fixed-length
events that take the else branch where no sanitization occurs.

Differentiate the bounce event by client type.  For USER_CLIENT,
send SNDRV_SEQ_EVENT_BOUNCE with SNDRV_SEQ_EVENT_LENGTH_VARIABLE
and data.ext pointing to the original event.  The variable-length
path in snd_seq_event_dup() copies the event data into chained
cells, and snd_seq_expand_var_event() copies only the content --
never the pointer -- to userspace.  For KERNEL_CLIENT, keep the
existing SNDRV_SEQ_EVENT_KERNEL_ERROR behavior with the quoted
pointer.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: HanQuan <eilaimemedsnaimel@gmail.com>
Link: https://patch.msgid.link/20260612103222.2528305-1-eilaimemedsnaimel@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/core/seq/seq_clientmgr.c | 32 +++++++++++++++++++++++++++-----
 1 file changed, 27 insertions(+), 5 deletions(-)

diff --git a/sound/core/seq/seq_clientmgr.c b/sound/core/seq/seq_clientmgr.c
index ce0dd53399bfac..9481fa0ca0f12e 100644
--- a/sound/core/seq/seq_clientmgr.c
+++ b/sound/core/seq/seq_clientmgr.c
@@ -538,16 +538,38 @@ static int bounce_error_event(struct snd_seq_client *client,
 
 	/* set up quoted error */
 	memset(&bounce_ev, 0, sizeof(bounce_ev));
-	bounce_ev.type = SNDRV_SEQ_EVENT_KERNEL_ERROR;
-	bounce_ev.flags = SNDRV_SEQ_EVENT_LENGTH_FIXED;
+
+	if (client->type == USER_CLIENT) {
+		/*
+		 * For user clients, send SNDRV_SEQ_EVENT_BOUNCE with the
+		 * original event embedded as variable-length data.  This
+		 * avoids exposing data.quote.event (a kernel pointer) to
+		 * userspace.  The variable-length path in snd_seq_event_dup()
+		 * copies the event data from data.ext.ptr into chained cells,
+		 * and snd_seq_expand_var_event() copies only the data content
+		 * -- never the pointer -- to userspace.
+		 */
+		bounce_ev.type = SNDRV_SEQ_EVENT_BOUNCE;
+		bounce_ev.flags = SNDRV_SEQ_EVENT_LENGTH_VARIABLE;
+		bounce_ev.data.ext.len = sizeof(struct snd_seq_event);
+		bounce_ev.data.ext.ptr = (char *)event;
+	} else {
+		/*
+		 * For kernel clients, quote the event pointer directly.
+		 * Kernel consumers can safely dereference the pointer.
+		 */
+		bounce_ev.type = SNDRV_SEQ_EVENT_KERNEL_ERROR;
+		bounce_ev.flags = SNDRV_SEQ_EVENT_LENGTH_FIXED;
+		bounce_ev.data.quote.origin = event->dest;
+		bounce_ev.data.quote.event = event;
+		bounce_ev.data.quote.value = -err; /* use positive value */
+	}
+
 	bounce_ev.queue = SNDRV_SEQ_QUEUE_DIRECT;
 	bounce_ev.source.client = SNDRV_SEQ_CLIENT_SYSTEM;
 	bounce_ev.source.port = SNDRV_SEQ_PORT_SYSTEM_ANNOUNCE;
 	bounce_ev.dest.client = client->number;
 	bounce_ev.dest.port = event->source.port;
-	bounce_ev.data.quote.origin = event->dest;
-	bounce_ev.data.quote.event = event;
-	bounce_ev.data.quote.value = -err; /* use positive value */
 	result = snd_seq_deliver_single_event(NULL, &bounce_ev, atomic, hop + 1);
 	if (result < 0) {
 		client->event_lost++;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0727/2077] iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (725 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0726/2077] ALSA: seq: Fix kernel heap address leak in bounce_error_event() Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0728/2077] iommufd: Clarify IOAS_MAP_FILE dma-buf support Greg Kroah-Hartman
                   ` (270 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Li RongQing, Logan Gunthorpe,
	Joerg Roedel, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Li RongQing <lirongqing@baidu.com>

[ Upstream commit db50fb87015b955a5a0c155293b2dd40d63a3b9e ]

In iommu_dma_map_sg(), when handling PCI P2PDMA cases, the DMA length
of the current scatterlist segment `s` is incorrectly assigned from the
head entry `sg->length` instead of the current entry `s->length`.

This typo causes all P2PDMA segments in the scatterlist to inherit the
length of the first segment, leading to corrupted DMA lengths for multi-
segment scatterlists.

Fix this by using `s->length` instead of `sg->length`.

Fixes: a25e7962db ("PCI/P2PDMA: Refactor the p2pdma mapping helpers")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iommu/dma-iommu.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/iommu/dma-iommu.c b/drivers/iommu/dma-iommu.c
index 381b60d9e7ceaf..3ca2c5da2843bf 100644
--- a/drivers/iommu/dma-iommu.c
+++ b/drivers/iommu/dma-iommu.c
@@ -1465,7 +1465,7 @@ int iommu_dma_map_sg(struct device *dev, struct scatterlist *sg, int nents,
 			 */
 			s->dma_address = pci_p2pdma_bus_addr_map(
 				p2pdma_state.mem, sg_phys(s));
-			sg_dma_len(s) = sg->length;
+			sg_dma_len(s) = s->length;
 			sg_dma_mark_bus_address(s);
 			continue;
 		default:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0728/2077] iommufd: Clarify IOAS_MAP_FILE dma-buf support
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (726 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0727/2077] iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0729/2077] spi: xilinx: use FIFO occupancy register to determine buffer size Greg Kroah-Hartman
                   ` (269 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alex Mastro, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alex Mastro <amastro@fb.com>

[ Upstream commit 298ab7e6f1637cec44163f52e84e2030ec16ed9d ]

IOMMU_IOAS_MAP_FILE is documented as mapping a memfd, but the
implementation first tries to resolve the fd as a dma-buf and has a
special path for supported dma-buf exporters. In particular, VFIO PCI
dma-bufs exported through VFIO_DEVICE_FEATURE_DMA_BUF can be mapped when
they describe a single DMA range.

Update the UAPI comment so userspace understands that certain kinds of
dma-buf are supported in addition to memfd.

Fixes: 44ebaa1744fd ("iommufd: Accept a DMABUF through IOMMU_IOAS_MAP_FILE")
Link: https://patch.msgid.link/r/20260610-tmp-v1-1-b8ccbf557391@fb.com
Signed-off-by: Alex Mastro <amastro@fb.com>
Assisted-by: Codex:gpt-5.5-high
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/uapi/linux/iommufd.h | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/include/uapi/linux/iommufd.h b/include/uapi/linux/iommufd.h
index e998dfbd696031..0425d452d41ed6 100644
--- a/include/uapi/linux/iommufd.h
+++ b/include/uapi/linux/iommufd.h
@@ -224,13 +224,17 @@ struct iommu_ioas_map {
  * @size: sizeof(struct iommu_ioas_map_file)
  * @flags: same as for iommu_ioas_map
  * @ioas_id: same as for iommu_ioas_map
- * @fd: the memfd to map
- * @start: byte offset from start of file to map from
+ * @fd: the memfd or supported dma-buf file to map
+ * @start: byte offset from start of the file to map from
  * @length: same as for iommu_ioas_map
  * @iova: same as for iommu_ioas_map
  *
- * Set an IOVA mapping from a memfd file.  All other arguments and semantics
- * match those of IOMMU_IOAS_MAP.
+ * Set an IOVA mapping from a memfd file. On kernels with dma-buf support,
+ * supported dma-buf files may also be accepted. This is not a generic
+ * dma-buf import path; currently supported dma-bufs include single-range
+ * VFIO PCI dma-bufs exported through VFIO_DEVICE_FEATURE_DMA_BUF, and
+ * other dma-bufs may be rejected. All other arguments and semantics match
+ * those of IOMMU_IOAS_MAP.
  */
 struct iommu_ioas_map_file {
 	__u32 size;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0729/2077] spi: xilinx: use FIFO occupancy register to determine buffer size
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (727 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0728/2077] iommufd: Clarify IOAS_MAP_FILE dma-buf support Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0730/2077] iommu: Avoid copying the user array twice in the full-array copy helper Greg Kroah-Hartman
                   ` (268 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lars Pöschel, Michal Simek,
	Mark Brown, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lars Pöschel <lars.poeschel@edag.com>

[ Upstream commit 47f3b5365536e8c38f264824ab15fdb74454e066 ]

The method the driver uses to determine the size of the FIFO has a
problem. What it currently does is this:
It stops the SPI hardware and writes to the TX FIFO register until TX
FIFO FULL asserts in the status register. But the hardware does not only
have the FIFO, it also has a shift register which can hold a byte. This
can be seen, when writing a byte to the FIFO (while the SPI hardware is
stopped,) the TX FIFO EMPTY is still empty. So, if we have a FIFO size
of 16 for example, the current method returns a 17.
This is a problem, at least when using the driver in irq mode. The same
size determined for the TX FIFO is also assumed for the RX FIFO. When a
SPI transaction wants to write the amount of the FIFO size or more
bytes, the following happens, for example with 16 bytes FIFO size:
The driver stops the SPI hardware and writes 17 bytes to the TX FIFO and
starts the SPI hardware and goes sleep.
The hardware then shifts out 17 bytes (FIFO + shift register) and
simultaneously reads bytes into the RX FIFO, but it only has 16 places,
so it looses one byte. Then TX FIFO empty asserts, wakes the driver
again, which has a fast path and reads 16 bytes from the RX FIFO, but
before reading the last 17th byte (which is lost) it does this:

	sr = xspi->read_fn(xspi->regs + XSPI_SR_OFFSET);
	if (!(sr & XSPI_SR_RX_EMPTY_MASK)) {
		xilinx_spi_rx(xspi);
		rx_words--;
	}

It reads the status register and checks if the RX FIFO is not empty.
But it is empty in our case. So this check spins in a while loop
forever locking the driver.

This patch fixes the logic to determine the FIFO size.

Fixes: 4c9a761402d7 ("spi/xilinx: Simplify spi_fill_tx_fifo")
Signed-off-by: Lars Pöschel <lars.poeschel@edag.com>
Reviewed-by: Michal Simek <michal.simek@amd.com>
Link: https://patch.msgid.link/20260612105244.9076-1-lars.poeschel.linux@edag.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/spi/spi-xilinx.c | 11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

diff --git a/drivers/spi/spi-xilinx.c b/drivers/spi/spi-xilinx.c
index 9f065d4e27d19a..b95485710e2f71 100644
--- a/drivers/spi/spi-xilinx.c
+++ b/drivers/spi/spi-xilinx.c
@@ -371,11 +371,18 @@ static int xilinx_spi_find_buffer_size(struct xilinx_spi *xspi)
 		xspi->regs + XIPIF_V123B_RESETR_OFFSET);
 
 	/* Fill the Tx FIFO with as many words as possible */
-	do {
+	while (1) {
 		xspi->write_fn(0, xspi->regs + XSPI_TXD_OFFSET);
 		sr = xspi->read_fn(xspi->regs + XSPI_SR_OFFSET);
+		if (sr & XSPI_SR_TX_FULL_MASK)
+			break;
+
 		n_words++;
-	} while (!(sr & XSPI_SR_TX_FULL_MASK));
+	}
+
+	/* Handle the NO FIFO case separately */
+	if (!n_words)
+		return 1;
 
 	return n_words;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0730/2077] iommu: Avoid copying the user array twice in the full-array copy helper
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (728 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0729/2077] spi: xilinx: use FIFO occupancy register to determine buffer size Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0731/2077] ASoC: sdw_utils: fix missing component_name for cs42l43 part_id 0x2A3B Greg Kroah-Hartman
                   ` (267 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nicolin Chen, Lu Baolu,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nicolin Chen <nicolinc@nvidia.com>

[ Upstream commit e28bee5b445178390d63f7a93a5a219063c6434e ]

iommu_copy_struct_from_full_user_array() copies a whole user array into a
kernel buffer. In the common case, where user entry_len equals destination
entry size, it takes a fast path and copies the whole array with a single
copy_from_user().

That fast path does not return, so it falls through into the item-by-item
copy_struct_from_user() loop and copies every entry a second time. For an
equal entry_len that loop is just a copy_from_user() of the same bytes, so
the whole array is copied twice for no benefit.

Return right after the bulk copy. The per-item loop then runs only on the
slow path, where entry_len differs and each entry needs size adaption.

Fixes: 4f2e59ccb698 ("iommu: Add iommu_copy_struct_from_full_user_array helper")
Link: https://patch.msgid.link/r/6c9eca4ff584cb977661e97799ac6fe934e7f51c.1780521606.git.nicolinc@nvidia.com
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Reviewed-by: Lu Baolu <baolu.lu@linux.intel.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/iommu.h | 1 +
 1 file changed, 1 insertion(+)

diff --git a/include/linux/iommu.h b/include/linux/iommu.h
index e587d4ac4d3310..6957144263793b 100644
--- a/include/linux/iommu.h
+++ b/include/linux/iommu.h
@@ -547,6 +547,7 @@ iommu_copy_struct_from_full_user_array(void *kdst, size_t kdst_entry_size,
 				   user_array->entry_num *
 					   user_array->entry_len))
 			return -EFAULT;
+		return 0;
 	}
 
 	/* Copy item by item */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0731/2077] ASoC: sdw_utils: fix missing component_name for cs42l43 part_id 0x2A3B
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (729 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0730/2077] iommu: Avoid copying the user array twice in the full-array copy helper Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0732/2077] cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach() Greg Kroah-Hartman
                   ` (266 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chia-Lin Kao (AceLan), Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chia-Lin Kao (AceLan) <acelan.kao@canonical.com>

[ Upstream commit c429fbea6174a7dd40c4215288589a50e8a33ff6 ]

commit 87a3f5c8ac20 ("ASoC: sdw_utils: cs42l43: allow spk component names
to be combined") moved spk:cs42l43-spk generation from rtd_init() into
the asoc_sdw_rtd_init() generic path by adding component_name to
codec_info_list entries. However, only the 0x4243 cs42l43 entry was
updated; the 0x2A3B entry (vendor_id 0x01fa, Cirrus Logic cs42l43 with
sidecar bridge) was missed.

Without component_name on the 0x2A3B dp6 DAI, asoc_sdw_rtd_init() never
accumulates spk_components and never appends 'spk:cs42l43-spk' (or its
sidecar alias 'spk:cs35l56-bridge') to card->components. The sof-soundwire
UCM regex ' spk:([a-z0-9]+...)' then fails to match, causing WirePlumber
to mark all HiFi profiles as unavailable=no and fall back to the Off
profile — resulting in Dummy Output in GNOME.

The existing sidecar redirect in asoc_sdw_rtd_init() already handles the
SOC_SDW_SIDECAR_AMPS case: when component_name is 'cs42l43-spk' and
sidecar amps are active, it substitutes 'cs35l56-bridge' into
card->components, which matches the existing cs35l56-bridge.conf UCM file.

Fixes: 87a3f5c8ac20 ("ASoC: sdw_utils: cs42l43: allow spk component names to be combined")
Signed-off-by: Chia-Lin Kao (AceLan) <acelan.kao@canonical.com>
Link: https://patch.msgid.link/20260610041753.1151088-1-acelan.kao@canonical.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/sdw_utils/soc_sdw_utils.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sound/soc/sdw_utils/soc_sdw_utils.c b/sound/soc/sdw_utils/soc_sdw_utils.c
index e440c23271001c..4e8646d231c4ff 100644
--- a/sound/soc/sdw_utils/soc_sdw_utils.c
+++ b/sound/soc/sdw_utils/soc_sdw_utils.c
@@ -818,6 +818,7 @@ struct asoc_sdw_codec_info codec_info_list[] = {
 			{
 				.direction = {true, false},
 				.codec_name = "cs42l43-codec",
+				.component_name = "cs42l43-spk",
 				.dai_name = "cs42l43-dp6",
 				.dai_type = SOC_SDW_DAI_TYPE_AMP,
 				.dailink = {SOC_SDW_AMP_OUT_DAI_ID, SOC_SDW_UNUSED_DAI_ID},
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0732/2077] cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (730 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0731/2077] ASoC: sdw_utils: fix missing component_name for cs42l43 part_id 0x2A3B Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0733/2077] cxl/region: Fill first free targets[] slot during auto-discovery Greg Kroah-Hartman
                   ` (265 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Li Ming, Alison Schofield,
	Dave Jiang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Li Ming <ming.li@zohomail.com>

[ Upstream commit cbda6a2c2bec2a5fb30a2ce85baeab15b5fc7db3 ]

In cxl_cancel_auto_attach(), it assumes cxled->pos is a valid index for
accessing p->targets[]. However, cxled->pos can be set to negative errno
in cxl_region_sort_targets() if cxl_calc_interleave_pos() fails. This
causes the driver to use a negative index to access p->targets[],
resulting in out-of-bounds access.

Fix it by walking p->targets[] instead of using cxled->pos directly.

Fixes: 87805c32e6ad ("cxl/region: Fix use-after-free from auto assembly failure")
Signed-off-by: Li Ming <ming.li@zohomail.com>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260606-fix_two_issues_introduced_by_cxl_cancel_auto_attach-v1-1-5d94ca06c4e4@zohomail.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cxl/core/region.c | 40 +++++++++++++++++++--------------------
 1 file changed, 19 insertions(+), 21 deletions(-)

diff --git a/drivers/cxl/core/region.c b/drivers/cxl/core/region.c
index e50dc716d4e820..8956b049c4620c 100644
--- a/drivers/cxl/core/region.c
+++ b/drivers/cxl/core/region.c
@@ -2011,8 +2011,9 @@ static int cxl_region_sort_targets(struct cxl_region *cxlr)
 		cxled->pos = cxl_calc_interleave_pos(cxled, &cxlr->hpa_range);
 		/*
 		 * Record that sorting failed, but still continue to calc
-		 * cxled->pos so that follow-on code paths can reliably
-		 * do p->targets[cxled->pos] to self-reference their entry.
+		 * cxled->pos so that cxl_calc_interleave_pos() emits its
+		 * dev_dbg() for every member. which is useful for auto
+		 * discovery debug.
 		 */
 		if (cxled->pos < 0)
 			rc = -ENXIO;
@@ -2202,18 +2203,30 @@ static int cxl_region_attach(struct cxl_region *cxlr,
 	return 0;
 }
 
-static int cxl_region_by_target(struct device *dev, const void *data)
+static int cxl_region_remove_target(struct device *dev, void *data)
 {
-	const struct cxl_endpoint_decoder *cxled = data;
+	struct cxl_endpoint_decoder *cxled = data;
 	struct cxl_region_params *p;
 	struct cxl_region *cxlr;
+	int i;
 
 	if (!is_cxl_region(dev))
 		return 0;
 
 	cxlr = to_cxl_region(dev);
 	p = &cxlr->params;
-	return p->targets[cxled->pos] == cxled;
+	for (i = 0; i < p->interleave_ways; i++) {
+		if (p->targets[i] == cxled) {
+			p->nr_targets--;
+			cxled->state = CXL_DECODER_STATE_AUTO;
+			cxled->pos = -1;
+			p->targets[i] = NULL;
+
+			return 1;
+		}
+	}
+
+	return 0;
 }
 
 /*
@@ -2222,25 +2235,10 @@ static int cxl_region_by_target(struct device *dev, const void *data)
  */
 static void cxl_cancel_auto_attach(struct cxl_endpoint_decoder *cxled)
 {
-	struct cxl_region_params *p;
-	struct cxl_region *cxlr;
-	int pos = cxled->pos;
-
 	if (cxled->state != CXL_DECODER_STATE_AUTO_STAGED)
 		return;
 
-	struct device *dev __free(put_device) =
-		bus_find_device(&cxl_bus_type, NULL, cxled, cxl_region_by_target);
-	if (!dev)
-		return;
-
-	cxlr = to_cxl_region(dev);
-	p = &cxlr->params;
-
-	p->nr_targets--;
-	cxled->state = CXL_DECODER_STATE_AUTO;
-	cxled->pos = -1;
-	p->targets[pos] = NULL;
+	bus_for_each_dev(&cxl_bus_type, NULL, cxled, cxl_region_remove_target);
 }
 
 static struct cxl_region *
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0733/2077] cxl/region: Fill first free targets[] slot during auto-discovery
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (731 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0732/2077] cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach() Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0734/2077] vfio: selftests: Ensure libvfio output dirs are always created Greg Kroah-Hartman
                   ` (264 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alison Schofield, Li Ming,
	Dave Jiang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Li Ming <ming.li@zohomail.com>

[ Upstream commit aa8a76711c15041ec1e42c3a74c15c2df0bd31f6 ]

Any invalid endpoint decoder pointer in the target array of an active
region is not allowed by cxl driver. This means cxl driver always
assumes the first p->nr_targets entries of the target array in an
auto-assembly region are valid. However, there are scenarios that could
leave NULL endpoint decoder pointer holes in the target array.

1. When cxl_cancel_auto_attach() removes an endpoint decoder from a
   target array, the target slot is set to NULL. If the removed endpoint
   decoder is not the last element in the target array, the target array
   will contain a NULL hole.

2. When a auto-assembly region removes an assigned endpoint decoder, if
   the removed endpoint decoder is not the last element in the target
   array, always remains a NULL hole in the target array.

When a NULL pointer hole exists in a region's target array, it
introduces two potential problems:
1. Access an endpoint decoder via a NULL pointer. it always trigger
   calltrace like that.
    Oops: general protection fault, probably for non-canonical address 0xdffffc0000000008: 0000 [#1] SMP KASAN PTI
    RIP: 0010:cxl_calc_interleave_pos+0x26/0x810 [cxl_core]
    Call Trace:
      <TASK>
      cxl_region_attach+0xc50/0x2140 [cxl_core]
      cxl_add_to_region+0x321/0x2330 [cxl_core]
      discover_region+0x92/0x150 [cxl_port]
      device_for_each_child+0xf3/0x170
      cxl_port_probe+0x150/0x200 [cxl_port]
      cxl_bus_probe+0x4f/0xa0 [cxl_core]
      really_probe+0x1c8/0x960
      __driver_probe_device+0x323/0x450
      driver_probe_device+0x45/0x120
      __device_attach_driver+0x15d/0x280
      bus_for_each_drv+0x10f/0x190

2. Not having enough valid endpoint decoders attached to an
   auto-assembly region. if an auto-assembly region is created with lock
   flag or assigned endpoint decoder with lock flag, which means
   assigned endpoint decoder will not be reset during detaching, they
   could re-attach to the auto-assembly region again. But cxl region
   driver relies on p->nr_targets to verify whether the required number
   of endpoint decoders has been attached, and NULL endpoint decoder
   pointers are still counted in that case.

To fix above issues, adjust cxl_region_attach_auto() logic to find the
first free target slot for endpoint decoder attachment, this ensures
NULL holes in the target array are filled, rather than adding new
endpoint decoders at the tail of the target array.

Fixes: 87805c32e6ad ("cxl/region: Fix use-after-free from auto assembly failure")
Fixes: 2230c4bdc412 ("cxl: Add handling of locked CXL decoder")
Suggested-by: Alison Schofield <alison.schofield@intel.com>
Signed-off-by: Li Ming <ming.li@zohomail.com>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260606-fix_two_issues_introduced_by_cxl_cancel_auto_attach-v1-2-5d94ca06c4e4@zohomail.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cxl/core/region.c | 15 ++++++++++++++-
 1 file changed, 14 insertions(+), 1 deletion(-)

diff --git a/drivers/cxl/core/region.c b/drivers/cxl/core/region.c
index 8956b049c4620c..174876e0475f1d 100644
--- a/drivers/cxl/core/region.c
+++ b/drivers/cxl/core/region.c
@@ -1848,8 +1848,21 @@ static int cxl_region_attach_auto(struct cxl_region *cxlr,
 	 * this means that userspace can view devices in the wrong position
 	 * before the region activates, and must be careful to understand when
 	 * it might be racing region autodiscovery.
+	 *
+	 * The endpoint decoder will be recorded into the first free slot of
+	 * the target array.
 	 */
-	pos = p->nr_targets;
+	for (pos = 0; pos < p->interleave_ways; pos++) {
+		if (!p->targets[pos])
+			break;
+	}
+
+	if (pos == p->interleave_ways) {
+		dev_err(&cxlr->dev, "%s: unable to find a free target slot\n",
+			dev_name(&cxled->cxld.dev));
+		return -ENXIO;
+	}
+
 	p->targets[pos] = cxled;
 	cxled->pos = pos;
 	cxled->state = CXL_DECODER_STATE_AUTO_STAGED;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0734/2077] vfio: selftests: Ensure libvfio output dirs are always created
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (732 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0733/2077] cxl/region: Fill first free targets[] slot during auto-discovery Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0735/2077] ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO Greg Kroah-Hartman
                   ` (263 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, David Matlack,
	Alex Williamson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Matlack <dmatlack@google.com>

[ Upstream commit 785562e31dbcd85ca583cf58c446e63aa8a5af08 ]

Add an explicit dependency between the output object files and the
output directories that need to be created to hold those files. This
ensures that the output directories are always created.

Creating the output directories at parse time (current behavior) doesn't
support the scenario where someone does "make clean all". The
directories will be created during parsing, deleted during "clean" and
then not available for the "all" target.

Use an order-only prerequisite for the output directories, rather than a
normal prerequisite, to avoid unnecessary recompilations.

Fixes: 19faf6fd969c ("vfio: selftests: Add a helper library for VFIO selftests")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/kvm/20260610010314.DB8861F00893@smtp.kernel.org/
Signed-off-by: David Matlack <dmatlack@google.com>
Link: https://lore.kernel.org/r/20260611213945.3714421-1-dmatlack@google.com
Signed-off-by: Alex Williamson <alex@shazbot.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/vfio/lib/libvfio.mk | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/tools/testing/selftests/vfio/lib/libvfio.mk b/tools/testing/selftests/vfio/lib/libvfio.mk
index 9f47bceed16f4c..f90235a1043fe8 100644
--- a/tools/testing/selftests/vfio/lib/libvfio.mk
+++ b/tools/testing/selftests/vfio/lib/libvfio.mk
@@ -19,11 +19,13 @@ LIBVFIO_OUTPUT := $(OUTPUT)/libvfio
 LIBVFIO_O := $(patsubst %.c, $(LIBVFIO_OUTPUT)/%.o, $(LIBVFIO_C))
 
 LIBVFIO_O_DIRS := $(shell dirname $(LIBVFIO_O) | uniq)
-$(shell mkdir -p $(LIBVFIO_O_DIRS))
+
+$(LIBVFIO_O_DIRS):
+	mkdir -p $@
 
 CFLAGS += -I$(LIBVFIO_SRCDIR)/include
 
-$(LIBVFIO_O): $(LIBVFIO_OUTPUT)/%.o : $(LIBVFIO_SRCDIR)/%.c
+$(LIBVFIO_O): $(LIBVFIO_OUTPUT)/%.o : $(LIBVFIO_SRCDIR)/%.c | $(LIBVFIO_O_DIRS)
 	$(CC) $(CFLAGS) $(CPPFLAGS) $(TARGET_ARCH) -c $< -o $@
 
 EXTRA_CLEAN += $(LIBVFIO_OUTPUT)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0735/2077] ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (733 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0734/2077] vfio: selftests: Ensure libvfio output dirs are always created Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0736/2077] cxl/region: Block region delete during region creation Greg Kroah-Hartman
                   ` (262 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Mark Brown,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guangshuo Li <lgs201920130244@gmail.com>

[ Upstream commit 69b4141b428bcf2cf7a863950c0d6e5c5ae89ac1 ]

The PLL lock failure path in adau1372_set_power() unwinds by putting
the regmap back in cache-only mode, asserting the optional power-down
GPIO and disabling mclk.

adau1372_enable_pll() enables CLK_CTRL.PLL_EN before polling the PLL
lock bit. If the lock fails on a board without a power-down GPIO, the
error path disables mclk and returns an error, but leaves PLL_EN set in
the hardware register. The normal power-off path already handles the
no-GPIO case by explicitly clearing PLL_EN.

Mirror that cleanup in the PLL lock failure path and clear PLL_EN while
the regmap is still live, before switching it back to cache-only mode.

Fixes: bfe6a264effc ("ASoC: adau1372: Fix clock leak on PLL lock failure")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260604125520.1428905-1-lgs201920130244@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/soc/codecs/adau1372.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/sound/soc/codecs/adau1372.c b/sound/soc/codecs/adau1372.c
index d7363f9d53bb31..879afeb81c422d 100644
--- a/sound/soc/codecs/adau1372.c
+++ b/sound/soc/codecs/adau1372.c
@@ -813,6 +813,11 @@ static int adau1372_set_power(struct adau1372 *adau1372, bool enable)
 		if (adau1372->use_pll) {
 			ret = adau1372_enable_pll(adau1372);
 			if (ret) {
+				if (!adau1372->pd_gpio)
+					regmap_update_bits(adau1372->regmap,
+							   ADAU1372_REG_CLK_CTRL,
+							   ADAU1372_CLK_CTRL_PLL_EN,
+							   0);
 				regcache_cache_only(adau1372->regmap, true);
 				if (adau1372->pd_gpio)
 					gpiod_set_value(adau1372->pd_gpio, 1);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0736/2077] cxl/region: Block region delete during region creation
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (734 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0735/2077] ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0737/2077] cxl/region: Resolve region deletion races Greg Kroah-Hartman
                   ` (261 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Williams, Alejandro Lucero,
	Dave Jiang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dan Williams <djbw@kernel.org>

[ Upstream commit d91feb88692e81b00cd22f0125cfcd04970b4a0b ]

Expand the range lock, rename it "regions_lock", to disable region deletion
in the critical period between construct_region() and attach_target(), as
well as the period between device_add() and registering the remove actions.

Otherwise, userspace can confuse the kernel. It can violate the assumption
the region stays registered through the completion of cxl_add_to_region().
It can violate the assumption that devm_add_action_or_reset() is working
with a live 'struct cxl_region'.

It is ok for the region to disappear outside of those windows as that
mirrors device hotplug flows where the proper locks are held.

Fixes: a32320b71f08 ("cxl/region: Add region autodiscovery")
Signed-off-by: Dan Williams <djbw@kernel.org>
Reviewed-by: Alejandro Lucero <alucerop@amd.com>
Tested-by: ALejandro Lucero <alucerop@amd.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Link: https://patch.msgid.link/20260519210158.1499795-2-djbw@kernel.org
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cxl/core/port.c   |  2 +-
 drivers/cxl/core/region.c | 12 ++++++++++--
 drivers/cxl/cxl.h         |  4 ++--
 3 files changed, 13 insertions(+), 5 deletions(-)

diff --git a/drivers/cxl/core/port.c b/drivers/cxl/core/port.c
index c5aacd7054f1d2..6e7a70d51cfe4d 100644
--- a/drivers/cxl/core/port.c
+++ b/drivers/cxl/core/port.c
@@ -2016,7 +2016,7 @@ struct cxl_root_decoder *cxl_root_decoder_alloc(struct cxl_port *port,
 		return ERR_PTR(rc);
 	}
 
-	mutex_init(&cxlrd->range_lock);
+	mutex_init(&cxlrd->regions_lock);
 
 	cxld = &cxlsd->cxld;
 	cxld->dev.type = &cxl_decoder_root_type;
diff --git a/drivers/cxl/core/region.c b/drivers/cxl/core/region.c
index 174876e0475f1d..3abf7703f7f25e 100644
--- a/drivers/cxl/core/region.c
+++ b/drivers/cxl/core/region.c
@@ -2790,6 +2790,10 @@ static ssize_t create_region_store(struct device *dev, const char *buf,
 	if (rc != 1)
 		return -EINVAL;
 
+	ACQUIRE(mutex_intr, regions_lock)(&cxlrd->regions_lock);
+	if ((rc = ACQUIRE_ERR(mutex_intr, &regions_lock)))
+		return rc;
+
 	cxlr = __create_region(cxlrd, mode, id, CXL_DECODER_HOSTONLYMEM);
 	if (IS_ERR(cxlr))
 		return PTR_ERR(cxlr);
@@ -2849,6 +2853,11 @@ static ssize_t delete_region_store(struct device *dev,
 	struct cxl_root_decoder *cxlrd = to_cxl_root_decoder(dev);
 	struct cxl_port *port = to_cxl_port(dev->parent);
 	struct cxl_region *cxlr;
+	int rc;
+
+	ACQUIRE(mutex_intr, regions_lock)(&cxlrd->regions_lock);
+	if ((rc = ACQUIRE_ERR(mutex_intr, &regions_lock)))
+		return rc;
 
 	cxlr = cxl_find_region_by_name(cxlrd, buf);
 	if (IS_ERR(cxlr))
@@ -3787,12 +3796,11 @@ int cxl_add_to_region(struct cxl_endpoint_decoder *cxled)
 	 * for the HPA range, one does the construction and the others
 	 * add to that.
 	 */
-	mutex_lock(&cxlrd->range_lock);
+	guard(mutex)(&cxlrd->regions_lock);
 	struct cxl_region *cxlr __free(put_cxl_region) =
 		cxl_find_region_by_range(cxlrd, &ctx.hpa_range);
 	if (!cxlr)
 		cxlr = construct_region(cxlrd, &ctx);
-	mutex_unlock(&cxlrd->range_lock);
 
 	rc = PTR_ERR_OR_ZERO(cxlr);
 	if (rc)
diff --git a/drivers/cxl/cxl.h b/drivers/cxl/cxl.h
index 1297594beaec31..3900a0778571d4 100644
--- a/drivers/cxl/cxl.h
+++ b/drivers/cxl/cxl.h
@@ -359,7 +359,7 @@ struct cxl_rd_ops {
  * @cache_size: extended linear cache size if exists, otherwise zero.
  * @region_id: region id for next region provisioning event
  * @platform_data: platform specific configuration data
- * @range_lock: sync region autodiscovery by address range
+ * @regions_lock: sync region discovery, construction, and deletion
  * @qos_class: QoS performance class cookie
  * @ops: CXL root decoder operations
  * @cxlsd: base cxl switch decoder
@@ -369,7 +369,7 @@ struct cxl_root_decoder {
 	resource_size_t cache_size;
 	atomic_t region_id;
 	void *platform_data;
-	struct mutex range_lock;
+	struct mutex regions_lock;
 	int qos_class;
 	struct cxl_rd_ops ops;
 	struct cxl_switch_decoder cxlsd;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0737/2077] cxl/region: Resolve region deletion races
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (735 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0736/2077] cxl/region: Block region delete during region creation Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0738/2077] cxl/memdev: Pin parents for entire memdev lifetime Greg Kroah-Hartman
                   ` (260 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sungwoo Kim, Dan Williams,
	Alejandro Lucero, Dave Jiang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dan Williams <djbw@kernel.org>

[ Upstream commit 4dd86ca99ffcc413cbf79063fd9956ef54e0ca91 ]

Sungwoo noticed that the sysfs trigger to delete a region may try to delete
a region multiple times. It also has no exclusion relative to the kernel
releasing the region via CXL root device teardown.

Instead of installing new cxl root devres actions per region, use the
existing root decoder unregistration event to remove all remaining regions.
An xarray of regions replaces a devres list of regions.

This handles 3 separate issues with the old approach:

1/ sysfs users racing to delete the same region: no longer possible now
   that the regions_lock is held over the lookup and deletion.

2/ multiple actions triggering deletion of the same region: solved by
   erasing regions while holding @regions_lock, and only proceeding on
   successful erasure.

3/ userspace racing devres_release_all() to trigger the devres not found
   warning: solved by sysfs unregistration not requiring a release action

Fixes: 779dd20cfb56 ("cxl/region: Add region creation support")
Reported-by: Sungwoo Kim <iam@sung-woo.kim>
Closes: http://lore.kernel.org/20260427032010.916681-2-iam@sung-woo.kim
Signed-off-by: Dan Williams <djbw@kernel.org>
Reviewed-by: Alejandro Lucero <alucerop@amd.com>
Tested-by: ALejandro Lucero <alucerop@amd.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Link: https://patch.msgid.link/20260519210158.1499795-3-djbw@kernel.org
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cxl/core/core.h   |  2 ++
 drivers/cxl/core/port.c   |  5 ++++
 drivers/cxl/core/region.c | 60 +++++++++++++++++++++------------------
 drivers/cxl/cxl.h         |  4 +++
 4 files changed, 44 insertions(+), 27 deletions(-)

diff --git a/drivers/cxl/core/core.h b/drivers/cxl/core/core.h
index 82ca3a4767080c..07555ae6385940 100644
--- a/drivers/cxl/core/core.h
+++ b/drivers/cxl/core/core.h
@@ -52,6 +52,7 @@ u64 cxl_dpa_to_hpa(struct cxl_region *cxlr, const struct cxl_memdev *cxlmd,
 		   u64 dpa);
 int devm_cxl_add_dax_region(struct cxl_region *cxlr);
 int devm_cxl_add_pmem_region(struct cxl_region *cxlr);
+void kill_regions(struct cxl_root_decoder *cxlrd);
 
 #else
 static inline u64 cxl_dpa_to_hpa(struct cxl_region *cxlr,
@@ -81,6 +82,7 @@ static inline int cxl_region_init(void)
 static inline void cxl_region_exit(void)
 {
 }
+static inline void kill_regions(struct cxl_root_decoder *cxlrd) { };
 #define CXL_REGION_ATTR(x) NULL
 #define CXL_REGION_TYPE(x) NULL
 #define SET_CXL_REGION_ATTR(x)
diff --git a/drivers/cxl/core/port.c b/drivers/cxl/core/port.c
index 6e7a70d51cfe4d..1215ee4f40351b 100644
--- a/drivers/cxl/core/port.c
+++ b/drivers/cxl/core/port.c
@@ -458,6 +458,8 @@ static void cxl_root_decoder_release(struct device *dev)
 
 	if (atomic_read(&cxlrd->region_id) >= 0)
 		memregion_free(atomic_read(&cxlrd->region_id));
+	mutex_destroy(&cxlrd->regions_lock);
+	xa_destroy(&cxlrd->regions);
 	__cxl_decoder_release(&cxlrd->cxlsd.cxld);
 	kfree(cxlrd);
 }
@@ -2017,6 +2019,7 @@ struct cxl_root_decoder *cxl_root_decoder_alloc(struct cxl_port *port,
 	}
 
 	mutex_init(&cxlrd->regions_lock);
+	xa_init(&cxlrd->regions);
 
 	cxld = &cxlsd->cxld;
 	cxld->dev.type = &cxl_decoder_root_type;
@@ -2192,6 +2195,8 @@ static void cxld_unregister(void *dev)
 	if (is_endpoint_decoder(dev))
 		cxl_decoder_detach(NULL, to_cxl_endpoint_decoder(dev), -1,
 				   DETACH_INVALIDATE);
+	if (is_root_decoder(dev))
+		kill_regions(to_cxl_root_decoder(dev));
 
 	device_unregister(dev);
 }
diff --git a/drivers/cxl/core/region.c b/drivers/cxl/core/region.c
index 3abf7703f7f25e..fda9e97a6ddcd2 100644
--- a/drivers/cxl/core/region.c
+++ b/drivers/cxl/core/region.c
@@ -2548,12 +2548,13 @@ static struct cxl_region *to_cxl_region(struct device *dev)
 	return container_of(dev, struct cxl_region, dev);
 }
 
-static void unregister_region(void *_cxlr)
+static void unregister_region(struct cxl_region *cxlr)
 {
-	struct cxl_region *cxlr = _cxlr;
+	struct cxl_root_decoder *cxlrd = to_cxl_root_decoder(cxlr->dev.parent);
 	struct cxl_region_params *p = &cxlr->params;
 	int i;
 
+	xa_erase(&cxlrd->regions, cxlr->id);
 	device_del(&cxlr->dev);
 
 	/*
@@ -2684,6 +2685,19 @@ static int cxl_region_calculate_adistance(struct notifier_block *nb,
 	return NOTIFY_STOP;
 }
 
+/* unwind all remaining regions */
+void kill_regions(struct cxl_root_decoder *cxlrd)
+{
+	unsigned long index;
+	struct cxl_region *cxlr;
+
+	guard(mutex)(&cxlrd->regions_lock);
+	/* no more region creation */
+	cxlrd->dead = true;
+	xa_for_each(&cxlrd->regions, index, cxlr)
+		unregister_region(cxlr);
+}
+
 /**
  * devm_cxl_add_region - Adds a region to a decoder
  * @cxlrd: root decoder
@@ -2722,14 +2736,15 @@ static struct cxl_region *devm_cxl_add_region(struct cxl_root_decoder *cxlrd,
 	if (rc)
 		goto err;
 
-	rc = devm_add_action_or_reset(port->uport_dev, unregister_region, cxlr);
-	if (rc)
+	rc = xa_insert(&cxlrd->regions, cxlr->id, cxlr, GFP_KERNEL);
+	if (rc) {
+		unregister_region(cxlr);
 		return ERR_PTR(rc);
+	}
 
 	dev_dbg(port->uport_dev, "%s: created %s\n",
 		dev_name(&cxlrd->cxlsd.cxld.dev), dev_name(dev));
 	return cxlr;
-
 err:
 	put_device(dev);
 	return ERR_PTR(rc);
@@ -2758,6 +2773,9 @@ static struct cxl_region *__create_region(struct cxl_root_decoder *cxlrd,
 {
 	int rc;
 
+	if (cxlrd->dead)
+		return ERR_PTR(-ENXIO);
+
 	switch (mode) {
 	case CXL_PARTMODE_RAM:
 	case CXL_PARTMODE_PMEM:
@@ -2833,38 +2851,27 @@ static ssize_t region_show(struct device *dev, struct device_attribute *attr,
 }
 DEVICE_ATTR_RO(region);
 
-static struct cxl_region *
-cxl_find_region_by_name(struct cxl_root_decoder *cxlrd, const char *name)
-{
-	struct cxl_decoder *cxld = &cxlrd->cxlsd.cxld;
-	struct device *region_dev;
-
-	region_dev = device_find_child_by_name(&cxld->dev, name);
-	if (!region_dev)
-		return ERR_PTR(-ENODEV);
-
-	return to_cxl_region(region_dev);
-}
-
 static ssize_t delete_region_store(struct device *dev,
 				   struct device_attribute *attr,
 				   const char *buf, size_t len)
 {
 	struct cxl_root_decoder *cxlrd = to_cxl_root_decoder(dev);
-	struct cxl_port *port = to_cxl_port(dev->parent);
 	struct cxl_region *cxlr;
-	int rc;
+	int rc, id;
 
 	ACQUIRE(mutex_intr, regions_lock)(&cxlrd->regions_lock);
 	if ((rc = ACQUIRE_ERR(mutex_intr, &regions_lock)))
 		return rc;
 
-	cxlr = cxl_find_region_by_name(cxlrd, buf);
-	if (IS_ERR(cxlr))
-		return PTR_ERR(cxlr);
+	rc = sscanf(buf, "region%d\n", &id);
+	if (rc != 1)
+		return -EINVAL;
 
-	devm_release_action(port->uport_dev, unregister_region, cxlr);
-	put_device(&cxlr->dev);
+	cxlr = xa_load(&cxlrd->regions, id);
+	if (!cxlr || !sysfs_streq(buf, dev_name(&cxlr->dev)))
+		return -ENODEV;
+
+	unregister_region(cxlr);
 
 	return len;
 }
@@ -3729,7 +3736,6 @@ static struct cxl_region *construct_region(struct cxl_root_decoder *cxlrd,
 {
 	struct cxl_endpoint_decoder *cxled = ctx->cxled;
 	struct cxl_memdev *cxlmd = cxled_to_memdev(cxled);
-	struct cxl_port *port = cxlrd_to_port(cxlrd);
 	struct cxl_dev_state *cxlds = cxlmd->cxlds;
 	int rc, part = READ_ONCE(cxled->part);
 	struct cxl_region *cxlr;
@@ -3750,7 +3756,7 @@ static struct cxl_region *construct_region(struct cxl_root_decoder *cxlrd,
 
 	rc = __construct_region(cxlr, ctx);
 	if (rc) {
-		devm_release_action(port->uport_dev, unregister_region, cxlr);
+		unregister_region(cxlr);
 		return ERR_PTR(rc);
 	}
 
diff --git a/drivers/cxl/cxl.h b/drivers/cxl/cxl.h
index 3900a0778571d4..f43abd1903ce96 100644
--- a/drivers/cxl/cxl.h
+++ b/drivers/cxl/cxl.h
@@ -360,6 +360,8 @@ struct cxl_rd_ops {
  * @region_id: region id for next region provisioning event
  * @platform_data: platform specific configuration data
  * @regions_lock: sync region discovery, construction, and deletion
+ * @regions: regions to remove at root decoder destruct time
+ * @dead: root decoder dead to region creation
  * @qos_class: QoS performance class cookie
  * @ops: CXL root decoder operations
  * @cxlsd: base cxl switch decoder
@@ -370,6 +372,8 @@ struct cxl_root_decoder {
 	atomic_t region_id;
 	void *platform_data;
 	struct mutex regions_lock;
+	struct xarray regions;
+	bool dead;
 	int qos_class;
 	struct cxl_rd_ops ops;
 	struct cxl_switch_decoder cxlsd;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0738/2077] cxl/memdev: Pin parents for entire memdev lifetime
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (736 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0737/2077] cxl/region: Resolve region deletion races Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0739/2077] power: supply: core: fix supplied_from allocations Greg Kroah-Hartman
                   ` (259 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Williams, Alejandro Lucero,
	Dave Jiang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dan Williams <djbw@kernel.org>

[ Upstream commit bd3a6ff4b84e0fc3fca8556d338270603df13f2e ]

In order to be able to manage the driver that uses a memdev attach
mechanism the parent needs to stick around for the
device_release_driver(cxlmd->dev.parent) event.

Fixes: 29317f8dc6ed ("cxl/mem: Introduce cxl_memdev_attach for CXL-dependent operation")
Signed-off-by: Dan Williams <djbw@kernel.org>
Reviewed-by: Alejandro Lucero <alucerop@amd.com>
Tested-by: ALejandro Lucero <alucerop@amd.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Link: https://patch.msgid.link/20260519210158.1499795-4-djbw@kernel.org
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/cxl/core/memdev.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/cxl/core/memdev.c b/drivers/cxl/core/memdev.c
index 80e65690eb773e..91c99eeea92ce4 100644
--- a/drivers/cxl/core/memdev.c
+++ b/drivers/cxl/core/memdev.c
@@ -25,9 +25,11 @@ static DEFINE_IDA(cxl_memdev_ida);
 static void cxl_memdev_release(struct device *dev)
 {
 	struct cxl_memdev *cxlmd = to_cxl_memdev(dev);
+	struct device *parent = dev->parent;
 
 	ida_free(&cxl_memdev_ida, cxlmd->id);
 	kfree(cxlmd);
+	put_device(parent);
 }
 
 static char *cxl_memdev_devnode(const struct device *dev, umode_t *mode, kuid_t *uid,
@@ -707,7 +709,7 @@ static struct cxl_memdev *cxl_memdev_alloc(struct cxl_dev_state *cxlds,
 	dev = &cxlmd->dev;
 	device_initialize(dev);
 	lockdep_set_class(&dev->mutex, &cxl_memdev_key);
-	dev->parent = cxlds->dev;
+	dev->parent = get_device(cxlds->dev);
 	dev->bus = &cxl_bus_type;
 	dev->devt = MKDEV(cxl_mem_major, cxlmd->id);
 	dev->type = &cxl_memdev_type;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0739/2077] power: supply: core: fix supplied_from allocations
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (737 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0738/2077] cxl/memdev: Pin parents for entire memdev lifetime Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0740/2077] handshake: Require admin permission for DONE command Greg Kroah-Hartman
                   ` (258 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lucas Tsai, Sebastian Reichel,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lucas Tsai <lucas_tsai@richtek.com>

[ Upstream commit ba61aed9a34671222d1149acfc2f0179a9ce7e80 ]

If dts property power-supplies has multiple values, then accessing to
psy->supplied_from[i-1] in __power_supply_populate_supplied_from will
overrun supplied_from array.

Fixes: f6e0b081fb30 ("power_supply: Populate supplied_from hierarchy from the device tree")
Signed-off-by: Lucas Tsai <lucas_tsai@richtek.com>
Link: https://patch.msgid.link/20260609114403.3896073-1-lucas_tsai@richtek.com
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/power/supply/power_supply_core.c | 11 +++--------
 1 file changed, 3 insertions(+), 8 deletions(-)

diff --git a/drivers/power/supply/power_supply_core.c b/drivers/power/supply/power_supply_core.c
index a446d3d086fcd2..2532e221b2e191 100644
--- a/drivers/power/supply/power_supply_core.c
+++ b/drivers/power/supply/power_supply_core.c
@@ -292,18 +292,13 @@ static int power_supply_check_supplies(struct power_supply *psy)
 	if (cnt == 1)
 		return 0;
 
-	/* All supplies found, allocate char ** array for filling */
-	psy->supplied_from = devm_kzalloc(&psy->dev, sizeof(*psy->supplied_from),
+	/* All supplies found, allocate char * array for filling */
+	psy->supplied_from = devm_kcalloc(&psy->dev,
+					  cnt - 1, sizeof(*psy->supplied_from),
 					  GFP_KERNEL);
 	if (!psy->supplied_from)
 		return -ENOMEM;
 
-	*psy->supplied_from = devm_kcalloc(&psy->dev,
-					   cnt - 1, sizeof(**psy->supplied_from),
-					   GFP_KERNEL);
-	if (!*psy->supplied_from)
-		return -ENOMEM;
-
 	return power_supply_populate_supplied_from(psy);
 }
 #else
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0740/2077] handshake: Require admin permission for DONE command
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (738 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0739/2077] power: supply: core: fix supplied_from allocations Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0741/2077] bnxt: fix head underflow on XDP head-grow Greg Kroah-Hartman
                   ` (257 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jeff Layton, Hannes Reinecke,
	Chuck Lever, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 81246a65303d9635266b1334490142caaf86a11f ]

ACCEPT and DONE are the two downcalls of the handshake genl
family, both intended for use by the trusted handshake agent
(tlshd). ACCEPT already requires GENL_ADMIN_PERM; DONE has
no privilege check at all.

The fd-lookup in handshake_nl_done_doit() only confirms that
some pending handshake request exists for the supplied sockfd;
it does not authenticate the sender. An unprivileged process
that guesses or observes a valid sockfd can therefore submit
a DONE with HANDSHAKE_A_DONE_STATUS == 0, leaving the kernel
consumer to proceed as if the handshake succeeded. A non-zero
status on a forged DONE tears down a legitimate in-flight
handshake before tlshd can report its real result.

Fixes: 3b3009ea8abb ("net/handshake: Create a NETLINK service for handling handshake requests")
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Link: https://patch.msgid.link/20260609141831.90694-1-cel@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/netlink/specs/handshake.yaml | 1 +
 net/handshake/genl.c                       | 2 +-
 2 files changed, 2 insertions(+), 1 deletion(-)

diff --git a/Documentation/netlink/specs/handshake.yaml b/Documentation/netlink/specs/handshake.yaml
index 1024297b38513a..ffec12b467597d 100644
--- a/Documentation/netlink/specs/handshake.yaml
+++ b/Documentation/netlink/specs/handshake.yaml
@@ -125,6 +125,7 @@ operations:
       name: done
       doc: Handler reports handshake completion
       attribute-set: done
+      flags: [admin-perm]
       do:
         request:
           attributes:
diff --git a/net/handshake/genl.c b/net/handshake/genl.c
index 4b20cd9cdd0e09..feac1ad063ee72 100644
--- a/net/handshake/genl.c
+++ b/net/handshake/genl.c
@@ -38,7 +38,7 @@ static const struct genl_split_ops handshake_nl_ops[] = {
 		.doit		= handshake_nl_done_doit,
 		.policy		= handshake_done_nl_policy,
 		.maxattr	= HANDSHAKE_A_DONE_REMOTE_AUTH,
-		.flags		= GENL_CMD_CAP_DO,
+		.flags		= GENL_ADMIN_PERM | GENL_CMD_CAP_DO,
 	},
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0741/2077] bnxt: fix head underflow on XDP head-grow
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (739 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0740/2077] handshake: Require admin permission for DONE command Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0742/2077] tcp: clear sock_ops cb flags before force-closing a child socket Greg Kroah-Hartman
                   ` (256 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joe Damato, Michael Chan,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joe Damato <joe@dama.to>

[ Upstream commit e26657fe3b85c068b01f42bb0c602f242d643ba9 ]

The xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on
a bnxt machine (and also crashes in NIPA).

It seems that the bug is an underflow in bnxt_rx_multi_page_skb, which
builds the skb head:

  napi_build_skb(data_ptr - bp->rx_offset, rxr->rx_page_size);

The problem with this expression is that in page mode, rx_offset is:

  bp->rx_offset = NET_IP_ALIGN + XDP_PACKET_HEADROOM;

Which evaluates (at least on x86_64) to 258.

The test test_xdp_native_adjst_head_grow_data tests a case where the
head is adjusted by -256.

When this test runs, data_ptr is shifted to frag_start + 2 (where
frag_start = page_address(page) + offset).

Then, bnxt_rx_multi_page_skb is invoked and the napi_build_skb
expression subtracts 258, landing at an address before frag_start. This
could be either the previous fragment or the previous physical page when
the offset is < 256 (e.g. if the fragment started at offset 0).

When the skb is freed, the page pool fragment reference is dropped on
either the wrong page or the wrong frag of the right page. In either
case, the corrupted reference count can lead to the page being
prematurely recycled while still in use. Once (incorrectly) recycled, it
can be handed out again and on driver teardown this would result in a
double free.

The commit under fixes updated this code to handle the case where the
native page size is >= 64k, but it unintentionally broke the head grow
case.

To fix this, add an offset field to struct bnxt_sw_rx_bd, mirroring the
existing offset field in struct bnxt_sw_rx_agg_bd. Populate it on
allocation and preserve it on reuse.

In bnxt_rx_multi_page_skb, use the newly added offset field to compute
the fragment start and pass that to napi_build_skb. Adjust the layout
with skb_reserve.

There are two cases, the non-adjustment case and the adjustment case.

In both cases, the skb is built at page_address(page) + offset to
account for the case where the native page size >= 64K and skb_reserve
is called with data_ptr - (page_address(page) + offset). That
difference equals bp->rx_offset when data_ptr was not moved, or
bp->rx_offset + xdp_adjust when XDP adjusted the head.

Re-running the failing test with this commit applied causes the test to
run successfully to completion.

The other rx_skb_func implementations don't have this issue.

Fixes: f6974b4c2d8e ("bnxt_en: Fix page pool logic for page size >= 64K")
Signed-off-by: Joe Damato <joe@dama.to>
Reviewed-by: Michael Chan <michael.chan@broadcom.com>
Link: https://patch.msgid.link/20260609204458.2237787-2-joe@dama.to
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/broadcom/bnxt/bnxt.c | 10 ++++++++--
 drivers/net/ethernet/broadcom/bnxt/bnxt.h |  1 +
 2 files changed, 9 insertions(+), 2 deletions(-)

diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.c b/drivers/net/ethernet/broadcom/bnxt/bnxt.c
index c999f9733326a5..1125130449887e 100644
--- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c
+++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c
@@ -1011,6 +1011,7 @@ int bnxt_alloc_rx_data(struct bnxt *bp, struct bnxt_rx_ring_info *rxr,
 		mapping += bp->rx_dma_offset;
 		rx_buf->data = page;
 		rx_buf->data_ptr = page_address(page) + offset + bp->rx_offset;
+		rx_buf->offset = offset;
 	} else {
 		u8 *data = __bnxt_alloc_rx_frag(bp, &mapping, rxr, gfp);
 
@@ -1019,6 +1020,7 @@ int bnxt_alloc_rx_data(struct bnxt *bp, struct bnxt_rx_ring_info *rxr,
 
 		rx_buf->data = data;
 		rx_buf->data_ptr = data + bp->rx_offset;
+		rx_buf->offset = 0;
 	}
 	rx_buf->mapping = mapping;
 
@@ -1040,6 +1042,7 @@ void bnxt_reuse_rx_data(struct bnxt_rx_ring_info *rxr, u16 cons, void *data)
 	prod_rx_buf->data_ptr = cons_rx_buf->data_ptr;
 
 	prod_rx_buf->mapping = cons_rx_buf->mapping;
+	prod_rx_buf->offset = cons_rx_buf->offset;
 
 	prod_bd = &rxr->rx_desc_ring[RX_RING(bp, prod)][RX_IDX(prod)];
 	cons_bd = &rxr->rx_desc_ring[RX_RING(bp, cons)][RX_IDX(cons)];
@@ -1175,8 +1178,11 @@ static struct sk_buff *bnxt_rx_multi_page_skb(struct bnxt *bp,
 	struct page *page = data;
 	u16 prod = rxr->rx_prod;
 	struct sk_buff *skb;
+	void *frag_start;
 	int err;
 
+	frag_start = page_address(page) + rxr->rx_buf_ring[cons].offset;
+
 	err = bnxt_alloc_rx_data(bp, rxr, prod, GFP_ATOMIC);
 	if (unlikely(err)) {
 		bnxt_reuse_rx_data(rxr, cons, data);
@@ -1185,13 +1191,13 @@ static struct sk_buff *bnxt_rx_multi_page_skb(struct bnxt *bp,
 	dma_addr -= bp->rx_dma_offset;
 	dma_sync_single_for_cpu(&bp->pdev->dev, dma_addr, rxr->rx_page_size,
 				bp->rx_dir);
-	skb = napi_build_skb(data_ptr - bp->rx_offset, rxr->rx_page_size);
+	skb = napi_build_skb(frag_start, rxr->rx_page_size);
 	if (!skb) {
 		page_pool_recycle_direct(rxr->page_pool, page);
 		return NULL;
 	}
 	skb_mark_for_recycle(skb);
-	skb_reserve(skb, bp->rx_offset);
+	skb_reserve(skb, data_ptr - (u8 *)frag_start);
 	__skb_put(skb, len);
 
 	return skb;
diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.h b/drivers/net/ethernet/broadcom/bnxt/bnxt.h
index 61c847b36b9ff3..a2e75cfb65ab04 100644
--- a/drivers/net/ethernet/broadcom/bnxt/bnxt.h
+++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.h
@@ -911,6 +911,7 @@ struct bnxt_sw_rx_bd {
 	void			*data;
 	u8			*data_ptr;
 	dma_addr_t		mapping;
+	unsigned int		offset;
 };
 
 struct bnxt_sw_rx_agg_bd {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0742/2077] tcp: clear sock_ops cb flags before force-closing a child socket
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (740 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0741/2077] bnxt: fix head underflow on XDP head-grow Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0743/2077] virtio_net: do not allow tunnel csum offload for non GSO packets Greg Kroah-Hartman
                   ` (255 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jiayuan Chen, Sechang Lim,
	Kuniyuki Iwashima, Eric Dumazet, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sechang Lim <rhkrqnwk98@gmail.com>

[ Upstream commit 990348e5bb457697c2f1f7f7b65154a3334d9d2b ]

A child socket inherits the listener's bpf_sock_ops_cb_flags via
sk_clone_lock(). If its setup fails in tcp_v4_syn_recv_sock() /
tcp_v6_syn_recv_sock(), the child is freed through put_and_exit, where
inet_csk_prepare_forced_close() drops the socket lock and tcp_done() runs
without it.

If BPF_SOCK_OPS_STATE_CB_FLAG was inherited, tcp_done() -> tcp_set_state()
calls tcp_call_bpf(), which expects the lock and trips sock_owned_by_me():

  WARNING: include/net/sock.h:1799 at tcp_set_state+0x433/0x550
  RIP: 0010:tcp_set_state+0x433/0x550 include/net/sock.h:1799
  Call Trace:
   <IRQ>
   tcp_done+0xba/0x250 net/ipv4/tcp.c:5095
   tcp_v4_syn_recv_sock+0x850/0xa50 net/ipv4/tcp_ipv4.c:1787
   tcp_check_req+0xf30/0x1360 net/ipv4/tcp_minisocks.c:926
   tcp_v4_rcv+0x1047/0x1b50 net/ipv4/tcp_ipv4.c:2164
   </IRQ>

The child is freed before it is ever established, so it should run no
sock_ops callback. Clear its cb flags in inet_csk_prepare_for_destroy_sock(),
the common point for the IPv4, IPv6 and chtls forced-close paths and for the
MPTCP ->syn_recv_sock() failure path (dispose_child), which reaches tcp_done()
on a child that was never established too.

Suggested-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Fixes: d44874910a26 ("bpf: Add BPF_SOCK_OPS_STATE_CB")
Signed-off-by: Sechang Lim <rhkrqnwk98@gmail.com>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260611092923.1895982-1-rhkrqnwk98@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/net/tcp.h               | 9 +++++++++
 net/ipv4/inet_connection_sock.c | 1 +
 2 files changed, 10 insertions(+)

diff --git a/include/net/tcp.h b/include/net/tcp.h
index 98848db62894aa..607298501e1230 100644
--- a/include/net/tcp.h
+++ b/include/net/tcp.h
@@ -2942,6 +2942,11 @@ static inline int tcp_call_bpf_3arg(struct sock *sk, int op, u32 arg1, u32 arg2,
 	return tcp_call_bpf(sk, op, 3, args);
 }
 
+static inline void tcp_clear_sock_ops_cb_flags(struct sock *sk)
+{
+	tcp_sk(sk)->bpf_sock_ops_cb_flags = 0;
+}
+
 #else
 static inline int tcp_call_bpf(struct sock *sk, int op, u32 nargs, u32 *args)
 {
@@ -2959,6 +2964,10 @@ static inline int tcp_call_bpf_3arg(struct sock *sk, int op, u32 arg1, u32 arg2,
 	return -EPERM;
 }
 
+static inline void tcp_clear_sock_ops_cb_flags(struct sock *sk)
+{
+}
+
 #endif
 
 static inline u32 tcp_timeout_init(struct sock *sk)
diff --git a/net/ipv4/inet_connection_sock.c b/net/ipv4/inet_connection_sock.c
index 5b934ce8d98a8c..690f7fb3f029e8 100644
--- a/net/ipv4/inet_connection_sock.c
+++ b/net/ipv4/inet_connection_sock.c
@@ -1285,6 +1285,7 @@ EXPORT_SYMBOL(inet_csk_destroy_sock);
 void inet_csk_prepare_for_destroy_sock(struct sock *sk)
 {
 	/* The below has to be done to allow calling inet_csk_destroy_sock */
+	tcp_clear_sock_ops_cb_flags(sk);
 	sock_set_flag(sk, SOCK_DEAD);
 	tcp_orphan_count_inc();
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0743/2077] virtio_net: do not allow tunnel csum offload for non GSO packets
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (741 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0742/2077] tcp: clear sock_ops cb flags before force-closing a child socket Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0744/2077] net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen Greg Kroah-Hartman
                   ` (254 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Fiona Ebner, Gabriel Goller,
	Michael S. Tsirkin, Paolo Abeni, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Paolo Abeni <pabeni@redhat.com>

[ Upstream commit 86c51f0f23136ea5ef5541f607287e07150cd23f ]

Fiona reports broken connectivity for virtio net setup using UDP tunnel
inside the guest and NIC with not UDP tunnel TSO support in the host.

Currently the virtio_net driver exposes csum offload for UDP-tunneled,
TCP non GSO packets. Such packet reach the host as CSUM_PARTIAL ones
with the 'encapsulation' flag cleared, as the virtio specification do
not support this specific kind of offload.

HW NICs with UDP tunnel TSO support - and those drivers directly
accessing skb->csum_start/csum_offset - are still capable of computing
the needed csum correctly, but otherwise the packets reach the wire with
bad csum on both the inner and outer transport header.

Address the issue explicitly disabling csum offload for UDP tunneled,
non GSO packets via the ndo_features_check op.

Fixes: 56a06bd40fab ("virtio_net: enable gso over UDP tunnel support.")
Reported-by: Fiona Ebner <f.ebner@proxmox.com>
Closes: https://bugzilla.proxmox.com/show_bug.cgi?id=7627
Tested-by: Fiona Ebner <f.ebner@proxmox.com>
Tested-by: Gabriel Goller <g.goller@proxmox.com>
Acked-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Gabriel Goller <g.goller@proxmox.com>
Tested-by: Gabriel Goller <g.goller@proxmox.com>
Link: https://patch.msgid.link/6c3b6c47fb05c100f384630dc48f3975cf37b67a.1781195144.git.pabeni@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/virtio_net.c | 15 ++++++++++++++-
 1 file changed, 14 insertions(+), 1 deletion(-)

diff --git a/drivers/net/virtio_net.c b/drivers/net/virtio_net.c
index f4adcfee7a8001..7d2eeb9b122667 100644
--- a/drivers/net/virtio_net.c
+++ b/drivers/net/virtio_net.c
@@ -6222,6 +6222,19 @@ static void virtnet_free_irq_moder(struct virtnet_info *vi)
 	rtnl_unlock();
 }
 
+static netdev_features_t virtnet_features_check(struct sk_buff *skb,
+						struct net_device *dev,
+						netdev_features_t features)
+{
+	/* Inner csum offload is only available for GSO packets. */
+	if (skb->encapsulation &&
+	    (!skb_is_gso(skb) || netif_needs_gso(skb, features)))
+		return features & ~NETIF_F_CSUM_MASK;
+
+	/* Passthru. */
+	return features;
+}
+
 static const struct net_device_ops virtnet_netdev = {
 	.ndo_open            = virtnet_open,
 	.ndo_stop   	     = virtnet_close,
@@ -6235,7 +6248,7 @@ static const struct net_device_ops virtnet_netdev = {
 	.ndo_bpf		= virtnet_xdp,
 	.ndo_xdp_xmit		= virtnet_xdp_xmit,
 	.ndo_xsk_wakeup         = virtnet_xsk_wakeup,
-	.ndo_features_check	= passthru_features_check,
+	.ndo_features_check	= virtnet_features_check,
 	.ndo_get_phys_port_name	= virtnet_get_phys_port_name,
 	.ndo_set_features	= virtnet_set_features,
 	.ndo_tx_timeout		= virtnet_tx_timeout,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0744/2077] net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (742 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0743/2077] virtio_net: do not allow tunnel csum offload for non GSO packets Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0745/2077] net/sched: sch_codel: " Greg Kroah-Hartman
                   ` (253 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anirudh Gupta, Jamal Hadi Salim,
	Victor Nogueira, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Victor Nogueira <victor@mojatatu.com>

[ Upstream commit 097f6fc7b1ae362dd7a9444b2572162fda73b284 ]

Whenever fq_codel drops packets during peek, it calls
qdisc_tree_reduce_backlog. An issue arises because it calls
qdisc_tree_reduce_backlog before it reincrements the qlen. If qlen drops
to zero, but peek returns an skb, the parent's qlen_notify callback will be
executed even though fq_codel still has 1 packet on the queue and, thus,
will mistakenly deactivate the parent's class causing issues like a recent
report [1] and a wild memory access in qfq:

[   29.371146][  T360] Oops: general protection fault, probably for non-canonical address 0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI
[   29.371666][  T360] KASAN: maybe wild-memory-access in range [0xdead000000000120-0xdead000000000127]
[   29.371987][  T360] CPU: 6 UID: 0 PID: 360 Comm: tc Not tainted 7.1.0-rc5-00285-gc530e5b2dbc6-dirty #82 PREEMPT(full)
[   29.372384][  T360] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[   29.372620][  T360] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:1029 (discriminator 2) include/linux/list.h:1043 (discriminator 2) net/sched/sch_qfq.c:1369 (discriminator 2) net/sched/sch_qfq.c:1395 (discriminator 2)) sch_qfq
[   29.373544][  T360] RSP: 0018:ffff888102417370 EFLAGS: 00010216
[   29.373800][  T360] RAX: 0000000000000000 RBX: ffff88811224d568 RCX: dffffc0000000000
[   29.374079][  T360] RDX: 1ffff11021fe1543 RSI: ffff88810ff0aa00 RDI: dffffc0000000000
[   29.374368][  T360] RBP: ffff88811224c280 R08: dead000000000122 R09: 1bd5a00000000024
[   29.374649][  T360] R10: fffffbfff7940329 R11: fffffbfff7940329 R12: 0000000000000000
[   29.374926][  T360] R13: dead000000000100 R14: ffff88811224d580 R15: ffff88811224d578
[   29.375207][  T360] FS:  00007f5b794e5780(0000) GS:ffff88815d1e9000(0000) knlGS:0000000000000000
[   29.375545][  T360] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   29.375823][  T360] CR2: 000055ffb091f000 CR3: 000000010a305000 CR4: 0000000000750ef0
[   29.376103][  T360] PKRU: 55555554
[   29.376258][  T360] Call Trace:
[   29.376401][  T360]  <TASK>
...
[   29.376885][  T360] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1487) sch_qfq
[   29.377074][  T360]  qdisc_reset (net/sched/sch_generic.c:1057)
[   29.377414][  T360]  __qdisc_destroy (net/sched/sch_generic.c:1096)
[   29.377600][  T360]  qdisc_graft (net/sched/sch_api.c:1062 net/sched/sch_api.c:1053 net/sched/sch_api.c:1159)
[   29.378593][  T360]  tc_get_qdisc (net/sched/sch_api.c:1528 net/sched/sch_api.c:1556)

Fix this by only calling qdisc_tree_reduce_backlog in peek after the
qlen is restored.

[1] http://lore.kernel.org/netdev/CAN2cbVe79oj0O9==m4+4x3v+O+qzRagA=2=wkrp9i9=CqYvyZA@mail.gmail.com/

Fixes: 342debc12183 ("codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()")
Reported-by: Anirudh Gupta <anirudhrudr@gmail.com>
Closes: https://lore.kernel.org/netdev/CAN2cbVe79oj0O9==m4+4x3v+O+qzRagA=2=wkrp9i9=CqYvyZA@mail.gmail.com/
Tested-by: Anirudh Gupta <anirudhrudr@gmail.com>
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
Link: https://patch.msgid.link/20260610192855.3121513-2-victor@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/sch_fq_codel.c | 41 ++++++++++++++++++++++++++++++++++++++--
 1 file changed, 39 insertions(+), 2 deletions(-)

diff --git a/net/sched/sch_fq_codel.c b/net/sched/sch_fq_codel.c
index 5302d50f4bef6c..09ab84580160ae 100644
--- a/net/sched/sch_fq_codel.c
+++ b/net/sched/sch_fq_codel.c
@@ -281,7 +281,7 @@ static void drop_func(struct sk_buff *skb, void *ctx)
 	qdisc_qstats_drop(sch);
 }
 
-static struct sk_buff *fq_codel_dequeue(struct Qdisc *sch)
+static struct sk_buff *__fq_codel_dequeue(struct Qdisc *sch)
 {
 	struct fq_codel_sched_data *q = qdisc_priv(sch);
 	struct sk_buff *skb;
@@ -318,12 +318,49 @@ static struct sk_buff *fq_codel_dequeue(struct Qdisc *sch)
 	qdisc_bstats_update(sch, skb);
 	WRITE_ONCE(flow->deficit, flow->deficit - qdisc_pkt_len(skb));
 
+	return skb;
+}
+
+static void fq_codel_dequeue_drop(struct Qdisc *sch)
+{
+	struct fq_codel_sched_data *q = qdisc_priv(sch);
+
 	if (q->cstats.drop_count) {
 		qdisc_tree_reduce_backlog(sch, q->cstats.drop_count,
 					  q->cstats.drop_len);
 		q->cstats.drop_count = 0;
 		q->cstats.drop_len = 0;
 	}
+}
+
+static struct sk_buff *fq_codel_dequeue(struct Qdisc *sch)
+{
+	struct sk_buff *skb;
+
+	skb =  __fq_codel_dequeue(sch);
+
+	fq_codel_dequeue_drop(sch);
+
+	return skb;
+}
+
+static struct sk_buff *fq_codel_peek(struct Qdisc *sch)
+{
+	struct sk_buff *skb = skb_peek(&sch->gso_skb);
+
+	if (!skb) {
+		skb = __fq_codel_dequeue(sch);
+
+		if (skb) {
+			__skb_queue_head(&sch->gso_skb, skb);
+			/* it's still part of the queue */
+			qdisc_qstats_backlog_inc(sch, skb);
+			sch->q.qlen++;
+		}
+
+		fq_codel_dequeue_drop(sch);
+	}
+
 	return skb;
 }
 
@@ -726,7 +763,7 @@ static struct Qdisc_ops fq_codel_qdisc_ops __read_mostly = {
 	.priv_size	=	sizeof(struct fq_codel_sched_data),
 	.enqueue	=	fq_codel_enqueue,
 	.dequeue	=	fq_codel_dequeue,
-	.peek		=	qdisc_peek_dequeued,
+	.peek		=	fq_codel_peek,
 	.init		=	fq_codel_init,
 	.reset		=	fq_codel_reset,
 	.destroy	=	fq_codel_destroy,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0745/2077] net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (743 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0744/2077] net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:06 ` [PATCH 7.1 0746/2077] net/sched: sch_dualpi2: " Greg Kroah-Hartman
                   ` (252 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jamal Hadi Salim, Victor Nogueira,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Victor Nogueira <victor@mojatatu.com>

[ Upstream commit 52f1da34c9f4d5bdc1e8b44242da5c7ba8db85f3 ]

Whenever codel drops packets during peek, it calls
qdisc_tree_reduce_backlog. An issue arises because it calls
qdisc_tree_reduce_backlog before it reincrements the qlen. If qlen drops
to zero, but peek returns an skb, the parent's qlen_notify callback will
be executed even though codel still has 1 packet on the queue and, thus,
will mistakenly deactivate the parent's class causing issues like a wild
memory access when qfq has codel as a child:

[   36.339843][  T370] Oops: general protection fault, probably for non-canonical address 0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI
[   36.340408][  T370] KASAN: maybe wild-memory-access in range [0xdead000000000120-0xdead000000000127]
[   36.340737][  T370] CPU: 2 UID: 0 PID: 370 Comm: tc Not tainted 7.1.0-rc5-00287-g66e13b626592 #87 PREEMPT(full)
[   36.341113][  T370] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[   36.341357][  T370] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:1029 (discriminator 2) include/linux/list.h:1043 (discriminator 2) net/sched/sch_qfq.c:1369 (discriminator 2) net/sched/sch_qfq.c:1395 (discriminator 2)) sch_qfq
[   36.342221][  T370] RSP: 0018:ffff8881100ef370 EFLAGS: 00010216
[   36.342422][  T370] RAX: 0000000000000000 RBX: ffff8881058a9568 RCX: dffffc0000000000
[   36.342664][  T370] RDX: 1ffff11021064dc3 RSI: ffff888108326e00 RDI: dffffc0000000000
[   36.342905][  T370] RBP: ffff8881058a8280 R08: dead000000000122 R09: 1bd5a00000000024
[   36.343140][  T370] R10: fffffbfff2940329 R11: fffffbfff2940329 R12: 0000000000000000
[   36.343383][  T370] R13: dead000000000100 R14: ffff8881058a9580 R15: ffff8881058a9578
[   36.343631][  T370] FS:  00007fc04b0ca780(0000) GS:ffff888184fef000(0000) knlGS:0000000000000000
[   36.343911][  T370] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   36.344116][  T370] CR2: 0000557c02c02000 CR3: 000000010e0ba000 CR4: 0000000000750ef0
[   36.344359][  T370] PKRU: 55555554
[   36.344481][  T370] Call Trace:
...
[   36.345054][  T370] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1487) sch_qfq
[   36.345222][  T370]  qdisc_reset (net/sched/sch_generic.c:1057)
[   36.345503][  T370]  __qdisc_destroy (net/sched/sch_generic.c:1096)
[   36.345677][  T370]  qdisc_graft (net/sched/sch_api.c:1062 net/sched/sch_api.c:1053 net/sched/sch_api.c:1159)
[   36.346335][  T370]  tc_get_qdisc (net/sched/sch_api.c:1528 net/sched/sch_api.c:1556)

Fix this by only calling qdisc_tree_reduce_backlog in peek after the
qlen is restored.

Fixes: 342debc12183 ("codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()")
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
Link: https://patch.msgid.link/20260610192855.3121513-3-victor@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/sch_codel.c | 48 ++++++++++++++++++++++++++++++++++++++-----
 1 file changed, 43 insertions(+), 5 deletions(-)

diff --git a/net/sched/sch_codel.c b/net/sched/sch_codel.c
index 317aae0ec7bd6a..7d5076196aff68 100644
--- a/net/sched/sch_codel.c
+++ b/net/sched/sch_codel.c
@@ -56,7 +56,7 @@ static void drop_func(struct sk_buff *skb, void *ctx)
 	qdisc_qstats_drop(sch);
 }
 
-static struct sk_buff *codel_qdisc_dequeue(struct Qdisc *sch)
+static struct sk_buff *__codel_qdisc_dequeue(struct Qdisc *sch)
 {
 	struct codel_sched_data *q = qdisc_priv(sch);
 	struct sk_buff *skb;
@@ -65,13 +65,51 @@ static struct sk_buff *codel_qdisc_dequeue(struct Qdisc *sch)
 			    &q->stats, qdisc_pkt_len, codel_get_enqueue_time,
 			    drop_func, dequeue_func);
 
+	if (skb)
+		qdisc_bstats_update(sch, skb);
+	return skb;
+}
+
+static void codel_dequeue_drop(struct Qdisc *sch)
+{
+	struct codel_sched_data *q = qdisc_priv(sch);
+
 	if (q->stats.drop_count) {
-		qdisc_tree_reduce_backlog(sch, q->stats.drop_count, q->stats.drop_len);
+		qdisc_tree_reduce_backlog(sch, q->stats.drop_count,
+					  q->stats.drop_len);
 		q->stats.drop_count = 0;
 		q->stats.drop_len = 0;
 	}
-	if (skb)
-		qdisc_bstats_update(sch, skb);
+}
+
+static struct sk_buff *codel_qdisc_dequeue(struct Qdisc *sch)
+{
+	struct sk_buff *skb;
+
+	skb = __codel_qdisc_dequeue(sch);
+
+	codel_dequeue_drop(sch);
+
+	return skb;
+}
+
+static struct sk_buff *codel_peek(struct Qdisc *sch)
+{
+	struct sk_buff *skb = skb_peek(&sch->gso_skb);
+
+	if (!skb) {
+		skb = __codel_qdisc_dequeue(sch);
+
+		if (skb) {
+			__skb_queue_head(&sch->gso_skb, skb);
+			/* it's still part of the queue */
+			qdisc_qstats_backlog_inc(sch, skb);
+			sch->q.qlen++;
+		}
+
+		codel_dequeue_drop(sch);
+	}
+
 	return skb;
 }
 
@@ -257,7 +295,7 @@ static struct Qdisc_ops codel_qdisc_ops __read_mostly = {
 
 	.enqueue	=	codel_qdisc_enqueue,
 	.dequeue	=	codel_qdisc_dequeue,
-	.peek		=	qdisc_peek_dequeued,
+	.peek		=	codel_peek,
 	.init		=	codel_init,
 	.reset		=	codel_reset,
 	.change 	=	codel_change,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0746/2077] net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (744 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0745/2077] net/sched: sch_codel: " Greg Kroah-Hartman
@ 2026-07-21 15:06 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0747/2077] net: mana: initialize gdma queue id to INVALID_QUEUE_ID Greg Kroah-Hartman
                   ` (251 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:06 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jamal Hadi Salim, Victor Nogueira,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Victor Nogueira <victor@mojatatu.com>

[ Upstream commit 15cd0c93bf4f892d66bc7a93667e2357b5673365 ]

Whenever dualpi2 drops packets during peek, it calls
qdisc_tree_reduce_backlog. An issue arises because it calls
qdisc_tree_reduce_backlog before it reincrements the qlen. If qlen drops
to zero, but peek returns an skb, the parent's qlen_notify callback will be
executed even though dualpi2 still has 1 packet on the queue and, thus,
mistakenly deactivates the parent's class which leads to a null-ptr-deref:

[  101.427314][  T599] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000009: 0000 [#1] SMP KASAN NOPTI
[  101.427755][  T599] KASAN: null-ptr-deref in range [0x0000000000000048-0x000000000000004f]
[  101.428048][  T599] CPU: 2 UID: 0 PID: 599 Comm: ping Not tainted 7.1.0-rc5-00284-gbce53c430ed7 #102 PREEMPT(full)
[  101.428400][  T599] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[  101.428608][  T599] RIP: 0010:qfq_dequeue (net/sched/sch_qfq.c:1150) sch_qfq
[  101.428821][  T599] Code: 00 fc ff df 80 3c 02 00 0f 85 46 0c 00 00 4c 8d 73 48 48 89 9d b8 02 00 00 48 b8 00 00 00 00 00 fc ff df 4c 89 f2 48 c1 ea 03 <80> 3c 02 00 0f 85 2d 0c 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b
All code
[  101.429348][  T599] RSP: 0018:ffff8881110df4f0 EFLAGS: 00010216
[  101.429541][  T599] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: dffffc0000000000
[  101.429763][  T599] RDX: 0000000000000009 RSI: 00000024c0000000 RDI: ffff88811436c2b0
[  101.429985][  T599] RBP: ffff88811436c000 R08: ffff88811436c280 R09: 1ffff11021277523
[  101.430206][  T599] R10: 1ffff11021277526 R11: 1ffff11021277527 R12: 00000024c0000000
[  101.430423][  T599] R13: ffff88811436c2b8 R14: 0000000000000048 R15: 0000000020000000
[  101.430642][  T599] FS:  00007f61813e1c40(0000) GS:ffff8881691ef000(0000) knlGS:0000000000000000
[  101.430913][  T599] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  101.431100][  T599] CR2: 00005651650850a8 CR3: 000000010ca0b000 CR4: 0000000000750ef0
[  101.431320][  T599] PKRU: 55555554
[  101.431433][  T599] Call Trace:
[  101.431544][  T599]  <TASK>
[  101.431628][  T599]  __qdisc_run (net/sched/sch_generic.c:322 net/sched/sch_generic.c:427 net/sched/sch_generic.c:445)
[  101.431792][  T599]  ? dev_qdisc_enqueue (./include/trace/events/qdisc.h:49 (discriminator 22) net/core/dev.c:4176 (discriminator 22))
[  101.431941][  T599]  __dev_queue_xmit (./include/net/pkt_sched.h:120 ./include/net/pkt_sched.h:117 net/core/dev.c:4292 net/core/dev.c:4831)

Fix this by only calling qdisc_tree_reduce_backlog in peek after the
qlen is restored.

Fixes: 8f9516daedd6 ("sched: Add enqueue/dequeue of dualpi2 qdisc")
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
Link: https://patch.msgid.link/20260610192855.3121513-4-victor@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/sch_dualpi2.c | 41 +++++++++++++++++++++++++++++++++++++++--
 1 file changed, 39 insertions(+), 2 deletions(-)

diff --git a/net/sched/sch_dualpi2.c b/net/sched/sch_dualpi2.c
index b81a922f5e4684..592c58938d3e80 100644
--- a/net/sched/sch_dualpi2.c
+++ b/net/sched/sch_dualpi2.c
@@ -577,7 +577,7 @@ static void drop_and_retry(struct dualpi2_sched_data *q, struct sk_buff *skb,
 	qdisc_qstats_drop(sch);
 }
 
-static struct sk_buff *dualpi2_qdisc_dequeue(struct Qdisc *sch)
+static struct sk_buff *__dualpi2_qdisc_dequeue(struct Qdisc *sch)
 {
 	struct dualpi2_sched_data *q = qdisc_priv(sch);
 	struct sk_buff *skb;
@@ -604,12 +604,49 @@ static struct sk_buff *dualpi2_qdisc_dequeue(struct Qdisc *sch)
 		break;
 	}
 
+	return skb;
+}
+
+static void dualpi2_dequeue_drop(struct Qdisc *sch)
+{
+	struct dualpi2_sched_data *q = qdisc_priv(sch);
+
 	if (q->deferred_drops_cnt) {
 		qdisc_tree_reduce_backlog(sch, q->deferred_drops_cnt,
 					  q->deferred_drops_len);
 		q->deferred_drops_cnt = 0;
 		q->deferred_drops_len = 0;
 	}
+}
+
+static struct sk_buff *dualpi2_qdisc_dequeue(struct Qdisc *sch)
+{
+	struct sk_buff *skb;
+
+	skb = __dualpi2_qdisc_dequeue(sch);
+
+	dualpi2_dequeue_drop(sch);
+
+	return skb;
+}
+
+static struct sk_buff *dualpi2_peek(struct Qdisc *sch)
+{
+	struct sk_buff *skb = skb_peek(&sch->gso_skb);
+
+	if (!skb) {
+		skb = __dualpi2_qdisc_dequeue(sch);
+
+		if (skb) {
+			__skb_queue_head(&sch->gso_skb, skb);
+			/* it's still part of the queue */
+			qdisc_qstats_backlog_inc(sch, skb);
+			sch->q.qlen++;
+		}
+
+		dualpi2_dequeue_drop(sch);
+	}
+
 	return skb;
 }
 
@@ -1164,7 +1201,7 @@ static struct Qdisc_ops dualpi2_qdisc_ops __read_mostly = {
 	.priv_size	= sizeof(struct dualpi2_sched_data),
 	.enqueue	= dualpi2_qdisc_enqueue,
 	.dequeue	= dualpi2_qdisc_dequeue,
-	.peek		= qdisc_peek_dequeued,
+	.peek		= dualpi2_peek,
 	.init		= dualpi2_init,
 	.destroy	= dualpi2_destroy,
 	.reset		= dualpi2_reset,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0747/2077] net: mana: initialize gdma queue id to INVALID_QUEUE_ID
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (745 preceding siblings ...)
  2026-07-21 15:06 ` [PATCH 7.1 0746/2077] net/sched: sch_dualpi2: " Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0748/2077] net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check Greg Kroah-Hartman
                   ` (250 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Aditya Garg, Dipayaan Roy,
	Haiyang Zhang, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aditya Garg <gargaditya@linux.microsoft.com>

[ Upstream commit 5985474e1cb4034680fac2145497a94b0860be50 ]

mana_gd_create_mana_wq_cq() leaves queue->id as 0 (from kzalloc_obj())
until mana_create_wq_obj() assigns the firmware-returned id. If creation
fails before that, cleanup calls mana_gd_destroy_cq() with id 0, NULLing
gc->cq_table[0] and silently breaking whichever real CQ owns that slot.

Initialize queue->id to INVALID_QUEUE_ID right after allocation, matching
mana_gd_create_eq(). The existing (id >= max_num_cqs) guard then
short-circuits cleanly.

Fixes: ca9c54d2d6a5 ("net: mana: Add a driver for Microsoft Azure Network Adapter (MANA)")
Signed-off-by: Aditya Garg <gargaditya@linux.microsoft.com>
Reviewed-by: Dipayaan Roy <dipayanroy@linux.microsoft.com>
Reviewed-by: Haiyang Zhang <haiyangz@microsoft.com>
Link: https://patch.msgid.link/20260608101345.2267320-2-gargaditya@linux.microsoft.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/microsoft/mana/gdma_main.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/net/ethernet/microsoft/mana/gdma_main.c b/drivers/net/ethernet/microsoft/mana/gdma_main.c
index d8e816882f02c2..ac71ca8450bf43 100644
--- a/drivers/net/ethernet/microsoft/mana/gdma_main.c
+++ b/drivers/net/ethernet/microsoft/mana/gdma_main.c
@@ -1192,6 +1192,8 @@ int mana_gd_create_mana_wq_cq(struct gdma_dev *gd,
 	if (!queue)
 		return -ENOMEM;
 
+	queue->id = INVALID_QUEUE_ID;
+
 	gmi = &queue->mem_info;
 	err = mana_gd_alloc_memory(gc, spec->queue_size, gmi);
 	if (err) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0748/2077] net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (746 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0747/2077] net: mana: initialize gdma queue id to INVALID_QUEUE_ID Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0749/2077] net: watchdog: fix refcount tracking races Greg Kroah-Hartman
                   ` (249 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Aditya Garg, Dipayaan Roy,
	Haiyang Zhang, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aditya Garg <gargaditya@linux.microsoft.com>

[ Upstream commit f8fd56977eeea3d6939b1a9cd8bd36f1779b3ad0 ]

mana_create_txq() has several error paths (after mana_alloc_queues() or
mana_create_wq_obj() failure) where tx_qp[i].tx_object stays as the
INVALID_MANA_HANDLE sentinel set at allocation. mana_destroy_txq() then
unconditionally calls mana_destroy_wq_obj() with (u64)-1, which firmware
rejects and logs an error.

Mirror the RX-side pattern in mana_destroy_rxq() and skip the destroy
when the handle is still INVALID_MANA_HANDLE.

Fixes: ca9c54d2d6a5 ("net: mana: Add a driver for Microsoft Azure Network Adapter (MANA)")
Signed-off-by: Aditya Garg <gargaditya@linux.microsoft.com>
Reviewed-by: Dipayaan Roy <dipayanroy@linux.microsoft.com>
Reviewed-by: Haiyang Zhang <haiyangz@microsoft.com>
Link: https://patch.msgid.link/20260608101345.2267320-3-gargaditya@linux.microsoft.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/microsoft/mana/mana_en.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/microsoft/mana/mana_en.c b/drivers/net/ethernet/microsoft/mana/mana_en.c
index c9b1df1ed1098c..d7de4c4d25bbe5 100644
--- a/drivers/net/ethernet/microsoft/mana/mana_en.c
+++ b/drivers/net/ethernet/microsoft/mana/mana_en.c
@@ -2334,7 +2334,8 @@ static void mana_destroy_txq(struct mana_port_context *apc)
 			netif_napi_del_locked(napi);
 			apc->tx_qp[i].txq.napi_initialized = false;
 		}
-		mana_destroy_wq_obj(apc, GDMA_SQ, apc->tx_qp[i].tx_object);
+		if (apc->tx_qp[i].tx_object != INVALID_MANA_HANDLE)
+			mana_destroy_wq_obj(apc, GDMA_SQ, apc->tx_qp[i].tx_object);
 
 		mana_deinit_cq(apc, &apc->tx_qp[i].tx_cq);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0749/2077] net: watchdog: fix refcount tracking races
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (747 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0748/2077] net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0750/2077] net: ethernet: mtk_wed: fix loading WO firmware for MT7986 Greg Kroah-Hartman
                   ` (248 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+381d82bbf0253710b35d,
	syzbot+3479efbc2821cb2a79f2, Eric Dumazet, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 8eed5519e496b7a07f441a0f579cb228a33189f7 ]

Blamed commit converted the untracked dev_hold()/dev_put() calls
in the watchdog code to use the tracked dev_hold_track()/dev_put_track()
(which were later renamed/interfaced to netdev_hold() and netdev_put()).

By introducing dev->watchdog_dev_tracker to store the
reference tracking information without adding synchronization
between netdev_watchdog_up() and dev_watchdog(), it enabled the
race condition where this pointer could be overwritten or freed
concurrently, leading to the list corruption crash syzbot reported:

list_del corruption, ffff888114a18c00->next is NULL
 kernel BUG at lib/list_debug.c:52 !
Oops: invalid opcode: 0000 [#1] SMP KASAN PTI
CPU: 1 UID: 0 PID: 91 Comm: kworker/u8:5 Not tainted syzkaller #0 PREEMPT(lazy)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/09/2026
Workqueue: events_unbound linkwatch_event
 RIP: 0010:__list_del_entry_valid_or_report.cold+0x22/0x2a lib/list_debug.c:52
Call Trace:
 <TASK>
  __list_del_entry_valid include/linux/list.h:132 [inline]
  __list_del_entry include/linux/list.h:246 [inline]
  list_move_tail include/linux/list.h:341 [inline]
  ref_tracker_free+0x1a7/0x6c0 lib/ref_tracker.c:329
  netdev_tracker_free include/linux/netdevice.h:4491 [inline]
  netdev_put include/linux/netdevice.h:4508 [inline]
  netdev_put include/linux/netdevice.h:4504 [inline]
  netdev_watchdog_down net/sched/sch_generic.c:600 [inline]
  dev_deactivate_many+0x28c/0xfe0 net/sched/sch_generic.c:1363
  dev_deactivate+0x109/0x1d0 net/sched/sch_generic.c:1397
  linkwatch_do_dev net/core/link_watch.c:184 [inline]
  linkwatch_do_dev+0xd3/0x120 net/core/link_watch.c:166
  __linkwatch_run_queue+0x3a5/0x810 net/core/link_watch.c:240
  linkwatch_event+0x8f/0xc0 net/core/link_watch.c:314
  process_one_work+0xa0e/0x1980 kernel/workqueue.c:3314
  process_scheduled_works kernel/workqueue.c:3397 [inline]
  worker_thread+0x5ef/0xe50 kernel/workqueue.c:3478
  kthread+0x370/0x450 kernel/kthread.c:436
  ret_from_fork+0x69a/0xc80 arch/x86/kernel/process.c:158
  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245

This patch has three coordinated parts:

1) Add dev->watchdog_lock and dev->watchdog_ref_held to serialize watchdog operations.

2) Remove netdev_watchdog_up() call from netif_carrier_on():
   This ensures netdev_watchdog_up() is only called from process/BH context
   (via linkwatch workqueue dev_activate()), allowing us to use
   spin_lock_bh() for synchronization.

3) Synchronize watchdog up and watchdog timer:
   Protect netdev_watchdog_up() with tx_global_lock and watchdog_lock.
   Only allocate a new tracker in netdev_watchdog_up() if one is
   not already present.
   In dev_watchdog(), ensure we don't release the tracker if the
   timer was rescheduled either by dev_watchdog() itself or concurrently
   by netdev_watchdog_up().

Fixes: f12bf6f3f942 ("net: watchdog: add net device refcount tracker")
Reported-by: syzbot+381d82bbf0253710b35d@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6a26b751.c25708ab.1b19ef.0013.GAE@google.com/T/#u
Tested-by: syzbot+3479efbc2821cb2a79f2@syzkaller.appspotmail.com
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260611152737.2580480-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/netdevice.h |  4 ++++
 net/core/dev.c            |  3 ++-
 net/sched/sch_generic.c   | 44 +++++++++++++++++++++++++++++----------
 3 files changed, 39 insertions(+), 12 deletions(-)

diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h
index 0e1e581efc5ac2..4a0e83709f29e4 100644
--- a/include/linux/netdevice.h
+++ b/include/linux/netdevice.h
@@ -1980,6 +1980,8 @@ enum netdev_reg_state {
  *	@qdisc_hash:		qdisc hash table
  *	@watchdog_timeo:	Represents the timeout that is used by
  *				the watchdog (see dev_watchdog())
+ *	@watchdog_lock:		protect watchdog_ref_held
+ *	@watchdog_ref_held:	True if the watchdog device ref is taken.
  *	@watchdog_timer:	List of timers
  *
  *	@proto_down_reason:	reason a netdev interface is held down
@@ -2392,6 +2394,8 @@ struct net_device {
 	/* These may be needed for future network-power-down code. */
 	struct timer_list	watchdog_timer;
 	int			watchdog_timeo;
+	spinlock_t		watchdog_lock;
+	bool			watchdog_ref_held;
 
 	u32                     proto_down_reason;
 
diff --git a/net/core/dev.c b/net/core/dev.c
index 0c6c270d9f7d11..731e661d7be657 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -11217,7 +11217,8 @@ static int netif_alloc_netdev_queues(struct net_device *dev)
 
 	netdev_for_each_tx_queue(dev, netdev_init_one_queue, NULL);
 	spin_lock_init(&dev->tx_global_lock);
-
+	spin_lock_init(&dev->watchdog_lock);
+	dev->watchdog_ref_held = false;
 	return 0;
 }
 
diff --git a/net/sched/sch_generic.c b/net/sched/sch_generic.c
index e35d9c58850fa9..3a0f3bb6a1ff4e 100644
--- a/net/sched/sch_generic.c
+++ b/net/sched/sch_generic.c
@@ -568,16 +568,24 @@ static void dev_watchdog(struct timer_list *t)
 				dev->netdev_ops->ndo_tx_timeout(dev, i);
 				netif_unfreeze_queues(dev);
 			}
-			if (!mod_timer(&dev->watchdog_timer,
-				       round_jiffies(oldest_start +
-						     dev->watchdog_timeo)))
-				release = false;
+			spin_lock(&dev->watchdog_lock);
+			mod_timer(&dev->watchdog_timer,
+				  round_jiffies(oldest_start +
+						dev->watchdog_timeo));
+			release = false;
+			spin_unlock(&dev->watchdog_lock);
 		}
 	}
 	spin_unlock(&dev->tx_global_lock);
 
-	if (release)
+	spin_lock(&dev->watchdog_lock);
+	if (timer_pending(&dev->watchdog_timer))
+		release = false;
+	if (release && dev->watchdog_ref_held) {
 		netdev_put(dev, &dev->watchdog_dev_tracker);
+		dev->watchdog_ref_held = false;
+	}
+	spin_unlock(&dev->watchdog_lock);
 }
 
 void netdev_watchdog_up(struct net_device *dev)
@@ -586,18 +594,34 @@ void netdev_watchdog_up(struct net_device *dev)
 		return;
 	if (dev->watchdog_timeo <= 0)
 		dev->watchdog_timeo = 5*HZ;
+	spin_lock_bh(&dev->tx_global_lock);
+
+	spin_lock(&dev->watchdog_lock);
 	if (!mod_timer(&dev->watchdog_timer,
-		       round_jiffies(jiffies + dev->watchdog_timeo)))
-		netdev_hold(dev, &dev->watchdog_dev_tracker,
-			    GFP_ATOMIC);
+		       round_jiffies(jiffies + dev->watchdog_timeo))) {
+		if (!dev->watchdog_ref_held) {
+			netdev_hold(dev, &dev->watchdog_dev_tracker,
+				    GFP_ATOMIC);
+			dev->watchdog_ref_held = true;
+		}
+	}
+	spin_unlock(&dev->watchdog_lock);
+
+	spin_unlock_bh(&dev->tx_global_lock);
 }
 EXPORT_SYMBOL_GPL(netdev_watchdog_up);
 
 static void netdev_watchdog_down(struct net_device *dev)
 {
 	netif_tx_lock_bh(dev);
-	if (timer_delete(&dev->watchdog_timer))
+
+	spin_lock(&dev->watchdog_lock);
+	if (timer_delete(&dev->watchdog_timer)) {
 		netdev_put(dev, &dev->watchdog_dev_tracker);
+		dev->watchdog_ref_held = false;
+	}
+	spin_unlock(&dev->watchdog_lock);
+
 	netif_tx_unlock_bh(dev);
 }
 
@@ -614,8 +638,6 @@ void netif_carrier_on(struct net_device *dev)
 			return;
 		atomic_inc(&dev->carrier_up_count);
 		linkwatch_fire_event(dev);
-		if (netif_running(dev))
-			netdev_watchdog_up(dev);
 	}
 }
 EXPORT_SYMBOL(netif_carrier_on);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0750/2077] net: ethernet: mtk_wed: fix loading WO firmware for MT7986
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (748 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0749/2077] net: watchdog: fix refcount tracking races Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0751/2077] net/sched: sch_dualpi2: Add missing module alias Greg Kroah-Hartman
                   ` (247 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhi-Jun You, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhi-Jun You <hujy652@gmail.com>

[ Upstream commit 9192a18f6de2f5e3eb3813ecd2895ac0f5c008a9 ]

MT7986 requires a different mask for second WO firmware.
Without this, WO would timeout after loading FW.

The correct mask was removed when adding WED for MT7988.
Add it back and add a WED version check to fix it.

This can be reproduced with a MT7986 + MT7916 board.

Fixes: e2f64db13aa1 ("net: ethernet: mtk_wed: introduce WED support for MT7988")
Signed-off-by: Zhi-Jun You <hujy652@gmail.com>
Link: https://patch.msgid.link/20260611150051.586-1-hujy652@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/mediatek/mtk_wed_mcu.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/drivers/net/ethernet/mediatek/mtk_wed_mcu.c b/drivers/net/ethernet/mediatek/mtk_wed_mcu.c
index fa6b2160341692..0d38183c6ba704 100644
--- a/drivers/net/ethernet/mediatek/mtk_wed_mcu.c
+++ b/drivers/net/ethernet/mediatek/mtk_wed_mcu.c
@@ -367,8 +367,12 @@ mtk_wed_mcu_load_firmware(struct mtk_wed_wo *wo)
 	/* wo firmware reset */
 	wo_w32(MTK_WO_MCU_CFG_LS_WF_MCCR_CLR_ADDR, 0xc00);
 
-	val = wo_r32(MTK_WO_MCU_CFG_LS_WF_MCU_CFG_WM_WA_ADDR) |
-	      MTK_WO_MCU_CFG_LS_WF_WM_WA_WM_CPU_RSTB_MASK;
+	val = wo_r32(MTK_WO_MCU_CFG_LS_WF_MCU_CFG_WM_WA_ADDR);
+
+	if (!mtk_wed_is_v3_or_greater(wo->hw) && wo->hw->index)
+		val |= MTK_WO_MCU_CFG_LS_WF_WM_WA_WA_CPU_RSTB_MASK;
+	else
+		val |= MTK_WO_MCU_CFG_LS_WF_WM_WA_WM_CPU_RSTB_MASK;
 	wo_w32(MTK_WO_MCU_CFG_LS_WF_MCU_CFG_WM_WA_ADDR, val);
 out:
 	release_firmware(fw);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0751/2077] net/sched: sch_dualpi2: Add missing module alias
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (749 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0750/2077] net: ethernet: mtk_wed: fix loading WO firmware for MT7986 Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0752/2077] bpf: Run generic devmap egress prog on private skb Greg Kroah-Hartman
                   ` (246 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Victor Nogueira, Pedro Tammela,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Victor Nogueira <victor@mojatatu.com>

[ Upstream commit ee1ba0add3fbd5a28fa5423be373acd147f1e344 ]

When a qdisc is added by name, the kernel tries to autoload its module
via request_qdisc_module(), which calls:

request_module(NET_SCH_ALIAS_PREFIX "%s", name);

i.e. it asks modprobe to resolve the "net-sch-<kind>" alias (e.g.
"net-sch-dualpi2") rather than the module's file name. Since dualpi2
was shipped without this alias, the autoload fails:

tc qdisc add dev lo root handle 1: dualpi2
Error: Specified qdisc kind is unknown.

Fix this by adding the missing alias so the qdisc is autoloaded on demand
like the others.

Fixes: 320d031ad6e4 ("sched: Struct definition and parsing of dualpi2 qdisc")
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
Reviewed-by: Pedro Tammela <pctammela@mojatatu.com>
Link: https://patch.msgid.link/20260611205849.3287640-1-victor@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sched/sch_dualpi2.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/sched/sch_dualpi2.c b/net/sched/sch_dualpi2.c
index 592c58938d3e80..5434df6ca8efe6 100644
--- a/net/sched/sch_dualpi2.c
+++ b/net/sched/sch_dualpi2.c
@@ -1210,6 +1210,7 @@ static struct Qdisc_ops dualpi2_qdisc_ops __read_mostly = {
 	.dump_stats	= dualpi2_dump_stats,
 	.owner		= THIS_MODULE,
 };
+MODULE_ALIAS_NET_SCH("dualpi2");
 
 static int __init dualpi2_module_init(void)
 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0752/2077] bpf: Run generic devmap egress prog on private skb
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (750 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0751/2077] net/sched: sch_dualpi2: Add missing module alias Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0753/2077] net/mlx5: Check max_macs devlink param value against max capability Greg Kroah-Hartman
                   ` (245 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jiayuan Chen, Jakub Kicinski,
	Toke Høiland-Jørgensen, Sun Jian, Alexei Starovoitov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sun Jian <sun.jian.kdev@gmail.com>

[ Upstream commit 6001896f00984d317fb75160ba05c4a885fbe2a0 ]

Generic XDP devmap multi redirect uses skb_clone() for intermediate
destinations and sends the last destination with the original skb. This
can leave multiple destinations sharing the same packet data.

This becomes visible after generic devmap egress-program support was
added: a devmap egress program may mutate packet data, and another
destination sharing the same data can observe that mutation.

Native XDP broadcast redirect does not have this issue because
xdpf_clone() copies the frame data for each destination. Generic XDP
should provide the same per-destination isolation before running a
devmap egress program.

Fix this by making cloned skbs private before running the generic devmap
egress program. Use skb_copy() instead of skb_unshare() so allocation
failure does not consume the skb and the existing caller error paths keep
their ownership semantics.

Fixes: 2ea5eabaf04a ("bpf: devmap: Implement devmap prog execution for generic XDP")
Suggested-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Suggested-by: Jakub Kicinski <kuba@kernel.org>
Reviewed-by: Toke Høiland-Jørgensen <toke@redhat.com>
Signed-off-by: Sun Jian <sun.jian.kdev@gmail.com>
Link: https://lore.kernel.org/r/20260612114032.244616-2-sun.jian.kdev@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/bpf/devmap.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/kernel/bpf/devmap.c b/kernel/bpf/devmap.c
index 5b9eac5342a90d..dc7b859e8bbfda 100644
--- a/kernel/bpf/devmap.c
+++ b/kernel/bpf/devmap.c
@@ -710,6 +710,18 @@ int dev_map_generic_redirect(struct bpf_dtab_netdev *dst, struct sk_buff *skb,
 	if (unlikely(err))
 		return err;
 
+	if (dst->xdp_prog && skb_cloned(skb)) {
+		struct sk_buff *nskb;
+
+		nskb = skb_copy(skb, GFP_ATOMIC);
+		if (!nskb)
+			return -ENOMEM;
+
+		nskb->mac_len = skb->mac_len;
+		consume_skb(skb);
+		skb = nskb;
+	}
+
 	/* Redirect has already succeeded semantically at this point, so we just
 	 * return 0 even if packet is dropped. Helper below takes care of
 	 * freeing skb.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0753/2077] net/mlx5: Check max_macs devlink param value against max capability
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (751 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0752/2077] bpf: Run generic devmap egress prog on private skb Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0754/2077] bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno Greg Kroah-Hartman
                   ` (244 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dragos Tatulea, Yael Chemla,
	Carolina Jubran, Tariq Toukan, Alexander Lobakin, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dragos Tatulea <dtatulea@nvidia.com>

[ Upstream commit d7b0413b35715d7b32cb12d4d424613eff85ed2b ]

The max_macs devlink param is checked against the FW max value only at
param register time (driver load) and inside the validate callback
(devlink param set). The stored DRIVERINIT value persists across FW
resets and devlink reloads without any further checks against the max.

If the FW link type changes from Ethernet to IB and a FW reset happens,
the MAX cap for log_max_current_uc_list will become zero, but the
previously stored max_macs value remains and is unconditionally
programmed into the HCA caps in handle_hca_cap(). FW will then return a
syndrome during SET_HCA_CAP:

 mlx5_cmd_out_err:839:(pid 3831): SET_HCA_CAP(0x109) op_mod(0x0) failed,
 status bad parameter(0x3), syndrome (0x537801), err(-22)
 set_hca_cap:907:(pid 3831): handle_hca_cap failed

This results in a failure to register the RDMA device.

This patch skips programming log_max_current_uc_list when the MAX
capability is 0 (in case of IB).

Fixes: 8680a60fc1fc ("net/mlx5: Let user configure max_macs generic param")
Signed-off-by: Dragos Tatulea <dtatulea@nvidia.com>
Reviewed-by: Yael Chemla <ychemla@nvidia.com>
Reviewed-by: Carolina Jubran <cjubran@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Reviewed-by: Alexander Lobakin <aleksander.lobakin@intel.com>
Link: https://patch.msgid.link/20260611135230.534513-1-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/mellanox/mlx5/core/main.c | 12 +++++++-----
 1 file changed, 7 insertions(+), 5 deletions(-)

diff --git a/drivers/net/ethernet/mellanox/mlx5/core/main.c b/drivers/net/ethernet/mellanox/mlx5/core/main.c
index 74827e8ca12555..37af619e5e0454 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/main.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/main.c
@@ -527,7 +527,6 @@ static int handle_hca_cap(struct mlx5_core_dev *dev, void *set_ctx)
 {
 	struct mlx5_profile *prof = &dev->profile;
 	void *set_hca_cap;
-	int max_uc_list;
 	int err;
 
 	err = mlx5_core_get_caps(dev, MLX5_CAP_GENERAL);
@@ -610,10 +609,13 @@ static int handle_hca_cap(struct mlx5_core_dev *dev, void *set_ctx)
 		MLX5_SET(cmd_hca_cap, set_hca_cap, roce,
 			 mlx5_is_roce_on(dev));
 
-	max_uc_list = max_uc_list_get_devlink_param(dev);
-	if (max_uc_list > 0)
-		MLX5_SET(cmd_hca_cap, set_hca_cap, log_max_current_uc_list,
-			 ilog2(max_uc_list));
+	if (MLX5_CAP_GEN_MAX(dev, log_max_current_uc_list)) {
+		int max_uc_list = max_uc_list_get_devlink_param(dev);
+
+		if (max_uc_list > 0)
+			MLX5_SET(cmd_hca_cap, set_hca_cap,
+				 log_max_current_uc_list, ilog2(max_uc_list));
+	}
 
 	/* enable absolute native port num */
 	if (MLX5_CAP_GEN_MAX(dev, abs_native_port_num))
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0754/2077] bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (752 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0753/2077] net/mlx5: Check max_macs devlink param value against max capability Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0755/2077] octeontx2-af: npc: Fix size of entry2cntr_map Greg Kroah-Hartman
                   ` (243 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Xu Kuohai, Alexei Starovoitov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xu Kuohai <xukuohai@huawei.com>

[ Upstream commit 4c71303c837449158815c521fcee4ec3b8721dbd ]

When a cgroup BPF program exits with 0, bpf_prog_run_array_cg() sets
the hook return value to -EPERM if it is not a valid errno. This is
correct for errno-based hooks, which return 0 on success and negative
errno on failure, but wrong for boolean and void LSM hooks. Boolean
LSM hooks should only return true or false, and void LSM hooks have
no return value at all.

Fix it by skipping setting -EPERM for hooks not returning errno.

Fixes: 69fd337a975c ("bpf: per-cgroup lsm flavor")
Signed-off-by: Xu Kuohai <xukuohai@huawei.com>
Link: https://lore.kernel.org/r/20260610201724.733943-2-xukuohai@huaweicloud.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/bpf_lsm.h |  6 ++++++
 kernel/bpf/bpf_lsm.c    | 20 ++++++++++++++++++
 kernel/bpf/cgroup.c     | 47 +++++++++++++++++++++++++++++------------
 3 files changed, 60 insertions(+), 13 deletions(-)

diff --git a/include/linux/bpf_lsm.h b/include/linux/bpf_lsm.h
index e4593b4a123824..dda272d78f013f 100644
--- a/include/linux/bpf_lsm.h
+++ b/include/linux/bpf_lsm.h
@@ -54,6 +54,7 @@ int bpf_set_dentry_xattr_locked(struct dentry *dentry, const char *name__str,
 				const struct bpf_dynptr *value_p, int flags);
 int bpf_remove_dentry_xattr_locked(struct dentry *dentry, const char *name__str);
 bool bpf_lsm_has_d_inode_locked(const struct bpf_prog *prog);
+bool bpf_lsm_hook_returns_errno(u32 btf_id);
 
 #else /* !CONFIG_BPF_LSM */
 
@@ -108,6 +109,11 @@ static inline bool bpf_lsm_has_d_inode_locked(const struct bpf_prog *prog)
 {
 	return false;
 }
+
+static inline bool bpf_lsm_hook_returns_errno(u32 btf_id)
+{
+	return true;
+}
 #endif /* CONFIG_BPF_LSM */
 
 #endif /* _LINUX_BPF_LSM_H */
diff --git a/kernel/bpf/bpf_lsm.c b/kernel/bpf/bpf_lsm.c
index c5c925f0020216..564071a92d7d20 100644
--- a/kernel/bpf/bpf_lsm.c
+++ b/kernel/bpf/bpf_lsm.c
@@ -427,6 +427,26 @@ BTF_ID(func, bpf_lsm_audit_rule_known)
 BTF_ID(func, bpf_lsm_inode_xattr_skipcap)
 BTF_SET_END(bool_lsm_hooks)
 
+/* hooks returning void */
+#define LSM_HOOK_void(DEFAULT, NAME, ...) BTF_ID(func, bpf_lsm_##NAME)
+#define LSM_HOOK_int(DEFAULT, NAME, ...)  /* nothing */
+#define LSM_HOOK(RET, DEFAULT, NAME, ...) LSM_HOOK_##RET(DEFAULT, NAME, __VA_ARGS__)
+BTF_SET_START(void_lsm_hooks)
+#include <linux/lsm_hook_defs.h>
+#undef LSM_HOOK
+#undef LSM_HOOK_void
+#undef LSM_HOOK_int
+BTF_SET_END(void_lsm_hooks)
+
+bool bpf_lsm_hook_returns_errno(u32 btf_id)
+{
+	if (btf_id_set_contains(&bool_lsm_hooks, btf_id))
+		return false;
+	if (btf_id_set_contains(&void_lsm_hooks, btf_id))
+		return false;
+	return true;
+}
+
 int bpf_lsm_get_retval_range(const struct bpf_prog *prog,
 			     struct bpf_retval_range *retval_range)
 {
diff --git a/kernel/bpf/cgroup.c b/kernel/bpf/cgroup.c
index 89ea605457906e..90921459e2c433 100644
--- a/kernel/bpf/cgroup.c
+++ b/kernel/bpf/cgroup.c
@@ -55,6 +55,28 @@ void __init cgroup_bpf_lifetime_notifier_init(void)
 						&cgroup_bpf_lifetime_nb));
 }
 
+#ifdef CONFIG_BPF_LSM
+struct cgroup_lsm_atype {
+	u32 attach_btf_id;
+	int refcnt;
+	bool returns_errno;
+};
+
+static struct cgroup_lsm_atype cgroup_lsm_atype[CGROUP_LSM_NUM];
+
+static bool cgroup_bpf_hook_returns_errno(enum cgroup_bpf_attach_type atype)
+{
+	if (atype >= CGROUP_LSM_START && atype <= CGROUP_LSM_END)
+		return READ_ONCE(cgroup_lsm_atype[atype - CGROUP_LSM_START].returns_errno);
+	return true;
+}
+#else
+static bool cgroup_bpf_hook_returns_errno(enum cgroup_bpf_attach_type atype)
+{
+	return true;
+}
+#endif
+
 /* __always_inline is necessary to prevent indirect call through run_prog
  * function pointer.
  */
@@ -83,7 +105,8 @@ bpf_prog_run_array_cg(const struct cgroup_bpf *cgrp,
 			*(ret_flags) |= (func_ret >> 1);
 			func_ret &= 1;
 		}
-		if (!func_ret && !IS_ERR_VALUE((long)run_ctx.retval))
+		if (!func_ret && cgroup_bpf_hook_returns_errno(atype) &&
+		    !IS_ERR_VALUE((long)run_ctx.retval))
 			run_ctx.retval = -EPERM;
 		item++;
 	}
@@ -156,13 +179,6 @@ unsigned int __cgroup_bpf_run_lsm_current(const void *ctx,
 }
 
 #ifdef CONFIG_BPF_LSM
-struct cgroup_lsm_atype {
-	u32 attach_btf_id;
-	int refcnt;
-};
-
-static struct cgroup_lsm_atype cgroup_lsm_atype[CGROUP_LSM_NUM];
-
 static enum cgroup_bpf_attach_type
 bpf_cgroup_atype_find(enum bpf_attach_type attach_type, u32 attach_btf_id)
 {
@@ -191,10 +207,13 @@ void bpf_cgroup_atype_get(u32 attach_btf_id, int cgroup_atype)
 
 	lockdep_assert_held(&cgroup_mutex);
 
-	WARN_ON_ONCE(cgroup_lsm_atype[i].attach_btf_id &&
-		     cgroup_lsm_atype[i].attach_btf_id != attach_btf_id);
-
-	cgroup_lsm_atype[i].attach_btf_id = attach_btf_id;
+	if (!cgroup_lsm_atype[i].attach_btf_id) {
+		cgroup_lsm_atype[i].attach_btf_id = attach_btf_id;
+		WRITE_ONCE(cgroup_lsm_atype[i].returns_errno,
+			   bpf_lsm_hook_returns_errno(attach_btf_id));
+	} else {
+		WARN_ON_ONCE(cgroup_lsm_atype[i].attach_btf_id != attach_btf_id);
+	}
 	cgroup_lsm_atype[i].refcnt++;
 }
 
@@ -203,8 +222,10 @@ void bpf_cgroup_atype_put(int cgroup_atype)
 	int i = cgroup_atype - CGROUP_LSM_START;
 
 	cgroup_lock();
-	if (--cgroup_lsm_atype[i].refcnt <= 0)
+	if (--cgroup_lsm_atype[i].refcnt <= 0) {
+		WRITE_ONCE(cgroup_lsm_atype[i].returns_errno, true);
 		cgroup_lsm_atype[i].attach_btf_id = 0;
+	}
 	WARN_ON_ONCE(cgroup_lsm_atype[i].refcnt < 0);
 	cgroup_unlock();
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0755/2077] octeontx2-af: npc: Fix size of entry2cntr_map
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (753 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0754/2077] bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0756/2077] net: airoha: Fix error handling in airoha_ppe_flush_sram_entries() Greg Kroah-Hartman
                   ` (242 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Subbaraya Sundeep, Ratheesh Kannoth,
	Paolo Abeni, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ratheesh Kannoth <rkannoth@marvell.com>

[ Upstream commit f9cd6fabe0e7c7f6fc30c6c192c7ed72aba37232 ]

KASAN prints below splat. This is caused by allocating counter for
reserved mcam entry for cpt 2nd pass entry. But mcam->entry2cntr_map
is not allocated for reserved entries.

BUG: KASAN: slab-out-of-bounds in npc_map_mcam_entry_and_cntr+0xb0/0x1a0
Write of size 2 at addr ffff0001033e7ffe by task kworker/0:1/14

CPU: 0 PID: 14 Comm: kworker/0:1 Not tainted 6.1.67 #1
Hardware name: Marvell CN106XX board (DT)
Workqueue: events work_for_cpu_fn
Call trace:
 dump_backtrace.part.0+0xe4/0xf0
 show_stack+0x18/0x30
 dump_stack_lvl+0x88/0xb4
 print_report+0x154/0x458
 kasan_report+0xb8/0x194
 __asan_store2+0x7c/0xa0
 npc_map_mcam_entry_and_cntr+0xb0/0x1a0
 rvu_mbox_handler_npc_mcam_write_entry+0x268/0x280
 npc_install_flow+0x840/0xfe0
 rvu_npc_install_cpt_pass2_entry+0x138/0x190
 rvu_nix_init+0x148c/0x2880
 rvu_probe+0x1800/0x30b0
 local_pci_probe+0x78/0xe0
 work_for_cpu_fn+0x30/0x50
 process_one_work+0x4cc/0x97c
 worker_thread+0x360/0x630
 kthread+0x1a0/0x1b0
 ret_from_fork+0x10/0x20

Fixes: 55307fcb9258 ("octeontx2-af: Add mbox messages to install and delete MCAM rules")
Cc: Subbaraya Sundeep <sbhatta@marvell.com>
Signed-off-by: Ratheesh Kannoth <rkannoth@marvell.com>
Link: https://patch.msgid.link/20260610022344.969774-1-rkannoth@marvell.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../ethernet/marvell/octeontx2/af/rvu_npc.c   | 40 +++++++------------
 1 file changed, 15 insertions(+), 25 deletions(-)

diff --git a/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c b/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c
index d301a3f0f87a86..4994385a822b72 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c
+++ b/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c
@@ -2181,7 +2181,7 @@ int npc_mcam_rsrcs_init(struct rvu *rvu, int blkaddr)
 	/* Alloc memory for MCAM entry to counter mapping and for tracking
 	 * counter's reference count.
 	 */
-	mcam->entry2cntr_map = kcalloc(mcam->bmap_entries, sizeof(u16),
+	mcam->entry2cntr_map = kcalloc(mcam->total_entries, sizeof(u16),
 				       GFP_KERNEL);
 	if (!mcam->entry2cntr_map)
 		goto free_cntr_map;
@@ -2197,10 +2197,11 @@ int npc_mcam_rsrcs_init(struct rvu *rvu, int blkaddr)
 	if (!mcam->entry2target_pffunc)
 		goto free_cntr_refcnt;
 
-	for (index = 0; index < mcam->bmap_entries; index++) {
+	for (index = 0; index < mcam->bmap_entries; index++)
 		mcam->entry2pfvf_map[index] = NPC_MCAM_INVALID_MAP;
+
+	for (index = 0; index < mcam->total_entries; index++)
 		mcam->entry2cntr_map[index] = NPC_MCAM_INVALID_MAP;
-	}
 
 	for (cntr = 0; cntr < mcam->counters.max; cntr++)
 		mcam->cntr2pfvf_map[cntr] = NPC_MCAM_INVALID_MAP;
@@ -3531,7 +3532,7 @@ static int __npc_mcam_free_counter(struct rvu *rvu,
 				   struct msg_rsp *rsp)
 {
 	struct npc_mcam *mcam = &rvu->hw->mcam;
-	u16 index, entry = 0;
+	u16 index;
 	int blkaddr, err;
 
 	blkaddr = rvu_get_blkaddr(rvu, BLKTYPE_NPC, 0);
@@ -3547,20 +3548,16 @@ static int __npc_mcam_free_counter(struct rvu *rvu,
 	mcam->cntr2pfvf_map[req->cntr] = NPC_MCAM_INVALID_MAP;
 	rvu_free_rsrc(&mcam->counters, req->cntr);
 
-	/* Disable all MCAM entry's stats which are using this counter */
-	while (entry < mcam->bmap_entries) {
+	/* Disable all MCAM entry's stats which are using this counter.
+	 * Scan the full MCAM index range: AF-reserved rules (e.g. CPT pass-2)
+	 */
+	for (index = 0; index < mcam->total_entries; index++) {
 		if (!mcam->cntr_refcnt[req->cntr])
 			break;
-
-		index = find_next_bit(mcam->bmap, mcam->bmap_entries, entry);
-		if (index >= mcam->bmap_entries)
-			break;
-		entry = index + 1;
 		if (mcam->entry2cntr_map[index] != req->cntr)
 			continue;
-
-		npc_unmap_mcam_entry_and_cntr(rvu, mcam, blkaddr,
-					      index, req->cntr);
+		npc_unmap_mcam_entry_and_cntr(rvu, mcam, blkaddr, index,
+					      req->cntr);
 	}
 
 	return 0;
@@ -3631,7 +3628,7 @@ int rvu_mbox_handler_npc_mcam_unmap_counter(struct rvu *rvu,
 		struct npc_mcam_unmap_counter_req *req, struct msg_rsp *rsp)
 {
 	struct npc_mcam *mcam = &rvu->hw->mcam;
-	u16 index, entry = 0;
+	u16 index;
 	int blkaddr, rc;
 
 	/* Counter is not supported for CN20K */
@@ -3658,20 +3655,13 @@ int rvu_mbox_handler_npc_mcam_unmap_counter(struct rvu *rvu,
 	}
 
 	/* Disable all MCAM entry's stats which are using this counter */
-	while (entry < mcam->bmap_entries) {
+	for (index = 0; index < mcam->total_entries; index++) {
 		if (!mcam->cntr_refcnt[req->cntr])
 			break;
-
-		index = find_next_bit(mcam->bmap, mcam->bmap_entries, entry);
-		if (index >= mcam->bmap_entries)
-			break;
-		entry = index + 1;
-
 		if (mcam->entry2cntr_map[index] != req->cntr)
 			continue;
-
-		npc_unmap_mcam_entry_and_cntr(rvu, mcam, blkaddr,
-					      index, req->cntr);
+		npc_unmap_mcam_entry_and_cntr(rvu, mcam, blkaddr, index,
+					      req->cntr);
 	}
 exit:
 	mutex_unlock(&mcam->lock);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0756/2077] net: airoha: Fix error handling in airoha_ppe_flush_sram_entries()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (754 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0755/2077] octeontx2-af: npc: Fix size of entry2cntr_map Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0757/2077] net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show() Greg Kroah-Hartman
                   ` (241 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wayen.Yan, Lorenzo Bianconi,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wayen.Yan <win847@gmail.com>

[ Upstream commit d7d81b00301398fcd38cf5b5869f0fdb674472ef ]

In airoha_ppe_flush_sram_entries(), the outer "err" variable was never
updated when the inner loop variable shadowed it, causing the function
to always return 0 even when airoha_ppe_foe_commit_sram_entry() fails.

Drop the outer "err" variable and return directly on error, propagating
the error code from airoha_ppe_foe_commit_sram_entry() correctly.

Fixes: 620d7b91aadb ("net: airoha: ppe: Flush PPE SRAM table during PPE setup")
Link: https://lore.kernel.org/netdev/6a2b40e4.4dd82583.3a5c46.e52f@mx.google.com/
Signed-off-by: Wayen.Yan <win847@gmail.com>
Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/6a2bd37a.4034e349.1b41bb.1caf@mx.google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/airoha/airoha_ppe.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/net/ethernet/airoha/airoha_ppe.c b/drivers/net/ethernet/airoha/airoha_ppe.c
index 5c9dff6bccd1e3..a124f15345a916 100644
--- a/drivers/net/ethernet/airoha/airoha_ppe.c
+++ b/drivers/net/ethernet/airoha/airoha_ppe.c
@@ -1330,7 +1330,7 @@ static int airoha_ppe_flush_sram_entries(struct airoha_ppe *ppe)
 {
 	u32 sram_num_entries = airoha_ppe_get_total_sram_num_entries(ppe);
 	struct airoha_foe_entry *hwe = ppe->foe;
-	int i, err = 0;
+	int i;
 
 	for (i = 0; i < sram_num_entries; i++) {
 		int err;
@@ -1338,10 +1338,10 @@ static int airoha_ppe_flush_sram_entries(struct airoha_ppe *ppe)
 		memset(&hwe[i], 0, sizeof(*hwe));
 		err = airoha_ppe_foe_commit_sram_entry(ppe, i);
 		if (err)
-			break;
+			return err;
 	}
 
-	return err;
+	return 0;
 }
 
 static struct airoha_npu *airoha_ppe_npu_get(struct airoha_eth *eth)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0757/2077] net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (755 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0756/2077] net: airoha: Fix error handling in airoha_ppe_flush_sram_entries() Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0758/2077] net: wwan: t7xx: check skb_clone in control TX Greg Kroah-Hartman
                   ` (240 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wentao Guan, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wentao Guan <guanwentao@uniontech.com>

[ Upstream commit 14a8bc41ce9edae42d56466063a7f2c84a16c45c ]

WED_MON_AMSDU_ENG_CNT point to different entry by 'base+n*offset' mode,
correct the wed amsdu entry number in wed_amsdu_show().

Fixes: 3f3de094e8342 ("net: ethernet: mtk_wed: debugfs: add WED 3.0 debugfs entries")
Signed-off-by: Wentao Guan <guanwentao@uniontech.com>
Link: https://patch.msgid.link/20260612064501.203058-1-guanwentao@uniontech.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/mediatek/mtk_wed_debugfs.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/net/ethernet/mediatek/mtk_wed_debugfs.c b/drivers/net/ethernet/mediatek/mtk_wed_debugfs.c
index 781c691473e14f..519c364e87d197 100644
--- a/drivers/net/ethernet/mediatek/mtk_wed_debugfs.c
+++ b/drivers/net/ethernet/mediatek/mtk_wed_debugfs.c
@@ -310,9 +310,9 @@ wed_amsdu_show(struct seq_file *s, void *data)
 			      WED_AMSDU_ENG_MAX_QGPP_CNT),
 		DUMP_WED_MASK(WED_MON_AMSDU_ENG_CNT9(1),
 			      WED_AMSDU_ENG_CUR_ENTRY),
-		DUMP_WED_MASK(WED_MON_AMSDU_ENG_CNT9(2),
+		DUMP_WED_MASK(WED_MON_AMSDU_ENG_CNT9(1),
 			      WED_AMSDU_ENG_MAX_BUF_MERGED),
-		DUMP_WED_MASK(WED_MON_AMSDU_ENG_CNT9(2),
+		DUMP_WED_MASK(WED_MON_AMSDU_ENG_CNT9(1),
 			      WED_AMSDU_ENG_MAX_MSDU_MERGED),
 
 		DUMP_STR("WED AMDSU ENG2 INFO"),
@@ -414,7 +414,7 @@ wed_amsdu_show(struct seq_file *s, void *data)
 			      WED_AMSDU_ENG_CUR_ENTRY),
 		DUMP_WED_MASK(WED_MON_AMSDU_ENG_CNT9(7),
 			      WED_AMSDU_ENG_MAX_BUF_MERGED),
-		DUMP_WED_MASK(WED_MON_AMSDU_ENG_CNT9(4),
+		DUMP_WED_MASK(WED_MON_AMSDU_ENG_CNT9(7),
 			      WED_AMSDU_ENG_MAX_MSDU_MERGED),
 
 		DUMP_STR("WED AMDSU ENG8 INFO"),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0758/2077] net: wwan: t7xx: check skb_clone in control TX
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (756 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0757/2077] net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show() Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0759/2077] dpll: fix stale iteration in dpll_pin_on_pin_unregister() Greg Kroah-Hartman
                   ` (239 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Loic Poulain,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ruoyu Wang <ruoyuw560@gmail.com>

[ Upstream commit 05f789fa90d95d5771230e78453cedff2486039d ]

t7xx_port_ctrl_tx() clones each skb fragment before passing it to the
port transmit path. The clone is used immediately to set cloned->len, so
an skb_clone() failure results in a NULL pointer dereference.

Check the clone before using it. If previous fragments were already
queued, preserve the driver's existing partial-write behavior by
returning the number of bytes submitted so far.

Fixes: 36bd28c1cb0d ("wwan: core: Support slicing in port TX flow of WWAN subsystem")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Link: https://patch.msgid.link/20260612035613.1192486-1-ruoyuw560@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/wwan/t7xx/t7xx_port_wwan.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/net/wwan/t7xx/t7xx_port_wwan.c b/drivers/net/wwan/t7xx/t7xx_port_wwan.c
index 7fc569565ff99a..d2529df7592a7f 100644
--- a/drivers/net/wwan/t7xx/t7xx_port_wwan.c
+++ b/drivers/net/wwan/t7xx/t7xx_port_wwan.c
@@ -106,6 +106,8 @@ static int t7xx_port_ctrl_tx(struct t7xx_port *port, struct sk_buff *skb)
 
 	while (cur) {
 		cloned = skb_clone(cur, GFP_KERNEL);
+		if (!cloned)
+			return cnt ? cnt : -ENOMEM;
 		cloned->len = skb_headlen(cur);
 		ret = t7xx_port_send_skb(port, cloned, 0, 0);
 		if (ret) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0759/2077] dpll: fix stale iteration in dpll_pin_on_pin_unregister()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (757 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0758/2077] net: wwan: t7xx: check skb_clone in control TX Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0760/2077] dpll: send delete notification before unregister in on-pin rollback Greg Kroah-Hartman
                   ` (238 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Grzegorz Nitka, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Grzegorz Nitka <grzegorz.nitka@intel.com>

[ Upstream commit 32239d600236a986c8e6d16aa814d3d91066b244 ]

Neither parent->dpll_refs nor pin->dpll_refs on its own is a correct
iteration target at unregister time:

  - pin->dpll_refs includes DPLLs the child was registered against
    via a different parent or directly; blind unregister WARNs on
    the cookie miss in dpll_xa_ref_pin_del().
  - parent->dpll_refs reflects the parent's current attachments, not
    those at child-register time. Another driver may have (un)reg'd
    the parent against additional DPLLs in the meantime, so we miss
    registrations that exist and visit DPLLs that have none.

Walk pin->dpll_refs and use dpll_pin_registration_find() to filter
to entries whose cookie is this parent. Symmetric with
dpll_pin_on_pin_register(), correct under any subsequent change to
parent->dpll_refs.

Fixes: 9431063ad323 ("dpll: core: Add DPLL framework base functions")
Signed-off-by: Grzegorz Nitka <grzegorz.nitka@intel.com>
Link: https://patch.msgid.link/20260607183045.1213735-4-grzegorz.nitka@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dpll/dpll_core.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/dpll/dpll_core.c b/drivers/dpll/dpll_core.c
index cbb635db43210f..1f1b9a6696231a 100644
--- a/drivers/dpll/dpll_core.c
+++ b/drivers/dpll/dpll_core.c
@@ -1018,14 +1018,19 @@ EXPORT_SYMBOL_GPL(dpll_pin_on_pin_register);
 void dpll_pin_on_pin_unregister(struct dpll_pin *parent, struct dpll_pin *pin,
 				const struct dpll_pin_ops *ops, void *priv)
 {
+	struct dpll_pin_registration *reg;
 	struct dpll_pin_ref *ref;
 	unsigned long i;
 
 	mutex_lock(&dpll_lock);
 	dpll_pin_delete_ntf(pin);
 	dpll_xa_ref_pin_del(&pin->parent_refs, parent, ops, priv, pin);
-	xa_for_each(&pin->dpll_refs, i, ref)
+	xa_for_each(&pin->dpll_refs, i, ref) {
+		reg = dpll_pin_registration_find(ref, ops, priv, parent);
+		if (!reg)
+			continue;
 		__dpll_pin_unregister(ref->dpll, pin, ops, priv, parent);
+	}
 	mutex_unlock(&dpll_lock);
 }
 EXPORT_SYMBOL_GPL(dpll_pin_on_pin_unregister);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0760/2077] dpll: send delete notification before unregister in on-pin rollback
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (758 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0759/2077] dpll: fix stale iteration in dpll_pin_on_pin_unregister() Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0761/2077] dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister() Greg Kroah-Hartman
                   ` (237 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Grzegorz Nitka, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Grzegorz Nitka <grzegorz.nitka@intel.com>

[ Upstream commit e83b403eb142be18d223fc599c0ac45519053671 ]

The rollback path in dpll_pin_on_pin_register() called
__dpll_pin_unregister() before dpll_pin_delete_ntf(). When the
unregister dropped the pin's last DPLL reference it cleared the
DPLL_REGISTERED mark in dpll_pin_xa, so the subsequent
dpll_pin_event_send() failed dpll_pin_available() and aborted with
-ENODEV. As a result userspace was never notified of the rollback
deletion and remained out of sync with the kernel.

Send the delete notification first, matching the order used by
dpll_pin_unregister() and dpll_pin_on_pin_unregister().

Fixes: 9d71b54b65b1 ("dpll: netlink: Add DPLL framework base functions")
Signed-off-by: Grzegorz Nitka <grzegorz.nitka@intel.com>
Link: https://patch.msgid.link/20260607183045.1213735-5-grzegorz.nitka@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dpll/dpll_core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/dpll/dpll_core.c b/drivers/dpll/dpll_core.c
index 1f1b9a6696231a..a58977c87de193 100644
--- a/drivers/dpll/dpll_core.c
+++ b/drivers/dpll/dpll_core.c
@@ -994,9 +994,9 @@ int dpll_pin_on_pin_register(struct dpll_pin *parent, struct dpll_pin *pin,
 dpll_unregister:
 	xa_for_each(&parent->dpll_refs, i, ref)
 		if (i < stop) {
+			dpll_pin_delete_ntf(pin);
 			__dpll_pin_unregister(ref->dpll, pin, ops, priv,
 					      parent);
-			dpll_pin_delete_ntf(pin);
 		}
 	dpll_xa_ref_pin_del(&pin->parent_refs, parent, ops, priv, pin);
 unlock:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0761/2077] dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (759 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0760/2077] dpll: send delete notification before unregister in on-pin rollback Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0762/2077] dpll: guard sync-pair removal on full pin unregister Greg Kroah-Hartman
                   ` (236 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Grzegorz Nitka, Arkadiusz Kubalewski,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Grzegorz Nitka <grzegorz.nitka@intel.com>

[ Upstream commit df0ba51ccf873e533669578104981109217d8201 ]

dpll_pin_on_pin_register() emits a creation notification for every
parent->dpll_refs entry, but dpll_pin_on_pin_unregister() emitted only
one deletion notification outside the loop. When a pin is registered
against multiple parent dplls, userspace sees N creates but a single
delete and leaks per-dpll state.

Move dpll_pin_delete_ntf() into the loop and call it before
__dpll_pin_unregister() so the DPLL_REGISTERED mark is still set when
dpll_pin_available() is consulted.

Fixes: 9d71b54b65b1 ("dpll: netlink: Add DPLL framework base functions")
Signed-off-by: Grzegorz Nitka <grzegorz.nitka@intel.com>
Reviewed-by: Arkadiusz Kubalewski <arkadiusz.kubalewski@intel.com>
Link: https://patch.msgid.link/20260607183045.1213735-6-grzegorz.nitka@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dpll/dpll_core.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/dpll/dpll_core.c b/drivers/dpll/dpll_core.c
index a58977c87de193..ac9654b42b77ca 100644
--- a/drivers/dpll/dpll_core.c
+++ b/drivers/dpll/dpll_core.c
@@ -1023,14 +1023,14 @@ void dpll_pin_on_pin_unregister(struct dpll_pin *parent, struct dpll_pin *pin,
 	unsigned long i;
 
 	mutex_lock(&dpll_lock);
-	dpll_pin_delete_ntf(pin);
-	dpll_xa_ref_pin_del(&pin->parent_refs, parent, ops, priv, pin);
 	xa_for_each(&pin->dpll_refs, i, ref) {
 		reg = dpll_pin_registration_find(ref, ops, priv, parent);
 		if (!reg)
 			continue;
+		dpll_pin_delete_ntf(pin);
 		__dpll_pin_unregister(ref->dpll, pin, ops, priv, parent);
 	}
+	dpll_xa_ref_pin_del(&pin->parent_refs, parent, ops, priv, pin);
 	mutex_unlock(&dpll_lock);
 }
 EXPORT_SYMBOL_GPL(dpll_pin_on_pin_unregister);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0762/2077] dpll: guard sync-pair removal on full pin unregister
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (760 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0761/2077] dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister() Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0763/2077] dpll: balance create/delete notifications in __dpll_pin_(un)register Greg Kroah-Hartman
                   ` (235 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Grzegorz Nitka, Arkadiusz Kubalewski,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Grzegorz Nitka <grzegorz.nitka@intel.com>

[ Upstream commit 0a5c720a7d57d2287d5566c4ad93ee26b7c06845 ]

__dpll_pin_unregister() wiped the global sync-pair state on every
(dpll, ops, priv, cookie) tuple removed from a pin. When a pin is
registered multiple times and only one registration is being torn
down, this dropped sync-pair pairings still in use by the surviving
registrations.

Move dpll_pin_ref_sync_pair_del() inside the xa_empty(&pin->dpll_refs)
branch so it only runs when the last registration is gone, alongside
clearing the DPLL_REGISTERED mark.

Fixes: 58256a26bfb3 ("dpll: add reference sync get/set")
Signed-off-by: Grzegorz Nitka <grzegorz.nitka@intel.com>
Reviewed-by: Arkadiusz Kubalewski <arkadiusz.kubalewski@intel.com>
Link: https://patch.msgid.link/20260607183045.1213735-7-grzegorz.nitka@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dpll/dpll_core.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/dpll/dpll_core.c b/drivers/dpll/dpll_core.c
index ac9654b42b77ca..e3d7aeed43088f 100644
--- a/drivers/dpll/dpll_core.c
+++ b/drivers/dpll/dpll_core.c
@@ -913,11 +913,12 @@ __dpll_pin_unregister(struct dpll_device *dpll, struct dpll_pin *pin,
 		      const struct dpll_pin_ops *ops, void *priv, void *cookie)
 {
 	ASSERT_DPLL_PIN_REGISTERED(pin);
-	dpll_pin_ref_sync_pair_del(pin->id);
 	dpll_xa_ref_pin_del(&dpll->pin_refs, pin, ops, priv, cookie);
 	dpll_xa_ref_dpll_del(&pin->dpll_refs, dpll, ops, priv, cookie);
-	if (xa_empty(&pin->dpll_refs))
+	if (xa_empty(&pin->dpll_refs)) {
+		dpll_pin_ref_sync_pair_del(pin->id);
 		xa_clear_mark(&dpll_pin_xa, pin->id, DPLL_REGISTERED);
+	}
 }
 
 /**
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0763/2077] dpll: balance create/delete notifications in __dpll_pin_(un)register
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (761 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0762/2077] dpll: guard sync-pair removal on full pin unregister Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0764/2077] landlock: Fix unmarked concurrent access to socket family Greg Kroah-Hartman
                   ` (234 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Grzegorz Nitka, Arkadiusz Kubalewski,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Grzegorz Nitka <grzegorz.nitka@intel.com>

[ Upstream commit 1a2292101c0dc422466c673031de03d2e871adbe ]

__dpll_pin_register() emits dpll_pin_create_ntf() internally, but
__dpll_pin_unregister() left the matching delete to its callers. The
counts then diverge on dpll_pin_on_pin_register() rollback and on
dpll_pin_on_pin_unregister(), leaking stale notifications.

Emit dpll_pin_delete_ntf() inside __dpll_pin_unregister() and drop the
now-redundant call in dpll_pin_unregister().

Fixes: 9431063ad323 ("dpll: core: Add DPLL framework base functions")
Signed-off-by: Grzegorz Nitka <grzegorz.nitka@intel.com>
Reviewed-by: Arkadiusz Kubalewski <arkadiusz.kubalewski@intel.com>
Link: https://patch.msgid.link/20260607183045.1213735-8-grzegorz.nitka@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dpll/dpll_core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/dpll/dpll_core.c b/drivers/dpll/dpll_core.c
index e3d7aeed43088f..8a8f2f4351235d 100644
--- a/drivers/dpll/dpll_core.c
+++ b/drivers/dpll/dpll_core.c
@@ -913,6 +913,7 @@ __dpll_pin_unregister(struct dpll_device *dpll, struct dpll_pin *pin,
 		      const struct dpll_pin_ops *ops, void *priv, void *cookie)
 {
 	ASSERT_DPLL_PIN_REGISTERED(pin);
+	dpll_pin_delete_ntf(pin);
 	dpll_xa_ref_pin_del(&dpll->pin_refs, pin, ops, priv, cookie);
 	dpll_xa_ref_dpll_del(&pin->dpll_refs, dpll, ops, priv, cookie);
 	if (xa_empty(&pin->dpll_refs)) {
@@ -940,7 +941,6 @@ void dpll_pin_unregister(struct dpll_device *dpll, struct dpll_pin *pin,
 		return;
 
 	mutex_lock(&dpll_lock);
-	dpll_pin_delete_ntf(pin);
 	__dpll_pin_unregister(dpll, pin, ops, priv, NULL);
 	mutex_unlock(&dpll_lock);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0764/2077] landlock: Fix unmarked concurrent access to socket family
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (762 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0763/2077] dpll: balance create/delete notifications in __dpll_pin_(un)register Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0765/2077] net: bcmgenet: Use weighted round-robin TX DMA arbitration Greg Kroah-Hartman
                   ` (233 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Matthieu Buffet,
	Mickaël Salaün, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matthieu Buffet <matthieu@buffet.re>

[ Upstream commit 0ce4243509d1580349dd0d50624036d6b097e958 ]

Socket family is read (twice) in a context where the socket is not
locked, so another thread can setsockopt(IPV6_ADDRFORM) to write it
concurrently. Add needed READ_ONCE() annotation.

Use the proper macro to access __sk_common.skc_family like everywhere
else.

Fixes: fff69fb03dde ("landlock: Support network rules with TCP bind and connect")
Signed-off-by: Matthieu Buffet <matthieu@buffet.re>
Link: https://patch.msgid.link/20260609211511.85630-1-matthieu@buffet.re
Link: https://patch.msgid.link/20260609211511.85630-2-matthieu@buffet.re
[mic: Squash two patches, move variable to ease backport, fix comment
formatting]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 security/landlock/net.c | 11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

diff --git a/security/landlock/net.c b/security/landlock/net.c
index a38bdfcffc22a3..4ee4002a8f5676 100644
--- a/security/landlock/net.c
+++ b/security/landlock/net.c
@@ -46,6 +46,7 @@ static int current_check_access_socket(struct socket *const sock,
 				       const int addrlen,
 				       access_mask_t access_request)
 {
+	unsigned short sock_family;
 	__be16 port;
 	struct layer_access_masks layer_masks = {};
 	const struct landlock_rule *rule;
@@ -66,6 +67,12 @@ static int current_check_access_socket(struct socket *const sock,
 	if (addrlen < offsetofend(typeof(*address), sa_family))
 		return -EINVAL;
 
+	/*
+	 * The socket is not locked, so sk_family can change concurrently due to
+	 * e.g. setsockopt(IPV6_ADDRFORM).
+	 */
+	sock_family = READ_ONCE(sock->sk->sk_family);
+
 	switch (address->sa_family) {
 	case AF_UNSPEC:
 		if (access_request == LANDLOCK_ACCESS_NET_CONNECT_TCP) {
@@ -102,7 +109,7 @@ static int current_check_access_socket(struct socket *const sock,
 			 * these checks, but it is safer to return a proper
 			 * error and test consistency thanks to kselftest.
 			 */
-			if (sock->sk->__sk_common.skc_family == AF_INET) {
+			if (sock_family == AF_INET) {
 				const struct sockaddr_in *const sockaddr =
 					(struct sockaddr_in *)address;
 
@@ -180,7 +187,7 @@ static int current_check_access_socket(struct socket *const sock,
 	 * check, but it is safer to return a proper error and test
 	 * consistency thanks to kselftest.
 	 */
-	if (address->sa_family != sock->sk->__sk_common.skc_family &&
+	if (address->sa_family != sock_family &&
 	    address->sa_family != AF_UNSPEC)
 		return -EINVAL;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0765/2077] net: bcmgenet: Use weighted round-robin TX DMA arbitration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (763 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0764/2077] landlock: Fix unmarked concurrent access to socket family Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0766/2077] octeontx2-af: fix NPC mailbox codes in mbox.h Greg Kroah-Hartman
                   ` (232 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ovidiu Panait, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ovidiu Panait <ovidiu.panait.rb@renesas.com>

[ Upstream commit fd615abd53110f0f815984e99e7cc51ca6b7d979 ]

Under heavy network traffic, we observed sporadic TX queue timeouts on the
Raspberry Pi 4. The timeouts can be reproduced by stress testing the TX
path with multiple concurrent iperf UDP streams:

    iperf3 -c <ip> -u -b0 -P16 -t60
    NETDEV WATCHDOG: CPU: 0: transmit queue 0 timed out 2044 ms
    NETDEV WATCHDOG: CPU: 3: transmit queue 0 timed out 2004 ms

Investigation showed that the timeouts are caused by the priority-based
arbiter. Under heavy load the highest priority queue starves the lower
priority ones, causing timeouts. The TX strict priority arbiter is not
suitable for the default use case where all the traffic gets spread
across all the TX queues.

Therefore, to fix this, switch the TX DMA arbiter to Weighted Round-Robin,
which services all queues, so they do not stall. The weights were chosen
to follow the existing priority scheme: q0 gets the smallest weight, while
q1-4 get the bulk of the TX bandwidth.

Fixes: 1c1008c793fa ("net: bcmgenet: add main driver file")
Signed-off-by: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
Link: https://patch.msgid.link/20260610085238.56300-1-ovidiu.panait.rb@renesas.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../net/ethernet/broadcom/genet/bcmgenet.c    | 23 +++++++------------
 1 file changed, 8 insertions(+), 15 deletions(-)

diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index 7c11cf9167620c..ad08c67269be54 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -40,9 +40,8 @@
 
 #include "bcmgenet.h"
 
-/* Default highest priority queue for multi queue support */
-#define GENET_Q1_PRIORITY	0
-#define GENET_Q0_PRIORITY	1
+#define GENET_Q0_WEIGHT		1
+#define GENET_Q1_WEIGHT		4
 
 #define GENET_Q0_RX_BD_CNT	\
 	(TOTAL_DESC - priv->hw_params->rx_queues * priv->hw_params->rx_bds_per_q)
@@ -2129,13 +2128,6 @@ static netdev_tx_t bcmgenet_xmit(struct sk_buff *skb, struct net_device *dev)
 	int i;
 
 	index = skb_get_queue_mapping(skb);
-	/* Mapping strategy:
-	 * queue_mapping = 0, unclassified, packet xmited through ring 0
-	 * queue_mapping = 1, goes to ring 1. (highest priority queue)
-	 * queue_mapping = 2, goes to ring 2.
-	 * queue_mapping = 3, goes to ring 3.
-	 * queue_mapping = 4, goes to ring 4.
-	 */
 	ring = &priv->tx_rings[index];
 	txq = netdev_get_tx_queue(dev, index);
 
@@ -2881,8 +2873,9 @@ static int bcmgenet_rdma_disable(struct bcmgenet_priv *priv)
 
 /* Initialize Tx queues
  *
- * Queues 1-4 are priority-based, each one has 32 descriptors,
- * with queue 1 being the highest priority queue.
+ * Queues 1-4 are the priority queues, each one has 32 descriptors.
+ * The weighted round-robin arbiter gives them a larger share of TX
+ * bandwidth than the default queue 0.
  *
  * Queue 0 is the default Tx queue with
  * GENET_Q0_TX_BD_CNT = 256 - 4 * 32 = 128 descriptors.
@@ -2900,8 +2893,8 @@ static void bcmgenet_init_tx_queues(struct net_device *dev)
 	unsigned int start = 0, end = GENET_Q0_TX_BD_CNT;
 	u32 i, ring_mask, dma_priority[3] = {0, 0, 0};
 
-	/* Enable strict priority arbiter mode */
-	bcmgenet_tdma_writel(priv, DMA_ARBITER_SP, DMA_ARB_CTRL);
+	/* Enable Weighted Round-Robin arbiter mode */
+	bcmgenet_tdma_writel(priv, DMA_ARBITER_WRR, DMA_ARB_CTRL);
 
 	/* Initialize Tx priority queues */
 	for (i = 0; i <= priv->hw_params->tx_queues; i++) {
@@ -2909,7 +2902,7 @@ static void bcmgenet_init_tx_queues(struct net_device *dev)
 		start = end;
 		end += priv->hw_params->tx_bds_per_q;
 		dma_priority[DMA_PRIO_REG_INDEX(i)] |=
-			(i ? GENET_Q1_PRIORITY : GENET_Q0_PRIORITY)
+			(i ? GENET_Q1_WEIGHT : GENET_Q0_WEIGHT)
 			<< DMA_PRIO_REG_SHIFT(i);
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0766/2077] octeontx2-af: fix NPC mailbox codes in mbox.h
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (764 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0765/2077] net: bcmgenet: Use weighted round-robin TX DMA arbitration Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0767/2077] net: airoha: Fix register index for Tx-fwd counter configuration Greg Kroah-Hartman
                   ` (231 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Suman Ghosh, Ratheesh Kannoth,
	Simon Horman, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ratheesh Kannoth <rkannoth@marvell.com>

[ Upstream commit 925551c944a1de3058dc3fb55a517eea7749835d ]

Several NPC mailbox command IDs in the 0x601x range were assigned out of
order. Renumber and reorder the M() definitions so each opcode matches
the stable contract expected by userspace tools and applications.

Fixes: 4e527f1e5c15 ("octeontx2-af: npc: cn20k: Add new mailboxes for CN20K silicon")
Cc: Suman Ghosh <sumang@marvell.com>
Signed-off-by: Ratheesh Kannoth <rkannoth@marvell.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260611083330.1652181-1-rkannoth@marvell.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../net/ethernet/marvell/octeontx2/af/mbox.h  | 31 +++++++++----------
 1 file changed, 15 insertions(+), 16 deletions(-)

diff --git a/drivers/net/ethernet/marvell/octeontx2/af/mbox.h b/drivers/net/ethernet/marvell/octeontx2/af/mbox.h
index dc42c81c094256..44fdd6ba7307c8 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/mbox.h
+++ b/drivers/net/ethernet/marvell/octeontx2/af/mbox.h
@@ -283,31 +283,30 @@ M(NPC_GET_FIELD_HASH_INFO, 0x6013, npc_get_field_hash_info,
 M(NPC_GET_FIELD_STATUS, 0x6014, npc_get_field_status,                     \
 				   npc_get_field_status_req,              \
 				   npc_get_field_status_rsp)              \
-M(NPC_CN20K_MCAM_GET_FREE_COUNT, 0x6015, npc_cn20k_get_fcnt,		\
-				 msg_req, npc_cn20k_get_fcnt_rsp)	\
-M(NPC_CN20K_GET_KEX_CFG, 0x6016, npc_cn20k_get_kex_cfg,			\
+M(NPC_MCAM_DEFRAG,	 0x6016,	npc_defrag,			\
+					msg_req,			\
+					msg_rsp)		\
+M(NPC_CN20K_GET_KEX_CFG, 0x6017, npc_cn20k_get_kex_cfg,			\
 				   msg_req, npc_cn20k_get_kex_cfg_rsp)	\
-M(NPC_CN20K_MCAM_WRITE_ENTRY,	0x6017, npc_cn20k_mcam_write_entry,	\
-				 npc_cn20k_mcam_write_entry_req, msg_rsp)  \
-M(NPC_CN20K_MCAM_ALLOC_AND_WRITE_ENTRY, 0x6018,				   \
-npc_cn20k_mcam_alloc_and_write_entry,					   \
+M(NPC_CN20K_MCAM_GET_FREE_COUNT, 0x6018, npc_cn20k_get_fcnt,			\
+				 msg_req, npc_cn20k_get_fcnt_rsp)	\
+M(NPC_CN20K_MCAM_WRITE_ENTRY,	0x6019, npc_cn20k_mcam_write_entry,			\
+				 npc_cn20k_mcam_write_entry_req, msg_rsp)	\
+M(NPC_CN20K_MCAM_ALLOC_AND_WRITE_ENTRY, 0x601a, npc_cn20k_mcam_alloc_and_write_entry,	\
 				npc_cn20k_mcam_alloc_and_write_entry_req,  \
 				npc_mcam_alloc_and_write_entry_rsp)  \
-M(NPC_CN20K_MCAM_READ_ENTRY,	0x6019, npc_cn20k_mcam_read_entry,	\
+M(NPC_CN20K_MCAM_READ_ENTRY,	0x601b, npc_cn20k_mcam_read_entry,	\
 				  npc_mcam_read_entry_req,		\
 				  npc_cn20k_mcam_read_entry_rsp)	\
-M(NPC_CN20K_MCAM_READ_BASE_RULE, 0x601a, npc_cn20k_read_base_steer_rule,       \
-				   msg_req, npc_cn20k_mcam_read_base_rule_rsp) \
-M(NPC_MCAM_DEFRAG,	     0x601b,	npc_defrag,			\
-					msg_req,			\
-					msg_rsp)			\
-M(NPC_MCAM_GET_NUM_KWS, 0x601c, npc_get_num_kws,		\
+M(NPC_CN20K_MCAM_READ_BASE_RULE, 0x601c, npc_cn20k_read_base_steer_rule,            \
+				   msg_req, npc_cn20k_mcam_read_base_rule_rsp)  \
+M(NPC_MCAM_GET_NUM_KWS, 0x601d, npc_get_num_kws,		\
 				npc_get_num_kws_req,		\
 				npc_get_num_kws_rsp)		\
-M(NPC_MCAM_GET_DFT_RL_IDXS, 0x601d, npc_get_dft_rl_idxs,	\
+M(NPC_MCAM_GET_DFT_RL_IDXS, 0x601e, npc_get_dft_rl_idxs,	\
 					msg_req,		\
 					npc_get_dft_rl_idxs_rsp)\
-M(NPC_MCAM_GET_NPC_PFL_INFO, 0x601e, npc_get_pfl_info,		\
+M(NPC_MCAM_GET_NPC_PFL_INFO, 0x601f, npc_get_pfl_info,		\
 					msg_req,		\
 					npc_get_pfl_info_rsp)	\
 /* NIX mbox IDs (range 0x8000 - 0xFFFF) */				\
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0767/2077] net: airoha: Fix register index for Tx-fwd counter configuration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (765 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0766/2077] octeontx2-af: fix NPC mailbox codes in mbox.h Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0768/2077] net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries Greg Kroah-Hartman
                   ` (230 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wayen.Yan, Lorenzo Bianconi,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wayen.Yan <win847@gmail.com>

[ Upstream commit 1402ecccf5630a0b7fa4749d7d2e72abc3f3d73d ]

In airoha_qdma_init_qos_stats(), the Tx-fwd counter configuration
register uses the same index (i << 1) as the Tx-cpu counter, which
overwrites the Tx-cpu configuration. The Tx-fwd counter value register
correctly uses (i << 1) + 1, so the configuration register should use
the same index.

Fix the REG_CNTR_CFG index from (i << 1) to ((i << 1) + 1) so that
the Tx-fwd counter is properly configured instead of clobbering the
Tx-cpu counter config.

Fixes: 20bf7d07c956 ("net: airoha: Add sched ETS offload support")
Signed-off-by: Wayen.Yan <win847@gmail.com>
Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/6a2b40e7.4dd82583.3a5c46.e566@mx.google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/airoha/airoha_eth.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/airoha/airoha_eth.c b/drivers/net/ethernet/airoha/airoha_eth.c
index 31cdb11cd78dac..329988a8400c13 100644
--- a/drivers/net/ethernet/airoha/airoha_eth.c
+++ b/drivers/net/ethernet/airoha/airoha_eth.c
@@ -1256,7 +1256,7 @@ static void airoha_qdma_init_qos_stats(struct airoha_qdma *qdma)
 			       FIELD_PREP(CNTR_CHAN_MASK, i));
 		/* Tx-fwd transferred count */
 		airoha_qdma_wr(qdma, REG_CNTR_VAL((i << 1) + 1), 0);
-		airoha_qdma_wr(qdma, REG_CNTR_CFG(i << 1),
+		airoha_qdma_wr(qdma, REG_CNTR_CFG((i << 1) + 1),
 			       CNTR_EN_MASK | CNTR_ALL_QUEUE_EN_MASK |
 			       CNTR_ALL_DSCP_RING_EN_MASK |
 			       FIELD_PREP(CNTR_SRC_MASK, 1) |
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0768/2077] net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (766 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0767/2077] net: airoha: Fix register index for Tx-fwd counter configuration Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0769/2077] kcm: use WRITE_ONCE() when changing lower socket callbacks Greg Kroah-Hartman
                   ` (229 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wayen.Yan, Lorenzo Bianconi,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wayen.Yan <win847@gmail.com>

[ Upstream commit 1c3a77471afbb3981af28f7f7c8b2487558e4b00 ]

In airoha_ppe_debugfs_foe_show(), the second switch statement falls
through from PPE_PKT_TYPE_IPV4_HNAPT/DSLITE to PPE_PKT_TYPE_IPV4_ROUTE,
accessing hwe->ipv4.new_tuple for all three types. However, IPv4 ROUTE
(3-tuple) entries do not contain a valid new_tuple — this field is only
meaningful for NATted flows (HNAPT/DSLITE). For ROUTE entries, the
memory at the new_tuple offset holds routing information, not NAT data,
so displaying "new=" produces garbage output.

Display new_tuple only for HNAPT and DSLITE, and let IPV4_ROUTE fall
through to the default case.

Fixes: 3fe15c640f38 ("net: airoha: Introduce PPE debugfs support")
Link: https://lore.kernel.org/6a2b40ea.4dd82583.3a5c46.e5a2@mx.google.com
Signed-off-by: Wayen.Yan <win847@gmail.com>
Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/6a2be54b.ef98c1b2.3c3224.2ed8@mx.google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/airoha/airoha_ppe_debugfs.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/drivers/net/ethernet/airoha/airoha_ppe_debugfs.c b/drivers/net/ethernet/airoha/airoha_ppe_debugfs.c
index 0112c41150bb05..e46a98514486ff 100644
--- a/drivers/net/ethernet/airoha/airoha_ppe_debugfs.c
+++ b/drivers/net/ethernet/airoha/airoha_ppe_debugfs.c
@@ -121,8 +121,6 @@ static int airoha_ppe_debugfs_foe_show(struct seq_file *m, void *private,
 		case PPE_PKT_TYPE_IPV4_DSLITE:
 			src_port = &hwe->ipv4.new_tuple.src_port;
 			dest_port = &hwe->ipv4.new_tuple.dest_port;
-			fallthrough;
-		case PPE_PKT_TYPE_IPV4_ROUTE:
 			src_addr = &hwe->ipv4.new_tuple.src_ip;
 			dest_addr = &hwe->ipv4.new_tuple.dest_ip;
 			seq_puts(m, " new=");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0769/2077] kcm: use WRITE_ONCE() when changing lower socket callbacks
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (767 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0768/2077] net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0770/2077] ALSA: seq: oss: Serialize readq reset state with q->lock Greg Kroah-Hartman
                   ` (228 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Paolo Abeni, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Runyu Xiao <runyu.xiao@seu.edu.cn>

[ Upstream commit 47186409c092cd7dd70350999186c700233e854d ]

kcm_attach() replaces a live lower TCP socket's sk_data_ready and
sk_write_space callbacks with KCM handlers, and kcm_unattach() restores
them later. Those callback-pointer updates are still plain stores even
though the same fields can be read and invoked concurrently on other
CPUs.

If another CPU observes an older callback snapshot after the live field
has already been restored, callback execution can run with a mismatched
target and sk_user_data state, leading to stale or misdirected wakeups.

Use WRITE_ONCE() for the callback replacement and restore operations so
these shared callback fields follow the same visibility contract already
established by the earlier 4022 fixes.

Fixes: ab7ac4eb9832 ("kcm: Kernel Connection Multiplexor module")
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Link: https://patch.msgid.link/20260611053543.2429462-1-runyu.xiao@seu.edu.cn
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/kcm/kcmsock.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/net/kcm/kcmsock.c b/net/kcm/kcmsock.c
index 3912e75079f5eb..a998336840c335 100644
--- a/net/kcm/kcmsock.c
+++ b/net/kcm/kcmsock.c
@@ -1304,8 +1304,8 @@ static int kcm_attach(struct socket *sock, struct socket *csock,
 	psock->save_write_space = csk->sk_write_space;
 	psock->save_state_change = csk->sk_state_change;
 	csk->sk_user_data = psock;
-	csk->sk_data_ready = psock_data_ready;
-	csk->sk_write_space = psock_write_space;
+	WRITE_ONCE(csk->sk_data_ready, psock_data_ready);
+	WRITE_ONCE(csk->sk_write_space, psock_write_space);
 	csk->sk_state_change = psock_state_change;
 
 	write_unlock_bh(&csk->sk_callback_lock);
@@ -1381,8 +1381,8 @@ static void kcm_unattach(struct kcm_psock *psock)
 	 */
 	write_lock_bh(&csk->sk_callback_lock);
 	csk->sk_user_data = NULL;
-	csk->sk_data_ready = psock->save_data_ready;
-	csk->sk_write_space = psock->save_write_space;
+	WRITE_ONCE(csk->sk_data_ready, psock->save_data_ready);
+	WRITE_ONCE(csk->sk_write_space, psock->save_write_space);
 	csk->sk_state_change = psock->save_state_change;
 	strp_stop(&psock->strp);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0770/2077] ALSA: seq: oss: Serialize readq reset state with q->lock
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (768 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0769/2077] kcm: use WRITE_ONCE() when changing lower socket callbacks Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0771/2077] ALSA: seq: avoid stale FIFO cells during resize Greg Kroah-Hartman
                   ` (227 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Cen Zhang, Takashi Iwai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cen Zhang <zzzccc427@gmail.com>

[ Upstream commit 49ce92d207820f588b0406add82f053decfbe5d9 ]

snd_seq_oss_readq_clear() resets qlen, head, and tail without
q->lock even though the normal reader and producer paths serialize the
same ring state under that spinlock. A reset can therefore race
snd_seq_oss_readq_free() or snd_seq_oss_readq_put_event() and leave
stale records in the queue, drop freshly queued ones, or report the
wrong readiness after wakeup. KCSAN reports a data race between
snd_seq_oss_readq_clear() and snd_seq_oss_readq_free().

Take q->lock while clearing the ring and resetting input_time. Factor
the enqueue logic into a caller-locked helper so
snd_seq_oss_readq_put_timestamp() updates its suppression state under
the same lock instead of racing the reset path.

The buggy scenario involves two paths, with each column showing the
order within that path:

reset path:                      locked readq updater:
1. snd_seq_oss_reset() or        1. A reader or callback producer
   release reaches                  takes q->lock on the same queue.
   snd_seq_oss_readq_clear().
2. snd_seq_oss_readq_clear()     2. The updater tests or modifies
   resets qlen, head, tail,         qlen, head, and tail.
   and input_time.
3. snd_seq_oss_readq_clear()     3. The updater completes its
   wakes sleepers on                read-modify-write sequence.
   q->midi_sleep.
4. Without q->lock, the reset    4. The resulting ring state drives
   can overlap the locked           later reads and readiness.
   update.

KCSAN reports:

BUG: KCSAN: data-race in snd_seq_oss_readq_clear /
snd_seq_oss_readq_free

write to 0xffff8881069fe608 of 4 bytes by task 120516 on cpu 0:
  snd_seq_oss_readq_free+0x6c/0x80
  snd_seq_oss_read+0xcb/0x250
  odev_read+0x38/0x60
  vfs_read+0xff/0x600
  ksys_read+0xb4/0x140
  __x64_sys_read+0x46/0x60
  do_syscall_64+0xbb/0x2f0
  entry_SYSCALL_64_after_hwframe+0x77/0x7f

read to 0xffff8881069fe608 of 4 bytes by task 120517 on cpu 1:
  snd_seq_oss_readq_clear+0x1f/0x90
  snd_seq_oss_reset+0xa7/0xf0
  snd_seq_oss_ioctl+0x6f6/0x7e0
  odev_ioctl+0x56/0xc0
  __x64_sys_ioctl+0xd1/0x120
  do_syscall_64+0xbb/0x2f0
  entry_SYSCALL_64_after_hwframe+0x77/0x7f

value changed: 0x00000001 -> 0x00000000

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")

Signed-off-by: Cen Zhang <zzzccc427@gmail.com>
Link: https://patch.msgid.link/20260614004801.3507773-1-zzzccc427@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/core/seq/oss/seq_oss_readq.c | 77 ++++++++++++++++++++----------
 1 file changed, 52 insertions(+), 25 deletions(-)

diff --git a/sound/core/seq/oss/seq_oss_readq.c b/sound/core/seq/oss/seq_oss_readq.c
index c880d47711698a..06e12707db2131 100644
--- a/sound/core/seq/oss/seq_oss_readq.c
+++ b/sound/core/seq/oss/seq_oss_readq.c
@@ -73,13 +73,17 @@ snd_seq_oss_readq_delete(struct seq_oss_readq *q)
 void
 snd_seq_oss_readq_clear(struct seq_oss_readq *q)
 {
-	if (q->qlen) {
-		q->qlen = 0;
-		q->head = q->tail = 0;
+	scoped_guard(spinlock_irqsave, &q->lock) {
+		if (q->qlen) {
+			q->qlen = 0;
+			q->head = 0;
+			q->tail = 0;
+		}
+		q->input_time = (unsigned long)-1;
 	}
+
 	/* if someone sleeping, wake'em up */
 	wake_up(&q->midi_sleep);
-	q->input_time = (unsigned long)-1;
 }
 
 /*
@@ -136,11 +140,11 @@ int snd_seq_oss_readq_sysex(struct seq_oss_readq *q, int dev,
 /*
  * copy an event to input queue:
  * return zero if enqueued
+ * caller must hold lock
  */
-int
-snd_seq_oss_readq_put_event(struct seq_oss_readq *q, union evrec *ev)
+static int snd_seq_oss_readq_put_event_locked(struct seq_oss_readq *q,
+					      union evrec *ev)
 {
-	guard(spinlock_irqsave)(&q->lock);
 	if (q->qlen >= q->maxlen - 1)
 		return -ENOMEM;
 
@@ -148,12 +152,27 @@ snd_seq_oss_readq_put_event(struct seq_oss_readq *q, union evrec *ev)
 	q->tail = (q->tail + 1) % q->maxlen;
 	q->qlen++;
 
-	/* wake up sleeper */
-	wake_up(&q->midi_sleep);
-
 	return 0;
 }
 
+/*
+ * copy an event to input queue:
+ * return zero if enqueued
+ */
+int
+snd_seq_oss_readq_put_event(struct seq_oss_readq *q, union evrec *ev)
+{
+	int rc;
+
+	scoped_guard(spinlock_irqsave, &q->lock) {
+		rc = snd_seq_oss_readq_put_event_locked(q, ev);
+		if (!rc)
+			wake_up(&q->midi_sleep);
+	}
+
+	return rc;
+}
+
 
 /*
  * pop queue
@@ -209,23 +228,31 @@ snd_seq_oss_readq_poll(struct seq_oss_readq *q, struct file *file, poll_table *w
 int
 snd_seq_oss_readq_put_timestamp(struct seq_oss_readq *q, unsigned long curt, int seq_mode)
 {
-	if (curt != q->input_time) {
-		union evrec rec;
-		memset(&rec, 0, sizeof(rec));
-		switch (seq_mode) {
-		case SNDRV_SEQ_OSS_MODE_SYNTH:
-			rec.echo = (curt << 8) | SEQ_WAIT;
-			snd_seq_oss_readq_put_event(q, &rec);
-			break;
-		case SNDRV_SEQ_OSS_MODE_MUSIC:
-			rec.t.code = EV_TIMING;
-			rec.t.cmd = TMR_WAIT_ABS;
-			rec.t.time = curt;
-			snd_seq_oss_readq_put_event(q, &rec);
-			break;
+	int queued = 0;
+
+	scoped_guard(spinlock_irqsave, &q->lock) {
+		if (curt != q->input_time) {
+			union evrec rec;
+
+			memset(&rec, 0, sizeof(rec));
+			switch (seq_mode) {
+			case SNDRV_SEQ_OSS_MODE_SYNTH:
+				rec.echo = (curt << 8) | SEQ_WAIT;
+				queued = !snd_seq_oss_readq_put_event_locked(q, &rec);
+				break;
+			case SNDRV_SEQ_OSS_MODE_MUSIC:
+				rec.t.code = EV_TIMING;
+				rec.t.cmd = TMR_WAIT_ABS;
+				rec.t.time = curt;
+				queued = !snd_seq_oss_readq_put_event_locked(q, &rec);
+				break;
+			}
+			q->input_time = curt;
 		}
-		q->input_time = curt;
 	}
+	if (queued)
+		wake_up(&q->midi_sleep);
+
 	return 0;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0771/2077] ALSA: seq: avoid stale FIFO cells during resize
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (769 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0770/2077] ALSA: seq: oss: Serialize readq reset state with q->lock Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0772/2077] netfilter: nf_conncount: callers must hold rcu read lock Greg Kroah-Hartman
                   ` (226 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Cen Zhang, Takashi Iwai, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cen Zhang <zzzccc427@gmail.com>

[ Upstream commit e546128291f8d688dcb931827e2efd2aa6c0734d ]

snd_seq_fifo_resize() still needs to publish the replacement pool
before it waits for FIFO users. A blocking snd_seq_read() holds
f->use_lock while it sleeps, so concurrent senders must be able to
queue to the new pool and wake that reader instead of failing against a
closing old pool.

However, snd_seq_fifo_event_in() duplicates an event before it takes
f->lock, and snd_seq_read() can dequeue a cell and later call
snd_seq_fifo_cell_putback() if copy_to_user() or
snd_seq_expand_var_event() fails. If resize swaps f->pool and detaches
oldhead in between, either path can relink an old-pool cell after the
snapshot. That stale cell sits outside the drained oldhead list, keeps
oldpool->counter elevated, and can leave snd_seq_pool_delete() waiting
for the retired pool to drain.

Keep the existing swap-before-wait ordering in snd_seq_fifo_resize(),
but reject stale cells before any FIFO relink. Revalidate event-in cells
under f->lock and retry them against the published replacement pool, and
free stale putback cells instead of linking them back into the FIFO.

The buggy scenario involves two paths, with each column showing the
order within that path:

resize path:                    relink path:
1. Allocate newpool.             1. Take f->use_lock.
2. Swap f->pool to newpool and   2. Duplicate or dequeue an old-pool
   detach oldhead.                  cell before oldpool closes.
3. Mark oldpool closing and      3. Reach a later relink point after
   wait for FIFO users.             resize published newpool.
4. Free oldhead and delete       4. Relink the old-pool cell after
   oldpool.                         resize detached oldhead.
                                 5. Drop f->use_lock.

The reproducer reports a resize ioctl blocked in the expected pool
teardown path:

signal: resize iteration=98 target_pool=4 exceeded 250ms
        (elapsed=251ms)
diagnostic: resize_tid=651 wchan=snd_seq_pool_done
diagnostic: resize_tid=651 stack=
  snd_seq_pool_done+0x5b/0x140
  snd_seq_pool_delete+0x7a/0x90
  snd_seq_fifo_resize+0x193/0x1e0
  snd_seq_ioctl_set_client_pool+0x214/0x260
  snd_seq_ioctl+0x119/0x540
  __x64_sys_ioctl+0xd1/0x120
  do_syscall_64+0xbb/0x2f0
  entry_SYSCALL_64_after_hwframe+0x77/0x7f

A second run with larger pools hit the same target path:

signal: resize iteration=32 target_pool=64 exceeded 250ms
        (elapsed=251ms)
diagnostic: resize_tid=663 wchan=snd_seq_pool_done
diagnostic: resize_tid=663 stack=
  snd_seq_pool_done+0x5b/0x140
  snd_seq_pool_delete+0x7a/0x90
  snd_seq_fifo_resize+0x193/0x1e0
  snd_seq_ioctl_set_client_pool+0x214/0x260
  snd_seq_ioctl+0x119/0x540
  __x64_sys_ioctl+0xd1/0x120
  do_syscall_64+0xbb/0x2f0
  entry_SYSCALL_64_after_hwframe+0x77/0x7f

Fixes: 2d7d54002e39 ("ALSA: seq: Fix race during FIFO resize")

Signed-off-by: Cen Zhang <zzzccc427@gmail.com>
Link: https://patch.msgid.link/20260614004801.3507773-2-zzzccc427@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/core/seq/seq_fifo.c | 52 ++++++++++++++++++++++++++++-----------
 1 file changed, 37 insertions(+), 15 deletions(-)

diff --git a/sound/core/seq/seq_fifo.c b/sound/core/seq/seq_fifo.c
index ebe1394c18a964..cffa8d43037476 100644
--- a/sound/core/seq/seq_fifo.c
+++ b/sound/core/seq/seq_fifo.c
@@ -101,13 +101,17 @@ int snd_seq_fifo_event_in(struct snd_seq_fifo *f,
 			  struct snd_seq_event *event)
 {
 	struct snd_seq_event_cell *cell;
+	struct snd_seq_pool *pool;
+	bool linked;
 	int err;
 
 	if (snd_BUG_ON(!f))
 		return -EINVAL;
 
 	guard(snd_seq_fifo)(f);
-	err = snd_seq_event_dup(f->pool, event, &cell, 1, NULL, NULL); /* always non-blocking */
+retry:
+	pool = READ_ONCE(f->pool);
+	err = snd_seq_event_dup(pool, event, &cell, 1, NULL, NULL); /* always non-blocking */
 	if (err < 0) {
 		if ((err == -ENOMEM) || (err == -EAGAIN))
 			atomic_inc(&f->overflow);
@@ -115,14 +119,24 @@ int snd_seq_fifo_event_in(struct snd_seq_fifo *f,
 	}
 		
 	/* append new cells to fifo */
+	linked = false;
 	scoped_guard(spinlock_irqsave, &f->lock) {
-		if (f->tail != NULL)
-			f->tail->next = cell;
-		f->tail = cell;
-		if (f->head == NULL)
-			f->head = cell;
-		cell->next = NULL;
-		f->cells++;
+		if (cell->pool == f->pool) {
+			if (f->tail)
+				f->tail->next = cell;
+			f->tail = cell;
+			if (!f->head)
+				f->head = cell;
+			cell->next = NULL;
+			f->cells++;
+			linked = true;
+		}
+	}
+
+	if (!linked) {
+		/* Retry against the replacement pool after resize publishes it. */
+		snd_seq_cell_free(cell);
+		goto retry;
 	}
 
 	/* wakeup client */
@@ -194,13 +208,21 @@ int snd_seq_fifo_cell_out(struct snd_seq_fifo *f,
 void snd_seq_fifo_cell_putback(struct snd_seq_fifo *f,
 			       struct snd_seq_event_cell *cell)
 {
+	bool linked = false;
+
 	if (cell) {
-		guard(spinlock_irqsave)(&f->lock);
-		cell->next = f->head;
-		f->head = cell;
-		if (!f->tail)
-			f->tail = cell;
-		f->cells++;
+		scoped_guard(spinlock_irqsave, &f->lock) {
+			if (cell->pool == f->pool) {
+				cell->next = f->head;
+				f->head = cell;
+				if (!f->tail)
+					f->tail = cell;
+				f->cells++;
+				linked = true;
+			}
+		}
+		if (!linked)
+			snd_seq_cell_free(cell);
 	}
 }
 
@@ -237,7 +259,7 @@ int snd_seq_fifo_resize(struct snd_seq_fifo *f, int poolsize)
 		oldpool = f->pool;
 		oldhead = f->head;
 		/* exchange pools */
-		f->pool = newpool;
+		WRITE_ONCE(f->pool, newpool);
 		f->head = NULL;
 		f->tail = NULL;
 		f->cells = 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0772/2077] netfilter: nf_conncount: callers must hold rcu read lock
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (770 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0771/2077] ALSA: seq: avoid stale FIFO cells during resize Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0773/2077] netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them Greg Kroah-Hartman
                   ` (225 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Florian Westphal, Pablo Neira Ayuso,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Florian Westphal <fw@strlen.de>

[ Upstream commit 64d7d5abe2160bba369b4a8f06bdf5630573bab0 ]

rcu_derefence_raw() should not have been used here, it concealed this bug.
Its used because struct rb_node lacks __rcu annotated pointers, so plain
rcu_derefence causes sparse warnings.

The major tradeoff is that rcu_derefence_raw() doesn't warn when the caller
isn't in a rcu read section.

Extend the rcu read lock scope accordingly and cause sparse warnings,
those warnings are the lesser evil.

Fixes: 11efd5cb04a1 ("openvswitch: Support conntrack zone limit")
Closes: https://sashiko.dev/#/patchset/20260603230610.7900-1-fw%40strlen.de
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/netfilter/nf_conncount.c | 6 +++---
 net/openvswitch/conntrack.c  | 2 +-
 2 files changed, 4 insertions(+), 4 deletions(-)

diff --git a/net/netfilter/nf_conncount.c b/net/netfilter/nf_conncount.c
index 00eed5b4d1b12a..dac29e933553d3 100644
--- a/net/netfilter/nf_conncount.c
+++ b/net/netfilter/nf_conncount.c
@@ -499,7 +499,7 @@ count_tree(struct net *net,
 	hash = jhash2(key, data->keylen, conncount_rnd) % CONNCOUNT_SLOTS;
 	root = &data->root[hash];
 
-	parent = rcu_dereference_raw(root->rb_node);
+	parent = rcu_dereference(root->rb_node);
 	while (parent) {
 		int diff;
 
@@ -507,9 +507,9 @@ count_tree(struct net *net,
 
 		diff = key_diff(key, rbconn->key, data->keylen);
 		if (diff < 0) {
-			parent = rcu_dereference_raw(parent->rb_left);
+			parent = rcu_dereference(parent->rb_left);
 		} else if (diff > 0) {
-			parent = rcu_dereference_raw(parent->rb_right);
+			parent = rcu_dereference(parent->rb_right);
 		} else {
 			int ret;
 
diff --git a/net/openvswitch/conntrack.c b/net/openvswitch/conntrack.c
index 7c9256572284f8..c6fd9c424e8fea 100644
--- a/net/openvswitch/conntrack.c
+++ b/net/openvswitch/conntrack.c
@@ -1797,10 +1797,10 @@ static int ovs_ct_limit_get_zone_limit(struct net *net,
 		} else {
 			rcu_read_lock();
 			limit = ct_limit_get(info, zone);
-			rcu_read_unlock();
 
 			err = __ovs_ct_limit_get_zone_limit(
 				net, info->data, zone, limit, reply);
+			rcu_read_unlock();
 			if (err)
 				return err;
 		}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0773/2077] netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (771 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0772/2077] netfilter: nf_conncount: callers must hold rcu read lock Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0774/2077] geneve: Fix off-by-one comparing with GRO_LEGACY_MAX_SIZE Greg Kroah-Hartman
                   ` (224 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pablo Neira Ayuso <pablo@netfilter.org>

[ Upstream commit 2354e975932dabb06fad239f07a3b68fd1809737 ]

Update nft_dup and nft_fwd to use the nf_dev_xmit_recursion() helpers.
This patch also disables BH when transmitting the skb to address a
possible migration to different CPU leading to imbalanced decrementation
of the recursion counters.

This is modeled after Florian Westphal's dev_xmit_recursion*() API
available since commit 97cdcf37b57e ("net: place xmit recursion in
softnet data") according to its current state in the tree.

Fixes: 1d47b55b36d2 ("netfilter: nft_fwd_netdev: use recursion counter in neigh egress path")
Fixes: f37ad9127039 ("netfilter: nf_dup_netdev: Move the recursion counter struct netdev_xmit")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/net/netfilter/nf_dup_netdev.h | 34 +++++++++++++++++++++++----
 net/netfilter/nf_dup_netdev.c         | 15 ++++++------
 net/netfilter/nft_fwd_netdev.c        | 17 ++++++++------
 3 files changed, 47 insertions(+), 19 deletions(-)

diff --git a/include/net/netfilter/nf_dup_netdev.h b/include/net/netfilter/nf_dup_netdev.h
index 609bcf422a9b31..f6b05bd80c3fe3 100644
--- a/include/net/netfilter/nf_dup_netdev.h
+++ b/include/net/netfilter/nf_dup_netdev.h
@@ -11,15 +11,39 @@ void nf_fwd_netdev_egress(const struct nft_pktinfo *pkt, int oif);
 
 #define NF_RECURSION_LIMIT	2
 
-static inline u8 *nf_get_nf_dup_skb_recursion(void)
-{
 #ifndef CONFIG_PREEMPT_RT
-	return this_cpu_ptr(&softnet_data.xmit.nf_dup_skb_recursion);
+static inline bool nf_dev_xmit_recursion(void)
+{
+	return unlikely(__this_cpu_read(softnet_data.xmit.nf_dup_skb_recursion) >
+			NF_RECURSION_LIMIT);
+}
+
+static inline void nf_dev_xmit_recursion_inc(void)
+{
+	__this_cpu_inc(softnet_data.xmit.nf_dup_skb_recursion);
+}
+
+static inline void nf_dev_xmit_recursion_dec(void)
+{
+	__this_cpu_dec(softnet_data.xmit.nf_dup_skb_recursion);
+}
 #else
-	return &current->net_xmit.nf_dup_skb_recursion;
-#endif
+static inline bool nf_dev_xmit_recursion(void)
+{
+	return unlikely(current->net_xmit.nf_dup_skb_recursion > NF_RECURSION_LIMIT);
+}
+
+static inline void nf_dev_xmit_recursion_inc(void)
+{
+	current->net_xmit.nf_dup_skb_recursion++;
 }
 
+static inline void nf_dev_xmit_recursion_dec(void)
+{
+	current->net_xmit.nf_dup_skb_recursion--;
+}
+#endif
+
 struct nft_offload_ctx;
 struct nft_flow_rule;
 
diff --git a/net/netfilter/nf_dup_netdev.c b/net/netfilter/nf_dup_netdev.c
index 3d88ef927f31cb..c6bd5c29bed66d 100644
--- a/net/netfilter/nf_dup_netdev.c
+++ b/net/netfilter/nf_dup_netdev.c
@@ -16,11 +16,6 @@
 static void nf_do_netdev_egress(struct sk_buff *skb, struct net_device *dev,
 				enum nf_dev_hooks hook)
 {
-	u8 *nf_dup_skb_recursion = nf_get_nf_dup_skb_recursion();
-
-	if (*nf_dup_skb_recursion > NF_RECURSION_LIMIT)
-		goto err;
-
 	if (hook == NF_NETDEV_INGRESS && skb_mac_header_was_set(skb)) {
 		if (skb_cow_head(skb, skb->mac_len))
 			goto err;
@@ -30,9 +25,15 @@ static void nf_do_netdev_egress(struct sk_buff *skb, struct net_device *dev,
 
 	skb->dev = dev;
 	skb_clear_tstamp(skb);
-	(*nf_dup_skb_recursion)++;
+	local_bh_disable();
+	if (nf_dev_xmit_recursion()) {
+		local_bh_enable();
+		goto err;
+	}
+	nf_dev_xmit_recursion_inc();
 	dev_queue_xmit(skb);
-	(*nf_dup_skb_recursion)--;
+	nf_dev_xmit_recursion_dec();
+	local_bh_enable();
 	return;
 err:
 	kfree_skb(skb);
diff --git a/net/netfilter/nft_fwd_netdev.c b/net/netfilter/nft_fwd_netdev.c
index b9e88d7cf3081a..a48c2f765bbaad 100644
--- a/net/netfilter/nft_fwd_netdev.c
+++ b/net/netfilter/nft_fwd_netdev.c
@@ -95,7 +95,6 @@ static void nft_fwd_neigh_eval(const struct nft_expr *expr,
 			      struct nft_regs *regs,
 			      const struct nft_pktinfo *pkt)
 {
-	u8 *nf_dup_skb_recursion = nf_get_nf_dup_skb_recursion();
 	struct nft_fwd_neigh *priv = nft_expr_priv(expr);
 	void *addr = &regs->data[priv->sreg_addr];
 	int oif = regs->data[priv->sreg_dev];
@@ -154,13 +153,15 @@ static void nft_fwd_neigh_eval(const struct nft_expr *expr,
 		goto out;
 	}
 
-	if (*nf_dup_skb_recursion > NF_RECURSION_LIMIT) {
+	dev = dev_get_by_index_rcu(nft_net(pkt), oif);
+	if (!dev) {
 		verdict = NF_DROP;
 		goto out;
 	}
 
-	dev = dev_get_by_index_rcu(nft_net(pkt), oif);
-	if (dev == NULL) {
+	local_bh_disable();
+	if (nf_dev_xmit_recursion()) {
+		local_bh_enable();
 		verdict = NF_DROP;
 		goto out;
 	}
@@ -169,16 +170,18 @@ static void nft_fwd_neigh_eval(const struct nft_expr *expr,
 	if (unlikely(skb_headroom(skb) < hh_len && dev->header_ops)) {
 		skb = skb_expand_head(skb, hh_len);
 		if (!skb) {
-			verdict = NF_STOLEN;
+			local_bh_enable();
 			goto out;
 		}
 	}
 
 	skb->dev = dev;
 	skb_clear_tstamp(skb);
-	(*nf_dup_skb_recursion)++;
+
+	nf_dev_xmit_recursion_inc();
 	neigh_xmit(neigh_table, dev, addr, skb);
-	(*nf_dup_skb_recursion)--;
+	nf_dev_xmit_recursion_dec();
+	local_bh_enable();
 out:
 	regs->verdict.code = verdict;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0774/2077] geneve: Fix off-by-one comparing with GRO_LEGACY_MAX_SIZE
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (772 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0773/2077] netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0775/2077] ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() Greg Kroah-Hartman
                   ` (223 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Alice Mikityanska, Willem de Bruijn,
	Paolo Abeni, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alice Mikityanska <alice@isovalent.com>

[ Upstream commit 2319688890d97c63da423a3c57c23b4ab5952dfc ]

GRO_LEGACY_MAX_SIZE = 65536; total_len being 65536 is too big to fit
into a u16. As can be seen in skb_gro_receive, packets bigger or equal
to gro_max_size (or GRO_LEGACY_MAX_SIZE) are dropped with -E2BIG. Apply
the same boundary to geneve_post_decap_hint to avoid writing 65536 to a
16-bit iph->tot_len field with an overflow.

Fixes: fd0dd796576e ("geneve: use GRO hint option in the RX path")
Signed-off-by: Alice Mikityanska <alice@isovalent.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260611192955.604661-3-alice.kernel@fastmail.im
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/geneve.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/geneve.c b/drivers/net/geneve.c
index 715180c3a1b34e..b2e74e815e5778 100644
--- a/drivers/net/geneve.c
+++ b/drivers/net/geneve.c
@@ -603,7 +603,7 @@ static int geneve_post_decap_hint(const struct sock *sk, struct sk_buff *skb,
 	ipv6h = (void *)skb->data + gro_hint->nested_nh_offset;
 	iph = (struct iphdr *)ipv6h;
 	total_len = skb->len - gro_hint->nested_nh_offset;
-	if (total_len > GRO_LEGACY_MAX_SIZE)
+	if (total_len >= GRO_LEGACY_MAX_SIZE)
 		return -E2BIG;
 
 	/*
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0775/2077] ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (773 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0774/2077] geneve: Fix off-by-one comparing with GRO_LEGACY_MAX_SIZE Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0776/2077] smb: client: fix conflicting option validation for new mount API Greg Kroah-Hartman
                   ` (222 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, WenTao Liang, Takashi Iwai,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Takashi Iwai <tiwai@suse.de>

[ Upstream commit b113a891252c3fa4fab11ec8c2894a22ecaf278c ]

snd_power_ref_and_wait() takes the power refcount and doesn't leave it
no matter whether it returns an error or not.  However, the majority
of callers don't expect but just returns without unreferencing in the
caller side upon errors.

For addressing the potential refcount unbalance, rather correct the
behavior of snd_power_ref_wait() to unreference upon returning an
error.

Note that the problem above is likely negligible; the function returns
an error only when the sound card is being shutdown, hence it doesn't
matter about the power refcount any longer at such a state.

Fixes: e94fdbd7b25d ("ALSA: control: Track in-flight control read/write/tlv accesses")
Reported-by: WenTao Liang <vulab@iscas.ac.cn>
Closes: https://lore.kernel.org/20260612022121.14329-1-vulab@iscas.ac.cn
Link: https://patch.msgid.link/20260614090507.772540-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 sound/core/init.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

diff --git a/sound/core/init.c b/sound/core/init.c
index 0c316189e94769..9bff101af6478f 100644
--- a/sound/core/init.c
+++ b/sound/core/init.c
@@ -1139,7 +1139,7 @@ EXPORT_SYMBOL(snd_card_file_remove);
  * typically around calling control ops.
  *
  * The caller needs to pull down the refcount via snd_power_unref() later
- * no matter whether the error is returned from this function or not.
+ * when this function returns 0.
  *
  * Return: Zero if successful, or a negative error code.
  */
@@ -1152,7 +1152,11 @@ int snd_power_ref_and_wait(struct snd_card *card)
 		       card->shutdown ||
 		       snd_power_get_state(card) == SNDRV_CTL_POWER_D0,
 		       snd_power_unref(card), snd_power_ref(card));
-	return card->shutdown ? -ENODEV : 0;
+	if (card->shutdown) {
+		snd_power_unref(card);
+		return  -ENODEV;
+	}
+	return 0;
 }
 EXPORT_SYMBOL_GPL(snd_power_ref_and_wait);
 
@@ -1169,7 +1173,8 @@ int snd_power_wait(struct snd_card *card)
 	int ret;
 
 	ret = snd_power_ref_and_wait(card);
-	snd_power_unref(card);
+	if (!ret)
+		snd_power_unref(card);
 	return ret;
 }
 EXPORT_SYMBOL(snd_power_wait);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0776/2077] smb: client: fix conflicting option validation for new mount API
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (774 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0775/2077] ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0777/2077] cifs: remove all cifs files before kill super Greg Kroah-Hartman
                   ` (221 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Henrique Carvalho, Steve French,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Henrique Carvalho <henrique.carvalho@suse.com>

[ Upstream commit 10ce03879f935f756bc8a386b3fa3a1c7264d950 ]

Apply conflicting option validation consistently across all the new
mount API paths, for both mount and remount.

Some checks were only applied during initial mount validation, while
others were handled during option parsing, causing mount and
remount/reconfigure to behave differently.

Move the conflicting option checks into smb3_handle_conflicting_options()
and call it from the common validation paths, including for
multichannel/max_channels handling.

Fixes: 24e0a1eff9e2 ("cifs: switch to new mount api")
Signed-off-by: Henrique Carvalho <henrique.carvalho@suse.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/smb/client/fs_context.c | 102 +++++++++++++++++++------------------
 1 file changed, 53 insertions(+), 49 deletions(-)

diff --git a/fs/smb/client/fs_context.c b/fs/smb/client/fs_context.c
index 2f86158f85d7b6..fd4b13cd654d90 100644
--- a/fs/smb/client/fs_context.c
+++ b/fs/smb/client/fs_context.c
@@ -693,6 +693,41 @@ static int smb3_handle_conflicting_options(struct fs_context *fc)
 {
 	struct smb3_fs_context *ctx = smb3_fc2context(fc);
 
+	if (ctx->rdma && ctx->vals->protocol_id < SMB30_PROT_ID) {
+		cifs_errorf(fc, "SMB Direct requires Version >=3.0\n");
+		return -EOPNOTSUPP;
+	}
+
+	if (ctx->multiuser && !IS_ENABLED(CONFIG_KEYS)) {
+		cifs_errorf(fc, "Multiuser mounts require kernels with CONFIG_KEYS enabled\n");
+		return -EOPNOTSUPP;
+	}
+
+	if (ctx->multiuser && ctx->upcall_target == UPTARGET_MOUNT) {
+		cifs_errorf(fc, "multiuser mount option not supported with upcalltarget set as 'mount'\n");
+		return -EINVAL;
+	}
+
+	if (ctx->uid_specified && !ctx->forceuid_specified) {
+		ctx->override_uid = 1;
+		pr_notice("enabling forceuid mount option implicitly because uid= option is specified\n");
+	}
+
+	if (ctx->gid_specified && !ctx->forcegid_specified) {
+		ctx->override_gid = 1;
+		pr_notice("enabling forcegid mount option implicitly because gid= option is specified\n");
+	}
+
+	if (ctx->override_uid && !ctx->uid_specified) {
+		ctx->override_uid = 0;
+		pr_notice("ignoring forceuid mount option specified with no uid= option\n");
+	}
+
+	if (ctx->override_gid && !ctx->gid_specified) {
+		ctx->override_gid = 0;
+		pr_notice("ignoring forcegid mount option specified with no gid= option\n");
+	}
+
 	if (ctx->multichannel_specified) {
 		if (ctx->multichannel) {
 			if (!ctx->max_channels_specified) {
@@ -711,19 +746,14 @@ static int smb3_handle_conflicting_options(struct fs_context *fc)
 				return -EINVAL;
 			}
 		}
-	} else {
-		if (ctx->max_channels_specified) {
-			if (ctx->max_channels > 1)
-				ctx->multichannel = true;
-			else
-				ctx->multichannel = false;
-		} else {
+	} else if (ctx->max_channels_specified) {
+		if (ctx->max_channels > 1)
+			ctx->multichannel = true;
+		else
 			ctx->multichannel = false;
-			ctx->max_channels = 1;
-		}
 	}
 
-	//resetting default values as remount doesn't initialize fs_context again
+	/* clear parse-time latches so they don't persist across remounts */
 	ctx->multichannel_specified = false;
 	ctx->max_channels_specified = false;
 
@@ -804,28 +834,23 @@ static int smb3_fs_context_parse_monolithic(struct fs_context *fc,
 		if (ret < 0)
 			break;
 	}
-	return ret ?: smb3_handle_conflicting_options(fc);
+	return ret;
 }
 
 /*
- * Validate the preparsed information in the config.
+ * smb3_fs_context_validate - check initial-mount-only constraints:
+ * UNC presence, address resolution, dialect warnings
+ *
+ * @fc: generic mount context
  */
 static int smb3_fs_context_validate(struct fs_context *fc)
 {
 	struct smb3_fs_context *ctx = smb3_fc2context(fc);
+	int rc;
 
-	if (ctx->rdma && ctx->vals->protocol_id < SMB30_PROT_ID) {
-		cifs_errorf(fc, "SMB Direct requires Version >=3.0\n");
-		return -EOPNOTSUPP;
-	}
-
-#ifndef CONFIG_KEYS
-	/* Muliuser mounts require CONFIG_KEYS support */
-	if (ctx->multiuser) {
-		cifs_errorf(fc, "Multiuser mounts require kernels with CONFIG_KEYS enabled\n");
-		return -1;
-	}
-#endif
+	rc = smb3_handle_conflicting_options(fc);
+	if (rc)
+		return rc;
 
 	if (ctx->got_version == false)
 		pr_warn_once("No dialect specified on mount. Default has changed to a more secure dialect, SMB2.1 or later (e.g. SMB3.1.1), from CIFS (SMB1). To use the less secure SMB1 dialect to access old servers which do not support SMB3.1.1 (or even SMB3 or SMB2.1) specify vers=1.0 on mount.\n");
@@ -860,26 +885,6 @@ static int smb3_fs_context_validate(struct fs_context *fc)
 	/* set the port that we got earlier */
 	cifs_set_port((struct sockaddr *)&ctx->dstaddr, ctx->port);
 
-	if (ctx->uid_specified && !ctx->forceuid_specified) {
-		ctx->override_uid = 1;
-		pr_notice("enabling forceuid mount option implicitly because uid= option is specified\n");
-	}
-
-	if (ctx->gid_specified && !ctx->forcegid_specified) {
-		ctx->override_gid = 1;
-		pr_notice("enabling forcegid mount option implicitly because gid= option is specified\n");
-	}
-
-	if (ctx->override_uid && !ctx->uid_specified) {
-		ctx->override_uid = 0;
-		pr_notice("ignoring forceuid mount option specified with no uid= option\n");
-	}
-
-	if (ctx->override_gid && !ctx->gid_specified) {
-		ctx->override_gid = 0;
-		pr_notice("ignoring forcegid mount option specified with no gid= option\n");
-	}
-
 	return 0;
 }
 
@@ -1078,6 +1083,10 @@ static int smb3_reconfigure(struct fs_context *fc)
 	if (rc)
 		return rc;
 
+	rc = smb3_handle_conflicting_options(fc);
+	if (rc)
+		return rc;
+
 	old_ctx = kzalloc_obj(*old_ctx);
 	if (!old_ctx)
 		return -ENOMEM;
@@ -1933,11 +1942,6 @@ static int smb3_fs_context_parse_param(struct fs_context *fc,
 	}
 	/* case Opt_ignore: - is ignored as expected ... */
 
-	if (ctx->multiuser && ctx->upcall_target == UPTARGET_MOUNT) {
-		cifs_errorf(fc, "multiuser mount option not supported with upcalltarget set as 'mount'\n");
-		goto cifs_parse_mount_err;
-	}
-
 	return 0;
 
  cifs_parse_mount_err:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0777/2077] cifs: remove all cifs files before kill super
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (775 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0776/2077] smb: client: fix conflicting option validation for new mount API Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0778/2077] smb/client: always return a value for FS_IOC_GETFLAGS Greg Kroah-Hartman
                   ` (220 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jian Zhang, Steve French,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jian Zhang <zhangjian496@huawei.com>

[ Upstream commit 6d9a4aaaa8b2612b5ef9d581e2f286a458b71ee1 ]

Cifs files may be put into fileinfo_put_wq during umounting cifs.
After umount done, cifsFileInfo_put_final is called, which cause
following BUG:

BUG: kernel NULL pointer dereference, address: 0000000000000000
...
[  134.222152]  list_lru_add+0x64/0x1a0
[  134.222399]  ? cifs_put_tcon+0x171/0x340 [cifs]
[  134.222772]  d_lru_add+0x44/0x60
[  134.222997]  dput+0x1fc/0x210
[  134.223213]  cifsFileInfo_put_final+0x11a/0x140 [cifs]
[  134.223576]  process_one_work+0x17c/0x320
[  134.223843]  worker_thread+0x188/0x280
[  134.224084]  ? __pfx_worker_thread+0x10/0x10
[  134.224366]  kthread+0xcc/0x100
[  134.224576]  ? __pfx_kthread+0x10/0x10
[  134.224827]  ret_from_fork+0x30/0x50
[  134.225063]  ? __pfx_kthread+0x10/0x10
[  134.225328]  ret_from_fork_asm+0x1b/0x30

This can be reproduce by following:
unshare -n bash -c "
mkdir -p ${CIFS_MNT}
ip netns attach root 1
ip link add eth0 type veth peer veth0 netns root
ip link set eth0 up
ip -n root link set veth0 up
ip addr add 192.168.0.2/24 dev eth0
ip -n root addr add 192.168.0.1/24 dev veth0
ip route add default via 192.168.0.1 dev eth0
ip netns exec root sysctl net.ipv4.ip_forward=1
ip netns exec root iptables -t nat -A POSTROUTING -s 192.168.0.2 -o
${DEV} -j MASQUERADE
mount -t cifs ${CIFS_PATH} ${CIFS_MNT} -o
vers=3.0,sec=ntlmssp,credentials=${CIFS_CRED},rsize=65536,wsize=65536,cache=none,echo_interval=1
touch ${CIFS_MNT}/a.txt
ip netns exec root iptables -t nat -D POSTROUTING -s 192.168.0.2 -o
${DEV} -j MASQUERADE
"
umount ${CIFS_MNT}

Fixes: 340cea84f691 ("cifs: open files should not hold ref on superblock")

Signed-off-by: Jian Zhang <zhangjian496@huawei.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/smb/client/connect.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/fs/smb/client/connect.c b/fs/smb/client/connect.c
index dcde25da468dfb..cbeb5637eeb925 100644
--- a/fs/smb/client/connect.c
+++ b/fs/smb/client/connect.c
@@ -3996,6 +3996,9 @@ cifs_umount(struct cifs_sb_info *cifs_sb)
 	}
 	spin_unlock(&cifs_sb->tlink_tree_lock);
 
+	flush_workqueue(serverclose_wq);
+	flush_workqueue(fileinfo_put_wq);
+
 	kfree(cifs_sb->prepath);
 	call_rcu(&cifs_sb->rcu, delayed_free);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0778/2077] smb/client: always return a value for FS_IOC_GETFLAGS
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (776 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0777/2077] cifs: remove all cifs files before kill super Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0779/2077] btrfs: Drop WQ_PERCPU from ordered_flags in btrfs_init_workqueues() Greg Kroah-Hartman
                   ` (219 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Huiwen He, ChenXiaoSong,
	Steve French, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Huiwen He <hehuiwen@kylinos.cn>

[ Upstream commit 7acbaa16b99edaf8ef432229d4b7a6f3b666767d ]

Currently, repeated lsattr calls on a regular CIFS file without the
compressed attribute may show random flags:

	$ touch test.bin
	$ lsattr test.bin
	s-S-ia-A-EjI---------m test.bin
	$ lsattr test.bin
	------d-cEjI---------m test.bin

The lsattr reproducer depends on the previous contents of its userspace
buffer, so it may not reproduce on every setup. A deterministic
reproducer is to initialize the ioctl argument before FS_IOC_GETFLAGS
on a file without the compressed attribute:

        int flags = 0x7fffffff;
        ioctl(fd, FS_IOC_GETFLAGS, &flags);

On an affected kernel, flags remains 0x7fffffff. With the fix, it is
set to 0.

This happens because when the cached inode does not have the compressed
bit set, the CIFS fallback path in FS_IOC_GETFLAGS returns success
without calling put_user() to write the zero flags value into the user
buffer. As a result, the caller observes stale contents from its own
buffer.

Fix this by always writing the visible flags value back to the user
buffer before returning success, even when the value is zero.

Fixes: 64a5cfa6db94 ("Allow setting per-file compression via SMB2/3")
Signed-off-by: Huiwen He <hehuiwen@kylinos.cn>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/smb/client/ioctl.c | 12 +++++-------
 1 file changed, 5 insertions(+), 7 deletions(-)

diff --git a/fs/smb/client/ioctl.c b/fs/smb/client/ioctl.c
index 17408bb8ab65bf..746d70091f3d1d 100644
--- a/fs/smb/client/ioctl.c
+++ b/fs/smb/client/ioctl.c
@@ -392,13 +392,11 @@ long cifs_ioctl(struct file *filep, unsigned int command, unsigned long arg)
 			}
 #endif /* CONFIG_CIFS_ALLOW_INSECURE_LEGACY */
 #endif /* CONFIG_CIFS_POSIX */
-			rc = 0;
-			if (CIFS_I(inode)->cifsAttrs & ATTR_COMPRESSED) {
-				/* add in the compressed bit */
-				ExtAttrBits = FS_COMPR_FL;
-				rc = put_user(ExtAttrBits & FS_FL_USER_VISIBLE,
-					      (int __user *)arg);
-			}
+			if (CIFS_I(inode)->cifsAttrs & FILE_ATTRIBUTE_COMPRESSED)
+				ExtAttrBits |= FS_COMPR_FL;
+
+			rc = put_user(ExtAttrBits & FS_FL_USER_VISIBLE,
+				      (int __user *)arg);
 			break;
 		case FS_IOC_SETFLAGS:
 			if (pSMBFile == NULL)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0779/2077] btrfs: Drop WQ_PERCPU from ordered_flags in btrfs_init_workqueues()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (777 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0778/2077] smb/client: always return a value for FS_IOC_GETFLAGS Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0780/2077] bpf: Guard __get_user acesss with access_ok for uprobe_multi data Greg Kroah-Hartman
                   ` (218 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nathan Chancellor, Breno Leitao,
	Marco Crivellari, David Sterba, Tejun Heo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nathan Chancellor <nathan@kernel.org>

[ Upstream commit c7703f05d85f71153f5e241184397bc34da305e3 ]

After commit 21c05ca88a54 ("workqueue: Add warnings and ensure one among
WQ_PERCPU or WQ_UNBOUND is present"), there is a warning from the
btrfs-qgroup-rescan workqueue at run time:

  workqueue: btrfs-qgroup-rescan uses both WQ_PERCPU and WQ_UNBOUND. Dropped WQ_PERCPU, keeping WQ_UNBOUND.

WQ_PERCPU is included in ordered_flags after commit 69635d7f4b34 ("fs:
WQ_PERCPU added to alloc_workqueue users") and WQ_UNBOUND is set in
alloc_ordered_workqueue(), which btrfs_alloc_ordered_workqueue() calls.

Drop WQ_PERCPU from ordered_flags, as alloc_ordered_workqueue() notes
that only WQ_FREEZABLE and WQ_MEM_RECLAIM are meaningful.

Fixes: 69635d7f4b34 ("fs: WQ_PERCPU added to alloc_workqueue users")
Fixes: 21c05ca88a54 ("workqueue: Add warnings and ensure one among WQ_PERCPU or WQ_UNBOUND is present")
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Reviewed-by: Breno Leitao <leitao@debian.org>
Acked-by: Marco Crivellari <marco.crivellari@suse.com>
Acked-by: David Sterba <dsterba@suse.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/btrfs/disk-io.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/btrfs/disk-io.c b/fs/btrfs/disk-io.c
index c0a30bb213d7a0..ab92b35fa3cc10 100644
--- a/fs/btrfs/disk-io.c
+++ b/fs/btrfs/disk-io.c
@@ -1928,7 +1928,7 @@ static int btrfs_init_workqueues(struct btrfs_fs_info *fs_info)
 {
 	u32 max_active = fs_info->thread_pool_size;
 	unsigned int flags = WQ_MEM_RECLAIM | WQ_FREEZABLE | WQ_UNBOUND;
-	unsigned int ordered_flags = WQ_MEM_RECLAIM | WQ_FREEZABLE | WQ_PERCPU;
+	unsigned int ordered_flags = WQ_MEM_RECLAIM | WQ_FREEZABLE;
 
 	fs_info->workers =
 		btrfs_alloc_workqueue(fs_info, "worker", flags, max_active, 16);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0780/2077] bpf: Guard __get_user acesss with access_ok for uprobe_multi data
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (778 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0779/2077] btrfs: Drop WQ_PERCPU from ordered_flags in btrfs_init_workqueues() Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0781/2077] selftests/bpf: Fix typo in verify_umulti_link_info Greg Kroah-Hartman
                   ` (217 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jiri Olsa, Alexei Starovoitov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiri Olsa <jolsa@kernel.org>

[ Upstream commit 4d87a251d45b4a95eb4c0abcfab809c9f231258a ]

As reported by sashiko [1] we need to use access_ok to check the user
space data bounds before we use __get-user to get it.

[1] https://lore.kernel.org/bpf/20260610145235.CB1441F00893@smtp.kernel.org/
Fixes: 0b779b61f651 ("bpf: Add cookies support for uprobe_multi link")
Fixes: 89ae89f53d20 ("bpf: Add multi uprobe link")
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Link: https://lore.kernel.org/r/20260611114230.950379-2-jolsa@kernel.org
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/trace/bpf_trace.c | 11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/kernel/trace/bpf_trace.c b/kernel/trace/bpf_trace.c
index a02bd258677ee1..a4de502950c4b9 100644
--- a/kernel/trace/bpf_trace.c
+++ b/kernel/trace/bpf_trace.c
@@ -3180,6 +3180,7 @@ int bpf_uprobe_multi_link_attach(const union bpf_attr *attr, struct bpf_prog *pr
 	unsigned long __user *uoffsets;
 	u64 __user *ucookies;
 	void __user *upath;
+	unsigned long size;
 	u32 flags, cnt, i;
 	struct path path;
 	char *name;
@@ -3217,6 +3218,16 @@ int bpf_uprobe_multi_link_attach(const union bpf_attr *attr, struct bpf_prog *pr
 	uref_ctr_offsets = u64_to_user_ptr(attr->link_create.uprobe_multi.ref_ctr_offsets);
 	ucookies = u64_to_user_ptr(attr->link_create.uprobe_multi.cookies);
 
+	/*
+	 * All uoffsets/uref_ctr_offsets/ucookies arrays have the same value
+	 * size, we need to check their address range is safe for __get_user
+	 * calls.
+	 */
+	size = sizeof(*uoffsets) * cnt;
+	if (!access_ok(uoffsets, size) || !access_ok(uref_ctr_offsets, size) ||
+	    !access_ok(ucookies, size))
+		return -EFAULT;
+
 	name = strndup_user(upath, PATH_MAX);
 	if (IS_ERR(name)) {
 		err = PTR_ERR(name);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0781/2077] selftests/bpf: Fix typo in verify_umulti_link_info
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (779 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0780/2077] bpf: Guard __get_user acesss with access_ok for uprobe_multi data Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0782/2077] selftests/bpf: Initialize operation name before use Greg Kroah-Hartman
                   ` (216 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jiri Olsa, Alexei Starovoitov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiri Olsa <jolsa@kernel.org>

[ Upstream commit df29003c55115737a8fb4f8a60c6c2bba4c4a484 ]

We verify info.uprobe_multi.flags against wrong kprobe-multi flag
(BPF_F_KPROBE_MULTI_RETURN). It's the same value as the correct
flag (BPF_F_UPROBE_MULTI_RETURN), so there's not functional change.

Fixes: 147c69307bcf ("selftests/bpf: Add link_info test for uprobe_multi link")
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Link: https://lore.kernel.org/r/20260611114230.950379-8-jolsa@kernel.org
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/bpf/prog_tests/fill_link_info.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/selftests/bpf/prog_tests/fill_link_info.c b/tools/testing/selftests/bpf/prog_tests/fill_link_info.c
index e401146207510a..f589eefbf9fbd5 100644
--- a/tools/testing/selftests/bpf/prog_tests/fill_link_info.c
+++ b/tools/testing/selftests/bpf/prog_tests/fill_link_info.c
@@ -469,7 +469,7 @@ verify_umulti_link_info(int fd, bool retprobe, __u64 *offsets,
 
 		ASSERT_EQ(info.uprobe_multi.pid, getpid(), "info.uprobe_multi.pid");
 		ASSERT_EQ(info.uprobe_multi.count, 3, "info.uprobe_multi.count");
-		ASSERT_EQ(info.uprobe_multi.flags & BPF_F_KPROBE_MULTI_RETURN,
+		ASSERT_EQ(info.uprobe_multi.flags & BPF_F_UPROBE_MULTI_RETURN,
 			  retprobe, "info.uprobe_multi.flags.retprobe");
 		ASSERT_EQ(info.uprobe_multi.path_size, strlen(path) + 1, "info.uprobe_multi.path_size");
 		ASSERT_STREQ(path_buf, path, "info.uprobe_multi.path");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0782/2077] selftests/bpf: Initialize operation name before use
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (780 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0781/2077] selftests/bpf: Fix typo in verify_umulti_link_info Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0783/2077] bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket Greg Kroah-Hartman
                   ` (215 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Leo Yan, Ihor Solodrai,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leo Yan <leo.yan@arm.com>

[ Upstream commit 55ffbe8a15b1254f44d56952fb425a10e3f15c31 ]

ASAN reports stack-buffer-overflow due to the uninitialized op_name.

Initialize it to fix the issue.

Fixes: 054b6c7866c7 ("selftests/bpf: Add verifier log tests for BPF_BTF_LOAD command")
Signed-off-by: Leo Yan <leo.yan@arm.com>
Acked-by: Ihor Solodrai <ihor.solodrai@linux.dev>
Link: https://lore.kernel.org/r/20260602-tools_build_fix_zero_init_bpf_only-v2-6-c76e5250ea1c@arm.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/testing/selftests/bpf/prog_tests/verifier_log.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/tools/testing/selftests/bpf/prog_tests/verifier_log.c b/tools/testing/selftests/bpf/prog_tests/verifier_log.c
index c01c0114af1b74..4542bb586d723b 100644
--- a/tools/testing/selftests/bpf/prog_tests/verifier_log.c
+++ b/tools/testing/selftests/bpf/prog_tests/verifier_log.c
@@ -317,6 +317,7 @@ static void verif_btf_log_subtest(bool bad_btf)
 	res = load_btf(&opts, true);
 	ASSERT_EQ(res, -ENOSPC, "half_log_fd");
 	ASSERT_EQ(strlen(logs.buf), 24, "log_fixed_25");
+	strscpy(op_name, "log_fixed", sizeof(op_name));
 	ASSERT_STRNEQ(logs.buf, logs.reference, 24, op_name);
 
 	/* validate rolling verifier log logic: try all variations of log buf
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0783/2077] bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (781 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0782/2077] selftests/bpf: Initialize operation name before use Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0784/2077] udf: fix nls leak on udf_fill_super() failure Greg Kroah-Hartman
                   ` (214 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Feng Zhou, Leon Hwang,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leon Hwang <leon.hwang@linux.dev>

[ Upstream commit ca0f587c029afa66227f7b932450b1c417403394 ]

When TCP over IPv4 via INET6 API, bpf_get/setsockopt with ipv4 will
fail, because sk->sk_family is AF_INET6. With ipv6 will success, not
take effect, because inet_csk(sk)->icsk_af_ops is ipv6_mapped and
use ip_queue_xmit, inet_sk(sk)->tos.

To relax this restriction, allow getting/setting tos for those possible
ipv4-mapped ipv6 sockets.

Fixes: ee7f1e1302f5 ("bpf: Change bpf_setsockopt(SOL_IP) to reuse do_ip_setsockopt()")
Signed-off-by: Feng Zhou <zhoufeng.zf@bytedance.com>
Signed-off-by: Leon Hwang <leon.hwang@linux.dev>
Link: https://lore.kernel.org/r/20260613162443.60515-2-leon.hwang@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/core/filter.c | 15 ++++++++++++++-
 1 file changed, 14 insertions(+), 1 deletion(-)

diff --git a/net/core/filter.c b/net/core/filter.c
index 40037413dd4ec7..83fcc64afa206b 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -5571,11 +5571,24 @@ static int sol_tcp_sockopt(struct sock *sk, int optname,
 				 KERNEL_SOCKPTR(optval), *optlen);
 }
 
+static bool sk_allows_sol_ip_sockopt(struct sock *sk)
+{
+	switch (sk->sk_family) {
+	case AF_INET:
+		return true;
+	case AF_INET6:
+		/* Allow getting/setting sockopt for possible ipv4-mapped ipv6 socket. */
+		return sk->sk_type != SOCK_RAW && !ipv6_only_sock(sk);
+	default:
+		return false;
+	}
+}
+
 static int sol_ip_sockopt(struct sock *sk, int optname,
 			  char *optval, int *optlen,
 			  bool getopt)
 {
-	if (sk->sk_family != AF_INET)
+	if (!sk_allows_sol_ip_sockopt(sk))
 		return -EINVAL;
 
 	switch (optname) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0784/2077] udf: fix nls leak on udf_fill_super() failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (782 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0783/2077] bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0785/2077] bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() Greg Kroah-Hartman
                   ` (213 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jan Kara, Al Viro, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Al Viro <viro@zeniv.linux.org.uk>

[ Upstream commit 462bdd08fbdf41db223c6117d907c8fd68d666ea ]

On all failure exits that go to error_out there we have already moved the
nls reference from uopt->nls_map to sbi->s_nls_map, leaving NULL behind.

Fixes: c4e89cc674ac ("udf: convert to new mount API")
Acked-by: Jan Kara <jack@suse.cz>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/udf/super.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/udf/super.c b/fs/udf/super.c
index 1b5282790de6f0..f5328c0084dca9 100644
--- a/fs/udf/super.c
+++ b/fs/udf/super.c
@@ -2330,7 +2330,7 @@ static int udf_fill_super(struct super_block *sb, struct fs_context *fc)
 
 error_out:
 	iput(sbi->s_vat_inode);
-	unload_nls(uopt->nls_map);
+	unload_nls(sbi->s_nls_map);
 	if (lvid_open)
 		udf_close_lvid(sb);
 	brelse(sbi->s_lvid_bh);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0785/2077] bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (783 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0784/2077] udf: fix nls leak on udf_fill_super() failure Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0786/2077] sockmap: Fix use-after-free in udp_bpf_recvmsg() Greg Kroah-Hartman
                   ` (212 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Xiang Mei, Xinyu Ma, Jiayuan Chen,
	Emil Tsalapatis, Kuniyuki Iwashima, Weiming Shi,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Weiming Shi <bestswngs@gmail.com>

[ Upstream commit 0c0a8ed85349dae298712d79cb276acfeb794d82 ]

When the scatterlist ring is full or nearly full, bpf_msg_push_data()
enters a copy fallback path and computes copy + len for the page
allocation size. Since len comes from BPF with arg3_type = ARG_ANYTHING
and both are u32, a crafted len can wrap the sum to a small value,
causing an undersized allocation followed by an out-of-bounds memcpy.

 BUG: unable to handle page fault for address: ffffed104089a402
 Oops: Oops: 0000 [#1] SMP KASAN NOPTI
 Call Trace:
  __asan_memcpy (mm/kasan/shadow.c:105)
  bpf_msg_push_data (net/core/filter.c:2852 net/core/filter.c:2788)
  bpf_prog_9ed8b5711920a7d7+0x2e/0x36
  sk_psock_msg_verdict (net/core/skmsg.c:934)
  tcp_bpf_sendmsg (net/ipv4/tcp_bpf.c:421 net/ipv4/tcp_bpf.c:584)
  __sys_sendto (net/socket.c:2206)
  do_syscall_64 (arch/x86/entry/syscall_64.c:94)
  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)

Add an overflow check before the allocation.

Link: https://lore.kernel.org/all/20260424155913.A19FDC19425@smtp.kernel.org
Fixes: 6fff607e2f14 ("bpf: sk_msg program helper bpf_msg_push_data")
Tested-by: Xiang Mei <xmei5@asu.edu>
Tested-by: Xinyu Ma <mmmxny@gmail.com>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://lore.kernel.org/r/20260615021959.140010-2-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/core/filter.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/net/core/filter.c b/net/core/filter.c
index 83fcc64afa206b..f159a21e92588d 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -2834,6 +2834,9 @@ BPF_CALL_4(bpf_msg_push_data, struct sk_msg *, msg, u32, start,
 	if (!space || (space == 1 && start != offset))
 		copy = msg->sg.data[i].length;
 
+	if (unlikely(copy + len < copy))
+		return -EINVAL;
+
 	page = alloc_pages(__GFP_NOWARN | GFP_ATOMIC | __GFP_COMP,
 			   get_order(copy + len));
 	if (unlikely(!page))
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0786/2077] sockmap: Fix use-after-free in udp_bpf_recvmsg()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (784 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0785/2077] bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0787/2077] bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check Greg Kroah-Hartman
                   ` (211 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+9307c991a6d07ce6e6d8,
	Jiayuan Chen, Jakub Sitnicki, Emil Tsalapatis, Kuniyuki Iwashima,
	Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kuniyuki Iwashima <kuniyu@google.com>

[ Upstream commit c010995b29c8939c6aa69e3cb26f8dbee163d156 ]

syzbot reported use-after-free of struct sk_msg in sk_msg_recvmsg(). [0]

sk_msg_recvmsg() peeks sk_msg from psock->ingress_msg under a lock,
but its processing is lockless.

Thus, sk_msg_recvmsg() must be serialised by callers, otherwise
multiple threads could touch the same sk_msg.

For example, TCP uses lock_sock(), and AF_UNIX uses unix_sk(sk)->iolock.

Initially, udp_bpf_recvmsg() had used lock_sock(), but the cited
commit removed it.

Let's serialise sk_msg_recvmsg() with lock_sock() in udp_bpf_recvmsg().

Note that holding spin_lock_bh(&sk->sk_receive_queue.lock) is not
an option due to copy_page_to_iter() in sk_msg_recvmsg().

[0]:
BUG: KASAN: slab-use-after-free in sk_msg_recvmsg+0xb54/0xc30 net/core/skmsg.c:428
Read of size 4 at addr ffff88814cdcf000 by task syz.0.24/6020

CPU: 1 UID: 0 PID: 6020 Comm: syz.0.24 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 01/13/2026
Call Trace:
 <TASK>
 dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
 print_address_description mm/kasan/report.c:378 [inline]
 print_report+0xba/0x230 mm/kasan/report.c:482
 kasan_report+0x117/0x150 mm/kasan/report.c:595
 sk_msg_recvmsg+0xb54/0xc30 net/core/skmsg.c:428
 udp_bpf_recvmsg+0x4bd/0xe00 net/ipv4/udp_bpf.c:84
 inet_recvmsg+0x260/0x270 net/ipv4/af_inet.c:891
 sock_recvmsg_nosec net/socket.c:1078 [inline]
 sock_recvmsg+0x1a8/0x270 net/socket.c:1100
 ____sys_recvmsg+0x1e6/0x4a0 net/socket.c:2812
 ___sys_recvmsg+0x215/0x590 net/socket.c:2854
 do_recvmmsg+0x334/0x800 net/socket.c:2949
 __sys_recvmmsg net/socket.c:3023 [inline]
 __do_sys_recvmmsg net/socket.c:3046 [inline]
 __se_sys_recvmmsg net/socket.c:3039 [inline]
 __x64_sys_recvmmsg+0x198/0x250 net/socket.c:3039
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xe2/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fb319f9aeb9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fb31ad97028 EFLAGS: 00000246 ORIG_RAX: 000000000000012b
RAX: ffffffffffffffda RBX: 00007fb31a216090 RCX: 00007fb319f9aeb9
RDX: 0000000000000001 RSI: 0000200000000400 RDI: 0000000000000004
RBP: 00007fb31a008c1f R08: 0000000000000000 R09: 0000000000000000
R10: 0000000040000021 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fb31a216128 R14: 00007fb31a216090 R15: 00007ffe21dd0a98
 </TASK>

Allocated by task 6019:
 kasan_save_stack mm/kasan/common.c:57 [inline]
 kasan_save_track+0x3e/0x80 mm/kasan/common.c:78
 poison_kmalloc_redzone mm/kasan/common.c:398 [inline]
 __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:415
 kasan_kmalloc include/linux/kasan.h:263 [inline]
 __kmalloc_cache_noprof+0x3d1/0x6e0 mm/slub.c:5780
 kmalloc_noprof include/linux/slab.h:957 [inline]
 kzalloc_noprof include/linux/slab.h:1094 [inline]
 alloc_sk_msg net/core/skmsg.c:510 [inline]
 sk_psock_skb_ingress_self+0x60/0x350 net/core/skmsg.c:612
 sk_psock_verdict_apply net/core/skmsg.c:1038 [inline]
 sk_psock_verdict_recv+0x7d9/0x8d0 net/core/skmsg.c:1236
 udp_read_skb+0x73e/0x7e0 net/ipv4/udp.c:2045
 sk_psock_verdict_data_ready+0x12d/0x550 net/core/skmsg.c:1257
 __udp_enqueue_schedule_skb+0xc54/0x10b0 net/ipv4/udp.c:1789
 __udp_queue_rcv_skb net/ipv4/udp.c:2346 [inline]
 udp_queue_rcv_one_skb+0xac5/0x19c0 net/ipv4/udp.c:2475
 __udp4_lib_mcast_deliver+0xc06/0xcf0 net/ipv4/udp.c:2585
 __udp4_lib_rcv+0x10f6/0x2620 net/ipv4/udp.c:2724
 ip_protocol_deliver_rcu+0x282/0x440 net/ipv4/ip_input.c:207
 ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:241
 NF_HOOK+0x336/0x3c0 include/linux/netfilter.h:318
 dst_input include/net/dst.h:474 [inline]
 ip_sublist_rcv_finish+0x221/0x2a0 net/ipv4/ip_input.c:584
 ip_list_rcv_finish net/ipv4/ip_input.c:628 [inline]
 ip_sublist_rcv+0x5c6/0xa70 net/ipv4/ip_input.c:644
 ip_list_rcv+0x3f1/0x450 net/ipv4/ip_input.c:678
 __netif_receive_skb_list_ptype net/core/dev.c:6195 [inline]
 __netif_receive_skb_list_core+0x7e5/0x810 net/core/dev.c:6242
 __netif_receive_skb_list net/core/dev.c:6294 [inline]
 netif_receive_skb_list_internal+0x995/0xcf0 net/core/dev.c:6385
 netif_receive_skb_list+0x54/0x410 net/core/dev.c:6437
 xdp_recv_frames net/bpf/test_run.c:269 [inline]
 xdp_test_run_batch net/bpf/test_run.c:350 [inline]
 bpf_test_run_xdp_live+0x1946/0x1cf0 net/bpf/test_run.c:379
 bpf_prog_test_run_xdp+0x81c/0x1160 net/bpf/test_run.c:1396
 bpf_prog_test_run+0x2c7/0x340 kernel/bpf/syscall.c:4703
 __sys_bpf+0x5cb/0x920 kernel/bpf/syscall.c:6182
 __do_sys_bpf kernel/bpf/syscall.c:6274 [inline]
 __se_sys_bpf kernel/bpf/syscall.c:6272 [inline]
 __x64_sys_bpf+0x7c/0x90 kernel/bpf/syscall.c:6272
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xe2/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

Freed by task 6021:
 kasan_save_stack mm/kasan/common.c:57 [inline]
 kasan_save_track+0x3e/0x80 mm/kasan/common.c:78
 kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:584
 poison_slab_object mm/kasan/common.c:253 [inline]
 __kasan_slab_free+0x5c/0x80 mm/kasan/common.c:285
 kasan_slab_free include/linux/kasan.h:235 [inline]
 slab_free_hook mm/slub.c:2540 [inline]
 slab_free mm/slub.c:6674 [inline]
 kfree+0x1be/0x650 mm/slub.c:6882
 kfree_sk_msg include/linux/skmsg.h:385 [inline]
 sk_msg_recvmsg+0xaa8/0xc30 net/core/skmsg.c:483
 udp_bpf_recvmsg+0x4bd/0xe00 net/ipv4/udp_bpf.c:84
 inet_recvmsg+0x260/0x270 net/ipv4/af_inet.c:891
 sock_recvmsg_nosec net/socket.c:1078 [inline]
 sock_recvmsg+0x1a8/0x270 net/socket.c:1100
 ____sys_recvmsg+0x1e6/0x4a0 net/socket.c:2812
 ___sys_recvmsg+0x215/0x590 net/socket.c:2854
 do_recvmmsg+0x334/0x800 net/socket.c:2949
 __sys_recvmmsg net/socket.c:3023 [inline]
 __do_sys_recvmmsg net/socket.c:3046 [inline]
 __se_sys_recvmmsg net/socket.c:3039 [inline]
 __x64_sys_recvmmsg+0x198/0x250 net/socket.c:3039
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xe2/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

Fixes: 9f2470fbc4cb ("skmsg: Improve udp_bpf_recvmsg() accuracy")
Reported-by: syzbot+9307c991a6d07ce6e6d8@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/69922ac9.a70a0220.2c38d7.00e0.GAE@google.com/
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Jakub Sitnicki <jakub@cloudflare.com>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://lore.kernel.org/r/20260615021959.140010-5-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/ipv4/udp_bpf.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/net/ipv4/udp_bpf.c b/net/ipv4/udp_bpf.c
index 9f33b07b148131..ad57c4c9eaab6f 100644
--- a/net/ipv4/udp_bpf.c
+++ b/net/ipv4/udp_bpf.c
@@ -50,7 +50,9 @@ static int udp_msg_wait_data(struct sock *sk, struct sk_psock *psock,
 	sk_set_bit(SOCKWQ_ASYNC_WAITDATA, sk);
 	ret = udp_msg_has_data(sk, psock);
 	if (!ret) {
+		release_sock(sk);
 		wait_woken(&wait, TASK_INTERRUPTIBLE, timeo);
+		lock_sock(sk);
 		ret = udp_msg_has_data(sk, psock);
 	}
 	sk_clear_bit(SOCKWQ_ASYNC_WAITDATA, sk);
@@ -79,6 +81,7 @@ static int udp_bpf_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
 		goto out;
 	}
 
+	lock_sock(sk);
 msg_bytes_ready:
 	copied = sk_msg_recvmsg(sk, psock, msg, len, flags);
 	if (!copied) {
@@ -90,11 +93,17 @@ static int udp_bpf_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
 		if (data) {
 			if (psock_has_data(psock))
 				goto msg_bytes_ready;
+
+			release_sock(sk);
+
 			ret = sk_udp_recvmsg(sk, msg, len, flags);
 			goto out;
 		}
 		copied = -EAGAIN;
 	}
+
+	release_sock(sk);
+
 	ret = copied;
 out:
 	sk_psock_put(sk, psock);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0787/2077] bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (785 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0786/2077] sockmap: Fix use-after-free in udp_bpf_recvmsg() Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0788/2077] MIPS: mm: Fix out-of-bounds write in maar_res_walk() Greg Kroah-Hartman
                   ` (210 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jiayuan Chen, Emil Tsalapatis,
	Kuniyuki Iwashima, Sechang Lim, Alexei Starovoitov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sechang Lim <rhkrqnwk98@gmail.com>

[ Upstream commit a48802fb2cd2d1e23651989f8ff4d15e9d5dad54 ]

start and len are u32, so

	u64 last = start + len;

evaluates start + len in 32-bit and wraps before storing it in last.
The bounds check

	if (start >= offset + l || last > msg->sg.size)
		return -EINVAL;

can then be passed with an out-of-range start/len, after which the pop
loop runs off the end of the scatterlist and sk_msg_shift_left() calls
put_page() on the empty msg->sg.end slot:

  Oops: general protection fault, probably for non-canonical address
  0xdffffc0000000001: 0000 [#1] SMP KASAN PTI
  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
  RIP: 0010:sk_msg_shift_left net/core/filter.c:2957 [inline]
  RIP: 0010:____bpf_msg_pop_data net/core/filter.c:3103 [inline]
  RIP: 0010:bpf_msg_pop_data+0x753/0x1a10 net/core/filter.c:2984
  Call Trace:
   <TASK>
   bpf_prog_4cc92c278f4d5d56+0x1b1/0x1e8
   bpf_prog_run_pin_on_cpu+0x107/0x320 include/linux/filter.h:746
   sk_psock_msg_verdict+0x357/0x7f0 net/core/skmsg.c:934
   tcp_bpf_send_verdict net/ipv4/tcp_bpf.c:420 [inline]
   tcp_bpf_sendmsg+0x766/0x1ae0 net/ipv4/tcp_bpf.c:583
   __sock_sendmsg+0x153/0x1c0 net/socket.c:802
   __sys_sendto+0x326/0x430 net/socket.c:2265
   __x64_sys_sendto+0xe3/0x100 net/socket.c:2268
   do_syscall_64+0x14c/0x480
   entry_SYSCALL_64_after_hwframe+0x77/0x7f
   </TASK>

Widen the addition with a (u64) cast so the bound is evaluated in
64-bit and a len near U32_MAX no longer wraps below msg->sg.size.

While here, change pop from int to u32. It counts bytes against the
unsigned scatterlist lengths and can never be negative, so the signed
type only invites sign-confusion in the pop loop.

Fixes: 7246d8ed4dcc ("bpf: helper to pop data from messages")
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Signed-off-by: Sechang Lim <rhkrqnwk98@gmail.com>
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://lore.kernel.org/r/20260615021959.140010-6-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/core/filter.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/net/core/filter.c b/net/core/filter.c
index f159a21e92588d..c140e2ed5d291f 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -3000,8 +3000,8 @@ BPF_CALL_4(bpf_msg_pop_data, struct sk_msg *, msg, u32, start,
 	   u32, len, u64, flags)
 {
 	u32 i = 0, l = 0, space, offset = 0;
-	u64 last = start + len;
-	int pop;
+	u64 last = (u64)start + len;
+	u32 pop;
 
 	if (unlikely(flags))
 		return -EINVAL;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0788/2077] MIPS: mm: Fix out-of-bounds write in maar_res_walk()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (786 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0787/2077] bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0789/2077] powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del Greg Kroah-Hartman
                   ` (209 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yadan Fan, Thomas Bogendoerfer,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yadan Fan <ydfan@suse.com>

[ Upstream commit 1b001b16bc88f3f7817e228acfd91ee01bdcfcce ]

maar_res_walk() uses wi->num_cfg as the index into the fixed-size
wi->cfg array, but checks whether the array is full only after it has
filled the selected entry. If walk_system_ram_range() reports more than
16 memory ranges, the overflow call writes one struct maar_config past
the end of the array before WARN_ON() prevents num_cfg from advancing.

Move the full-array check before taking the array slot and return non-zero
when the scratch array is full, so walk_system_ram_range() terminates the
walk instead of invoking the callback for further ranges.

Fixes: a5718fe8f70f ("MIPS: mm: Drop boot_mem_map")

Signed-off-by: Yadan Fan <ydfan@suse.com>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/mips/mm/init.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/arch/mips/mm/init.c b/arch/mips/mm/init.c
index 55b25e85122a32..1c07ca84ee2141 100644
--- a/arch/mips/mm/init.c
+++ b/arch/mips/mm/init.c
@@ -272,9 +272,15 @@ static int maar_res_walk(unsigned long start_pfn, unsigned long nr_pages,
 			 void *data)
 {
 	struct maar_walk_info *wi = data;
-	struct maar_config *cfg = &wi->cfg[wi->num_cfg];
+	struct maar_config *cfg;
 	unsigned int maar_align;
 
+	/* Ensure we don't overflow the cfg array */
+	if (WARN_ON(wi->num_cfg >= ARRAY_SIZE(wi->cfg)))
+		return -1;
+
+	cfg = &wi->cfg[wi->num_cfg];
+
 	/* MAAR registers hold physical addresses right shifted by 4 bits */
 	maar_align = BIT(MIPS_MAAR_ADDR_SHIFT + 4);
 
@@ -283,9 +289,7 @@ static int maar_res_walk(unsigned long start_pfn, unsigned long nr_pages,
 	cfg->upper = ALIGN_DOWN(PFN_PHYS(start_pfn + nr_pages), maar_align) - 1;
 	cfg->attrs = MIPS_MAAR_S;
 
-	/* Ensure we don't overflow the cfg array */
-	if (!WARN_ON(wi->num_cfg >= ARRAY_SIZE(wi->cfg)))
-		wi->num_cfg++;
+	wi->num_cfg++;
 
 	return 0;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0789/2077] powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (787 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0788/2077] MIPS: mm: Fix out-of-bounds write in maar_res_walk() Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0790/2077] powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down Greg Kroah-Hartman
                   ` (208 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shrikanth Hegde, Aboorva Devarajan,
	Madhavan Srinivasan, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aboorva Devarajan <aboorvad@linux.ibm.com>

[ Upstream commit 81e3a86030462824a67d697739cf3f387f4ba350 ]

fsl_emb_pmu_del() unconditionally calls put_cpu_var(cpu_hw_events) at
the 'out:' label, but only calls the matching get_cpu_var() after the
'i < 0' early-return check. When event->hw.idx is negative the
function jumps to 'out:' without having taken get_cpu_var(), and the
trailing put_cpu_var() then issues an unmatched preempt_enable(),
underflowing preempt_count.

On a CONFIG_PREEMPT=y kernel preempt_count would underflow and
eventually present as a 'scheduling while atomic' BUG.

Move put_cpu_var() to pair with get_cpu_var() so the percpu access is
correctly bracketed and the 'out:' label only handles perf_pmu_enable.

Fixes: a11106544f33 ("powerpc/perf: e500 support")
Reviewed-by: Shrikanth Hegde <sshegde@linux.ibm.com>
Signed-off-by: Aboorva Devarajan <aboorvad@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260605082912.305100-2-aboorvad@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/powerpc/perf/core-fsl-emb.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/arch/powerpc/perf/core-fsl-emb.c b/arch/powerpc/perf/core-fsl-emb.c
index 7120ab20cbfecb..02b5dd74c187a0 100644
--- a/arch/powerpc/perf/core-fsl-emb.c
+++ b/arch/powerpc/perf/core-fsl-emb.c
@@ -366,9 +366,10 @@ static void fsl_emb_pmu_del(struct perf_event *event, int flags)
 
 	cpuhw->n_events--;
 
+	put_cpu_var(cpu_hw_events);
+
  out:
 	perf_pmu_enable(event->pmu);
-	put_cpu_var(cpu_hw_events);
 }
 
 static void fsl_emb_pmu_start(struct perf_event *event, int ef_flags)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0790/2077] powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (788 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0789/2077] powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0791/2077] powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus Greg Kroah-Hartman
                   ` (207 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Aboorva Devarajan,
	Madhavan Srinivasan, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aboorva Devarajan <aboorvad@linux.ibm.com>

[ Upstream commit 0ecd26e93e698c8327521910fc6296f5b84a4b92 ]

pnv_kexec_wait_secondaries_down() calls get_cpu() to obtain the current
CPU id but never calls the matching put_cpu(), leaking one
preempt_disable() nesting level on every invocation.

In practice the imbalance does not trigger a visible splat because the
kexec teardown path is a one-way trip: IRQs are already disabled, no
schedule() occurs after the leak, and default_machine_kexec() overwrites
preempt_count with HARDIRQ_OFFSET before jumping into kexec_sequence()
which never returns. However the bookkeeping is still wrong.

The function only needs the current CPU id, and this path runs with
interrupts disabled and the CPU pinned, so the preempt_disable()
side-effect of get_cpu() is unnecessary. Replace it with
raw_smp_processor_id().

Fixes: 298b34d7d578 ("powerpc/powernv: Fix kexec races going back to OPAL")
Signed-off-by: Aboorva Devarajan <aboorvad@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260605082912.305100-3-aboorvad@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/powerpc/platforms/powernv/setup.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/arch/powerpc/platforms/powernv/setup.c b/arch/powerpc/platforms/powernv/setup.c
index 4dbb47ddbdcc4b..06ed5e2aa26584 100644
--- a/arch/powerpc/platforms/powernv/setup.c
+++ b/arch/powerpc/platforms/powernv/setup.c
@@ -396,7 +396,8 @@ static void pnv_kexec_wait_secondaries_down(void)
 {
 	int my_cpu, i, notified = -1;
 
-	my_cpu = get_cpu();
+	/* Called with interrupts disabled, so the CPU is pinned. */
+	my_cpu = raw_smp_processor_id();
 
 	for_each_online_cpu(i) {
 		uint8_t status;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0791/2077] powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (789 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0790/2077] powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0792/2077] KEYS: Use acquire when reading state in keyring search Greg Kroah-Hartman
                   ` (206 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Aboorva Devarajan, Shrikanth Hegde,
	Madhavan Srinivasan, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aboorva Devarajan <aboorvad@linux.ibm.com>

[ Upstream commit 5c86f1c1f972761a04bf22f4c0618d1aa714185b ]

kexec_prepare_cpus_wait() calls get_cpu() internally to obtain the
current CPU id. kexec_prepare_cpus() calls kexec_prepare_cpus_wait()
twice -- once for KEXEC_STATE_IRQS_OFF and once for
KEXEC_STATE_REAL_MODE -- but only issues a single put_cpu() at the end,
leaving preempt_count elevated by one extra nesting level.

In practice the imbalance does not trigger a 'scheduling while atomic'
splat because the kexec path is a one-way trip: IRQs are already
disabled, no schedule() occurs after the leak, and
default_machine_kexec() overwrites preempt_count with HARDIRQ_OFFSET
before jumping into kexec_sequence() which never returns. However the
bookkeeping is still wrong.

kexec_prepare_cpus() calls local_irq_disable()/hard_irq_disable()
before invoking kexec_prepare_cpus_wait(), so the CPU is already pinned
and the get_cpu()/put_cpu() preempt_disable() bracketing is unnecessary.
Only the current CPU id is needed, so replace get_cpu() with
raw_smp_processor_id() and drop the now-unneeded put_cpu().

Fixes: 1fc711f7ffb0 ("powerpc/kexec: Fix race in kexec shutdown")
Signed-off-by: Aboorva Devarajan <aboorvad@linux.ibm.com>
Reviewed-by: Shrikanth Hegde <sshegde@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260605082912.305100-4-aboorvad@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/powerpc/kexec/core_64.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/arch/powerpc/kexec/core_64.c b/arch/powerpc/kexec/core_64.c
index 825ab8a88f18e6..58c13a59b93b58 100644
--- a/arch/powerpc/kexec/core_64.c
+++ b/arch/powerpc/kexec/core_64.c
@@ -169,7 +169,7 @@ static void kexec_prepare_cpus_wait(int wait_state)
 	int my_cpu, i, notified=-1;
 
 	hw_breakpoint_disable();
-	my_cpu = get_cpu();
+	my_cpu = raw_smp_processor_id();
 	/* Make sure each CPU has at least made it to the state we need.
 	 *
 	 * FIXME: There is a (slim) chance of a problem if not all of the CPUs
@@ -267,8 +267,6 @@ static void kexec_prepare_cpus(void)
 	/* after we tell the others to go down */
 	if (ppc_md.kexec_cpu_down)
 		ppc_md.kexec_cpu_down(0, 0);
-
-	put_cpu();
 }
 
 #else /* ! SMP */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0792/2077] KEYS: Use acquire when reading state in keyring search
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (790 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0791/2077] powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0793/2077] tipc: fix UAF in tipc_l2_send_msg() Greg Kroah-Hartman
                   ` (205 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Gui-Dong Han, Jarkko Sakkinen,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Gui-Dong Han <hanguidong02@gmail.com>

[ Upstream commit c1201b37f666f6466ab1fd3a381c2b7a4b7e9fee ]

The negative-key race fix added release/acquire ordering for key use.

Publish payload before state; read state before payload.

keyring_search_iterator() still uses READ_ONCE() before match callbacks.
An asymmetric match callback calls asymmetric_key_ids(), which reads
key->payload.data[asym_key_ids].

Use key_read_state() there to complete that ordering.

Fixes: 363b02dab09b ("KEYS: Fix race between updating and finding a negative key")
Signed-off-by: Gui-Dong Han <hanguidong02@gmail.com>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Link: https://lore.kernel.org/r/20260529033406.20673-1-hanguidong02@gmail.com
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 security/keys/keyring.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/keys/keyring.c b/security/keys/keyring.c
index 5a9887d6b7be3c..7a2ee0ded7c931 100644
--- a/security/keys/keyring.c
+++ b/security/keys/keyring.c
@@ -576,7 +576,7 @@ static int keyring_search_iterator(const void *object, void *iterator_data)
 	struct keyring_search_context *ctx = iterator_data;
 	const struct key *key = keyring_ptr_to_key(object);
 	unsigned long kflags = READ_ONCE(key->flags);
-	short state = READ_ONCE(key->state);
+	short state = key_read_state(key);
 
 	kenter("{%d}", key->serial);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0793/2077] tipc: fix UAF in tipc_l2_send_msg()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (791 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0792/2077] KEYS: Use acquire when reading state in keyring search Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0794/2077] tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) Greg Kroah-Hartman
                   ` (204 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+64ec81389cbad56a8c35,
	Eric Dumazet, Jon Maloy, Tung Nguyen, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit f4c3d89fc986b0da196ddfc6cfe0ea5d5d08bec6 ]

Syzbot reported a slab-use-after-free in ipvlan_hard_header() when
called from tipc_l2_send_msg().

The root cause is that tipc_disable_l2_media() calls synchronize_net()
while b->media_ptr is still valid. This allows concurrent RCU readers
to obtain the device pointer after synchronize_net() has finished.
The pointer is cleared later in bearer_disable(), but without any
subsequent synchronization, allowing the device to be freed while
still in use by readers.

Fix this by clearing b->media_ptr in tipc_disable_l2_media() before
calling synchronize_net().

This is safe to do now because the call order in bearer_disable()
was reversed in 0d051bf93c06 ("tipc: make bearer packet filtering generic")
to call tipc_node_delete_links() (which needs the pointer) before
disable_media().

Fixes: 282b3a056225 ("tipc: send out RESET immediately when link goes down")
https: //lore.kernel.org/netdev/6a2c1007.428ffe26.258b27.015d.GAE@google.com/T/#u
Reported-by: syzbot+64ec81389cbad56a8c35@syzkaller.appspotmail.com
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Jon Maloy <jmaloy@redhat.com>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20260612135949.4010482-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/tipc/bearer.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/tipc/bearer.c b/net/tipc/bearer.c
index a3bd1ef17558a3..05dcd2f9e887a6 100644
--- a/net/tipc/bearer.c
+++ b/net/tipc/bearer.c
@@ -482,6 +482,7 @@ void tipc_disable_l2_media(struct tipc_bearer *b)
 	dev = (struct net_device *)rtnl_dereference(b->media_ptr);
 	dev_remove_pack(&b->pt);
 	RCU_INIT_POINTER(dev->tipc_ptr, NULL);
+	RCU_INIT_POINTER(b->media_ptr, NULL);
 	synchronize_net();
 	dev_put(dev);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0794/2077] tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (792 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0793/2077] tipc: fix UAF in tipc_l2_send_msg() Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0795/2077] net: airoha: Fix always-true condition in PPE1 queue reservation loop Greg Kroah-Hartman
                   ` (203 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+ebdb22d461c904fc3cb2,
	Eric Dumazet, Kuniyuki Iwashima, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 2bf43d0e2e6a27d52a7d624e2d6b9116972e8a22 ]

When MTU is large, ip6_default_advmss() can return IPV6_MAXPLEN (65535).
This is interpreted by TCP as mss_clamp, allowing the MSS to reach 65535.

However, 0xFFFF is also used as a magic value GSO_BY_FRAGS in the kernel.
If a TCP packet with gso_size=0xFFFF is passed to skb_segment(), it will
be mistakenly treated as GSO_BY_FRAGS, leading to a NULL pointer
dereference because local TCP packets do not use frag_list.

Fix this by returning min(IPV6_MAXPLEN, GSO_BY_FRAGS - 1) (65534) from
ip6_default_advmss() when MTU is large.

Also update the stale comment in ip6_default_advmss() which suggested
that IPV6_MAXPLEN is returned to mean "any MSS".

Fixes: 3953c46c3ac7 ("sk_buff: allow segmenting based on frag sizes")
Reported-by: syzbot+ebdb22d461c904fc3cb2@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6a2c3193.8812e0fc.3c3fa4.0001.GAE@google.com/T/#u
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20260612162517.83394-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/ipv6/route.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index 636f0120d7e38d..3c97ba01297aa8 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -3275,11 +3275,11 @@ static unsigned int ip6_default_advmss(const struct dst_entry *dst)
 	/*
 	 * Maximal non-jumbo IPv6 payload is IPV6_MAXPLEN and
 	 * corresponding MSS is IPV6_MAXPLEN - tcp_header_size.
-	 * IPV6_MAXPLEN is also valid and means: "any MSS,
-	 * rely only on pmtu discovery"
+	 * Limit the default MSS to GSO_BY_FRAGS - 1 to avoid
+	 * collision with the GSO_BY_FRAGS magic value (0xFFFF).
 	 */
 	if (mtu > IPV6_MAXPLEN - sizeof(struct tcphdr))
-		mtu = IPV6_MAXPLEN;
+		mtu = min_t(unsigned int, IPV6_MAXPLEN, GSO_BY_FRAGS - 1);
 	return mtu;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0795/2077] net: airoha: Fix always-true condition in PPE1 queue reservation loop
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (793 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0794/2077] tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0796/2077] net: ti: icssg-prueth: Fix AF_XDP fill ring alloc and wakeup condition Greg Kroah-Hartman
                   ` (202 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wayen.Yan, Lorenzo Bianconi,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wayen.Yan <win847@gmail.com>

[ Upstream commit c66f8511a8109fa50767941b26d3623e316fde02 ]

In airoha_fe_pse_ports_init(), the inner condition for PPE1 queue
reservation is identical to the for-loop bound, making it always true
and the else branch dead code:

  for (q = 0; q < pse_port_num_queues[FE_PSE_PORT_PPE1]; q++) {
      if (q < pse_port_num_queues[FE_PSE_PORT_PPE1])  /* always true */
          set RSV_PAGES;
      else
          set 0;  /* unreachable */
  }

The intended behavior is to reserve pages only for the first half of
the queues, matching the PPE2 implementation on line 334 which
correctly uses the /2 divisor. Fix the PPE1 condition accordingly.

Fixes: 23020f049327 ("net: airoha: Introduce ethernet support for EN7581 SoC")
Signed-off-by: Wayen.Yan <win847@gmail.com>
Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/6a2ca3de.ad59c0a6.147df9.2ac1@mx.google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/airoha/airoha_eth.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/airoha/airoha_eth.c b/drivers/net/ethernet/airoha/airoha_eth.c
index 329988a8400c13..7b8d0c5e262ab6 100644
--- a/drivers/net/ethernet/airoha/airoha_eth.c
+++ b/drivers/net/ethernet/airoha/airoha_eth.c
@@ -311,7 +311,7 @@ static void airoha_fe_pse_ports_init(struct airoha_eth *eth)
 					 PSE_QUEUE_RSV_PAGES);
 	/* PPE1 */
 	for (q = 0; q < pse_port_num_queues[FE_PSE_PORT_PPE1]; q++) {
-		if (q < pse_port_num_queues[FE_PSE_PORT_PPE1])
+		if (q < pse_port_num_queues[FE_PSE_PORT_PPE1] / 2)
 			airoha_fe_set_pse_oq_rsv(eth, FE_PSE_PORT_PPE1, q,
 						 PSE_QUEUE_RSV_PAGES);
 		else
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0796/2077] net: ti: icssg-prueth: Fix AF_XDP fill ring alloc and wakeup condition
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (794 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0795/2077] net: airoha: Fix always-true condition in PPE1 queue reservation loop Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0797/2077] net: ti: icssg: Use undirected TX tag for native XDP in HSR offload mode Greg Kroah-Hartman
                   ` (201 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Meghana Malladi, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Meghana Malladi <m-malladi@ti.com>

[ Upstream commit dfb787f7d157f97ba91344b584d33481f572530e ]

emac_rx_packet_zc() calls prueth_rx_alloc_zc() with count (frames
received in the current NAPI poll) as the allocation budget.  Two
problems arise from this:

1. When the CPPI5 descriptor pool is exhausted (avail_desc == 0,
   FDQ already holds the maximum number of descriptors), count > 0
   still triggers allocation attempts that all fail, spamming the
   kernel log with "rx push: failed to allocate descriptor" at
   high packet rates.

2. The XSK wakeup condition "ret < count" is wrong when avail_desc
   is zero: ret == 0 and count can be up to 64, so the condition is
   always true.  This causes ~200 spurious ndo_xsk_wakeup() calls
   per second even when the FDQ is already full, wasting CPU cycles
   in repeated NAPI invocations that process zero frames.

Fix both by introducing alloc_budget = min(budget, avail_desc):
- When avail_desc == 0 no allocation is attempted, avoiding pool
  exhaustion errors.  The wakeup condition "ret < alloc_budget"
  evaluates to 0 < 0 == false, correctly clearing the wakeup flag
  so the hardware IRQ re-arms NAPI without spurious kicks.
- In steady state avail_desc == count <= budget, so alloc_budget
  == count and behaviour is unchanged.
- After a dry-ring stall (count == 0, avail_desc > 0), alloc_budget
  > 0 causes new descriptors to be posted to the FDQ so the hardware
  can resume receiving immediately.

Fixes: 7a64bb388df3 ("net: ti: icssg-prueth: Add AF_XDP zero copy for RX")
Signed-off-by: Meghana Malladi <m-malladi@ti.com>
Link: https://patch.msgid.link/20260611185744.2498070-2-m-malladi@ti.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/ti/icssg/icssg_common.c | 14 ++++++--------
 1 file changed, 6 insertions(+), 8 deletions(-)

diff --git a/drivers/net/ethernet/ti/icssg/icssg_common.c b/drivers/net/ethernet/ti/icssg/icssg_common.c
index a28a608f9bf4b9..55a696912811f6 100644
--- a/drivers/net/ethernet/ti/icssg/icssg_common.c
+++ b/drivers/net/ethernet/ti/icssg/icssg_common.c
@@ -927,6 +927,7 @@ static int emac_rx_packet_zc(struct prueth_emac *emac, u32 flow_id,
 	struct cppi5_host_desc_t *desc_rx;
 	struct prueth_swdata *swdata;
 	dma_addr_t desc_dma, buf_dma;
+	int avail_desc, alloc_budget;
 	struct xdp_buff *xdp;
 	int xdp_status = 0;
 	int count = 0;
@@ -993,16 +994,13 @@ static int emac_rx_packet_zc(struct prueth_emac *emac, u32 flow_id,
 	if (xdp_status & ICSSG_XDP_REDIR)
 		xdp_do_flush();
 
-	/* Allocate xsk buffers from the pool for the "count" number of
-	 * packets processed in order to be able to receive more packets.
-	 */
-	ret = prueth_rx_alloc_zc(emac, count);
+	avail_desc = k3_cppi_desc_pool_avail(rx_chn->desc_pool);
+	alloc_budget = min_t(int, budget, avail_desc);
+
+	ret = prueth_rx_alloc_zc(emac, alloc_budget);
 
 	if (xsk_uses_need_wakeup(rx_chn->xsk_pool)) {
-		/* If the user space doesn't provide enough buffers then it must
-		 * explicitly wake up the kernel when new buffers are available
-		 */
-		if (ret < count)
+		if (ret < alloc_budget)
 			xsk_set_rx_need_wakeup(rx_chn->xsk_pool);
 		else
 			xsk_clear_rx_need_wakeup(rx_chn->xsk_pool);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0797/2077] net: ti: icssg: Use undirected TX tag for native XDP in HSR offload mode
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (795 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0796/2077] net: ti: icssg-prueth: Fix AF_XDP fill ring alloc and wakeup condition Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0798/2077] net: ti: icssg: Use undirected TX tag for XDP zero copy " Greg Kroah-Hartman
                   ` (200 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Meghana Malladi, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Meghana Malladi <m-malladi@ti.com>

[ Upstream commit bcbf73d98195577a89e788179843f6d0c66244a5 ]

emac_xmit_xdp_frame() always sets the CPPI5 descriptor destination
tag to emac->port_id, which directs the PRU firmware to transmit
the frame on that specific slave port only.  In HSR offload mode
this bypasses the firmware's HSR duplication logic: the frame goes
out on one ring leg and never appears on the other, breaking HSR
redundancy for XDP_TX paths.

icssg_ndo_start_xmit() already handles this correctly: when HSR
offload mode is active and NETIF_F_HW_HSR_DUP is set it substitutes
PRUETH_UNDIRECTED_PKT_DST_TAG (port 0) so the PRU duplicates the
frame to both slave ports.  It also sets PRUETH_UNDIRECTED_PKT_TAG_INS
in epib[1] when NETIF_F_HW_HSR_TAG_INS is set so the PRU inserts the
HSR sequence tag, which XDP_TX frames lack (the tag is stripped by
the PRU on RX before the frame reaches the XDP program).

Apply the same logic in emac_xmit_xdp_frame() so XDP_TX frames in
HSR mode are treated identically to skb TX via hsr0.

Fixes: 62aa3246f462 ("net: ti: icssg-prueth: Add XDP support")
Signed-off-by: Meghana Malladi <m-malladi@ti.com>
Link: https://patch.msgid.link/20260611185744.2498070-3-m-malladi@ti.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/ti/icssg/icssg_common.c | 21 ++++++++++++++++++--
 1 file changed, 19 insertions(+), 2 deletions(-)

diff --git a/drivers/net/ethernet/ti/icssg/icssg_common.c b/drivers/net/ethernet/ti/icssg/icssg_common.c
index 55a696912811f6..ede32f266729ee 100644
--- a/drivers/net/ethernet/ti/icssg/icssg_common.c
+++ b/drivers/net/ethernet/ti/icssg/icssg_common.c
@@ -696,6 +696,7 @@ u32 emac_xmit_xdp_frame(struct prueth_emac *emac,
 	dma_addr_t desc_dma, buf_dma;
 	struct prueth_swdata *swdata;
 	struct page *page;
+	u32 dst_tag_id;
 	u32 *epib;
 	int ret;
 
@@ -737,9 +738,25 @@ u32 emac_xmit_xdp_frame(struct prueth_emac *emac,
 
 	/* set dst tag to indicate internal qid at the firmware which is at
 	 * bit8..bit15. bit0..bit7 indicates port num for directed
-	 * packets in case of switch mode operation
+	 * packets in case of switch mode operation and port num 0
+	 * for undirected packets in case of HSR offload mode.
+	 *
+	 * XDP_TX frames arrive on a slave port with the HSR tag already
+	 * stripped by the PRU firmware.  Like skb TX via hsr0, they must
+	 * be sent as undirected so the PRU duplicates them to both ports
+	 * and re-inserts the HSR sequence tag.
 	 */
-	cppi5_desc_set_tags_ids(&first_desc->hdr, 0, (emac->port_id | (q_idx << 8)));
+	dst_tag_id = emac->port_id | (q_idx << 8);
+
+	if (emac->prueth->is_hsr_offload_mode &&
+	    (ndev->features & NETIF_F_HW_HSR_DUP))
+		dst_tag_id = PRUETH_UNDIRECTED_PKT_DST_TAG;
+
+	if (emac->prueth->is_hsr_offload_mode &&
+	    (ndev->features & NETIF_F_HW_HSR_TAG_INS))
+		epib[1] |= PRUETH_UNDIRECTED_PKT_TAG_INS;
+
+	cppi5_desc_set_tags_ids(&first_desc->hdr, 0, dst_tag_id);
 	k3_udma_glue_tx_dma_to_cppi5_addr(tx_chn->tx_chn, &buf_dma);
 	cppi5_hdesc_attach_buf(first_desc, buf_dma, xdpf->len, buf_dma, xdpf->len);
 	swdata = cppi5_hdesc_get_swdata(first_desc);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0798/2077] net: ti: icssg: Use undirected TX tag for XDP zero copy in HSR offload mode
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (796 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0797/2077] net: ti: icssg: Use undirected TX tag for native XDP in HSR offload mode Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0799/2077] net: ethernet: oa_tc6: mdiobus->parent initialized with NULL Greg Kroah-Hartman
                   ` (199 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Meghana Malladi, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Meghana Malladi <m-malladi@ti.com>

[ Upstream commit f9691288413ceb4fc72f3ccc4d8e42adf66eb28d ]

emac_xsk_xmit_zc() has the same issue as the fixed emac_xmit_xdp_frame():
it always sets the CPPI5 descriptor destination tag to emac->port_id,
which directs the PRU firmware to transmit on only one slave port in HSR
mode, breaking redundancy.

Apply the same fix: in HSR offload mode when NETIF_F_HW_HSR_DUP is set,
use PRUETH_UNDIRECTED_PKT_DST_TAG (port 0) so the PRU duplicates frames
to both ports. Also set PRUETH_UNDIRECTED_PKT_TAG_INS when
NETIF_F_HW_HSR_TAG_INS is set so the PRU re-inserts the HSR sequence tag
that was stripped by the PRU on RX before the XDP program saw the frame.

This ensures XSK XDP_TX frames in HSR mode are treated identically to
skb TX via hsr0.

Fixes: 8756ef2eb078 ("net: ti: icssg-prueth: Add AF_XDP zero copy for TX")
Signed-off-by: Meghana Malladi <m-malladi@ti.com>
Link: https://patch.msgid.link/20260611185744.2498070-4-m-malladi@ti.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/ti/icssg/icssg_common.c | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/drivers/net/ethernet/ti/icssg/icssg_common.c b/drivers/net/ethernet/ti/icssg/icssg_common.c
index ede32f266729ee..82ddef9c17d54e 100644
--- a/drivers/net/ethernet/ti/icssg/icssg_common.c
+++ b/drivers/net/ethernet/ti/icssg/icssg_common.c
@@ -105,6 +105,7 @@ static int emac_xsk_xmit_zc(struct prueth_emac *emac,
 	struct xdp_desc xdp_desc;
 	int num_tx = 0, pkt_len;
 	int descs_avail, ret;
+	u32 dst_tag_id;
 	u32 *epib;
 	int i;
 
@@ -137,9 +138,17 @@ static int emac_xsk_xmit_zc(struct prueth_emac *emac,
 		epib[0] = 0;
 		epib[1] = 0;
 		cppi5_hdesc_set_pktlen(host_desc, pkt_len);
-		cppi5_desc_set_tags_ids(&host_desc->hdr, 0,
-					(emac->port_id | (q_idx << 8)));
+		dst_tag_id = emac->port_id | (q_idx << 8);
+
+		if (emac->prueth->is_hsr_offload_mode &&
+		    (ndev->features & NETIF_F_HW_HSR_DUP))
+			dst_tag_id = PRUETH_UNDIRECTED_PKT_DST_TAG;
+
+		if (emac->prueth->is_hsr_offload_mode &&
+		    (ndev->features & NETIF_F_HW_HSR_TAG_INS))
+			epib[1] |= PRUETH_UNDIRECTED_PKT_TAG_INS;
 
+		cppi5_desc_set_tags_ids(&host_desc->hdr, 0, dst_tag_id);
 		k3_udma_glue_tx_dma_to_cppi5_addr(tx_chn->tx_chn, &dma_buf);
 		cppi5_hdesc_attach_buf(host_desc, dma_buf, pkt_len, dma_buf,
 				       pkt_len);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0799/2077] net: ethernet: oa_tc6: mdiobus->parent initialized with NULL
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (797 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0798/2077] net: ti: icssg: Use undirected TX tag for XDP zero copy " Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0800/2077] net: ethernet: oa_tc6: Remove FCS size in RX frame Greg Kroah-Hartman
                   ` (198 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Selvamani Rajagopal, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvamani Rajagopal <Selvamani.Rajagopal@onsemi.com>

[ Upstream commit a221d3f7e3f3ea6a3b4bc511cf2a59242daa06e1 ]

As "dev" pointer in oa_tc6 structure is never initialized,
mbiobus->parent was initialized with NULL.  This change
fixes it by initializing it with device pointer of spi.

Fixes: 8f9bf857e43b ("net: ethernet: oa_tc6: implement internal PHY initialization")
Signed-off-by: Selvamani Rajagopal <Selvamani.Rajagopal@onsemi.com>
Link: https://patch.msgid.link/20260611-level-trigger-v5-2-4533a9e85ce2@onsemi.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/oa_tc6.c |    3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

--- a/drivers/net/ethernet/oa_tc6.c
+++ b/drivers/net/ethernet/oa_tc6.c
@@ -107,7 +107,6 @@
 
 /* Internal structure for MAC-PHY drivers */
 struct oa_tc6 {
-	struct device *dev;
 	struct net_device *netdev;
 	struct phy_device *phydev;
 	struct mii_bus *mdiobus;
@@ -518,7 +517,7 @@ static int oa_tc6_mdiobus_register(struc
 	tc6->mdiobus->read_c45 = oa_tc6_mdiobus_read_c45;
 	tc6->mdiobus->write_c45 = oa_tc6_mdiobus_write_c45;
 	tc6->mdiobus->name = "oa-tc6-mdiobus";
-	tc6->mdiobus->parent = tc6->dev;
+	tc6->mdiobus->parent = &tc6->spi->dev;
 
 	snprintf(tc6->mdiobus->id, ARRAY_SIZE(tc6->mdiobus->id), "%s",
 		 dev_name(&tc6->spi->dev));



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0800/2077] net: ethernet: oa_tc6: Remove FCS size in RX frame
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (798 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0799/2077] net: ethernet: oa_tc6: mdiobus->parent initialized with NULL Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0801/2077] dt-bindings: net: updated interrupt type to be active low, level triggered Greg Kroah-Hartman
                   ` (197 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Selvamani Rajagopal, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvamani Rajagopal <Selvamani.Rajagopal@onsemi.com>

[ Upstream commit a5a1d11dd3729146abe7420b874bab15870a42b4 ]

OA TC6 MAC-PHY appends FCS to the incoming frame. It must be
removed from the frame before being passed to the stack.

With FCS in the frame, many applications, like ping or any
application that uses IP layer may work as they may
carry the packet size information in the protocol.

Application like ptp4l, particularly if it uses layer 2
for its communication, it will fail with "bad message" due to
the extra 4 bytes added by the presence of FCS.

Fixes: d70a0d8f2f2d ("net: ethernet: oa_tc6: implement receive path to receive rx ethernet frames")
Signed-off-by: Selvamani Rajagopal <Selvamani.Rajagopal@onsemi.com>
Link: https://patch.msgid.link/20260611-level-trigger-v5-3-4533a9e85ce2@onsemi.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/oa_tc6.c |   11 +++++++++++
 1 file changed, 11 insertions(+)

--- a/drivers/net/ethernet/oa_tc6.c
+++ b/drivers/net/ethernet/oa_tc6.c
@@ -751,6 +751,17 @@ static int oa_tc6_process_rx_chunk_foote
 
 static void oa_tc6_submit_rx_skb(struct oa_tc6 *tc6)
 {
+	/* MAC-PHY delivers each frame with its Ethernet FCS attached.
+	 * Strip it before handing over to the stack, unless the user
+	 * has asked to keep it via NETIF_F_RXFCS. Keeping the FCS
+	 * in the frame is harmless for IP traffic, but is parsed as
+	 * a (malformed) suffix TLV by PTP, which makes ptp4l reject
+	 * every message with "bad message" error.
+	 */
+	if (!(tc6->netdev->features & NETIF_F_RXFCS) &&
+	    tc6->rx_skb->len > ETH_FCS_LEN)
+		skb_trim(tc6->rx_skb, tc6->rx_skb->len - ETH_FCS_LEN);
+
 	tc6->rx_skb->protocol = eth_type_trans(tc6->rx_skb, tc6->netdev);
 	tc6->netdev->stats.rx_packets++;
 	tc6->netdev->stats.rx_bytes += tc6->rx_skb->len;



^ permalink raw reply	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0801/2077] dt-bindings: net: updated interrupt type to be active low, level triggered
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (799 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0800/2077] net: ethernet: oa_tc6: Remove FCS size in RX frame Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0802/2077] ionic: Fix check in ionic_get_link_ext_stats Greg Kroah-Hartman
                   ` (196 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Selvamani Rajagopal,
	Krzysztof Kozlowski, Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvamani Rajagopal <Selvamani.Rajagopal@onsemi.com>

[ Upstream commit 31e56112e6544afba0a50d60251175585ee62943 ]

According to OPEN Alliance 10BASE-T1x MACPHY Serial Interface (TC6)
specification, interrupt type is active low, level triggered interrupt.

Specification calls for when interrupt level will be asserted and what
condition it is de-asserted. By using edge triggered interrupt, there is a
potential chance to miss it, particularly if it is asserted when interrupt
is disabled.

Level triggered interrupt can't be missed as it gets de-asserted only on
interrupt handler taking actions on interrupting conditions.

Fixes: ac49b950bea9 ("dt-bindings: net: add Microchip's LAN865X 10BASE-T1S MACPHY")
Signed-off-by: Selvamani Rajagopal <Selvamani.Rajagopal@onsemi.com>
Acked-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Link: https://patch.msgid.link/20260611-level-trigger-v5-4-4533a9e85ce2@onsemi.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/devicetree/bindings/net/microchip,lan8650.yaml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/Documentation/devicetree/bindings/net/microchip,lan8650.yaml b/Documentation/devicetree/bindings/net/microchip,lan8650.yaml
index 61e11d4a07c407..766ff58147ae36 100644
--- a/Documentation/devicetree/bindings/net/microchip,lan8650.yaml
+++ b/Documentation/devicetree/bindings/net/microchip,lan8650.yaml
@@ -67,7 +67,7 @@ examples:
         pinctrl-names = "default";
         pinctrl-0 = <&eth0_pins>;
         interrupt-parent = <&gpio>;
-        interrupts = <6 IRQ_TYPE_EDGE_FALLING>;
+        interrupts = <6 IRQ_TYPE_LEVEL_LOW>;
         local-mac-address = [04 05 06 01 02 03];
         spi-max-frequency = <15000000>;
       };
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0802/2077] ionic: Fix check in ionic_get_link_ext_stats
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (800 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0801/2077] dt-bindings: net: updated interrupt type to be active low, level triggered Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0803/2077] RDMA/bnxt_re: Initialize dpi variable to zero Greg Kroah-Hartman
                   ` (195 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Brett Creeley, Eric Joyner,
	Jakub Kicinski, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Brett Creeley <brett.creeley@amd.com>

[ Upstream commit 7678e69079c10b2fb10977f28f44ddb22971ea5b ]

The current check will fail if SR-IOV is not initialized for the
physical function; this is because is_physfn is 0 if sriov_init() isn't
run or fails. Change the check that prevents getting the link down count
to use is_virtfn instead so that VFs don't get this functionality, which
was the original intent.

Fixes: 132b4ebfa090 ("ionic: add support for ethtool extended stat link_down_count")
Signed-off-by: Brett Creeley <brett.creeley@amd.com>
Signed-off-by: Eric Joyner <eric.joyner@amd.com>
Link: https://patch.msgid.link/20260614205303.48088-2-eric.joyner@amd.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/ethernet/pensando/ionic/ionic_ethtool.c | 11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

diff --git a/drivers/net/ethernet/pensando/ionic/ionic_ethtool.c b/drivers/net/ethernet/pensando/ionic/ionic_ethtool.c
index 78a802eb159f0a..6069fa46091318 100644
--- a/drivers/net/ethernet/pensando/ionic/ionic_ethtool.c
+++ b/drivers/net/ethernet/pensando/ionic/ionic_ethtool.c
@@ -116,8 +116,15 @@ static void ionic_get_link_ext_stats(struct net_device *netdev,
 {
 	struct ionic_lif *lif = netdev_priv(netdev);
 
-	if (lif->ionic->pdev->is_physfn)
-		stats->link_down_events = lif->link_down_count;
+	if (lif->ionic->pdev->is_virtfn)
+		return;
+
+	if (!lif->ionic->idev.port_info) {
+		netdev_err_once(netdev, "port_info not initialized\n");
+		return;
+	}
+
+	stats->link_down_events = lif->link_down_count;
 }
 
 static int ionic_get_link_ksettings(struct net_device *netdev,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0803/2077] RDMA/bnxt_re: Initialize dpi variable to zero
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (801 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0802/2077] ionic: Fix check in ionic_get_link_ext_stats Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0804/2077] RDMA/bnxt_re: Free SRQ toggle page after firmware teardown Greg Kroah-Hartman
                   ` (194 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anantha Prabhu, Kalesh AP,
	Selvin Xavier, Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvin Xavier <selvin.xavier@broadcom.com>

[ Upstream commit 978b27d6ce538bb832ccd69e45802824e4301c4b ]

dpi is initialized only for BNXT_RE_ALLOC_WC_PAGE, but copied
for all the cases. So initialize the dpi to 0.

Fixes: eee6268421a2 ("RDMA/bnxt_re: Move the UAPI methods to a dedicated file")
Fixes: 360da60d6c6e ("RDMA/bnxt_re: Enable low latency push")
Link: https://patch.msgid.link/r/20260615224751.232802-2-selvin.xavier@broadcom.com
Reviewed-by: Anantha Prabhu <anantha.prabhu@broadcom.com>
Signed-off-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/uapi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/bnxt_re/uapi.c b/drivers/infiniband/hw/bnxt_re/uapi.c
index 3eaee7101615bf..61ddfa94c1aa1a 100644
--- a/drivers/infiniband/hw/bnxt_re/uapi.c
+++ b/drivers/infiniband/hw/bnxt_re/uapi.c
@@ -76,8 +76,8 @@ static int UVERBS_HANDLER(BNXT_RE_METHOD_ALLOC_PAGE)(struct uverbs_attr_bundle *
 	struct ib_ucontext *ib_uctx;
 	struct bnxt_re_dev *rdev;
 	u64 mmap_offset;
+	u32 dpi = 0;
 	u32 length;
-	u32 dpi;
 	u64 addr;
 	int err;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0804/2077] RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (802 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0803/2077] RDMA/bnxt_re: Initialize dpi variable to zero Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0805/2077] RDMA/bnxt_re: Free CQ " Greg Kroah-Hartman
                   ` (193 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Selvin Xavier, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvin Xavier <selvin.xavier@broadcom.com>

[ Upstream commit 131e2918b9b0529687e67e2e58047304027f095a ]

Free the toggle page only after firmware teardown completes so that
an NQ interrupt arriving during bnxt_qplib_destroy_srq() won't write
the toggle values to an already-freed page. Move free_page() after
bnxt_qplib_destroy_srq().

Fixes: 181028a0d84c ("RDMA/bnxt_re: Share a page to expose per SRQ info with userspace")
Link: https://patch.msgid.link/r/20260615224751.232802-3-selvin.xavier@broadcom.com
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/ib_verbs.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index 365ec2767d2535..822484f3b95979 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -2029,11 +2029,11 @@ int bnxt_re_destroy_srq(struct ib_srq *ib_srq, struct ib_udata *udata)
 	if (ret)
 		return ret;
 
-	if (rdev->chip_ctx->modes.toggle_bits & BNXT_QPLIB_SRQ_TOGGLE_BIT) {
-		free_page((unsigned long)srq->uctx_srq_page);
+	if (rdev->chip_ctx->modes.toggle_bits & BNXT_QPLIB_SRQ_TOGGLE_BIT)
 		hash_del(&srq->hash_entry);
-	}
 	bnxt_qplib_destroy_srq(&rdev->qplib_res, qplib_srq);
+	if (rdev->chip_ctx->modes.toggle_bits & BNXT_QPLIB_SRQ_TOGGLE_BIT)
+		free_page((unsigned long)srq->uctx_srq_page);
 	ib_umem_release(srq->umem);
 	atomic_dec(&rdev->stats.res.srq_count);
 	return ib_respond_empty_udata(udata);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0805/2077] RDMA/bnxt_re: Free CQ toggle page after firmware teardown
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (803 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0804/2077] RDMA/bnxt_re: Free SRQ toggle page after firmware teardown Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:07 ` [PATCH 7.1 0806/2077] RDMA/bnxt_re: Avoid displaying the kernel pointer Greg Kroah-Hartman
                   ` (192 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Selvin Xavier, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvin Xavier <selvin.xavier@broadcom.com>

[ Upstream commit bb45e06f9914ca64ac95341a80a0c20bb8dd46a9 ]

Free the toggle page only after firmware teardown completes so that
an NQ interrupt arriving during bnxt_qplib_destroy_cq() won't write
the toggle value to an already-freed page. Move free_page() after
bnxt_qplib_destroy_cq.

Fixes: e275919d9669 ("RDMA/bnxt_re: Share a page to expose per CQ info with userspace")
Link: https://patch.msgid.link/r/20260615224751.232802-4-selvin.xavier@broadcom.com
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/ib_verbs.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index 822484f3b95979..7bea3bee434b8c 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -3332,11 +3332,11 @@ int bnxt_re_destroy_cq(struct ib_cq *ib_cq, struct ib_udata *udata)
 	if (ret)
 		return ret;
 
-	if (cctx->modes.toggle_bits & BNXT_QPLIB_CQ_TOGGLE_BIT) {
-		free_page((unsigned long)cq->uctx_cq_page);
+	if (cctx->modes.toggle_bits & BNXT_QPLIB_CQ_TOGGLE_BIT)
 		hash_del(&cq->hash_entry);
-	}
 	bnxt_qplib_destroy_cq(&rdev->qplib_res, &cq->qplib_cq);
+	if (cctx->modes.toggle_bits & BNXT_QPLIB_CQ_TOGGLE_BIT)
+		free_page((unsigned long)cq->uctx_cq_page);
 
 	bnxt_re_put_nq(rdev, nq);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0806/2077] RDMA/bnxt_re: Avoid displaying the kernel pointer
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (804 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0805/2077] RDMA/bnxt_re: Free CQ " Greg Kroah-Hartman
@ 2026-07-21 15:07 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0807/2077] RDMA/bnxt_re: Refactor bnxt_re_init_user_qp() Greg Kroah-Hartman
                   ` (191 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:07 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kalesh AP, Selvin Xavier,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvin Xavier <selvin.xavier@broadcom.com>

[ Upstream commit 7d70c704a06f620d5d421ab76bac5e225bfb4308 ]

While dumping the info on MR using the rdma tool, we
dump the mr_hwq which is a kernel pointer. There is
no need to expose this value for end user. So avoid
it.

Fixes: 7363eb76b7f3 ("RDMA/bnxt_re: Support driver specific data collection using rdma tool")
Link: https://patch.msgid.link/r/20260615224751.232802-9-selvin.xavier@broadcom.com
Reviewed-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/main.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/drivers/infiniband/hw/bnxt_re/main.c b/drivers/infiniband/hw/bnxt_re/main.c
index a892f117291796..d25fdc458120e8 100644
--- a/drivers/infiniband/hw/bnxt_re/main.c
+++ b/drivers/infiniband/hw/bnxt_re/main.c
@@ -1093,8 +1093,6 @@ static int bnxt_re_fill_res_mr_entry(struct sk_buff *msg, struct ib_mr *ib_mr)
 		goto err;
 	if (rdma_nl_put_driver_u32(msg, "element_size", mr_hwq->element_size))
 		goto err;
-	if (rdma_nl_put_driver_u64_hex(msg, "hwq", (unsigned long)mr_hwq))
-		goto err;
 	if (rdma_nl_put_driver_u64_hex(msg, "va", mr->qplib_mr.va))
 		goto err;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0807/2077] RDMA/bnxt_re: Refactor bnxt_re_init_user_qp()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (805 preceding siblings ...)
  2026-07-21 15:07 ` [PATCH 7.1 0806/2077] RDMA/bnxt_re: Avoid displaying the kernel pointer Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0808/2077] RDMA/bnxt_re: Update msn table size for app allocated QPs Greg Kroah-Hartman
                   ` (190 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sriharsha Basavapatna, Selvin Xavier,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>

[ Upstream commit 9a79dcbedcc7a0330a227f23fbd220515c61d54c ]

The umem changes for CQ added a helper - bnxt_re_setup_sginfo().
Use the same helper for QP creation since we support only 4K
pages for QP ring memory too.

Add a new helper function bnxt_re_get_psn_bytes() to improve
readability as this code will be updated in subsequent patches.

Link: https://patch.msgid.link/r/20260519150041.7251-2-sriharsha.basavapatna@broadcom.com
Signed-off-by: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
Reviewed-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Stable-dep-of: dc95931b7e13 ("RDMA/bnxt_re: Add a max slot check for SQ")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/ib_verbs.c | 127 +++++++++++++----------
 1 file changed, 73 insertions(+), 54 deletions(-)

diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index 7bea3bee434b8c..dac50fe6725aea 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -1136,34 +1136,64 @@ static int bnxt_re_setup_swqe_size(struct bnxt_re_qp *qp,
 	return 0;
 }
 
+static int bnxt_re_setup_sginfo(struct bnxt_re_dev *rdev,
+				struct ib_umem *umem,
+				struct bnxt_qplib_sg_info *sginfo)
+{
+	unsigned long page_size;
+
+	if (!umem)
+		return -EINVAL;
+
+	page_size = ib_umem_find_best_pgsz(umem, SZ_4K, 0);
+	if (!page_size || page_size != SZ_4K)
+		return -EINVAL;
+
+	sginfo->umem = umem;
+	sginfo->npages = ib_umem_num_dma_blocks(umem, page_size);
+	sginfo->pgsize = page_size;
+	sginfo->pgshft = __builtin_ctz(page_size);
+	return 0;
+}
+
+static int bnxt_re_get_psn_bytes(struct bnxt_re_dev *rdev,
+				 struct bnxt_re_ucontext *cntx,
+				 struct bnxt_qplib_qp *qplib_qp,
+				 struct bnxt_re_qp_req *ureq)
+{
+	int psn_sz, psn_nume;
+
+	psn_sz = bnxt_qplib_is_chip_gen_p5_p7(rdev->chip_ctx) ?
+				sizeof(struct sq_psn_search_ext) :
+				sizeof(struct sq_psn_search);
+	if (cntx && bnxt_re_is_var_size_supported(rdev, cntx)) {
+		psn_nume = ureq->sq_slots;
+	} else {
+		psn_nume = (qplib_qp->wqe_mode == BNXT_QPLIB_WQE_MODE_STATIC) ?
+		qplib_qp->sq.max_wqe : ((qplib_qp->sq.max_wqe * qplib_qp->sq.wqe_size) /
+			 sizeof(struct bnxt_qplib_sge));
+	}
+	if (_is_host_msn_table(rdev->qplib_res.dattr->dev_cap_flags2))
+		psn_nume = roundup_pow_of_two(psn_nume);
+
+	return psn_nume * psn_sz;
+}
+
 static int bnxt_re_init_user_qp(struct bnxt_re_dev *rdev, struct bnxt_re_pd *pd,
 				struct bnxt_re_qp *qp, struct bnxt_re_ucontext *cntx,
 				struct bnxt_re_qp_req *ureq)
 {
 	struct bnxt_qplib_qp *qplib_qp;
-	int bytes = 0, psn_sz;
 	struct ib_umem *umem;
-	int psn_nume;
+	int bytes;
+	int rc;
 
 	qplib_qp = &qp->qplib_qp;
 
 	bytes = (qplib_qp->sq.max_wqe * qplib_qp->sq.wqe_size);
 	/* Consider mapping PSN search memory only for RC QPs. */
-	if (qplib_qp->type == CMDQ_CREATE_QP_TYPE_RC) {
-		psn_sz = bnxt_qplib_is_chip_gen_p5_p7(rdev->chip_ctx) ?
-						   sizeof(struct sq_psn_search_ext) :
-						   sizeof(struct sq_psn_search);
-		if (cntx && bnxt_re_is_var_size_supported(rdev, cntx)) {
-			psn_nume = ureq->sq_slots;
-		} else {
-			psn_nume = (qplib_qp->wqe_mode == BNXT_QPLIB_WQE_MODE_STATIC) ?
-			qplib_qp->sq.max_wqe : ((qplib_qp->sq.max_wqe * qplib_qp->sq.wqe_size) /
-				 sizeof(struct bnxt_qplib_sge));
-		}
-		if (_is_host_msn_table(rdev->qplib_res.dattr->dev_cap_flags2))
-			psn_nume = roundup_pow_of_two(psn_nume);
-		bytes += (psn_nume * psn_sz);
-	}
+	if (qplib_qp->type == CMDQ_CREATE_QP_TYPE_RC)
+		bytes += bnxt_re_get_psn_bytes(rdev, cntx, qplib_qp, ureq);
 
 	bytes = PAGE_ALIGN(bytes);
 	umem = ib_umem_get(&rdev->ibdev, ureq->qpsva, bytes,
@@ -1172,33 +1202,42 @@ static int bnxt_re_init_user_qp(struct bnxt_re_dev *rdev, struct bnxt_re_pd *pd,
 		return PTR_ERR(umem);
 
 	qp->sumem = umem;
-	qplib_qp->sq.sg_info.umem = umem;
-	qplib_qp->sq.sg_info.pgsize = PAGE_SIZE;
-	qplib_qp->sq.sg_info.pgshft = PAGE_SHIFT;
-	qplib_qp->qp_handle = ureq->qp_handle;
+	rc = bnxt_re_setup_sginfo(rdev, qp->sumem, &qplib_qp->sq.sg_info);
+	if (rc)
+		goto fail;
+
+	if (qp->qplib_qp.srq)
+		goto done;
 
-	if (!qp->qplib_qp.srq) {
-		bytes = (qplib_qp->rq.max_wqe * qplib_qp->rq.wqe_size);
-		bytes = PAGE_ALIGN(bytes);
-		umem = ib_umem_get(&rdev->ibdev, ureq->qprva, bytes,
-				   IB_ACCESS_LOCAL_WRITE);
-		if (IS_ERR(umem))
-			goto rqfail;
-		qp->rumem = umem;
-		qplib_qp->rq.sg_info.umem = umem;
-		qplib_qp->rq.sg_info.pgsize = PAGE_SIZE;
-		qplib_qp->rq.sg_info.pgshft = PAGE_SHIFT;
+	bytes = (qplib_qp->rq.max_wqe * qplib_qp->rq.wqe_size);
+	bytes = PAGE_ALIGN(bytes);
+	umem = ib_umem_get(&rdev->ibdev, ureq->qprva, bytes,
+			   IB_ACCESS_LOCAL_WRITE);
+	if (IS_ERR(umem)) {
+		rc = PTR_ERR(umem);
+		goto fail;
 	}
 
+	qp->rumem = umem;
+	rc = bnxt_re_setup_sginfo(rdev, qp->rumem, &qplib_qp->rq.sg_info);
+	if (rc)
+		goto rqfail;
+
+done:
+	qplib_qp->qp_handle = ureq->qp_handle;
 	qplib_qp->dpi = &cntx->dpi;
 	qplib_qp->is_user = true;
 	return 0;
+
 rqfail:
+	ib_umem_release(qp->rumem);
+	qp->rumem = NULL;
+	memset(&qplib_qp->rq.sg_info, 0, sizeof(qplib_qp->rq.sg_info));
+fail:
 	ib_umem_release(qp->sumem);
 	qp->sumem = NULL;
 	memset(&qplib_qp->sq.sg_info, 0, sizeof(qplib_qp->sq.sg_info));
-
-	return PTR_ERR(umem);
+	return rc;
 }
 
 static struct bnxt_re_ah *bnxt_re_create_shadow_qp_ah
@@ -3345,26 +3384,6 @@ int bnxt_re_destroy_cq(struct ib_cq *ib_cq, struct ib_udata *udata)
 	return ib_respond_empty_udata(udata);
 }
 
-static int bnxt_re_setup_sginfo(struct bnxt_re_dev *rdev,
-				struct ib_umem *umem,
-				struct bnxt_qplib_sg_info *sginfo)
-{
-	unsigned long page_size;
-
-	if (!umem)
-		return -EINVAL;
-
-	page_size = ib_umem_find_best_pgsz(umem, SZ_4K, 0);
-	if (!page_size || page_size != SZ_4K)
-		return -EINVAL;
-
-	sginfo->umem = umem;
-	sginfo->npages = ib_umem_num_dma_blocks(umem, page_size);
-	sginfo->pgsize = page_size;
-	sginfo->pgshft = __builtin_ctz(page_size);
-	return 0;
-}
-
 int bnxt_re_create_user_cq(struct ib_cq *ibcq, const struct ib_cq_init_attr *attr,
 			   struct uverbs_attr_bundle *attrs)
 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0808/2077] RDMA/bnxt_re: Update msn table size for app allocated QPs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (806 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0807/2077] RDMA/bnxt_re: Refactor bnxt_re_init_user_qp() Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0809/2077] RDMA/bnxt_re: Enhance dbr usecnt logic in doorbell uapis Greg Kroah-Hartman
                   ` (189 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sriharsha Basavapatna, Selvin Xavier,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>

[ Upstream commit 9ce2a8c81c3099f68d371d040d77aab8cd1a9ed5 ]

For app allocated QPs, the driver shouldn't use slots/round-up logic
to compute the msn table size. The application handles this logic
and computes 'sq_npsn' and passes it to the driver using a new uapi
parameter.

Link: https://patch.msgid.link/r/20260519150041.7251-5-sriharsha.basavapatna@broadcom.com
Signed-off-by: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
Reviewed-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Stable-dep-of: dc95931b7e13 ("RDMA/bnxt_re: Add a max slot check for SQ")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/ib_verbs.c | 61 +++++++++++++++---------
 include/uapi/rdma/bnxt_re-abi.h          |  1 +
 2 files changed, 40 insertions(+), 22 deletions(-)

diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index dac50fe6725aea..2aaf9093b612d6 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -1159,29 +1159,39 @@ static int bnxt_re_setup_sginfo(struct bnxt_re_dev *rdev,
 static int bnxt_re_get_psn_bytes(struct bnxt_re_dev *rdev,
 				 struct bnxt_re_ucontext *cntx,
 				 struct bnxt_qplib_qp *qplib_qp,
-				 struct bnxt_re_qp_req *ureq)
+				 struct bnxt_re_qp_req *ureq,
+				 bool fixed_que_attr)
 {
 	int psn_sz, psn_nume;
 
-	psn_sz = bnxt_qplib_is_chip_gen_p5_p7(rdev->chip_ctx) ?
-				sizeof(struct sq_psn_search_ext) :
-				sizeof(struct sq_psn_search);
-	if (cntx && bnxt_re_is_var_size_supported(rdev, cntx)) {
-		psn_nume = ureq->sq_slots;
+	if (rdev->dev_attr &&
+	    _is_host_msn_table(rdev->dev_attr->dev_cap_flags2))
+		psn_sz = sizeof(struct sq_msn_search);
+	else
+		psn_sz = bnxt_qplib_is_chip_gen_p5_p7(rdev->chip_ctx) ?
+					sizeof(struct sq_psn_search_ext) :
+					sizeof(struct sq_psn_search);
+	if (!fixed_que_attr) {
+		if (cntx && bnxt_re_is_var_size_supported(rdev, cntx)) {
+			psn_nume = ureq->sq_slots;
+		} else {
+			psn_nume = (qplib_qp->wqe_mode == BNXT_QPLIB_WQE_MODE_STATIC) ?
+			qplib_qp->sq.max_wqe : ((qplib_qp->sq.max_wqe * qplib_qp->sq.wqe_size) /
+				 sizeof(struct bnxt_qplib_sge));
+		}
+		if (_is_host_msn_table(rdev->qplib_res.dattr->dev_cap_flags2))
+			psn_nume = roundup_pow_of_two(psn_nume);
 	} else {
-		psn_nume = (qplib_qp->wqe_mode == BNXT_QPLIB_WQE_MODE_STATIC) ?
-		qplib_qp->sq.max_wqe : ((qplib_qp->sq.max_wqe * qplib_qp->sq.wqe_size) /
-			 sizeof(struct bnxt_qplib_sge));
+		psn_nume = ureq->sq_npsn;
 	}
-	if (_is_host_msn_table(rdev->qplib_res.dattr->dev_cap_flags2))
-		psn_nume = roundup_pow_of_two(psn_nume);
 
 	return psn_nume * psn_sz;
 }
 
 static int bnxt_re_init_user_qp(struct bnxt_re_dev *rdev, struct bnxt_re_pd *pd,
 				struct bnxt_re_qp *qp, struct bnxt_re_ucontext *cntx,
-				struct bnxt_re_qp_req *ureq)
+				struct bnxt_re_qp_req *ureq,
+				bool fixed_que_attr)
 {
 	struct bnxt_qplib_qp *qplib_qp;
 	struct ib_umem *umem;
@@ -1193,7 +1203,7 @@ static int bnxt_re_init_user_qp(struct bnxt_re_dev *rdev, struct bnxt_re_pd *pd,
 	bytes = (qplib_qp->sq.max_wqe * qplib_qp->sq.wqe_size);
 	/* Consider mapping PSN search memory only for RC QPs. */
 	if (qplib_qp->type == CMDQ_CREATE_QP_TYPE_RC)
-		bytes += bnxt_re_get_psn_bytes(rdev, cntx, qplib_qp, ureq);
+		bytes += bnxt_re_get_psn_bytes(rdev, cntx, qplib_qp, ureq, fixed_que_attr);
 
 	bytes = PAGE_ALIGN(bytes);
 	umem = ib_umem_get(&rdev->ibdev, ureq->qpsva, bytes,
@@ -1636,7 +1646,9 @@ static int bnxt_re_init_qp_type(struct bnxt_re_dev *rdev,
 	return qptype;
 }
 
-static void bnxt_re_qp_calculate_msn_psn_size(struct bnxt_re_qp *qp)
+static void bnxt_re_qp_calculate_msn_psn_size(struct bnxt_re_qp *qp,
+					      bool fixed_que_attr,
+					      struct bnxt_re_qp_req *req)
 {
 	struct bnxt_qplib_qp *qplib_qp = &qp->qplib_qp;
 	struct bnxt_qplib_q *sq = &qplib_qp->sq;
@@ -1659,12 +1671,17 @@ static void bnxt_re_qp_calculate_msn_psn_size(struct bnxt_re_qp *qp)
 
 	/* Update msn tbl size */
 	if (qplib_qp->is_host_msn_tbl && qplib_qp->psn_sz) {
-		if (wqe_mode == BNXT_QPLIB_WQE_MODE_STATIC)
-			qplib_qp->msn_tbl_sz =
-				roundup_pow_of_two(bnxt_qplib_set_sq_size(sq, wqe_mode));
-		else
-			qplib_qp->msn_tbl_sz =
-				roundup_pow_of_two(bnxt_qplib_set_sq_size(sq, wqe_mode)) / 2;
+		if (!fixed_que_attr) {
+			if (wqe_mode == BNXT_QPLIB_WQE_MODE_STATIC)
+				qplib_qp->msn_tbl_sz =
+					roundup_pow_of_two(bnxt_qplib_set_sq_size(sq, wqe_mode));
+			else
+				qplib_qp->msn_tbl_sz =
+					roundup_pow_of_two(bnxt_qplib_set_sq_size(sq, wqe_mode))
+						/ 2;
+		} else {
+			qplib_qp->msn_tbl_sz = req->sq_npsn;
+		}
 		qplib_qp->msn = 0;
 	}
 }
@@ -1738,12 +1755,12 @@ static int bnxt_re_init_qp_attr(struct bnxt_re_qp *qp, struct bnxt_re_pd *pd,
 		bnxt_re_adjust_gsi_sq_attr(qp, init_attr, uctx);
 
 	if (uctx) { /* This will update DPI and qp_handle */
-		rc = bnxt_re_init_user_qp(rdev, pd, qp, uctx, ureq);
+		rc = bnxt_re_init_user_qp(rdev, pd, qp, uctx, ureq, fixed_que_attr);
 		if (rc)
 			return rc;
 	}
 
-	bnxt_re_qp_calculate_msn_psn_size(qp);
+	bnxt_re_qp_calculate_msn_psn_size(qp, fixed_que_attr, ureq);
 
 	rc = bnxt_re_setup_qp_hwqs(qp);
 	if (rc)
diff --git a/include/uapi/rdma/bnxt_re-abi.h b/include/uapi/rdma/bnxt_re-abi.h
index 40955eaba32e60..db8400f2ce3bc5 100644
--- a/include/uapi/rdma/bnxt_re-abi.h
+++ b/include/uapi/rdma/bnxt_re-abi.h
@@ -135,6 +135,7 @@ struct bnxt_re_qp_req {
 	__aligned_u64 qp_handle;
 	__aligned_u64 comp_mask;
 	__u32 sq_slots;
+	__u32 sq_npsn;
 };
 
 struct bnxt_re_qp_resp {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0809/2077] RDMA/bnxt_re: Enhance dbr usecnt logic in doorbell uapis
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (807 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0808/2077] RDMA/bnxt_re: Update msn table size for app allocated QPs Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0810/2077] RDMA/bnxt_re: Support doorbells for app allocated QPs Greg Kroah-Hartman
                   ` (188 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sriharsha Basavapatna, Selvin Xavier,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>

[ Upstream commit 73607410f4f1b0d5c3d0af2d70a79c265482a0e3 ]

The current logic in the doorbell cleanup function is not
sufficient for a change in a subsequent patch, that fails
doorbell remove operation in some conditions. The cleanup
should facilitate freeing of the dbr object when the caller
may not retry the teardown operation (implicit teardown:
process-exit/driver-removal).

Extend this counter to use kref mechanism so that the dbr
object gets freed (via kref callback) when there are no more
references to it, rather than directly freeing it in the
cleanup uapi.

Link: https://patch.msgid.link/r/20260519150041.7251-7-sriharsha.basavapatna@broadcom.com
Signed-off-by: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
Reviewed-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Stable-dep-of: dc95931b7e13 ("RDMA/bnxt_re: Add a max slot check for SQ")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/ib_verbs.h |  3 ++-
 drivers/infiniband/hw/bnxt_re/uapi.c     | 16 +++++++++++++---
 2 files changed, 15 insertions(+), 4 deletions(-)

diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.h b/drivers/infiniband/hw/bnxt_re/ib_verbs.h
index 08f71a94d55d7b..13dac48ed453e8 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.h
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.h
@@ -167,7 +167,7 @@ struct bnxt_re_dbr_obj {
 	struct bnxt_re_dev *rdev;
 	struct bnxt_qplib_dpi dpi;
 	struct bnxt_re_user_mmap_entry *entry;
-	atomic_t usecnt; /* QPs using this dbr */
+	struct kref usecnt; /* 1 (uobject) + n (QPs using this dbr) */
 };
 
 struct bnxt_re_flow {
@@ -308,4 +308,5 @@ void bnxt_re_unlock_cqs(struct bnxt_re_qp *qp, unsigned long flags);
 struct bnxt_re_user_mmap_entry*
 bnxt_re_mmap_entry_insert(struct bnxt_re_ucontext *uctx, u64 mem_offset,
 			  enum bnxt_re_mmap_flag mmap_flag, u64 *offset);
+void bnxt_re_dbr_kref_release(struct kref *ref);
 #endif /* __BNXT_RE_IB_VERBS_H__ */
diff --git a/drivers/infiniband/hw/bnxt_re/uapi.c b/drivers/infiniband/hw/bnxt_re/uapi.c
index 61ddfa94c1aa1a..058f76f9b679b1 100644
--- a/drivers/infiniband/hw/bnxt_re/uapi.c
+++ b/drivers/infiniband/hw/bnxt_re/uapi.c
@@ -369,6 +369,7 @@ static int UVERBS_HANDLER(BNXT_RE_METHOD_DBR_ALLOC)(struct uverbs_attr_bundle *a
 	}
 
 	obj->rdev = rdev;
+	kref_init(&obj->usecnt);
 	uobj->object = obj;
 	uverbs_finalize_uobj_create(attrs, BNXT_RE_ALLOC_DBR_HANDLE);
 
@@ -391,15 +392,24 @@ static int UVERBS_HANDLER(BNXT_RE_METHOD_DBR_ALLOC)(struct uverbs_attr_bundle *a
 	return ret;
 }
 
+void bnxt_re_dbr_kref_release(struct kref *ref)
+{
+	struct bnxt_re_dbr_obj *obj =
+		container_of(ref, struct bnxt_re_dbr_obj, usecnt);
+	struct bnxt_re_dev *rdev = obj->rdev;
+
+	rdma_user_mmap_entry_remove(&obj->entry->rdma_entry);
+	bnxt_qplib_free_uc_dpi(&rdev->qplib_res, &obj->dpi);
+	kfree(obj);
+}
+
 static int bnxt_re_dbr_cleanup(struct ib_uobject *uobject,
 			       enum rdma_remove_reason why,
 			       struct uverbs_attr_bundle *attrs)
 {
 	struct bnxt_re_dbr_obj *obj = uobject->object;
-	struct bnxt_re_dev *rdev = obj->rdev;
 
-	rdma_user_mmap_entry_remove(&obj->entry->rdma_entry);
-	bnxt_qplib_free_uc_dpi(&rdev->qplib_res, &obj->dpi);
+	kref_put(&obj->usecnt, bnxt_re_dbr_kref_release);
 	return 0;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0810/2077] RDMA/bnxt_re: Support doorbells for app allocated QPs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (808 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0809/2077] RDMA/bnxt_re: Enhance dbr usecnt logic in doorbell uapis Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0811/2077] RDMA/bnxt_re: Enable " Greg Kroah-Hartman
                   ` (187 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sriharsha Basavapatna, Selvin Xavier,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>

[ Upstream commit 7e812673a948395675e9893e75b0fc60d19bbf27 ]

App allocated QPs can use a separate doorbell for each QP.
This doorbell region can be passed through a new driver specific
DBR_HANDLE attribute, during QP creation. When this attribute
is set, associate the QP with the given doorbell region.

While the QP holds a reference to the dbr, the dbr itself
cannot be destroyed and is rejected with EBUSY error.

Link: https://patch.msgid.link/r/20260519150041.7251-9-sriharsha.basavapatna@broadcom.com
Signed-off-by: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
Reviewed-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Stable-dep-of: dc95931b7e13 ("RDMA/bnxt_re: Add a max slot check for SQ")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/ib_verbs.c | 35 ++++++++++++++++++++----
 drivers/infiniband/hw/bnxt_re/ib_verbs.h |  1 +
 drivers/infiniband/hw/bnxt_re/uapi.c     | 24 ++++++++++++++++
 include/uapi/rdma/bnxt_re-abi.h          |  4 +++
 4 files changed, 59 insertions(+), 5 deletions(-)

diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index 2aaf9093b612d6..0f30e551415945 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -1024,6 +1024,9 @@ int bnxt_re_destroy_qp(struct ib_qp *ib_qp, struct ib_udata *udata)
 	if (rc)
 		ibdev_err(&rdev->ibdev, "Failed to destroy HW QP");
 
+	if (qp->dbr_obj)
+		kref_put(&qp->dbr_obj->usecnt, bnxt_re_dbr_kref_release);
+
 	if (rdma_is_kernel_res(&qp->ib_qp.res)) {
 		flags = bnxt_re_lock_cqs(qp);
 		bnxt_qplib_clean_qp(&qp->qplib_qp);
@@ -1191,7 +1194,8 @@ static int bnxt_re_get_psn_bytes(struct bnxt_re_dev *rdev,
 static int bnxt_re_init_user_qp(struct bnxt_re_dev *rdev, struct bnxt_re_pd *pd,
 				struct bnxt_re_qp *qp, struct bnxt_re_ucontext *cntx,
 				struct bnxt_re_qp_req *ureq,
-				bool fixed_que_attr)
+				bool fixed_que_attr,
+				struct bnxt_re_dbr_obj *dbr_obj)
 {
 	struct bnxt_qplib_qp *qplib_qp;
 	struct ib_umem *umem;
@@ -1234,8 +1238,11 @@ static int bnxt_re_init_user_qp(struct bnxt_re_dev *rdev, struct bnxt_re_pd *pd,
 		goto rqfail;
 
 done:
+	if (dbr_obj)
+		qplib_qp->dpi = &dbr_obj->dpi;
+	else
+		qplib_qp->dpi = &cntx->dpi;
 	qplib_qp->qp_handle = ureq->qp_handle;
-	qplib_qp->dpi = &cntx->dpi;
 	qplib_qp->is_user = true;
 	return 0;
 
@@ -1689,7 +1696,8 @@ static void bnxt_re_qp_calculate_msn_psn_size(struct bnxt_re_qp *qp,
 static int bnxt_re_init_qp_attr(struct bnxt_re_qp *qp, struct bnxt_re_pd *pd,
 				struct ib_qp_init_attr *init_attr,
 				struct bnxt_re_ucontext *uctx,
-				struct bnxt_re_qp_req *ureq)
+				struct bnxt_re_qp_req *ureq,
+				struct bnxt_re_dbr_obj *dbr_obj)
 {
 	struct bnxt_qplib_dev_attr *dev_attr;
 	struct bnxt_qplib_qp *qplqp;
@@ -1755,7 +1763,8 @@ static int bnxt_re_init_qp_attr(struct bnxt_re_qp *qp, struct bnxt_re_pd *pd,
 		bnxt_re_adjust_gsi_sq_attr(qp, init_attr, uctx);
 
 	if (uctx) { /* This will update DPI and qp_handle */
-		rc = bnxt_re_init_user_qp(rdev, pd, qp, uctx, ureq, fixed_que_attr);
+		rc = bnxt_re_init_user_qp(rdev, pd, qp, uctx, ureq, fixed_que_attr,
+					  dbr_obj);
 		if (rc)
 			return rc;
 	}
@@ -1891,7 +1900,9 @@ static int bnxt_re_add_unique_gid(struct bnxt_re_dev *rdev)
 int bnxt_re_create_qp(struct ib_qp *ib_qp, struct ib_qp_init_attr *qp_init_attr,
 		      struct ib_udata *udata)
 {
+	struct bnxt_re_dbr_obj *dbr_obj = NULL;
 	struct bnxt_qplib_dev_attr *dev_attr;
+	struct uverbs_attr_bundle *attrs;
 	struct bnxt_re_ucontext *uctx;
 	struct bnxt_re_qp_req ureq;
 	struct bnxt_re_dev *rdev;
@@ -1912,6 +1923,17 @@ int bnxt_re_create_qp(struct ib_qp *ib_qp, struct ib_qp_init_attr *qp_init_attr,
 		rc = ib_copy_validate_udata_in_cm(udata, ureq, qp_handle, 0);
 		if (rc)
 			return rc;
+
+		attrs = rdma_udata_to_uverbs_attr_bundle(udata);
+		if (uverbs_attr_is_valid(attrs,
+					 BNXT_RE_CREATE_QP_ATTR_DBR_HANDLE)) {
+			dbr_obj = uverbs_attr_get_obj(attrs,
+						      BNXT_RE_CREATE_QP_ATTR_DBR_HANDLE);
+			if (IS_ERR(dbr_obj))
+				return PTR_ERR(dbr_obj);
+			kref_get(&dbr_obj->usecnt);
+			qp->dbr_obj = dbr_obj;
+		}
 	}
 
 	rc = bnxt_re_test_qp_limits(rdev, qp_init_attr, dev_attr);
@@ -1921,7 +1943,8 @@ int bnxt_re_create_qp(struct ib_qp *ib_qp, struct ib_qp_init_attr *qp_init_attr,
 	}
 
 	qp->rdev = rdev;
-	rc = bnxt_re_init_qp_attr(qp, pd, qp_init_attr, uctx, &ureq);
+	rc = bnxt_re_init_qp_attr(qp, pd, qp_init_attr, uctx, &ureq,
+				  dbr_obj);
 	if (rc)
 		goto fail;
 
@@ -1991,6 +2014,8 @@ int bnxt_re_create_qp(struct ib_qp *ib_qp, struct ib_qp_init_attr *qp_init_attr,
 	bnxt_qplib_free_qp_res(&rdev->qplib_res, &qp->qplib_qp);
 	bnxt_re_qp_free_umem(qp);
 fail:
+	if (dbr_obj)
+		kref_put(&dbr_obj->usecnt, bnxt_re_dbr_kref_release);
 	return rc;
 }
 
diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.h b/drivers/infiniband/hw/bnxt_re/ib_verbs.h
index 13dac48ed453e8..cdc403bf9e5d64 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.h
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.h
@@ -96,6 +96,7 @@ struct bnxt_re_qp {
 	struct bnxt_re_cq	*scq;
 	struct bnxt_re_cq	*rcq;
 	struct dentry		*dentry;
+	struct bnxt_re_dbr_obj *dbr_obj; /* doorbell region */
 };
 
 struct bnxt_re_cq {
diff --git a/drivers/infiniband/hw/bnxt_re/uapi.c b/drivers/infiniband/hw/bnxt_re/uapi.c
index 058f76f9b679b1..65539f6bacb6bd 100644
--- a/drivers/infiniband/hw/bnxt_re/uapi.c
+++ b/drivers/infiniband/hw/bnxt_re/uapi.c
@@ -409,6 +409,15 @@ static int bnxt_re_dbr_cleanup(struct ib_uobject *uobject,
 {
 	struct bnxt_re_dbr_obj *obj = uobject->object;
 
+	/* If it is being destroyed explicitly while QPs still hold a
+	 * reference (> 1), reject it with EBUSY. If no QP references
+	 * or implicit teardown (process exit, driver removal), drop
+	 * the uobject reference unconditionally. The object gets freed
+	 * (bnxt_re_dbr_kref_release) when the usecnt goes to zero.
+	 */
+	if (why == RDMA_REMOVE_DESTROY && kref_read(&obj->usecnt) > 1)
+		return -EBUSY;
+
 	kref_put(&obj->usecnt, bnxt_re_dbr_kref_release);
 	return 0;
 }
@@ -469,11 +478,26 @@ DECLARE_UVERBS_NAMED_METHOD(BNXT_RE_METHOD_GET_DEFAULT_DBR,
 DECLARE_UVERBS_GLOBAL_METHODS(BNXT_RE_OBJECT_DEFAULT_DBR,
 			      &UVERBS_METHOD(BNXT_RE_METHOD_GET_DEFAULT_DBR));
 
+ADD_UVERBS_ATTRIBUTES_SIMPLE(
+	bnxt_re_qp_create,
+	UVERBS_OBJECT_QP,
+	UVERBS_METHOD_QP_CREATE,
+	UVERBS_ATTR_IDR(BNXT_RE_CREATE_QP_ATTR_DBR_HANDLE,
+			BNXT_RE_OBJECT_DBR,
+			UVERBS_ACCESS_READ,
+			UA_OPTIONAL));
+
+const struct uapi_definition bnxt_re_create_qp_defs[] = {
+	UAPI_DEF_CHAIN_OBJ_TREE(UVERBS_OBJECT_QP, &bnxt_re_qp_create),
+	{},
+};
+
 const struct uapi_definition bnxt_re_uapi_defs[] = {
 	UAPI_DEF_CHAIN_OBJ_TREE_NAMED(BNXT_RE_OBJECT_ALLOC_PAGE),
 	UAPI_DEF_CHAIN_OBJ_TREE_NAMED(BNXT_RE_OBJECT_NOTIFY_DRV),
 	UAPI_DEF_CHAIN_OBJ_TREE_NAMED(BNXT_RE_OBJECT_GET_TOGGLE_MEM),
 	UAPI_DEF_CHAIN_OBJ_TREE_NAMED(BNXT_RE_OBJECT_DBR),
 	UAPI_DEF_CHAIN_OBJ_TREE_NAMED(BNXT_RE_OBJECT_DEFAULT_DBR),
+	UAPI_DEF_CHAIN(bnxt_re_create_qp_defs),
 	{}
 };
diff --git a/include/uapi/rdma/bnxt_re-abi.h b/include/uapi/rdma/bnxt_re-abi.h
index db8400f2ce3bc5..4da8cda337dcbd 100644
--- a/include/uapi/rdma/bnxt_re-abi.h
+++ b/include/uapi/rdma/bnxt_re-abi.h
@@ -138,6 +138,10 @@ struct bnxt_re_qp_req {
 	__u32 sq_npsn;
 };
 
+enum bnxt_re_create_qp_attrs {
+	BNXT_RE_CREATE_QP_ATTR_DBR_HANDLE = UVERBS_ID_DRIVER_NS_WITH_UHW,
+};
+
 struct bnxt_re_qp_resp {
 	__u32 qpid;
 	__u32 rsvd;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0811/2077] RDMA/bnxt_re: Enable app allocated QPs
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (809 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0810/2077] RDMA/bnxt_re: Support doorbells for app allocated QPs Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0812/2077] RDMA/bnxt_re: Add a max slot check for SQ Greg Kroah-Hartman
                   ` (186 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sriharsha Basavapatna, Selvin Xavier,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>

[ Upstream commit 47b730054f05a05acd497c138bf3255a5de1a973 ]

The driver supports a new comp_mask: REQ_MASK_FIXED_QUE_ATTR.
The application sets this comp_mask bit in the CREATE_QP ureq
to indicate direct control of the QP. The driver goes through
the required processing for app allocated QPs (previous patches).
Only variable WQE mode is supported for these QPs.

This patch removes an unused comp_mask:
	BNXT_RE_QP_REQ_MASK_VAR_WQE_SQ_SLOTS

Link: https://patch.msgid.link/r/20260519150041.7251-10-sriharsha.basavapatna@broadcom.com
Signed-off-by: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
Reviewed-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Stable-dep-of: dc95931b7e13 ("RDMA/bnxt_re: Add a max slot check for SQ")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/ib_verbs.c | 18 +++++++++++++++---
 include/uapi/rdma/bnxt_re-abi.h          |  2 +-
 2 files changed, 16 insertions(+), 4 deletions(-)

diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index 0f30e551415945..e97c17727da162 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -1697,7 +1697,8 @@ static int bnxt_re_init_qp_attr(struct bnxt_re_qp *qp, struct bnxt_re_pd *pd,
 				struct ib_qp_init_attr *init_attr,
 				struct bnxt_re_ucontext *uctx,
 				struct bnxt_re_qp_req *ureq,
-				struct bnxt_re_dbr_obj *dbr_obj)
+				struct bnxt_re_dbr_obj *dbr_obj,
+				bool fixed_que_attr)
 {
 	struct bnxt_qplib_dev_attr *dev_attr;
 	struct bnxt_qplib_qp *qplqp;
@@ -1720,6 +1721,13 @@ static int bnxt_re_init_qp_attr(struct bnxt_re_qp *qp, struct bnxt_re_pd *pd,
 		return qptype;
 	qplqp->type = (u8)qptype;
 	qplqp->wqe_mode = bnxt_re_is_var_size_supported(rdev, uctx);
+	if (fixed_que_attr) {
+		if (qplqp->wqe_mode != BNXT_QPLIB_WQE_MODE_VARIABLE)
+			return -EOPNOTSUPP;
+		if (!ureq->sq_npsn ||
+		    ureq->sq_npsn > roundup_pow_of_two(ureq->sq_slots / 2))
+			return -EINVAL;
+	}
 	qplqp->dev_cap_flags = dev_attr->dev_cap_flags;
 	qplqp->cctx = rdev->chip_ctx;
 	if (init_attr->qp_type == IB_QPT_RC) {
@@ -1904,6 +1912,7 @@ int bnxt_re_create_qp(struct ib_qp *ib_qp, struct ib_qp_init_attr *qp_init_attr,
 	struct bnxt_qplib_dev_attr *dev_attr;
 	struct uverbs_attr_bundle *attrs;
 	struct bnxt_re_ucontext *uctx;
+	bool fixed_que_attr = false;
 	struct bnxt_re_qp_req ureq;
 	struct bnxt_re_dev *rdev;
 	struct bnxt_re_pd *pd;
@@ -1920,7 +1929,8 @@ int bnxt_re_create_qp(struct ib_qp *ib_qp, struct ib_qp_init_attr *qp_init_attr,
 
 	uctx = rdma_udata_to_drv_context(udata, struct bnxt_re_ucontext, ib_uctx);
 	if (udata) {
-		rc = ib_copy_validate_udata_in_cm(udata, ureq, qp_handle, 0);
+		rc = ib_copy_validate_udata_in_cm(udata, ureq, qp_handle,
+						  BNXT_RE_QP_REQ_MASK_FIXED_QUE_ATTR);
 		if (rc)
 			return rc;
 
@@ -1934,6 +1944,8 @@ int bnxt_re_create_qp(struct ib_qp *ib_qp, struct ib_qp_init_attr *qp_init_attr,
 			kref_get(&dbr_obj->usecnt);
 			qp->dbr_obj = dbr_obj;
 		}
+		if (ureq.comp_mask & BNXT_RE_QP_REQ_MASK_FIXED_QUE_ATTR)
+			fixed_que_attr = true;
 	}
 
 	rc = bnxt_re_test_qp_limits(rdev, qp_init_attr, dev_attr);
@@ -1944,7 +1956,7 @@ int bnxt_re_create_qp(struct ib_qp *ib_qp, struct ib_qp_init_attr *qp_init_attr,
 
 	qp->rdev = rdev;
 	rc = bnxt_re_init_qp_attr(qp, pd, qp_init_attr, uctx, &ureq,
-				  dbr_obj);
+				  dbr_obj, fixed_que_attr);
 	if (rc)
 		goto fail;
 
diff --git a/include/uapi/rdma/bnxt_re-abi.h b/include/uapi/rdma/bnxt_re-abi.h
index 4da8cda337dcbd..a4599d7b736aa4 100644
--- a/include/uapi/rdma/bnxt_re-abi.h
+++ b/include/uapi/rdma/bnxt_re-abi.h
@@ -126,7 +126,7 @@ struct bnxt_re_resize_cq_req {
 };
 
 enum bnxt_re_qp_mask {
-	BNXT_RE_QP_REQ_MASK_VAR_WQE_SQ_SLOTS = 0x1,
+	BNXT_RE_QP_REQ_MASK_FIXED_QUE_ATTR = 0x1,
 };
 
 struct bnxt_re_qp_req {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0812/2077] RDMA/bnxt_re: Add a max slot check for SQ
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (810 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0811/2077] RDMA/bnxt_re: Enable " Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0813/2077] RDMA/bnxt_re: Proper rollback if the ioremap fails Greg Kroah-Hartman
                   ` (185 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sriharsha Basavapatna, Selvin Xavier,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvin Xavier <selvin.xavier@broadcom.com>

[ Upstream commit dc95931b7e1326dacae547874bf38c092e5960d8 ]

The variable WQE mode must be validated against
the maximum slots supported by HW. The max supported
value is 64K. Adding a max and min check and fail if user
supplied value is more than the max supported and zero.

Fixes: d8ea645d6984 ("RDMA/bnxt_re: Handle variable WQE support for user applications")
Link: https://patch.msgid.link/r/20260615224751.232802-10-selvin.xavier@broadcom.com
Reviewed-by: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/ib_verbs.c | 3 +++
 drivers/infiniband/hw/bnxt_re/qplib_sp.h | 1 +
 2 files changed, 4 insertions(+)

diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index e97c17727da162..24270371a0a562 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -1721,6 +1721,9 @@ static int bnxt_re_init_qp_attr(struct bnxt_re_qp *qp, struct bnxt_re_pd *pd,
 		return qptype;
 	qplqp->type = (u8)qptype;
 	qplqp->wqe_mode = bnxt_re_is_var_size_supported(rdev, uctx);
+	if (uctx && qplqp->wqe_mode == BNXT_QPLIB_WQE_MODE_VARIABLE &&
+	    (!ureq->sq_slots || ureq->sq_slots > BNXT_RE_MAX_SQ_SLOTS))
+		return -EINVAL;
 	if (fixed_que_attr) {
 		if (qplqp->wqe_mode != BNXT_QPLIB_WQE_MODE_VARIABLE)
 			return -EOPNOTSUPP;
diff --git a/drivers/infiniband/hw/bnxt_re/qplib_sp.h b/drivers/infiniband/hw/bnxt_re/qplib_sp.h
index 9fadd637cb5b10..c4193ae75b54da 100644
--- a/drivers/infiniband/hw/bnxt_re/qplib_sp.h
+++ b/drivers/infiniband/hw/bnxt_re/qplib_sp.h
@@ -369,6 +369,7 @@ int bnxt_qplib_destroy_flow(struct bnxt_qplib_res *res);
 #define BNXT_VAR_MAX_SLOT_ALIGN 256
 #define BNXT_VAR_MAX_SGE        13
 #define BNXT_RE_MAX_RQ_WQES     65536
+#define BNXT_RE_MAX_SQ_SLOTS    65536
 
 #define BNXT_STATIC_MAX_SGE	6
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0813/2077] RDMA/bnxt_re: Proper rollback if the ioremap fails
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (811 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0812/2077] RDMA/bnxt_re: Add a max slot check for SQ Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0814/2077] RDMA/bnxt_re: Avoid repeated requests to allocate WC pages Greg Kroah-Hartman
                   ` (184 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sriharsha Basavapatna, Selvin Xavier,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvin Xavier <selvin.xavier@broadcom.com>

[ Upstream commit 87267803a8c824616eb147c5dad7030a5db6f878 ]

bnxt_qplib_alloc_dpi returns success even if ioremap fails.
Add the proper rollback when the ioremap fails and return
-ENOMEM status.

Fixes: 0ac20faf5d83 ("RDMA/bnxt_re: Reorg the bar mapping")
Fixes: 360da60d6c6e ("RDMA/bnxt_re: Enable low latency push")
Link: https://patch.msgid.link/r/20260615224751.232802-11-selvin.xavier@broadcom.com
Reviewed-by: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/qplib_res.c | 11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/drivers/infiniband/hw/bnxt_re/qplib_res.c b/drivers/infiniband/hw/bnxt_re/qplib_res.c
index 95e0489c53c371..756f8b5f042a94 100644
--- a/drivers/infiniband/hw/bnxt_re/qplib_res.c
+++ b/drivers/infiniband/hw/bnxt_re/qplib_res.c
@@ -764,9 +764,13 @@ int bnxt_qplib_alloc_dpi(struct bnxt_qplib_res *res,
 		break;
 	case BNXT_QPLIB_DPI_TYPE_WC:
 		dpi->dbr = ioremap_wc(umaddr, PAGE_SIZE);
+		if (!dpi->dbr)
+			goto fail_ioremap;
 		break;
 	default:
 		dpi->dbr = ioremap(umaddr, PAGE_SIZE);
+		if (!dpi->dbr)
+			goto fail_ioremap;
 		break;
 	}
 
@@ -774,6 +778,13 @@ int bnxt_qplib_alloc_dpi(struct bnxt_qplib_res *res,
 	mutex_unlock(&res->dpi_tbl_lock);
 	return 0;
 
+fail_ioremap:
+	/* Roll back the bit we just claimed. */
+	set_bit(bit_num, dpit->tbl);
+	dpit->app_tbl[bit_num] = NULL;
+	mutex_unlock(&res->dpi_tbl_lock);
+	return -ENOMEM;
+
 }
 
 int bnxt_qplib_dealloc_dpi(struct bnxt_qplib_res *res,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0814/2077] RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (812 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0813/2077] RDMA/bnxt_re: Proper rollback if the ioremap fails Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0815/2077] RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled Greg Kroah-Hartman
                   ` (183 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kalesh AP, Selvin Xavier,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvin Xavier <selvin.xavier@broadcom.com>

[ Upstream commit 441baa79043431807115fd030d7d0bb14ed441a0 ]

Applications can request multiple WC pages for the same ucontext.
As of now, only 1 WC page per ucontext is supported. Add a lock to
avoid concurrent access and a check to fail repeated requests.
Also, if the mmap entry insert fails for the WC, free the Doorbell
page index mapped for the WC page.

Fixes: eee6268421a2 ("RDMA/bnxt_re: Move the UAPI methods to a dedicated file")
Fixes: 360da60d6c6e ("RDMA/bnxt_re: Enable low latency push")
Link: https://patch.msgid.link/r/20260615224751.232802-12-selvin.xavier@broadcom.com
Reviewed-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/ib_verbs.c |  1 +
 drivers/infiniband/hw/bnxt_re/ib_verbs.h |  1 +
 drivers/infiniband/hw/bnxt_re/uapi.c     | 33 +++++++++++++++++++-----
 3 files changed, 29 insertions(+), 6 deletions(-)

diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index 24270371a0a562..57290634746366 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -4720,6 +4720,7 @@ int bnxt_re_alloc_ucontext(struct ib_ucontext *ctx, struct ib_udata *udata)
 		goto fail;
 	}
 	spin_lock_init(&uctx->sh_lock);
+	mutex_init(&uctx->wcdpi_lock);
 
 	resp.comp_mask = BNXT_RE_UCNTX_CMASK_HAVE_CCTX;
 	chip_met_rev_num = rdev->chip_ctx->chip_num;
diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.h b/drivers/infiniband/hw/bnxt_re/ib_verbs.h
index cdc403bf9e5d64..acb40fc528d244 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.h
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.h
@@ -142,6 +142,7 @@ struct bnxt_re_ucontext {
 	struct bnxt_re_dev	*rdev;
 	struct bnxt_qplib_dpi	dpi;
 	struct bnxt_qplib_dpi   wcdpi;
+	struct mutex		wcdpi_lock;	/* serialises WC DPI alloc/free */
 	void			*shpg;
 	spinlock_t		sh_lock;	/* protect shpg */
 	struct rdma_user_mmap_entry *shpage_mmap;
diff --git a/drivers/infiniband/hw/bnxt_re/uapi.c b/drivers/infiniband/hw/bnxt_re/uapi.c
index 65539f6bacb6bd..5b0215eb4f58ff 100644
--- a/drivers/infiniband/hw/bnxt_re/uapi.c
+++ b/drivers/infiniband/hw/bnxt_re/uapi.c
@@ -98,14 +98,23 @@ static int UVERBS_HANDLER(BNXT_RE_METHOD_ALLOC_PAGE)(struct uverbs_attr_bundle *
 
 	switch (alloc_type) {
 	case BNXT_RE_ALLOC_WC_PAGE:
-		if (cctx->modes.db_push)  {
+		if (cctx->modes.db_push) {
+			mutex_lock(&uctx->wcdpi_lock);
+			/* already allocated — one WC page per context */
+			if (uctx->wcdpi.dbr) {
+				mutex_unlock(&uctx->wcdpi_lock);
+				return -EEXIST;
+			}
 			if (bnxt_qplib_alloc_dpi(&rdev->qplib_res, &uctx->wcdpi,
-						 uctx, BNXT_QPLIB_DPI_TYPE_WC))
+						 uctx, BNXT_QPLIB_DPI_TYPE_WC)) {
+				mutex_unlock(&uctx->wcdpi_lock);
 				return -ENOMEM;
+			}
 			length = PAGE_SIZE;
 			dpi = uctx->wcdpi.dpi;
 			addr = (u64)uctx->wcdpi.umdbr;
 			mmap_flag = BNXT_RE_MMAP_WC_DB;
+			mutex_unlock(&uctx->wcdpi_lock);
 		} else {
 			return -EINVAL;
 		}
@@ -128,8 +137,15 @@ static int UVERBS_HANDLER(BNXT_RE_METHOD_ALLOC_PAGE)(struct uverbs_attr_bundle *
 	}
 
 	entry = bnxt_re_mmap_entry_insert(uctx, addr, mmap_flag, &mmap_offset);
-	if (!entry)
+	if (!entry) {
+		if (mmap_flag == BNXT_RE_MMAP_WC_DB) {
+			mutex_lock(&uctx->wcdpi_lock);
+			bnxt_qplib_dealloc_dpi(&rdev->qplib_res, &uctx->wcdpi);
+			uctx->wcdpi.dbr = NULL;
+			mutex_unlock(&uctx->wcdpi_lock);
+		}
 		return -ENOMEM;
+	}
 
 	uobj->object = entry;
 	uverbs_finalize_uobj_create(attrs, BNXT_RE_ALLOC_PAGE_HANDLE);
@@ -160,11 +176,16 @@ static int alloc_page_obj_cleanup(struct ib_uobject *uobject,
 
 	switch (entry->mmap_flag) {
 	case BNXT_RE_MMAP_WC_DB:
-		if (uctx && uctx->wcdpi.dbr) {
+		if (uctx) {
 			struct bnxt_re_dev *rdev = uctx->rdev;
 
-			bnxt_qplib_dealloc_dpi(&rdev->qplib_res, &uctx->wcdpi);
-			uctx->wcdpi.dbr = NULL;
+			mutex_lock(&uctx->wcdpi_lock);
+			if (uctx->wcdpi.dbr) {
+				bnxt_qplib_dealloc_dpi(&rdev->qplib_res,
+						       &uctx->wcdpi);
+				uctx->wcdpi.dbr = NULL;
+			}
+			mutex_unlock(&uctx->wcdpi_lock);
 		}
 		break;
 	case BNXT_RE_MMAP_DBR_BAR:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0815/2077] RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (813 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0814/2077] RDMA/bnxt_re: Avoid repeated requests to allocate WC pages Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0816/2077] RDMA/bnxt_re: Reject GET_TOGGLE_MEM when toggle page was not allocated Greg Kroah-Hartman
                   ` (182 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sriharsha Basavapatna, Selvin Xavier,
	Jason Gunthorpe, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvin Xavier <selvin.xavier@broadcom.com>

[ Upstream commit a57592c6392a8e333c9c2731701297a5a279313a ]

No need to support the DBR related page allocations if the pacing feature
is disabled. Fail the request if pacing is disabled.

Fixes: ea2224857882 ("RDMA/bnxt_re: Update alloc_page uapi for pacing")
Link: https://patch.msgid.link/r/20260615224751.232802-15-selvin.xavier@broadcom.com
Reviewed-by: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/uapi.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/infiniband/hw/bnxt_re/uapi.c b/drivers/infiniband/hw/bnxt_re/uapi.c
index 5b0215eb4f58ff..2891b18b9437f5 100644
--- a/drivers/infiniband/hw/bnxt_re/uapi.c
+++ b/drivers/infiniband/hw/bnxt_re/uapi.c
@@ -121,12 +121,16 @@ static int UVERBS_HANDLER(BNXT_RE_METHOD_ALLOC_PAGE)(struct uverbs_attr_bundle *
 
 		break;
 	case BNXT_RE_ALLOC_DBR_BAR_PAGE:
+		if (!rdev->pacing.dbr_pacing)
+			return -EOPNOTSUPP;
 		length = PAGE_SIZE;
 		addr = (u64)rdev->pacing.dbr_bar_addr;
 		mmap_flag = BNXT_RE_MMAP_DBR_BAR;
 		break;
 
 	case BNXT_RE_ALLOC_DBR_PAGE:
+		if (!rdev->pacing.dbr_pacing)
+			return -EOPNOTSUPP;
 		length = PAGE_SIZE;
 		addr = (u64)rdev->pacing.dbr_page;
 		mmap_flag = BNXT_RE_MMAP_DBR_PAGE;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0816/2077] RDMA/bnxt_re: Reject GET_TOGGLE_MEM when toggle page was not allocated
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (814 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0815/2077] RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0817/2077] RDMA/hns: Fix memory leak of bonding resources Greg Kroah-Hartman
                   ` (181 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Selvin Xavier, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Selvin Xavier <selvin.xavier@broadcom.com>

[ Upstream commit 33a215f499b0643cd88a32ab5b8de1547be419c6 ]

If a user calls BNXT_RE_METHOD_GET_TOGGLE_MEM on a device that does not
support the CQ/SRQ toggle feature, uctx_cq_page or uctx_srq_page will
be NULL.

Add an explicit -EOPNOTSUPP return after capturing the address from
uctx_cq_page / uctx_srq_page if the address is zero.

Fixes: e275919d9669 ("RDMA/bnxt_re: Share a page to expose per CQ info with userspace")
Fixes: 181028a0d84c ("RDMA/bnxt_re: Share a page to expose per SRQ info with userspace")
Link: https://patch.msgid.link/r/20260615224751.232802-16-selvin.xavier@broadcom.com
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/bnxt_re/uapi.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/infiniband/hw/bnxt_re/uapi.c b/drivers/infiniband/hw/bnxt_re/uapi.c
index 2891b18b9437f5..ca6b1630cd83db 100644
--- a/drivers/infiniband/hw/bnxt_re/uapi.c
+++ b/drivers/infiniband/hw/bnxt_re/uapi.c
@@ -277,6 +277,8 @@ static int UVERBS_HANDLER(BNXT_RE_METHOD_GET_TOGGLE_MEM)(struct uverbs_attr_bund
 			return -EINVAL;
 
 		addr = (u64)cq->uctx_cq_page;
+		if (!addr)
+			return -EOPNOTSUPP;
 		break;
 	case BNXT_RE_SRQ_TOGGLE_MEM:
 		srq = bnxt_re_search_for_srq(rdev, res_id);
@@ -284,6 +286,8 @@ static int UVERBS_HANDLER(BNXT_RE_METHOD_GET_TOGGLE_MEM)(struct uverbs_attr_bund
 			return -EINVAL;
 
 		addr = (u64)srq->uctx_srq_page;
+		if (!addr)
+			return -EOPNOTSUPP;
 		break;
 
 	default:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0817/2077] RDMA/hns: Fix memory leak of bonding resources
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (815 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0816/2077] RDMA/bnxt_re: Reject GET_TOGGLE_MEM when toggle page was not allocated Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0818/2077] RDMA/irdma: Replace waitqueue and flag with completion Greg Kroah-Hartman
                   ` (180 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Junxian Huang, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Junxian Huang <huangjunxian6@hisilicon.com>

[ Upstream commit c0bd03b850d81a8914168d87ddf7f6ffa58875ef ]

In a corner case of concurrent driver removal and driver reset,
bonding resource is first released in hns_roce_hw_v2_exit() during
driver removal, and then is allocated again in hns_roce_register_device()
during driver reset. This leads to memory leak because the release
timing has already passed. This may also lead to a kernel panic
as below because of the leaked notifier callback:

Call trace:
  0xffffa20fccc04978 (P)
  raw_notifier_call_chain+0x20/0x38
  call_netdevice_notifiers_info+0x60/0xb8
  netdev_lower_state_changed+0x4c/0xb8

As Sashiko suggested, the teardown order of bonding resources should
be inverted to make sure the resources are released when the driver
is removed.

Fixes: b37ad2e290fc ("RDMA/hns: Initialize bonding resources")
Link: https://patch.msgid.link/r/20260613102045.811623-1-huangjunxian6@hisilicon.com
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
index 8810fa0b659731..60478382e82ff5 100644
--- a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
+++ b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
@@ -7586,8 +7586,8 @@ static int __init hns_roce_hw_v2_init(void)
 
 static void __exit hns_roce_hw_v2_exit(void)
 {
-	hns_roce_dealloc_bond_grp();
 	hnae3_unregister_client(&hns_roce_hw_v2_client);
+	hns_roce_dealloc_bond_grp();
 	hns_roce_cleanup_debugfs();
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0818/2077] RDMA/irdma: Replace waitqueue and flag with completion
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (816 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0817/2077] RDMA/hns: Fix memory leak of bonding resources Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0819/2077] net: serialize netif_running() check in enqueue_to_backlog() Greg Kroah-Hartman
                   ` (179 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Jason Gunthorpe,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jacob Moroni <jmoroni@google.com>

[ Upstream commit d9c8c45e6d2f438a3c8e643ae78b59454fa0fadd ]

The driver previously used a waitqueue along with an explicit
request_done flag, but without proper barriers around request_done.

An earlier patch by Gui-Dong Han <hanguidong02@gmail.com> attempted
to fix this by adding the missing memory barriers. Rather than
adding the barriers, this patch replaces the waitqueue+flag with
a completion, which is designed for this exact purpose.

Fixes: 44d9e52977a1 ("RDMA/irdma: Implement device initialization definitions")
Fixes: 915cc7ac0f8e ("RDMA/irdma: Add miscellaneous utility definitions")
Link: https://patch.msgid.link/r/20260616155601.1081448-1-jmoroni@google.com
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/infiniband/hw/irdma/hw.c    |  7 +++----
 drivers/infiniband/hw/irdma/main.h  |  3 +--
 drivers/infiniband/hw/irdma/utils.c | 12 +++++-------
 3 files changed, 9 insertions(+), 13 deletions(-)

diff --git a/drivers/infiniband/hw/irdma/hw.c b/drivers/infiniband/hw/irdma/hw.c
index f9be467d137f82..c345cc6542566b 100644
--- a/drivers/infiniband/hw/irdma/hw.c
+++ b/drivers/infiniband/hw/irdma/hw.c
@@ -235,8 +235,7 @@ static void irdma_complete_cqp_request(struct irdma_cqp *cqp,
 				       struct irdma_cqp_request *cqp_request)
 {
 	if (cqp_request->waiting) {
-		WRITE_ONCE(cqp_request->request_done, true);
-		wake_up(&cqp_request->waitq);
+		complete_all(&cqp_request->comp);
 	} else if (cqp_request->callback_fcn) {
 		cqp_request->callback_fcn(cqp_request);
 	}
@@ -1107,9 +1106,9 @@ static int irdma_create_cqp(struct irdma_pci_f *rf)
 	INIT_LIST_HEAD(&cqp->cqp_avail_reqs);
 	INIT_LIST_HEAD(&cqp->cqp_pending_reqs);
 
-	/* init the waitqueue of the cqp_requests and add them to the list */
+	/* init the completion of the cqp_requests and add them to the list */
 	for (i = 0; i < sqsize; i++) {
-		init_waitqueue_head(&cqp->cqp_requests[i].waitq);
+		init_completion(&cqp->cqp_requests[i].comp);
 		list_add_tail(&cqp->cqp_requests[i].list, &cqp->cqp_avail_reqs);
 	}
 	init_waitqueue_head(&cqp->remove_wq);
diff --git a/drivers/infiniband/hw/irdma/main.h b/drivers/infiniband/hw/irdma/main.h
index 3d49bd57bae7cf..8c17a201c1fd2f 100644
--- a/drivers/infiniband/hw/irdma/main.h
+++ b/drivers/infiniband/hw/irdma/main.h
@@ -161,13 +161,12 @@ struct irdma_cqp_compl_info {
 
 struct irdma_cqp_request {
 	struct cqp_cmds_info info;
-	wait_queue_head_t waitq;
+	struct completion comp;
 	struct list_head list;
 	refcount_t refcnt;
 	void (*callback_fcn)(struct irdma_cqp_request *cqp_request);
 	void *param;
 	struct irdma_cqp_compl_info compl_info;
-	bool request_done; /* READ/WRITE_ONCE macros operate on it */
 	bool waiting:1;
 	bool dynamic:1;
 	bool pending:1;
diff --git a/drivers/infiniband/hw/irdma/utils.c b/drivers/infiniband/hw/irdma/utils.c
index 495e5daff4b457..8e9e159f19ffe2 100644
--- a/drivers/infiniband/hw/irdma/utils.c
+++ b/drivers/infiniband/hw/irdma/utils.c
@@ -442,7 +442,7 @@ struct irdma_cqp_request *irdma_alloc_and_get_cqp_request(struct irdma_cqp *cqp,
 		if (cqp_request) {
 			cqp_request->dynamic = true;
 			if (wait)
-				init_waitqueue_head(&cqp_request->waitq);
+				init_completion(&cqp_request->comp);
 		}
 	}
 	if (!cqp_request) {
@@ -480,7 +480,7 @@ void irdma_free_cqp_request(struct irdma_cqp *cqp,
 	if (cqp_request->dynamic) {
 		kfree(cqp_request);
 	} else {
-		WRITE_ONCE(cqp_request->request_done, false);
+		reinit_completion(&cqp_request->comp);
 		cqp_request->callback_fcn = NULL;
 		cqp_request->waiting = false;
 		cqp_request->pending = false;
@@ -515,8 +515,7 @@ irdma_free_pending_cqp_request(struct irdma_cqp *cqp,
 {
 	if (cqp_request->waiting) {
 		cqp_request->compl_info.error = true;
-		WRITE_ONCE(cqp_request->request_done, true);
-		wake_up(&cqp_request->waitq);
+		complete_all(&cqp_request->comp);
 	}
 	wait_event_timeout(cqp->remove_wq,
 			   refcount_read(&cqp_request->refcnt) == 1, 1000);
@@ -609,9 +608,8 @@ static int irdma_wait_event(struct irdma_pci_f *rf,
 	cqp_timeout.compl_cqp_cmds = atomic64_read(&rf->sc_dev.cqp->completed_ops);
 	do {
 		irdma_cqp_ce_handler(rf, &rf->ccq.sc_cq);
-		if (wait_event_timeout(cqp_request->waitq,
-				       READ_ONCE(cqp_request->request_done),
-				       msecs_to_jiffies(CQP_COMPL_WAIT_TIME_MS)))
+		if (wait_for_completion_timeout(&cqp_request->comp,
+					msecs_to_jiffies(CQP_COMPL_WAIT_TIME_MS)))
 			break;
 
 		if (cqp_request->pending)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0819/2077] net: serialize netif_running() check in enqueue_to_backlog()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (817 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0818/2077] RDMA/irdma: Replace waitqueue and flag with completion Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0820/2077] ksmbd: fix use-after-free in same_client_has_lease() Greg Kroah-Hartman
                   ` (178 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+965506b59a2de0b6905c,
	Eric Dumazet, Julian Anastasov, Kuniyuki Iwashima, Jakub Kicinski,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 46762cefe7f4e5bffc1eb467810a7bbb02e461d7 ]

Syzbot reported a KASAN slab-use-after-free in fib_rules_lookup().

The root cause is a race condition where packets can escape the backlog
flushing during device unregistration (e.g., during netns exit).

Commit e9e4dd3267d0 ("net: do not process device backlog during unregistration")
introduced a lockless netif_running() check in enqueue_to_backlog() to
prevent queuing packets to an unregistering device.

However, this creates a TOCTOU race window.

A lockless transmitter (like veth_xmit) can pass
the check before dev_close() clears IFF_UP. If the transmitter is then
delayed, flush_all_backlogs() can run and finish before the transmitter
grabs the backlog lock and queues the packet. The packet then escapes
the flush and triggers UAF later when processed.

Fix this by moving the netif_running() check inside the backlog lock.
This serializes the check with the flush work (which also grabs the lock).
We then either queue the packet before the flush runs (so it gets flushed),
or check netif_running() after the flush/close completes (so it gets dropped).

Fixes: e9e4dd3267d0 ("net: do not process device backlog during unregistration")
Reported-by: syzbot+965506b59a2de0b6905c@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6a315824.b0403584.28d0ff.0000.GAE@google.com/T/#u
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Julian Anastasov <ja@ssi.bg>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20260616141317.407791-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/core/dev.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/net/core/dev.c b/net/core/dev.c
index 731e661d7be657..f81ce83fb3250d 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -5381,8 +5381,6 @@ static int enqueue_to_backlog(struct sk_buff *skb, int cpu,
 	u32 tail;
 
 	reason = SKB_DROP_REASON_DEV_READY;
-	if (unlikely(!netif_running(skb->dev)))
-		goto bad_dev;
 
 	sd = &per_cpu(softnet_data, cpu);
 
@@ -5394,6 +5392,10 @@ static int enqueue_to_backlog(struct sk_buff *skb, int cpu,
 	backlog_lock_irq_save(sd, &flags);
 	qlen = skb_queue_len(&sd->input_pkt_queue);
 	if (likely(qlen <= max_backlog)) {
+		if (unlikely(!netif_running(skb->dev))) {
+			backlog_unlock_irq_restore(sd, flags);
+			goto bad_dev;
+		}
 		if (!qlen) {
 			/* Schedule NAPI for backlog device. We can use
 			 * non atomic operation as we own the queue lock.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0820/2077] ksmbd: fix use-after-free in same_client_has_lease()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (818 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0819/2077] net: serialize netif_running() check in enqueue_to_backlog() Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0821/2077] mfd: bd72720: Drop BUCK11 ID Greg Kroah-Hartman
                   ` (177 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Namjae Jeon,
	Steve French, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guangshuo Li <lgs201920130244@gmail.com>

[ Upstream commit 65b655f65c3ca1ab5d598d3832bb0ff531725858 ]

same_client_has_lease() returns an opinfo pointer from ci->m_op_list
after dropping ci->m_lock without taking a reference.

smb_grant_oplock() then dereferences that pointer in copy_lease() and
when checking breaking_cnt. A concurrent close can remove the old lease
from ci->m_op_list and drop the last reference before the caller uses
the returned pointer, leading to a use-after-free.

Take a reference when same_client_has_lease() selects an existing lease,
drop any previous match while scanning, and release the returned
reference in smb_grant_oplock() after copying the lease state.

Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/smb/server/oplock.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/fs/smb/server/oplock.c b/fs/smb/server/oplock.c
index b193dde4810dca..60e7e821c2455d 100644
--- a/fs/smb/server/oplock.c
+++ b/fs/smb/server/oplock.c
@@ -528,7 +528,12 @@ static struct oplock_info *same_client_has_lease(struct ksmbd_inode *ci,
 
 		ret = compare_guid_key(opinfo, client_guid, lctx->lease_key);
 		if (ret) {
+			if (!atomic_inc_not_zero(&opinfo->refcount))
+				continue;
+			if (m_opinfo)
+				opinfo_put(m_opinfo);
 			m_opinfo = opinfo;
+
 			/* skip upgrading lease about breaking lease */
 			if (atomic_read(&opinfo->breaking_cnt))
 				continue;
@@ -1246,6 +1251,7 @@ int smb_grant_oplock(struct ksmbd_work *work, int req_op_level, u64 pid,
 			if (atomic_read(&m_opinfo->breaking_cnt))
 				opinfo->o_lease->flags =
 					SMB2_LEASE_FLAG_BREAK_IN_PROGRESS_LE;
+			opinfo_put(m_opinfo);
 			goto out;
 		}
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0821/2077] mfd: bd72720: Drop BUCK11 ID
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (819 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0820/2077] ksmbd: fix use-after-free in same_client_has_lease() Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0822/2077] mfd: rsmu: Fix page register setup Greg Kroah-Hartman
                   ` (176 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Matti Vaittinen, Lee Jones,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matti Vaittinen <mazziesaccount@gmail.com>

[ Upstream commit 6a2cb13761d90ef3fa960db189a2cc1bdf965ae1 ]

The BD72720 header reserves an ID for BUCK11. While this does not (at
the moment) cause problems I can see, it is misleading as the BD72720
contains only 10 BUCKs.

Make the code clearer and drop the BUCK11 ID.

Fixes: af25277b1ddc ("mfd: rohm-bd71828: Support ROHM BD72720")
Signed-off-by: Matti Vaittinen <mazziesaccount@gmail.com>
Link: https://patch.msgid.link/812c3749a18d609d6f4698506bc516ec7183dfdd.1775565298.git.mazziesaccount@gmail.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/mfd/rohm-bd72720.h | 1 -
 1 file changed, 1 deletion(-)

diff --git a/include/linux/mfd/rohm-bd72720.h b/include/linux/mfd/rohm-bd72720.h
index ae7343bcab064c..d8ddbf232bb3ee 100644
--- a/include/linux/mfd/rohm-bd72720.h
+++ b/include/linux/mfd/rohm-bd72720.h
@@ -21,7 +21,6 @@ enum {
 	BD72720_BUCK8,
 	BD72720_BUCK9,
 	BD72720_BUCK10,
-	BD72720_BUCK11,
 	BD72720_LDO1,
 	BD72720_LDO2,
 	BD72720_LDO3,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0822/2077] mfd: rsmu: Fix page register setup
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (820 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0821/2077] mfd: bd72720: Drop BUCK11 ID Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0823/2077] mfd: cs42l43: Sanity check firmware size Greg Kroah-Hartman
                   ` (175 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Matthew Bystrin, Lee Jones,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matthew Bystrin <dev.mbstr@gmail.com>

[ Upstream commit 6bc38f26ed07197b11a2b588edf1f43bfbc81d76 ]

Fix writes to page register in 8A3400x family (Clock Matrix).

All calls to rsmu_write_page_register() (both in i2c and spi) have
resulted in early return, because all addresses in
include/linux/mfd/idt8a340_reg.h are less than RSMU_CM_SCSR_BASE.

There were 2 separate patch series which have to be merged in one time:
mfd and ptp. The latter have been merged, the former[1] have not.

Link: https://lore.kernel.org/netdev/LV3P220MB1202F8E2FCCFBA2519B4966EA0192@LV3P220MB1202.NAMP220.PROD.OUTLOOK.COM/
Fixes: 67d6c76fc815 ("mfd: rsmu: Support 32-bit address space")
Signed-off-by: Matthew Bystrin <dev.mbstr@gmail.com>
Link: https://patch.msgid.link/20260429072047.1111427-2-dev.mbstr@gmail.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/mfd/rsmu_i2c.c | 6 +-----
 drivers/mfd/rsmu_spi.c | 5 +----
 2 files changed, 2 insertions(+), 9 deletions(-)

diff --git a/drivers/mfd/rsmu_i2c.c b/drivers/mfd/rsmu_i2c.c
index cba64f107a2fd1..9e5fc8259eec2e 100644
--- a/drivers/mfd/rsmu_i2c.c
+++ b/drivers/mfd/rsmu_i2c.c
@@ -134,14 +134,10 @@ static int rsmu_i2c_write_device(struct rsmu_ddata *rsmu, u8 reg, u8 *buf, u8 by
 static int rsmu_write_page_register(struct rsmu_ddata *rsmu, u32 reg,
 				    rsmu_rw_device rsmu_write_device)
 {
-	u32 page = reg & RSMU_CM_PAGE_MASK;
+	u32 page = (reg | RSMU_CM_SCSR_BASE) & RSMU_CM_PAGE_MASK;
 	u8 buf[4];
 	int err;
 
-	/* Do not modify offset register for none-scsr registers */
-	if (reg < RSMU_CM_SCSR_BASE)
-		return 0;
-
 	/* Simply return if we are on the same page */
 	if (rsmu->page == page)
 		return 0;
diff --git a/drivers/mfd/rsmu_spi.c b/drivers/mfd/rsmu_spi.c
index 39d9be1e141fb6..c931d8cea0a1a9 100644
--- a/drivers/mfd/rsmu_spi.c
+++ b/drivers/mfd/rsmu_spi.c
@@ -101,11 +101,8 @@ static int rsmu_write_page_register(struct rsmu_ddata *rsmu, u32 reg)
 
 	switch (rsmu->type) {
 	case RSMU_CM:
-		/* Do not modify page register for none-scsr registers */
-		if (reg < RSMU_CM_SCSR_BASE)
-			return 0;
 		page_reg = RSMU_CM_PAGE_ADDR;
-		page = reg & RSMU_PAGE_MASK;
+		page = (reg | RSMU_CM_SCSR_BASE) & RSMU_PAGE_MASK;
 		buf[0] = (u8)(page & 0xFF);
 		buf[1] = (u8)((page >> 8) & 0xFF);
 		buf[2] = (u8)((page >> 16) & 0xFF);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0823/2077] mfd: cs42l43: Sanity check firmware size
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (821 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0822/2077] mfd: rsmu: Fix page register setup Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0824/2077] ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write Greg Kroah-Hartman
                   ` (174 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Charles Keepax, Lee Jones,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Charles Keepax <ckeepax@opensource.cirrus.com>

[ Upstream commit b6ef1a74b3ec254f87a6a3c554fe8f8083ebd37c ]

Currently the code checks if a firmware was received, however it does
not verify that the firmware size is larger than the firmware header. As
the firmware pointer is dereferenced as a pointer to the header
structure this could lead to an out of bounds memory access. Add the
missing check.

Fixes: ace6d1448138 ("mfd: cs42l43: Add support for cs42l43 core driver")
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Link: https://patch.msgid.link/20260508134804.1787461-1-ckeepax@opensource.cirrus.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/mfd/cs42l43.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/mfd/cs42l43.c b/drivers/mfd/cs42l43.c
index 166881751e698a..ed6d93893de04d 100644
--- a/drivers/mfd/cs42l43.c
+++ b/drivers/mfd/cs42l43.c
@@ -722,7 +722,7 @@ static void cs42l43_mcu_load_firmware(const struct firmware *firmware, void *con
 	unsigned int loadaddr, val;
 	int ret;
 
-	if (!firmware) {
+	if (!firmware || firmware->size < sizeof(*hdr)) {
 		dev_err(cs42l43->dev, "Failed to load firmware\n");
 		cs42l43->firmware_error = -ENODEV;
 		goto err;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0824/2077] ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (822 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0823/2077] mfd: cs42l43: Sanity check firmware size Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0825/2077] 9p: avoid returning ERR_PTR(0) from mkdir operations Greg Kroah-Hartman
                   ` (173 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+b225d4dfce6219600c42,
	Aleksandr Nogikh, Heming Zhao, Mark Fasheh, Joel Becker,
	Junxiao Bi, Joseph Qi, Changwei Ge, Jun Piao, Andrew Morton,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aleksandr Nogikh <nogikh@google.com>

[ Upstream commit ff6f26c58421614b02694ac9d219ac61d924bc68 ]

A circular locking dependency involves INODE_ALLOC_SYSTEM_INODE,
EXTENT_ALLOC_SYSTEM_INODE, and ORPHAN_DIR_SYSTEM_INODE.

1. ocfs2_mknod() acquires INODE_ALLOC then EXTENT_ALLOC.

2. ocfs2_dio_end_io_write() acquires EXTENT_ALLOC for unwritten
   extents, then ORPHAN_DIR via ocfs2_del_inode_from_orphan() while still
   holding EXTENT_ALLOC.

3. ocfs2_wipe_inode() acquires ORPHAN_DIR then INODE_ALLOC via
   ocfs2_remove_inode.

Break the cycle in ocfs2_dio_end_io_write() by freeing the allocation
contexts (releasing EXTENT_ALLOC) before acquiring ORPHAN_DIR.

WARNING: possible circular locking dependency detected
------------------------------------------------------
is trying to acquire lock:
ffff8881e78b33a0
(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}, at:
ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299

but task is already holding lock:
ffff8881e78b4fa0
(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}, at:
ocfs2_evict_inode+0xe97/0x43b0 fs/ocfs2/inode.c:1299

the existing dependency chain (in reverse order) is:

-> #2 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}:
       inode_lock include/linux/fs.h:1029 [inline]
       ocfs2_del_inode_from_orphan+0x12e/0x7a0 fs/ocfs2/namei.c:2728
       ocfs2_dio_end_io+0xf9c/0x1370 fs/ocfs2/aops.c:2418
       dio_complete+0x25b/0x790 fs/direct-io.c:281

-> #1 (&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:
       inode_lock include/linux/fs.h:1029 [inline]
       ocfs2_reserve_suballoc_bits+0x16d/0x4840 fs/ocfs2/suballoc.c:882
       ocfs2_reserve_new_metadata_blocks+0x415/0x9a0
       fs/ocfs2/suballoc.c:1078
       ocfs2_mknod+0x10f3/0x2260 fs/ocfs2/namei.c:351

-> #0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:
       __lock_acquire+0x15a5/0x2cf0 kernel/locking/lockdep.c:5237
       lock_acquire+0x106/0x350 kernel/locking/lockdep.c:5868
       down_write+0x96/0x200 kernel/locking/rwsem.c:1625
       inode_lock include/linux/fs.h:1029 [inline]
       ocfs2_remove_inode fs/ocfs2/inode.c:733 [inline]
       ocfs2_wipe_inode fs/ocfs2/inode.c:896 [inline]
       ocfs2_delete_inode fs/ocfs2/inode.c:1157 [inline]
       ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299

Chain exists of:
  &ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE] -->
  &ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE] -->
  &ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]

 Possible unsafe locking scenario:

       CPU0                    CPU1
       ----                    ----
  lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);
                               lock(&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]);
                               lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);
  lock(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]);

 *** DEADLOCK ***

Link: https://lore.kernel.org/97c902a6-3bcf-43ea-9b70-f1f136a6c3f2@mail.kernel.org
Fixes: d647c5b2fbf8 ("ocfs2: split transactions in dio completion to avoid credit exhaustion")
Assisted-by: Gemini:gemini-3.1-pro-preview Gemini:gemini-3-flash-preview syzbot
Reported-by: syzbot+b225d4dfce6219600c42@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b225d4dfce6219600c42
Link: https://syzkaller.appspot.com/ai_job?id=0b53ce1e-2972-4192-aa85-8097a702762c
Signed-off-by: Aleksandr Nogikh <nogikh@google.com>
Reviewed-by: Heming Zhao <heming.zhao@suse.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Joseph Qi <jiangqi903@gmail.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ocfs2/aops.c | 13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

diff --git a/fs/ocfs2/aops.c b/fs/ocfs2/aops.c
index 6ec198bdab1211..4acdbb70882cdf 100644
--- a/fs/ocfs2/aops.c
+++ b/fs/ocfs2/aops.c
@@ -2372,6 +2372,15 @@ static int ocfs2_dio_end_io_write(struct inode *inode,
 unlock:
 	up_write(&oi->ip_alloc_sem);
 
+	if (data_ac) {
+		ocfs2_free_alloc_context(data_ac);
+		data_ac = NULL;
+	}
+	if (meta_ac) {
+		ocfs2_free_alloc_context(meta_ac);
+		meta_ac = NULL;
+	}
+
 	/* everything looks good, let's start the cleanup */
 	if (!ret && dwc->dw_orphaned) {
 		BUG_ON(dwc->dw_writer_pid != task_pid_nr(current));
@@ -2383,10 +2392,6 @@ static int ocfs2_dio_end_io_write(struct inode *inode,
 	ocfs2_inode_unlock(inode, 1);
 	brelse(di_bh);
 out:
-	if (data_ac)
-		ocfs2_free_alloc_context(data_ac);
-	if (meta_ac)
-		ocfs2_free_alloc_context(meta_ac);
 	ocfs2_run_deallocs(osb, &dealloc);
 	ocfs2_dio_free_write_ctx(inode, dwc);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0825/2077] 9p: avoid returning ERR_PTR(0) from mkdir operations
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (823 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0824/2077] ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0826/2077] net/9p: fix race condition on rdma->state in trans_rdma.c Greg Kroah-Hartman
                   ` (172 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Laight, Christian Schoenebeck,
	Hongling Zeng, Dominique Martinet, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hongling Zeng <zenghongling@kylinos.cn>

[ Upstream commit 314b58c01a9047567fd19446ca5fd46c473b89ff ]

When mkdir succeeds, v9fs_vfs_mkdir_dotl() and v9fs_vfs_mkdir() return
ERR_PTR(0) which is incorrect. They should return NULL instead for
success and ERR_PTR() only with negative error codes for failure.

Return NULL instead of passing to ERR_PTR while err is zero
Fixes smatch warnings:
  fs/9p/vfs_inode_dotl.c:420 v9fs_vfs_mkdir_dotl() warn: passing zero to 'ERR_PTR'
  fs/9p/vfs_inode.c:695 v9fs_vfs_mkdir() warn: passing zero to 'ERR_PTR'

The v9fs_vfs_mkdir() code was further simplified because v9fs_create()
can never return NULL, so we do not need to check for fid being set
separately, and the error path can be a simple return immediately after
v9fs_create() failure.
There is no intended functional change.

Fixes: 88d5baf69082 ("Change inode_operations.mkdir to return struct dentry *")
Suggested-by: David Laight <david.laight.linux@gmail.com>
Acked-by: Christian Schoenebeck <linux_oss@crudebyte.com>
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Message-ID: <20260520022650.14217-1-zenghongling@kylinos.cn>
Signed-off-by: Dominique Martinet <asmadeus@codewreck.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/9p/vfs_inode.c      | 19 ++++++-------------
 fs/9p/vfs_inode_dotl.c |  4 ++--
 2 files changed, 8 insertions(+), 15 deletions(-)

diff --git a/fs/9p/vfs_inode.c b/fs/9p/vfs_inode.c
index f468acb8ee7df6..cdaa259af16de7 100644
--- a/fs/9p/vfs_inode.c
+++ b/fs/9p/vfs_inode.c
@@ -672,27 +672,20 @@ v9fs_vfs_create(struct mnt_idmap *idmap, struct inode *dir,
 static struct dentry *v9fs_vfs_mkdir(struct mnt_idmap *idmap, struct inode *dir,
 				     struct dentry *dentry, umode_t mode)
 {
-	int err;
 	u32 perm;
 	struct p9_fid *fid;
 	struct v9fs_session_info *v9ses;
 
 	p9_debug(P9_DEBUG_VFS, "name %pd\n", dentry);
-	err = 0;
 	v9ses = v9fs_inode2v9ses(dir);
 	perm = unixmode2p9mode(v9ses, mode | S_IFDIR);
 	fid = v9fs_create(v9ses, dir, dentry, NULL, perm, P9_OREAD);
-	if (IS_ERR(fid)) {
-		err = PTR_ERR(fid);
-		fid = NULL;
-	} else {
-		inc_nlink(dir);
-		v9fs_invalidate_inode_attr(dir);
-	}
-
-	if (fid)
-		p9_fid_put(fid);
-	return ERR_PTR(err);
+	if (IS_ERR(fid))
+		return ERR_CAST(fid);
+	inc_nlink(dir);
+	v9fs_invalidate_inode_attr(dir);
+	p9_fid_put(fid);
+	return NULL;
 }
 
 /**
diff --git a/fs/9p/vfs_inode_dotl.c b/fs/9p/vfs_inode_dotl.c
index 141fb54db65d2f..e90808808ea571 100644
--- a/fs/9p/vfs_inode_dotl.c
+++ b/fs/9p/vfs_inode_dotl.c
@@ -349,7 +349,7 @@ static struct dentry *v9fs_vfs_mkdir_dotl(struct mnt_idmap *idmap,
 					  struct inode *dir, struct dentry *dentry,
 					  umode_t omode)
 {
-	int err;
+	int err = 0;
 	struct v9fs_session_info *v9ses;
 	struct p9_fid *fid = NULL, *dfid = NULL;
 	kgid_t gid;
@@ -412,7 +412,7 @@ static struct dentry *v9fs_vfs_mkdir_dotl(struct mnt_idmap *idmap,
 	p9_fid_put(fid);
 	v9fs_put_acl(dacl, pacl);
 	p9_fid_put(dfid);
-	return ERR_PTR(err);
+	return err ? ERR_PTR(err) : NULL;
 }
 
 static int
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0826/2077] net/9p: fix race condition on rdma->state in trans_rdma.c
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (824 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0825/2077] 9p: avoid returning ERR_PTR(0) from mkdir operations Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0827/2077] 9p: Add missing read barrier in virtio zero-copy path Greg Kroah-Hartman
                   ` (171 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yizhou Zhao, Yuxiang Yang, Ao Wang,
	Xuewei Feng, Qi Li, Ke Xu, Dominique Martinet, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>

[ Upstream commit 7d54894a1ee265a72d70f7cae1da6cc774cccc71 ]

The rdma->state field is modified without holding req_lock in both
recv_done() and p9_cm_event_handler(), while rdma_request() accesses
the same field under the req_lock spinlock. This inconsistent locking
creates a race condition:

- recv_done() running in softirq completion context sets
  rdma->state = P9_RDMA_FLUSHING without acquiring req_lock

- p9_cm_event_handler() modifies rdma->state at multiple points
  (ADDR_RESOLVED, ROUTE_RESOLVED, ESTABLISHED, CLOSED) without
  req_lock

- rdma_request() uses spin_lock_irqsave(&rdma->req_lock, flags) to
  protect the read-modify-write of rdma->state

The race can cause lost state transitions: recv_done() or the CM
event handler could set state to FLUSHING/CLOSED while rdma_request()
is concurrently checking or modifying state under the lock, leading to
the FLUSHING transition being silently overwritten by CLOSING. This
corrupts the connection state machine and can cause use-after-free on
RDMA request objects during teardown.

Fix by adding req_lock protection to all rdma->state modifications in
recv_done() and p9_cm_event_handler(), matching the pattern already
used in rdma_request(). Use spin_lock_irqsave/spin_unlock_irqrestore
in the CM event handler since it can race with recv_done() which runs
in softirq context.

Tested with a kernel module that races two threads (simulating
rdma_request and recv_done/CM handler) on rdma->state with proper
locking: 5.5M+ FLUSHING writes over 27M iterations with 0 lost
transitions.

Fixes: 473c7dd1d7b5 ("9p/rdma: remove useless check in cm_event_handler")
Reported-by: Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
Reported-by: Yuxiang Yang <yangyx22@mails.tsinghua.edu.cn>
Reported-by: Ao Wang <wangao@seu.edu.cn>
Reported-by: Xuewei Feng <fengxw06@126.com>
Reported-by: Qi Li <qli01@tsinghua.edu.cn>
Reported-by: Ke Xu <xuke@tsinghua.edu.cn>
Assisted-by: GLM:GLM-5.1
Signed-off-by: Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
Message-ID: <20260529073933.77315-1-zhaoyz24@mails.tsinghua.edu.cn>
Signed-off-by: Dominique Martinet <asmadeus@codewreck.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/9p/trans_rdma.c | 19 +++++++++++++++++--
 1 file changed, 17 insertions(+), 2 deletions(-)

diff --git a/net/9p/trans_rdma.c b/net/9p/trans_rdma.c
index aa5bd74d333f3b..b4274f10fa4487 100644
--- a/net/9p/trans_rdma.c
+++ b/net/9p/trans_rdma.c
@@ -128,25 +128,36 @@ p9_cm_event_handler(struct rdma_cm_id *id, struct rdma_cm_event *event)
 {
 	struct p9_client *c = id->context;
 	struct p9_trans_rdma *rdma = c->trans;
+	unsigned long flags;
+
 	switch (event->event) {
 	case RDMA_CM_EVENT_ADDR_RESOLVED:
+		spin_lock_irqsave(&rdma->req_lock, flags);
 		BUG_ON(rdma->state != P9_RDMA_INIT);
 		rdma->state = P9_RDMA_ADDR_RESOLVED;
+		spin_unlock_irqrestore(&rdma->req_lock, flags);
 		break;
 
 	case RDMA_CM_EVENT_ROUTE_RESOLVED:
+		spin_lock_irqsave(&rdma->req_lock, flags);
 		BUG_ON(rdma->state != P9_RDMA_ADDR_RESOLVED);
 		rdma->state = P9_RDMA_ROUTE_RESOLVED;
+		spin_unlock_irqrestore(&rdma->req_lock, flags);
 		break;
 
 	case RDMA_CM_EVENT_ESTABLISHED:
+		spin_lock_irqsave(&rdma->req_lock, flags);
 		BUG_ON(rdma->state != P9_RDMA_ROUTE_RESOLVED);
 		rdma->state = P9_RDMA_CONNECTED;
+		spin_unlock_irqrestore(&rdma->req_lock, flags);
 		break;
 
 	case RDMA_CM_EVENT_DISCONNECTED:
-		if (rdma)
+		if (rdma) {
+			spin_lock_irqsave(&rdma->req_lock, flags);
 			rdma->state = P9_RDMA_CLOSED;
+			spin_unlock_irqrestore(&rdma->req_lock, flags);
+		}
 		c->status = Disconnected;
 		break;
 
@@ -184,6 +195,7 @@ recv_done(struct ib_cq *cq, struct ib_wc *wc)
 	struct p9_req_t *req;
 	int err = 0;
 	int16_t tag;
+	unsigned long flags;
 
 	req = NULL;
 	ib_dma_unmap_single(rdma->cm_id->device, c->busa, client->msize,
@@ -220,7 +232,10 @@ recv_done(struct ib_cq *cq, struct ib_wc *wc)
  err_out:
 	p9_debug(P9_DEBUG_ERROR, "req %p err %d status %d\n",
 			req, err, wc->status);
-	rdma->state = P9_RDMA_FLUSHING;
+	spin_lock_irqsave(&rdma->req_lock, flags);
+	if (rdma->state < P9_RDMA_FLUSHING)
+		rdma->state = P9_RDMA_FLUSHING;
+	spin_unlock_irqrestore(&rdma->req_lock, flags);
 	client->status = Disconnected;
 	goto out;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0827/2077] 9p: Add missing read barrier in virtio zero-copy path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (825 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0826/2077] net/9p: fix race condition on rdma->state in trans_rdma.c Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0828/2077] eventpoll: expand top-of-file overview / locking doc Greg Kroah-Hartman
                   ` (170 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Gui-Dong Han, Dominique Martinet,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Gui-Dong Han <hanguidong02@gmail.com>

[ Upstream commit aa88278693cbfaf7a2acf961379973fbb63b165c ]

Commit 2b6e72ed747f ("9P: Add memory barriers to protect request
fields over cb/rpc threads handoff") added a read barrier after
p9_client_rpc() waits for req->status, pairing with the write barrier in
p9_client_cb(). The virtio zero-copy wait path was missed.

Add the same read barrier after the zero-copy wait before reading the
completed request.

Fixes: 2b6e72ed747f ("9P: Add memory barriers to protect request fields over cb/rpc threads handoff")
Signed-off-by: Gui-Dong Han <hanguidong02@gmail.com>
Message-ID: <20260529075441.233369-1-hanguidong02@gmail.com>
Signed-off-by: Dominique Martinet <asmadeus@codewreck.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/9p/trans_virtio.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/net/9p/trans_virtio.c b/net/9p/trans_virtio.c
index 4cdab7094b273a..b0d0094ec8e2c8 100644
--- a/net/9p/trans_virtio.c
+++ b/net/9p/trans_virtio.c
@@ -532,6 +532,11 @@ p9_virtio_zc_request(struct p9_client *client, struct p9_req_t *req,
 	p9_debug(P9_DEBUG_TRANS, "virtio request kicked\n");
 	err = io_wait_event_killable(req->wq,
 				     READ_ONCE(req->status) >= REQ_STATUS_RCVD);
+	/*
+	 * Make sure our req is coherent with regard to updates in other
+	 * threads - echoes to wmb() in the callback
+	 */
+	smp_rmb();
 	// RERROR needs reply (== error string) in static data
 	if (READ_ONCE(req->status) == REQ_STATUS_RCVD &&
 	    unlikely(req->rc.sdata[4] == P9_RERROR))
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0828/2077] eventpoll: expand top-of-file overview / locking doc
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (826 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0827/2077] 9p: Add missing read barrier in virtio zero-copy path Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0829/2077] eventpoll: rename epi->next and txlist for clarity Greg Kroah-Hartman
                   ` (169 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Brauner (Amutable),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Brauner <brauner@kernel.org>

[ Upstream commit 7c25a0bd4bf7139944c5893ff61211f4b5a3455e ]

The existing ~40-line "LOCKING:" banner covered the three-level lock
hierarchy (epnested_mutex > ep->mtx > ep->lock) but nothing else.
Lifetime rules, the ready-list state machine, the three removal paths,
and the POLLFREE contract are implicit in the code. The recent UAF
series (a6dc643c6931, 07712db80857, 8c2e52ebbe88, f2e467a48287) rode
on invariants that were only implicit.

Codify them at the top of the file: the subsystem overview, the lock
hierarchy and its mutex_lock_nested() subclass convention (reworded
from the old banner), a field-protection table for struct eventpoll
and struct epitem that names the two faces of the rbn/rcu union (rbn
under ep->mtx while linked into ep->rbr; rcu touched only by
kfree_rcu(epi) on the free path), the ovflist sentinel encoding and
scan-flip invariants, the three removal paths (A ep_remove, B
ep_clear_and_put, C eventpoll_release_file) and the epi_fget() pin
that orchestrates A vs C, and the POLLFREE store-release /
load-acquire handshake.

No functional change.

Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Link: https://patch.msgid.link/20260424-work-epoll-rework-v1-1-249ed00a20f3@kernel.org
Signed-off-by: Christian Brauner <brauner@kernel.org>
Stable-dep-of: 0c4aefe3c2d0 ("eventpoll: Fix epoll_wait() report false negative")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/eventpoll.c | 199 ++++++++++++++++++++++++++++++++++++++++---------
 1 file changed, 162 insertions(+), 37 deletions(-)

diff --git a/fs/eventpoll.c b/fs/eventpoll.c
index dc8dc529684bfb..9cd6b3511f065a 100644
--- a/fs/eventpoll.c
+++ b/fs/eventpoll.c
@@ -41,45 +41,170 @@
 #include <net/busy_poll.h>
 
 /*
- * LOCKING:
- * There are three level of locking required by epoll :
+ * fs/eventpoll.c - Efficient event polling ("epoll") kernel implementation.
  *
- * 1) epnested_mutex (mutex)
- * 2) ep->mtx (mutex)
- * 3) ep->lock (spinlock)
  *
- * The acquire order is the one listed above, from 1 to 3.
- * We need a spinlock (ep->lock) because we manipulate objects
- * from inside the poll callback, that might be triggered from
- * a wake_up() that in turn might be called from IRQ context.
- * So we can't sleep inside the poll callback and hence we need
- * a spinlock. During the event transfer loop (from kernel to
- * user space) we could end up sleeping due a copy_to_user(), so
- * we need a lock that will allow us to sleep. This lock is a
- * mutex (ep->mtx). It is acquired during the event transfer loop,
- * during epoll_ctl(EPOLL_CTL_DEL) and during eventpoll_release_file().
- * The epnested_mutex is acquired when inserting an epoll fd onto another
- * epoll fd. We do this so that we walk the epoll tree and ensure that this
- * insertion does not create a cycle of epoll file descriptors, which
- * could lead to deadlock. We need a global mutex to prevent two
- * simultaneous inserts (A into B and B into A) from racing and
- * constructing a cycle without either insert observing that it is
- * going to.
- * It is necessary to acquire multiple "ep->mtx"es at once in the
- * case when one epoll fd is added to another. In this case, we
- * always acquire the locks in the order of nesting (i.e. after
- * epoll_ctl(e1, EPOLL_CTL_ADD, e2), e1->mtx will always be acquired
- * before e2->mtx). Since we disallow cycles of epoll file
- * descriptors, this ensures that the mutexes are well-ordered. In
- * order to communicate this nesting to lockdep, when walking a tree
- * of epoll file descriptors, we use the current recursion depth as
- * the lockdep subkey.
- * It is possible to drop the "ep->mtx" and to use the global
- * mutex "epnested_mutex" (together with "ep->lock") to have it working,
- * but having "ep->mtx" will make the interface more scalable.
- * Events that require holding "epnested_mutex" are very rare, while for
- * normal operations the epoll private "ep->mtx" will guarantee
- * a better scalability.
+ * Overview
+ * --------
+ *
+ * Each epoll_create(2) returns an anonymous [eventpoll] file whose
+ * ->private_data is a struct eventpoll. Each EPOLL_CTL_ADD installs
+ * a struct epitem linking one (watched file, fd) pair back to that
+ * eventpoll via the watched file's f_op->poll() wait queue(s). When
+ * the watched file signals readiness, ep_poll_callback() fires and
+ * marks the epitem ready. epoll_wait(2) drains the ready list under
+ * ep->mtx, re-queueing items in level-triggered mode.
+ *
+ * epoll instances can watch other epoll instances up to EP_MAX_NESTS
+ * deep; cycles are forbidden and detected at EPOLL_CTL_ADD time.
+ *
+ *
+ * Locking
+ * -------
+ *
+ * Three levels, acquired from outer to inner:
+ *
+ *   epnested_mutex   (global; rare; taken only for EPOLL_CTL_ADD
+ *                     loop / path checks)
+ *     > ep->mtx     (per-eventpoll; sleepable; serializes most ops)
+ *       > ep->lock  (per-eventpoll; IRQ-safe spinlock)
+ *
+ *   file->f_lock    (per-file; NOT IRQ-safe; guards f_ep hlist ops;
+ *                    nested inside ep->mtx, outside ep->lock)
+ *
+ * Rationale:
+ *   - ep->lock is a spinlock because ep_poll_callback() is called from
+ *     wake_up() which may run in hard-IRQ context. All ep->lock
+ *     critical sections use spin_lock_irqsave().
+ *   - ep->mtx is a sleepable mutex because the event delivery loop
+ *     calls copy_to_user(), and ep_insert() may sleep in
+ *     kmem_cache_alloc() and f_op->poll().
+ *   - epnested_mutex is global because cycle detection needs a global
+ *     view of the epoll topology; a per-object scheme would let two
+ *     concurrent inserts (A into B, B into A) construct a cycle
+ *     without either observer seeing it.
+ *   - Per-ep ep->mtx is preferred for scalability elsewhere. Events
+ *     that require epnested_mutex are rare.
+ *
+ * When EPOLL_CTL_ADD nests one eventpoll inside another we acquire
+ * ep->mtx on both: outer first, target second. Since cycles are
+ * forbidden the set of live ep->mtx holds is always a strict chain,
+ * communicated to lockdep via mutex_lock_nested() subclasses derived
+ * from the current recursion depth.
+ *
+ *
+ * Field protection
+ * ----------------
+ *
+ * struct eventpoll:
+ *   mtx              - self
+ *   rbr              - ep->mtx
+ *   ovflist, rdllist - ep->lock (IRQ-safe)
+ *   wq               - ep->lock for queue mutation
+ *   poll_wait        - internal waitqueue spinlock
+ *   refs             - file->f_lock for adds; ep->mtx for removes;
+ *                      RCU for readers (hlist_del_rcu + kfree_rcu(ep))
+ *   ws               - ep->mtx
+ *   gen, loop_check_depth - epnested_mutex
+ *   file, user       - immutable after setup
+ *   refcount         - atomic (refcount_t)
+ *   napi_*           - READ_ONCE / WRITE_ONCE
+ *
+ * struct epitem:
+ *   rbn / rcu union  - rbn: ep->mtx (while epi is linked in ep->rbr).
+ *                      rcu: written only by kfree_rcu(epi) on the free
+ *                      path; otherwise untouched by epoll code.
+ *   rdllink, next    - ep->lock
+ *   ffd, ep          - immutable after ep_insert()
+ *   pwqlist          - ep->mtx for writes; POLLFREE clears pwq->whead
+ *                      via smp_store_release(), see below
+ *   fllink           - file->f_lock for mutation; hlist_del_rcu +
+ *                      kfree_rcu(epi) for safe RCU readers
+ *   ws               - RCU (rcu_assign_pointer /
+ *                      rcu_dereference_check(mtx))
+ *   event            - ep->mtx for writes; lockless read in
+ *                      ep_poll_callback pairs with smp_mb() in
+ *                      ep_modify()
+ *
+ *
+ * Ready-list state machine
+ * ------------------------
+ *
+ * Readiness is tracked in two lists under ep->lock:
+ *
+ *   rdllist   - doubly-linked FIFO; the "current" ready list.
+ *   ovflist   - singly-linked LIFO; used during a scan to catch
+ *               events that arrive while rdllist is being iterated
+ *               without ep->lock.
+ *
+ * Encoded in ep->ovflist:
+ *   EP_UNACTIVE_PTR - no scan active; callback appends to rdllist.
+ *   NULL            - scan active, no spill yet.
+ *   pointer to epi  - scan active with spilled items (LIFO).
+ *
+ * Encoded in epi->next:
+ *   EP_UNACTIVE_PTR - epi is not on ovflist.
+ *   otherwise       - next epi on ovflist (NULL at tail).
+ *
+ * ep_start_scan() flips "not scanning" to "scanning" and splices
+ * rdllist into a caller-local txlist. ep_done_scan() drains ovflist
+ * back to rdllist (list_add head-insert reverses LIFO to FIFO),
+ * flips back to "not scanning", and re-splices any items the caller
+ * left in txlist (e.g., level-triggered re-queues).
+ *
+ *
+ * Removal paths
+ * -------------
+ *
+ * Three paths dispose of epitems and/or eventpolls:
+ *
+ *   A. ep_remove()              - EPOLL_CTL_DEL and ep_insert()
+ *                                 rollback. Caller holds ep->mtx.
+ *   B. ep_clear_and_put()       - close of the epoll fd itself
+ *                                 (ep_eventpoll_release).
+ *   C. eventpoll_release_file() - close of a watched file, invoked
+ *                                 from __fput().
+ *
+ * Coordination:
+ *   A and C exclude each other via the watched file's refcount.
+ *   A pins the file with epi_fget() before touching file->f_ep or
+ *   file->f_lock; if the pin fails, __fput() is in flight and C
+ *   will clean this epi up. See the epi_fget() block comment.
+ *   A and B both hold ep->mtx serially. B walks the rbtree with
+ *   rb_next() captured before ep_remove() erases the current node.
+ *   B and C both take ep->mtx; the loser sees fewer entries or an
+ *   empty file->f_ep.
+ *
+ * Within every path the internal order is strict:
+ *   ep_unregister_pollwait()  - drain pwqlist; synchronizes with any
+ *                                in-flight ep_poll_callback via the
+ *                                watched wait-queue head's lock.
+ *   ep_remove_file()          - hlist_del_rcu of epi->fllink and,
+ *                                if last watcher, clear file->f_ep,
+ *                                under file->f_lock.
+ *   ep_remove_epi()           - rb_erase, rdllist unlink (ep->lock),
+ *                                wakeup_source_unregister,
+ *                                kfree_rcu(epi).
+ *
+ * kfree_rcu(epi) defers the free past RCU readers in
+ * reverse_path_check_proc(); kfree_rcu(ep) defers past readers in
+ * ep_get_upwards_depth_proc().
+ *
+ *
+ * POLLFREE handshake
+ * ------------------
+ *
+ * When a subsystem tears down a wait-queue head that an epitem is
+ * registered on (binder, signalfd, ...), it wakes the callback with
+ * POLLFREE and must RCU-defer the head's free. The store/load pair:
+ *
+ *   ep_poll_callback() POLLFREE branch:
+ *     smp_store_release(&pwq->whead, NULL)
+ *
+ *   ep_remove_wait_queue():
+ *     smp_load_acquire(&pwq->whead)
+ *
+ * See those sites for the full argument.
  */
 
 /* Epoll private bits inside the event mask */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0829/2077] eventpoll: rename epi->next and txlist for clarity
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (827 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0828/2077] eventpoll: expand top-of-file overview / locking doc Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0830/2077] eventpoll: Fix epoll_wait() report false negative Greg Kroah-Hartman
                   ` (168 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Brauner (Amutable),
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Brauner <brauner@kernel.org>

[ Upstream commit f38567bb63ae029e3b63fcb99b6a2dcc6f421e69 ]

Two list-related names were confusing in isolation:

  struct epitem::next
    A singly-linked link slot used only when an epi is queued on
    ep->ovflist during an ep_start_scan/ep_done_scan window. The
    bare name "next" suggests a generic list link and doesn't say
    which list it belongs to.

  txlist
    The caller-local list_head used by ep_send_events() and
    __ep_eventpoll_poll() to hold the batch of items stolen from
    ep->rdllist for the current scan. "txlist" ("transmission
    list") is abbreviated and overloaded: it doesn't distinguish
    itself from ep->rdllist or ep->ovflist at a glance.

Rename for what each actually is:

  struct epitem::next   -> struct epitem::ovflist_next
  local txlist          -> scan_batch

With these in place:
  - epi->ovflist_next reads as "this is the ep->ovflist link slot",
    matching the rdllink pattern above it.
  - scan_batch reads as "the batch currently being scanned", clearly
    distinct from rdllist (canonical ready list) and ovflist
    (scan-window overflow).

ep->rdllist and ep->ovflist struct field names are preserved -- they
are long-standing interface-facing identifiers, and the new inline
helpers (ep_is_scanning, epi_on_ovflist, ...) already hide the
sentinel semantics at call sites.

No functional change.

Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Link: https://patch.msgid.link/20260424-work-epoll-rework-v1-15-249ed00a20f3@kernel.org
Signed-off-by: Christian Brauner <brauner@kernel.org>
Stable-dep-of: 0c4aefe3c2d0 ("eventpoll: Fix epoll_wait() report false negative")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/eventpoll.c | 62 ++++++++++++++++++++++++++------------------------
 1 file changed, 32 insertions(+), 30 deletions(-)

diff --git a/fs/eventpoll.c b/fs/eventpoll.c
index 9cd6b3511f065a..c2f97187f9db41 100644
--- a/fs/eventpoll.c
+++ b/fs/eventpoll.c
@@ -142,15 +142,15 @@
  *   NULL            - scan active, no spill yet.
  *   pointer to epi  - scan active with spilled items (LIFO).
  *
- * Encoded in epi->next:
+ * Encoded in epi->ovflist_next:
  *   EP_UNACTIVE_PTR - epi is not on ovflist.
  *   otherwise       - next epi on ovflist (NULL at tail).
  *
  * ep_start_scan() flips "not scanning" to "scanning" and splices
- * rdllist into a caller-local txlist. ep_done_scan() drains ovflist
+ * rdllist into a caller-local scan_batch. ep_done_scan() drains ovflist
  * back to rdllist (list_add head-insert reverses LIFO to FIFO),
  * flips back to "not scanning", and re-splices any items the caller
- * left in txlist (e.g., level-triggered re-queues).
+ * left in scan_batch (e.g., level-triggered re-queues).
  *
  *
  * Removal paths
@@ -261,14 +261,16 @@ struct epitem {
 		struct rcu_head rcu;
 	};
 
-	/* List header used to link this structure to the eventpoll ready list */
+	/* Link on the owning eventpoll's ready list (ep->rdllist). */
 	struct list_head rdllink;
 
 	/*
-	 * Works together "struct eventpoll"->ovflist in keeping the
-	 * single linked chain of items.
+	 * Link on the owning eventpoll's scan-overflow list (ep->ovflist),
+	 * EP_UNACTIVE_PTR when not linked. See epi_on_ovflist() /
+	 * epi_clear_ovflist() and the "Ready-list state machine" section
+	 * in the top-of-file banner.
 	 */
-	struct epitem *next;
+	struct epitem *ovflist_next;
 
 	/* The file descriptor information this item refers to */
 	struct epoll_filefd ffd;
@@ -525,13 +527,13 @@ static inline void ep_exit_scan(struct eventpoll *ep)
 /* True iff @epi is currently linked on its ep's ovflist. */
 static inline bool epi_on_ovflist(const struct epitem *epi)
 {
-	return epi->next != EP_UNACTIVE_PTR;
+	return epi->ovflist_next != EP_UNACTIVE_PTR;
 }
 
 /* Mark @epi as not on any ovflist (init and post-drain). */
 static inline void epi_clear_ovflist(struct epitem *epi)
 {
-	epi->next = EP_UNACTIVE_PTR;
+	epi->ovflist_next = EP_UNACTIVE_PTR;
 }
 
 /**
@@ -884,7 +886,7 @@ static inline void ep_pm_stay_awake_rcu(struct epitem *epi)
  * ep->mutex needs to be held because we could be hit by
  * eventpoll_release_file() and epoll_ctl().
  */
-static void ep_start_scan(struct eventpoll *ep, struct list_head *txlist)
+static void ep_start_scan(struct eventpoll *ep, struct list_head *scan_batch)
 {
 	/*
 	 * Steal the ready list, and re-init the original one to the
@@ -896,13 +898,13 @@ static void ep_start_scan(struct eventpoll *ep, struct list_head *txlist)
 	 */
 	lockdep_assert_irqs_enabled();
 	spin_lock_irq(&ep->lock);
-	list_splice_init(&ep->rdllist, txlist);
+	list_splice_init(&ep->rdllist, scan_batch);
 	ep_enter_scan(ep);
 	spin_unlock_irq(&ep->lock);
 }
 
 static void ep_done_scan(struct eventpoll *ep,
-			 struct list_head *txlist)
+			 struct list_head *scan_batch)
 {
 	struct epitem *epi, *nepi;
 
@@ -913,10 +915,10 @@ static void ep_done_scan(struct eventpoll *ep,
 	 * We re-insert them inside the main ready-list here.
 	 */
 	for (nepi = READ_ONCE(ep->ovflist); (epi = nepi) != NULL; ) {
-		nepi = epi->next;
+		nepi = epi->ovflist_next;
 		epi_clear_ovflist(epi);
 		/*
-		 * Skip items that the caller already returned via @txlist
+		 * Skip items that the caller already returned via @scan_batch
 		 * -- the list_splice() below takes care of those.
 		 */
 		if (!ep_is_linked(epi)) {
@@ -932,9 +934,9 @@ static void ep_done_scan(struct eventpoll *ep,
 	ep_exit_scan(ep);
 
 	/*
-	 * Quickly re-inject items left on "txlist".
+	 * Quickly re-inject items left on "scan_batch".
 	 */
-	list_splice(txlist, &ep->rdllist);
+	list_splice(scan_batch, &ep->rdllist);
 	__pm_relax(ep->ws);
 
 	if (!list_empty(&ep->rdllist)) {
@@ -1155,7 +1157,7 @@ static __poll_t ep_item_poll(const struct epitem *epi, poll_table *pt, int depth
 static __poll_t __ep_eventpoll_poll(struct file *file, poll_table *wait, int depth)
 {
 	struct eventpoll *ep = file->private_data;
-	LIST_HEAD(txlist);
+	LIST_HEAD(scan_batch);
 	struct epitem *epi, *tmp;
 	poll_table pt;
 	__poll_t res = 0;
@@ -1170,8 +1172,8 @@ static __poll_t __ep_eventpoll_poll(struct file *file, poll_table *wait, int dep
 	 * the ready list.
 	 */
 	mutex_lock_nested(&ep->mtx, depth);
-	ep_start_scan(ep, &txlist);
-	list_for_each_entry_safe(epi, tmp, &txlist, rdllink) {
+	ep_start_scan(ep, &scan_batch);
+	list_for_each_entry_safe(epi, tmp, &scan_batch, rdllink) {
 		if (ep_item_poll(epi, &pt, depth + 1)) {
 			res = EPOLLIN | EPOLLRDNORM;
 			break;
@@ -1185,7 +1187,7 @@ static __poll_t __ep_eventpoll_poll(struct file *file, poll_table *wait, int dep
 			list_del_init(&epi->rdllink);
 		}
 	}
-	ep_done_scan(ep, &txlist);
+	ep_done_scan(ep, &scan_batch);
 	mutex_unlock(&ep->mtx);
 	return res;
 }
@@ -1441,7 +1443,7 @@ static int ep_poll_callback(wait_queue_entry_t *wait, unsigned mode, int sync, v
 	 */
 	if (ep_is_scanning(ep)) {
 		if (!epi_on_ovflist(epi)) {
-			epi->next = READ_ONCE(ep->ovflist);
+			epi->ovflist_next = READ_ONCE(ep->ovflist);
 			WRITE_ONCE(ep->ovflist, epi);
 			ep_pm_stay_awake_rcu(epi);
 		}
@@ -1962,7 +1964,7 @@ static int ep_modify(struct eventpoll *ep, struct epitem *epi,
  * next slot), 0 if the re-poll reported no caller-requested events
  * (@epi drops out of the ready list; a future callback will re-add
  * it), or -EFAULT if copy_to_user() faulted (in which case @epi is
- * re-inserted at the head of @txlist so ep_done_scan() merges it
+ * re-inserted at the head of @scan_batch so ep_done_scan() merges it
  * back to rdllist for the next attempt).
  *
  * PM bookkeeping and level-triggered re-queue are handled here.
@@ -1971,7 +1973,7 @@ static int ep_modify(struct eventpoll *ep, struct epitem *epi,
 static int ep_deliver_event(struct eventpoll *ep, struct epitem *epi,
 			    poll_table *pt,
 			    struct epoll_event __user **uevents,
-			    struct list_head *txlist)
+			    struct list_head *scan_batch)
 {
 	struct epoll_event __user *next;
 	struct wakeup_source *ws;
@@ -2009,7 +2011,7 @@ static int ep_deliver_event(struct eventpoll *ep, struct epitem *epi,
 		 * ep_done_scan() splices it onto rdllist for the next
 		 * attempt.
 		 */
-		list_add(&epi->rdllink, txlist);
+		list_add(&epi->rdllink, scan_batch);
 		ep_pm_stay_awake(epi);
 		return -EFAULT;
 	}
@@ -2035,7 +2037,7 @@ static int ep_send_events(struct eventpoll *ep,
 			  struct epoll_event __user *events, int maxevents)
 {
 	struct epitem *epi, *tmp;
-	LIST_HEAD(txlist);
+	LIST_HEAD(scan_batch);
 	poll_table pt;
 	int res = 0;
 
@@ -2050,19 +2052,19 @@ static int ep_send_events(struct eventpoll *ep,
 	init_poll_funcptr(&pt, NULL);
 
 	mutex_lock(&ep->mtx);
-	ep_start_scan(ep, &txlist);
+	ep_start_scan(ep, &scan_batch);
 
 	/*
 	 * We can loop without lock because we are passed a task-private
-	 * txlist; items cannot vanish while we hold ep->mtx.
+	 * scan_batch; items cannot vanish while we hold ep->mtx.
 	 */
-	list_for_each_entry_safe(epi, tmp, &txlist, rdllink) {
+	list_for_each_entry_safe(epi, tmp, &scan_batch, rdllink) {
 		int delivered;
 
 		if (res >= maxevents)
 			break;
 
-		delivered = ep_deliver_event(ep, epi, &pt, &events, &txlist);
+		delivered = ep_deliver_event(ep, epi, &pt, &events, &scan_batch);
 		if (delivered < 0) {
 			if (!res)
 				res = delivered;
@@ -2071,7 +2073,7 @@ static int ep_send_events(struct eventpoll *ep,
 		res += delivered;
 	}
 
-	ep_done_scan(ep, &txlist);
+	ep_done_scan(ep, &scan_batch);
 	mutex_unlock(&ep->mtx);
 
 	return res;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0830/2077] eventpoll: Fix epoll_wait() report false negative
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (828 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0829/2077] eventpoll: rename epi->next and txlist for clarity Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0831/2077] gpiolib: acpi: Only trigger ActiveBoth interrupts on boot Greg Kroah-Hartman
                   ` (167 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mateusz Guzik, Nam Cao,
	Christian Brauner (Amutable), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nam Cao <namcao@linutronix.de>

[ Upstream commit 0c4aefe3c2d0f272a2ad73699a12d4446ffdbe7b ]

ep_events_available() checks for available events by looking at
ep->rdllist and ep_is_scanning(). However, this is done without a lock
and can report false negative if ep_start_scan() or ep_done_scan() are
executed by another task concurrently. For example:
_________________________________________________________________________
                                   |ep_start_scan()
                                   |  list_splice_init(&ep->rdllist, ...)
ep_events_available()              |
  !list_empty_careful(&ep->rdllist)|
  || ep_is_scanning(ep)            |
	                           |  ep_enter_scan(ep)
___________________________________|_____________________________________

Another example:
_________________________________________________________________________
ep_events_available()              |
                                   |ep_start_scan()
                                   |  list_splice_init(&ep->rdllist, ...)
	                           |  ep_enter_scan(ep)
  !list_empty_careful(&ep->rdllist)|
                                   |ep_done_scan()
                                   |  ep_exit_scan(ep)
                                   |  list_splice(..., &ep->rdllist)
  || ep_is_scanning(ep)            |
___________________________________|_____________________________________

In the above examples, ep_events_available() sees no event despite
events being available. In case epoll_wait() is called with timeout=0,
epoll_wait() will wrongly return "no event" to user.

Introduce a sequence lock to resolve this issue.

Measuring the time consumption of 10 million loop iterations doing
epoll_wait(), the following performance drop is observed:

   timeout  #event  before    after    diff
     0ms      0     3727ms   3974ms   +6.6%
     0ms      1     8099ms   9134ms    +13%
     1ms      1    13525ms  13586ms  +0.45%

Considering the use case of epoll_wait() (wait for events, do something
with the events, repeat), it should only contribute to a small portion of
user's CPU consumption. Therefore this performance drop is not alarming.

Fixes: c5a282e9635e ("fs/epoll: reduce the scope of wq lock in epoll_wait()")
Suggested-by: Mateusz Guzik <mjguzik@gmail.com>
Signed-off-by: Nam Cao <namcao@linutronix.de>
Link: https://patch.msgid.link/4363cd8e34a21d4f0d257be1b33e84dc25030fdf.1780422138.git.namcao@linutronix.de
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/eventpoll.c | 20 +++++++++++++++++++-
 1 file changed, 19 insertions(+), 1 deletion(-)

diff --git a/fs/eventpoll.c b/fs/eventpoll.c
index c2f97187f9db41..c35580194ad0e3 100644
--- a/fs/eventpoll.c
+++ b/fs/eventpoll.c
@@ -38,6 +38,7 @@
 #include <linux/compat.h>
 #include <linux/rculist.h>
 #include <linux/capability.h>
+#include <linux/seqlock.h>
 #include <net/busy_poll.h>
 
 /*
@@ -317,6 +318,9 @@ struct eventpoll {
 	/* Lock which protects rdllist and ovflist */
 	spinlock_t lock;
 
+	/* Protect switching between rdllist and ovflist */
+	seqcount_spinlock_t seq;
+
 	/* RB tree root used to store monitored fd structs */
 	struct rb_root_cached rbr;
 
@@ -546,7 +550,10 @@ static inline void epi_clear_ovflist(struct epitem *epi)
  */
 static inline int ep_events_available(struct eventpoll *ep)
 {
-	return !list_empty_careful(&ep->rdllist) || ep_is_scanning(ep);
+	unsigned int seq = read_seqcount_begin(&ep->seq);
+
+	return !list_empty_careful(&ep->rdllist) || ep_is_scanning(ep) ||
+		read_seqcount_retry(&ep->seq, seq);
 }
 
 #ifdef CONFIG_NET_RX_BUSY_POLL
@@ -898,8 +905,12 @@ static void ep_start_scan(struct eventpoll *ep, struct list_head *scan_batch)
 	 */
 	lockdep_assert_irqs_enabled();
 	spin_lock_irq(&ep->lock);
+	write_seqcount_begin(&ep->seq);
+
 	list_splice_init(&ep->rdllist, scan_batch);
 	ep_enter_scan(ep);
+
+	write_seqcount_end(&ep->seq);
 	spin_unlock_irq(&ep->lock);
 }
 
@@ -930,6 +941,9 @@ static void ep_done_scan(struct eventpoll *ep,
 			ep_pm_stay_awake(epi);
 		}
 	}
+
+	write_seqcount_begin(&ep->seq);
+
 	/* Back out of scan mode; callbacks target ep->rdllist again. */
 	ep_exit_scan(ep);
 
@@ -937,6 +951,9 @@ static void ep_done_scan(struct eventpoll *ep,
 	 * Quickly re-inject items left on "scan_batch".
 	 */
 	list_splice(scan_batch, &ep->rdllist);
+
+	write_seqcount_end(&ep->seq);
+
 	__pm_relax(ep->ws);
 
 	if (!list_empty(&ep->rdllist)) {
@@ -1313,6 +1330,7 @@ static int ep_alloc(struct eventpoll **pep)
 
 	mutex_init(&ep->mtx);
 	spin_lock_init(&ep->lock);
+	seqcount_spinlock_init(&ep->seq, &ep->lock);
 	init_waitqueue_head(&ep->wq);
 	init_waitqueue_head(&ep->poll_wait);
 	INIT_LIST_HEAD(&ep->rdllist);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0831/2077] gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (829 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0830/2077] eventpoll: Fix epoll_wait() report false negative Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0832/2077] i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845 Greg Kroah-Hartman
                   ` (166 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Francesco Lauritano, Marco Scardovi,
	Armin Wolf, Mario Limonciello, Mika Westerberg, Hans de Goede,
	Andy Shevchenko, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mario Limonciello <mario.limonciello@amd.com>

[ Upstream commit 3bb62e3f99a557d257e5f5a803200051b7de3afa ]

Commit ca876c7483b6 ("gpiolib-acpi: make sure we trigger edge events at
least once on boot") introduced logic to trigger edge-based GPIO
interrupts during initialization to ensure proper initial state setup
when firmware doesn't initialize it.

However, according to the Microsoft GPIO documentation, triggering GPIO
interrupts during initialization should only happen for interrupts
marked as ActiveBoth (both IRQF_TRIGGER_RISING and IRQF_TRIGGER_FALLING)
and only when the associated GPIO line is already asserted (logic level
low).

The current implementation incorrectly triggers:
1. Any edge-triggered interrupt (RISING-only or FALLING-only)
2. RISING interrupts when value is high and FALLING when value is low

This causes problems at bootup for single-edge interrupts that
don't follow the ActiveBoth pattern.

Fix this by:
- Only triggering when BOTH rising and falling edges are configured
- Only triggering when the GPIO line is asserted (value == 0)

Reported-by: Francesco Lauritano <francesco.lauritano1@protonmail.com>
Closes: https://lore.kernel.org/all/6iFCwGH2vssb7NRUTWGpkubGMNbgIlBHSz40z8ZsezjxngXpoiiRiJaijviNvhiDAGIr43bfUmdxLmxYoHDjyft4DgwFc3Pnu5hzPguTa0s=@protonmail.com/
Tested-by: Marco Scardovi <mscardovi95@gmail.com>
Fixes: ca876c7483b69 ("gpiolib-acpi: make sure we trigger edge events at least once on boot")
Link: https://learn.microsoft.com/en-us/windows-hardware/drivers/bringup/general-purpose-i-o--gpio-
Suggested-by: Armin Wolf <W_Armin@gmx.de>
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Reviewed-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpio/gpiolib-acpi-core.c | 19 +++++++++++++++----
 1 file changed, 15 insertions(+), 4 deletions(-)

diff --git a/drivers/gpio/gpiolib-acpi-core.c b/drivers/gpio/gpiolib-acpi-core.c
index 09f860200a059b..eb8a40cfb7a981 100644
--- a/drivers/gpio/gpiolib-acpi-core.c
+++ b/drivers/gpio/gpiolib-acpi-core.c
@@ -233,12 +233,23 @@ static void acpi_gpiochip_request_irq(struct acpi_gpio_chip *acpi_gpio,
 
 	event->irq_requested = true;
 
-	/* Make sure we trigger the initial state of edge-triggered IRQs */
+	/*
+	 * Make sure we trigger the initial state of ActiveBoth IRQs.
+	 *
+	 * According to the Microsoft GPIO documentation, triggering GPIO
+	 * interrupts marked as ActiveBoth during initialization is correct
+	 * as long as the associated GPIO line is already "asserted"
+	 * (logic level low). We should not trigger edge-based GPIO
+	 * interrupts not marked as ActiveBoth.
+	 *
+	 * See: https://learn.microsoft.com/en-us/windows-hardware/drivers/bringup/general-purpose-i-o--gpio-
+	 * Section: "GPIO controllers and ActiveBoth interrupts"
+	 */
 	if (acpi_gpio_need_run_edge_events_on_boot() &&
-	    (event->irqflags & (IRQF_TRIGGER_RISING | IRQF_TRIGGER_FALLING))) {
+	    ((event->irqflags & (IRQF_TRIGGER_RISING | IRQF_TRIGGER_FALLING)) ==
+	     (IRQF_TRIGGER_RISING | IRQF_TRIGGER_FALLING))) {
 		value = gpiod_get_raw_value_cansleep(event->desc);
-		if (((event->irqflags & IRQF_TRIGGER_RISING) && value == 1) ||
-		    ((event->irqflags & IRQF_TRIGGER_FALLING) && value == 0))
+		if (value == 0)
 			event->handler(event->irq, event);
 	}
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0832/2077] i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (830 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0831/2077] gpiolib: acpi: Only trigger ActiveBoth interrupts on boot Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0833/2077] staging: rtl8723bs: fix stainfo check in rtw_aes_decrypt Greg Kroah-Hartman
                   ` (165 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Stanley Chu, Frank Li,
	Alexandre Belloni, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stanley Chu <yschu@nuvoton.com>

[ Upstream commit fa1d4fa118f4229168e9ca88cea260c5e5a94652 ]

The NPCM845 I3C controller may raise a false SLVSTART interrupt. The
handler first latches MSTATUS and then clears SLVSTART. If a real IBI
request arrives after the handler latches MSTATUS but before it clears
the SLVSTART interrupt status, HW sets the SLVREQ state. However, the
handler still relies on the stale MSTATUS snapshot, returns early, and
misses the real IBI. No further interrupt is generated for this pending
IBI.

Re-read MSTATUS to obtain the latest state and avoid missing a real IBI
due to this race condition.

Fixes: 4dd12e944f07 ("i3c: master: svc: Fix npcm845 invalid slvstart event")
Signed-off-by: Stanley Chu <yschu@nuvoton.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260413005040.1211107-2-yschu@nuvoton.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/i3c/master/svc-i3c-master.c | 16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

diff --git a/drivers/i3c/master/svc-i3c-master.c b/drivers/i3c/master/svc-i3c-master.c
index e2d99a3ac07da7..63063741fbd129 100644
--- a/drivers/i3c/master/svc-i3c-master.c
+++ b/drivers/i3c/master/svc-i3c-master.c
@@ -672,10 +672,18 @@ static irqreturn_t svc_i3c_master_irq_handler(int irq, void *dev_id)
 	/* Clear the interrupt status */
 	writel(SVC_I3C_MINT_SLVSTART, master->regs + SVC_I3C_MSTATUS);
 
-	/* Ignore the false event */
-	if (svc_has_quirk(master, SVC_I3C_QUIRK_FALSE_SLVSTART) &&
-	    !SVC_I3C_MSTATUS_STATE_SLVREQ(active))
-		return IRQ_HANDLED;
+	if (svc_has_quirk(master, SVC_I3C_QUIRK_FALSE_SLVSTART)) {
+		/*
+		 * Re-read MSTATUS to obtain the latest state and avoid
+		 * missing an IBI that arrives after MSTATUS is latched
+		 * but before SLVSTART is cleared.
+		 */
+		active = readl(master->regs + SVC_I3C_MSTATUS);
+
+		/* Ignore the false event */
+		if (!SVC_I3C_MSTATUS_STATE_SLVREQ(active))
+			return IRQ_HANDLED;
+	}
 
 	/*
 	 * The SDA line remains low until the request is processed.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0833/2077] staging: rtl8723bs: fix stainfo check in rtw_aes_decrypt
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (831 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0832/2077] i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845 Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0834/2077] staging: nvec: fix use-after-free in nvec_rx_completed() Greg Kroah-Hartman
                   ` (164 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Luka Gejak, Dan Carpenter,
	Maksym Pikhotskyi, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Maksym Pikhotskyi <mpikhotskyi@gmail.com>

[ Upstream commit 9a3f9b3c47d8f071b0eb9e63906ac0448058278d ]

The null-pointer-guard was incorrect, returning _FAIL on valid pointer.
Invert the guard, so it returns _FAIL on invalid pointer.

Fixes: e23ad1570028 ("staging: rtl8723bs: use guard clause for stainfo check")
Reported-by: Luka Gejak <luka.gejak@linux.dev>
Closes: https://lore.kernel.org/linux-staging/E4BF62EF-C6F6-431F-8EDC-77C1E613E66B@linux.dev/
Reviewed-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: Maksym Pikhotskyi <mpikhotskyi@gmail.com>
Reviewed-by: Luka Gejak <luka.gejak@linux.dev>
Link: https://patch.msgid.link/20260417095452.23440-1-mpikhotskyi@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/staging/rtl8723bs/core/rtw_security.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/staging/rtl8723bs/core/rtw_security.c b/drivers/staging/rtl8723bs/core/rtw_security.c
index a00504ff291098..f467cb5b1dca39 100644
--- a/drivers/staging/rtl8723bs/core/rtw_security.c
+++ b/drivers/staging/rtl8723bs/core/rtw_security.c
@@ -1212,7 +1212,7 @@ u32 rtw_aes_decrypt(struct adapter *padapter, u8 *precvframe)
 	if (prxattrib->encrypt != _AES_)
 		return _SUCCESS;
 	stainfo = rtw_get_stainfo(&padapter->stapriv, &prxattrib->ta[0]);
-	if (stainfo)
+	if (!stainfo)
 		return _FAIL;
 	if (is_multicast_ether_addr(prxattrib->ra)) {
 		static unsigned long start;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0834/2077] staging: nvec: fix use-after-free in nvec_rx_completed()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (832 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0833/2077] staging: rtl8723bs: fix stainfo check in rtw_aes_decrypt Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0835/2077] perf dwarf-aux: Fix libdw segmentation fault in cu_walk_functions_at Greg Kroah-Hartman
                   ` (163 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Alexandru Hossu,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alexandru Hossu <hossu.alexandru@gmail.com>

[ Upstream commit 26813881181deb3a32fbb59eadb2599cbe8423f6 ]

In nvec_rx_completed(), when an incomplete RX transfer is detected,
nvec_msg_free() is called to return the message back to the pool by
clearing its 'used' atomic flag. Immediately after this, the code
accesses nvec->rx->data[0] to check the message type.

Since nvec_msg_free() marks the pool slot as available via atomic_set(),
any concurrent or subsequent call to nvec_msg_alloc() could claim that
same slot and overwrite its data[] array. Reading nvec->rx->data[0] after
freeing the message is therefore a use-after-free.

Fix this by saving the message type byte before calling nvec_msg_free(),
then using the saved value for the battery quirk check.

Fixes: d6bdcf2e1019 ("staging: nvec: Add battery quirk to ignore incomplete responses")
Reviewed-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: Alexandru Hossu <hossu.alexandru@gmail.com>
Link: https://patch.msgid.link/20260427081713.3401874-2-hossu.alexandru@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/staging/nvec/nvec.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/staging/nvec/nvec.c b/drivers/staging/nvec/nvec.c
index 952c5a849a563d..2a3499dd4d6342 100644
--- a/drivers/staging/nvec/nvec.c
+++ b/drivers/staging/nvec/nvec.c
@@ -494,6 +494,8 @@ static void nvec_tx_completed(struct nvec_chip *nvec)
 static void nvec_rx_completed(struct nvec_chip *nvec)
 {
 	if (nvec->rx->pos != nvec_msg_size(nvec->rx)) {
+		unsigned char msg_type = nvec->rx->data[0];
+
 		dev_err(nvec->dev, "RX incomplete: Expected %u bytes, got %u\n",
 			(uint)nvec_msg_size(nvec->rx),
 			(uint)nvec->rx->pos);
@@ -502,7 +504,7 @@ static void nvec_rx_completed(struct nvec_chip *nvec)
 		nvec->state = 0;
 
 		/* Battery quirk - Often incomplete, and likes to crash */
-		if (nvec->rx->data[0] == NVEC_BAT)
+		if (msg_type == NVEC_BAT)
 			complete(&nvec->ec_transfer);
 
 		return;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0835/2077] perf dwarf-aux: Fix libdw segmentation fault in cu_walk_functions_at
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (833 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0834/2077] staging: nvec: fix use-after-free in nvec_rx_completed() Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0836/2077] perf dwarf-aux: Fix libdw API contract violations Greg Kroah-Hartman
                   ` (162 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
	Adrian Hunter, Ingo Molnar, James Clark, Jiri Olsa,
	Masami Hiramatsu, Peter Zijlstra, Zecheng Li,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit d37a5467709e627370124d7346ef71ce605ababa ]

A segmentation fault was observed in `libdw` when running `perf kmem`
with `--page stat` on some workloads. The crash occurred deep inside
`libdw` (specifically in `dwarf_child` and `dwarf_diename`) when
processing DWARF information.

The root cause was improper error handling of `dwarf_getfuncs` in
`die_find_realfunc` and `die_find_tailfunc`.

`dwarf_getfuncs` returns:
 - `0` on success (when all functions have been processed).
 - A positive offset if the callback aborts early (e.g., via
   `DWARF_CB_ABORT` when a match is found).
 - `-1` on error.

The original code used `if (!dwarf_getfuncs(...)) return NULL;`. On
error (`-1`), `!-1` evaluates to `0` (false), bypassing the error
check. Execution then proceeded as if a match was found, returning
uninitialized stack memory (`die_mem`) to the caller
(`cu_walk_functions_at`). When `cu_walk_functions_at` passed this
uninitialized memory to `libdw` via `dwarf_diename`, it caused a
segmentation fault.

Fix this by correcting the error check to `if (dwarf_getfuncs(...) <= 0)`.

Fixes: e0d153c69040 ("perf-probe: Move dwarf library routines to dwarf-aux.{c, h}")
Fixes: d4c537e6bf86 ("perf probe: Ignore tail calls to probed functions")
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Zecheng Li <zli94@ncsu.edu>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/dwarf-aux.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/tools/perf/util/dwarf-aux.c b/tools/perf/util/dwarf-aux.c
index 92db2fccc788ab..109a166a6d19ce 100644
--- a/tools/perf/util/dwarf-aux.c
+++ b/tools/perf/util/dwarf-aux.c
@@ -171,7 +171,6 @@ int cu_walk_functions_at(Dwarf_Die *cu_die, Dwarf_Addr addr,
 	}
 
 	return ret;
-
 }
 
 /**
@@ -620,7 +619,7 @@ Dwarf_Die *die_find_tailfunc(Dwarf_Die *cu_die, Dwarf_Addr addr,
 	ad.addr = addr;
 	ad.die_mem = die_mem;
 	/* dwarf_getscopes can't find subprogram. */
-	if (!dwarf_getfuncs(cu_die, __die_search_func_tail_cb, &ad, 0))
+	if (dwarf_getfuncs(cu_die, __die_search_func_tail_cb, &ad, 0) <= 0)
 		return NULL;
 	else
 		return die_mem;
@@ -659,7 +658,7 @@ Dwarf_Die *die_find_realfunc(Dwarf_Die *cu_die, Dwarf_Addr addr,
 	ad.addr = addr;
 	ad.die_mem = die_mem;
 	/* dwarf_getscopes can't find subprogram. */
-	if (!dwarf_getfuncs(cu_die, __die_search_func_cb, &ad, 0))
+	if (dwarf_getfuncs(cu_die, __die_search_func_cb, &ad, 0) <= 0)
 		return NULL;
 	else
 		return die_mem;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0836/2077] perf dwarf-aux: Fix libdw API contract violations
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (834 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0835/2077] perf dwarf-aux: Fix libdw segmentation fault in cu_walk_functions_at Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0837/2077] perf libdw: Fix libdw API contract violations and memory leaks Greg Kroah-Hartman
                   ` (161 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter,
	Ingo Molnar, James Clark, Jiri Olsa, Masami Hiramatsu,
	Namhyung Kim, Peter Zijlstra, Zecheng Li,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit 17e9b4243e76f0a0fe951d30ce990d6081a8b426 ]

Check return values of `dwarf_decl_line` (where non-optional),
`dwarf_getfuncs`, and `dwarf_lineaddr` to prevent using uninitialized
stack variables or incorrectly reporting success on failure.

For the root DIE in `die_walk_lines()`, `dwarf_decl_line` and
`die_get_decl_file` are optional and their failures are handled
gracefully to avoid breaking line walking on valid functions.
Specifically, remove the strict `!decf` (declared file) check that
would prematurely abort line walking on generated or artificial
functions lacking this optional attribute.

Additionally:
 - Add NULL pointer protection for `strcmp()` in `die_walk_lines()`
   when `inf` or `decf` are NULL to prevent crashes on generated
   code.
 - Use `dwarf_attr_integrate` in `die_get_data_member_location` to
   correctly resolve inherited member locations (e.g. via abstract
   origin or specification).

Fixes: 57f95bf5f882 ("perf probe: Show correct statement line number by perf probe -l")
Fixes: 3f4460a28fb2 ("perf probe: Filter out redundant inline-instances")
Fixes: 75186a9b09e4 ("perf probe: Fix to show lines of sys_ functions correctly")
Fixes: e0d153c69040 ("perf-probe: Move dwarf library routines to dwarf-aux.{c, h}")
Fixes: 6243b9dc4c99 ("perf probe: Move dwarf specific functions to dwarf-aux.c")
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Zecheng Li <zli94@ncsu.edu>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/dwarf-aux.c | 34 +++++++++++++++++-----------------
 tools/perf/util/dwarf-aux.h |  5 +++++
 2 files changed, 22 insertions(+), 17 deletions(-)

diff --git a/tools/perf/util/dwarf-aux.c b/tools/perf/util/dwarf-aux.c
index 109a166a6d19ce..d7160f87ac7d7a 100644
--- a/tools/perf/util/dwarf-aux.c
+++ b/tools/perf/util/dwarf-aux.c
@@ -125,7 +125,8 @@ int cu_find_lineinfo(Dwarf_Die *cu_die, Dwarf_Addr addr,
 	    && die_entrypc(&die_mem, &faddr) == 0 &&
 	    faddr == addr) {
 		*fname = die_get_decl_file(&die_mem);
-		dwarf_decl_line(&die_mem, lineno);
+		if (dwarf_decl_line(&die_mem, lineno) != 0)
+			return -ENOENT;
 		goto out;
 	}
 
@@ -459,7 +460,7 @@ int die_get_data_member_location(Dwarf_Die *mb_die, Dwarf_Word *offs)
 	size_t nexpr;
 	int ret;
 
-	if (dwarf_attr(mb_die, DW_AT_data_member_location, &attr) == NULL)
+	if (dwarf_attr_integrate(mb_die, DW_AT_data_member_location, &attr) == NULL)
 		return -ENOENT;
 
 	if (dwarf_formudata(&attr, offs) != 0) {
@@ -795,8 +796,7 @@ static int __die_walk_instances_cb(Dwarf_Die *inst, void *data)
 
 	/* Ignore redundant instances */
 	if (dwarf_tag(inst) == DW_TAG_inlined_subroutine) {
-		dwarf_decl_line(origin, &tmp);
-		if (die_get_call_lineno(inst) == tmp) {
+		if (dwarf_decl_line(origin, &tmp) == 0 && die_get_call_lineno(inst) == tmp) {
 			tmp = die_get_decl_fileno(origin);
 			if (die_get_call_fileno(inst) == tmp)
 				return DIE_FIND_CB_CONTINUE;
@@ -950,11 +950,6 @@ int die_walk_lines(Dwarf_Die *rt_die, line_walk_callback_t callback, void *data)
 		cu_die = dwarf_diecu(rt_die, &die_mem, NULL, NULL);
 		dwarf_decl_line(rt_die, &decl);
 		decf = die_get_decl_file(rt_die);
-		if (!decf) {
-			pr_debug2("Failed to get the declared file name of %s\n",
-				  dwarf_diename(rt_die));
-			return -EINVAL;
-		}
 	} else
 		cu_die = rt_die;
 	if (!cu_die) {
@@ -998,11 +993,12 @@ int die_walk_lines(Dwarf_Die *rt_die, line_walk_callback_t callback, void *data)
 			if (die_find_inlinefunc(rt_die, addr, &die_mem)) {
 				/* Call-site check */
 				inf = die_get_call_file(&die_mem);
-				if ((inf && !strcmp(inf, decf)) &&
+				if ((inf == decf || (inf && decf && !strcmp(inf, decf))) &&
 				    die_get_call_lineno(&die_mem) == lineno)
 					goto found;
 
-				dwarf_decl_line(&die_mem, &inl);
+				if (dwarf_decl_line(&die_mem, &inl) != 0)
+					inl = 0;
 				if (inl != decl ||
 				    decf != die_get_decl_file(&die_mem))
 					continue;
@@ -1034,8 +1030,10 @@ int die_walk_lines(Dwarf_Die *rt_die, line_walk_callback_t callback, void *data)
 			.data = data,
 			.retval = 0,
 		};
-		dwarf_getfuncs(cu_die, __die_walk_culines_cb, &param, 0);
-		ret = param.retval;
+		if (dwarf_getfuncs(cu_die, __die_walk_culines_cb, &param, 0) < 0)
+			ret = -EINVAL;
+		else
+			ret = param.retval;
 	}
 
 	return ret;
@@ -1939,10 +1937,12 @@ static bool die_get_postprologue_addr(unsigned long entrypc_idx,
 			break;
 	}
 
-	dwarf_lineaddr(line, postprologue_addr);
-	if (*postprologue_addr >= highpc)
-		dwarf_lineaddr(dwarf_onesrcline(lines, i - 1),
-			       postprologue_addr);
+	if (dwarf_lineaddr(line, postprologue_addr) != 0)
+		return false;
+	if (*postprologue_addr >= highpc) {
+		if (dwarf_lineaddr(dwarf_onesrcline(lines, i - 1), postprologue_addr) != 0)
+			return false;
+	}
 
 	return true;
 }
diff --git a/tools/perf/util/dwarf-aux.h b/tools/perf/util/dwarf-aux.h
index a79968a2e573b3..161f0bf980b6ee 100644
--- a/tools/perf/util/dwarf-aux.h
+++ b/tools/perf/util/dwarf-aux.h
@@ -10,6 +10,11 @@
 #include <elfutils/libdwfl.h>
 #include <elfutils/version.h>
 
+static inline const char *die_name(Dwarf_Die *die)
+{
+	return dwarf_diename(die) ?: "<unknown>";
+}
+
 struct strbuf;
 
 /* Find the realpath of the target file */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0837/2077] perf libdw: Fix libdw API contract violations and memory leaks
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (835 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0836/2077] perf dwarf-aux: Fix libdw API contract violations Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0838/2077] perf probe-finder: Fix libdw API contract violations Greg Kroah-Hartman
                   ` (160 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter,
	Ingo Molnar, James Clark, Jiri Olsa, Masami Hiramatsu,
	Namhyung Kim, Peter Zijlstra, Zecheng Li,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit 9c6d535ddb794fb540c3b142ab1d7416d469c1de ]

Check return values of `dwfl_report_end` and `dwfl_module_addrdie`
to prevent using uninitialized stack variables or reporting success on
failure.

Additionally:
 - Ensure `*file` is freed and inline frames are cleared on error in
   `libdw__addr2line()` to prevent memory leaks and duplicated
   callchains when falling back to other unwinders.
 - Use `die_name()` safe wrapper inside the inline function unwinding
   callback (`libdw_a2l_cb`).
 - Refactor `libdw_a2l_cb`'s repeated memory error handling/cleanup
   paths using a cleaner goto control flow.

Fixes: b7a2b011e9627ff3 ("perf powerpc: Unify the skip-callchain-idx libdw with that for addr2line")
Fixes: 88c51002d06f9a68 ("perf addr2line: Add a libdw implementation")
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Ian Rogers <irogers@google.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Zecheng Li <zli94@ncsu.edu>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/libdw.c | 49 ++++++++++++++++++++++++++++++++++++-----
 1 file changed, 43 insertions(+), 6 deletions(-)

diff --git a/tools/perf/util/libdw.c b/tools/perf/util/libdw.c
index 21697788410308..15bf646d104f5a 100644
--- a/tools/perf/util/libdw.c
+++ b/tools/perf/util/libdw.c
@@ -60,7 +60,10 @@ struct Dwfl *dso__libdw_dwfl(struct dso *dso)
 		return NULL;
 	}
 
-	dwfl_report_end(dwfl, /*removed=*/NULL, /*arg=*/NULL);
+	if (dwfl_report_end(dwfl, /*removed=*/NULL, /*arg=*/NULL) != 0) {
+		dwfl_end(dwfl);
+		return NULL;
+	}
 	dso__set_libdw(dso, dwfl);
 
 	return dwfl;
@@ -72,18 +75,19 @@ struct libdw_a2l_cb_args {
 	struct inline_node *node;
 	char *leaf_srcline;
 	bool leaf_srcline_used;
+	int err;
 };
 
 static int libdw_a2l_cb(Dwarf_Die *die, void *_args)
 {
 	struct libdw_a2l_cb_args *args  = _args;
-	struct symbol *inline_sym = new_inline_sym(args->dso, args->sym, dwarf_diename(die));
+	struct symbol *inline_sym = new_inline_sym(args->dso, args->sym, die_name(die));
 	const char *call_fname = die_get_call_file(die);
 	char *call_srcline = srcline__unknown;
 	struct inline_list *ilist;
 
 	if (!inline_sym)
-		return -ENOMEM;
+		goto abort_enomem;
 
 	/* Assign caller information to the parent. */
 	if (call_fname)
@@ -103,12 +107,27 @@ static int libdw_a2l_cb(Dwarf_Die *die, void *_args)
 
 	/* Add this symbol to the chain as the leaf. */
 	if (!args->leaf_srcline_used) {
-		inline_list__append_tail(inline_sym, args->leaf_srcline, args->node);
+		if (inline_list__append_tail(inline_sym, args->leaf_srcline, args->node) != 0)
+			goto abort_delete_sym;
 		args->leaf_srcline_used = true;
 	} else {
-		inline_list__append_tail(inline_sym, strdup(args->leaf_srcline), args->node);
+		char *srcline = strdup(args->leaf_srcline);
+
+		if (!srcline)
+			goto abort_delete_sym;
+		if (inline_list__append_tail(inline_sym, srcline, args->node) != 0) {
+			free(srcline);
+			goto abort_delete_sym;
+		}
 	}
 	return 0;
+
+abort_delete_sym:
+	if (inline_sym->inlined)
+		symbol__delete(inline_sym);
+abort_enomem:
+	args->err = -ENOMEM;
+	return DWARF_CB_ABORT;
 }
 
 int libdw__addr2line(u64 addr, char **file, unsigned int *line_nr,
@@ -162,11 +181,29 @@ int libdw__addr2line(u64 addr, char **file, unsigned int *line_nr,
 			.leaf_srcline = srcline_from_fileline(src ?: "<unknown>", lineno),
 		};
 
+		if (!args.leaf_srcline) {
+			if (file && *file) {
+				free(*file);
+				*file = NULL;
+			}
+			return 0;
+		}
+
 		/* Walk from the parent down to the leaf. */
-		cu_walk_functions_at(cudie, addr, libdw_a2l_cb, &args);
+		if (cudie)
+			cu_walk_functions_at(cudie, addr, libdw_a2l_cb, &args);
 
 		if (!args.leaf_srcline_used)
 			free(args.leaf_srcline);
+
+		if (args.err) {
+			if (file && *file) {
+				free(*file);
+				*file = NULL;
+			}
+			inline_node__clear_frames(node);
+			return 0;
+		}
 	}
 	return 1;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0838/2077] perf probe-finder: Fix libdw API contract violations
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (836 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0837/2077] perf libdw: Fix libdw API contract violations and memory leaks Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0839/2077] perf annotate-data: " Greg Kroah-Hartman
                   ` (159 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter,
	Ingo Molnar, James Clark, Jiri Olsa, Masami Hiramatsu,
	Namhyung Kim, Peter Zijlstra, Zecheng Li,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit 9a2ef19b5f5218d35c161f272a901f6c070faf79 ]

Check return values of `dwarf_formsdata`, `dwarf_entrypc`,
`dwarf_highpc`, `dwarf_bytesize`, `dwarf_attr`, `dwarf_decl_line`,
`dwarf_getfuncs`, and `dwarf_formref_die`. Validate `dwarf_diename` and
`dwarf_diecu` results to prevent potential crashes. Fix C90 mixed
declarations.

Additionally:
 - Avoid vfprintf undefined behavior with NULL strings by using the
   `die_name()` helper for `dwarf_diename()` in `pr_*` calls,
   including when warning about tail calls.
 - Prevent NULL pointer dereference in `convert_variable_fields()`
   when processing array elements for variables in registers.
 - Fallback to offset 0 in `line_range_search_cb()` instead of
   skipping functions without `DW_AT_decl_line`.
 - Relax `dwarf_getfuncs` error checking in
   `find_probe_point_by_func()` and `find_line_range_by_func()` to
   prevent premature CU search aborts, ensuring robustness against
   corrupted CUs.

Fixes: 66f69b2197167cb9 ("perf probe: Support DW_AT_const_value constant value")
Fixes: 3d918a12a1b3088a ("perf probe: Find fentry mcount fuzzed parameter location")
Fixes: bcfc082150c6b1e9 ("perf probe: Remove redundant dwarf functions")
Fixes: 221d061182b8ff55 ("perf probe: Fix to search local variables in appropriate scope")
Fixes: b55a87ade3839c33 ("perf probe: Remove die() from probe-finder code")
Fixes: 4c859351226c920b ("perf probe: Support glob wildcards for function name")
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Zecheng Li <zli94@ncsu.edu>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/probe-finder.c | 102 +++++++++++++++++++++------------
 1 file changed, 65 insertions(+), 37 deletions(-)

diff --git a/tools/perf/util/probe-finder.c b/tools/perf/util/probe-finder.c
index 64328abeef8b24..f3f9a1573502c9 100644
--- a/tools/perf/util/probe-finder.c
+++ b/tools/perf/util/probe-finder.c
@@ -79,7 +79,7 @@ static int convert_variable_location(Dwarf_Die *vr_die, Dwarf_Addr addr,
 	unsigned int regn;
 	Dwarf_Word offs = 0;
 	bool ref = false;
-	const char *regs;
+	const char *regs, *name;
 	int ret, ret2 = 0;
 
 	if (dwarf_attr(vr_die, DW_AT_external, &attr) != NULL)
@@ -93,7 +93,8 @@ static int convert_variable_location(Dwarf_Die *vr_die, Dwarf_Addr addr,
 		if (!tvar)
 			return 0;
 
-		dwarf_formsdata(&attr, &snum);
+		if (dwarf_formsdata(&attr, &snum) != 0)
+			return -ENOENT;
 		ret = asprintf(&tvar->value, "\\%ld", (long)snum);
 
 		return ret < 0 ? -ENOMEM : 0;
@@ -103,8 +104,7 @@ static int convert_variable_location(Dwarf_Die *vr_die, Dwarf_Addr addr,
 	if (dwarf_attr(vr_die, DW_AT_location, &attr) == NULL)
 		return -EINVAL;	/* Broken DIE ? */
 	if (dwarf_getlocation_addr(&attr, addr, &op, &nops, 1) <= 0) {
-		ret = dwarf_entrypc(sp_die, &tmp);
-		if (ret)
+		if (dwarf_entrypc(sp_die, &tmp) != 0)
 			return -ENOENT;
 
 		if (probe_conf.show_location_range &&
@@ -115,8 +115,7 @@ static int convert_variable_location(Dwarf_Die *vr_die, Dwarf_Addr addr,
 			return -ENOENT;
 		}
 
-		ret = dwarf_highpc(sp_die, &tmp);
-		if (ret)
+		if (dwarf_highpc(sp_die, &tmp) != 0)
 			return -ENOENT;
 		/*
 		 * This is fuzzed by fentry mcount. We try to find the
@@ -138,12 +137,16 @@ static int convert_variable_location(Dwarf_Die *vr_die, Dwarf_Addr addr,
 static_var:
 		if (!tvar)
 			return ret2;
+
 		/* Static variables on memory (not stack), make @varname */
-		ret = strlen(dwarf_diename(vr_die));
+		name = dwarf_diename(vr_die);
+		if (!name)
+			return -ENOENT;
+		ret = strlen(name);
 		tvar->value = zalloc(ret + 2);
 		if (tvar->value == NULL)
 			return -ENOMEM;
-		snprintf(tvar->value, ret + 2, "@%s", dwarf_diename(vr_die));
+		snprintf(tvar->value, ret + 2, "@%s", name);
 		tvar->ref = alloc_trace_arg_ref((long)offs);
 		if (tvar->ref == NULL)
 			return -ENOMEM;
@@ -234,13 +237,14 @@ static int convert_variable_type(Dwarf_Die *vr_die,
 	}
 
 	if (die_get_real_type(vr_die, &type) == NULL) {
-		pr_warning("Failed to get a type information of %s.\n",
-			   dwarf_diename(vr_die));
+		const char *name = dwarf_diename(vr_die);
+
+		pr_warning("Failed to get a type information of %s.\n", name ?: "<unknown>");
 		return -ENOENT;
 	}
 
 	pr_debug("%s type is %s.\n",
-		 dwarf_diename(vr_die), dwarf_diename(&type));
+		 die_name(vr_die), die_name(&type));
 
 	if (cast && (!strcmp(cast, "string") || !strcmp(cast, "ustring"))) {
 		/* String type */
@@ -249,7 +253,7 @@ static int convert_variable_type(Dwarf_Die *vr_die,
 		    ret != DW_TAG_array_type) {
 			pr_warning("Failed to cast into string: "
 				   "%s(%s) is not a pointer nor array.\n",
-				   dwarf_diename(vr_die), dwarf_diename(&type));
+				   die_name(vr_die), die_name(&type));
 			return -EINVAL;
 		}
 		if (die_get_real_type(&type, &type) == NULL) {
@@ -272,7 +276,7 @@ static int convert_variable_type(Dwarf_Die *vr_die,
 		    !die_compare_name(&type, "unsigned char")) {
 			pr_warning("Failed to cast into string: "
 				   "%s is not (unsigned) char *.\n",
-				   dwarf_diename(vr_die));
+				   die_name(vr_die));
 			return -EINVAL;
 		}
 		tvar->type = strdup(cast);
@@ -299,7 +303,7 @@ static int convert_variable_type(Dwarf_Die *vr_die,
 	/* Check the bitwidth */
 	if (ret > MAX_BASIC_TYPE_BITS) {
 		pr_info("%s exceeds max-bitwidth. Cut down to %d bits.\n",
-			dwarf_diename(&type), MAX_BASIC_TYPE_BITS);
+			die_name(&type), MAX_BASIC_TYPE_BITS);
 		ret = MAX_BASIC_TYPE_BITS;
 	}
 	ret = snprintf(buf, 16, "%c%d", prefix, ret);
@@ -333,12 +337,14 @@ static int convert_variable_fields(Dwarf_Die *vr_die, const char *varname,
 		pr_warning("Failed to get the type of %s.\n", varname);
 		return -ENOENT;
 	}
-	pr_debug2("Var real type: %s (%x)\n", dwarf_diename(&type),
+	pr_debug2("Var real type: %s (%x)\n", die_name(&type),
 		  (unsigned)dwarf_dieoffset(&type));
 	tag = dwarf_tag(&type);
 
 	if (field->name[0] == '[' &&
 	    (tag == DW_TAG_array_type || tag == DW_TAG_pointer_type)) {
+		int bsize;
+
 		/* Save original type for next field or type */
 		memcpy(die_mem, &type, sizeof(*die_mem));
 		/* Get the type of this array */
@@ -346,7 +352,7 @@ static int convert_variable_fields(Dwarf_Die *vr_die, const char *varname,
 			pr_warning("Failed to get the type of %s.\n", varname);
 			return -ENOENT;
 		}
-		pr_debug2("Array real type: %s (%x)\n", dwarf_diename(&type),
+		pr_debug2("Array real type: %s (%x)\n", die_name(&type),
 			 (unsigned)dwarf_dieoffset(&type));
 		if (tag == DW_TAG_pointer_type) {
 			ref = zalloc(sizeof(struct probe_trace_arg_ref));
@@ -357,7 +363,15 @@ static int convert_variable_fields(Dwarf_Die *vr_die, const char *varname,
 			else
 				*ref_ptr = ref;
 		}
-		ref->offset += dwarf_bytesize(&type) * field->index;
+		bsize = dwarf_bytesize(&type);
+
+		if (bsize < 0)
+			return -EINVAL;
+		if (!ref) {
+			pr_warning("Array indexing not supported for variables in registers.\n");
+			return -ENOTSUP;
+		}
+		ref->offset += bsize * field->index;
 		ref->user_access = user_access;
 		goto next;
 	} else if (tag == DW_TAG_pointer_type) {
@@ -414,7 +428,7 @@ static int convert_variable_fields(Dwarf_Die *vr_die, const char *varname,
 
 	if (die_find_member(&type, field->name, die_mem) == NULL) {
 		pr_warning("%s(type:%s) has no member %s.\n", varname,
-			   dwarf_diename(&type), field->name);
+			   die_name(&type), field->name);
 		return -EINVAL;
 	}
 
@@ -461,7 +475,7 @@ static int convert_variable(Dwarf_Die *vr_die, struct probe_finder *pf)
 	int ret;
 
 	pr_debug("Converting variable %s into trace event.\n",
-		 dwarf_diename(vr_die));
+		 die_name(vr_die));
 
 	ret = convert_variable_location(vr_die, pf->addr, pf->fb_ops,
 					&pf->sp_die, pf, pf->tvar);
@@ -542,7 +556,7 @@ static int convert_to_trace_point(Dwarf_Die *sp_die, Dwfl_Module *mod,
 	/* Verify the address is correct */
 	if (!dwarf_haspc(sp_die, paddr)) {
 		pr_warning("Specified offset is out of %s\n",
-			   dwarf_diename(sp_die));
+			   die_name(sp_die));
 		return -EINVAL;
 	}
 
@@ -599,7 +613,7 @@ static int call_probe_finder(Dwarf_Die *sc_die, struct probe_finder *pf)
 		if (!die_find_realfunc(&pf->cu_die, pf->addr, &pf->sp_die)) {
 			if (die_find_tailfunc(&pf->cu_die, pf->addr, &pf->sp_die)) {
 				pr_warning("Ignoring tail call from %s\n",
-						dwarf_diename(&pf->sp_die));
+						die_name(&pf->sp_die));
 				return 0;
 			} else {
 				pr_warning("Failed to find probe point in any "
@@ -611,10 +625,16 @@ static int call_probe_finder(Dwarf_Die *sc_die, struct probe_finder *pf)
 		memcpy(&pf->sp_die, sc_die, sizeof(Dwarf_Die));
 
 	/* Get the frame base attribute/ops from subprogram */
-	dwarf_attr(&pf->sp_die, DW_AT_frame_base, &fb_attr);
-	ret = dwarf_getlocation_addr(&fb_attr, pf->addr, &pf->fb_ops, &nops, 1);
-	if (ret <= 0 || nops == 0) {
+	if (dwarf_attr(&pf->sp_die, DW_AT_frame_base, &fb_attr) == NULL) {
 		pf->fb_ops = NULL;
+	} else {
+		ret = dwarf_getlocation_addr(&fb_attr, pf->addr, &pf->fb_ops, &nops, 1);
+		if (ret <= 0 || nops == 0)
+			pf->fb_ops = NULL;
+	}
+
+	if (pf->fb_ops == NULL) {
+		/* Not supported */
 	} else if (nops == 1 && pf->fb_ops[0].atom == DW_OP_call_frame_cfa &&
 		   (pf->cfi_eh != NULL || pf->cfi_dbg != NULL)) {
 		if ((dwarf_cfi_addrframe(pf->cfi_eh, pf->addr, &frame) != 0 &&
@@ -667,8 +687,8 @@ static int find_best_scope_cb(Dwarf_Die *fn_die, void *data)
 		}
 	} else {
 		/* With the line number, find the nearest declared DIE */
-		dwarf_decl_line(fn_die, &lno);
-		if (lno < fsp->line && fsp->diff > fsp->line - lno) {
+		if (dwarf_decl_line(fn_die, &lno) == 0 && lno < fsp->line &&
+		    fsp->diff > fsp->line - lno) {
 			/* Keep a candidate and continue */
 			fsp->diff = fsp->line - lno;
 			memcpy(fsp->die_mem, fn_die, sizeof(Dwarf_Die));
@@ -924,12 +944,12 @@ static int probe_point_inline_cb(Dwarf_Die *in_die, void *data)
 		/* Get probe address */
 		if (die_entrypc(in_die, &addr) != 0) {
 			pr_warning("Failed to get entry address of %s.\n",
-				   dwarf_diename(in_die));
+				   die_name(in_die));
 			return -ENOENT;
 		}
 		if (addr == 0) {
 			pr_debug("%s has no valid entry address. skipped.\n",
-				 dwarf_diename(in_die));
+				 die_name(in_die));
 			return -ENOENT;
 		}
 		pf->addr = addr;
@@ -971,12 +991,13 @@ static int probe_point_search_cb(Dwarf_Die *sp_die, void *data)
 	if (pp->file && fname && strtailcmp(pp->file, fname))
 		return DWARF_CB_OK;
 
-	pr_debug("Matched function: %s [%lx]\n", dwarf_diename(sp_die),
+	pr_debug("Matched function: %s [%lx]\n", die_name(sp_die),
 		 (unsigned long)dwarf_dieoffset(sp_die));
 	pf->fname = fname;
 	pf->abstrace_dieoffset = dwarf_dieoffset(sp_die);
 	if (pp->line) { /* Function relative line */
-		dwarf_decl_line(sp_die, &pf->lno);
+		if (dwarf_decl_line(sp_die, &pf->lno) != 0)
+			return DWARF_CB_OK;
 		pf->lno += pp->line;
 		param->retval = find_probe_point_by_line(pf);
 	} else if (die_is_func_instance(sp_die)) {
@@ -985,7 +1006,7 @@ static int probe_point_search_cb(Dwarf_Die *sp_die, void *data)
 		/* But in some case the entry address is 0 */
 		if (pf->addr == 0) {
 			pr_debug("%s has no entry PC. Skipped\n",
-				 dwarf_diename(sp_die));
+				 die_name(sp_die));
 			param->retval = 0;
 		/* Real function */
 		} else if (pp->lazy_line)
@@ -1018,7 +1039,8 @@ static int find_probe_point_by_func(struct probe_finder *pf)
 {
 	struct dwarf_callback_param _param = {.data = (void *)pf,
 					      .retval = 0};
-	dwarf_getfuncs(&pf->cu_die, probe_point_search_cb, &_param, 0);
+	if (dwarf_getfuncs(&pf->cu_die, probe_point_search_cb, &_param, 0) < 0)
+		pr_debug("Failed to get functions from CU\n");
 	return _param.retval;
 }
 
@@ -1207,7 +1229,8 @@ static int copy_variables_cb(Dwarf_Die *die_mem, void *data)
 		 * points to correct die.
 		 */
 		if (dwarf_attr(die_mem, DW_AT_abstract_origin, &attr)) {
-			dwarf_formref_die(&attr, &var_die);
+			if (dwarf_formref_die(&attr, &var_die) == NULL)
+				goto out;
 			if (pf->abstrace_dieoffset != dwarf_dieoffset(&var_die))
 				goto out;
 		}
@@ -1293,13 +1316,16 @@ static int add_probe_trace_event(Dwarf_Die *sc_die, struct probe_finder *pf)
 	if (ret < 0)
 		goto end;
 
-	tev->point.realname = strdup(dwarf_diename(sc_die));
+	tev->point.realname = strdup(die_name(sc_die));
 	if (!tev->point.realname) {
 		ret = -ENOMEM;
 		goto end;
 	}
 
-	tev->lang = dwarf_srclang(dwarf_diecu(sc_die, &pf->cu_die, NULL, NULL));
+	if (dwarf_diecu(sc_die, &pf->cu_die, NULL, NULL) != NULL)
+		tev->lang = dwarf_srclang(&pf->cu_die);
+	else
+		tev->lang = DW_LANG_C; /* Fallback */
 
 	pr_debug("Probe point found: %s+%lu\n", tev->point.symbol,
 		 tev->point.offset);
@@ -1794,7 +1820,8 @@ static int line_range_search_cb(Dwarf_Die *sp_die, void *data)
 
 	if (die_match_name(sp_die, lr->function) && die_is_func_def(sp_die)) {
 		lf->fname = die_get_decl_file(sp_die);
-		dwarf_decl_line(sp_die, &lr->offset);
+		if (dwarf_decl_line(sp_die, &lr->offset) != 0)
+			lr->offset = 0; /* Fallback if no line info */
 		pr_debug("fname: %s, lineno:%d\n", lf->fname, lr->offset);
 		lf->lno_s = lr->offset + lr->start;
 		if (lf->lno_s < 0)	/* Overflow */
@@ -1818,7 +1845,8 @@ static int line_range_search_cb(Dwarf_Die *sp_die, void *data)
 static int find_line_range_by_func(struct line_finder *lf)
 {
 	struct dwarf_callback_param param = {.data = (void *)lf, .retval = 0};
-	dwarf_getfuncs(&lf->cu_die, line_range_search_cb, &param, 0);
+	if (dwarf_getfuncs(&lf->cu_die, line_range_search_cb, &param, 0) < 0)
+		pr_debug("Failed to get functions from CU\n");
 	return param.retval;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0839/2077] perf annotate-data: Fix libdw API contract violations
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (837 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0838/2077] perf probe-finder: Fix libdw API contract violations Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0840/2077] perf debuginfo: " Greg Kroah-Hartman
                   ` (158 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter,
	Ingo Molnar, James Clark, Jiri Olsa, Masami Hiramatsu,
	Namhyung Kim, Peter Zijlstra, Zecheng Li,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit 5aa1941900050a2c80d29bc7ee0dfbddbad8f294 ]

Check return values of `dwarf_aggregate_size` and `dwarf_formudata`.

Additionally:
 - Avoid `vfprintf` undefined behavior with `NULL` strings by using
   the `die_name()` helper for `dwarf_diename()` in `pr_*` calls.
 - Use `die_get_data_member_location()` (updated to use
   `dwarf_attr_integrate`) to correctly parse location expressions
   for inherited member locations in the fallback path when
   `dwarf_formudata()` fails.

Fixes: 2bc3cf575a162a2c ("perf annotate-data: Improve debug message with location info")
Fixes: 4a111cadac85362e ("perf annotate-data: Add member field in the data type")
Fixes: 8b1042c425f6a5a9 ("perf annotate-data: Set bitfield member offset and size properly")
Fixes: fc044c53b99fad03 ("perf annotate-data: Add dso->data_types tree")
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Zecheng Li <zli94@ncsu.edu>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/annotate-data.c | 27 +++++++++++++++++----------
 1 file changed, 17 insertions(+), 10 deletions(-)

diff --git a/tools/perf/util/annotate-data.c b/tools/perf/util/annotate-data.c
index 1eff0a27237d94..63e3c54fab421f 100644
--- a/tools/perf/util/annotate-data.c
+++ b/tools/perf/util/annotate-data.c
@@ -74,7 +74,8 @@ void pr_debug_type_name(Dwarf_Die *die, enum type_state_kind kind)
 		break;
 	}
 
-	dwarf_aggregate_size(die, &size);
+	if (dwarf_aggregate_size(die, &size) != 0)
+		size = 0;
 
 	strbuf_init(&sb, 32);
 	die_get_typename_from_type(die, &sb);
@@ -146,9 +147,9 @@ static void pr_debug_scope(Dwarf_Die *scope_die)
 
 	tag = dwarf_tag(scope_die);
 	if (tag == DW_TAG_subprogram)
-		pr_info("[function] %s\n", dwarf_diename(scope_die));
+		pr_info("[function] %s\n", die_name(scope_die));
 	else if (tag == DW_TAG_inlined_subroutine)
-		pr_info("[inlined] %s\n", dwarf_diename(scope_die));
+		pr_info("[inlined] %s\n", die_name(scope_die));
 	else if (tag == DW_TAG_lexical_block)
 		pr_info("[block]\n");
 	else
@@ -250,9 +251,12 @@ static int __add_member_cb(Dwarf_Die *die, void *arg)
 	if (dwarf_aggregate_size(&die_mem, &size) < 0)
 		size = 0;
 
-	if (dwarf_attr_integrate(die, DW_AT_data_member_location, &attr))
-		dwarf_formudata(&attr, &loc);
-	else {
+	if (dwarf_attr_integrate(die, DW_AT_data_member_location, &attr)) {
+		if (dwarf_formudata(&attr, &loc) != 0) {
+			if (die_get_data_member_location(die, &loc) != 0)
+				loc = 0;
+		}
+	} else {
 		/* bitfield member */
 		if (dwarf_attr_integrate(die, DW_AT_data_bit_offset, &attr) &&
 		    dwarf_formudata(&attr, &loc) == 0)
@@ -273,7 +277,9 @@ static int __add_member_cb(Dwarf_Die *die, void *arg)
 				     dwarf_diename(die), (long)bit_size) < 0)
 				member->var_name = NULL;
 		} else {
-			member->var_name = strdup(dwarf_diename(die));
+			const char *name = dwarf_diename(die);
+
+			member->var_name = name ? strdup(name) : NULL;
 		}
 
 		if (member->var_name == NULL) {
@@ -370,7 +376,8 @@ static struct annotated_data_type *dso__findnew_data_type(struct dso *dso,
 	if (dwarf_tag(type_die) == DW_TAG_typedef)
 		die_get_real_type(type_die, type_die);
 
-	dwarf_aggregate_size(type_die, &size);
+	if (dwarf_aggregate_size(type_die, &size) != 0)
+		size = 0;
 
 	/* Check existing nodes in dso->data_types tree */
 	key.self.type_name = type_name;
@@ -1569,7 +1576,7 @@ static int find_data_type_die(struct data_loc_info *dloc, Dwarf_Die *type_die)
 	offset = loc->offset;
 
 	pr_debug_dtp("CU for %s (die:%#lx)\n",
-		     dwarf_diename(&cu_die), (long)dwarf_dieoffset(&cu_die));
+		     die_name(&cu_die), (long)dwarf_dieoffset(&cu_die));
 
 	if (reg == DWARF_REG_PC) {
 		if (get_global_var_type(&cu_die, dloc, dloc->ip, dloc->var_addr,
@@ -1636,7 +1643,7 @@ static int find_data_type_die(struct data_loc_info *dloc, Dwarf_Die *type_die)
 		}
 
 		pr_debug_dtp("found \"%s\" (die: %#lx) in scope=%d/%d (die: %#lx) ",
-			     dwarf_diename(&var_die), (long)dwarf_dieoffset(&var_die),
+			     die_name(&var_die), (long)dwarf_dieoffset(&var_die),
 			     i+1, nr_scopes, (long)dwarf_dieoffset(&scopes[i]));
 
 		if (reg == DWARF_REG_PC) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0840/2077] perf debuginfo: Fix libdw API contract violations
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (838 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0839/2077] perf annotate-data: " Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0841/2077] perf callchain: Handle multiple address spaces Greg Kroah-Hartman
                   ` (157 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
	Adrian Hunter, Ingo Molnar, James Clark, Jiri Olsa,
	Masami Hiramatsu, Peter Zijlstra, Zecheng Li,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit 31088ccf0312b1a547046f1f69890ede07834a30 ]

Check return value of `dwfl_report_end` during offline initialization.
Validate `dwfl_module_relocation_info` result before passing to `strcmp`
to avoid potential segmentation faults.

Additionally:
 - Fix a file descriptor leak in `debuginfo__init_offline_dwarf()` when
   `dwfl_report_offline()` or subsequent setup calls fail.

Fixes: 6f1b6291cf73cb32 ("perf tools: Add util/debuginfo.[ch] files")
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Zecheng Li <zli94@ncsu.edu>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/debuginfo.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/tools/perf/util/debuginfo.c b/tools/perf/util/debuginfo.c
index 0e35c13abd041c..84a78b30ceac10 100644
--- a/tools/perf/util/debuginfo.c
+++ b/tools/perf/util/debuginfo.c
@@ -42,6 +42,7 @@ static int debuginfo__init_offline_dwarf(struct debuginfo *dbg,
 {
 	GElf_Addr dummy;
 	int fd;
+	bool fd_consumed = false;
 
 	fd = open(path, O_RDONLY);
 	if (fd < 0)
@@ -55,6 +56,7 @@ static int debuginfo__init_offline_dwarf(struct debuginfo *dbg,
 	dbg->mod = dwfl_report_offline(dbg->dwfl, "", "", fd);
 	if (!dbg->mod)
 		goto error;
+	fd_consumed = true;
 
 	dbg->dbg = dwfl_module_getdwarf(dbg->mod, &dbg->bias);
 	if (!dbg->dbg)
@@ -62,13 +64,14 @@ static int debuginfo__init_offline_dwarf(struct debuginfo *dbg,
 
 	dwfl_module_build_id(dbg->mod, &dbg->build_id, &dummy);
 
-	dwfl_report_end(dbg->dwfl, NULL, NULL);
+	if (dwfl_report_end(dbg->dwfl, NULL, NULL) != 0)
+		goto error;
 
 	return 0;
 error:
 	if (dbg->dwfl)
 		dwfl_end(dbg->dwfl);
-	else
+	if (!fd_consumed)
 		close(fd);
 	memset(dbg, 0, sizeof(*dbg));
 
@@ -167,7 +170,7 @@ int debuginfo__get_text_offset(struct debuginfo *dbg, Dwarf_Addr *offs,
 	/* Search the relocation related .text section */
 	for (i = 0; i < n; i++) {
 		p = dwfl_module_relocation_info(dbg->mod, i, &shndx);
-		if (strcmp(p, ".text") == 0) {
+		if (p && strcmp(p, ".text") == 0) {
 			/* OK, get the section header */
 			scn = elf_getscn(elf, shndx);
 			if (!scn)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0841/2077] perf callchain: Handle multiple address spaces
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (839 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0840/2077] perf debuginfo: " Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0842/2077] coresight: cti: Fix DT filter signals silently ignored Greg Kroah-Hartman
                   ` (156 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Richter, Namhyung Kim,
	Alexander Gordeev, Heiko Carstens, Jan Polensky, linux-s390,
	Sumanth Korikkar, Vasily Gorbik, Arnaldo Carvalho de Melo,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Richter <tmricht@linux.ibm.com>

[ Upstream commit ae15db3e9b639491007cc1e9e99638e4b6091781 ]

perf test 'perf inject to convert DWARF callchains to regular ones'
fails on s390. It was introduced with commit 92ea788d2af4e65a ("perf
inject: Add --convert-callchain option")

The failure comes the difference in output. Without the inject script to
convert DWARF the callchains is:

 # perf record -F 999 --call-graph dwarf -- perf test -w noploop
 # perf report -i perf.data --stdio --no-children -q \
					 --percent-limit=1 > /tmp/111
 # cat /tmp/111
    99.30%  perf-noploop  perf               [.] noploop
            |
            ---noploop
               run_workload (inlined)
               cmd_test
               run_builtin (inlined)
               handle_internal_command
               run_argv (inlined)
               main
               __libc_start_call_main
               __libc_start_main_impl (inlined)
               _start
 #

With the inject script step the output is:

 # perf inject -i perf.data --convert-callchain -o /tmp/perf-inject-1.out
 # perf report -i /tmp/perf-inject-1.out --stdio --no-children -q \
		--percent-limit=1 > /tmp/222
 # cat /tmp/222
    99.40%  perf-noploop  perf               [.] noploop
            |
            ---noploop
               run_workload (inlined)
               cmd_test
               run_builtin (inlined)
               handle_internal_command
               run_argv (inlined)
               main
               _start
 # diff /tmp/111 /tmp/222
 1c1
 <     99.30%  perf-noploop  perf               [.] noploop
 ---
 >     99.40%  perf-noploop  perf               [.] noploop
 10,11d9
 <                __libc_start_call_main
 <                __libc_start_main_impl (inlined)
 #

The difference are the symbols __libc_start_call_main and
__libc_start_main_impl.

On x86_64, kernel and user space share a single virtual address space,
with the kernel mapped to the upper end of memory. The instruction
pointer value alone is sufficient to distinguish between user space and
kernel space addresses.

This is not true for s390, which uses separate address spaces for user
and kernel.

The same virtual address can be valid in both address spaces, so the
instruction pointer value alone cannot determine whether an address
belongs to the kernel or user space.

Instead, perf must rely on the cpumode metadata derived from the
processor status word (PSW) at sample time.

In function perf_event__convert_sample_callchain() the first part
copies a kernel callchain and context entries, if any.

It then appends additional entries ignoring the address space
architecture. Taking that into account, the symbols at addresses

   0x3ff970348cb __libc_start_call_main
   0x3ff970349c5 __libc_start_main_impl

(located after the kernel address space on s390) are now included.

Output before:

 # perf test 83
 83: perf inject to convert DWARF callchains to regular ones : FAILED!

Output after:
 # perf test 83
 83: perf inject to convert DWARF callchains to regular ones : Ok

Question to Namhyung:

In function perf_event__convert_sample_callchain() just before the
for() loop this patch modifies, the kernel callchain is copied,
see this comment and the next 5 lines:

   /* copy kernel callchain and context entries */

Then why is machine__kernel_ip() needed in the for() loop, when
the kernel entries have been copied just before the loop?

Note: This patch was tested on x86_64 virtual machine and succeeded.

Fixes: 92ea788d2af4e65a ("perf inject: Add --convert-callchain option")
Signed-off-by: Thomas Richter <tmricht@linux.ibm.com>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Cc: Alexander Gordeev <agordeev@linux.ibm.com>
Cc: Heiko Carstens <hca@linux.ibm.com>
Cc: Jan Polensky <japo@linux.ibm.com>
Cc: linux-s390@vger.kernel.org
Cc: Sumanth Korikkar <sumanthk@linux.ibm.com>
Cc: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/arch/common.c    | 4 +++-
 tools/perf/builtin-inject.c | 3 ++-
 2 files changed, 5 insertions(+), 2 deletions(-)

diff --git a/tools/perf/arch/common.c b/tools/perf/arch/common.c
index 21836f70f231e4..ad0cab830a4da3 100644
--- a/tools/perf/arch/common.c
+++ b/tools/perf/arch/common.c
@@ -237,5 +237,7 @@ int perf_env__lookup_objdump(struct perf_env *env, char **path)
  */
 bool perf_env__single_address_space(struct perf_env *env)
 {
-	return strcmp(perf_env__arch(env), "sparc");
+	const char *arch = perf_env__arch(env);
+
+	return strcmp(arch, "s390") && strcmp(arch, "sparc");
 }
diff --git a/tools/perf/builtin-inject.c b/tools/perf/builtin-inject.c
index f174bc69cec453..6ab20df358c43b 100644
--- a/tools/perf/builtin-inject.c
+++ b/tools/perf/builtin-inject.c
@@ -438,7 +438,8 @@ static int perf_event__convert_sample_callchain(const struct perf_tool *tool,
 
 	node = cursor->first;
 	for (k = 0; k < cursor->nr && i < PERF_MAX_STACK_DEPTH; k++) {
-		if (machine__kernel_ip(machine, node->ip))
+		if (machine->single_address_space &&
+		    machine__kernel_ip(machine, node->ip))
 			/* kernel IPs were added already */;
 		else if (node->ms.sym && node->ms.sym->inlined)
 			/* we can't handle inlined callchains */;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0842/2077] coresight: cti: Fix DT filter signals silently ignored
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (840 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0841/2077] perf callchain: Handle multiple address spaces Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0843/2077] soundwire: dont program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral Greg Kroah-Hartman
                   ` (155 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yingchao Deng, Leo Yan,
	Suzuki K Poulose, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yingchao Deng <yingchao.deng@oss.qualcomm.com>

[ Upstream commit 551bb2fd5e4ed63d33aa11f07102cce5179b7595 ]

In cti_plat_process_filter_sigs(), after allocating a temporary
cti_trig_grp struct via kzalloc_obj(), the code never assigns tg->nr_sigs
= nr_filter_sigs. Since kzalloc zero-initialises the struct, tg->nr_sigs
remains 0. cti_plat_read_trig_group() guards with:
    if (!tgrp->nr_sigs)
        return 0;

so it returns immediately without reading any signal indices from DT.

Fix by assigning tg->nr_sigs before calling cti_plat_read_trig_group().

Fixes: a5614770ab97 ("coresight: cti: Add device tree support for custom CTI")
Signed-off-by: Yingchao Deng <yingchao.deng@oss.qualcomm.com>
Reviewed-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20260426-nr_sigs-v1-1-3b9df99dab97@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwtracing/coresight/coresight-cti-platform.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/hwtracing/coresight/coresight-cti-platform.c b/drivers/hwtracing/coresight/coresight-cti-platform.c
index 4eff96f48594e8..d6d5388705c3e1 100644
--- a/drivers/hwtracing/coresight/coresight-cti-platform.c
+++ b/drivers/hwtracing/coresight/coresight-cti-platform.c
@@ -329,6 +329,7 @@ static int cti_plat_process_filter_sigs(struct cti_drvdata *drvdata,
 	if (!tg)
 		return -ENOMEM;
 
+	tg->nr_sigs = nr_filter_sigs;
 	err = cti_plat_read_trig_group(tg, fwnode, CTI_DT_FILTER_OUT_SIGS);
 	if (!err)
 		drvdata->config.trig_out_filter |= tg->used_mask;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0843/2077] soundwire: dont program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (841 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0842/2077] coresight: cti: Fix DT filter signals silently ignored Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0844/2077] soundwire: fix bug in sdw_add_element_group_count found by syzkaller Greg Kroah-Hartman
                   ` (154 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bard Liao, Simon Trimmer,
	Péter Ujfalusi, Ranjani Sridharan, Vinod Koul, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bard Liao <yung-chuan.liao@linux.intel.com>

[ Upstream commit c368dd5cbd61ffab2b6f8a89b0d5775e2e16cde6 ]

The SDW_SCP_BUSCLOCK_SCALE register will be programmed when the
Peripheral is attached. We can and should skip programming the
SDW_SCP_BUSCLOCK_SCALE register when the Peripheral is unattached.

Fixes: 645291cfe5e5 ("Soundwire: stream: program BUSCLOCK_SCALE")
Signed-off-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Reviewed-by: Simon Trimmer <simont@opensource.cirrus.com>
Reviewed-by: Péter Ujfalusi <peter.ujfalusi@linux.intel.com>
Reviewed-by: Ranjani Sridharan <ranjani.sridharan@linux.intel.com>
Link: https://patch.msgid.link/20260428084612.322701-1-yung-chuan.liao@linux.intel.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/soundwire/stream.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/drivers/soundwire/stream.c b/drivers/soundwire/stream.c
index 4ed8fb7663ad40..0b96268380283e 100644
--- a/drivers/soundwire/stream.c
+++ b/drivers/soundwire/stream.c
@@ -697,6 +697,13 @@ static int sdw_program_params(struct sdw_bus *bus, bool prepare)
 		if (scale_index < 0)
 			return scale_index;
 
+		/* Skip the unattached Peripherals */
+		if (!completion_done(&slave->enumeration_complete)) {
+			dev_warn(&slave->dev,
+				 "Not enumerated, skip programming BUSCLOCK_SCALE\n");
+			continue;
+		}
+
 		ret = sdw_write_no_pm(slave, addr1, scale_index);
 		if (ret < 0) {
 			dev_err(&slave->dev, "SDW_SCP_BUSCLOCK_SCALE register write failed\n");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0844/2077] soundwire: fix bug in sdw_add_element_group_count found by syzkaller
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (842 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0843/2077] soundwire: dont program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0845/2077] coresight: tmc: Fix overflow when calculating is bigger than 2GiB Greg Kroah-Hartman
                   ` (153 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bard Liao, Andy Shevchenko,
	Baoli.Zhang, Vinod Koul, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Baoli.Zhang <baoli.zhang@linux.intel.com>

[ Upstream commit f772ff5a0e6758fd412803c09e03ba3bca5f5878 ]

The original implementation caused an out-of-bounds memory access
in the sdw_add_element_group_count for-loop when i == num.

for (i = 0; i <= num; i++) {
    if (rate == group->rates[i] && lane == group->lanes[i])
        ...

To fix this error, the function now checks for existing rate/lane
entries in the group(a function parameter) using a for-loop before
adding them.

No functional changes apart from this fix.

Fixes: 9026118f20e2 ("soundwire: Add generic bandwidth allocation algorithm")
Reviewed-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Signed-off-by: Baoli.Zhang <baoli.zhang@linux.intel.com>
Link: https://patch.msgid.link/20260506055039.3751028-2-baoli.zhang@linux.intel.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../soundwire/generic_bandwidth_allocation.c  | 47 +++++++++----------
 1 file changed, 22 insertions(+), 25 deletions(-)

diff --git a/drivers/soundwire/generic_bandwidth_allocation.c b/drivers/soundwire/generic_bandwidth_allocation.c
index fb3970e12dac9c..f016ad088a1db0 100644
--- a/drivers/soundwire/generic_bandwidth_allocation.c
+++ b/drivers/soundwire/generic_bandwidth_allocation.c
@@ -299,39 +299,36 @@ static int sdw_add_element_group_count(struct sdw_group *group,
 	int num = group->count;
 	int i;
 
-	for (i = 0; i <= num; i++) {
+	for (i = 0; i < num; i++) {
 		if (rate == group->rates[i] && lane == group->lanes[i])
-			break;
-
-		if (i != num)
-			continue;
-
-		if (group->count >= group->max_size) {
-			unsigned int *rates;
-			unsigned int *lanes;
+			return 0;
+	}
 
-			group->max_size += 1;
-			rates = krealloc(group->rates,
-					 (sizeof(int) * group->max_size),
-					 GFP_KERNEL);
-			if (!rates)
-				return -ENOMEM;
+	if (group->count >= group->max_size) {
+		unsigned int *rates;
+		unsigned int *lanes;
 
-			group->rates = rates;
+		group->max_size += 1;
+		rates = krealloc(group->rates,
+				 (sizeof(int) * group->max_size),
+				 GFP_KERNEL);
+		if (!rates)
+			return -ENOMEM;
 
-			lanes = krealloc(group->lanes,
-					 (sizeof(int) * group->max_size),
-					 GFP_KERNEL);
-			if (!lanes)
-				return -ENOMEM;
+		group->rates = rates;
 
-			group->lanes = lanes;
-		}
+		lanes = krealloc(group->lanes,
+				 (sizeof(int) * group->max_size),
+				 GFP_KERNEL);
+		if (!lanes)
+			return -ENOMEM;
 
-		group->rates[group->count] = rate;
-		group->lanes[group->count++] = lane;
+		group->lanes = lanes;
 	}
 
+	group->rates[group->count] = rate;
+	group->lanes[group->count++] = lane;
+
 	return 0;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0845/2077] coresight: tmc: Fix overflow when calculating is bigger than 2GiB
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (843 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0844/2077] soundwire: fix bug in sdw_add_element_group_count found by syzkaller Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0846/2077] coresight: ete: Always save state on power down Greg Kroah-Hartman
                   ` (152 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michiel van Tol, Leo Yan,
	Suzuki K Poulose, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leo Yan <leo.yan@arm.com>

[ Upstream commit f195d54deef1bc6dd3326394975baff02c7ae487 ]

When specifying a 2GB AUX buffer, the ETR driver ends up allocating only
a 1MB buffer instead:

  # echo 'file coresight-tmc-etr.c +p' > \
	/sys/kernel/debug/dynamic_debug/control
  # perf record -e cs_etm/@tmc_etr0,timestamp=0/u -C 0 -m ,2G -- test
  coresight tmc_etr0: allocated buffer of size 1024KB in mode 0

The page index is an 'int' type, and shifting it by PAGE_SHIFT overflows
when the resulting value exceeds 2GB.  This produces a negative value,
causing the driver to fall back to the minimum buffer size (1MB).

Cast the page index to a wider type to accommodate large buffer sizes.
Also fix a similar issue in the buffer offset calculation.

Reported-by: Michiel van Tol <michiel.vantol@arm.com>
Fixes: 99443ea19e8b ("coresight: Add generic TMC sg table framework")
Fixes: eebe8dbd8630 ("coresight: tmc: Decouple the perf buffer allocation from sysfs mode")
Signed-off-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20260217-arm_coresight_fix_big_buffer_size-v1-1-774e893d8e3f@arm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwtracing/coresight/coresight-tmc-etr.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/hwtracing/coresight/coresight-tmc-etr.c b/drivers/hwtracing/coresight/coresight-tmc-etr.c
index 4dc1defe27a5f7..361a433e6f0c55 100644
--- a/drivers/hwtracing/coresight/coresight-tmc-etr.c
+++ b/drivers/hwtracing/coresight/coresight-tmc-etr.c
@@ -154,7 +154,7 @@ tmc_pages_get_offset(struct tmc_pages *tmc_pages, dma_addr_t addr)
 	for (i = 0; i < tmc_pages->nr_pages; i++) {
 		page_start = tmc_pages->daddrs[i];
 		if (addr >= page_start && addr < (page_start + PAGE_SIZE))
-			return i * PAGE_SIZE + (addr - page_start);
+			return (long)i * PAGE_SIZE + (addr - page_start);
 	}
 
 	return -EINVAL;
@@ -1379,7 +1379,7 @@ alloc_etr_buf(struct tmc_drvdata *drvdata, struct perf_event *event,
 	node = (event->cpu == -1) ? NUMA_NO_NODE : cpu_to_node(event->cpu);
 
 	/* Use the minimum limit if the required size is smaller */
-	size = nr_pages << PAGE_SHIFT;
+	size = (ssize_t)nr_pages << PAGE_SHIFT;
 	size = max_t(ssize_t, size, TMC_ETR_PERF_MIN_BUF_SIZE);
 
 	/*
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0846/2077] coresight: ete: Always save state on power down
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (844 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0845/2077] coresight: tmc: Fix overflow when calculating is bigger than 2GiB Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0847/2077] coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore Greg Kroah-Hartman
                   ` (151 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, James Clark, Leo Yan,
	Suzuki K Poulose, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: James Clark <james.clark@linaro.org>

[ Upstream commit 2ab4645fe4206c142a5f1491e191c906279686cf ]

System register ETMs and ETE are unlikely to be preserved on CPU power
down. The ETE DT binding also never documented
"arm,coresight-loses-context-with-cpu" so nobody would have legitimately
been able to use that binding to fix it and ACPI has no such binding at
all.

Fix it by hard coding the setting for sysreg ETMs (ETE is always sysreg)
or ACPI boots. Use a local variable when setting up save_state so that
it's immune to concurrent probing when devices have different
configurations which is an issue with modifying the global.

This fixes the following error when using Coresight with ACPI on the FVP
which supports CPU PM:

  coresight ete0: External agent took claim tag
  WARNING: drivers/hwtracing/coresight/coresight-core.c:248 at coresight_disclaim_device_unlocked+0xe0/0xe8, CPU#0: perf/117

Fixes: 35e1c9163e02 ("coresight: ete: Add support for ETE tracing")
Signed-off-by: James Clark <james.clark@linaro.org>
Reviewed-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20260505-james-cs-ete-pm_save_enable-v3-1-485d21dd79b8@linaro.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../coresight/coresight-etm4x-core.c          | 48 +++++++++++++------
 1 file changed, 34 insertions(+), 14 deletions(-)

diff --git a/drivers/hwtracing/coresight/coresight-etm4x-core.c b/drivers/hwtracing/coresight/coresight-etm4x-core.c
index d565a73f0042e3..591dfe0bc63505 100644
--- a/drivers/hwtracing/coresight/coresight-etm4x-core.c
+++ b/drivers/hwtracing/coresight/coresight-etm4x-core.c
@@ -56,10 +56,14 @@ MODULE_PARM_DESC(boot_enable, "Enable tracing on boot");
 #define PARAM_PM_SAVE_NEVER	  1 /* never save any state */
 #define PARAM_PM_SAVE_SELF_HOSTED 2 /* save self-hosted state only */
 
+/*
+ * Save option for ETM4. ETE, sysreg ETM4s and ACPI boots ignore this option and
+ * will always save.
+ */
 static int pm_save_enable = PARAM_PM_SAVE_FIRMWARE;
 module_param(pm_save_enable, int, 0444);
 MODULE_PARM_DESC(pm_save_enable,
-	"Save/restore state on power down: 1 = never, 2 = self-hosted");
+	"Save/restore state on power down: 1 = never, 2 = self-hosted. MMIO and DT only.");
 
 static struct etmv4_drvdata *etmdrvdata[NR_CPUS];
 static void etm4_set_default_config(struct etmv4_config *config);
@@ -2012,7 +2016,7 @@ static int etm4_cpu_save(struct etmv4_drvdata *drvdata)
 {
 	int ret = 0;
 
-	if (pm_save_enable != PARAM_PM_SAVE_SELF_HOSTED)
+	if (!drvdata->save_state)
 		return 0;
 
 	/*
@@ -2127,7 +2131,7 @@ static void __etm4_cpu_restore(struct etmv4_drvdata *drvdata)
 
 static void etm4_cpu_restore(struct etmv4_drvdata *drvdata)
 {
-	if (pm_save_enable != PARAM_PM_SAVE_SELF_HOSTED)
+	if (!drvdata->save_state)
 		return;
 
 	if (coresight_get_mode(drvdata->csdev))
@@ -2212,6 +2216,17 @@ static void etm4_pm_clear(void)
 	}
 }
 
+static bool etm4x_always_pm_save(struct device *dev, struct csdev_access *csa)
+{
+	/*
+	 * Only IO mem ETM devices will benefit from skipping PM save and only
+	 * DT has the option to control it, not ACPI. Otherwise system register
+	 * based ETMs and ETEs will always lose context on CPU power down, so
+	 * always save.
+	 */
+	return !csa->io_mem || is_acpi_device_node(dev_fwnode(dev));
+}
+
 static int etm4_add_coresight_dev(struct etm4_init_arg *init_arg)
 {
 	int ret;
@@ -2221,6 +2236,7 @@ static int etm4_add_coresight_dev(struct etm4_init_arg *init_arg)
 	struct coresight_desc desc = { 0 };
 	u8 major, minor;
 	char *type_name;
+	bool pm_save;
 
 	if (!drvdata)
 		return -EINVAL;
@@ -2248,6 +2264,21 @@ static int etm4_add_coresight_dev(struct etm4_init_arg *init_arg)
 
 	etm4_set_default(&drvdata->config);
 
+	if (etm4x_always_pm_save(dev, init_arg->csa))
+		pm_save = true;
+	else if (pm_save_enable == PARAM_PM_SAVE_FIRMWARE)
+		pm_save = coresight_loses_context_with_cpu(dev);
+	else
+		pm_save = pm_save_enable != PARAM_PM_SAVE_NEVER;
+
+	if (pm_save) {
+		drvdata->save_state = devm_kmalloc(dev,
+						   sizeof(struct etmv4_save_state),
+						   GFP_KERNEL);
+		if (!drvdata->save_state)
+			return -ENOMEM;
+	}
+
 	pdata = coresight_get_platform_data(dev);
 	if (IS_ERR(pdata))
 		return PTR_ERR(pdata);
@@ -2305,17 +2336,6 @@ static int etm4_probe(struct device *dev)
 	if (ret)
 		return ret;
 
-	if (pm_save_enable == PARAM_PM_SAVE_FIRMWARE)
-		pm_save_enable = coresight_loses_context_with_cpu(dev) ?
-			       PARAM_PM_SAVE_SELF_HOSTED : PARAM_PM_SAVE_NEVER;
-
-	if (pm_save_enable != PARAM_PM_SAVE_NEVER) {
-		drvdata->save_state = devm_kmalloc(dev,
-				sizeof(struct etmv4_save_state), GFP_KERNEL);
-		if (!drvdata->save_state)
-			return -ENOMEM;
-	}
-
 	raw_spin_lock_init(&drvdata->spinlock);
 
 	drvdata->cpu = coresight_get_cpu(dev);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0847/2077] coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (845 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0846/2077] coresight: ete: Always save state on power down Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0848/2077] PCI/ASPM: Dont reconfigure ASPM entering low-power state Greg Kroah-Hartman
                   ` (150 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Leo Yan, James Clark,
	Suzuki K Poulose, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leo Yan <leo.yan@arm.com>

[ Upstream commit 0ec0a8785d21f63db520bd9d2a67c55e855d36a8 ]

It is a typo to use trcvmidcctlr0 to save and restore TRCVMIDCCTLR1.
Use trcvmidcctlr1 instead.

Fixes: f5bd523690d2 ("coresight: etm4x: Convert all register accesses")
Signed-off-by: Leo Yan <leo.yan@arm.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20260408-arm_cs_fix_trcvmidcctlr1_typo-v1-1-6a5695363b46@arm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwtracing/coresight/coresight-etm4x-core.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/hwtracing/coresight/coresight-etm4x-core.c b/drivers/hwtracing/coresight/coresight-etm4x-core.c
index 591dfe0bc63505..a251375db24b17 100644
--- a/drivers/hwtracing/coresight/coresight-etm4x-core.c
+++ b/drivers/hwtracing/coresight/coresight-etm4x-core.c
@@ -1983,7 +1983,7 @@ static int __etm4_cpu_save(struct etmv4_drvdata *drvdata)
 
 	state->trcvmidcctlr0 = etm4x_read32(csa, TRCVMIDCCTLR0);
 	if (drvdata->numvmidc > 4)
-		state->trcvmidcctlr0 = etm4x_read32(csa, TRCVMIDCCTLR1);
+		state->trcvmidcctlr1 = etm4x_read32(csa, TRCVMIDCCTLR1);
 
 	state->trcclaimset = etm4x_read32(csa, TRCCLAIMCLR);
 
@@ -2106,7 +2106,7 @@ static void __etm4_cpu_restore(struct etmv4_drvdata *drvdata)
 
 	etm4x_relaxed_write32(csa, state->trcvmidcctlr0, TRCVMIDCCTLR0);
 	if (drvdata->numvmidc > 4)
-		etm4x_relaxed_write32(csa, state->trcvmidcctlr0, TRCVMIDCCTLR1);
+		etm4x_relaxed_write32(csa, state->trcvmidcctlr1, TRCVMIDCCTLR1);
 
 	etm4x_relaxed_write32(csa, state->trcclaimset, TRCCLAIMSET);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0848/2077] PCI/ASPM: Dont reconfigure ASPM entering low-power state
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (846 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0847/2077] coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0849/2077] PCI: Introduce named defines for PCI ROM Greg Kroah-Hartman
                   ` (149 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Carlos Bilbao (Lambda),
	Bjorn Helgaas, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Carlos Bilbao <carlos.bilbao@kernel.org>

[ Upstream commit c855c9921da72e535c24737c748f603a52d03f7e ]

Reconfiguring ASPM when a device transitions to low-power state can enable
L1.1/L1.2 substates on the PCIe link at a time when the device is sleeping
and may be unable to exit them. ASPM should be reconfigured on D0 entry
(resume), not on the way down.

pci_set_low_power_state() calls pcie_aspm_pm_state_change() after writing
D3hot to PCI_PM_CTRL. pcie_aspm_pm_state_change() resets link->aspm_capable
to link->aspm_support and then calls pcie_config_aspm_path(), which can
enable ASPM L1.1/L1.2 substates on the PCIe link. If the device cannot
recover the link from L1.2 while in D3hot, subsequent config space reads
return 0xFFFF ("device inaccessible") and pci_power_up() fails with
messages like:

  vfio-pci 0000:5d:00.0: Unable to change power state from D3hot to D0, device inaccessible

This was observed on NVIDIA H100 SXM5 GPUs bound to vfio-pci when Linux
runtime PM suspends them to D3hot: the GPU becomes permanently inaccessible
and disappears from the PCIe bus.

The call to pcie_aspm_pm_state_change() in pci_set_low_power_state() was
restored by f93e71aea6c6 ("Revert "PCI/ASPM: Remove
pcie_aspm_pm_state_change()""), which reverted 08d0cc5f3426 ("PCI/ASPM:
Remove pcie_aspm_pm_state_change()").  The revert was necessary because the
removal broke suspend/resume on certain platforms that required ASPM to be
reconfigured on D0 entry. However, the revert restored the call in both
pci_set_full_power_state() (D0 entry) and pci_set_low_power_state()
(low-power entry).

Only the D0-entry call is needed to fix the suspend/resume regression. The
low-power-entry call is harmful: reconfiguring ASPM immediately after
putting a device into D3hot can enable link substates that the device or
platform cannot exit while the device is sleeping.

Remove the pcie_aspm_pm_state_change() call from pci_set_low_power_state().
ASPM will still be reconfigured correctly when the device returns to D0 via
pci_set_full_power_state().

Fixes: f93e71aea6c6 ("Revert "PCI/ASPM: Remove pcie_aspm_pm_state_change()"")
Signed-off-by: Carlos Bilbao (Lambda) <carlos.bilbao@kernel.org>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260428040104.78524-1-carlos.bilbao@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/pci.c | 3 ---
 1 file changed, 3 deletions(-)

diff --git a/drivers/pci/pci.c b/drivers/pci/pci.c
index d34266651ad09f..0ee01d99e3275c 100644
--- a/drivers/pci/pci.c
+++ b/drivers/pci/pci.c
@@ -1514,9 +1514,6 @@ static int pci_set_low_power_state(struct pci_dev *dev, pci_power_t state, bool
 				     pci_power_name(dev->current_state),
 				     pci_power_name(state));
 
-	if (dev->bus->self)
-		pcie_aspm_pm_state_change(dev->bus->self, locked);
-
 	return 0;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0849/2077] PCI: Introduce named defines for PCI ROM
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (847 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0848/2077] PCI/ASPM: Dont reconfigure ASPM entering low-power state Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0850/2077] PCI: Check ROM header and data structure addr before accessing Greg Kroah-Hartman
                   ` (148 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guixin Liu, Bjorn Helgaas,
	Andy Shevchenko, Krzysztof Wilczyński, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guixin Liu <kanie@linux.alibaba.com>

[ Upstream commit 113e86bc58a918f85d250723436a4d541a873358 ]

Convert the magic numbers associated with PCI ROM into named
definitions. Some of these definitions will be used in the second
fix patch.

Signed-off-by: Guixin Liu <kanie@linux.alibaba.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Reviewed-by: Krzysztof Wilczyński <kwilczynski@kernel.org>
Link: https://patch.msgid.link/20260508082128.3344255-2-kanie@linux.alibaba.com
Stable-dep-of: 538796b807fc ("PCI: Check ROM header and data structure addr before accessing")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/rom.c | 40 ++++++++++++++++++++++++++++------------
 1 file changed, 28 insertions(+), 12 deletions(-)

diff --git a/drivers/pci/rom.c b/drivers/pci/rom.c
index e18d3a4383ba6b..d4a141bd148b4b 100644
--- a/drivers/pci/rom.c
+++ b/drivers/pci/rom.c
@@ -5,13 +5,28 @@
  * (C) Copyright 2004 Jon Smirl <jonsmirl@yahoo.com>
  * (C) Copyright 2004 Silicon Graphics, Inc. Jesse Barnes <jbarnes@sgi.com>
  */
+
+#include <linux/bits.h>
 #include <linux/kernel.h>
 #include <linux/export.h>
 #include <linux/pci.h>
+#include <linux/sizes.h>
 #include <linux/slab.h>
 
 #include "pci.h"
 
+#define PCI_ROM_HEADER_SIZE			0x1A
+#define PCI_ROM_POINTER_TO_DATA_STRUCT		0x18
+#define PCI_ROM_LAST_IMAGE_INDICATOR		0x15
+#define PCI_ROM_LAST_IMAGE_INDICATOR_BIT	BIT(7)
+#define PCI_ROM_IMAGE_LEN			0x10
+#define PCI_ROM_IMAGE_SECTOR_SIZE		SZ_512
+#define PCI_ROM_IMAGE_SIGNATURE			0xAA55
+
+/* Data structure signature is "PCIR" in ASCII representation */
+#define PCI_ROM_DATA_STRUCT_SIGNATURE		0x52494350
+#define PCI_ROM_DATA_STRUCT_LEN			0x0A
+
 /**
  * pci_enable_rom - enable ROM decoding for a PCI device
  * @pdev: PCI device to enable
@@ -91,26 +106,27 @@ static size_t pci_get_rom_size(struct pci_dev *pdev, void __iomem *rom,
 	do {
 		void __iomem *pds;
 		/* Standard PCI ROMs start out with these bytes 55 AA */
-		if (readw(image) != 0xAA55) {
-			pci_info(pdev, "Invalid PCI ROM header signature: expecting 0xaa55, got %#06x\n",
-				 readw(image));
+		if (readw(image) != PCI_ROM_IMAGE_SIGNATURE) {
+			pci_info(pdev, "Invalid PCI ROM header signature: expecting %#06x, got %#06x\n",
+				 PCI_ROM_IMAGE_SIGNATURE, readw(image));
 			break;
 		}
-		/* get the PCI data structure and check its "PCIR" signature */
-		pds = image + readw(image + 24);
-		if (readl(pds) != 0x52494350) {
-			pci_info(pdev, "Invalid PCI ROM data signature: expecting 0x52494350, got %#010x\n",
-				 readl(pds));
+		/* Get the PCI data structure and check its "PCIR" signature */
+		pds = image + readw(image + PCI_ROM_POINTER_TO_DATA_STRUCT);
+		if (readl(pds) != PCI_ROM_DATA_STRUCT_SIGNATURE) {
+			pci_info(pdev, "Invalid PCI ROM data signature: expecting %#010x, got %#010x\n",
+				 PCI_ROM_DATA_STRUCT_SIGNATURE, readl(pds));
 			break;
 		}
-		last_image = readb(pds + 21) & 0x80;
-		length = readw(pds + 16);
-		image += length * 512;
+		last_image = readb(pds + PCI_ROM_LAST_IMAGE_INDICATOR) &
+				   PCI_ROM_LAST_IMAGE_INDICATOR_BIT;
+		length = readw(pds + PCI_ROM_IMAGE_LEN);
+		image += length * PCI_ROM_IMAGE_SECTOR_SIZE;
 		/* Avoid iterating through memory outside the resource window */
 		if (image >= rom + size)
 			break;
 		if (!last_image) {
-			if (readw(image) != 0xAA55) {
+			if (readw(image) != PCI_ROM_IMAGE_SIGNATURE) {
 				pci_info(pdev, "No more image in the PCI ROM\n");
 				break;
 			}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0850/2077] PCI: Check ROM header and data structure addr before accessing
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (848 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0849/2077] PCI: Introduce named defines for PCI ROM Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0851/2077] x86/platform/olpc: xo15: Drop wakeup source on driver removal Greg Kroah-Hartman
                   ` (147 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guanghui Feng, Guixin Liu,
	Bjorn Helgaas, Andy Shevchenko, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guixin Liu <kanie@linux.alibaba.com>

[ Upstream commit 538796b807fcfb81b2ce40cc97a614fd8588feb5 ]

We meet a crash when running stress-ng on x86_64 machine:

  BUG: unable to handle page fault for address: ffa0000007f40000
  RIP: 0010:pci_get_rom_size+0x52/0x220
  Call Trace:
  <TASK>
    pci_map_rom+0x80/0x130
    pci_read_rom+0x4b/0xe0
    kernfs_file_read_iter+0x96/0x180
    vfs_read+0x1b1/0x300

Our analysis reveals that the ROM space's start address is
0xffa0000007f30000, and size is 0x10000. Because of broken ROM space,
before calling readl(pds), the pds's value is 0xffa0000007f3ffff, which is
already pointed to the ROM space end, invoking readl() would read 4 bytes
therefore cause an out-of-bounds access and trigger a crash.  Fix this by
adding image header and data structure checking.

We also found another crash on arm64 machine:

  Unable to handle kernel paging request at virtual address ffff8000dd1393ff
  Mem abort info:
  ESR = 0x0000000096000021
  EC = 0x25: DABT (current EL), IL = 32 bits
  SET = 0, FnV = 0
  EA = 0, S1PTW = 0
  FSC = 0x21: alignment fault

The call trace is the same with x86_64, but the crash reason is that the
data structure addr is not aligned with 4, and arm64 machine report
"alignment fault". Fix this by adding alignment checking.

Fixes: 47b975d234ea ("PCI: Avoid iterating through memory outside the resource window")
Suggested-by: Guanghui Feng <guanghuifeng@linux.alibaba.com>
Signed-off-by: Guixin Liu <kanie@linux.alibaba.com>
[bhelgaas: shorten function names, wrap comments]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Link: https://patch.msgid.link/20260508082128.3344255-3-kanie@linux.alibaba.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/rom.c | 123 +++++++++++++++++++++++++++++++++++++++-------
 1 file changed, 105 insertions(+), 18 deletions(-)

diff --git a/drivers/pci/rom.c b/drivers/pci/rom.c
index d4a141bd148b4b..f2105c6ceef524 100644
--- a/drivers/pci/rom.c
+++ b/drivers/pci/rom.c
@@ -6,9 +6,12 @@
  * (C) Copyright 2004 Silicon Graphics, Inc. Jesse Barnes <jbarnes@sgi.com>
  */
 
+#include <linux/align.h>
 #include <linux/bits.h>
 #include <linux/kernel.h>
 #include <linux/export.h>
+#include <linux/io.h>
+#include <linux/overflow.h>
 #include <linux/pci.h>
 #include <linux/sizes.h>
 #include <linux/slab.h>
@@ -27,6 +30,15 @@
 #define PCI_ROM_DATA_STRUCT_SIGNATURE		0x52494350
 #define PCI_ROM_DATA_STRUCT_LEN			0x0A
 
+/*
+ * Per PCI Firmware r3.3, sec 5.1.3, a conformant PCI Data Structure is at
+ * least 24 bytes (0x18), large enough to cover every fixed field this
+ * driver reads (up to the Indicator byte at offset 0x15).  Reject smaller
+ * device-claimed lengths so the follow-up readers in pci_get_rom_size()
+ * cannot escape the mapped ROM window.
+ */
+#define PCI_ROM_DATA_STRUCT_MIN_LEN		0x18
+
 /**
  * pci_enable_rom - enable ROM decoding for a PCI device
  * @pdev: PCI device to enable
@@ -84,6 +96,91 @@ void pci_disable_rom(struct pci_dev *pdev)
 }
 EXPORT_SYMBOL_GPL(pci_disable_rom);
 
+static bool pci_rom_header_valid(struct pci_dev *pdev, void __iomem *image,
+				 void __iomem *rom, size_t size,
+				 bool expect_valid)
+{
+	unsigned long rom_end = (unsigned long)rom + size - 1;
+	unsigned long header_end;
+	u16 signature;
+
+	/*
+	 * Per PCI Firmware r3.3, sec 5.1, each image must start on a
+	 * 512-byte boundary and must contain the PCI Expansion ROM header.
+	 * Because @rom is page-aligned (returned by ioremap()), checking
+	 * 512-byte alignment of @image is equivalent to enforcing the
+	 * spec's sector-aligned layout within the ROM.  This also
+	 * satisfies the natural-alignment requirement of readw() on archs
+	 * such as arm64 that disallow unaligned IOMEM access.
+	 */
+	if (!IS_ALIGNED((unsigned long)image, PCI_ROM_IMAGE_SECTOR_SIZE))
+		return false;
+
+	if (check_add_overflow((unsigned long)image, PCI_ROM_HEADER_SIZE - 1,
+				&header_end))
+		return false;
+
+	if (image < rom || header_end > rom_end)
+		return false;
+
+	/* Standard PCI ROMs start out with these bytes 55 AA */
+	signature = readw(image);
+	if (signature != PCI_ROM_IMAGE_SIGNATURE) {
+		if (expect_valid) {
+			pci_info(pdev, "Invalid PCI ROM header signature: expecting %#06x, got %#06x\n",
+				 PCI_ROM_IMAGE_SIGNATURE, signature);
+		} else {
+			pci_info(pdev, "No more images in PCI ROM\n");
+		}
+		return false;
+	}
+
+	return true;
+}
+
+static bool pci_rom_data_struct_valid(struct pci_dev *pdev, void __iomem *pds,
+				      void __iomem *rom, size_t size)
+{
+	unsigned long rom_end = (unsigned long)rom + size - 1;
+	unsigned long end;
+	u32 signature;
+	u16 data_len;
+
+	/*
+	 * Some CPU architectures require IOMEM access addresses to be
+	 * aligned, for example arm64, so since we're about to call
+	 * readl(), check here for 4-byte alignment.
+	 */
+	if (!IS_ALIGNED((unsigned long)pds, 4))
+		return false;
+
+	if (check_add_overflow((unsigned long)pds, PCI_ROM_DATA_STRUCT_LEN + 1,
+				&end))
+		return false;
+
+	if (pds < rom || end > rom_end)
+		return false;
+
+	signature = readl(pds);
+	if (signature != PCI_ROM_DATA_STRUCT_SIGNATURE) {
+		pci_info(pdev, "Invalid PCI ROM data signature: expecting %#010x, got %#010x\n",
+			 PCI_ROM_DATA_STRUCT_SIGNATURE, signature);
+		return false;
+	}
+
+	data_len = readw(pds + PCI_ROM_DATA_STRUCT_LEN);
+	if (data_len < PCI_ROM_DATA_STRUCT_MIN_LEN || data_len == U16_MAX)
+		return false;
+
+	if (check_add_overflow((unsigned long)pds, data_len - 1, &end))
+		return false;
+
+	if (end > rom_end)
+		return false;
+
+	return true;
+}
+
 /**
  * pci_get_rom_size - obtain the actual size of the ROM image
  * @pdev: target PCI device
@@ -99,38 +196,28 @@ static size_t pci_get_rom_size(struct pci_dev *pdev, void __iomem *rom,
 			       size_t size)
 {
 	void __iomem *image;
-	int last_image;
 	unsigned int length;
+	bool last_image;
 
 	image = rom;
 	do {
 		void __iomem *pds;
-		/* Standard PCI ROMs start out with these bytes 55 AA */
-		if (readw(image) != PCI_ROM_IMAGE_SIGNATURE) {
-			pci_info(pdev, "Invalid PCI ROM header signature: expecting %#06x, got %#06x\n",
-				 PCI_ROM_IMAGE_SIGNATURE, readw(image));
+		if (!pci_rom_header_valid(pdev, image, rom, size, true))
 			break;
-		}
+
 		/* Get the PCI data structure and check its "PCIR" signature */
 		pds = image + readw(image + PCI_ROM_POINTER_TO_DATA_STRUCT);
-		if (readl(pds) != PCI_ROM_DATA_STRUCT_SIGNATURE) {
-			pci_info(pdev, "Invalid PCI ROM data signature: expecting %#010x, got %#010x\n",
-				 PCI_ROM_DATA_STRUCT_SIGNATURE, readl(pds));
+		if (!pci_rom_data_struct_valid(pdev, pds, rom, size))
 			break;
-		}
+
 		last_image = readb(pds + PCI_ROM_LAST_IMAGE_INDICATOR) &
 				   PCI_ROM_LAST_IMAGE_INDICATOR_BIT;
 		length = readw(pds + PCI_ROM_IMAGE_LEN);
 		image += length * PCI_ROM_IMAGE_SECTOR_SIZE;
-		/* Avoid iterating through memory outside the resource window */
-		if (image >= rom + size)
+
+		if (!last_image &&
+		    !pci_rom_header_valid(pdev, image, rom, size, false))
 			break;
-		if (!last_image) {
-			if (readw(image) != PCI_ROM_IMAGE_SIGNATURE) {
-				pci_info(pdev, "No more image in the PCI ROM\n");
-				break;
-			}
-		}
 	} while (length && !last_image);
 
 	/* never return a size larger than the PCI resource window */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0851/2077] x86/platform/olpc: xo15: Drop wakeup source on driver removal
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (849 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0850/2077] PCI: Check ROM header and data structure addr before accessing Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0852/2077] platform/x86: xo15-ebook: Fix wakeup source and GPE handling Greg Kroah-Hartman
                   ` (146 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki,
	Ilpo Järvinen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit cc966553e6ff0849978b5754531b768b0ff54985 ]

Prevent leaking a wakeup source object after removing the driver by
adding appropriate cleanup code to its remove callback function.

Fixes: a0f30f592d2d ("x86, olpc: Add XO-1.5 SCI driver")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/2069931.usQuhbGJ8B@rafael.j.wysocki
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 arch/x86/platform/olpc/olpc-xo15-sci.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/arch/x86/platform/olpc/olpc-xo15-sci.c b/arch/x86/platform/olpc/olpc-xo15-sci.c
index 82c51b6ec52889..276caf756a9c50 100644
--- a/arch/x86/platform/olpc/olpc-xo15-sci.c
+++ b/arch/x86/platform/olpc/olpc-xo15-sci.c
@@ -186,6 +186,7 @@ static int xo15_sci_add(struct acpi_device *device)
 
 static void xo15_sci_remove(struct acpi_device *device)
 {
+	device_init_wakeup(&device->dev, false);
 	acpi_disable_gpe(NULL, xo15_sci_gpe);
 	acpi_remove_gpe_handler(NULL, xo15_sci_gpe, xo15_sci_gpe_handler);
 	cancel_work_sync(&sci_work);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0852/2077] platform/x86: xo15-ebook: Fix wakeup source and GPE handling
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (850 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0851/2077] x86/platform/olpc: xo15: Drop wakeup source on driver removal Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0853/2077] perf sched: Add missing mmap2 handler in timehist Greg Kroah-Hartman
                   ` (145 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki,
	Ilpo Järvinen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit b2fc2c6ebbd2d49935c8960755d8170faead2159 ]

The device_set_wakeup_enable() call in ebook_switch_add() doesn't
actually do anything because power.can_wakeup is not set for ACPI
device objects.  Moreover, had it done anything, it would have
registered a wakeup source object that wouldn't have been used
going forward and that wakeup source would have been leaked after
driver removal because ebook_switch_remove() doesn't clean it up.
Accordingly, remove that call from ebook_switch_add().

Also prevent leaking an enabled ACPI GPE after removing the driver by
adding appropriate cleanup code to ebook_switch_remove().

Fixes: 89ca11771a4b ("OLPC XO-1.5 ebook switch driver")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/1966125.tdWV9SEqCh@rafael.j.wysocki
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/platform/x86/xo15-ebook.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/platform/x86/xo15-ebook.c b/drivers/platform/x86/xo15-ebook.c
index 4d1b1b310cc563..1568169b78727b 100644
--- a/drivers/platform/x86/xo15-ebook.c
+++ b/drivers/platform/x86/xo15-ebook.c
@@ -38,6 +38,7 @@ MODULE_DEVICE_TABLE(acpi, ebook_device_ids);
 struct ebook_switch {
 	struct input_dev *input;
 	char phys[32];			/* for input device */
+	bool gpe_enabled;
 };
 
 static int ebook_send_state(struct acpi_device *device)
@@ -128,7 +129,7 @@ static int ebook_switch_add(struct acpi_device *device)
 		/* Button's GPE is run-wake GPE */
 		acpi_enable_gpe(device->wakeup.gpe_device,
 				device->wakeup.gpe_number);
-		device_set_wakeup_enable(&device->dev, true);
+		button->gpe_enabled = true;
 	}
 
 	return 0;
@@ -144,6 +145,10 @@ static void ebook_switch_remove(struct acpi_device *device)
 {
 	struct ebook_switch *button = acpi_driver_data(device);
 
+	if (button->gpe_enabled)
+		acpi_disable_gpe(device->wakeup.gpe_device,
+				 device->wakeup.gpe_number);
+
 	input_unregister_device(button->input);
 	kfree(button);
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0853/2077] perf sched: Add missing mmap2 handler in timehist
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (851 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0852/2077] platform/x86: xo15-ebook: Fix wakeup source and GPE handling Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0854/2077] perf tool: Fix missing schedstat delegates and dont_split_sample_group in delegate_tool Greg Kroah-Hartman
                   ` (144 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter,
	David Ahern, Gabriel Marin, Ingo Molnar, James Clark, Jiri Olsa,
	Namhyung Kim, Peter Zijlstra, Arnaldo Carvalho de Melo,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit 91182741369b261c441e63e6678893032a6d7e4c ]

perf_sched__timehist() registers event handlers for options using the
sched->tool struct. It registers handlers for MMAP, COMM, EXIT, FORK, etc.
but completely omits registering a handler for MMAP2 events.

Failing to register both MMAP and MMAP2 handlers causes modern systems
(which primarily output MMAP2 records) to silently drop VMA map mappings.
This results in uninitialized machine/thread mapping structures, making it
impossible to resolve shared library instruction pointers (IPs) to dynamic
symbols/DSOs during timehist callchain analysis.

Fix this by correctly registering perf_event__process_mmap2 in
sched->tool inside perf_sched__timehist().

Fixes: 49394a2a24c78ce0 ("perf sched timehist: Introduce timehist command")
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: David Ahern <dsahern@gmail.com>
Cc: Gabriel Marin <gmx@google.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 555247568e7a61..241c2f808f7b02 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -3299,6 +3299,7 @@ static int perf_sched__timehist(struct perf_sched *sched)
 	 */
 	sched->tool.sample	 = perf_timehist__process_sample;
 	sched->tool.mmap	 = perf_event__process_mmap;
+	sched->tool.mmap2	 = perf_event__process_mmap2;
 	sched->tool.comm	 = perf_event__process_comm;
 	sched->tool.exit	 = perf_event__process_exit;
 	sched->tool.fork	 = perf_event__process_fork;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0854/2077] perf tool: Fix missing schedstat delegates and dont_split_sample_group in delegate_tool
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (852 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0853/2077] perf sched: Add missing mmap2 handler in timehist Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0855/2077] PCI: intel-gw: Move interrupt enable to own function Greg Kroah-Hartman
                   ` (143 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter,
	Gabriel Marin, Ingo Molnar, James Clark, Jiri Olsa, Namhyung Kim,
	Peter Zijlstra, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit 09d355618f7ccc27ffc7fc668b2e232872962079 ]

delegate_tool was missing the delegate overrides for schedstat_cpu
and schedstat_domain. As a result, when allocated with zalloc, these
callbacks defaulted to NULL, causing a segmentation fault crash if
any schedstat events were delivered during event processing.
Fix this by adding delegate_schedstat_cpu and delegate_schedstat_domain
via the CREATE_DELEGATE_OP2 macro, and ensuring delegate_tool__init
correctly registers them.

Additionally, delegate_tool__init completely omitted copying the
dont_split_sample_group property from the delegate. This would cause
wrapper tools to default the flag to false, which corrupts piped event
processing (e.g., in perf inject) by triggering duplicate event
deliveries on split sample values in deliver_sample_group().

Similarly, perf_tool__init() omitted the initialization of this
boolean field. On stack-allocated tools that rely on this initializer
(like intel-tpebs or __cmd_evlist), this could result in uninitialized
stack garbage evaluating to true—silently dropping non-leader event
members in deliver_sample_group().

Fix both issues by properly copying the field in delegate_tool__init
and initializing it to false in perf_tool__init.

Fixes: 6331b266935916bf ("perf tool: Add a delegate_tool that just delegates actions to another tool")
Fixes: 79bcd34e0f3da39f ("perf inject: Fix leader sampling inserting additional samples")
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Gabriel Marin <gmx@google.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/tool.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/tools/perf/util/tool.c b/tools/perf/util/tool.c
index 013c7839e2cfd2..ff2150517b7558 100644
--- a/tools/perf/util/tool.c
+++ b/tools/perf/util/tool.c
@@ -285,6 +285,7 @@ void perf_tool__init(struct perf_tool *tool, bool ordered_events)
 	tool->no_warn = false;
 	tool->show_feat_hdr = SHOW_FEAT_NO_HEADER;
 	tool->merge_deferred_callchains = true;
+	tool->dont_split_sample_group = false;
 
 	tool->sample = process_event_sample_stub;
 	tool->mmap = process_event_stub;
@@ -433,6 +434,8 @@ CREATE_DELEGATE_OP2(stat_config);
 CREATE_DELEGATE_OP2(stat_round);
 CREATE_DELEGATE_OP2(thread_map);
 CREATE_DELEGATE_OP2(time_conv);
+CREATE_DELEGATE_OP2(schedstat_cpu);
+CREATE_DELEGATE_OP2(schedstat_domain);
 CREATE_DELEGATE_OP2(tracing_data);
 
 #define CREATE_DELEGATE_OP3(name)					\
@@ -470,6 +473,7 @@ void delegate_tool__init(struct delegate_tool *tool, struct perf_tool *delegate)
 	tool->tool.no_warn = delegate->no_warn;
 	tool->tool.show_feat_hdr = delegate->show_feat_hdr;
 	tool->tool.merge_deferred_callchains = delegate->merge_deferred_callchains;
+	tool->tool.dont_split_sample_group = delegate->dont_split_sample_group;
 
 	tool->tool.sample = delegate_sample;
 	tool->tool.read = delegate_read;
@@ -516,4 +520,6 @@ void delegate_tool__init(struct delegate_tool *tool, struct perf_tool *delegate)
 	tool->tool.bpf_metadata = delegate_bpf_metadata;
 	tool->tool.compressed = delegate_compressed;
 	tool->tool.auxtrace = delegate_auxtrace;
+	tool->tool.schedstat_cpu = delegate_schedstat_cpu;
+	tool->tool.schedstat_domain = delegate_schedstat_domain;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0855/2077] PCI: intel-gw: Move interrupt enable to own function
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (853 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0854/2077] perf tool: Fix missing schedstat delegates and dont_split_sample_group in delegate_tool Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0856/2077] PCI: intel-gw: Enable clock before PHY init Greg Kroah-Hartman
                   ` (142 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Florian Eckert,
	Manivannan Sadhasivam, Bjorn Helgaas, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Florian Eckert <fe@dev.tdt.de>

[ Upstream commit abddc0539e5931f4ad2f589a03cbba5a6a64485f ]

To improve the readability of the code, move the interrupt enable
instructions to a separate function. That is already done for the disable
interrupt instruction.

In addition, clear and disable all pending interrupts, as is done in
intel_pcie_core_irq_disable(). After that, enable all relevant interrupts
again. The 'PCIE_APP_IRNEN' definition contains all the relevant interrupts
that are of interest.

This change is also done in the MaxLinear SDK [1]. As I unfortunately don’t
have any documentation for this IP core, I suspect that the intention is to
set the IP core for interrupt handling to a specific state. Perhaps the
problem is that the IP core did not reinitialize the interrupt register
properly after a power cycle.

In my view, it can’t do any harm to switch the interrupt off and then on
again to set them to a specific state.

The reason why the MaxLinear SDK is used as a reference here is, that this
PCIe DWC IP is used in the URX851 and URX850 SoC. This SoC was originally
developed by Intel when they acquired Lantiq’s home networking division in
2015 [2]. In 2020 the home network division was sold to MaxLinear [3].
Since then, this SoC belongs to MaxLinear. They use their own SDK, which
runs on kernel version '5.15.x'.

[1] https://github.com/maxlinear/linux/blob/updk_9.1.90/drivers/pci/controller/dwc/pcie-intel-gw.c#L431
[2] https://www.intc.com/news-events/press-releases/detail/364/intel-to-acquire-lantiq-advancing-the-connected-home
[3] https://investors.maxlinear.com/press-releases/detail/395/maxlinear-to-acquire-intels-home-gateway-platform

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260417-pcie-intel-gw-v5-3-0a2b933fe04f@dev.tdt.de
Stable-dep-of: 1eedabe7c617 ("PCI: intel-gw: Add .start_link() callback")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/dwc/pcie-intel-gw.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

diff --git a/drivers/pci/controller/dwc/pcie-intel-gw.c b/drivers/pci/controller/dwc/pcie-intel-gw.c
index c21906eced6189..3a85bd0ef1b7f9 100644
--- a/drivers/pci/controller/dwc/pcie-intel-gw.c
+++ b/drivers/pci/controller/dwc/pcie-intel-gw.c
@@ -196,6 +196,13 @@ static void intel_pcie_device_rst_deassert(struct intel_pcie *pcie)
 	gpiod_set_value_cansleep(pcie->reset_gpio, 0);
 }
 
+static void intel_pcie_core_irq_enable(struct intel_pcie *pcie)
+{
+	pcie_app_wr(pcie, PCIE_APP_IRNEN, 0);
+	pcie_app_wr(pcie, PCIE_APP_IRNCR, PCIE_APP_IRN_INT);
+	pcie_app_wr(pcie, PCIE_APP_IRNEN, PCIE_APP_IRN_INT);
+}
+
 static void intel_pcie_core_irq_disable(struct intel_pcie *pcie)
 {
 	pcie_app_wr(pcie, PCIE_APP_IRNEN, 0);
@@ -317,9 +324,7 @@ static int intel_pcie_host_setup(struct intel_pcie *pcie)
 	if (ret)
 		goto app_init_err;
 
-	/* Enable integrated interrupts */
-	pcie_app_wr_mask(pcie, PCIE_APP_IRNEN, PCIE_APP_IRN_INT,
-			 PCIE_APP_IRN_INT);
+	intel_pcie_core_irq_enable(pcie);
 
 	return 0;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0856/2077] PCI: intel-gw: Enable clock before PHY init
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (854 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0855/2077] PCI: intel-gw: Move interrupt enable to own function Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0857/2077] PCI: intel-gw: Add .start_link() callback Greg Kroah-Hartman
                   ` (141 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Florian Eckert,
	Manivannan Sadhasivam, Bjorn Helgaas, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Florian Eckert <fe@dev.tdt.de>

[ Upstream commit febf9ed3c35e5eec7ea384ebbd55a5296e3ca5e9 ]

To ensure that the boot sequence is correct, the DWC PCIe core clock must
be switched on before PHY init call [1]. This changes are based on patched
kernel sources of the MaxLinear SDK.

The reason why the MaxLinear SDK is used as a reference here is, that this
PCIe DWC IP is used in the URX851 and URX850 SoC. This SoC was originally
developed by Intel when they acquired Lantiq’s home networking division in
2015 [2]. In 2020 the home network division was sold to MaxLinear [3].
Since then, this SoC belongs to MaxLinear. They use their own SDK, which
runs on kernel version '5.15.x'.

[1] https://github.com/maxlinear/linux/blob/updk_9.1.90/drivers/pci/controller/dwc/pcie-intel-gw.c#L544
[2] https://www.intc.com/news-events/press-releases/detail/364/intel-to-acquire-lantiq-advancing-the-connected-home
[3] https://investors.maxlinear.com/press-releases/detail/395/maxlinear-to-acquire-intels-home-gateway-platform

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260417-pcie-intel-gw-v5-4-0a2b933fe04f@dev.tdt.de
Stable-dep-of: 1eedabe7c617 ("PCI: intel-gw: Add .start_link() callback")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/dwc/pcie-intel-gw.c | 19 ++++++++++---------
 1 file changed, 10 insertions(+), 9 deletions(-)

diff --git a/drivers/pci/controller/dwc/pcie-intel-gw.c b/drivers/pci/controller/dwc/pcie-intel-gw.c
index 3a85bd0ef1b7f9..e84703c1c4a1c8 100644
--- a/drivers/pci/controller/dwc/pcie-intel-gw.c
+++ b/drivers/pci/controller/dwc/pcie-intel-gw.c
@@ -292,13 +292,9 @@ static int intel_pcie_host_setup(struct intel_pcie *pcie)
 
 	intel_pcie_core_rst_assert(pcie);
 	intel_pcie_device_rst_assert(pcie);
-
-	ret = phy_init(pcie->phy);
-	if (ret)
-		return ret;
-
 	intel_pcie_core_rst_deassert(pcie);
 
+	/* Controller clock must be provided earlier than PHY */
 	ret = clk_prepare_enable(pcie->core_clk);
 	if (ret) {
 		dev_err(pcie->pci.dev, "Core clock enable failed: %d\n", ret);
@@ -307,13 +303,17 @@ static int intel_pcie_host_setup(struct intel_pcie *pcie)
 
 	pci->atu_base = pci->dbi_base + 0xC0000;
 
+	ret = phy_init(pcie->phy);
+	if (ret)
+		goto phy_err;
+
 	intel_pcie_ltssm_disable(pcie);
 	intel_pcie_link_setup(pcie);
 	intel_pcie_init_n_fts(pci);
 
 	ret = dw_pcie_setup_rc(&pci->pp);
 	if (ret)
-		goto app_init_err;
+		goto err;
 
 	dw_pcie_upconfig_setup(pci);
 
@@ -322,17 +322,18 @@ static int intel_pcie_host_setup(struct intel_pcie *pcie)
 
 	ret = dw_pcie_wait_for_link(pci);
 	if (ret)
-		goto app_init_err;
+		goto err;
 
 	intel_pcie_core_irq_enable(pcie);
 
 	return 0;
 
-app_init_err:
+err:
+	phy_exit(pcie->phy);
+phy_err:
 	clk_disable_unprepare(pcie->core_clk);
 clk_err:
 	intel_pcie_core_rst_assert(pcie);
-	phy_exit(pcie->phy);
 
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0857/2077] PCI: intel-gw: Add .start_link() callback
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (855 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0856/2077] PCI: intel-gw: Enable clock before PHY init Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0858/2077] PCI: loongson: Do not ignore downstream devices on external bridges Greg Kroah-Hartman
                   ` (140 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Florian Eckert,
	Manivannan Sadhasivam, Bjorn Helgaas, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Florian Eckert <fe@dev.tdt.de>

[ Upstream commit 1eedabe7c6170b5c73c7d801f427c127be74916e ]

The pcie-intel-gw driver had no .start_link() callback.  Add one so the
driver works again and does not abort with the following error messages
during probing:

  intel-gw-pcie d1000000.pcie: host bridge /soc/pcie@d1000000 ranges:
  intel-gw-pcie d1000000.pcie:      MEM 0x00dc000000..0x00ddffffff -> 0x00dc000000
  intel-combo-phy d0c00000.combo-phy: Set combo mode: combophy[1]: mode: PCIe single lane mode
  intel-gw-pcie d1000000.pcie: No outbound iATU found
  intel-gw-pcie d1000000.pcie: Cannot initialize host
  intel-gw-pcie d1000000.pcie: probe with driver intel-gw-pcie failed with error -22
  intel-gw-pcie c1100000.pcie: host bridge /soc/pcie@c1100000 ranges:
  intel-gw-pcie c1100000.pcie:      MEM 0x00ce000000..0x00cfffffff -> 0x00ce000000
  intel-combo-phy c0c00000.combo-phy: Set combo mode: combophy[3]: mode: PCIe single lane mode
  intel-gw-pcie c1100000.pcie: No outbound iATU found
  intel-gw-pcie c1100000.pcie: Cannot initialize host
  intel-gw-pcie c1100000.pcie: probe with driver intel-gw-pcie failed with error -22

Fixes: c5097b9869a1 ("Revert "PCI: dwc: Wait for link up only if link is started"")
Fixes: da56a1bfbab5 ("PCI: dwc: Wait for link up only if link is started")
Signed-off-by: Florian Eckert <fe@dev.tdt.de>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
[bhelgaas: remove timestamps]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260417-pcie-intel-gw-v5-5-0a2b933fe04f@dev.tdt.de
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/dwc/pcie-intel-gw.c | 24 ++++++++++------------
 1 file changed, 11 insertions(+), 13 deletions(-)

diff --git a/drivers/pci/controller/dwc/pcie-intel-gw.c b/drivers/pci/controller/dwc/pcie-intel-gw.c
index e84703c1c4a1c8..f157c716953c2d 100644
--- a/drivers/pci/controller/dwc/pcie-intel-gw.c
+++ b/drivers/pci/controller/dwc/pcie-intel-gw.c
@@ -285,6 +285,16 @@ static void intel_pcie_turn_off(struct intel_pcie *pcie)
 	pcie_rc_cfg_wr_mask(pcie, PCI_COMMAND, PCI_COMMAND_MEMORY, 0);
 }
 
+static int intel_pcie_start_link(struct dw_pcie *pci)
+{
+	struct intel_pcie *pcie = dev_get_drvdata(pci->dev);
+
+	intel_pcie_device_rst_deassert(pcie);
+	intel_pcie_ltssm_enable(pcie);
+
+	return 0;
+}
+
 static int intel_pcie_host_setup(struct intel_pcie *pcie)
 {
 	int ret;
@@ -311,25 +321,12 @@ static int intel_pcie_host_setup(struct intel_pcie *pcie)
 	intel_pcie_link_setup(pcie);
 	intel_pcie_init_n_fts(pci);
 
-	ret = dw_pcie_setup_rc(&pci->pp);
-	if (ret)
-		goto err;
-
 	dw_pcie_upconfig_setup(pci);
 
-	intel_pcie_device_rst_deassert(pcie);
-	intel_pcie_ltssm_enable(pcie);
-
-	ret = dw_pcie_wait_for_link(pci);
-	if (ret)
-		goto err;
-
 	intel_pcie_core_irq_enable(pcie);
 
 	return 0;
 
-err:
-	phy_exit(pcie->phy);
 phy_err:
 	clk_disable_unprepare(pcie->core_clk);
 clk_err:
@@ -387,6 +384,7 @@ static int intel_pcie_rc_init(struct dw_pcie_rp *pp)
 }
 
 static const struct dw_pcie_ops intel_pcie_ops = {
+	.start_link = intel_pcie_start_link,
 };
 
 static const struct dw_pcie_host_ops intel_pcie_dw_ops = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0858/2077] PCI: loongson: Do not ignore downstream devices on external bridges
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (856 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0857/2077] PCI: intel-gw: Add .start_link() callback Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0859/2077] rust: alloc: fix assert in `Vec::reserve` doc test Greg Kroah-Hartman
                   ` (139 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jiaxun Yang, Lain  Fearyncess  Yang,
	Rong Zhang, Manivannan Sadhasivam, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rong Zhang <i@rong.moe>

[ Upstream commit 1389ab9bf9f627d4daed86f492091b00f110aa86 ]

Loongson PCI host controllers have a hardware quirk that requires
software to ignore downstream devices with device number > 0 on the
internal bridges. The current implementation applies the workaround to
all non-root buses, which breaks external bridges (e.g., PCIe switches)
with multiple downstream devices.

Fix it by only applying the workaround to internal bridges.

Tested on Loongson-LS3A4000-7A1000-NUC-SE, using AMD Promontory 21
chipset add-in card [1].

  $ lspci -tnnnvvv
  -[0000:00]-+-00.0  Loongson Technology LLC 7A1000 Chipset Hyper Transport Bridge Controller [0014:7a00]
             +-00.1  Loongson Technology LLC 7A2000 Chipset Hyper Transport Bridge Controller [0014:7a10]
             +-03.0  Loongson Technology LLC 2K1000/2000 / 7A1000 Chipset Gigabit Ethernet Controller [0014:7a03]
             +-04.0  Loongson Technology LLC 2K1000 / 7A1000/2000 Chipset USB OHCI Controller [0014:7a24]
             +-04.1  Loongson Technology LLC 2K1000 / 7A1000/2000 Chipset USB EHCI Controller [0014:7a14]
             +-05.0  Loongson Technology LLC 2K1000 / 7A1000/2000 Chipset USB OHCI Controller [0014:7a24]
             +-05.1  Loongson Technology LLC 2K1000 / 7A1000/2000 Chipset USB EHCI Controller [0014:7a14]
             +-06.0  Loongson Technology LLC 7A1000 Chipset Vivante GC1000 GPU [0014:7a15]
             +-06.1  Loongson Technology LLC 2K1000 / 7A1000 Chipset Display Controller [0014:7a06]
             +-07.0  Loongson Technology LLC 2K1000/2000/3000 / 3B6000M / 7A1000/2000 Chipset HD Audio Controller [0014:7a07]
             +-08.0  Loongson Technology LLC 2K1000 / 7A1000 Chipset 3Gb/s SATA AHCI Controller [0014:7a08]
             +-08.1  Loongson Technology LLC 2K1000 / 7A1000 Chipset 3Gb/s SATA AHCI Controller [0014:7a08]
             +-08.2  Loongson Technology LLC 2K1000 / 7A1000 Chipset 3Gb/s SATA AHCI Controller [0014:7a08]
             +-09.0-[01]----00.0  Qualcomm Technologies, Inc QCNFA765 Wireless Network Adapter [17cb:1103]
             +-0a.0-[02]----00.0  Etron Technology, Inc. EJ188/EJ198 USB 3.0 Host Controller [1b6f:7052]
             +-0f.0-[03-08]----00.0-[04-08]--+-00.0-[05]----00.0  Shenzhen Longsys Electronics Co., Ltd. FORESEE XP1000 / Lexar Professional CFexpress Type B Gold series, NM620 PCIe NVME SSD (DRAM-less) [1d97:5216]
             |                               +-08.0-[06]----00.0  MAXIO Technology (Hangzhou) Ltd. NVMe SSD Controller MAP1202 (DRAM-less) [1e4b:1202]
             |                               +-0c.0-[07]----00.0  Advanced Micro Devices, Inc. [AMD] 600 Series Chipset USB 3.2 Controller [1022:43f7]
             |                               \-0d.0-[08]----00.0  Advanced Micro Devices, Inc. [AMD] 600 Series Chipset SATA Controller [1022:43f6]
             \-16.0  Loongson Technology LLC 7A1000 Chipset SPI Controller [0014:7a0b]

Fixes: 2410e3301fcc ("PCI: loongson: Don't access non-existent devices")
Co-developed-by: Jiaxun Yang <jiaxun.yang@flygoat.com>
Signed-off-by: Jiaxun Yang <jiaxun.yang@flygoat.com>
Co-developed-by: Lain "Fearyncess" Yang <i@lain.vg>
Signed-off-by: Lain "Fearyncess" Yang <i@lain.vg>
Signed-off-by: Rong Zhang <i@rong.moe>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Link: https://oshwhub.com/wesd/b650 [1]
Link: https://patch.msgid.link/20260501-ls7a-bridge-fixes-v2-1-69fa93683805@rong.moe
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/pci-loongson.c | 31 ++++++++++++++-------------
 1 file changed, 16 insertions(+), 15 deletions(-)

diff --git a/drivers/pci/controller/pci-loongson.c b/drivers/pci/controller/pci-loongson.c
index 9609e6f50b9816..d0c643996476f8 100644
--- a/drivers/pci/controller/pci-loongson.c
+++ b/drivers/pci/controller/pci-loongson.c
@@ -80,6 +80,18 @@ DECLARE_PCI_FIXUP_EARLY(PCI_VENDOR_ID_LOONGSON,
 DECLARE_PCI_FIXUP_EARLY(PCI_VENDOR_ID_LOONGSON,
 			DEV_LS7A_LPC, system_bus_quirk);
 
+static const struct pci_device_id loongson_internal_bridge_devids[] = {
+	{ PCI_VDEVICE(LOONGSON, DEV_LS2K_PCIE_PORT0) },
+	{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT0) },
+	{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT1) },
+	{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT2) },
+	{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT3) },
+	{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT4) },
+	{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT5) },
+	{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT6) },
+	{ 0, },
+};
+
 /*
  * Some Loongson PCIe ports have hardware limitations on their Maximum Read
  * Request Size. They can't handle anything larger than this.  Sane
@@ -92,24 +104,13 @@ static void loongson_set_min_mrrs_quirk(struct pci_dev *pdev)
 {
 	struct pci_bus *bus = pdev->bus;
 	struct pci_dev *bridge;
-	static const struct pci_device_id bridge_devids[] = {
-		{ PCI_VDEVICE(LOONGSON, DEV_LS2K_PCIE_PORT0) },
-		{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT0) },
-		{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT1) },
-		{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT2) },
-		{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT3) },
-		{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT4) },
-		{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT5) },
-		{ PCI_VDEVICE(LOONGSON, DEV_LS7A_PCIE_PORT6) },
-		{ 0, },
-	};
 
 	/* look for the matching bridge */
 	while (!pci_is_root_bus(bus)) {
 		bridge = bus->self;
 		bus = bus->parent;
 
-		if (pci_match_id(bridge_devids, bridge)) {
+		if (pci_match_id(loongson_internal_bridge_devids, bridge)) {
 			if (pcie_get_readrq(pdev) > 256) {
 				pci_info(pdev, "limiting MRRS to 256\n");
 				pcie_set_readrq(pdev, 256);
@@ -266,11 +267,11 @@ static void __iomem *pci_loongson_map_bus(struct pci_bus *bus,
 	struct loongson_pci *priv = pci_bus_to_loongson_pci(bus);
 
 	/*
-	 * Do not read more than one device on the bus other than
-	 * the host bus.
+	 * Do not read more than one device on the internal bridges.
 	 */
 	if ((priv->data->flags & FLAG_DEV_FIX) && bus->self) {
-		if (!pci_is_root_bus(bus) && (device > 0))
+		if (!pci_is_root_bus(bus) && (device > 0) &&
+		    pci_match_id(loongson_internal_bridge_devids, bus->self))
 			return NULL;
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0859/2077] rust: alloc: fix assert in `Vec::reserve` doc test
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (857 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0858/2077] PCI: loongson: Do not ignore downstream devices on external bridges Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0860/2077] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() Greg Kroah-Hartman
                   ` (138 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Miguel Ojeda, Hsiu Che Yu,
	Alice Ryhl, Alexandre Courbot, Danilo Krummrich, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hsiu Che Yu <yu.whisper.personal@gmail.com>

[ Upstream commit 75619f2df7a5da6ffb61eedc2a73fdf70c65471c ]

The assert in the doctest used `>= 10`, which only checks that the
capacity can hold `additional` elements, ignoring the existing length
of `v`. The correct check should ensure there is room for `additional`
*extra* elements on top of what is already in the vector.

Fix the assert to use `>= v.len() + 10` so the example accurately
reflects the actual semantics of the function.

Reported-by: Miguel Ojeda <miguel.ojeda.sandonis@gmail.com>
Closes: https://lore.kernel.org/rust-for-linux/CANiq72nkXWhjK9iFRrhGtkMZGsvNE_zVsu4JnxaFRfxWL7RRdg@mail.gmail.com/
Fixes: 2aac4cd7dae3d ("rust: alloc: implement kernel `Vec` type")
Signed-off-by: Hsiu Che Yu <yu.whisper.personal@gmail.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Reviewed-by: Alexandre Courbot <acourbot@nvidia.com>
Link: https://patch.msgid.link/20260427-doctest-kvec-reserve-v1-1-0623abcd9c2e@gmail.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 rust/kernel/alloc/kvec.rs | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/rust/kernel/alloc/kvec.rs b/rust/kernel/alloc/kvec.rs
index 5c24fcf05bdfe6..0f7b43e81030cd 100644
--- a/rust/kernel/alloc/kvec.rs
+++ b/rust/kernel/alloc/kvec.rs
@@ -614,7 +614,7 @@ where
     ///
     /// v.reserve(10, GFP_KERNEL)?;
     /// let cap = v.capacity();
-    /// assert!(cap >= 10);
+    /// assert!(cap >= v.len() + 10);
     ///
     /// v.reserve(10, GFP_KERNEL)?;
     /// let new_cap = v.capacity();
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0860/2077] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (858 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0859/2077] rust: alloc: fix assert in `Vec::reserve` doc test Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0861/2077] bus: mhi: ep: Add missing state_lock protection for mhi_state access Greg Kroah-Hartman
                   ` (137 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sumit Kumar, Manivannan Sadhasivam,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sumit Kumar <sumit.kumar@oss.qualcomm.com>

[ Upstream commit 9dece4435d396e9877e27483552b910ba8654169 ]

There is a potential deadlock scenario in mhi_ep_reset_worker() where
the state_lock mutex is acquired twice in the same call chain:

mhi_ep_reset_worker()
  mutex_lock(&mhi_cntrl->state_lock)
    mhi_ep_power_up()
      mhi_ep_set_ready_state()
        mutex_lock(&mhi_cntrl->state_lock)  <- Deadlock

Fix this by releasing the state_lock before calling mhi_ep_power_up().
The lock is only needed to protect current MHI state read operation. The
lock can be safely released before proceeding with the power up sequence.

Fixes: 7a97b6b47353 ("bus: mhi: ep: Add support for handling MHI_RESET")
Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://patch.msgid.link/20260414-reset_worker_deadlock-v2-1-42fd682b45db@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/bus/mhi/ep/main.c | 7 +++----
 1 file changed, 3 insertions(+), 4 deletions(-)

diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c
index 0277e1ab119886..425525e232f919 100644
--- a/drivers/bus/mhi/ep/main.c
+++ b/drivers/bus/mhi/ep/main.c
@@ -1087,11 +1087,12 @@ static void mhi_ep_reset_worker(struct work_struct *work)
 
 	mhi_ep_power_down(mhi_cntrl);
 
-	mutex_lock(&mhi_cntrl->state_lock);
-
 	/* Reset MMIO to signal host that the MHI_RESET is completed in endpoint */
 	mhi_ep_mmio_reset(mhi_cntrl);
+
+	mutex_lock(&mhi_cntrl->state_lock);
 	cur_state = mhi_cntrl->mhi_state;
+	mutex_unlock(&mhi_cntrl->state_lock);
 
 	/*
 	 * Only proceed further if the reset is due to SYS_ERR. The host will
@@ -1100,8 +1101,6 @@ static void mhi_ep_reset_worker(struct work_struct *work)
 	 */
 	if (cur_state == MHI_STATE_SYS_ERR)
 		mhi_ep_power_up(mhi_cntrl);
-
-	mutex_unlock(&mhi_cntrl->state_lock);
 }
 
 /*
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0861/2077] bus: mhi: ep: Add missing state_lock protection for mhi_state access
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (859 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0860/2077] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0862/2077] coresight: fix missing error code when trace ID is invalid Greg Kroah-Hartman
                   ` (136 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sumit Kumar, Manivannan Sadhasivam,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sumit Kumar <sumit.kumar@oss.qualcomm.com>

[ Upstream commit ce3e534ee9c8d13a68c8a611c3b7bd0c2152d2ab ]

The mhi_cntrl->mhi_state field should be protected by state_lock to
ensure atomic state transitions. However, mhi_ep_power_up() access
mhi_state without holding this lock, which can race with concurrent state
transitions and lead to state corruption.

Add proper state_lock protection around mhi_state access.

Fixes: fb3a26b7e8af ("bus: mhi: ep: Add support for powering up the MHI endpoint stack")
Fixes: f7d0806bdb1b3 ("bus: mhi: ep: Add support for handling SYS_ERR condition")
Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://patch.msgid.link/20260414-reset_worker_deadlock-v2-2-42fd682b45db@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/bus/mhi/ep/main.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c
index 425525e232f919..5330b03dc6369c 100644
--- a/drivers/bus/mhi/ep/main.c
+++ b/drivers/bus/mhi/ep/main.c
@@ -1147,7 +1147,9 @@ int mhi_ep_power_up(struct mhi_ep_cntrl *mhi_cntrl)
 	for (i = 0; i < mhi_cntrl->event_rings; i++)
 		mhi_ep_ring_init(&mhi_cntrl->mhi_event[i].ring, RING_TYPE_ER, i);
 
+	mutex_lock(&mhi_cntrl->state_lock);
 	mhi_cntrl->mhi_state = MHI_STATE_RESET;
+	mutex_unlock(&mhi_cntrl->state_lock);
 
 	/* Set AMSS EE before signaling ready state */
 	mhi_ep_mmio_set_env(mhi_cntrl, MHI_EE_AMSS);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0862/2077] coresight: fix missing error code when trace ID is invalid
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (860 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0861/2077] bus: mhi: ep: Add missing state_lock protection for mhi_state access Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0863/2077] clk: qcom: cmnpll: Account for reference clock divider Greg Kroah-Hartman
                   ` (135 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, James Clark, Richard Cheng, Jie Gan,
	Leo Yan, Suzuki K Poulose, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jie Gan <jie.gan@oss.qualcomm.com>

[ Upstream commit f4526ffee6ff9f5845b430957417149eded74bf3 ]

When coresight_path_assign_trace_id() cannot assign a valid trace ID,
coresight_enable_sysfs() takes the err_path goto with ret still 0,
returning success to the caller despite no trace session being started.

Change coresight_path_assign_trace_id() to return int, moving the
IS_VALID_CS_TRACE_ID() check inside it so it returns -EINVAL on failure
and 0 on success. Update both callers to propagate this return value
directly instead of inspecting path->trace_id after the call.

Fixes: d87d76d823d1 ("Coresight: Allocate trace ID after building the path")
Reviewed-by: James Clark <james.clark@linaro.org>
Reviewed-by: Richard Cheng <icheng@nvidia.com>
Signed-off-by: Jie Gan <jie.gan@oss.qualcomm.com>
Reviewed-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20260512-fix-trace-id-error-v4-1-eb3de789767a@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwtracing/coresight/coresight-core.c  | 23 +++++++++++--------
 .../hwtracing/coresight/coresight-etm-perf.c  |  5 ++--
 drivers/hwtracing/coresight/coresight-priv.h  |  2 +-
 drivers/hwtracing/coresight/coresight-sysfs.c |  4 ++--
 4 files changed, 19 insertions(+), 15 deletions(-)

diff --git a/drivers/hwtracing/coresight/coresight-core.c b/drivers/hwtracing/coresight/coresight-core.c
index 46f247f73cf64a..2105bb8139407b 100644
--- a/drivers/hwtracing/coresight/coresight-core.c
+++ b/drivers/hwtracing/coresight/coresight-core.c
@@ -739,8 +739,8 @@ static int coresight_get_trace_id(struct coresight_device *csdev,
  * Call this after creating the path and before enabling it. This leaves
  * the trace ID set on the path, or it remains 0 if it couldn't be assigned.
  */
-void coresight_path_assign_trace_id(struct coresight_path *path,
-				    enum cs_mode mode)
+int coresight_path_assign_trace_id(struct coresight_path *path,
+				   enum cs_mode mode)
 {
 	struct coresight_device *sink = coresight_get_sink(path);
 	struct coresight_node *nd;
@@ -750,15 +750,18 @@ void coresight_path_assign_trace_id(struct coresight_path *path,
 		/* Assign a trace ID to the path for the first device that wants to do it */
 		trace_id = coresight_get_trace_id(nd->csdev, mode, sink);
 
-		/*
-		 * 0 in this context is that it didn't want to assign so keep searching.
-		 * Non 0 is either success or fail.
-		 */
-		if (trace_id != 0) {
-			path->trace_id = trace_id;
-			return;
-		}
+		/* 0 means the device has no ID assignment, so keep searching */
+		if (trace_id == 0)
+			continue;
+
+		if (!IS_VALID_CS_TRACE_ID(trace_id))
+			return -EINVAL;
+
+		path->trace_id = trace_id;
+		return 0;
 	}
+
+	return -EINVAL;
 }
 
 /**
diff --git a/drivers/hwtracing/coresight/coresight-etm-perf.c b/drivers/hwtracing/coresight/coresight-etm-perf.c
index f85dedf89a3f9e..89ba7c9a661370 100644
--- a/drivers/hwtracing/coresight/coresight-etm-perf.c
+++ b/drivers/hwtracing/coresight/coresight-etm-perf.c
@@ -324,6 +324,7 @@ static void *etm_setup_aux(struct perf_event *event, void **pages,
 	struct coresight_device *sink = NULL;
 	struct coresight_device *user_sink = NULL, *last_sink = NULL;
 	struct etm_event_data *event_data = NULL;
+	int ret;
 
 	event_data = alloc_event_data(cpu);
 	if (!event_data)
@@ -420,8 +421,8 @@ static void *etm_setup_aux(struct perf_event *event, void **pages,
 		}
 
 		/* ensure we can allocate a trace ID for this CPU */
-		coresight_path_assign_trace_id(path, CS_MODE_PERF);
-		if (!IS_VALID_CS_TRACE_ID(path->trace_id)) {
+		ret = coresight_path_assign_trace_id(path, CS_MODE_PERF);
+		if (ret) {
 			cpumask_clear_cpu(cpu, mask);
 			coresight_release_path(path);
 			continue;
diff --git a/drivers/hwtracing/coresight/coresight-priv.h b/drivers/hwtracing/coresight/coresight-priv.h
index 1ea882dffd703b..34c7e792adbd99 100644
--- a/drivers/hwtracing/coresight/coresight-priv.h
+++ b/drivers/hwtracing/coresight/coresight-priv.h
@@ -153,7 +153,7 @@ int coresight_make_links(struct coresight_device *orig,
 void coresight_remove_links(struct coresight_device *orig,
 			    struct coresight_connection *conn);
 u32 coresight_get_sink_id(struct coresight_device *csdev);
-void coresight_path_assign_trace_id(struct coresight_path *path,
+int coresight_path_assign_trace_id(struct coresight_path *path,
 				   enum cs_mode mode);
 
 #if IS_ENABLED(CONFIG_CORESIGHT_SOURCE_ETM3X)
diff --git a/drivers/hwtracing/coresight/coresight-sysfs.c b/drivers/hwtracing/coresight/coresight-sysfs.c
index d2a6ed8bcc74d6..b6a870399e8341 100644
--- a/drivers/hwtracing/coresight/coresight-sysfs.c
+++ b/drivers/hwtracing/coresight/coresight-sysfs.c
@@ -211,8 +211,8 @@ int coresight_enable_sysfs(struct coresight_device *csdev)
 		goto out;
 	}
 
-	coresight_path_assign_trace_id(path, CS_MODE_SYSFS);
-	if (!IS_VALID_CS_TRACE_ID(path->trace_id))
+	ret = coresight_path_assign_trace_id(path, CS_MODE_SYSFS);
+	if (ret)
 		goto err_path;
 
 	ret = coresight_enable_path(path, CS_MODE_SYSFS);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0863/2077] clk: qcom: cmnpll: Account for reference clock divider
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (861 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0862/2077] coresight: fix missing error code when trace ID is invalid Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0864/2077] dt-bindings: clock: qcom,sm6125-dispcc: reference qcom,gcc.yaml Greg Kroah-Hartman
                   ` (134 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Luo Jie, Konrad Dybcio,
	George Moussalem, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Luo Jie <jie.luo@oss.qualcomm.com>

[ Upstream commit 88c543fff756450bcd04ec4560c4440be36c9e75 ]

The clk_cmn_pll_recalc_rate() function must account for the reference clock
divider programmed in CMN_PLL_REFCLK_CONFIG. Without this fix, platforms
with a reference divider other than 1 calculate incorrect CMN PLL rates.
For example, on IPQ5332 where the reference divider is 2, the computed rate
becomes twice the actual output.

Read CMN_PLL_REFCLK_DIV and divide the parent rate by this value before
applying the 2 * FACTOR scaling. This yields the correct rate calculation:
rate = (parent_rate / ref_div) * 2 * factor.

Maintain backward compatibility with earlier platforms (e.g. IPQ9574,
IPQ5424, IPQ5018) that use ref_div = 1.

Fixes: f81715a4c87c ("clk: qcom: Add CMN PLL clock controller driver for IPQ SoC")
Signed-off-by: Luo Jie <jie.luo@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Tested-by: George Moussalem <george.moussalem@outlook.com>
Link: https://lore.kernel.org/r/20260106-qcom_ipq5332_cmnpll-v2-1-f9f7e4efbd79@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clk/qcom/ipq-cmn-pll.c | 11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

diff --git a/drivers/clk/qcom/ipq-cmn-pll.c b/drivers/clk/qcom/ipq-cmn-pll.c
index 5763e4df59a1a2..889c176089c2fe 100644
--- a/drivers/clk/qcom/ipq-cmn-pll.c
+++ b/drivers/clk/qcom/ipq-cmn-pll.c
@@ -199,7 +199,7 @@ static unsigned long clk_cmn_pll_recalc_rate(struct clk_hw *hw,
 					     unsigned long parent_rate)
 {
 	struct clk_cmn_pll *cmn_pll = to_clk_cmn_pll(hw);
-	u32 val, factor;
+	u32 val, factor, ref_div;
 
 	/*
 	 * The value of CMN_PLL_DIVIDER_CTRL_FACTOR is automatically adjusted
@@ -207,8 +207,15 @@ static unsigned long clk_cmn_pll_recalc_rate(struct clk_hw *hw,
 	 */
 	regmap_read(cmn_pll->regmap, CMN_PLL_DIVIDER_CTRL, &val);
 	factor = FIELD_GET(CMN_PLL_DIVIDER_CTRL_FACTOR, val);
+	if (WARN_ON(factor == 0))
+		factor = 1;
 
-	return parent_rate * 2 * factor;
+	regmap_read(cmn_pll->regmap, CMN_PLL_REFCLK_CONFIG, &val);
+	ref_div = FIELD_GET(CMN_PLL_REFCLK_DIV, val);
+	if (WARN_ON(ref_div == 0))
+		ref_div = 1;
+
+	return div_u64((u64)parent_rate * 2 * factor, ref_div);
 }
 
 static int clk_cmn_pll_determine_rate(struct clk_hw *hw,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0864/2077] dt-bindings: clock: qcom,sm6125-dispcc: reference qcom,gcc.yaml
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (862 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0863/2077] clk: qcom: cmnpll: Account for reference clock divider Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0865/2077] PCI: dwc: Apply ECRC workaround for DesignWare cores prior to 5.10a Greg Kroah-Hartman
                   ` (133 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, kernel test robot, Biswapriyo Nath,
	Krzysztof Kozlowski, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Biswapriyo Nath <nathbappai@gmail.com>

[ Upstream commit dbabf6a32ffb69a604f966ec01a20a060836939d ]

Just like most of Qualcomm clock controllers, we can reference common
qcom,gcc.yaml schema to unify the common parts of the binding. This
also adds the '#reset-cells' property which is permitted for the
SM6125 SoC clock controllers, but not listed as a valid property.

Fixes: bb4d28e377cf ("arm64: dts: qcom: sm6125: Add missing MDSS core reset")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202603150629.GYoouFwZ-lkp@intel.com/
Signed-off-by: Biswapriyo Nath <nathbappai@gmail.com>
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260330-ginkgo-add-usb-ir-vib-v3-2-c4b778b0d7f8@gmail.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../bindings/clock/qcom,dispcc-sm6125.yaml      | 17 +++++------------
 1 file changed, 5 insertions(+), 12 deletions(-)

diff --git a/Documentation/devicetree/bindings/clock/qcom,dispcc-sm6125.yaml b/Documentation/devicetree/bindings/clock/qcom,dispcc-sm6125.yaml
index ef2b1e2044309a..a177a1934b19f9 100644
--- a/Documentation/devicetree/bindings/clock/qcom,dispcc-sm6125.yaml
+++ b/Documentation/devicetree/bindings/clock/qcom,dispcc-sm6125.yaml
@@ -42,12 +42,6 @@ properties:
       - const: cfg_ahb_clk
       - const: gcc_disp_gpll0_div_clk_src
 
-  '#clock-cells':
-    const: 1
-
-  '#power-domain-cells':
-    const: 1
-
   power-domains:
     description:
       A phandle and PM domain specifier for the CX power domain.
@@ -58,18 +52,16 @@ properties:
       A phandle to an OPP node describing the power domain's performance point.
     maxItems: 1
 
-  reg:
-    maxItems: 1
-
 required:
   - compatible
-  - reg
   - clocks
   - clock-names
-  - '#clock-cells'
   - '#power-domain-cells'
 
-additionalProperties: false
+allOf:
+  - $ref: qcom,gcc.yaml#
+
+unevaluatedProperties: false
 
 examples:
   - |
@@ -101,6 +93,7 @@ examples:
       power-domains = <&rpmpd SM6125_VDDCX>;
 
       #clock-cells = <1>;
+      #reset-cells = <1>;
       #power-domain-cells = <1>;
     };
 ...
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0865/2077] PCI: dwc: Apply ECRC workaround for DesignWare cores prior to 5.10a
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (863 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0864/2077] dt-bindings: clock: qcom,sm6125-dispcc: reference qcom,gcc.yaml Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:08 ` [PATCH 7.1 0866/2077] PCI: qcom: Set max OPP before DBI access during resume Greg Kroah-Hartman
                   ` (132 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Manikanta Maddireddy,
	Manivannan Sadhasivam, Bjorn Helgaas, Jon Hunter, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Manikanta Maddireddy <mmaddireddy@nvidia.com>

[ Upstream commit 1e1b554c2b910591aa3fffdb8077a2ca33bf3cb2 ]

The ECRC (TLP digest) workaround was originally applied only for DesignWare
core version 4.90a. Per discussion in Synopsys case, the dependency of the
iATU TD bit on ECRC generation was removed in 5.10a, so apply the
workaround for all DWC versions below that release.

Replace the misleading comment that referred to raw version constants
with readable DesignWare release name to help readability.

Fixes: b210b1595606 ("PCI: dwc: Apply ECRC workaround to DesignWare 5.00a as well")
Signed-off-by: Manikanta Maddireddy <mmaddireddy@nvidia.com>
[mani: corrected fixes tag format]
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Jon Hunter <jonathanh@nvidia.com>
Link: https://patch.msgid.link/20260410062507.657453-1-mmaddireddy@nvidia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/dwc/pcie-designware.c | 16 ++++++++--------
 drivers/pci/controller/dwc/pcie-designware.h |  1 +
 2 files changed, 9 insertions(+), 8 deletions(-)

diff --git a/drivers/pci/controller/dwc/pcie-designware.c b/drivers/pci/controller/dwc/pcie-designware.c
index c11cf61b8319e6..76c9a0a10367b3 100644
--- a/drivers/pci/controller/dwc/pcie-designware.c
+++ b/drivers/pci/controller/dwc/pcie-designware.c
@@ -487,13 +487,13 @@ static inline void dw_pcie_writel_atu_ob(struct dw_pcie *pci, u32 index, u32 reg
 static inline u32 dw_pcie_enable_ecrc(u32 val)
 {
 	/*
-	 * DWC versions 0x3530302a and 0x3536322a have a design issue where
-	 * the 'TD' bit in the Control register-1 of the ATU outbound
-	 * region acts like an override for the ECRC setting, i.e., the
-	 * presence of TLP Digest (ECRC) in the outgoing TLPs is solely
-	 * determined by this bit. This is contrary to the PCIe spec which
-	 * says that the enablement of the ECRC is solely determined by the
-	 * AER registers.
+	 * DesignWare core versions prior to 5.10A have a design issue where the
+	 * 'TD' bit in the Control register-1 of the ATU outbound region acts
+	 * like an override for the ECRC setting, i.e., the presence of TLP
+	 * Digest (ECRC) in the outgoing TLPs is solely determined by this
+	 * bit. This is contrary to the PCIe spec which says that the
+	 * enablement of the ECRC is solely determined by the AER
+	 * registers.
 	 *
 	 * Because of this, even when the ECRC is enabled through AER
 	 * registers, the transactions going through ATU won't have TLP
@@ -563,7 +563,7 @@ int dw_pcie_prog_outbound_atu(struct dw_pcie *pci,
 	if (upper_32_bits(limit_addr) > upper_32_bits(parent_bus_addr) &&
 	    dw_pcie_ver_is_ge(pci, 460A))
 		val |= PCIE_ATU_INCREASE_REGION_SIZE;
-	if (dw_pcie_ver_is(pci, 490A) || dw_pcie_ver_is(pci, 500A))
+	if (!dw_pcie_ver_is_ge(pci, 510A))
 		val = dw_pcie_enable_ecrc(val);
 	dw_pcie_writel_atu_ob(pci, atu->index, PCIE_ATU_REGION_CTRL1, val);
 
diff --git a/drivers/pci/controller/dwc/pcie-designware.h b/drivers/pci/controller/dwc/pcie-designware.h
index 3e69ef60165b0e..a07b7abda41f3f 100644
--- a/drivers/pci/controller/dwc/pcie-designware.h
+++ b/drivers/pci/controller/dwc/pcie-designware.h
@@ -35,6 +35,7 @@
 #define DW_PCIE_VER_480A		0x3438302a
 #define DW_PCIE_VER_490A		0x3439302a
 #define DW_PCIE_VER_500A		0x3530302a
+#define DW_PCIE_VER_510A		0x3531302a
 #define DW_PCIE_VER_520A		0x3532302a
 #define DW_PCIE_VER_540A		0x3534302a
 #define DW_PCIE_VER_562A		0x3536322a
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0866/2077] PCI: qcom: Set max OPP before DBI access during resume
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (864 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0865/2077] PCI: dwc: Apply ECRC workaround for DesignWare cores prior to 5.10a Greg Kroah-Hartman
@ 2026-07-21 15:08 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0867/2077] phy: phy-can-transceiver: Check driver match and driver data against NULL Greg Kroah-Hartman
                   ` (131 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:08 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Qiang Yu, Manivannan Sadhasivam,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Qiang Yu <qiang.yu@oss.qualcomm.com>

[ Upstream commit 5dc31cd4a91a7f006d23efa97a5594a7e3ac7790 ]

During resume, qcom_pcie_icc_opp_update() may access DBI registers before
the OPP votes are restored, triggering NoC errors.

Set the PCIe controller to the maximum OPP first in resume_noirq(), then
proceed with link/DBI accesses. The OPP is later updated again based on
the actual link bandwidth requirements.

Introduce a helper to reuse the max-OPP setup code and share it with
probe().

Fixes: 5b6272e0efd5 ("PCI: qcom: Add OPP support to scale performance")
Signed-off-by: Qiang Yu <qiang.yu@oss.qualcomm.com>
[mani: commit log and error log rewording]
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Link: https://patch.msgid.link/20260416-setmaxopp-v1-1-6a74e2d945a0@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/dwc/pcie-qcom.c | 42 ++++++++++++++++----------
 1 file changed, 26 insertions(+), 16 deletions(-)

diff --git a/drivers/pci/controller/dwc/pcie-qcom.c b/drivers/pci/controller/dwc/pcie-qcom.c
index 7d8eaef436efec..8604aa564dce67 100644
--- a/drivers/pci/controller/dwc/pcie-qcom.c
+++ b/drivers/pci/controller/dwc/pcie-qcom.c
@@ -1613,6 +1613,22 @@ static void qcom_pcie_icc_opp_update(struct qcom_pcie *pcie)
 	}
 }
 
+static int qcom_pcie_set_max_opp(struct device *dev)
+{
+	unsigned long max_freq = ULONG_MAX;
+	struct dev_pm_opp *opp;
+	int ret;
+
+	opp = dev_pm_opp_find_freq_floor(dev, &max_freq);
+	if (IS_ERR(opp))
+		return PTR_ERR(opp);
+
+	ret = dev_pm_opp_set_opp(dev, opp);
+	dev_pm_opp_put(opp);
+
+	return ret;
+}
+
 static int qcom_pcie_link_transition_count(struct seq_file *s, void *data)
 {
 	struct qcom_pcie *pcie = (struct qcom_pcie *)dev_get_drvdata(s->private);
@@ -1851,9 +1867,7 @@ static int qcom_pcie_probe(struct platform_device *pdev)
 	struct qcom_pcie_perst *perst, *tmp_perst;
 	struct qcom_pcie_port *port, *tmp_port;
 	const struct qcom_pcie_cfg *pcie_cfg;
-	unsigned long max_freq = ULONG_MAX;
 	struct device *dev = &pdev->dev;
-	struct dev_pm_opp *opp;
 	struct qcom_pcie *pcie;
 	struct dw_pcie_rp *pp;
 	struct resource *res;
@@ -1957,21 +1971,9 @@ static int qcom_pcie_probe(struct platform_device *pdev)
 	 * probe(), OPP will be updated using qcom_pcie_icc_opp_update().
 	 */
 	if (!ret) {
-		opp = dev_pm_opp_find_freq_floor(dev, &max_freq);
-		if (IS_ERR(opp)) {
-			ret = PTR_ERR(opp);
-			dev_err_probe(pci->dev, ret,
-				      "Unable to find max freq OPP\n");
-			goto err_pm_runtime_put;
-		} else {
-			ret = dev_pm_opp_set_opp(dev, opp);
-		}
-
-		dev_pm_opp_put(opp);
+		ret = qcom_pcie_set_max_opp(dev);
 		if (ret) {
-			dev_err_probe(pci->dev, ret,
-				      "Failed to set OPP for freq %lu\n",
-				      max_freq);
+			dev_err_probe(dev, ret, "Failed to set max OPP\n");
 			goto err_pm_runtime_put;
 		}
 
@@ -2106,6 +2108,14 @@ static int qcom_pcie_resume_noirq(struct device *dev)
 		return 0;
 
 	if (pm_suspend_target_state != PM_SUSPEND_MEM) {
+		if (pcie->use_pm_opp) {
+			ret = qcom_pcie_set_max_opp(dev);
+			if (ret) {
+				dev_err(dev, "Failed to set max OPP: %d\n", ret);
+				return ret;
+			}
+		}
+
 		ret = icc_enable(pcie->icc_cpu);
 		if (ret) {
 			dev_err(dev, "Failed to enable CPU-PCIe interconnect path: %d\n", ret);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0867/2077] phy: phy-can-transceiver: Check driver match and driver data against NULL
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (865 preceding siblings ...)
  2026-07-21 15:08 ` [PATCH 7.1 0866/2077] PCI: qcom: Set max OPP before DBI access during resume Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0868/2077] perf pmu-events AMD: Switch l2_itlb_misses to bp_l1_tlb_miss_l2_tlb_miss.all Greg Kroah-Hartman
                   ` (130 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Andy Shevchenko, Vinod Koul,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Andy Shevchenko <andriy.shevchenko@linux.intel.com>

[ Upstream commit ebee9004cc0200b2b708ebf7ac625d35c71c049f ]

Every platform driver can be forced to match a device that doesn't
match its list of device IDs because of device_match_driver_override()
so platform drivers that rely on the existence of a device's driver
data need to verify its presence.

Accordingly, add requisite match and driver data checks against NULL
to the driver where they are missing.

Fixes: a4a86d273ff1 ("phy: phy-can-transceiver: Add support for generic CAN transceiver driver")
Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Link: https://patch.msgid.link/20260513220336.369628-2-andriy.shevchenko@linux.intel.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/phy/phy-can-transceiver.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/phy/phy-can-transceiver.c b/drivers/phy/phy-can-transceiver.c
index 2b52e47f247a2b..1808f903c05707 100644
--- a/drivers/phy/phy-can-transceiver.c
+++ b/drivers/phy/phy-can-transceiver.c
@@ -162,6 +162,9 @@ static int can_transceiver_phy_probe(struct platform_device *pdev)
 	int err, i, num_ch = 1;
 
 	match = of_match_node(can_transceiver_phy_ids, pdev->dev.of_node);
+	if (!match || !match->data)
+		return -ENODEV;
+
 	drvdata = match->data;
 	if (drvdata->flags & CAN_TRANSCEIVER_DUAL_CH)
 		num_ch = 2;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0868/2077] perf pmu-events AMD: Switch l2_itlb_misses to bp_l1_tlb_miss_l2_tlb_miss.all
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (866 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0867/2077] phy: phy-can-transceiver: Check driver match and driver data against NULL Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0869/2077] perf unwind: Refactor get_entries to allow dynamic libdw/libunwind selection Greg Kroah-Hartman
                   ` (129 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sandipan Das, Ian Rogers,
	Adrian Hunter, Alexander Shishkin, Ingo Molnar, James Clark,
	Jiri Olsa, Namhyung Kim, Peter Zijlstra, Ravi Bangoria,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit 41a543c86d110073275e5294852d692e5faf6b3b ]

l2_itlb_misses is a valid legacy cache event name, hence allowing it
in all_events in metric.py. l2_itlb_misses was also a json event for
AMD zen1, zen2 and zen3.

For zen4, zen5 and zen6 the checking that metric events are within the
json was skipping l2_itlb_misses as it is a valid legacy event, however,
the PMU driver lacks the event mapping causing it to be a bad event when
used in the metric.

Add bp_l1_tlb_miss_l2_tlb_miss.all as the l2 itlb miss event (bp =
branch predictor, the AMD way to say itlb), so that is used in
preference to l2_itlb_misses when the event exists.

Remove l2_itlb_misses from metric.py as the legacy event isn't used by
any metrics and having it is error prone for newer AMD zen models.

Fixes: e596f329668ec2b5 ("perf jevents: Add itlb metric group for AMD")
Reviewed-by: Sandipan Das <sandipan.das@amd.com>
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Ravi Bangoria <ravi.bangoria@amd.com>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/pmu-events/amd_metrics.py | 2 +-
 tools/perf/pmu-events/metric.py      | 1 -
 2 files changed, 1 insertion(+), 2 deletions(-)

diff --git a/tools/perf/pmu-events/amd_metrics.py b/tools/perf/pmu-events/amd_metrics.py
index e2defaffde3e6b..971f6e7af1f828 100755
--- a/tools/perf/pmu-events/amd_metrics.py
+++ b/tools/perf/pmu-events/amd_metrics.py
@@ -268,7 +268,7 @@ def AmdDtlb() -> Optional[MetricGroup]:
 def AmdItlb():
     global _zen_model
     l2h = Event("bp_l1_tlb_miss_l2_tlb_hit", "bp_l1_tlb_miss_l2_hit")
-    l2m = Event("l2_itlb_misses")
+    l2m = Event("bp_l1_tlb_miss_l2_tlb_miss.all", "l2_itlb_misses",)
     l2r = l2h + l2m
 
     itlb_l1_mg = None
diff --git a/tools/perf/pmu-events/metric.py b/tools/perf/pmu-events/metric.py
index 585454828c2fe9..ac582db785fc10 100644
--- a/tools/perf/pmu-events/metric.py
+++ b/tools/perf/pmu-events/metric.py
@@ -25,7 +25,6 @@ def LoadEvents(directory: str) -> None:
       "cycles",
       "duration_time",
       "instructions",
-      "l2_itlb_misses",
   }
   for file in os.listdir(os.fsencode(directory)):
     filename = os.fsdecode(file)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0869/2077] perf unwind: Refactor get_entries to allow dynamic libdw/libunwind selection
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (867 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0868/2077] perf pmu-events AMD: Switch l2_itlb_misses to bp_l1_tlb_miss_l2_tlb_miss.all Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0870/2077] perf pmu: Skip test on Arm64 when #slots is zero Greg Kroah-Hartman
                   ` (128 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter, Albert Ou,
	Alexander Shishkin, Alexandre Ghiti, Andrew Jones, Athira Rajeev,
	Dapeng Mi, Dmitrii Dolgov, Florian Fainelli, Howard Chu,
	Ingo Molnar, James Clark, Jiri Olsa, John Garry, Leo Yan,
	libunwind-devel, Li Guan, Namhyung Kim, Palmer Dabbelt,
	Paul Walmsley, Peter Zijlstra, Shimin Guo, Thomas Richter,
	Tomas Glozar, Will Deacon, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit 4248ae6e799605b3e62855be6085935d89de50d1 ]

Currently, both libdw and libunwind define 'unwind__get_entries'. This
causes a duplicate symbol build failure when both are compiled into
perf.

This commit refactors the DWARF unwind post-processing to be
configurable at runtime via the .perfconfig file option
'unwind.style', or using the argument '--unwind-style' in the commands
'perf report', 'perf script' and 'perf inject', in a similar manner to
the addr2line or the disassembler style.

The file 'tools/perf/util/unwind.c' adds the top-level dispatch
function 'unwind__get_entries'. The backend implementations are
renamed to 'libdw__get_entries' and 'libunwind__get_entries'. Both are
attempted as fallbacks if not configured, or if the primary backend
fails.

Fixes: 2e9191573a69ff96 ("perf build: Remove NO_LIBDW_DWARF_UNWIND option")
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Albert Ou <aou@eecs.berkeley.edu>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Alexandre Ghiti <alex@ghiti.fr>
Cc: Andrew Jones <andrew.jones@oss.qualcomm.com>
Cc: Athira Rajeev <atrajeev@linux.ibm.com>
Cc: Dapeng Mi <dapeng1.mi@linux.intel.com>
Cc: Dmitrii Dolgov <9erthalion6@gmail.com>
Cc: Florian Fainelli <florian.fainelli@broadcom.com>
Cc: Howard Chu <howardchu95@gmail.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: John Garry <john.g.garry@oracle.com>
Cc: Leo Yan <leo.yan@linux.dev>
Cc: libunwind-devel@nongnu.org
Cc: Li Guan <guanli.oerv@isrc.iscas.ac.cn>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Palmer Dabbelt <palmer@dabbelt.com>
Cc: Paul Walmsley <pjw@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Shimin Guo <shimin.guo@skydio.com>
Cc: Thomas Richter <tmricht@linux.ibm.com>
Cc: Tomas Glozar <tglozar@redhat.com>
Cc: Will Deacon <will@kernel.org>
[ Don't mix declarations and code, move 'entries' variable to the start of scope ]
[ Use pr_warning_once() instead of pr_err() in stubs for get_entries(), suggested by a local sashiko instance ]
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-inject.c              |   4 +
 tools/perf/builtin-report.c              |   4 +
 tools/perf/builtin-script.c              |   4 +
 tools/perf/util/Build                    |   1 +
 tools/perf/util/config.c                 |   4 +
 tools/perf/util/symbol_conf.h            |  10 +++
 tools/perf/util/unwind-libdw.c           |  20 ++++-
 tools/perf/util/unwind-libunwind-local.c |  27 ++++--
 tools/perf/util/unwind-libunwind.c       |   2 +-
 tools/perf/util/unwind.c                 | 104 +++++++++++++++++++++++
 tools/perf/util/unwind.h                 |  61 ++++++++-----
 11 files changed, 208 insertions(+), 33 deletions(-)
 create mode 100644 tools/perf/util/unwind.c

diff --git a/tools/perf/builtin-inject.c b/tools/perf/builtin-inject.c
index 6ab20df358c43b..a2493f1097df97 100644
--- a/tools/perf/builtin-inject.c
+++ b/tools/perf/builtin-inject.c
@@ -26,6 +26,7 @@
 #include "util/synthetic-events.h"
 #include "util/thread.h"
 #include "util/namespaces.h"
+#include "util/unwind.h"
 #include "util/util.h"
 #include "util/tsc.h"
 
@@ -2563,6 +2564,9 @@ int cmd_inject(int argc, const char **argv)
 		OPT_STRING(0, "guestmount", &symbol_conf.guestmount, "directory",
 			   "guest mount directory under which every guest os"
 			   " instance has a subdir"),
+		OPT_CALLBACK(0, "unwind-style", NULL, "unwind style",
+			     "unwind styles (libdw,libunwind)",
+			     unwind__option),
 		OPT_BOOLEAN(0, "convert-callchain", &inject.convert_callchain,
 			    "Generate callchains using DWARF and drop register/stack data"),
 		OPT_END()
diff --git a/tools/perf/builtin-report.c b/tools/perf/builtin-report.c
index 95c0bdba6b1165..0b0966d94128ee 100644
--- a/tools/perf/builtin-report.c
+++ b/tools/perf/builtin-report.c
@@ -48,6 +48,7 @@
 #include "util/time-utils.h"
 #include "util/auxtrace.h"
 #include "util/units.h"
+#include "util/unwind.h"
 #include "util/util.h" // perf_tip()
 #include "ui/ui.h"
 #include "ui/progress.h"
@@ -1449,6 +1450,9 @@ int cmd_report(int argc, const char **argv)
 	OPT_CALLBACK(0, "addr2line-style", NULL, "addr2line style",
 		     "addr2line styles (libdw,llvm,libbfd,addr2line)",
 		     report_parse_addr2line_config),
+	OPT_CALLBACK(0, "unwind-style", NULL, "unwind style",
+		     "unwind styles (libdw,libunwind)",
+		     unwind__option),
 	OPT_BOOLEAN(0, "demangle", &symbol_conf.demangle,
 		    "Symbol demangling. Enabled by default, use --no-demangle to disable."),
 	OPT_BOOLEAN(0, "demangle-kernel", &symbol_conf.demangle_kernel,
diff --git a/tools/perf/builtin-script.c b/tools/perf/builtin-script.c
index c8ac9f01a36bc5..fd0b4609516b3e 100644
--- a/tools/perf/builtin-script.c
+++ b/tools/perf/builtin-script.c
@@ -63,6 +63,7 @@
 #include <linux/err.h>
 #include "util/dlfilter.h"
 #include "util/record.h"
+#include "util/unwind.h"
 #include "util/util.h"
 #include "util/cgroup.h"
 #include "util/annotate.h"
@@ -4159,6 +4160,9 @@ int cmd_script(int argc, const char **argv)
 			"Enable symbol demangling"),
 	OPT_BOOLEAN(0, "demangle-kernel", &symbol_conf.demangle_kernel,
 			"Enable kernel symbol demangling"),
+	OPT_CALLBACK(0, "unwind-style", NULL, "unwind style",
+		     "unwind styles (libdw,libunwind)",
+		     unwind__option),
 	OPT_STRING(0, "addr2line", &symbol_conf.addr2line_path, "path",
 			"addr2line binary to use for line numbers"),
 	OPT_STRING(0, "time", &script.time_str, "str",
diff --git a/tools/perf/util/Build b/tools/perf/util/Build
index 70cc91d00804d7..01edfccebb88e0 100644
--- a/tools/perf/util/Build
+++ b/tools/perf/util/Build
@@ -216,6 +216,7 @@ ifndef CONFIG_SETNS
 perf-util-y += setns.o
 endif
 
+perf-util-y += unwind.o
 perf-util-$(CONFIG_LIBDW) += probe-finder.o
 perf-util-$(CONFIG_LIBDW) += dwarf-aux.o
 perf-util-$(CONFIG_LIBDW) += dwarf-regs.o
diff --git a/tools/perf/util/config.c b/tools/perf/util/config.c
index 087002fb1b9bc8..7988149dc7ed8e 100644
--- a/tools/perf/util/config.c
+++ b/tools/perf/util/config.c
@@ -23,6 +23,7 @@
 #include "build-id.h"
 #include "debug.h"
 #include "config.h"
+#include "unwind.h"
 #include <sys/types.h>
 #include <sys/stat.h>
 #include <stdlib.h>
@@ -525,6 +526,9 @@ int perf_default_config(const char *var, const char *value,
 	if (strstarts(var, "addr2line."))
 		return addr2line_configure(var, value, dummy);
 
+	if (strstarts(var, "unwind."))
+		return unwind__configure(var, value, dummy);
+
 	/* Add other config variables here. */
 	return 0;
 }
diff --git a/tools/perf/util/symbol_conf.h b/tools/perf/util/symbol_conf.h
index 6cd454d7c98e6b..0dee5aa6a5340d 100644
--- a/tools/perf/util/symbol_conf.h
+++ b/tools/perf/util/symbol_conf.h
@@ -9,6 +9,15 @@
 struct strlist;
 struct intlist;
 
+enum unwind_style {
+	UNWIND_STYLE_UNKNOWN = 0,
+	UNWIND_STYLE_LIBDW,
+	UNWIND_STYLE_LIBUNWIND,
+};
+
+#define MAX_UNWIND_STYLE (UNWIND_STYLE_LIBUNWIND + 1)
+
+
 enum a2l_style {
 	A2L_STYLE_UNKNOWN = 0,
 	A2L_STYLE_LIBDW,
@@ -81,6 +90,7 @@ struct symbol_conf {
 	const char		*addr2line_path;
 	enum a2l_style	addr2line_style[MAX_A2L_STYLE];
 	int             addr2line_timeout_ms;
+	enum unwind_style unwind_style[MAX_UNWIND_STYLE];
 	unsigned long	time_quantum;
        struct strlist	*dso_list,
 			*comm_list,
diff --git a/tools/perf/util/unwind-libdw.c b/tools/perf/util/unwind-libdw.c
index 05e8e68bd49c44..7f35042be56779 100644
--- a/tools/perf/util/unwind-libdw.c
+++ b/tools/perf/util/unwind-libdw.c
@@ -339,7 +339,7 @@ frame_callback(Dwfl_Frame *state, void *arg)
 	       DWARF_CB_ABORT : DWARF_CB_OK;
 }
 
-int unwind__get_entries(unwind_entry_cb_t cb, void *arg,
+int libdw__get_entries(unwind_entry_cb_t cb, void *arg,
 			struct thread *thread,
 			struct perf_sample *data,
 			int max_stack,
@@ -353,10 +353,10 @@ int unwind__get_entries(unwind_entry_cb_t cb, void *arg,
 	static struct unwind_info *ui;
 	Dwfl *dwfl;
 	Dwarf_Word ip;
-	int err = -EINVAL, i;
+	int err = -EINVAL, i, entries;
 
 	if (!data->user_regs || !data->user_regs->regs)
-		return -EINVAL;
+		return 0;
 
 	ui = zalloc(sizeof(*ui) + sizeof(ui->entries[0]) * max_stack);
 	if (!ui)
@@ -430,6 +430,18 @@ int unwind__get_entries(unwind_entry_cb_t cb, void *arg,
 		map_symbol__exit(&ui->entries[i].ms);
 
 	dwfl_ui_ti->ui = NULL;
+	entries = (int)ui->idx;
 	free(ui);
-	return 0;
+	/*
+	 * Unwinder return contract:
+	 *  > 0 : unwinding succeeded (stops fallback). If we found frames but hit an error
+	 *        (e.g. truncated stack), report success to preserve existing frames.
+	 *    0 : unwinding failed without yielding frames. Ignore non-fatal errors
+	 *        (e.g. missing debug info, DWARF corruption) to allow fallback unwinder or
+	 *        kernel callchain resolution to proceed.
+	 *  < 0 : fatal error (e.g. -ENOMEM). Aborts unwinding entirely.
+	 */
+	if (err)
+		return (err == -ENOMEM) ? -ENOMEM : (entries > 0 ? 1 : 0);
+	return entries;
 }
diff --git a/tools/perf/util/unwind-libunwind-local.c b/tools/perf/util/unwind-libunwind-local.c
index 87d496e9dfa666..27e2f7b3178954 100644
--- a/tools/perf/util/unwind-libunwind-local.c
+++ b/tools/perf/util/unwind-libunwind-local.c
@@ -744,7 +744,7 @@ static int get_entries(struct unwind_info *ui, unwind_entry_cb_t cb,
 	ret = perf_reg_value(&val, perf_sample__user_regs(ui->sample),
 			     perf_arch_reg_ip(e_machine));
 	if (ret)
-		return ret;
+		return 0;
 
 	ips[i++] = (unw_word_t) val;
 
@@ -757,7 +757,7 @@ static int get_entries(struct unwind_info *ui, unwind_entry_cb_t cb,
 		addr_space = maps__addr_space(thread__maps(ui->thread));
 
 		if (addr_space == NULL)
-			return -1;
+			return 0;
 
 		ret = unw_init_remote(&c, addr_space, ui);
 		if (ret && !ui->best_effort)
@@ -785,15 +785,30 @@ static int get_entries(struct unwind_info *ui, unwind_entry_cb_t cb,
 	/*
 	 * Display what we got based on the order setup.
 	 */
+	int entries = 0;
 	for (i = 0; i < max_stack && !ret; i++) {
 		int j = i;
 
 		if (callchain_param.order == ORDER_CALLER)
 			j = max_stack - i - 1;
-		ret = ips[j] ? entry(ips[j], ui->thread, cb, arg) : 0;
+		if (ips[j]) {
+			ret = entry(ips[j], ui->thread, cb, arg);
+			if (ret)
+				break;
+			entries++;
+		}
 	}
 
-	return ret;
+	/*
+	 * Unwinder return contract:
+	 *  > 0 : unwinding succeeded (stops fallback).
+	 *    0 : unwinding failed without yielding frames. Ignore non-fatal errors
+	 *        (e.g. stepping failure) to allow fallback unwinder or kernel callchains.
+	 *  < 0 : fatal error (e.g. -ENOMEM). Aborts unwinding entirely.
+	 */
+	if (ret == -ENOMEM)
+		return -ENOMEM;
+	return (entries > 0 || ret == 0) ? entries : 0;
 }
 
 static int _unwind__get_entries(unwind_entry_cb_t cb, void *arg,
@@ -809,10 +824,10 @@ static int _unwind__get_entries(unwind_entry_cb_t cb, void *arg,
 	};
 
 	if (!data->user_regs || !data->user_regs->regs)
-		return -EINVAL;
+		return 0;
 
 	if (max_stack <= 0)
-		return -EINVAL;
+		return 0;
 
 	return get_entries(&ui, cb, arg, max_stack);
 }
diff --git a/tools/perf/util/unwind-libunwind.c b/tools/perf/util/unwind-libunwind.c
index cb8be6acfb6f54..a0016b897dae26 100644
--- a/tools/perf/util/unwind-libunwind.c
+++ b/tools/perf/util/unwind-libunwind.c
@@ -79,7 +79,7 @@ void unwind__finish_access(struct maps *maps)
 		ops->finish_access(maps);
 }
 
-int unwind__get_entries(unwind_entry_cb_t cb, void *arg,
+int libunwind__get_entries(unwind_entry_cb_t cb, void *arg,
 			 struct thread *thread,
 			 struct perf_sample *data, int max_stack,
 			 bool best_effort)
diff --git a/tools/perf/util/unwind.c b/tools/perf/util/unwind.c
new file mode 100644
index 00000000000000..4ed4b1d55c69f8
--- /dev/null
+++ b/tools/perf/util/unwind.c
@@ -0,0 +1,104 @@
+// SPDX-License-Identifier: GPL-2.0
+#include "debug.h"
+#include "symbol_conf.h"
+#include "unwind.h"
+#include <linux/string.h>
+#include <string.h>
+#include <stdlib.h>
+
+int unwind__get_entries(unwind_entry_cb_t cb __maybe_unused, void *arg __maybe_unused,
+			struct thread *thread __maybe_unused,
+			struct perf_sample *data __maybe_unused,
+			int max_stack __maybe_unused,
+			bool best_effort __maybe_unused)
+{
+	int ret = 0;
+
+#if defined(HAVE_LIBDW_SUPPORT) || defined(HAVE_LIBUNWIND_SUPPORT)
+	if (symbol_conf.unwind_style[0] == UNWIND_STYLE_UNKNOWN) {
+		int i = 0;
+#ifdef HAVE_LIBDW_SUPPORT
+		symbol_conf.unwind_style[i++] = UNWIND_STYLE_LIBDW;
+#endif
+#ifdef HAVE_LIBUNWIND_SUPPORT
+		symbol_conf.unwind_style[i++] = UNWIND_STYLE_LIBUNWIND;
+#endif
+	}
+#endif //defined(HAVE_LIBDW_SUPPORT) || defined(HAVE_LIBUNWIND_SUPPORT)
+
+	for (size_t i = 0; i < ARRAY_SIZE(symbol_conf.unwind_style); i++) {
+		switch (symbol_conf.unwind_style[i]) {
+		case UNWIND_STYLE_LIBDW:
+			ret = libdw__get_entries(cb, arg, thread, data, max_stack, best_effort);
+			break;
+		case UNWIND_STYLE_LIBUNWIND:
+			ret = libunwind__get_entries(cb, arg, thread, data, max_stack, best_effort);
+			break;
+		case UNWIND_STYLE_UNKNOWN:
+		default:
+#if !defined(HAVE_LIBDW_SUPPORT) && !defined(HAVE_LIBUNWIND_SUPPORT)
+			pr_warning_once(
+				"Error: dwarf unwinding not supported, build perf with libdw or libunwind.\n");
+#endif
+			ret = 0;
+			break;
+		}
+		if (ret > 0) {
+			ret = 0;
+			break;
+		}
+		if (ret < 0)
+			break;
+	}
+	return ret;
+}
+
+int unwind__configure(const char *var, const char *value, void *cb __maybe_unused)
+{
+	static const char * const unwind_style_names[] = {
+		[UNWIND_STYLE_LIBDW] = "libdw",
+		[UNWIND_STYLE_LIBUNWIND] = "libunwind",
+		NULL
+	};
+	char *s, *p, *saveptr;
+	size_t i = 0;
+
+	if (strcmp(var, "unwind.style"))
+		return 0;
+
+	if (!value)
+		return -1;
+
+	s = strdup(value);
+	if (!s)
+		return -1;
+
+	memset(symbol_conf.unwind_style, 0, sizeof(symbol_conf.unwind_style));
+
+	p = strtok_r(s, ",", &saveptr);
+	while (p && i < ARRAY_SIZE(symbol_conf.unwind_style)) {
+		bool found = false;
+		char *q = strim(p);
+
+		for (size_t j = UNWIND_STYLE_LIBDW; j < MAX_UNWIND_STYLE; j++) {
+			if (!strcasecmp(q, unwind_style_names[j])) {
+				symbol_conf.unwind_style[i++] = j;
+				found = true;
+				break;
+			}
+		}
+		if (!found)
+			pr_warning("Unknown unwind style: %s\n", q);
+		p = strtok_r(NULL, ",", &saveptr);
+	}
+
+	free(s);
+	return 0;
+}
+
+int unwind__option(const struct option *opt __maybe_unused,
+		   const char *arg,
+		   int unset __maybe_unused)
+{
+	return unwind__configure("unwind.style", arg, NULL);
+}
diff --git a/tools/perf/util/unwind.h b/tools/perf/util/unwind.h
index 9f7164c6d9aa9e..69ba08afda792d 100644
--- a/tools/perf/util/unwind.h
+++ b/tools/perf/util/unwind.h
@@ -4,9 +4,10 @@
 
 #include <linux/compiler.h>
 #include <linux/types.h>
-#include "util/map_symbol.h"
+#include "map_symbol.h"
 
 struct maps;
+struct option;
 struct perf_sample;
 struct thread;
 
@@ -26,7 +27,9 @@ struct unwind_libunwind_ops {
 			   struct perf_sample *data, int max_stack, bool best_effort);
 };
 
-#ifdef HAVE_DWARF_UNWIND_SUPPORT
+int unwind__configure(const char *var, const char *value, void *cb);
+int unwind__option(const struct option *opt, const char *arg, int unset);
+
 /*
  * When best_effort is set, don't report errors and fail silently. This could
  * be expanded in the future to be more permissive about things other than
@@ -36,8 +39,31 @@ int unwind__get_entries(unwind_entry_cb_t cb, void *arg,
 			struct thread *thread,
 			struct perf_sample *data, int max_stack,
 			bool best_effort);
-/* libunwind specific */
+
+#ifdef HAVE_LIBDW_SUPPORT
+int libdw__get_entries(unwind_entry_cb_t cb, void *arg,
+		       struct thread *thread,
+		       struct perf_sample *data, int max_stack,
+		       bool best_effort);
+#else
+#include "debug.h"
+static inline int libdw__get_entries(unwind_entry_cb_t cb __maybe_unused, void *arg __maybe_unused,
+				     struct thread *thread __maybe_unused,
+				     struct perf_sample *data __maybe_unused,
+				     int max_stack __maybe_unused,
+				     bool best_effort __maybe_unused)
+{
+	pr_warning_once("Error: libdw dwarf unwinding not built into perf\n");
+	return 0;
+}
+#endif
+
 #ifdef HAVE_LIBUNWIND_SUPPORT
+/* libunwind specific */
+int libunwind__get_entries(unwind_entry_cb_t cb, void *arg,
+			   struct thread *thread,
+			   struct perf_sample *data, int max_stack,
+			   bool best_effort);
 #ifndef LIBUNWIND__ARCH_REG_ID
 #define LIBUNWIND__ARCH_REG_ID(regnum) libunwind__arch_reg_id(regnum)
 #endif
@@ -47,25 +73,15 @@ int unwind__prepare_access(struct maps *maps, struct map *map, bool *initialized
 void unwind__flush_access(struct maps *maps);
 void unwind__finish_access(struct maps *maps);
 #else
-static inline int unwind__prepare_access(struct maps *maps __maybe_unused,
-					 struct map *map __maybe_unused,
-					 bool *initialized __maybe_unused)
-{
-	return 0;
-}
-
-static inline void unwind__flush_access(struct maps *maps __maybe_unused) {}
-static inline void unwind__finish_access(struct maps *maps __maybe_unused) {}
-#endif
-#else
-static inline int
-unwind__get_entries(unwind_entry_cb_t cb __maybe_unused,
-		    void *arg __maybe_unused,
-		    struct thread *thread __maybe_unused,
-		    struct perf_sample *data __maybe_unused,
-		    int max_stack __maybe_unused,
-		    bool best_effort __maybe_unused)
+#include "debug.h"
+static inline int libunwind__get_entries(unwind_entry_cb_t cb __maybe_unused,
+					 void *arg __maybe_unused,
+					 struct thread *thread __maybe_unused,
+					 struct perf_sample *data __maybe_unused,
+					 int max_stack __maybe_unused,
+					 bool best_effort __maybe_unused)
 {
+	pr_warning_once("Error: libunwind dwarf unwinding not built into perf\n");
 	return 0;
 }
 
@@ -78,5 +94,6 @@ static inline int unwind__prepare_access(struct maps *maps __maybe_unused,
 
 static inline void unwind__flush_access(struct maps *maps __maybe_unused) {}
 static inline void unwind__finish_access(struct maps *maps __maybe_unused) {}
-#endif /* HAVE_DWARF_UNWIND_SUPPORT */
+#endif
+
 #endif /* __UNWIND_H */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0870/2077] perf pmu: Skip test on Arm64 when #slots is zero
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (868 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0869/2077] perf unwind: Refactor get_entries to allow dynamic libdw/libunwind selection Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0871/2077] clk: at91: sam9x7: Fix gmac_gclk clock definition Greg Kroah-Hartman
                   ` (127 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, James Clark, Leo Yan,
	Adrian Hunter, Alexander Shishkin, Jiri Olsa, Mark Rutland,
	Namhyung Kim, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leo Yan <leo.yan@arm.com>

[ Upstream commit 2e2ba7d1ea554ee6e9e751a53eebf3e9270b0670 ]

Some Arm64 PMUs expose 'caps/slots' as 0 when the slot count is not
implemented, tool_pmu__read_event() currently returns false for this,
so metrics that reference #slots are reported as syntax error.

Since the commit 3a61fd866ef9 ("perf expr: Return -EINVAL for syntax
error in expr__find_ids()"), these syntax errors are populated as
failures and make the PMU metric test fail:

    9.3: Parsing of PMU event table metrics:
    --- start ---
    ...

    Found metric 'backend_bound'
    metric expr 100 * (stall_slot_backend / (#slots * cpu_cycles)) for backend_bound
    parsing metric: 100 * (stall_slot_backend / (#slots * cpu_cycles))
    Failure to read '#slots'
    literal: #slots = nan
    syntax error
    Fail to parse metric or group `backend_bound'

    ...
    ---- end(-1) ----
    9.3: Parsing of PMU event table metrics    : FAILED!

This commit introduces a new function is_expected_broken_metric() to
identify broken metrics, and treats metrics containing "#slots" as
expected broken when #slots == 0 on Arm64 platforms.

Fixes: 3a61fd866ef9aaa1 ("perf expr: Return -EINVAL for syntax error in expr__find_ids()")
Reviewed-by: Ian Rogers <irogers@google.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Signed-off-by: Leo Yan <leo.yan@arm.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Mark Rutland <mark.rutland@arm.com>
Cc: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/tests/pmu-events.c | 24 ++++++++++++++++++++++--
 1 file changed, 22 insertions(+), 2 deletions(-)

diff --git a/tools/perf/tests/pmu-events.c b/tools/perf/tests/pmu-events.c
index a9971686216880..b1609a7e1d8c94 100644
--- a/tools/perf/tests/pmu-events.c
+++ b/tools/perf/tests/pmu-events.c
@@ -15,6 +15,7 @@
 #include "util/expr.h"
 #include "util/hashmap.h"
 #include "util/parse-events.h"
+#include "util/tool_pmu.h"
 #include "metricgroup.h"
 #include "stat.h"
 
@@ -817,6 +818,26 @@ struct metric {
 	struct metric_ref metric_ref;
 };
 
+static bool is_expected_broken_metric(const struct pmu_metric *pm)
+{
+	if (!strcmp(pm->metric_name, "M1") || !strcmp(pm->metric_name, "M2") ||
+	    !strcmp(pm->metric_name, "M3"))
+		return true;
+
+#if defined(__aarch64__)
+	/*
+	 * Arm64 platforms may return "#slots == 0", which is treated as a
+	 * syntax error by the parser. Don't test these metrics when running
+	 * on such platforms.
+	 */
+	if (strstr(pm->metric_expr, "#slots") &&
+	    !tool_pmu__cpu_slots_per_cycle())
+		return true;
+#endif
+
+	return false;
+}
+
 static int test__parsing_callback(const struct pmu_metric *pm,
 				  const struct pmu_metrics_table *table,
 				  void *data)
@@ -852,8 +873,7 @@ static int test__parsing_callback(const struct pmu_metric *pm,
 
 	err = metricgroup__parse_groups_test(evlist, table, pm->metric_name);
 	if (err) {
-		if (!strcmp(pm->metric_name, "M1") || !strcmp(pm->metric_name, "M2") ||
-		    !strcmp(pm->metric_name, "M3")) {
+		if (is_expected_broken_metric(pm)) {
 			(*failures)--;
 			pr_debug("Expected broken metric %s skipping\n", pm->metric_name);
 			err = 0;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0871/2077] clk: at91: sam9x7: Fix gmac_gclk clock definition
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (869 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0870/2077] perf pmu: Skip test on Arm64 when #slots is zero Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0872/2077] iio: light: acpi-als: Check ACPI_COMPANION() against NULL Greg Kroah-Hartman
                   ` (126 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Mihai Sain, Claudiu Beznea,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mihai Sain <mihai.sain@microchip.com>

[ Upstream commit b6f6ebb0fb57ae6da622fb8fd4ebdc9ba1ae5756 ]

According to the datasheet (see link section), table 12.1, instance ID 24
is used for the GMAC generic clock, while instance ID 67 is reserved. Add
the correct gmac_gclk entry at ID 24, aligned with the SoC clock layout,
and remove the old misplaced entry at ID 67.

Link: https://ww1.microchip.com/downloads/aemDocuments/documents/MPU32/ProductDocuments/DataSheets/SAM9X75-SIP-Series-Data-Sheet-DS60001827.pdf
Fixes: 33013b43e271 ("clk: at91: sam9x7: add sam9x7 pmc driver")
Signed-off-by: Mihai Sain <mihai.sain@microchip.com>
Link: https://lore.kernel.org/r/20260309075329.1528-4-mihai.sain@microchip.com
[claudiu.beznea: massaged the patch description]
Signed-off-by: Claudiu Beznea <claudiu.beznea@tuxon.dev>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clk/at91/sam9x7.c | 18 +++++++++---------
 1 file changed, 9 insertions(+), 9 deletions(-)

diff --git a/drivers/clk/at91/sam9x7.c b/drivers/clk/at91/sam9x7.c
index 89868a0aeaba93..6b330c3e6bca84 100644
--- a/drivers/clk/at91/sam9x7.c
+++ b/drivers/clk/at91/sam9x7.c
@@ -569,6 +569,15 @@ static const struct {
 		.pp_chg_id = INT_MIN,
 	},
 
+	{
+		.n = "gmac_gclk",
+		.id = 24,
+		.pp = { "audiopll_divpmcck", "plla_div2pmcck", },
+		.pp_mux_table = { 6, 8, },
+		.pp_count = 2,
+		.pp_chg_id = INT_MIN,
+	},
+
 	{
 		.n = "lcd_gclk",
 		.id = 25,
@@ -702,15 +711,6 @@ static const struct {
 		.pp_count = 1,
 		.pp_chg_id = INT_MIN,
 	},
-
-	{
-		.n = "gmac_gclk",
-		.id = 67,
-		.pp = { "audiopll_divpmcck", "plla_div2pmcck", },
-		.pp_mux_table = { 6, 8, },
-		.pp_count = 2,
-		.pp_chg_id = INT_MIN,
-	},
 };
 
 static void __init sam9x7_pmc_setup(struct device_node *np)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0872/2077] iio: light: acpi-als: Check ACPI_COMPANION() against NULL
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (870 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0871/2077] clk: at91: sam9x7: Fix gmac_gclk clock definition Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0873/2077] soundwire: intel_ace2x: release bpt_stream when close it Greg Kroah-Hartman
                   ` (125 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Andy Shevchenko,
	Jonathan Cameron, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit ff29241030eb6f4505d903d87c29f51c1866a95d ]

Every platform driver can be forced to match a device that doesn't match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device's ACPI companion
object need to verify its presence.

Accordingly, add a requisite ACPI_COMPANION() check against NULL to the
acpi-als IIO driver.

Fixes: d4243cb08a27 ("iio: light: acpi-als: Convert ACPI driver to a platform one")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iio/light/acpi-als.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/iio/light/acpi-als.c b/drivers/iio/light/acpi-als.c
index ab229318dce94c..1983a7f17aa930 100644
--- a/drivers/iio/light/acpi-als.c
+++ b/drivers/iio/light/acpi-als.c
@@ -179,11 +179,15 @@ static irqreturn_t acpi_als_trigger_handler(int irq, void *p)
 static int acpi_als_probe(struct platform_device *pdev)
 {
 	struct device *dev = &pdev->dev;
-	struct acpi_device *device = ACPI_COMPANION(dev);
+	struct acpi_device *device;
 	struct iio_dev *indio_dev;
 	struct acpi_als *als;
 	int ret;
 
+	device = ACPI_COMPANION(dev);
+	if (!device)
+		return -ENODEV;
+
 	indio_dev = devm_iio_device_alloc(dev, sizeof(*als));
 	if (!indio_dev)
 		return -ENOMEM;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0873/2077] soundwire: intel_ace2x: release bpt_stream when close it
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (871 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0872/2077] iio: light: acpi-als: Check ACPI_COMPANION() against NULL Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0874/2077] coresight: Fix source not disabled on idr_alloc_u32 failure Greg Kroah-Hartman
                   ` (124 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bard Liao, Simon Trimmer,
	Pierre-Louis Bossart, Vinod Koul, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bard Liao <yung-chuan.liao@linux.intel.com>

[ Upstream commit 8a7fe10eec64bfb7cf4091bca540de4c55d56bfa ]

The BPT stream was allocated in intel_ace2x_bpt_open_stream(), we need
to free it in intel_ace2x_bpt_close_stream().

Fixes: 4c1ce9f37d8a8 ("soundwire: intel_ace2x: add BPT send_async/wait callbacks")
Signed-off-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Reviewed-by: Simon Trimmer <simont@opensource.cirrus.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260514141625.1834216-1-yung-chuan.liao@linux.intel.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/soundwire/intel_ace2x.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/soundwire/intel_ace2x.c b/drivers/soundwire/intel_ace2x.c
index 20422534baf19f..6cd3a873237501 100644
--- a/drivers/soundwire/intel_ace2x.c
+++ b/drivers/soundwire/intel_ace2x.c
@@ -317,6 +317,7 @@ static void intel_ace2x_bpt_close_stream(struct sdw_intel *sdw, struct sdw_slave
 		dev_err(cdns->dev, "%s: remove slave failed: %d\n",
 			__func__, ret);
 
+	sdw_release_stream(cdns->bus.bpt_stream);
 	cdns->bus.bpt_stream = NULL;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0874/2077] coresight: Fix source not disabled on idr_alloc_u32 failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (872 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0873/2077] soundwire: intel_ace2x: release bpt_stream when close it Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0875/2077] coresight: Handle helper enable failure properly Greg Kroah-Hartman
                   ` (123 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jie Gan, Yeoreum Yun,
	Suzuki K Poulose, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jie Gan <jie.gan@oss.qualcomm.com>

[ Upstream commit ea2c2b9e2a66e2b4aa0455b2d70058e2f0ea4d23 ]

In coresight_enable_sysfs(), for non-CPU sources (SOFTWARE, TPDM,
OTHERS), the source device is enabled via coresight_enable_source_sysfs()
before idr_alloc_u32() maps the path. If idr_alloc_u32() fails, the
original code jumped directly to err_source, which only calls
coresight_disable_path() and coresight_release_path(). The source device
was left enabled with an incremented refcnt but no path tracked for it,
leaving the device in an inconsistent state.

Disable the source before jumping to err_source so the enable and path
operations are fully unwound.

Fixes: 5c0016d7b343 ("coresight: core: Use IDR for non-cpu bound sources' paths.")
Signed-off-by: Jie Gan <jie.gan@oss.qualcomm.com>
Reviewed-by: Yeoreum Yun <yeoreum.yun@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20260515-arm_coresight_path_power_management_improvement-v14-1-f88c4a3ecfe9@arm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwtracing/coresight/coresight-sysfs.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/hwtracing/coresight/coresight-sysfs.c b/drivers/hwtracing/coresight/coresight-sysfs.c
index b6a870399e8341..da6f22b512c92a 100644
--- a/drivers/hwtracing/coresight/coresight-sysfs.c
+++ b/drivers/hwtracing/coresight/coresight-sysfs.c
@@ -244,8 +244,10 @@ int coresight_enable_sysfs(struct coresight_device *csdev)
 		 */
 		hash = hashlen_hash(hashlen_string(NULL, dev_name(&csdev->dev)));
 		ret = idr_alloc_u32(&path_idr, path, &hash, hash, GFP_KERNEL);
-		if (ret)
+		if (ret) {
+			coresight_disable_source_sysfs(csdev, NULL);
 			goto err_source;
+		}
 		break;
 	default:
 		/* We can't be here */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0875/2077] coresight: Handle helper enable failure properly
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (873 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0874/2077] coresight: Fix source not disabled on idr_alloc_u32 failure Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0876/2077] PCI: mediatek-gen3: Do full device power down on removal Greg Kroah-Hartman
                   ` (122 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yeoreum Yun, James Clark, Jie Gan,
	Leo Yan, Suzuki K Poulose, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Leo Yan <leo.yan@arm.com>

[ Upstream commit 864754d0a084141085f154db044401fb2dce6a34 ]

If a helper fails to be enabled, unwind any helpers that were already
enabled earlier in the loop. This avoids leaving partially enabled
helpers behind.

Fixes: 6148652807ba ("coresight: Enable and disable helper devices adjacent to the path")
Reviewed-by: Yeoreum Yun <yeoreum.yun@arm.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Tested-by: James Clark <james.clark@linaro.org>
Tested-by: Jie Gan <jie.gan@oss.qualcomm.com>
Signed-off-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20260515-arm_coresight_path_power_management_improvement-v14-2-f88c4a3ecfe9@arm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwtracing/coresight/coresight-core.c | 11 ++++++++++-
 1 file changed, 10 insertions(+), 1 deletion(-)

diff --git a/drivers/hwtracing/coresight/coresight-core.c b/drivers/hwtracing/coresight/coresight-core.c
index 2105bb8139407b..256f6a32621b8e 100644
--- a/drivers/hwtracing/coresight/coresight-core.c
+++ b/drivers/hwtracing/coresight/coresight-core.c
@@ -499,10 +499,19 @@ static int coresight_enable_helpers(struct coresight_device *csdev,
 
 		ret = coresight_enable_helper(helper, mode, path);
 		if (ret)
-			return ret;
+			goto err;
 	}
 
 	return 0;
+
+err:
+	while (i--) {
+		helper = csdev->pdata->out_conns[i]->dest_dev;
+		if (helper && coresight_is_helper(helper))
+			coresight_disable_helper(helper, path);
+	}
+
+	return ret;
 }
 
 int coresight_enable_path(struct coresight_path *path, enum cs_mode mode)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0876/2077] PCI: mediatek-gen3: Do full device power down on removal
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (874 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0875/2077] coresight: Handle helper enable failure properly Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0877/2077] mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr() Greg Kroah-Hartman
                   ` (121 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chen-Yu Tsai, Manivannan Sadhasivam,
	Bjorn Helgaas, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chen-Yu Tsai <wenst@chromium.org>

[ Upstream commit d39d55d7411c18ca6aeb63aafa8035f4ad8b317f ]

When power control for downstream devices was introduced in the
mediatek-gen3 PCIe controller driver, only the power to the downstream
devices was cut when the controller driver is removed. This matched
existing behavior, but in hindsight a proper power down sequence should
have been followed.

Call mtk_pcie_devices_power_down() on driver removal so that in addition
to removing power from the downstream devices, PERST# is asserted.

Fixes: 1a152e21940a ("PCI: mediatek-gen3: Integrate new pwrctrl API")
Signed-off-by: Chen-Yu Tsai <wenst@chromium.org>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Link: https://patch.msgid.link/20260505105918.1823170-1-wenst@chromium.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/pcie-mediatek-gen3.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pci/controller/pcie-mediatek-gen3.c b/drivers/pci/controller/pcie-mediatek-gen3.c
index b0accd82858921..e6acca7e79a0ff 100644
--- a/drivers/pci/controller/pcie-mediatek-gen3.c
+++ b/drivers/pci/controller/pcie-mediatek-gen3.c
@@ -1260,7 +1260,7 @@ static void mtk_pcie_remove(struct platform_device *pdev)
 	pci_remove_root_bus(host->bus);
 	pci_unlock_rescan_remove();
 
-	pci_pwrctrl_power_off_devices(pcie->dev);
+	mtk_pcie_devices_power_down(pcie);
 	mtk_pcie_power_down(pcie);
 	pci_pwrctrl_destroy_devices(pcie->dev);
 	mtk_pcie_irq_teardown(pcie);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0877/2077] mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (875 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0876/2077] PCI: mediatek-gen3: Do full device power down on removal Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0878/2077] mailbox: mtk-adsp: fix UAF during device teardown Greg Kroah-Hartman
                   ` (120 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Conor Dooley, Jassi Brar,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Conor Dooley <conor.dooley@microchip.com>

[ Upstream commit e30d8b2730a33e5e8789371e947c3529789a6070 ]

mpfs_mbox_inbox_isr() writes to the sysreg scb syscon, not the control
scb syscon, but checks for the presence of the latter. Ultimately this
makes little difference because if one syscon is present, both will be.

Fixes: a4123ffab9ece ("mailbox: mpfs: support new, syscon based, devicetree configuration")
Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Jassi Brar <jassisinghbrar@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/mailbox/mailbox-mpfs.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/mailbox/mailbox-mpfs.c b/drivers/mailbox/mailbox-mpfs.c
index d5d9effece9797..ef40fe2be30d65 100644
--- a/drivers/mailbox/mailbox-mpfs.c
+++ b/drivers/mailbox/mailbox-mpfs.c
@@ -201,7 +201,7 @@ static irqreturn_t mpfs_mbox_inbox_isr(int irq, void *data)
 	struct mbox_chan *chan = data;
 	struct mpfs_mbox *mbox = (struct mpfs_mbox *)chan->con_priv;
 
-	if (mbox->control_scb)
+	if (mbox->sysreg_scb)
 		regmap_write(mbox->sysreg_scb, MESSAGE_INT_OFFSET, 0);
 	else
 		writel_relaxed(0, mbox->int_reg);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0878/2077] mailbox: mtk-adsp: fix UAF during device teardown
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (876 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0877/2077] mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr() Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0879/2077] mailbox: dont free the channel if the startup callback failed Greg Kroah-Hartman
                   ` (119 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sergey Senozhatsky, Tzung-Bi Shih,
	Jassi Brar, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sergey Senozhatsky <senozhatsky@chromium.org>

[ Upstream commit b57d1a40bc43258372fa1f4d39305e093947a262 ]

When the SOF audio driver fails to initialize (e.g. firmware boot
timeout), its devres unwind frees the snd_sof_dev object that the
mailbox client (mtk-adsp-ipc) reaches via chan->cl->rx_callback.
The mtk-adsp-mailbox shutdown clears the mailbox command registers
but leaves the IRQ line unmasked, so a late interrupt can still
queue a threaded handler after mbox_free_channel() had cleared
chan->cl, and mbox_chan_received_data() would then trigger UAF:

  BUG: KASAN: slab-use-after-free in sof_ipc3_validate_fw_version
   sof_ipc3_validate_fw_version
   sof_ipc3_do_rx_work
   sof_ipc3_rx_msg
   mt8196_dsp_handle_request
   mtk_adsp_ipc_recv
   mbox_chan_received_data
   mtk_adsp_mbox_isr
   irq_thread_fn
  Freed by task ...:
   kfree
   devres_release_all
   really_probe
   ... (sof-audio-of-mt8196 probe failure)

The crash was observed roughly three seconds after the failed probe.

disable_irq() in shutdown and enable_irq() in startup. disable_irq()
also waits for any in-flight interrupts, so by the time
mbox_free_channel() proceeds to clear chan->cl no rx_callback can run.

In addition, request the IRQ with IRQF_NO_AUTOEN so it stays masked
between probe and the first client bind — otherwise an early interrupt
can crash on chan->cl == NULL in mbox_chan_received_data().

Fixes: af2dfa96c52d ("mailbox: mediatek: add support for adsp mailbox controller")
Signed-off-by: Sergey Senozhatsky <senozhatsky@chromium.org>
Reviewed-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Jassi Brar <jassisinghbrar@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/mailbox/mtk-adsp-mailbox.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/drivers/mailbox/mtk-adsp-mailbox.c b/drivers/mailbox/mtk-adsp-mailbox.c
index 91487aa4d7da08..8bcecddee0eb5c 100644
--- a/drivers/mailbox/mtk-adsp-mailbox.c
+++ b/drivers/mailbox/mtk-adsp-mailbox.c
@@ -19,6 +19,7 @@ struct mtk_adsp_mbox_priv {
 	struct mbox_controller mbox;
 	void __iomem *va_mboxreg;
 	const struct mtk_adsp_mbox_cfg *cfg;
+	int irq;
 };
 
 struct mtk_adsp_mbox_cfg {
@@ -67,6 +68,8 @@ static int mtk_adsp_mbox_startup(struct mbox_chan *chan)
 	writel(0xFFFFFFFF, priv->va_mboxreg + priv->cfg->clr_in);
 	writel(0xFFFFFFFF, priv->va_mboxreg + priv->cfg->clr_out);
 
+	enable_irq(priv->irq);
+
 	return 0;
 }
 
@@ -74,6 +77,8 @@ static void mtk_adsp_mbox_shutdown(struct mbox_chan *chan)
 {
 	struct mtk_adsp_mbox_priv *priv = get_mtk_adsp_mbox_priv(chan->mbox);
 
+	disable_irq(priv->irq);
+
 	/* Clear ADSP mbox command */
 	writel(0xFFFFFFFF, priv->va_mboxreg + priv->cfg->clr_in);
 	writel(0xFFFFFFFF, priv->va_mboxreg + priv->cfg->clr_out);
@@ -139,8 +144,10 @@ static int mtk_adsp_mbox_probe(struct platform_device *pdev)
 	if (irq < 0)
 		return irq;
 
+	priv->irq = irq;
 	ret = devm_request_threaded_irq(dev, irq, mtk_adsp_mbox_irq,
-					mtk_adsp_mbox_isr, IRQF_TRIGGER_NONE,
+					mtk_adsp_mbox_isr,
+					IRQF_TRIGGER_NONE | IRQF_NO_AUTOEN,
 					dev_name(dev), mbox->chans);
 	if (ret < 0)
 		return ret;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0879/2077] mailbox: dont free the channel if the startup callback failed
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (877 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0878/2077] mailbox: mtk-adsp: fix UAF during device teardown Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0880/2077] PCI/pwrctrl: Lock device when calling device_is_bound() Greg Kroah-Hartman
                   ` (118 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Wolfram Sang, Jassi Brar,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wolfram Sang <wsa+renesas@sang-engineering.com>

[ Upstream commit 4f176444dcc977d1888fd9220c357a4d32338ee0 ]

If the optional startup() callbacks fails, we need to clear some states.
Currently, this is done by freeing the channel. This does, however, more
than needed which creates problems. Namely, it is calling the shutdown()
callback. This is totally not intuitive. No user expects that shutdown()
is called when startup() fails, similar to remove() not being called
when probe() fails. Currently, quite some mailbox users register the IRQ
in startup() and free them in shutdown(). These drivers will get a WARN
about freeing an already free IRQ. Other subtle issues could arise from
this unexpected behaviour.

To solve this problem, introduce a helper which does the minimal cleanup
and use it in both, in free_channel() and after startup() failed.

Link: https://sashiko.dev/#/patchset/20260402112709.13002-1-wsa%2Brenesas%40sang-engineering.com # second issue
Fixes: 2b6d83e2b8b7 ("mailbox: Introduce framework for mailbox")
Signed-off-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Signed-off-by: Jassi Brar <jassisinghbrar@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/mailbox/mailbox.c | 26 +++++++++++++++-----------
 1 file changed, 15 insertions(+), 11 deletions(-)

diff --git a/drivers/mailbox/mailbox.c b/drivers/mailbox/mailbox.c
index bbc9fd75a95f7c..006ea5a5c32074 100644
--- a/drivers/mailbox/mailbox.c
+++ b/drivers/mailbox/mailbox.c
@@ -327,6 +327,19 @@ int mbox_flush(struct mbox_chan *chan, unsigned long timeout)
 }
 EXPORT_SYMBOL_GPL(mbox_flush);
 
+static void mbox_clean_and_put_channel(struct mbox_chan *chan)
+{
+	/* The queued TX requests are simply aborted, no callbacks are made */
+	scoped_guard(spinlock_irqsave, &chan->lock) {
+		chan->cl = NULL;
+		chan->active_req = MBOX_NO_MSG;
+		if (chan->txdone_method == MBOX_TXDONE_BY_ACK)
+			chan->txdone_method = MBOX_TXDONE_BY_POLL;
+	}
+
+	module_put(chan->mbox->dev->driver->owner);
+}
+
 static int __mbox_bind_client(struct mbox_chan *chan, struct mbox_client *cl)
 {
 	struct device *dev = cl->dev;
@@ -350,10 +363,9 @@ static int __mbox_bind_client(struct mbox_chan *chan, struct mbox_client *cl)
 
 	if (chan->mbox->ops->startup) {
 		ret = chan->mbox->ops->startup(chan);
-
 		if (ret) {
 			dev_err(dev, "Unable to startup the chan (%d)\n", ret);
-			mbox_free_channel(chan);
+			mbox_clean_and_put_channel(chan);
 			return ret;
 		}
 	}
@@ -495,15 +507,7 @@ void mbox_free_channel(struct mbox_chan *chan)
 	if (chan->mbox->ops->shutdown)
 		chan->mbox->ops->shutdown(chan);
 
-	/* The queued TX requests are simply aborted, no callbacks are made */
-	scoped_guard(spinlock_irqsave, &chan->lock) {
-		chan->cl = NULL;
-		chan->active_req = MBOX_NO_MSG;
-		if (chan->txdone_method == MBOX_TXDONE_BY_ACK)
-			chan->txdone_method = MBOX_TXDONE_BY_POLL;
-	}
-
-	module_put(chan->mbox->dev->driver->owner);
+	mbox_clean_and_put_channel(chan);
 }
 EXPORT_SYMBOL_GPL(mbox_free_channel);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0880/2077] PCI/pwrctrl: Lock device when calling device_is_bound()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (878 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0879/2077] mailbox: dont free the channel if the startup callback failed Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0881/2077] coresight: platform: defer connection counter increment until alloc succeeds Greg Kroah-Hartman
                   ` (117 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bartosz Golaszewski, Bjorn Helgaas,
	Manivannan Sadhasivam, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>

[ Upstream commit 548f3d287d92bcbc908b02db57fb889f8a8276a0 ]

The kerneldoc for device_is_bound() states that it must be called with
the device lock taken. Synchronize the two calls in pwrctrl core.

Fixes: b35cf3b6aa1e ("PCI/pwrctrl: Add APIs to power on/off pwrctrl devices")
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Manivannan Sadhasivam <mani@kernel.org>
Link: https://patch.msgid.link/20260518100700.47581-1-bartosz.golaszewski@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/pwrctrl/core.c | 26 +++++++++++++++-----------
 1 file changed, 15 insertions(+), 11 deletions(-)

diff --git a/drivers/pci/pwrctrl/core.c b/drivers/pci/pwrctrl/core.c
index 97cff5b8ca8852..cd08d590483b86 100644
--- a/drivers/pci/pwrctrl/core.c
+++ b/drivers/pci/pwrctrl/core.c
@@ -161,10 +161,12 @@ static void pci_pwrctrl_power_off_device(struct device_node *np)
 	if (!pdev)
 		return;
 
-	if (device_is_bound(&pdev->dev)) {
-		ret = __pci_pwrctrl_power_off_device(&pdev->dev);
-		if (ret)
-			dev_err(&pdev->dev, "Failed to power off device: %d", ret);
+	scoped_guard(device, &pdev->dev) {
+		if (device_is_bound(&pdev->dev)) {
+			ret = __pci_pwrctrl_power_off_device(&pdev->dev);
+			if (ret)
+				dev_err(&pdev->dev, "Failed to power off device: %d", ret);
+		}
 	}
 
 	platform_device_put(pdev);
@@ -205,7 +207,7 @@ static int __pci_pwrctrl_power_on_device(struct device *dev)
 static int pci_pwrctrl_power_on_device(struct device_node *np)
 {
 	struct platform_device *pdev;
-	int ret;
+	int ret = 0;
 
 	for_each_available_child_of_node_scoped(np, child) {
 		ret = pci_pwrctrl_power_on_device(child);
@@ -217,12 +219,14 @@ static int pci_pwrctrl_power_on_device(struct device_node *np)
 	if (!pdev)
 		return 0;
 
-	if (device_is_bound(&pdev->dev)) {
-		ret = __pci_pwrctrl_power_on_device(&pdev->dev);
-	} else {
-		/* FIXME: Use blocking wait instead of probe deferral */
-		dev_dbg(&pdev->dev, "driver is not bound\n");
-		ret = -EPROBE_DEFER;
+	scoped_guard(device, &pdev->dev) {
+		if (device_is_bound(&pdev->dev)) {
+			ret = __pci_pwrctrl_power_on_device(&pdev->dev);
+		} else {
+			/* FIXME: Use blocking wait instead of probe deferral */
+			dev_dbg(&pdev->dev, "driver is not bound\n");
+			ret = -EPROBE_DEFER;
+		}
 	}
 
 	platform_device_put(pdev);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0881/2077] coresight: platform: defer connection counter increment until alloc succeeds
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (879 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0880/2077] PCI/pwrctrl: Lock device when calling device_is_bound() Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0882/2077] PCI: dwc: Fix signedness bug in fault injection test code Greg Kroah-Hartman
                   ` (116 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jie Gan, James Clark,
	Suzuki K Poulose, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jie Gan <jie.gan@oss.qualcomm.com>

[ Upstream commit 1563ae33dc4f5ebac96b93af2ef72e72aaaa31ae ]

coresight_add_out_conn() increments nr_outconns before calling
devm_krealloc_array() and again before devm_kmalloc(). If either
allocation fails, the counter is already bumped while the corresponding
array entry is NULL or uninitialized garbage.

coresight_add_in_conn() has the same problem with nr_inconns and
devm_krealloc_array().

In both cases the probe returns -ENOMEM, which causes
coresight_get_platform_data() to call coresight_release_platform_data()
for cleanup. That function iterates up to nr_outconns (or nr_inconns)
entries and dereferences each pointer unconditionally, hitting the NULL
or garbage entry and panicking instead of failing gracefully.

Fix by moving the counter increments to after all allocations succeed,
so the struct is always consistent on any error path.

Fixes: 3d4ff657e454 ("coresight: Dynamically add connections")
Fixes: e3f4e68797a9 ("coresight: Store in-connections as well as out-connections")
Signed-off-by: Jie Gan <jie.gan@oss.qualcomm.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20260511-fix-ref-count-issue-v1-1-99d647810d3c@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hwtracing/coresight/coresight-platform.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/drivers/hwtracing/coresight/coresight-platform.c b/drivers/hwtracing/coresight/coresight-platform.c
index e337b6e2bf327c..93c2d075cad66f 100644
--- a/drivers/hwtracing/coresight/coresight-platform.c
+++ b/drivers/hwtracing/coresight/coresight-platform.c
@@ -45,9 +45,8 @@ coresight_add_out_conn(struct device *dev,
 		}
 	}
 
-	pdata->nr_outconns++;
 	pdata->out_conns =
-		devm_krealloc_array(dev, pdata->out_conns, pdata->nr_outconns,
+		devm_krealloc_array(dev, pdata->out_conns, pdata->nr_outconns + 1,
 				    sizeof(*pdata->out_conns), GFP_KERNEL);
 	if (!pdata->out_conns)
 		return ERR_PTR(-ENOMEM);
@@ -63,7 +62,8 @@ coresight_add_out_conn(struct device *dev,
 	 * used right away.
 	 */
 	*conn = *new_conn;
-	pdata->out_conns[pdata->nr_outconns - 1] = conn;
+	pdata->out_conns[pdata->nr_outconns] = conn;
+	pdata->nr_outconns++;
 	return conn;
 }
 EXPORT_SYMBOL_GPL(coresight_add_out_conn);
@@ -86,13 +86,13 @@ int coresight_add_in_conn(struct coresight_connection *out_conn)
 			return 0;
 		}
 
-	pdata->nr_inconns++;
 	pdata->in_conns =
-		devm_krealloc_array(dev, pdata->in_conns, pdata->nr_inconns,
+		devm_krealloc_array(dev, pdata->in_conns, pdata->nr_inconns + 1,
 				    sizeof(*pdata->in_conns), GFP_KERNEL);
 	if (!pdata->in_conns)
 		return -ENOMEM;
-	pdata->in_conns[pdata->nr_inconns - 1] = out_conn;
+	pdata->in_conns[pdata->nr_inconns] = out_conn;
+	pdata->nr_inconns++;
 	return 0;
 }
 EXPORT_SYMBOL_GPL(coresight_add_in_conn);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0882/2077] PCI: dwc: Fix signedness bug in fault injection test code
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (880 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0881/2077] coresight: platform: defer connection counter increment until alloc succeeds Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0883/2077] PCI: mediatek-gen3: Fix incorrectly skipped pwrctrl error message Greg Kroah-Hartman
                   ` (115 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Manivannan Sadhasivam,
	Hans Zhang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dan Carpenter <error27@gmail.com>

[ Upstream commit 94ac934d2c054fba4a22d8dc84749094c5fa0ec0 ]

The kstrtou32() function returns negative error code or zero on success.
However, in this case "val" is a u32 and the function returns signed long,
so negative error codes from kstrtou32() are returned as high positive
values.

Store the error code in an int instead.

Fixes: d20ee8e2dbd6 ("PCI: dwc: Add debugfs based Error Injection support for DWC")
Signed-off-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Reviewed-by: Hans Zhang <18255117159@163.com>
Link: https://patch.msgid.link/agL-Uwfn26SI4Gb0@stanley.mountain
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/dwc/pcie-designware-debugfs.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/drivers/pci/controller/dwc/pcie-designware-debugfs.c b/drivers/pci/controller/dwc/pcie-designware-debugfs.c
index d0884253be97e4..4bfc1748f2d737 100644
--- a/drivers/pci/controller/dwc/pcie-designware-debugfs.c
+++ b/drivers/pci/controller/dwc/pcie-designware-debugfs.c
@@ -306,6 +306,7 @@ static ssize_t err_inj_write(struct file *file, const char __user *buf,
 	u32 val, counter, vc_num, err_group, type_mask;
 	int val_diff = 0;
 	char *kern_buf;
+	int ret;
 
 	err_group = err_inj_list[pdata->idx].err_inj_group;
 	type_mask = err_inj_type_mask[err_group];
@@ -327,10 +328,10 @@ static ssize_t err_inj_write(struct file *file, const char __user *buf,
 			return -EINVAL;
 		}
 	} else {
-		val = kstrtou32(kern_buf, 0, &counter);
-		if (val) {
+		ret = kstrtou32(kern_buf, 0, &counter);
+		if (ret) {
 			kfree(kern_buf);
-			return val;
+			return ret;
 		}
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0883/2077] PCI: mediatek-gen3: Fix incorrectly skipped pwrctrl error message
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (881 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0882/2077] PCI: dwc: Fix signedness bug in fault injection test code Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0884/2077] platform/x86: classmate-laptop: Address memory leaks on driver removal Greg Kroah-Hartman
                   ` (114 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Chen-Yu Tsai,
	Manivannan Sadhasivam, Hans Zhang, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chen-Yu Tsai <wenst@chromium.org>

[ Upstream commit 8ba433753d9b131c2e43b1ff7ba8c5730cef8231 ]

When pwrctrl integration was added, the error message for
pci_pwrctrl_create_devices() failure was incorrectly added after the goto
statement, causing it to be skipped.

Move the goto statement after the dev_err_probe() call so that the
error message actually gets printed (or saved if probe is deferred).

Fixes: 1a152e21940a ("PCI: mediatek-gen3: Integrate new pwrctrl API")
Reported-by: Dan Carpenter <error27@gmail.com>
Closes: https://lore.kernel.org/all/adjNaKB5KGpl6qIp@stanley.mountain/
Signed-off-by: Chen-Yu Tsai <wenst@chromium.org>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Reviewed-by: Hans Zhang <18255117159@163.com>
Link: https://patch.msgid.link/20260512103347.1751080-1-wenst@chromium.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/pcie-mediatek-gen3.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pci/controller/pcie-mediatek-gen3.c b/drivers/pci/controller/pcie-mediatek-gen3.c
index e6acca7e79a0ff..88e3fdcb74c062 100644
--- a/drivers/pci/controller/pcie-mediatek-gen3.c
+++ b/drivers/pci/controller/pcie-mediatek-gen3.c
@@ -1222,8 +1222,8 @@ static int mtk_pcie_probe(struct platform_device *pdev)
 
 	err = pci_pwrctrl_create_devices(pcie->dev);
 	if (err) {
-		goto err_tear_down_irq;
 		dev_err_probe(dev, err, "failed to create pwrctrl devices\n");
+		goto err_tear_down_irq;
 	}
 
 	err = mtk_pcie_setup(pcie);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0884/2077] platform/x86: classmate-laptop: Address memory leaks on driver removal
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (882 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0883/2077] PCI: mediatek-gen3: Fix incorrectly skipped pwrctrl error message Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0885/2077] clk: microchip: mpfs-ccc: fix peripheral driver registration failures after oob fix Greg Kroah-Hartman
                   ` (113 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki,
	Thadeu Lima de Souza Cascardo, Ilpo Järvinen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit 4baf44b4051940ba1abc68ef5136d25cb1806521 ]

Switch over cmpc_accel_add_v4() and cmpc_accel_add() to using
devm_kzalloc() for allocating the accel object which will cause it
to be freed automatically on device removal, so it won't be leaked
any more.

This also simplifies the rollback paths in these functions somewhat.

Fixes: 529aa8cb0a59 ("classmate-laptop: add support for Classmate PC ACPI devices")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Acked-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Link: https://patch.msgid.link/10846403.nUPlyArG6x@rafael.j.wysocki
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/platform/x86/classmate-laptop.c | 12 ++++--------
 1 file changed, 4 insertions(+), 8 deletions(-)

diff --git a/drivers/platform/x86/classmate-laptop.c b/drivers/platform/x86/classmate-laptop.c
index e6eed3d65580ae..a5fe34211afb99 100644
--- a/drivers/platform/x86/classmate-laptop.c
+++ b/drivers/platform/x86/classmate-laptop.c
@@ -400,7 +400,7 @@ static int cmpc_accel_add_v4(struct acpi_device *acpi)
 	struct input_dev *inputdev;
 	struct cmpc_accel *accel;
 
-	accel = kmalloc_obj(*accel);
+	accel = devm_kzalloc(&acpi->dev, sizeof(*accel), GFP_KERNEL);
 	if (!accel)
 		return -ENOMEM;
 
@@ -411,7 +411,7 @@ static int cmpc_accel_add_v4(struct acpi_device *acpi)
 
 	error = device_create_file(&acpi->dev, &cmpc_accel_sensitivity_attr_v4);
 	if (error)
-		goto failed_sensitivity;
+		return error;
 
 	accel->g_select = CMPC_ACCEL_G_SELECT_DEFAULT;
 	cmpc_accel_set_g_select_v4(acpi->handle, accel->g_select);
@@ -434,8 +434,6 @@ static int cmpc_accel_add_v4(struct acpi_device *acpi)
 	device_remove_file(&acpi->dev, &cmpc_accel_g_select_attr_v4);
 failed_g_select:
 	device_remove_file(&acpi->dev, &cmpc_accel_sensitivity_attr_v4);
-failed_sensitivity:
-	kfree(accel);
 	return error;
 }
 
@@ -650,7 +648,7 @@ static int cmpc_accel_add(struct acpi_device *acpi)
 	struct input_dev *inputdev;
 	struct cmpc_accel *accel;
 
-	accel = kmalloc_obj(*accel);
+	accel = devm_kzalloc(&acpi->dev, sizeof(*accel), GFP_KERNEL);
 	if (!accel)
 		return -ENOMEM;
 
@@ -659,7 +657,7 @@ static int cmpc_accel_add(struct acpi_device *acpi)
 
 	error = device_create_file(&acpi->dev, &cmpc_accel_sensitivity_attr);
 	if (error)
-		goto failed_file;
+		return error;
 
 	error = cmpc_add_acpi_notify_device(acpi, "cmpc_accel",
 					    cmpc_accel_idev_init);
@@ -673,8 +671,6 @@ static int cmpc_accel_add(struct acpi_device *acpi)
 
 failed_input:
 	device_remove_file(&acpi->dev, &cmpc_accel_sensitivity_attr);
-failed_file:
-	kfree(accel);
 	return error;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0885/2077] clk: microchip: mpfs-ccc: fix peripheral driver registration failures after oob fix
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (883 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0884/2077] platform/x86: classmate-laptop: Address memory leaks on driver removal Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0886/2077] perf build-id: Fix off-by-one bug when printing kernel/module build-id Greg Kroah-Hartman
                   ` (112 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Brian Masney, Conor Dooley,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Conor Dooley <conor.dooley@microchip.com>

[ Upstream commit c8a3be5bc2b2f2d53c56a8b9cab731e917b95c07 ]

Commit 2f7ae8ab6aa73 ("clk: microchip: mpfs-ccc: fix out of bounds
access during output registration") fixed the out of bounds access, but
it did so by packing sparse indices into a linear space. When
peripheral drivers request clocks, they obviously don't care for this
compression and use the sparse indices, and therefore try to request the
wrong clocks or clocks that don't exist.

The most straightforward fix here seems to stop being clever with the
packing and just overallocate the array.

Fixes: 2f7ae8ab6aa73 ("clk: microchip: mpfs-ccc: fix out of bounds access during output registration")
Fixes: d39fb172760e ("clk: microchip: add PolarFire SoC fabric clock support")
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clk/microchip/clk-mpfs-ccc.c | 15 ++++-----------
 1 file changed, 4 insertions(+), 11 deletions(-)

diff --git a/drivers/clk/microchip/clk-mpfs-ccc.c b/drivers/clk/microchip/clk-mpfs-ccc.c
index 0a76a1aaa50f7f..40c17593e5941d 100644
--- a/drivers/clk/microchip/clk-mpfs-ccc.c
+++ b/drivers/clk/microchip/clk-mpfs-ccc.c
@@ -32,6 +32,7 @@
 #define MPFS_CCC_FIXED_DIV		4
 #define MPFS_CCC_OUTPUTS_PER_PLL	4
 #define MPFS_CCC_REFS_PER_PLL		2
+#define MPFS_CCC_NUM_CLKS		16
 
 struct mpfs_ccc_data {
 	void __iomem **pll_base;
@@ -178,7 +179,7 @@ static int mpfs_ccc_register_outputs(struct device *dev, struct mpfs_ccc_out_hw_
 			return dev_err_probe(dev, ret, "failed to register clock id: %d\n",
 					     out_hw->id);
 
-		data->hw_data.hws[out_hw->id - 2] = &out_hw->divider.hw;
+		data->hw_data.hws[out_hw->id] = &out_hw->divider.hw;
 	}
 
 	return 0;
@@ -231,17 +232,9 @@ static int mpfs_ccc_probe(struct platform_device *pdev)
 {
 	struct mpfs_ccc_data *clk_data;
 	void __iomem *pll_base[ARRAY_SIZE(mpfs_ccc_pll_clks)];
-	unsigned int num_clks;
 	int ret;
 
-	/*
-	 * If DLLs get added here, mpfs_ccc_register_outputs() currently packs
-	 * sparse clock IDs in the hws array
-	 */
-	num_clks = ARRAY_SIZE(mpfs_ccc_pll_clks) + ARRAY_SIZE(mpfs_ccc_pll0out_clks) +
-		   ARRAY_SIZE(mpfs_ccc_pll1out_clks);
-
-	clk_data = devm_kzalloc(&pdev->dev, struct_size(clk_data, hw_data.hws, num_clks),
+	clk_data = devm_kzalloc(&pdev->dev, struct_size(clk_data, hw_data.hws, MPFS_CCC_NUM_CLKS),
 				GFP_KERNEL);
 	if (!clk_data)
 		return -ENOMEM;
@@ -255,7 +248,7 @@ static int mpfs_ccc_probe(struct platform_device *pdev)
 		return PTR_ERR(pll_base[1]);
 
 	clk_data->pll_base = pll_base;
-	clk_data->hw_data.num = num_clks;
+	clk_data->hw_data.num = MPFS_CCC_NUM_CLKS;
 	clk_data->dev = &pdev->dev;
 
 	ret = mpfs_ccc_register_plls(clk_data->dev, mpfs_ccc_pll_clks,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0886/2077] perf build-id: Fix off-by-one bug when printing kernel/module build-id
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (884 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0885/2077] clk: microchip: mpfs-ccc: fix peripheral driver registration failures after oob fix Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0887/2077] perf event: Fix size of synthesized sample with branch stacks Greg Kroah-Hartman
                   ` (111 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Petlan, Ian Rogers,
	Namhyung Kim, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Petlan <mpetlan@redhat.com>

[ Upstream commit 017bca78e4d72b1ff027d368c20a1b2c654edaf7 ]

When changing sprintf functions to snprintf, one byte got lost. Since
snprintf ones do not handle the '\0' terminating character, the number
of printed characters is 40, while sizeof(sbuild_id) is 41, including
the terminating '\0' character.

This makes the later check fail so that nothing is printed.

Fix that.

Before:

    [Michael@Carbon ~]$ perf buildid-list -k
    [Michael@Carbon ~]$

After:

    [Michael@Carbon ~]$ perf buildid-list -k
    a527806324d543c4bc3ff2f9c9519d494fed5f68
    [Michael@Carbon ~]$

Fixes: fccaaf6fbbc59910 ("perf build-id: Change sprintf functions to snprintf")
Signed-off-by: Michael Petlan <mpetlan@redhat.com>
Tested-by: Ian Rogers <irogers@google.com>
Cc: Ian Rogers <irogers@google.com>
Cc: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-buildid-list.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/tools/perf/builtin-buildid-list.c b/tools/perf/builtin-buildid-list.c
index a91bbb34ac9463..e0881b0ac38ff2 100644
--- a/tools/perf/builtin-buildid-list.c
+++ b/tools/perf/builtin-buildid-list.c
@@ -61,7 +61,7 @@ static int sysfs__fprintf_build_id(FILE *fp)
 	int ret;
 
 	ret = sysfs__snprintf_build_id("/", sbuild_id, sizeof(sbuild_id));
-	if (ret != sizeof(sbuild_id))
+	if (ret + 1 != sizeof(sbuild_id))
 		return ret < 0 ? ret : -EINVAL;
 
 	return fprintf(fp, "%s\n", sbuild_id);
@@ -73,7 +73,7 @@ static int filename__fprintf_build_id(const char *name, FILE *fp)
 	int ret;
 
 	ret = filename__snprintf_build_id(name, sbuild_id, sizeof(sbuild_id));
-	if (ret != sizeof(sbuild_id))
+	if (ret + 1 != sizeof(sbuild_id))
 		return ret < 0 ? ret : -EINVAL;
 
 	return fprintf(fp, "%s\n", sbuild_id);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0887/2077] perf event: Fix size of synthesized sample with branch stacks
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (885 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0886/2077] perf build-id: Fix off-by-one bug when printing kernel/module build-id Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0888/2077] perf inject: Fix itrace branch stack synthesis Greg Kroah-Hartman
                   ` (110 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
	Adrian Hunter, Dapeng Mi, Ingo Molnar, James Clark, Kan Liang,
	Leo Yan, Peter Zijlstra, Ravi Bangoria, Thomas Falcon,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit 059e9100d82aae2254f1b06835a55755936b1417 ]

Synthesizing branch stacks for Intel-PT highlighted an issue where
PERF_SAMPLE_BRANCH_HW_INDEX was assumed to always be set in the
perf_event_attr branch_sample_type. This caused an incorrect size
calculation.

Fix the writing of the nr and hw_idx values during sample event
synthesis by passing the branch_sample_type into the sample size
and synthesis functions. Also update hardware tracers (Intel PT,
ARM SPE, CS-ETM) to retrieve and pass their branch_sample_type
dynamically to prevent payload misalignment.

Fixes: d3f85437ad6a5511 ("perf evsel: Support PERF_SAMPLE_BRANCH_HW_INDEX")
Assisted-by: Gemini:gemini-3.1-pro-preview
Signed-off-by: Ian Rogers <irogers@google.com>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Dapeng Mi <dapeng1.mi@linux.intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Kan Liang <kan.liang@linux.intel.com>
Cc: Leo Yan <leo.yan@linux.dev>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Ravi Bangoria <ravi.bangoria@amd.com>
Cc: Thomas Falcon <thomas.falcon@intel.com>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/bench/inject-buildid.c  |  9 ++++++---
 tools/perf/builtin-inject.c        | 12 +++++++++---
 tools/perf/tests/dlfilter-test.c   |  8 ++++++--
 tools/perf/tests/sample-parsing.c  |  5 +++--
 tools/perf/util/arm-spe.c          | 28 ++++++++++++++++++++++++----
 tools/perf/util/cs-etm.c           | 28 +++++++++++++++++++++++-----
 tools/perf/util/intel-bts.c        |  3 ++-
 tools/perf/util/intel-pt.c         | 27 +++++++++++++++++++++++----
 tools/perf/util/synthetic-events.c | 25 ++++++++++++++++++-------
 tools/perf/util/synthetic-events.h |  6 ++++--
 10 files changed, 118 insertions(+), 33 deletions(-)

diff --git a/tools/perf/bench/inject-buildid.c b/tools/perf/bench/inject-buildid.c
index aad572a78d7fcf..bfd2c5ec9488e0 100644
--- a/tools/perf/bench/inject-buildid.c
+++ b/tools/perf/bench/inject-buildid.c
@@ -228,9 +228,12 @@ static ssize_t synthesize_sample(struct bench_data *data, struct bench_dso *dso,
 
 	event.header.type = PERF_RECORD_SAMPLE;
 	event.header.misc = PERF_RECORD_MISC_USER;
-	event.header.size = perf_event__sample_event_size(&sample, bench_sample_type, 0);
-
-	perf_event__synthesize_sample(&event, bench_sample_type, 0, &sample);
+	event.header.size = perf_event__sample_event_size(&sample, bench_sample_type,
+							   /*read_format=*/0,
+							   /*branch_sample_type=*/0);
+	perf_event__synthesize_sample(&event, bench_sample_type,
+				      /*read_format=*/0,
+				      /*branch_sample_type=*/0, &sample);
 
 	return writen(data->input_pipe[1], &event, event.header.size);
 }
diff --git a/tools/perf/builtin-inject.c b/tools/perf/builtin-inject.c
index a2493f1097df97..2f20e782c7f272 100644
--- a/tools/perf/builtin-inject.c
+++ b/tools/perf/builtin-inject.c
@@ -465,8 +465,13 @@ static int perf_event__convert_sample_callchain(const struct perf_tool *tool,
 	/* remove sample_type {STACK,REGS}_USER for synthesize */
 	sample_type &= ~(PERF_SAMPLE_STACK_USER | PERF_SAMPLE_REGS_USER);
 
-	perf_event__synthesize_sample(event_copy, sample_type,
-				      evsel->core.attr.read_format, sample);
+	ret = perf_event__synthesize_sample(event_copy, sample_type,
+					    evsel->core.attr.read_format,
+					    evsel->core.attr.branch_sample_type, sample);
+	if (ret) {
+		pr_err("Failed to synthesize sample\n");
+		return ret;
+	}
 	return perf_event__repipe_synth(tool, event_copy);
 }
 
@@ -1102,7 +1107,8 @@ static int perf_inject__sched_stat(const struct perf_tool *tool,
 	sample_sw.period = sample->period;
 	sample_sw.time	 = sample->time;
 	perf_event__synthesize_sample(event_sw, evsel->core.attr.sample_type,
-				      evsel->core.attr.read_format, &sample_sw);
+				      evsel->core.attr.read_format,
+				      evsel->core.attr.branch_sample_type, &sample_sw);
 	build_id__mark_dso_hit(tool, event_sw, &sample_sw, evsel, machine);
 	ret = perf_event__repipe(tool, event_sw, &sample_sw, machine);
 	perf_sample__exit(&sample_sw);
diff --git a/tools/perf/tests/dlfilter-test.c b/tools/perf/tests/dlfilter-test.c
index e63790c61d53a0..204663571943cb 100644
--- a/tools/perf/tests/dlfilter-test.c
+++ b/tools/perf/tests/dlfilter-test.c
@@ -188,8 +188,12 @@ static int write_sample(struct test_data *td, u64 sample_type, u64 id, pid_t pid
 
 	event->header.type = PERF_RECORD_SAMPLE;
 	event->header.misc = PERF_RECORD_MISC_USER;
-	event->header.size = perf_event__sample_event_size(&sample, sample_type, 0);
-	err = perf_event__synthesize_sample(event, sample_type, 0, &sample);
+	event->header.size = perf_event__sample_event_size(&sample, sample_type,
+							   /*read_format=*/0,
+							   /*branch_sample_type=*/0);
+	err = perf_event__synthesize_sample(event, sample_type,
+					    /*read_format=*/0,
+					    /*branch_sample_type=*/0, &sample);
 	if (err)
 		return test_result("perf_event__synthesize_sample() failed", TEST_FAIL);
 
diff --git a/tools/perf/tests/sample-parsing.c b/tools/perf/tests/sample-parsing.c
index a7327c942ca209..55f0b73ca20e05 100644
--- a/tools/perf/tests/sample-parsing.c
+++ b/tools/perf/tests/sample-parsing.c
@@ -310,7 +310,8 @@ static int do_test(u64 sample_type, u64 sample_regs, u64 read_format)
 		sample.read.one.lost  = 1;
 	}
 
-	sz = perf_event__sample_event_size(&sample, sample_type, read_format);
+	sz = perf_event__sample_event_size(&sample, sample_type, read_format,
+					   evsel.core.attr.branch_sample_type);
 	bufsz = sz + 4096; /* Add a bit for overrun checking */
 	event = malloc(bufsz);
 	if (!event) {
@@ -324,7 +325,7 @@ static int do_test(u64 sample_type, u64 sample_regs, u64 read_format)
 	event->header.size = sz;
 
 	err = perf_event__synthesize_sample(event, sample_type, read_format,
-					    &sample);
+					    evsel.core.attr.branch_sample_type, &sample);
 	if (err) {
 		pr_debug("%s failed for sample_type %#"PRIx64", error %d\n",
 			 "perf_event__synthesize_sample", sample_type, err);
diff --git a/tools/perf/util/arm-spe.c b/tools/perf/util/arm-spe.c
index e5835042acdf76..3e54ed41653bdc 100644
--- a/tools/perf/util/arm-spe.c
+++ b/tools/perf/util/arm-spe.c
@@ -482,10 +482,30 @@ static void arm_spe__prep_branch_stack(struct arm_spe_queue *speq)
 	bstack->hw_idx = -1ULL;
 }
 
-static int arm_spe__inject_event(union perf_event *event, struct perf_sample *sample, u64 type)
+static int arm_spe__inject_event(struct arm_spe *spe, union perf_event *event,
+				 struct perf_sample *sample, u64 type)
 {
-	event->header.size = perf_event__sample_event_size(sample, type, 0);
-	return perf_event__synthesize_sample(event, type, 0, sample);
+	struct evsel *evsel = sample->evsel;
+	u64 branch_sample_type = 0;
+	size_t sz;
+
+	if (!evsel && spe->session && spe->session->evlist)
+		evsel = evlist__id2evsel(spe->session->evlist, sample->id);
+
+	if (evsel)
+		branch_sample_type = evsel->core.attr.branch_sample_type;
+
+	event->header.type = PERF_RECORD_SAMPLE;
+	sz = perf_event__sample_event_size(sample, type, /*read_format=*/0,
+					   branch_sample_type);
+	if (sz >= PERF_SAMPLE_MAX_SIZE) {
+		pr_err("Sample size %zu exceeds max size %d\n", sz, PERF_SAMPLE_MAX_SIZE);
+		return -EFAULT;
+	}
+	event->header.size = sz;
+
+	return perf_event__synthesize_sample(event, type, /*read_format=*/0,
+					     branch_sample_type, sample);
 }
 
 static inline int
@@ -497,7 +517,7 @@ arm_spe_deliver_synth_event(struct arm_spe *spe,
 	int ret;
 
 	if (spe->synth_opts.inject) {
-		ret = arm_spe__inject_event(event, sample, spe->sample_type);
+		ret = arm_spe__inject_event(spe, event, sample, spe->sample_type);
 		if (ret)
 			return ret;
 	}
diff --git a/tools/perf/util/cs-etm.c b/tools/perf/util/cs-etm.c
index 8a639d2e51a4c5..6ec48de2944101 100644
--- a/tools/perf/util/cs-etm.c
+++ b/tools/perf/util/cs-etm.c
@@ -1422,11 +1422,29 @@ static void cs_etm__update_last_branch_rb(struct cs_etm_queue *etmq,
 		bs->nr += 1;
 }
 
-static int cs_etm__inject_event(union perf_event *event,
+static int cs_etm__inject_event(struct cs_etm_auxtrace *etm, union perf_event *event,
 			       struct perf_sample *sample, u64 type)
 {
-	event->header.size = perf_event__sample_event_size(sample, type, 0);
-	return perf_event__synthesize_sample(event, type, 0, sample);
+	struct evsel *evsel = sample->evsel;
+	u64 branch_sample_type = 0;
+	size_t sz;
+
+	if (!evsel && etm->session && etm->session->evlist)
+		evsel = evlist__id2evsel(etm->session->evlist, sample->id);
+
+	if (evsel)
+		branch_sample_type = evsel->core.attr.branch_sample_type;
+
+	sz = perf_event__sample_event_size(sample, type, /*read_format=*/0,
+					   branch_sample_type);
+	if (sz >= PERF_SAMPLE_MAX_SIZE) {
+		pr_err("Sample size %zu exceeds max size %d\n", sz, PERF_SAMPLE_MAX_SIZE);
+		return -EFAULT;
+	}
+	event->header.size = sz;
+
+	return perf_event__synthesize_sample(event, type, /*read_format=*/0,
+					     branch_sample_type, sample);
 }
 
 
@@ -1592,7 +1610,7 @@ static int cs_etm__synth_instruction_sample(struct cs_etm_queue *etmq,
 		sample.branch_stack = tidq->last_branch;
 
 	if (etm->synth_opts.inject) {
-		ret = cs_etm__inject_event(event, &sample,
+		ret = cs_etm__inject_event(etm, event, &sample,
 					   etm->instructions_sample_type);
 		if (ret)
 			return ret;
@@ -1667,7 +1685,7 @@ static int cs_etm__synth_branch_sample(struct cs_etm_queue *etmq,
 	}
 
 	if (etm->synth_opts.inject) {
-		ret = cs_etm__inject_event(event, &sample,
+		ret = cs_etm__inject_event(etm, event, &sample,
 					   etm->branches_sample_type);
 		if (ret)
 			return ret;
diff --git a/tools/perf/util/intel-bts.c b/tools/perf/util/intel-bts.c
index 382255393fb3bf..0b18ebd13f7c84 100644
--- a/tools/perf/util/intel-bts.c
+++ b/tools/perf/util/intel-bts.c
@@ -303,7 +303,8 @@ static int intel_bts_synth_branch_sample(struct intel_bts_queue *btsq,
 		event.sample.header.size = bts->branches_event_size;
 		ret = perf_event__synthesize_sample(&event,
 						    bts->branches_sample_type,
-						    0, &sample);
+						    /*read_format=*/0, /*branch_sample_type=*/0,
+						    &sample);
 		if (ret)
 			return ret;
 	}
diff --git a/tools/perf/util/intel-pt.c b/tools/perf/util/intel-pt.c
index fc9eec8b54b824..dd2637678b405c 100644
--- a/tools/perf/util/intel-pt.c
+++ b/tools/perf/util/intel-pt.c
@@ -1728,11 +1728,30 @@ static void intel_pt_prep_b_sample(struct intel_pt *pt,
 	event->sample.header.misc = sample->cpumode;
 }
 
-static int intel_pt_inject_event(union perf_event *event,
+static int intel_pt_inject_event(struct intel_pt *pt, union perf_event *event,
 				 struct perf_sample *sample, u64 type)
 {
-	event->header.size = perf_event__sample_event_size(sample, type, 0);
-	return perf_event__synthesize_sample(event, type, 0, sample);
+	struct evsel *evsel = sample->evsel;
+	u64 branch_sample_type = 0;
+	size_t sz;
+
+	if (!evsel && pt->session && pt->session->evlist)
+		evsel = evlist__id2evsel(pt->session->evlist, sample->id);
+
+	if (evsel)
+		branch_sample_type = evsel->core.attr.branch_sample_type;
+
+	event->header.type = PERF_RECORD_SAMPLE;
+	sz = perf_event__sample_event_size(sample, type, /*read_format=*/0,
+					   branch_sample_type);
+	if (sz >= PERF_SAMPLE_MAX_SIZE) {
+		pr_err("Sample size %zu exceeds max size %d\n", sz, PERF_SAMPLE_MAX_SIZE);
+		return -EFAULT;
+	}
+	event->header.size = sz;
+
+	return perf_event__synthesize_sample(event, type, /*read_format=*/0,
+					     branch_sample_type, sample);
 }
 
 static inline int intel_pt_opt_inject(struct intel_pt *pt,
@@ -1742,7 +1761,7 @@ static inline int intel_pt_opt_inject(struct intel_pt *pt,
 	if (!pt->synth_opts.inject)
 		return 0;
 
-	return intel_pt_inject_event(event, sample, type);
+	return intel_pt_inject_event(pt, event, sample, type);
 }
 
 static int intel_pt_deliver_synth_event(struct intel_pt *pt,
diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic-events.c
index 85bee747f4cd2a..2461f25a4d7dc2 100644
--- a/tools/perf/util/synthetic-events.c
+++ b/tools/perf/util/synthetic-events.c
@@ -1455,7 +1455,8 @@ int perf_event__synthesize_stat_round(const struct perf_tool *tool,
 	return process(tool, (union perf_event *) &event, NULL, machine);
 }
 
-size_t perf_event__sample_event_size(const struct perf_sample *sample, u64 type, u64 read_format)
+size_t perf_event__sample_event_size(const struct perf_sample *sample, u64 type, u64 read_format,
+				     u64 branch_sample_type)
 {
 	size_t sz, result = sizeof(struct perf_record_sample);
 
@@ -1515,8 +1516,10 @@ size_t perf_event__sample_event_size(const struct perf_sample *sample, u64 type,
 
 	if (type & PERF_SAMPLE_BRANCH_STACK) {
 		sz = sample->branch_stack->nr * sizeof(struct branch_entry);
-		/* nr, hw_idx */
-		sz += 2 * sizeof(u64);
+		/* nr */
+		sz += sizeof(u64);
+		if (branch_sample_type & PERF_SAMPLE_BRANCH_HW_INDEX)
+			sz += sizeof(u64);
 		result += sz;
 	}
 
@@ -1605,7 +1608,7 @@ static __u64 *copy_read_group_values(__u64 *array, __u64 read_format,
 }
 
 int perf_event__synthesize_sample(union perf_event *event, u64 type, u64 read_format,
-				  const struct perf_sample *sample)
+				  u64 branch_sample_type, const struct perf_sample *sample)
 {
 	__u64 *array;
 	size_t sz;
@@ -1719,9 +1722,17 @@ int perf_event__synthesize_sample(union perf_event *event, u64 type, u64 read_fo
 
 	if (type & PERF_SAMPLE_BRANCH_STACK) {
 		sz = sample->branch_stack->nr * sizeof(struct branch_entry);
-		/* nr, hw_idx */
-		sz += 2 * sizeof(u64);
-		memcpy(array, sample->branch_stack, sz);
+
+		*array++ = sample->branch_stack->nr;
+
+		if (branch_sample_type & PERF_SAMPLE_BRANCH_HW_INDEX) {
+			if (sample->no_hw_idx)
+				*array++ = 0;
+			else
+				*array++ = sample->branch_stack->hw_idx;
+		}
+
+		memcpy(array, perf_sample__branch_entries((struct perf_sample *)sample), sz);
 		array = (void *)array + sz;
 	}
 
diff --git a/tools/perf/util/synthetic-events.h b/tools/perf/util/synthetic-events.h
index b0edad0c310010..8c7f49f9ccf54a 100644
--- a/tools/perf/util/synthetic-events.h
+++ b/tools/perf/util/synthetic-events.h
@@ -81,7 +81,8 @@ int perf_event__synthesize_mmap_events(const struct perf_tool *tool, union perf_
 int perf_event__synthesize_modules(const struct perf_tool *tool, perf_event__handler_t process, struct machine *machine);
 int perf_event__synthesize_namespaces(const struct perf_tool *tool, union perf_event *event, pid_t pid, pid_t tgid, perf_event__handler_t process, struct machine *machine);
 int perf_event__synthesize_cgroups(const struct perf_tool *tool, perf_event__handler_t process, struct machine *machine);
-int perf_event__synthesize_sample(union perf_event *event, u64 type, u64 read_format, const struct perf_sample *sample);
+int perf_event__synthesize_sample(union perf_event *event, u64 type, u64 read_format,
+				  u64 branch_sample_type, const struct perf_sample *sample);
 int perf_event__synthesize_stat_config(const struct perf_tool *tool, struct perf_stat_config *config, perf_event__handler_t process, struct machine *machine);
 int perf_event__synthesize_stat_events(struct perf_stat_config *config, const struct perf_tool *tool, struct evlist *evlist, perf_event__handler_t process, bool attrs);
 int perf_event__synthesize_stat_round(const struct perf_tool *tool, u64 time, u64 type, perf_event__handler_t process, struct machine *machine);
@@ -97,7 +98,8 @@ void perf_event__synthesize_final_bpf_metadata(struct perf_session *session,
 
 int perf_tool__process_synth_event(const struct perf_tool *tool, union perf_event *event, struct machine *machine, perf_event__handler_t process);
 
-size_t perf_event__sample_event_size(const struct perf_sample *sample, u64 type, u64 read_format);
+size_t perf_event__sample_event_size(const struct perf_sample *sample, u64 type,
+				     u64 read_format, u64 branch_sample_type);
 
 int __machine__synthesize_threads(struct machine *machine, const struct perf_tool *tool,
 				  struct target *target, struct perf_thread_map *threads,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0888/2077] perf inject: Fix itrace branch stack synthesis
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (886 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0887/2077] perf event: Fix size of synthesized sample with branch stacks Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0889/2077] staging: most: video: avoid double free on video register failure Greg Kroah-Hartman
                   ` (109 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter, Dapeng Mi,
	Ingo Molnar, James Clark, Leo Yan, Namhyung Kim, Peter Zijlstra,
	Ravi Bangoria, Thomas Falcon, Arnaldo Carvalho de Melo,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ian Rogers <irogers@google.com>

[ Upstream commit daac18e7c42c012e289bfd310503f9417e4a9481 ]

When using "perf inject --itrace=L" to synthesize branch stacks from
AUX data, several issues caused failures with the generated file:

1. The synthesized samples were delivered without the
   PERF_SAMPLE_BRANCH_STACK flag if it was not in the original event's
   sample_type. Fixed by using sample_type | evsel->synth_sample_type
   in intel_pt_do_synth_pebs_sample.

2. Modifying evsel->core.attr.sample_type early in __cmd_inject caused
   parse failures for subsequent records in the input file. Fixed by
   moving this modification to just before writing the header.

3. perf_event__repipe_sample was narrowed to only synthesize samples
   when branch stack injection was requested, and restored the use of
   perf_inject__cut_auxtrace_sample as a fallback to preserve
   functionality.

4. Potential Heap Overflow in perf_event__repipe_sample: Addressed by
   adding a check that prints an error and returns -EFAULT if the
   calculated event size exceeds PERF_SAMPLE_MAX_SIZE.

5. Header vs Payload Mismatch in __cmd_inject: Addressed by narrowing
   the condition so that HEADER_BRANCH_STACK is only set in the file
   header if add_last_branch was true.

6. NULL Pointer Dereference in intel-pt.c: When branch stack injection
   is requested (add_last_branch is true) but last_branch is false
   (e.g., perf inject --itrace=L), ptq->last_branch was not allocated.
   However, PEBS branch stack synthesis (via synth_sample_type) still
   forced LBR handling in do_synth_pebs_sample(), dereferencing the
   NULL ptq->last_branch pointer. Guarding the dereference is not
   sufficient because downstream sample size calculation and synthesis
   strictly require a non-NULL branch_stack when the bit is set.
   Fixed by ensuring ptq->last_branch is allocated in
   intel_pt_alloc_queue() when add_last_branch is requested.

7. Modifying event attributes in perf_event__repipe_attr in-place caused
   SIGSEGV on read-only mmap buffers in file mode and downstream parser
   breakage in pipe mode. Fixed by processing the unmodified attribute
   first, returning immediately in non-pipe mode, and correctly
   synthesizing a new attribute event for pipe output using
   perf_event__synthesize_attr. Also:
   - Added a size validation check and integer underflow protection when
     parsing n_ids.
   - Prevented Trailing ID memory corruption by zero-initializing the
     local attr copy and safely copying using min_t(size_t, sizeof(attr),
     event->attr.attr.size).
   - Resolved ID array parsing mismatch downstream by expanding attr.size
     to sizeof(struct perf_event_attr) before synthesis to guarantee
     perfect header/attribute size alignment.

8. Potential dangling pointer vulnerability in perf_event__repipe_sample:
   Addressed by restoring the original sample->branch_stack pointer
   before returning, including on early error return paths.

9. Off-by-one error in sample size check in perf_event__repipe_sample:
   Fixed by checking if sz >= PERF_SAMPLE_MAX_SIZE instead of >.

10. Unadvertised size field left in payload by cut_auxtrace_sample:
    Addressed by excluding the 8-byte size field from the copied
    payload to correctly match the cleared PERF_SAMPLE_AUX bit. Cut
    the AUX sample payload even if size is 0.

11. Inaccurate sample size calculation and uninitialized memory leaks in
    convert_sample_callchain: Fixed by replacing manual arithmetic with
    perf_event__sample_event_size and adding a bounds check against
    PERF_SAMPLE_MAX_SIZE.

12. Omission of branch_sample_type in file headers: Addressed by
    expanding older, smaller attributes to PERF_ATTR_SIZE_VER2 in
    __cmd_inject to ensure branch_sample_type is not silently omitted.

Fixes: 0f0aa5e0693ce400 ("perf inject: Add Instruction Tracing support")
Assisted-by: Gemini:gemini-3.1-pro-preview
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Dapeng Mi <dapeng1.mi@linux.intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Leo Yan <leo.yan@linux.dev>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Ravi Bangoria <ravi.bangoria@amd.com>
Cc: Thomas Falcon <thomas.falcon@intel.com>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-inject.c | 153 ++++++++++++++++++++++++++++++++----
 tools/perf/util/intel-pt.c  |   8 +-
 2 files changed, 142 insertions(+), 19 deletions(-)

diff --git a/tools/perf/builtin-inject.c b/tools/perf/builtin-inject.c
index 2f20e782c7f272..7a64935b7e2b0b 100644
--- a/tools/perf/builtin-inject.c
+++ b/tools/perf/builtin-inject.c
@@ -216,12 +216,23 @@ static int perf_event__repipe_op4_synth(const struct perf_tool *tool,
 	return perf_event__repipe_synth(tool, event);
 }
 
+static int perf_event__repipe_synth_cb(const struct perf_tool *tool,
+				       union perf_event *event,
+				       struct perf_sample *sample __maybe_unused,
+				       struct machine *machine __maybe_unused)
+{
+	return perf_event__repipe_synth(tool, event);
+}
+
 static int perf_event__repipe_attr(const struct perf_tool *tool,
 				   union perf_event *event,
 				   struct evlist **pevlist)
 {
 	struct perf_inject *inject = container_of(tool, struct perf_inject,
 						  tool);
+	struct perf_event_attr attr;
+	size_t n_ids;
+	u64 *ids;
 	int ret;
 
 	ret = perf_event__process_attr(tool, event, pevlist);
@@ -232,7 +243,37 @@ static int perf_event__repipe_attr(const struct perf_tool *tool,
 	if (!inject->output.is_pipe)
 		return 0;
 
-	return perf_event__repipe_synth(tool, event);
+	if (!inject->itrace_synth_opts.set)
+		return perf_event__repipe_synth(tool, event);
+
+	if (event->header.size < sizeof(struct perf_event_header) + sizeof(u64)) {
+		pr_err("Attribute event size %u is too small\n", event->header.size);
+		return -EINVAL;
+	}
+
+	if (event->header.size - sizeof(event->header) < event->attr.attr.size) {
+		pr_err("Attribute event size %u is too small for attr.size %u\n",
+		       event->header.size, event->attr.attr.size);
+		return -EINVAL;
+	}
+
+	memset(&attr, 0, sizeof(attr));
+	memcpy(&attr, &event->attr.attr,
+	       min_t(size_t, sizeof(attr), (size_t)event->attr.attr.size));
+
+	n_ids = event->header.size - sizeof(event->header) - event->attr.attr.size;
+	n_ids /= sizeof(u64);
+	ids = perf_record_header_attr_id(event);
+
+	attr.size = sizeof(struct perf_event_attr);
+	attr.sample_type &= ~PERF_SAMPLE_AUX;
+
+	if (inject->itrace_synth_opts.add_last_branch) {
+		attr.sample_type |= PERF_SAMPLE_BRANCH_STACK;
+		attr.branch_sample_type |= PERF_SAMPLE_BRANCH_HW_INDEX;
+	}
+	return perf_event__synthesize_attr(tool, &attr, (u32)n_ids, ids,
+					   perf_event__repipe_synth_cb);
 }
 
 static int perf_event__repipe_event_update(const struct perf_tool *tool,
@@ -331,8 +372,8 @@ perf_inject__cut_auxtrace_sample(struct perf_inject *inject,
 				 union perf_event *event,
 				 struct perf_sample *sample)
 {
-	size_t sz1 = sample->aux_sample.data - (void *)event;
-	size_t sz2 = event->header.size - sample->aux_sample.size - sz1;
+	size_t sz1 = sample->aux_sample.data - (void *)event - sizeof(u64);
+	size_t sz2 = event->header.size - sample->aux_sample.size - (sz1 + sizeof(u64));
 	union perf_event *ev;
 
 	if (inject->event_copy == NULL) {
@@ -343,13 +384,12 @@ perf_inject__cut_auxtrace_sample(struct perf_inject *inject,
 	ev = (union perf_event *)inject->event_copy;
 	if (sz1 > event->header.size || sz2 > event->header.size ||
 	    sz1 + sz2 > event->header.size ||
-	    sz1 < sizeof(struct perf_event_header) + sizeof(u64))
+	    sz1 < sizeof(struct perf_event_header))
 		return event;
 
 	memcpy(ev, event, sz1);
 	memcpy((void *)ev + sz1, (void *)event + event->header.size - sz2, sz2);
 	ev->header.size = sz1 + sz2;
-	((u64 *)((void *)ev + sz1))[-1] = 0;
 
 	return ev;
 }
@@ -369,14 +409,77 @@ static int perf_event__repipe_sample(const struct perf_tool *tool,
 	struct perf_inject *inject = container_of(tool, struct perf_inject,
 						  tool);
 
-	if (evsel && evsel->handler) {
+	if (evsel == NULL)
+		return perf_event__repipe_synth(tool, event);
+
+	if (evsel->handler) {
 		inject_handler f = evsel->handler;
 		return f(tool, event, sample, evsel, machine);
 	}
 
 	build_id__mark_dso_hit(tool, event, sample, evsel, machine);
 
-	if (inject->itrace_synth_opts.set && sample->aux_sample.size) {
+	if (inject->itrace_synth_opts.set &&
+	    (inject->itrace_synth_opts.last_branch ||
+	     inject->itrace_synth_opts.add_last_branch)) {
+		union perf_event *event_copy = (void *)inject->event_copy;
+		struct branch_stack dummy_bs = { .nr = 0, .hw_idx = 0 };
+		int err;
+		size_t sz;
+		u64 orig_type = evsel->core.attr.sample_type;
+		u64 orig_branch_type = evsel->core.attr.branch_sample_type;
+
+		struct branch_stack *orig_bs = sample->branch_stack;
+
+		if (event_copy == NULL) {
+			inject->event_copy = malloc(PERF_SAMPLE_MAX_SIZE);
+			if (!inject->event_copy)
+				return -ENOMEM;
+
+			event_copy = (void *)inject->event_copy;
+		}
+
+		if (!sample->branch_stack)
+			sample->branch_stack = &dummy_bs;
+
+		if (inject->itrace_synth_opts.add_last_branch) {
+			/* Temporarily add in type bits for synthesis. */
+			evsel->core.attr.sample_type |= PERF_SAMPLE_BRANCH_STACK;
+			evsel->core.attr.branch_sample_type |= PERF_SAMPLE_BRANCH_HW_INDEX;
+		}
+		evsel->core.attr.sample_type &= ~PERF_SAMPLE_AUX;
+
+		sz = perf_event__sample_event_size(sample, evsel->core.attr.sample_type,
+						   evsel->core.attr.read_format,
+						   evsel->core.attr.branch_sample_type);
+
+		if (sz >= PERF_SAMPLE_MAX_SIZE) {
+			pr_err("Sample size %zu exceeds max size %d\n", sz, PERF_SAMPLE_MAX_SIZE);
+			evsel->core.attr.sample_type = orig_type;
+			evsel->core.attr.branch_sample_type = orig_branch_type;
+			sample->branch_stack = orig_bs;
+			return -EFAULT;
+		}
+
+		event_copy->header.type = PERF_RECORD_SAMPLE;
+		event_copy->header.misc = event->header.misc;
+		event_copy->header.size = sz;
+
+		err = perf_event__synthesize_sample(event_copy, evsel->core.attr.sample_type,
+						    evsel->core.attr.read_format,
+						    evsel->core.attr.branch_sample_type, sample);
+
+		evsel->core.attr.sample_type = orig_type;
+		evsel->core.attr.branch_sample_type = orig_branch_type;
+		sample->branch_stack = orig_bs;
+
+		if (err) {
+			pr_err("Failed to synthesize sample\n");
+			return err;
+		}
+		event = event_copy;
+	} else if (inject->itrace_synth_opts.set &&
+		   (evsel->core.attr.sample_type & PERF_SAMPLE_AUX)) {
 		event = perf_inject__cut_auxtrace_sample(inject, event, sample);
 		if (IS_ERR(event))
 			return PTR_ERR(event);
@@ -397,7 +500,7 @@ static int perf_event__convert_sample_callchain(const struct perf_tool *tool,
 	struct callchain_cursor_node *node;
 	struct thread *thread;
 	u64 sample_type = evsel->core.attr.sample_type;
-	u32 sample_size = event->header.size;
+	size_t sz;
 	u64 i, k;
 	int ret;
 
@@ -456,15 +559,18 @@ static int perf_event__convert_sample_callchain(const struct perf_tool *tool,
 out:
 	memcpy(event_copy, event, sizeof(event->header));
 
-	/* adjust sample size for stack and regs */
-	sample_size -= sample->user_stack.size;
-	sample_size -= (hweight64(evsel->core.attr.sample_regs_user) + 1) * sizeof(u64);
-	sample_size += (sample->callchain->nr + 1) * sizeof(u64);
-	event_copy->header.size = sample_size;
-
 	/* remove sample_type {STACK,REGS}_USER for synthesize */
 	sample_type &= ~(PERF_SAMPLE_STACK_USER | PERF_SAMPLE_REGS_USER);
 
+	sz = perf_event__sample_event_size(sample, sample_type,
+					   evsel->core.attr.read_format,
+					   evsel->core.attr.branch_sample_type);
+	if (sz >= PERF_SAMPLE_MAX_SIZE) {
+		pr_err("Sample size %zu exceeds max size %d\n", sz, PERF_SAMPLE_MAX_SIZE);
+		return -EFAULT;
+	}
+	event_copy->header.size = sz;
+
 	ret = perf_event__synthesize_sample(event_copy, sample_type,
 					    evsel->core.attr.read_format,
 					    evsel->core.attr.branch_sample_type, sample);
@@ -2442,12 +2548,27 @@ static int __cmd_inject(struct perf_inject *inject)
 		 * synthesized hardware events, so clear the feature flag.
 		 */
 		if (inject->itrace_synth_opts.set) {
+			struct evsel *evsel;
+
 			perf_header__clear_feat(&session->header,
 						HEADER_AUXTRACE);
-			if (inject->itrace_synth_opts.last_branch ||
-			    inject->itrace_synth_opts.add_last_branch)
+
+			evlist__for_each_entry(session->evlist, evsel) {
+				evsel->core.attr.sample_type &= ~PERF_SAMPLE_AUX;
+			}
+
+			if (inject->itrace_synth_opts.add_last_branch) {
 				perf_header__set_feat(&session->header,
 						      HEADER_BRANCH_STACK);
+
+				evlist__for_each_entry(session->evlist, evsel) {
+					evsel->core.attr.sample_type |= PERF_SAMPLE_BRANCH_STACK;
+					if (evsel->core.attr.size < PERF_ATTR_SIZE_VER2)
+						evsel->core.attr.size = PERF_ATTR_SIZE_VER2;
+					evsel->core.attr.branch_sample_type |=
+						PERF_SAMPLE_BRANCH_HW_INDEX;
+				}
+			}
 		}
 
 		/*
diff --git a/tools/perf/util/intel-pt.c b/tools/perf/util/intel-pt.c
index dd2637678b405c..d9c86ac4974866 100644
--- a/tools/perf/util/intel-pt.c
+++ b/tools/perf/util/intel-pt.c
@@ -1307,7 +1307,8 @@ static struct intel_pt_queue *intel_pt_alloc_queue(struct intel_pt *pt,
 			goto out_free;
 	}
 
-	if (pt->synth_opts.last_branch || pt->synth_opts.other_events) {
+	if (pt->synth_opts.last_branch || pt->synth_opts.add_last_branch ||
+	    pt->synth_opts.other_events) {
 		unsigned int entry_cnt = max(LBRS_MAX, pt->br_stack_sz);
 
 		ptq->last_branch = intel_pt_alloc_br_stack(entry_cnt);
@@ -2505,7 +2506,7 @@ static int intel_pt_do_synth_pebs_sample(struct intel_pt_queue *ptq, struct evse
 		intel_pt_add_xmm(intr_regs, pos, items, regs_mask);
 	}
 
-	if (sample_type & PERF_SAMPLE_BRANCH_STACK) {
+	if ((sample_type | evsel->synth_sample_type) & PERF_SAMPLE_BRANCH_STACK) {
 		if (items->mask[INTEL_PT_LBR_0_POS] ||
 		    items->mask[INTEL_PT_LBR_1_POS] ||
 		    items->mask[INTEL_PT_LBR_2_POS]) {
@@ -2576,7 +2577,8 @@ static int intel_pt_do_synth_pebs_sample(struct intel_pt_queue *ptq, struct evse
 		sample.transaction = txn;
 	}
 
-	ret = intel_pt_deliver_synth_event(pt, event, &sample, sample_type);
+	ret = intel_pt_deliver_synth_event(pt, event, &sample,
+					   sample_type | evsel->synth_sample_type);
 	perf_sample__exit(&sample);
 	return ret;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0889/2077] staging: most: video: avoid double free on video register failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (887 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0888/2077] perf inject: Fix itrace branch stack synthesis Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0890/2077] usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() Greg Kroah-Hartman
                   ` (108 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guangshuo Li <lgs201920130244@gmail.com>

[ Upstream commit 7cb1c5b32a2bfde961fff8d5204526b609bcb30a ]

comp_register_videodev() allocates a video_device with
video_device_alloc() and releases it if video_register_device() fails.

This can double free the video_device when __video_register_device()
reaches device_register() and that call fails:

  video_register_device()
    -> __video_register_device()
       -> device_register() fails
          -> put_device(&vdev->dev)
             -> v4l2_device_release()
                -> vdev->release(vdev)
                   -> video_device_release(vdev)

  comp_register_videodev()
    -> video_device_release(mdev->vdev)

Use video_device_release_empty() while registering the device so that
registration failure paths do not free mdev->vdev through vdev->release().
comp_register_videodev() then releases mdev->vdev exactly once on failure.
Restore video_device_release() after successful registration so the
registered device keeps its normal lifetime handling.

This issue was found by a static analysis tool I am developing.

Fixes: eab231c0398a ("staging: most: v4l2-aim: remove unnecessary label err_vbi_dev")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260517111218.945796-1-lgs201920130244@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/staging/most/video/video.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/staging/most/video/video.c b/drivers/staging/most/video/video.c
index 04351f8ccccf17..aab57768f4f707 100644
--- a/drivers/staging/most/video/video.c
+++ b/drivers/staging/most/video/video.c
@@ -420,6 +420,7 @@ static int comp_register_videodev(struct most_video_dev *mdev)
 
 	/* Fill the video capture device struct */
 	*mdev->vdev = comp_videodev_template;
+	mdev->vdev->release = video_device_release_empty;
 	mdev->vdev->v4l2_dev = &mdev->v4l2_dev;
 	mdev->vdev->lock = &mdev->lock;
 	snprintf(mdev->vdev->name, sizeof(mdev->vdev->name), "MOST: %s",
@@ -432,9 +433,13 @@ static int comp_register_videodev(struct most_video_dev *mdev)
 		v4l2_err(&mdev->v4l2_dev, "video_register_device failed (%d)\n",
 			 ret);
 		video_device_release(mdev->vdev);
+		return ret;
 	}
 
-	return ret;
+	mdev->vdev->release = video_device_release;
+
+	return 0;
+
 }
 
 static void comp_unregister_videodev(struct most_video_dev *mdev)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0890/2077] usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (888 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0889/2077] staging: most: video: avoid double free on video register failure Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0891/2077] usb: host: max3421: Reject hub port requests for non-existent ports Greg Kroah-Hartman
                   ` (107 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Seungjin Bae, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Seungjin Bae <eeodqql09@gmail.com>

[ Upstream commit cff06b03b530ae1fe8a13e93a7848f2130e00fb4 ]

The `max3421_hub_control()` function handles USB hub class requests
to the virtual root hub. In the `default` branches of both the
`ClearPortFeature` and `SetPortFeature` switch statements, it modifies
`max3421_hcd->port_status` by left shifting 1 by the request's `value`
parameter. However, it does not validate whether this shift will exceed
the width of `port_status`.

So if a malicious userspace task with access to the root hub via
/dev/bus/usb/.../001 issues a USBDEVFS_CONTROL ioctl with `wValue`
greater than or equal to 32, the left shift operation invokes
shift-out-of-bounds undefined behavior. This results in arbitrary
bit corruption of `port_status`, including the normally-immutable
change bits, which can bypass internal state checks and confuse the
hub status.

Fix this by rejecting requests whose `value` exceeds the shift width
before performing the shift.

This issue was found using a KLEE-based symbolic execution tool for
kernel drivers that I'm currently developing.

Fixes: 2d53139f3162 ("Add support for using a MAX3421E chip as a host driver.")
Signed-off-by: Seungjin Bae <eeodqql09@gmail.com>
Link: https://patch.msgid.link/20260518224901.1887013-1-eeodqql09@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/usb/host/max3421-hcd.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/usb/host/max3421-hcd.c b/drivers/usb/host/max3421-hcd.c
index 0e17c988d36a2d..3d6b351dcb1a28 100644
--- a/drivers/usb/host/max3421-hcd.c
+++ b/drivers/usb/host/max3421-hcd.c
@@ -1694,6 +1694,8 @@ max3421_hub_control(struct usb_hcd *hcd, u16 type_req, u16 value, u16 index,
 						!pdata->vbus_active_level);
 			fallthrough;
 		default:
+			if (value >= 32)
+				goto error;
 			max3421_hcd->port_status &= ~(1 << value);
 		}
 		break;
@@ -1747,6 +1749,8 @@ max3421_hub_control(struct usb_hcd *hcd, u16 type_req, u16 value, u16 index,
 			max3421_reset_port(hcd);
 			fallthrough;
 		default:
+			if (value >= 32)
+				goto error;
 			if ((max3421_hcd->port_status & USB_PORT_STAT_POWER)
 			    != 0)
 				max3421_hcd->port_status |= (1 << value);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0891/2077] usb: host: max3421: Reject hub port requests for non-existent ports
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (889 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0890/2077] usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0892/2077] perf test amd ibs: Fix incorrect kernel version check Greg Kroah-Hartman
                   ` (106 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Alan Stern, Seungjin Bae,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Seungjin Bae <eeodqql09@gmail.com>

[ Upstream commit 11b5c101e2fd206104b05bc92554d356989423a8 ]

The `max3421_hub_control()` function handles USB hub class requests
to the virtual root hub. The `GetPortStatus` case correctly rejects
requests with `index != 1`, since the virtual root hub has only a
single port. However, the `ClearPortFeature` and `SetPortFeature`
cases lack the same check.

Fix this by extending the `index != 1` rejection to both cases,
matching the existing behavior of `GetPortStatus`.

Fixes: 2d53139f3162 ("Add support for using a MAX3421E chip as a host driver.")
Suggested-by: Alan Stern <stern@rowland.harvard.edu>
Reviewed-by: Alan Stern <stern@rowland.harvard.edu>
Signed-off-by: Seungjin Bae <eeodqql09@gmail.com>
Link: https://patch.msgid.link/20260518224901.1887013-3-eeodqql09@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/usb/host/max3421-hcd.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/usb/host/max3421-hcd.c b/drivers/usb/host/max3421-hcd.c
index 3d6b351dcb1a28..73e76d0e697385 100644
--- a/drivers/usb/host/max3421-hcd.c
+++ b/drivers/usb/host/max3421-hcd.c
@@ -1685,6 +1685,8 @@ max3421_hub_control(struct usb_hcd *hcd, u16 type_req, u16 value, u16 index,
 	case ClearHubFeature:
 		break;
 	case ClearPortFeature:
+		if (index != 1)
+			goto error;
 		switch (value) {
 		case USB_PORT_FEAT_SUSPEND:
 			break;
@@ -1728,6 +1730,8 @@ max3421_hub_control(struct usb_hcd *hcd, u16 type_req, u16 value, u16 index,
 		break;
 
 	case SetPortFeature:
+		if (index != 1)
+			goto error;
 		switch (value) {
 		case USB_PORT_FEAT_LINK_STATE:
 		case USB_PORT_FEAT_U1_TIMEOUT:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0892/2077] perf test amd ibs: Fix incorrect kernel version check
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (890 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0891/2077] usb: host: max3421: Reject hub port requests for non-existent ports Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0893/2077] gpib: Fix inappropriate ioctl error return Greg Kroah-Hartman
                   ` (105 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ravi Bangoria, Namhyung Kim,
	Ananth Narayan, Dapeng Mi, Ian Rogers, Ingo Molnar, James Clark,
	Manali Shukla, Peter Zijlstra, Sandipan Das, Santosh Shukla,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ravi Bangoria <ravi.bangoria@amd.com>

[ Upstream commit 0b97e92393a178765ee1ea01fe5087efece2c425 ]

"AMD IBS sample period" unit test is getting skipped on kernel v7.x. Fix
the kernel version >= v6.15 check.

Fixes: 21fb366b2f457611 ("perf test amd: Skip amd-ibs-period test on kernel < v6.15")
Signed-off-by: Ravi Bangoria <ravi.bangoria@amd.com>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Cc: Ananth Narayan <ananth.narayan@amd.com>
Cc: Dapeng Mi <dapeng1.mi@linux.intel.com>
Cc: Ian Rogers <irogers@google.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Manali Shukla <manali.shukla@amd.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Ravi Bangoria <ravi.bangoria@amd.com>
Cc: Sandipan Das <sandipan.das@amd.com>
Cc: Santosh Shukla <santosh.shukla@amd.com>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/arch/x86/tests/amd-ibs-period.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/perf/arch/x86/tests/amd-ibs-period.c b/tools/perf/arch/x86/tests/amd-ibs-period.c
index cee9e11c05e08c..6a92b3a23ed7a6 100644
--- a/tools/perf/arch/x86/tests/amd-ibs-period.c
+++ b/tools/perf/arch/x86/tests/amd-ibs-period.c
@@ -932,7 +932,7 @@ static bool kernel_v6_15_or_newer(void)
 	endptr++;
 	minor = strtol(endptr, NULL, 10);
 
-	return major >= 6 && minor >= 15;
+	return major > 6 || (major == 6 && minor >= 15);
 }
 
 int test__amd_ibs_period(struct test_suite *test __maybe_unused,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0893/2077] gpib: Fix inappropriate ioctl error return
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (891 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0892/2077] perf test amd ibs: Fix incorrect kernel version check Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0894/2077] char: tlclk: fix use-after-free in tlclk_cleanup() Greg Kroah-Hartman
                   ` (104 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Dave Penkler, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Penkler <dpenkler@gmail.com>

[ Upstream commit 70ea440324e8c1a10837f721352f5bd469c85007 ]

The driver was returning -ENOTTY in the case the ioctl command
was not recognised. Change it to -EBADRQC.

Fixes: 9dde4559e939 ("staging: gpib: Add GPIB common core driver")
Signed-off-by: Dave Penkler <dpenkler@gmail.com>
Link: https://patch.msgid.link/20260411102025.2000-3-dpenkler@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpib/common/gpib_os.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/drivers/gpib/common/gpib_os.c b/drivers/gpib/common/gpib_os.c
index 5909274ddc1226..7dca60488872f3 100644
--- a/drivers/gpib/common/gpib_os.c
+++ b/drivers/gpib/common/gpib_os.c
@@ -613,7 +613,7 @@ long ibioctl(struct file *filep, unsigned int cmd, unsigned long arg)
 	unsigned int minor = iminor(file_inode(filep));
 	struct gpib_board *board;
 	struct gpib_file_private *file_priv = filep->private_data;
-	long retval = -ENOTTY;
+	long retval = -EBADRQC;
 
 	if (minor >= GPIB_MAX_NUM_BOARDS) {
 		pr_err("gpib: invalid minor number of device file\n");
@@ -806,7 +806,6 @@ long ibioctl(struct file *filep, unsigned int cmd, unsigned long arg)
 		mutex_unlock(&board->big_gpib_mutex);
 		return write_ioctl(file_priv, board, arg);
 	default:
-		retval = -ENOTTY;
 		goto done;
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0894/2077] char: tlclk: fix use-after-free in tlclk_cleanup()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (892 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0893/2077] gpib: Fix inappropriate ioctl error return Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0895/2077] hpet: Check ACPI_COMPANION() against NULL at probe time Greg Kroah-Hartman
                   ` (103 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, James Kim, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: James Kim <james010kim@gmail.com>

[ Upstream commit bbf003b7794d6ad6f939fdd29f1f1bde8ac554c1 ]

This patch improves the module cleanup process in the tlclk driver to
prevent potential use-after-free and race conditions.

Currently, the file_operations structure does not specify the .owner
field, which could allow the module to be unloaded while user-space
processes are still interacting with the device. Additionally, the
tlclk_cleanup() function frees the alarm_events memory before ensuring
that blocked processes in the waitqueue are fully awakened and that the
switchover_timer has completed.

To address these cases, this patch:
- Sets '.owner = THIS_MODULE' in tlclk_fops to safely defer module
  unloading while the device is in use.
- Updates tlclk_cleanup() to explicitly wake up all blocked readers
  (wake_up_all), properly release hardware I/O regions, and safely
  delete the timer (timer_delete_sync) prior to freeing memory.

Fixes: 1a80ba882730 ("[PATCH] Telecom Clock Driver for MPCBL0010 ATCA computer blade")
Signed-off-by: James Kim <james010kim@gmail.com>
Link: https://patch.msgid.link/20260503101131.64219-1-james010kim@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/char/tlclk.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/char/tlclk.c b/drivers/char/tlclk.c
index 677d230a226cf5..dd45fe5eb6f270 100644
--- a/drivers/char/tlclk.c
+++ b/drivers/char/tlclk.c
@@ -264,6 +264,7 @@ static ssize_t tlclk_read(struct file *filp, char __user *buf, size_t count,
 }
 
 static const struct file_operations tlclk_fops = {
+	.owner = THIS_MODULE,
 	.read = tlclk_read,
 	.open = tlclk_open,
 	.release = tlclk_release,
@@ -837,6 +838,9 @@ static void __exit tlclk_cleanup(void)
 	misc_deregister(&tlclk_miscdev);
 	unregister_chrdev(tlclk_major, "telco_clock");
 
+	got_event = 1;
+	wake_up_all(&wq);
+
 	release_region(TLCLK_BASE, 8);
 	timer_delete_sync(&switchover_timer);
 	kfree(alarm_events);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0895/2077] hpet: Check ACPI_COMPANION() against NULL at probe time
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (893 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0894/2077] char: tlclk: fix use-after-free in tlclk_cleanup() Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0896/2077] sonypi: " Greg Kroah-Hartman
                   ` (102 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit fa5e2952341b792b72d5410dbfcd0b2ac8046d2a ]

Every platform driver can be forced to match a device that doesn't match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device's ACPI companion
object need to verify its presence.

Accordingly, add a requisite ACPI_COMPANION() check against NULL to the
hpet driver.

Fixes: 71f0a267346b ("hpet: Convert ACPI driver to a platform one")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/4750803.LvFx2qVVIh@rafael.j.wysocki
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/char/hpet.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/char/hpet.c b/drivers/char/hpet.c
index 46c84e5df00fd5..285c6037417ab2 100644
--- a/drivers/char/hpet.c
+++ b/drivers/char/hpet.c
@@ -976,10 +976,14 @@ static acpi_status hpet_resources(struct acpi_resource *res, void *data)
 
 static int hpet_acpi_probe(struct platform_device *pdev)
 {
-	struct acpi_device *device = ACPI_COMPANION(&pdev->dev);
+	struct acpi_device *device;
 	acpi_status result;
 	struct hpet_data data;
 
+	device = ACPI_COMPANION(&pdev->dev);
+	if (!device)
+		return -ENODEV;
+
 	memset(&data, 0, sizeof(data));
 
 	result =
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0896/2077] sonypi: Check ACPI_COMPANION() against NULL at probe time
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (894 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0895/2077] hpet: Check ACPI_COMPANION() against NULL at probe time Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0897/2077] gpib: fix double decrement of descriptor_busy in command_ioctl() Greg Kroah-Hartman
                   ` (101 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>

[ Upstream commit 950f35211b85db26fc1aae67bf1e14ccef393a0a ]

Every platform driver can be forced to match a device that doesn't match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device's ACPI companion
object need to verify its presence.

Accordingly, add a requisite ACPI_COMPANION() check against NULL to the
sonypi driver.

Fixes: 7e488b0af021 ("sonypi: Convert ACPI driver to a platform one")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/5087721.GXAFRqVoOG@rafael.j.wysocki
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/char/sonypi.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/char/sonypi.c b/drivers/char/sonypi.c
index ccda997a9098a3..24c1b26f34d6b1 100644
--- a/drivers/char/sonypi.c
+++ b/drivers/char/sonypi.c
@@ -1117,7 +1117,11 @@ static int sonypi_disable(void)
 #ifdef CONFIG_ACPI
 static int sonypi_acpi_probe(struct platform_device *pdev)
 {
-	struct acpi_device *device = ACPI_COMPANION(&pdev->dev);
+	struct acpi_device *device;
+
+	device = ACPI_COMPANION(&pdev->dev);
+	if (!device)
+		return -ENODEV;
 
 	sonypi_acpi_device = device;
 	strcpy(acpi_device_name(device), "Sony laptop hotkeys");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0897/2077] gpib: fix double decrement of descriptor_busy in command_ioctl()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (895 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0896/2077] sonypi: " Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0898/2077] gpib: cb7210: Fix region leak when request_irq fails Greg Kroah-Hartman
                   ` (100 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ruikai Peng, Adam Crosser,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Adam Crosser <adam.crosser@praetorian.com>

[ Upstream commit c4faab452b3c1ada003d49c477609dd80523b9bf ]

commit d1857f8296dc ("gpib: fix use-after-free in IO ioctl handlers")
introduced a descriptor_busy reference counter to pin struct
gpib_descriptor across IO ioctl operations.  In command_ioctl(), the
error path inside the loop decrements descriptor_busy and breaks, but
execution then falls through to the unconditional decrement after the
loop, underflowing the counter to -1.

This re-enables the use-after-free that the original fix was meant to
prevent: a concurrent close_dev_ioctl() sees descriptor_busy == 0 on
an actively-used descriptor and frees it.

Remove the early decrement from the error path.  The post-loop
decrement already handles all exit paths, matching the correct pattern
used in read_ioctl() and write_ioctl().

Fixes: d1857f8296dc ("gpib: fix use-after-free in IO ioctl handlers")
Reported-by: Ruikai Peng <ruikai@pwno.io>
Signed-off-by: Adam Crosser <adam.crosser@praetorian.com>
Link: https://patch.msgid.link/20260424123750.855863-1-adam.r.crosser@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpib/common/gpib_os.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/gpib/common/gpib_os.c b/drivers/gpib/common/gpib_os.c
index 7dca60488872f3..fcf13432c7dd55 100644
--- a/drivers/gpib/common/gpib_os.c
+++ b/drivers/gpib/common/gpib_os.c
@@ -1017,7 +1017,6 @@ static int command_ioctl(struct gpib_file_private *file_priv,
 		userbuf += bytes_written;
 		if (retval < 0) {
 			atomic_set(&desc->io_in_progress, 0);
-			atomic_dec(&desc->descriptor_busy);
 
 			wake_up_interruptible(&board->wait);
 			break;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0898/2077] gpib: cb7210: Fix region leak when request_irq fails
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (896 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0897/2077] gpib: fix double decrement of descriptor_busy in command_ioctl() Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0899/2077] clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing Greg Kroah-Hartman
                   ` (99 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Hongling Zeng, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hongling Zeng <zenghongling@kylinos.cn>

[ Upstream commit 5ad28496055858166eb2268344c8fda2c26d3561 ]

When request_irq() fails, the region allocated by request_region()
is not released. Fix this by calling release_region() before returning.

  Smatch warning:
    drivers/gpib/cb7210/cb7210.c:1068 cb_isa_attach() warn: 'config->ibbase'
  from __request_region() not released on lines: 1064.

Fixes: 82e3508046f9 ("staging: gpib: cb7210 console messaging cleanup")
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Link: https://patch.msgid.link/20260503093036.283546-1-zenghongling@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpib/cb7210/cb7210.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/gpib/cb7210/cb7210.c b/drivers/gpib/cb7210/cb7210.c
index 6dd8637c5964b3..05058bf2cd50bc 100644
--- a/drivers/gpib/cb7210/cb7210.c
+++ b/drivers/gpib/cb7210/cb7210.c
@@ -1062,6 +1062,7 @@ static int cb_isa_attach(struct gpib_board *board, const struct gpib_board_confi
 	// install interrupt handler
 	if (request_irq(config->ibirq, cb7210_interrupt, isr_flags, DRV_NAME, board)) {
 		dev_err(board->gpib_dev, "failed to obtain IRQ %d\n", config->ibirq);
+		release_region(nec7210_iobase(cb_priv), cb7210_iosize);
 		return -EBUSY;
 	}
 	cb_priv->irq = config->ibirq;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0899/2077] clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (897 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0898/2077] gpib: cb7210: Fix region leak when request_irq fails Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0900/2077] docs: threat-model: add missing closing parenthesis Greg Kroah-Hartman
                   ` (98 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lad Prabhakar, Geert Uytterhoeven,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>

[ Upstream commit 1f10c4509649e7c5f6d5d3acccf3ef6fbb5cdd46 ]

Rename the internal loop iterator variable in the for_each_mod_clock()
macro from 'i' to '__i'.

The current naming conflicts with local loop variables named 'i' inside
code blocks that utilize the macro, triggering compiler warnings due to
variable shadowing:

  drivers/clk/renesas/rzg2l-cpg.c:1494:36: warning: declaration of `i` shadows a previous local [-Wshadow]
   1494 |                  for (unsigned int i = 0; i < clk->num_shared_mstop_clks; i++)

Using a unique identifier for the macro-internal iterator resolves the
shadowing warnings globally across all macro expansions.

Fixes: 3fd4a8bb4b63 ("clk: renesas: rzg2l: Add macro to loop through module clocks")
Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260520092947.70596-1-prabhakar.mahadev-lad.rj@bp.renesas.com
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clk/renesas/rzg2l-cpg.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/clk/renesas/rzg2l-cpg.c b/drivers/clk/renesas/rzg2l-cpg.c
index abfd8634d2bef2..c7bb5b97e7c45b 100644
--- a/drivers/clk/renesas/rzg2l-cpg.c
+++ b/drivers/clk/renesas/rzg2l-cpg.c
@@ -1340,10 +1340,10 @@ struct mod_clock {
 #define to_mod_clock(_hw) container_of(_hw, struct mod_clock, hw)
 
 #define for_each_mod_clock(mod_clock, hw, priv) \
-	for (unsigned int i = 0; (priv) && i < (priv)->num_mod_clks; i++) \
-		if ((priv)->clks[(priv)->num_core_clks + i] == ERR_PTR(-ENOENT)) \
+	for (unsigned int __i = 0; (priv) && __i < (priv)->num_mod_clks; __i++) \
+		if ((priv)->clks[(priv)->num_core_clks + __i] == ERR_PTR(-ENOENT)) \
 			continue; \
-		else if (((hw) = __clk_get_hw((priv)->clks[(priv)->num_core_clks + i])) && \
+		else if (((hw) = __clk_get_hw((priv)->clks[(priv)->num_core_clks + __i])) && \
 			 ((mod_clock) = to_mod_clock(hw)))
 
 /* Need to be called with a lock held to avoid concurrent access to mstop->usecnt. */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0900/2077] docs: threat-model: add missing closing parenthesis
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (898 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0899/2077] clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0901/2077] powerpc tools perf: Initialize error code in auxtrace_record_init function Greg Kroah-Hartman
                   ` (97 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Baruch Siach, Willy Tarreau,
	Jonathan Corbet, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Baruch Siach <baruch@tkos.co.il>

[ Upstream commit 89f332c1ef348e260a885085cd7821d6d72db7ec ]

Fixes: a03ef333fbd6 ("Documentation: security-bugs: explain what is and is not a security bug")
Signed-off-by: Baruch Siach <baruch@tkos.co.il>
Acked-by: Willy Tarreau <w@1wt.eu>
Signed-off-by: Jonathan Corbet <corbet@lwn.net>
Message-ID: <da8ee1e8b4e99261ec11544c4e1a4f81316ae965.1779032501.git.baruch@tkos.co.il>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/process/threat-model.rst | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/Documentation/process/threat-model.rst b/Documentation/process/threat-model.rst
index f177b8d3c1cafd..9dd8011dde828b 100644
--- a/Documentation/process/threat-model.rst
+++ b/Documentation/process/threat-model.rst
@@ -176,7 +176,7 @@ regular bug:
   * problems seen only under development simulators, emulators, or combinations
     that do not exist on real systems at the time of reporting (issues
     involving tens of millions of threads, tens of thousands of CPUs,
-    unrealistic CPU frequencies, RAM sizes or disk capacities, network speeds.
+    unrealistic CPU frequencies, RAM sizes or disk capacities, network speeds).
 
   * issues whose reproduction requires hardware modification or emulation,
     including fake USB devices that pretend to be another one.
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0901/2077] powerpc tools perf: Initialize error code in auxtrace_record_init function
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (899 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0900/2077] docs: threat-model: add missing closing parenthesis Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0902/2077] PCI: qcom: Disable ASPM L0s for SA8775P Greg Kroah-Hartman
                   ` (96 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Adrian Hunter, Athira Rajeev,
	Namhyung Kim, Hari Bathini, Ian Rogers, Jiri Olsa, linuxppc-dev,
	Madhavan Srinivasan, Michael Petlan, Shivani Nittor,
	Tanushree Shah, Tejas Manhas, Thomas Richter,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Athira Rajeev <atrajeev@linux.ibm.com>

[ Upstream commit 789d22d77879eabb042627f6627cdb62787bc142 ]

perf trace record fails some cases in powerpc

 # perf test "perf trace record and replay"
 128: perf trace record and replay                                    : FAILED!

  # perf trace record sleep 1
  # echo $?
    32

This is happening because of non-zero err value from
auxtrace_record__init() function.

 static int record__auxtrace_init(struct record *rec)
 {
        int err;

        if ((rec->opts.auxtrace_snapshot_opts || rec->opts.auxtrace_sample_opts)
            && record__threads_enabled(rec)) {
                pr_err("AUX area tracing options are not available in parallel streaming mode.\n");
                return -EINVAL;
        }

        if (!rec->itr) {
                rec->itr = auxtrace_record__init(rec->evlist, &err);
                if (err)
                        return err;
        }

Here "int err" is not initialised. The code expects "err" to be set from
auxtrace_record__init() function.

Update auxtrace_record__init() in arch/powerpc/util/auxtrace.c to clear
err value in the beginning.

- Clear err value in beginning of function. Any fail later will
set appropriate return code to err.

- Even if we haven't found any event for auxtrace, perf record
should continue for other events. NULL return
will indicate that there is no auxtrace record initialized.

- Not having "err" set here will affect monitoring of other events
also because perf record will fail seeing random value in err.

Set err to -EINVAL before invoking auxtrace_record__init() in
builtin-record.c

With the fix,

  # perf trace record sleep 1
  [ perf record: Woken up 2 times to write data ]
  [ perf record: Captured and wrote 0.033 MB perf.data (228 samples) ]

Fixes: 1dbfaf94cf66ec4b ("perf powerpc: Add basic CONFIG_AUXTRACE support for VPA pmu on powerpc")
Reviewed-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Athira Rajeev <atrajeev@linux.ibm.com>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Cc: Athira Rajeev <atrajeev@linux.ibm.com>
Cc: Hari Bathini <hbathini@linux.vnet.ibm.com>
Cc: Ian Rogers <irogers@google.com>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: linuxppc-dev@lists.ozlabs.org
Cc: Madhavan Srinivasan <maddy@linux.ibm.com>
Cc: Michael Petlan <mpetlan@redhat.com>
Cc: Shivani Nittor <shivani@linux.ibm.com>
Cc: Tanushree Shah <tanushree.shah@ibm.com>
Cc: Tejas Manhas <tejas.manhas1@ibm.com>
Cc: Thomas Richter <tmricht@linux.ibm.com>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/arch/powerpc/util/auxtrace.c | 6 ++++++
 tools/perf/builtin-record.c             | 1 +
 2 files changed, 7 insertions(+)

diff --git a/tools/perf/arch/powerpc/util/auxtrace.c b/tools/perf/arch/powerpc/util/auxtrace.c
index e39deff6c857a8..4600a1661b4fe3 100644
--- a/tools/perf/arch/powerpc/util/auxtrace.c
+++ b/tools/perf/arch/powerpc/util/auxtrace.c
@@ -71,6 +71,12 @@ struct auxtrace_record *auxtrace_record__init(struct evlist *evlist,
 	struct evsel *pos;
 	int found = 0;
 
+	/*
+	 * Set err value to zero here. Any fail later
+	 * will set appropriate return code to err.
+	 */
+	*err = 0;
+
 	evlist__for_each_entry(evlist, pos) {
 		if (strstarts(pos->name, "vpa_dtl")) {
 			found = 1;
diff --git a/tools/perf/builtin-record.c b/tools/perf/builtin-record.c
index 4a5eba498c0259..708825747af5da 100644
--- a/tools/perf/builtin-record.c
+++ b/tools/perf/builtin-record.c
@@ -865,6 +865,7 @@ static int record__auxtrace_init(struct record *rec)
 	}
 
 	if (!rec->itr) {
+		err = -EINVAL;
 		rec->itr = auxtrace_record__init(rec->evlist, &err);
 		if (err)
 			return err;
-- 
2.53.0





^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0902/2077] PCI: qcom: Disable ASPM L0s for SA8775P
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (900 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0901/2077] powerpc tools perf: Initialize error code in auxtrace_record_init function Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0903/2077] timers/migration: Update stale @online doc to @available Greg Kroah-Hartman
                   ` (95 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shawn Guo, Manivannan Sadhasivam,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shawn Guo <shengchao.guo@oss.qualcomm.com>

[ Upstream commit 29f692985819f4089f02a86e151a72f6d4cdd90d ]

Due to a hardware issue, L0s is not properly supported by the PCIe
controller on the SA8775p SoC. If enabled, the L0s to L0 transition
triggers below correctable AER errors and may also affect link stability:

  pcieport 0000:00:00.0: PME: Signaling with IRQ 332
  pcieport 0000:00:00.0: AER: enabled with IRQ 332
  pcieport 0000:00:00.0: AER: Correctable error message received from 0000:01:00.0
  pci 0000:01:00.0: PCIe Bus Error: severity=Correctable, type=Data Link Layer, (Transmitter ID)
  pci 0000:01:00.0:   device [17cb:1103] error status/mask=00001000/0000e000
  pci 0000:01:00.0:    [12] Timeout
  pcieport 0000:00:00.0: AER: Multiple Correctable error message received from 0000:01:00.0
  pcieport 0000:00:00.0: PCIe Bus Error: severity=Correctable, type=Data Link Layer, (Transmitter ID)
  pcieport 0000:00:00.0:   device [17cb:0115] error status/mask=00001000/0000e000
  pcieport 0000:00:00.0:    [12] Timeout

Hence, disable L0s for the SA8775p SoC to allow it to properly function
by sacrificing a little bit of power saving.

Fixes: 58d0d3e032b3 ("PCI: qcom-ep: Add support for SA8775P SOC")
Assisted-by: Claude:claude-4-6-sonnet
Signed-off-by: Shawn Guo <shengchao.guo@oss.qualcomm.com>
[mani: commit log, corrected fixes tag]
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Link: https://patch.msgid.link/20260419093934.1223027-1-shengchao.guo@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/dwc/pcie-qcom.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/pci/controller/dwc/pcie-qcom.c b/drivers/pci/controller/dwc/pcie-qcom.c
index 8604aa564dce67..2af75739797512 100644
--- a/drivers/pci/controller/dwc/pcie-qcom.c
+++ b/drivers/pci/controller/dwc/pcie-qcom.c
@@ -1473,6 +1473,7 @@ static const struct qcom_pcie_cfg cfg_1_9_0 = {
 static const struct qcom_pcie_cfg cfg_1_34_0 = {
 	.ops = &ops_1_9_0,
 	.override_no_snoop = true,
+	.no_l0s = true,
 };
 
 static const struct qcom_pcie_cfg cfg_2_1_0 = {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0903/2077] timers/migration: Update stale @online doc to @available
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (901 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0902/2077] PCI: qcom: Disable ASPM L0s for SA8775P Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0904/2077] perf header: Sanity check HEADER_EVENT_DESC attr.size before swap Greg Kroah-Hartman
                   ` (94 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhan Xusheng, Thomas Gleixner,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhan Xusheng <zhanxusheng@xiaomi.com>

[ Upstream commit 45a13ba52c82dbec9715222c51e629e85daa37d7 ]

Commit 8312cab5ff47 ("timers/migration: Rename 'online' bit to
'available'") renamed the 'online' field of struct tmigr_cpu to
'available'. The kernel doc comment above the struct still describes the
old field name.

Update it to reflect the actual field name and use the 'available' wording
in the description.

Fixes: 8312cab5ff47 ("timers/migration: Rename 'online' bit to 'available'")
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260526022106.1302279-1-zhanxusheng@xiaomi.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 kernel/time/timer_migration.h | 18 ++++++++++--------
 1 file changed, 10 insertions(+), 8 deletions(-)

diff --git a/kernel/time/timer_migration.h b/kernel/time/timer_migration.h
index 70879cde6fdd01..4c0073f3d3212e 100644
--- a/kernel/time/timer_migration.h
+++ b/kernel/time/timer_migration.h
@@ -75,15 +75,17 @@ struct tmigr_group {
 /**
  * struct tmigr_cpu - timer migration per CPU group
  * @lock:		Lock protecting the tmigr_cpu group information
- * @online:		Indicates whether the CPU is online; In deactivate path
- *			it is required to know whether the migrator in the top
- *			level group is to be set offline, while a timer is
- *			pending. Then another online CPU needs to be notified to
- *			take over the migrator role. Furthermore the information
- *			is required in CPU hotplug path as the CPU is able to go
- *			idle before the timer migration hierarchy hotplug AP is
- *			reached. During this phase, the CPU has to handle the
+ * @available:		Indicates whether the CPU is available for handling
+ *			global timers. In the deactivate path it is required to
+ *			know whether the migrator in the top level group is to
+ *			be set offline, while a timer is pending. Then another
+ *			available CPU needs to be notified to take over the
+ *			migrator role. Furthermore the information is required
+ *			in the CPU hotplug path as the CPU is able to go idle
+ *			before the timer migration hierarchy hotplug callback is
+ *			reached.  During this phase, the CPU has to handle the
  *			global timers on its own and must not act as a migrator.
+
  * @idle:		Indicates whether the CPU is idle in the timer migration
  *			hierarchy
  * @remote:		Is set when timers of the CPU are expired remotely
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0904/2077] perf header: Sanity check HEADER_EVENT_DESC attr.size before swap
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (902 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0903/2077] timers/migration: Update stale @online doc to @available Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0905/2077] perf header: Validate bitmap size before allocating in do_read_bitmap() Greg Kroah-Hartman
                   ` (93 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Jiri Olsa, Namhyung Kim,
	Wang Nan, Arnaldo Carvalho de Melo, Sasha Levin, sashiko-bot

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 944f65c8b8231d26d4db6be67bcb641142603cb4 ]

read_event_desc() reads nre (event count), sz (attr size), and nr
(IDs per event) from the file and uses them to control allocations
and loops without validating them against the section size.

A crafted perf.data could trigger large allocations or many loop
iterations before __do_read() eventually rejects the reads.

Add bounds checks in read_event_desc():
- Reject sz smaller than PERF_ATTR_SIZE_VER0.
- Require at least one event (nre > 0).
- Check that nre events fit in the remaining section, using the
  minimum per-event footprint of sz + sizeof(u32).
- Pre-swap attr->size to native byte order, then reject values
  below PERF_ATTR_SIZE_VER0 or above sz before calling
  perf_event__attr_swap() to prevent heap out-of-bounds access.
- Handle ABI0 (attr.size == 0): substitute PERF_ATTR_SIZE_VER0,
  and on native-endian files write the value back so
  free_event_desc() does not treat the zero as its end-of-array
  sentinel (it iterates while attr.size != 0).  The swap path
  skips the write-back — perf_event__attr_swap() has its own
  ABI0 fallback that sets VER0 after swapping.
- Check that nr IDs fit in the remaining section before allocating.

Fixes: b30b61729246 ("perf tools: Fix a problem when opening old perf.data with different byte order")
Reported-by: sashiko-bot@kernel.org # Running on a local machine
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Wang Nan <wangnan0@huawei.com>
Assisted-by: Claude:claude-opus-4.6-1m
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/header.c | 54 ++++++++++++++++++++++++++++++++++++++++
 1 file changed, 54 insertions(+)

diff --git a/tools/perf/util/header.c b/tools/perf/util/header.c
index f30e48eb3fc32d..30e5e50ab98b8b 100644
--- a/tools/perf/util/header.c
+++ b/tools/perf/util/header.c
@@ -2135,9 +2135,28 @@ static struct evsel *read_event_desc(struct feat_fd *ff)
 	if (do_read_u32(ff, &nre))
 		goto error;
 
+	/* Size of each of the nre attributes. */
 	if (do_read_u32(ff, &sz))
 		goto error;
 
+	/*
+	 * Require at least one event with an attr no smaller than the
+	 * first published struct, and reject sz values where
+	 * sz + sizeof(u32) would overflow size_t (possible on 32-bit)
+	 * or nre == UINT32_MAX where nre + 1 wraps to 0 in the calloc.
+	 *
+	 * The minimum section footprint per event is sz bytes for the
+	 * attr plus a u32 for the id count, check that nre events fit.
+	 */
+	if (!nre || sz < PERF_ATTR_SIZE_VER0 ||
+	    sz > ff->size || (size_t)sz > SIZE_MAX - sizeof(u32) ||
+	    nre == UINT32_MAX ||
+	    nre > (ff->size - ff->offset) / (sz + sizeof(u32))) {
+		pr_err("Invalid HEADER_EVENT_DESC: nre=%u sz=%u (min %d)\n",
+		       nre, sz, PERF_ATTR_SIZE_VER0);
+		goto error;
+	}
+
 	/* buffer to hold on file attr struct */
 	buf = malloc(sz);
 	if (!buf)
@@ -2153,6 +2172,9 @@ static struct evsel *read_event_desc(struct feat_fd *ff)
 		msz = sz;
 
 	for (i = 0, evsel = events; i < nre; evsel++, i++) {
+		struct perf_event_attr *attr = buf;
+		u32 attr_size;
+
 		evsel->core.idx = i;
 
 		/*
@@ -2162,6 +2184,32 @@ static struct evsel *read_event_desc(struct feat_fd *ff)
 		if (__do_read(ff, buf, sz))
 			goto error;
 
+		/* Reject before attr_swap to prevent OOB via bswap_safe() */
+		attr_size = ff->ph->needs_swap ? bswap_32(attr->size) : attr->size;
+		/* ABI0: size == 0 means the producer didn't set it */
+		if (!attr_size) {
+			attr_size = PERF_ATTR_SIZE_VER0;
+			/*
+			 * Write back so free_event_desc() doesn't
+			 * treat this event as the end-of-array sentinel
+			 * (it iterates while attr.size != 0).
+			 *
+			 * Only for native — the swap path must NOT
+			 * write native-endian VER0 here because
+			 * perf_event__attr_swap() would re-swap it
+			 * to 0x40000000, defeating bswap_safe() bounds.
+			 * perf_event__attr_swap() has its own ABI0
+			 * fallback that sets VER0 after swapping.
+			 */
+			if (!ff->ph->needs_swap)
+				attr->size = attr_size;
+		}
+		if (attr_size < PERF_ATTR_SIZE_VER0 || attr_size > sz) {
+			pr_err("Event %d attr.size (%u) invalid (min: %d, max: %u)\n",
+			       i, attr_size, PERF_ATTR_SIZE_VER0, sz);
+			goto error;
+		}
+
 		if (ff->ph->needs_swap)
 			perf_event__attr_swap(buf);
 
@@ -2183,6 +2231,12 @@ static struct evsel *read_event_desc(struct feat_fd *ff)
 		if (!nr)
 			continue;
 
+		/* Prevent oversized allocation from crafted nr */
+		if (nr > (ff->size - ff->offset) / sizeof(*id)) {
+			pr_err("Event %d: id count %u exceeds remaining section\n", i, nr);
+			goto error;
+		}
+
 		id = calloc(nr, sizeof(*id));
 		if (!id)
 			goto error;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0905/2077] perf header: Validate bitmap size before allocating in do_read_bitmap()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (903 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0904/2077] perf header: Sanity check HEADER_EVENT_DESC attr.size before swap Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0906/2077] iio: light: si1133: reset counter to prevent race condition Greg Kroah-Hartman
                   ` (92 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Jiri Olsa, Namhyung Kim,
	Arnaldo Carvalho de Melo, Sasha Levin, sashiko-bot

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 3669697bda41c562d90eb38f54881cc02ef3d51c ]

do_read_bitmap() reads a u64 bit count from the file and passes it
to bitmap_zalloc() without checking it against the remaining section
size. A crafted perf.data could trigger a large allocation that would
only fail later when the per-element reads exceed section bounds.

Additionally, bitmap_zalloc() takes an int parameter, so a crafted
size with bits set above bit 31 (e.g. 0x100000040) would pass the
section bounds check but truncate when passed to bitmap_zalloc(),
allocating a much smaller buffer than the subsequent read loop
expects.

Reject size values that exceed INT_MAX, and check that the data
needed (BITS_TO_U64(size) u64 values) fits in the remaining section
before allocating.  Switch from bitmap_zalloc() to calloc() of u64
units so the allocation size matches the u64 read/write granularity
and avoids unsigned long vs u64 mismatch on 32-bit architectures.

Fix do_write_bitmap() to use memcpy to read u64-sized chunks from
the unsigned long bitmap, preventing out-of-bounds reads on 32-bit
systems where sizeof(unsigned long) is 4 but the bitmap is stored
in u64 units.

Fix process_mem_topology() minimum section size: the check used
nr * 2 * sizeof(u64) per node, but do_read_bitmap() reads an
additional u64 for the bitmap size, so the minimum is 3 * sizeof(u64).

Fix memory leak in process_mem_topology() error paths: replace
free(nodes) with memory_node__delete_nodes() to free per-node
bitmaps allocated by do_read_bitmap().

Currently used by process_mem_topology() for HEADER_MEM_TOPOLOGY.

Fixes: a881fc56038a ("perf header: Sanity check HEADER_MEM_TOPOLOGY")
Closes: https://lore.kernel.org/linux-perf-users/20260414224622.2AE69C19425@smtp.kernel.org/
Closes: https://lore.kernel.org/linux-perf-users/20260410223242.DD76FC19421@smtp.kernel.org/
Reported-by: sashiko-bot@kernel.org # Running on a local machine
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6-1m
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/header.c | 34 +++++++++++++++++++++++++++++-----
 1 file changed, 29 insertions(+), 5 deletions(-)

diff --git a/tools/perf/util/header.c b/tools/perf/util/header.c
index 30e5e50ab98b8b..7b641a569af139 100644
--- a/tools/perf/util/header.c
+++ b/tools/perf/util/header.c
@@ -158,15 +158,25 @@ int do_write(struct feat_fd *ff, const void *buf, size_t size)
 /* Return: 0 if succeeded, -ERR if failed. */
 static int do_write_bitmap(struct feat_fd *ff, unsigned long *set, u64 size)
 {
-	u64 *p = (u64 *) set;
+	size_t byte_size = BITS_TO_LONGS(size) * sizeof(unsigned long);
 	int i, ret;
 
 	ret = do_write(ff, &size, sizeof(size));
 	if (ret < 0)
 		return ret;
 
+	/*
+	 * The on-disk format uses u64 elements, but the in-memory bitmap
+	 * uses unsigned long, which is only 4 bytes on 32-bit architectures.
+	 * Copy with bounded size so the last element doesn't read past the
+	 * bitmap allocation when BITS_TO_LONGS(size) is odd.
+	 */
 	for (i = 0; (u64) i < BITS_TO_U64(size); i++) {
-		ret = do_write(ff, p + i, sizeof(*p));
+		u64 val = 0;
+		size_t off = i * sizeof(val);
+
+		memcpy(&val, (char *)set + off, min(sizeof(val), byte_size - off));
+		ret = do_write(ff, &val, sizeof(val));
 		if (ret < 0)
 			return ret;
 	}
@@ -297,7 +307,20 @@ static int do_read_bitmap(struct feat_fd *ff, unsigned long **pset, u64 *psize)
 	if (ret)
 		return ret;
 
-	set = bitmap_zalloc(size);
+	/* Bitmap APIs use int for nbits; reject u64 values that truncate. */
+	if (size > INT_MAX ||
+	    BITS_TO_U64(size) > (ff->size - ff->offset) / sizeof(u64)) {
+		pr_debug("do_read_bitmap: size %" PRIu64 " exceeds section bounds\n", size);
+		return -1;
+	}
+
+	/*
+	 * bitmap_zalloc() allocates in unsigned long units, which are only
+	 * 4 bytes on 32-bit architectures. The read loop below casts the
+	 * buffer to u64 * and writes 8-byte elements, so allocate in u64
+	 * units to ensure the buffer is large enough.
+	 */
+	set = calloc(BITS_TO_U64(size), sizeof(u64));
 	if (!set)
 		return -ENOMEM;
 
@@ -3411,7 +3434,8 @@ static int process_mem_topology(struct feat_fd *ff,
 		return -1;
 	}
 
-	if (ff->size < 3 * sizeof(u64) + nr * 2 * sizeof(u64)) {
+	/* Per node: node_id(u64) + mem_size(u64) + bitmap_nr_bits(u64) */
+	if (ff->size < 3 * sizeof(u64) + nr * 3 * sizeof(u64)) {
 		pr_err("Invalid HEADER_MEM_TOPOLOGY: section too small (%zu) for %llu nodes\n",
 		       ff->size, (unsigned long long)nr);
 		return -1;
@@ -3446,7 +3470,7 @@ static int process_mem_topology(struct feat_fd *ff,
 
 out:
 	if (ret)
-		free(nodes);
+		memory_node__delete_nodes(nodes, nr);
 	return ret;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0906/2077] iio: light: si1133: reset counter to prevent race condition
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (904 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0905/2077] perf header: Validate bitmap size before allocating in do_read_bitmap() Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0907/2077] iio: light: si1133: prevent race condition on timeout Greg Kroah-Hartman
                   ` (91 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Joshua Crofts,
	Jonathan Cameron, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joshua Crofts <joshua.crofts1@gmail.com>

[ Upstream commit 0a5f45ed2342aabae1e32c72558d15be28940a95 ]

Sashiko reported a potential race condition happening when the driver
returns an errno after a timeout in the si1133_command() function. The
premature exit causes the hardware and software counters to become out
of sync by not updating data->rsp_seq, therefore the internal hardware
counter keeps incrementing.

Fix this by adding a call to si1133_cmd_reset_counter() before returning
from timeout.

Fixes: e01e7eaf37d8 ("iio: light: introduce si1133")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/message/20260428-si1133-checkup-v2-5-70ad14bfefe2%40gmail.com
Assisted-by: gemini:gemini-3.1-pro-preview
Signed-off-by: Joshua Crofts <joshua.crofts1@gmail.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iio/light/si1133.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/iio/light/si1133.c b/drivers/iio/light/si1133.c
index 44fa152dbd24c2..c88c79202be2e2 100644
--- a/drivers/iio/light/si1133.c
+++ b/drivers/iio/light/si1133.c
@@ -427,6 +427,11 @@ static int si1133_command(struct si1133_data *data, u8 cmd)
 			dev_warn(dev,
 				 "Failed to read command 0x%02x, ret=%d\n",
 				 cmd, err);
+			/*
+			 * Reset counter on err to prevent software and hardware
+			 * counters being out of sync.
+			 */
+			si1133_cmd_reset_counter(data);
 			goto out;
 		}
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0907/2077] iio: light: si1133: prevent race condition on timeout
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (905 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0906/2077] iio: light: si1133: reset counter to prevent race condition Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0908/2077] iio: magnetometer: ak8975: fix potential kernel stack memory leak Greg Kroah-Hartman
                   ` (90 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Joshua Crofts,
	Jonathan Cameron, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joshua Crofts <joshua.crofts1@gmail.com>

[ Upstream commit 8c50a95ceb230d17801758a9e41ffbbbe46f8b4d ]

Sashiko reported a bug where the si1133_command exits on timeout
without halting the sensor or masking the interrupt. If the sensor
completes the command later, any subsequent command to the sensor
will cause the IRQ handler to complete immediately, returning stale
data to the driver all while the command hasn't finished yet, shifting
all potential reads in the future.

Fix this by masking the IRQ if wait_for_completion_timeout() fails.
When initiating a new command, do a dummy read of the IRQ_STATUS
register and turn the IRQ back on.

Fixes: e01e7eaf37d8 ("iio: light: introduce si1133")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/message/20260428-si1133-checkup-v2-5-70ad14bfefe2%40gmail.com
Assisted-by: gemini:gemini-3.1-pro-preview
Signed-off-by: Joshua Crofts <joshua.crofts1@gmail.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iio/light/si1133.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/drivers/iio/light/si1133.c b/drivers/iio/light/si1133.c
index c88c79202be2e2..bf7bf0f1631d49 100644
--- a/drivers/iio/light/si1133.c
+++ b/drivers/iio/light/si1133.c
@@ -395,8 +395,14 @@ static int si1133_command(struct si1133_data *data, u8 cmd)
 
 	expected_seq = (data->rsp_seq + 1) & SI1133_MAX_CMD_CTR;
 
-	if (cmd == SI1133_CMD_FORCE)
+	if (cmd == SI1133_CMD_FORCE) {
+		/* Flush pending IRQs from a previous timeout. */
+		regmap_read(data->regmap, SI1133_REG_IRQ_STATUS, &resp);
+		regmap_write(data->regmap, SI1133_REG_IRQ_ENABLE,
+			     SI1133_IRQ_CHANNEL_ENABLE);
+
 		reinit_completion(&data->completion);
+	}
 
 	err = regmap_write(data->regmap, SI1133_REG_COMMAND, cmd);
 	if (err) {
@@ -409,6 +415,7 @@ static int si1133_command(struct si1133_data *data, u8 cmd)
 		/* wait for irq */
 		if (!wait_for_completion_timeout(&data->completion,
 			msecs_to_jiffies(SI1133_COMPLETION_TIMEOUT_MS))) {
+			regmap_write(data->regmap, SI1133_REG_IRQ_ENABLE, 0);
 			err = -ETIMEDOUT;
 			goto out;
 		}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0908/2077] iio: magnetometer: ak8975: fix potential kernel stack memory leak
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (906 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0907/2077] iio: light: si1133: prevent race condition on timeout Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0909/2077] iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling Greg Kroah-Hartman
                   ` (89 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Joshua Crofts,
	Jonathan Cameron, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joshua Crofts <joshua.crofts1@gmail.com>

[ Upstream commit a9a00d727b7bbc5e913a919530a9dd468935bf95 ]

Currently in the AK8975 driver there are four instances where potential
uninitialized kernel stack memory leaks can occur. If
i2c_smbus_read_i2c_block_data_or_emulated() returns a value less than
the size of the buffer, uninitialized bytes are retained in the buffer
and later the buffer is passed on to IIO buffers, potentially leaking
memory to userspace.

Fix this by adding checks whether the return value of the function is
equal to the size of the buffer and subsequently if the value is
lesser than zero to distinguish from a returned error code.

Fixes: bc11ca4a0b84 ("iio:magnetometer:ak8975: triggered buffer support")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260513-ak8975-fix-v1-1-104ea605dd54%40gmail.com
Signed-off-by: Joshua Crofts <joshua.crofts1@gmail.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iio/magnetometer/ak8975.c | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/drivers/iio/magnetometer/ak8975.c b/drivers/iio/magnetometer/ak8975.c
index b3468756bdf1e9..ddf6dcc6fbddae 100644
--- a/drivers/iio/magnetometer/ak8975.c
+++ b/drivers/iio/magnetometer/ak8975.c
@@ -495,6 +495,10 @@ static int ak8975_who_i_am(struct i2c_client *client,
 		dev_err(&client->dev, "Error reading WIA\n");
 		return ret;
 	}
+	if (ret != sizeof(wia_val)) {
+		dev_err(&client->dev, "Error reading WIA\n");
+		return -EIO;
+	}
 
 	if (wia_val[0] != AK8975_DEVICE_ID)
 		return -ENODEV;
@@ -619,6 +623,10 @@ static int ak8975_setup(struct i2c_client *client)
 		dev_err(&client->dev, "Not able to read asa data\n");
 		return ret;
 	}
+	if (ret != sizeof(data->asa)) {
+		dev_err(&client->dev, "Error reading asa data\n");
+		return -EIO;
+	}
 
 	/* After reading fuse ROM data set power-down mode */
 	ret = ak8975_set_mode(data, POWER_DOWN);
@@ -758,6 +766,10 @@ static int ak8975_read_axis(struct iio_dev *indio_dev, int index, int *val)
 			sizeof(rval), (u8*)&rval);
 	if (ret < 0)
 		goto exit;
+	if (ret != sizeof(rval)) {
+		ret = -EIO;
+		goto exit;
+	}
 
 	/* Read out ST2 for release lock on measurement data. */
 	ret = i2c_smbus_read_byte_data(client, data->def->ctrl_regs[ST2]);
@@ -874,6 +886,8 @@ static void ak8975_fill_buffer(struct iio_dev *indio_dev)
 							(u8 *)fval);
 	if (ret < 0)
 		goto unlock;
+	if (ret != sizeof(fval))
+		goto unlock;
 
 	mutex_unlock(&data->lock);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0909/2077] iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (907 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0908/2077] iio: magnetometer: ak8975: fix potential kernel stack memory leak Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0910/2077] iio: accel: mma8452: handle I2C read error(s) in mma8452_read() Greg Kroah-Hartman
                   ` (88 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guilherme Ivo Bozi, Salih Erim,
	Jonathan Cameron, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guilherme Ivo Bozi <guilherme.bozi@usp.br>

[ Upstream commit 947eb6f0a274f8b15a0248051a65b069effd5057 ]

ams_event_to_channel() may return a pointer past the end of
dev->channels when no matching scan_index is found. This can lead
to invalid memory access in ams_handle_event().

Add a bounds check in ams_event_to_channel() and return NULL when
no channel is found. Also guard the caller to safely handle this
case.

Fixes: d5c70627a794 ("iio: adc: Add Xilinx AMS driver")
Signed-off-by: Guilherme Ivo Bozi <guilherme.bozi@usp.br>
Reviewed-by: Salih Erim <salih.erim@amd.com>
Tested-by: Salih Erim <salih.erim@amd.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iio/adc/xilinx-ams.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/iio/adc/xilinx-ams.c b/drivers/iio/adc/xilinx-ams.c
index 124470c9252978..6191cd1b29a510 100644
--- a/drivers/iio/adc/xilinx-ams.c
+++ b/drivers/iio/adc/xilinx-ams.c
@@ -871,6 +871,9 @@ static const struct iio_chan_spec *ams_event_to_channel(struct iio_dev *dev,
 		if (dev->channels[i].scan_index == scan_index)
 			break;
 
+	if (i == dev->num_channels)
+		return NULL;
+
 	return &dev->channels[i];
 }
 
@@ -1012,6 +1015,8 @@ static void ams_handle_event(struct iio_dev *indio_dev, u32 event)
 	const struct iio_chan_spec *chan;
 
 	chan = ams_event_to_channel(indio_dev, event);
+	if (!chan)
+		return;
 
 	if (chan->type == IIO_TEMP) {
 		/*
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0910/2077] iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (908 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0909/2077] iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0911/2077] iio: tcs3472: power down chip on probe failure Greg Kroah-Hartman
                   ` (87 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sanjay Chitroda, Jonathan Cameron,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sanjay Chitroda <sanjayembeddedse@gmail.com>

[ Upstream commit 5bdff291d20c31b365d9ddfe9c426fbfb41da5bb ]

Currently, If i2c_smbus_read_i2c_block_data() fails but
mma8452_set_runtime_pm_state() succeeds, mma8452_read() returns 0.

As a result, the caller mma8452_read_raw() assumes the read was
successful and proceeds to use a buffer containing uninitialized
stack memory.

Add proper checking of the I2C read return value and propagate errors
to the caller.

Fixes: 96c0cb2bbfe0 ("iio: mma8452: add support for runtime power management")
Signed-off-by: Sanjay Chitroda <sanjayembeddedse@gmail.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iio/accel/mma8452.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/iio/accel/mma8452.c b/drivers/iio/accel/mma8452.c
index 15172ba2972c59..cefc7cf4bd8353 100644
--- a/drivers/iio/accel/mma8452.c
+++ b/drivers/iio/accel/mma8452.c
@@ -252,6 +252,8 @@ static int mma8452_read(struct mma8452_data *data, __be16 buf[3])
 
 	ret = i2c_smbus_read_i2c_block_data(data->client, MMA8452_OUT_X,
 					    3 * sizeof(__be16), (u8 *)buf);
+	if (ret < 0)
+		return ret;
 
 	ret = mma8452_set_runtime_pm_state(data->client, false);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0911/2077] iio: tcs3472: power down chip on probe failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (909 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0910/2077] iio: accel: mma8452: handle I2C read error(s) in mma8452_read() Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0912/2077] clk: at91: keep securam node alive while mapping it Greg Kroah-Hartman
                   ` (86 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Aldo Conte, Jonathan Cameron,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aldo Conte <aldocontelk@gmail.com>

[ Upstream commit b39f3bb9f5580d19bc0c10dea9224d75fed45f1d ]

If tcs3472_probe() fails after enabling the chip (by writing PON | AEN
to the ENABLE register), the error paths return without powering down
the device.

Add an 'error_powerdown' label at the end of the cleanup chain that
calls tcs3472_powerdown() to power down the chip. The existing label
cascade is rerouted to fall through to the new label.

Move tcs3472_powerdown() above tcs3472_probe() so the probe can call
it without a forward declaration.

Found by code inspection while reviewing the probe error paths in
preparation for the devm_ conversion.

Fixes: eb869ade30a6 ("iio: Add tcs3472 color light sensor driver")
Signed-off-by: Aldo Conte <aldocontelk@gmail.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/iio/light/tcs3472.c | 38 +++++++++++++++++++------------------
 1 file changed, 20 insertions(+), 18 deletions(-)

diff --git a/drivers/iio/light/tcs3472.c b/drivers/iio/light/tcs3472.c
index 12429a3261b38e..849ca7885d7193 100644
--- a/drivers/iio/light/tcs3472.c
+++ b/drivers/iio/light/tcs3472.c
@@ -440,6 +440,23 @@ static const struct iio_info tcs3472_info = {
 	.attrs = &tcs3472_attribute_group,
 };
 
+static int tcs3472_powerdown(struct tcs3472_data *data)
+{
+	int ret;
+	u8 enable_mask = TCS3472_ENABLE_AEN | TCS3472_ENABLE_PON;
+
+	mutex_lock(&data->lock);
+
+	ret = i2c_smbus_write_byte_data(data->client, TCS3472_ENABLE,
+					data->enable & ~enable_mask);
+	if (!ret)
+		data->enable &= ~enable_mask;
+
+	mutex_unlock(&data->lock);
+
+	return ret;
+}
+
 static int tcs3472_probe(struct i2c_client *client)
 {
 	struct tcs3472_data *data;
@@ -513,7 +530,7 @@ static int tcs3472_probe(struct i2c_client *client)
 	ret = iio_triggered_buffer_setup(indio_dev, NULL,
 		tcs3472_trigger_handler, NULL);
 	if (ret < 0)
-		return ret;
+		goto error_powerdown;
 
 	if (client->irq) {
 		ret = request_threaded_irq(client->irq, NULL,
@@ -536,23 +553,8 @@ static int tcs3472_probe(struct i2c_client *client)
 		free_irq(client->irq, indio_dev);
 buffer_cleanup:
 	iio_triggered_buffer_cleanup(indio_dev);
-	return ret;
-}
-
-static int tcs3472_powerdown(struct tcs3472_data *data)
-{
-	int ret;
-	u8 enable_mask = TCS3472_ENABLE_AEN | TCS3472_ENABLE_PON;
-
-	mutex_lock(&data->lock);
-
-	ret = i2c_smbus_write_byte_data(data->client, TCS3472_ENABLE,
-		data->enable & ~enable_mask);
-	if (!ret)
-		data->enable &= ~enable_mask;
-
-	mutex_unlock(&data->lock);
-
+error_powerdown:
+	tcs3472_powerdown(data);
 	return ret;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0912/2077] clk: at91: keep securam node alive while mapping it
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (910 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0911/2077] iio: tcs3472: power down chip on probe failure Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0913/2077] HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter Greg Kroah-Hartman
                   ` (85 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuho Choi, Alexandre Belloni,
	Claudiu Beznea, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yuho Choi <dbgh9129@gmail.com>

[ Upstream commit 22fa1c39ba6fe726b547c877c924379b7fee260a ]

pmc_register_ops() gets an owned reference to the
"atmel,sama5d2-securam" node with of_find_compatible_node().  The
success path dropped that reference before passing the node to
of_iomap(), leaving of_iomap() to consume a node pointer after the caller
had released its reference.

Move of_node_put() after of_iomap() so the node remains referenced for
the mapping operation.  The unavailable-node error path already releases
the reference.

Fixes: 4d21be864092 ("clk: at91: pmc: execute suspend/resume only for backup mode")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Reviewed-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Link: https://patch.msgid.link/20260529042051.1626978-1-dbgh9129@gmail.com
Signed-off-by: Claudiu Beznea <claudiu.beznea@tuxon.dev>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clk/at91/pmc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/clk/at91/pmc.c b/drivers/clk/at91/pmc.c
index b618a5e00b0068..03a6c31d6aa8b5 100644
--- a/drivers/clk/at91/pmc.c
+++ b/drivers/clk/at91/pmc.c
@@ -180,9 +180,9 @@ static int __init pmc_register_ops(void)
 		of_node_put(np);
 		return -ENODEV;
 	}
-	of_node_put(np);
 
 	at91_pmc_backup_suspend = of_iomap(np, 0);
+	of_node_put(np);
 	if (!at91_pmc_backup_suspend) {
 		pr_warn("%s(): unable to map securam\n", __func__);
 		return -ENOMEM;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0913/2077] HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (911 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0912/2077] clk: at91: keep securam node alive while mapping it Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0914/2077] docs: changes.rst: restore pahole 1.26 minimum (regressed by sort) Greg Kroah-Hartman
                   ` (84 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rosen Penev, Benjamin Tissoires,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rosen Penev <rosenp@gmail.com>

[ Upstream commit f22a5db8a7d38152556f230d6d68e59dbc27971b ]

The @dev member described in the kernel-doc does not exist in the
struct. Remove the stale entry.

Fixes: 0610430e3dea ("HID: logitech-hidpp: add input_device ptr to struct hidpp_device")
Assisted-by: opencode:big-pickle

Signed-off-by: Rosen Penev <rosenp@gmail.com>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hid/hid-logitech-hidpp.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/hid/hid-logitech-hidpp.c b/drivers/hid/hid-logitech-hidpp.c
index ccbf28869a968d..1990ba5b26ea67 100644
--- a/drivers/hid/hid-logitech-hidpp.c
+++ b/drivers/hid/hid-logitech-hidpp.c
@@ -164,7 +164,6 @@ struct hidpp_battery {
 /**
  * struct hidpp_scroll_counter - Utility class for processing high-resolution
  *                             scroll events.
- * @dev: the input device for which events should be reported.
  * @wheel_multiplier: the scalar multiplier to be applied to each wheel event
  * @remainder: counts the number of high-resolution units moved since the last
  *             low-resolution event (REL_WHEEL or REL_HWHEEL) was sent. Should
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0914/2077] docs: changes.rst: restore pahole 1.26 minimum (regressed by sort)
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (912 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0913/2077] HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0915/2077] clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock Greg Kroah-Hartman
                   ` (83 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhan Xusheng, Jonathan Corbet,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhan Xusheng <zhanxusheng1024@gmail.com>

[ Upstream commit 2c1ccd9a1d786503086e83fe83e5c3b3c953b70e ]

Commit 9edd04c4189e ("docs: Raise minimum pahole version to 1.26 for
KF_IMPLICIT_ARGS kfuncs") raised the minimum required pahole version
from 1.22 to 1.26 in the requirements table and added a paragraph
explaining the failure mode for distributions still shipping pahole
v1.25 (e.g. Ubuntu 24.04 LTS).

The next day, commit ece7e57afd51 ("docs: changes.rst and ver_linux:
sort the lists") came through a different tree (docs vs sched_ext) and
re-flowed the table alphabetically, but its base did not include
9edd04c4189e.  When the two commits met in mainline, the textual rewrite
of the table won and the version bump was lost.  The added "Since Linux
7.0..." paragraph also disappeared.

The result is that changes.rst on master (v7.1-rc5) lists pahole 1.22
again, even though sched_ext kfuncs annotated with KF_IMPLICIT_ARGS
genuinely require v1.26 to produce a correct vmlinux BTF.  Users on
distributions with pahole v1.25 hit "func_proto incompatible with
vmlinux" when loading any sched_ext BPF program (scx_simple,
scx_qmap, ...) and have no documentation pointing them at the version
gap.

Restore both changes from 9edd04c4189e.

Fixes: ece7e57afd51 ("docs: changes.rst and ver_linux: sort the lists")
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Signed-off-by: Jonathan Corbet <corbet@lwn.net>
Message-ID: <20260526022033.1301884-1-zhanxusheng@xiaomi.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/process/changes.rst | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/Documentation/process/changes.rst b/Documentation/process/changes.rst
index 9a99037270ff27..a4db8f7b3afb7d 100644
--- a/Documentation/process/changes.rst
+++ b/Documentation/process/changes.rst
@@ -53,7 +53,7 @@ mcelog                 0.6              mcelog --version
 mkimage (optional)     2017.01          mkimage --version
 nfs-utils              1.0.5            showmount --version
 openssl & libcrypto    1.0.0            openssl version
-pahole                 1.22             pahole --version
+pahole                 1.26             pahole --version
 pcmciautils            004              pccardctl -V
 PPP                    2.4.0            pppd --version
 procps                 3.2.0            ps --version
@@ -147,6 +147,11 @@ Since Linux 5.2, if CONFIG_DEBUG_INFO_BTF is selected, the build system
 generates BTF (BPF Type Format) from DWARF in vmlinux, a bit later from kernel
 modules as well.  This requires pahole v1.22 or later.
 
+Since Linux 7.0, kfuncs annotated with KF_IMPLICIT_ARGS require pahole v1.26
+or later.  Without it, such kfuncs will have incorrect BTF prototypes in
+vmlinux, causing BPF programs to fail to load with a "func_proto incompatible
+with vmlinux" error.  Many sched_ext kfuncs are affected.
+
 It is found in the 'dwarves' or 'pahole' distro packages or from
 https://fedorapeople.org/~acme/dwarves/.
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0915/2077] clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (913 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0914/2077] docs: changes.rst: restore pahole 1.26 minimum (regressed by sort) Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0916/2077] clk: spacemit: k3: Fix PCIe clock register offset Greg Kroah-Hartman
                   ` (82 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yixun Lan, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yixun Lan <dlan@kernel.org>

[ Upstream commit d8a4cef90b1a4ae9196a5bfba683eb9a0c75acdc ]

According to SpacemiT updated docs, the PCIe master and slave clock's
parent is the pll2_d6 clock, so fix it.

Fixes: e371a77255b8 ("clk: spacemit: k3: add the clock tree")
Link: https://patch.msgid.link/20260511-06-pci-clk-fix-v2-1-c9a5e563bab3@kernel.org
Signed-off-by: Yixun Lan <dlan@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clk/spacemit/ccu-k3.c | 20 ++++++++++----------
 1 file changed, 10 insertions(+), 10 deletions(-)

diff --git a/drivers/clk/spacemit/ccu-k3.c b/drivers/clk/spacemit/ccu-k3.c
index bb8b75bdbdb30d..1a53b14739fed0 100644
--- a/drivers/clk/spacemit/ccu-k3.c
+++ b/drivers/clk/spacemit/ccu-k3.c
@@ -947,16 +947,16 @@ static const struct clk_parent_data edp1_pclk_parents[] = {
 };
 CCU_MUX_GATE_DEFINE(edp1_pxclk, edp1_pclk_parents, APMU_LCD_EDP_CTRL, 18, 1, BIT(17), 0);
 
-CCU_GATE_DEFINE(pciea_mstr_clk, CCU_PARENT_HW(axi_clk), APMU_PCIE_CLK_RES_CTRL_A, BIT(2), 0);
-CCU_GATE_DEFINE(pciea_slv_clk, CCU_PARENT_HW(axi_clk), APMU_PCIE_CLK_RES_CTRL_A, BIT(1), 0);
-CCU_GATE_DEFINE(pcieb_mstr_clk, CCU_PARENT_HW(axi_clk), APMU_PCIE_CLK_RES_CTRL_B, BIT(2), 0);
-CCU_GATE_DEFINE(pcieb_slv_clk, CCU_PARENT_HW(axi_clk), APMU_PCIE_CLK_RES_CTRL_B, BIT(1), 0);
-CCU_GATE_DEFINE(pciec_mstr_clk, CCU_PARENT_HW(axi_clk), APMU_PCIE_CLK_RES_CTRL_C, BIT(2), 0);
-CCU_GATE_DEFINE(pciec_slv_clk, CCU_PARENT_HW(axi_clk), APMU_PCIE_CLK_RES_CTRL_C, BIT(1), 0);
-CCU_GATE_DEFINE(pcied_mstr_clk, CCU_PARENT_HW(axi_clk), APMU_PCIE_CLK_RES_CTRL_D, BIT(2), 0);
-CCU_GATE_DEFINE(pcied_slv_clk, CCU_PARENT_HW(axi_clk), APMU_PCIE_CLK_RES_CTRL_D, BIT(1), 0);
-CCU_GATE_DEFINE(pciee_mstr_clk, CCU_PARENT_HW(axi_clk), APMU_PCIE_CLK_RES_CTRL_E, BIT(2), 0);
-CCU_GATE_DEFINE(pciee_slv_clk, CCU_PARENT_HW(axi_clk), APMU_PCIE_CLK_RES_CTRL_E, BIT(1), 0);
+CCU_GATE_DEFINE(pciea_mstr_clk, CCU_PARENT_HW(pll2_d6), APMU_PCIE_CLK_RES_CTRL_A, BIT(2), 0);
+CCU_GATE_DEFINE(pciea_slv_clk, CCU_PARENT_HW(pll2_d6), APMU_PCIE_CLK_RES_CTRL_A, BIT(1), 0);
+CCU_GATE_DEFINE(pcieb_mstr_clk, CCU_PARENT_HW(pll2_d6), APMU_PCIE_CLK_RES_CTRL_B, BIT(2), 0);
+CCU_GATE_DEFINE(pcieb_slv_clk, CCU_PARENT_HW(pll2_d6), APMU_PCIE_CLK_RES_CTRL_B, BIT(1), 0);
+CCU_GATE_DEFINE(pciec_mstr_clk, CCU_PARENT_HW(pll2_d6), APMU_PCIE_CLK_RES_CTRL_C, BIT(2), 0);
+CCU_GATE_DEFINE(pciec_slv_clk, CCU_PARENT_HW(pll2_d6), APMU_PCIE_CLK_RES_CTRL_C, BIT(1), 0);
+CCU_GATE_DEFINE(pcied_mstr_clk, CCU_PARENT_HW(pll2_d6), APMU_PCIE_CLK_RES_CTRL_D, BIT(2), 0);
+CCU_GATE_DEFINE(pcied_slv_clk, CCU_PARENT_HW(pll2_d6), APMU_PCIE_CLK_RES_CTRL_D, BIT(1), 0);
+CCU_GATE_DEFINE(pciee_mstr_clk, CCU_PARENT_HW(pll2_d6), APMU_PCIE_CLK_RES_CTRL_E, BIT(2), 0);
+CCU_GATE_DEFINE(pciee_slv_clk, CCU_PARENT_HW(pll2_d6), APMU_PCIE_CLK_RES_CTRL_E, BIT(1), 0);
 
 static const struct clk_parent_data emac_1588_parents[] = {
 	CCU_PARENT_NAME(vctcxo_24m),
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0916/2077] clk: spacemit: k3: Fix PCIe clock register offset
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (914 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0915/2077] clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0917/2077] fs/ntfs3: add bounds check to run_get_highest_vcn() Greg Kroah-Hartman
                   ` (81 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Conor Dooley, Yixun Lan, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yixun Lan <dlan@kernel.org>

[ Upstream commit 2f20c859a82a291483a8b3f01cbfbb1642782a14 ]

The offset of PCIe Clock CTRL register for port B and C controller was
wrongly swapped, correct it here.

Fixes: 091d19cc2401 ("clk: spacemit: k3: extract common header")
Acked-by: Conor Dooley <conor.dooley@microchip.com>
Link: https://patch.msgid.link/20260511-06-pci-clk-fix-v2-2-c9a5e563bab3@kernel.org
Signed-off-by: Yixun Lan <dlan@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/soc/spacemit/k3-syscon.h | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/include/soc/spacemit/k3-syscon.h b/include/soc/spacemit/k3-syscon.h
index 0299bea065a05d..a68255dd641f31 100644
--- a/include/soc/spacemit/k3-syscon.h
+++ b/include/soc/spacemit/k3-syscon.h
@@ -168,8 +168,8 @@
 #define APMU_CPU_C2_CLK_CTRL		0x394
 #define APMU_CPU_C3_CLK_CTRL		0x208
 #define APMU_PCIE_CLK_RES_CTRL_A	0x1f0
-#define APMU_PCIE_CLK_RES_CTRL_B	0x1c8
-#define APMU_PCIE_CLK_RES_CTRL_C	0x1d0
+#define APMU_PCIE_CLK_RES_CTRL_B	0x1d0
+#define APMU_PCIE_CLK_RES_CTRL_C	0x1c8
 #define APMU_PCIE_CLK_RES_CTRL_D	0x1e0
 #define APMU_PCIE_CLK_RES_CTRL_E	0x1e8
 #define APMU_EMAC0_CLK_RES_CTRL		0x3e4
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0917/2077] fs/ntfs3: add bounds check to run_get_highest_vcn()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (915 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0916/2077] clk: spacemit: k3: Fix PCIe clock register offset Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0918/2077] fs/ntfs3: fix wrong LCN in run_remove_range() when splitting a run Greg Kroah-Hartman
                   ` (80 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jaeyeong Lee, Konstantin Komarov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>

[ Upstream commit bb11485a87fbb2254b62cfed630b699d50e57da8 ]

run_get_highest_vcn() parses a packed NTFS mapping-pairs buffer without
any length bound, relying solely on a 0x00 terminator to stop.  A
crafted $LogFile UpdateMappingPairs record whose embedded attribute
contains mapping-pairs runs without a terminator causes the function to
read past the slab allocation, triggering a KASAN slab-out-of-bounds
read on mount.

The sibling function run_unpack() received an analogous bounds-check in
commit b62567bca474 ("ntfs3: add buffer boundary checks to run_unpack()"),
but run_get_highest_vcn() was missed.

Take a run_buf_size parameter and reject any run header whose payload
would extend past the buffer end, mirroring the pattern used by
run_unpack().  The caller in fslog.c passes the remaining attribute
bytes after the mapping-pairs offset.

KASAN report (on mainline v7.1 merge window HEAD):

  BUG: KASAN: slab-out-of-bounds in run_get_highest_vcn+0x3c0/0x410
  Read of size 1 at addr ffff88800e2d5400 by task mount/72
  Call Trace:
   run_get_highest_vcn+0x3c0/0x410
   do_action.isra.0+0x3ba8/0x7b50
   log_replay+0x9ddd/0x10200
   ntfs_loadlog_and_replay+0x4ad/0x610
   ntfs_fill_super+0x214a/0x4540

Fixes: b62567bca474 ("ntfs3: add buffer boundary checks to run_unpack()")
Signed-off-by: Jaeyeong Lee <lee@jaeyeong.cc>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs3/fslog.c   | 5 ++++-
 fs/ntfs3/ntfs_fs.h | 3 ++-
 fs/ntfs3/run.c     | 9 +++++++--
 3 files changed, 13 insertions(+), 4 deletions(-)

diff --git a/fs/ntfs3/fslog.c b/fs/ntfs3/fslog.c
index ca78cfe2b37f89..0504e5e8a5087a 100644
--- a/fs/ntfs3/fslog.c
+++ b/fs/ntfs3/fslog.c
@@ -3368,7 +3368,10 @@ static int do_action(struct ntfs_log *log, struct OPEN_ATTR_ENRTY *oe,
 		memmove(Add2Ptr(attr, aoff), data, dlen);
 
 		if (run_get_highest_vcn(le64_to_cpu(attr->nres.svcn),
-					attr_run(attr), &t64)) {
+					attr_run(attr),
+				        le32_to_cpu(attr->size) - 
+				                le16_to_cpu(attr->nres.run_off),	
+					&t64)) {
 			goto dirty_vol;
 		}
 
diff --git a/fs/ntfs3/ntfs_fs.h b/fs/ntfs3/ntfs_fs.h
index bbf3b6a1dcbee4..d53febc2559c03 100644
--- a/fs/ntfs3/ntfs_fs.h
+++ b/fs/ntfs3/ntfs_fs.h
@@ -877,7 +877,8 @@ int run_unpack_ex(struct runs_tree *run, struct ntfs_sb_info *sbi, CLST ino,
 #else
 #define run_unpack_ex run_unpack
 #endif
-int run_get_highest_vcn(CLST vcn, const u8 *run_buf, u64 *highest_vcn);
+int run_get_highest_vcn(CLST vcn, const u8 *run_buf, size_t run_buf_size, 
+		       u64 *highest_vcn);
 int run_clone(const struct runs_tree *run, struct runs_tree *new_run);
 bool run_remove_range(struct runs_tree *run, CLST vcn, CLST len, CLST *done);
 CLST run_len(const struct runs_tree *run);
diff --git a/fs/ntfs3/run.c b/fs/ntfs3/run.c
index 1ce7d92fb27482..19aa044fd1fcc9 100644
--- a/fs/ntfs3/run.c
+++ b/fs/ntfs3/run.c
@@ -1205,18 +1205,23 @@ int run_unpack_ex(struct runs_tree *run, struct ntfs_sb_info *sbi, CLST ino,
  * Return the highest vcn from a mapping pairs array
  * it used while replaying log file.
  */
-int run_get_highest_vcn(CLST vcn, const u8 *run_buf, u64 *highest_vcn)
+int run_get_highest_vcn(CLST vcn, const u8 *run_buf, size_t run_buf_size, 
+		       u64 *highest_vcn)
 {
+	const u8 *run_last = run_buf + run_buf_size;
 	u64 vcn64 = vcn;
 	u8 size_size;
 
-	while ((size_size = *run_buf & 0xF)) {
+	while (run_buf < run_last && (size_size = *run_buf & 0xF)) {
 		u8 offset_size = *run_buf++ >> 4;
 		u64 len;
 
 		if (size_size > 8 || offset_size > 8)
 			return -EINVAL;
 
+		if (run_buf + size_size + offset_size > run_last) 
+			return -EINVAL;
+
 		len = run_unpack_s64(run_buf, size_size, 0);
 		if (!len)
 			return -EINVAL;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0918/2077] fs/ntfs3: fix wrong LCN in run_remove_range() when splitting a run
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (916 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0917/2077] fs/ntfs3: add bounds check to run_get_highest_vcn() Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0919/2077] fs/ntfs3: call _ntfs_bad_inode() when failing to rename Greg Kroah-Hartman
                   ` (79 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Zhan Xusheng, Konstantin Komarov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhan Xusheng <zhanxusheng1024@gmail.com>

[ Upstream commit 36c7276816ed4266c155b71b1fa747b2785f23f7 ]

When run_remove_range() removes a middle portion of a non-sparse run,
it splits the run into head and tail parts.  The tail is inserted via
run_add_entry() but uses the original r->lcn as its starting LCN
instead of advancing it by the split offset.

For example, removing VCN range [10, 20) from a run
{vcn=0, lcn=100, len=30} should produce:
  {vcn=0,  lcn=100, len=10}   (head)
  {vcn=20, lcn=120, len=10}   (tail, lcn advanced by 20)

But the current code produces:
  {vcn=0,  lcn=100, len=10}
  {vcn=20, lcn=100, len=10}   (wrong: points to same physical clusters)

This creates overlapping physical mappings in the in-memory run tree,
which can corrupt cluster allocation decisions and lead to data
corruption.

The correct pattern is already used in run_insert_range():
  CLST lcn2 = r->lcn == SPARSE_LCN ? SPARSE_LCN : (r->lcn + len1);

Apply the same logic in run_remove_range().

Fixes: 10d7c95af043 ("fs/ntfs3: add delayed-allocation (delalloc) support")
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs3/run.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/fs/ntfs3/run.c b/fs/ntfs3/run.c
index 19aa044fd1fcc9..ad7db67514ef7c 100644
--- a/fs/ntfs3/run.c
+++ b/fs/ntfs3/run.c
@@ -1297,9 +1297,12 @@ bool run_remove_range(struct runs_tree *run, CLST vcn, CLST len, CLST *done)
 
 		if (r_end > end) {
 			/* Remove a middle part, split. */
+			CLST tail_lcn = r->lcn == SPARSE_LCN ?
+					SPARSE_LCN : (r->lcn + (end - r->vcn));
+
 			*done += len;
 			r->len = d;
-			return run_add_entry(run, end, r->lcn, r_end - end,
+			return run_add_entry(run, end, tail_lcn, r_end - end,
 					     false);
 		}
 		/* Remove tail of run .*/
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0919/2077] fs/ntfs3: call _ntfs_bad_inode() when failing to rename
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (917 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0918/2077] fs/ntfs3: fix wrong LCN in run_remove_range() when splitting a run Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0920/2077] ntfs3: Allocate iomap inline_data using alloc_page Greg Kroah-Hartman
                   ` (78 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+4d8e30dbafb5c1260479,
	Helen Koike, Konstantin Komarov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Helen Koike <koike@igalia.com>

[ Upstream commit e8ed78f40eecd0176fda71d673f6957c98e7ffbe ]

It is safe to call _ntfs_bad_inode on live inodes since:
  commit 519b078998ce ("fs/ntfs3: Exclude call make_bad_inode for live nodes.")

The WARN_ON was added when it wasn't safe by:
  commit d99208b91933 ("fs/ntfs3: cancle set bad inode after removing name fails")

Replace the WARN_ON with a call to _ntfs_bad_inode() to prevent further
operations on the inconsistent inode.

Reported-by: syzbot+4d8e30dbafb5c1260479@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=4d8e30dbafb5c1260479
Fixes: 519b078998ce ("fs/ntfs3: Exclude call make_bad_inode for live nodes.")
Signed-off-by: Helen Koike <koike@igalia.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs3/frecord.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/ntfs3/frecord.c b/fs/ntfs3/frecord.c
index 7b035da63c1219..78eb065c7e431b 100644
--- a/fs/ntfs3/frecord.c
+++ b/fs/ntfs3/frecord.c
@@ -2800,8 +2800,8 @@ int ni_rename(struct ntfs_inode *dir_ni, struct ntfs_inode *new_dir_ni,
 	err = ni_add_name(new_dir_ni, ni, new_de);
 	if (!err) {
 		err = ni_remove_name(dir_ni, ni, de, &de2, &undo);
-		WARN_ON(err &&
-			ni_remove_name(new_dir_ni, ni, new_de, &de2, &undo));
+		if (err && ni_remove_name(new_dir_ni, ni, new_de, &de2, &undo))
+			_ntfs_bad_inode(&ni->vfs_inode);
 	}
 
 	/*
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0920/2077] ntfs3: Allocate iomap inline_data using alloc_page
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (918 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0919/2077] fs/ntfs3: call _ntfs_bad_inode() when failing to rename Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0921/2077] ntfs3: avoid another -Wmaybe-uninitialized warning Greg Kroah-Hartman
                   ` (77 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mihai Brodschi, Konstantin Komarov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mihai Brodschi <m.brodschi@gmail.com>

[ Upstream commit 70d3855594cf6e8791970714b65cac3202d6160e ]

This fixes a BUG reported in iomap_write_end_inline:
iomap_inline_data_valid checks that the inline_data fits within
a page. If the inline_data is allocated with kmemdup there's no
guarantee that it's page-aligned, so the check sometimes fails.
Allocate it with alloc_page to ensure it's page-aligned.

Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221446
Fixes: 099ef9ab9203 ("fs/ntfs3: implement iomap-based file operations")
Signed-off-by: Mihai Brodschi <m.brodschi@gmail.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs3/attrib.c | 10 +++++++---
 fs/ntfs3/inode.c  |  4 ++--
 2 files changed, 9 insertions(+), 5 deletions(-)

diff --git a/fs/ntfs3/attrib.c b/fs/ntfs3/attrib.c
index e61c5bf7e27e44..ff0bf45759480b 100644
--- a/fs/ntfs3/attrib.c
+++ b/fs/ntfs3/attrib.c
@@ -1004,6 +1004,7 @@ int attr_data_get_block_locked(struct ntfs_inode *ni, CLST vcn, CLST clen,
 	struct ATTRIB *attr, *attr_b;
 	struct ATTR_LIST_ENTRY *le, *le_b;
 	struct mft_inode *mi, *mi_b;
+	struct page *page;
 	CLST hint, svcn, to_alloc, evcn1, next_svcn, asize, end, vcn0;
 	CLST alloc, evcn;
 	unsigned fr;
@@ -1042,10 +1043,13 @@ int attr_data_get_block_locked(struct ntfs_inode *ni, CLST vcn, CLST clen,
 		*lcn = RESIDENT_LCN;
 		*len = data_size;
 		if (res && data_size) {
-			*res = kmemdup(resident_data(attr_b), data_size,
-				       GFP_KERNEL);
-			if (!*res)
+			page = alloc_page(GFP_KERNEL);
+			if (!page) {
 				err = -ENOMEM;
+			} else {
+				*res = page_address(page);
+				memcpy(*res, resident_data(attr_b), data_size);
+			}
 		}
 		goto out;
 	}
diff --git a/fs/ntfs3/inode.c b/fs/ntfs3/inode.c
index 42af1abe17f883..031f85fd53d4e8 100644
--- a/fs/ntfs3/inode.c
+++ b/fs/ntfs3/inode.c
@@ -801,7 +801,7 @@ static int ntfs_iomap_begin(struct inode *inode, loff_t offset, loff_t length,
 
 	if (lcn == RESIDENT_LCN) {
 		if (offset >= clen) {
-			kfree(res);
+			__free_page(virt_to_page(res));
 			if (flags & IOMAP_REPORT) {
 				/* special code for report. */
 				return -ENOENT;
@@ -921,7 +921,7 @@ static int ntfs_iomap_end(struct inode *inode, loff_t pos, loff_t length,
 
 out:
 	if (iomap->type == IOMAP_INLINE) {
-		kfree(iomap->private);
+		__free_page(virt_to_page(iomap->private));
 		iomap->private = NULL;
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0921/2077] ntfs3: avoid another -Wmaybe-uninitialized warning
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (919 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0920/2077] ntfs3: Allocate iomap inline_data using alloc_page Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0922/2077] fs/ntfs3: fix mount failure on 64K page-size kernels Greg Kroah-Hartman
                   ` (76 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Konstantin Komarov,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnd Bergmann <arnd@arndb.de>

[ Upstream commit 1bf15dd17385e3730521d17e9e158c475cd7474b ]

The ntfs3 specific -Wmaybe-uninitialized flag found one more false-postive,
this time with gcc-10 on s390:

fs/ntfs3/frecord.c: In function 'ni_expand_list':
fs/ntfs3/frecord.c:1370:16: error: 'ins_attr' may be used uninitialized in this function [-Werror=maybe-uninitialized]

Add an explicit NULL pointer check before using the pointer, and
initialize it to NULL.

Fixes: 48d9b57b169f ("fs/ntfs3: add a subset of W=1 warnings for stricter checks")
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs3/frecord.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/ntfs3/frecord.c b/fs/ntfs3/frecord.c
index 78eb065c7e431b..bb3348f256d997 100644
--- a/fs/ntfs3/frecord.c
+++ b/fs/ntfs3/frecord.c
@@ -1330,7 +1330,7 @@ int ni_expand_list(struct ntfs_inode *ni)
 {
 	int err = 0;
 	u32 asize, done = 0;
-	struct ATTRIB *attr, *ins_attr;
+	struct ATTRIB *attr, *ins_attr = NULL;
 	struct ATTR_LIST_ENTRY *le;
 	bool is_mft = ni->mi.rno == MFT_REC_MFT;
 	struct MFT_REF ref;
@@ -1363,7 +1363,7 @@ int ni_expand_list(struct ntfs_inode *ni)
 				      le16_to_cpu(attr->name_off), true,
 				      &ins_attr, NULL, NULL);
 
-		if (err)
+		if (err || !ins_attr)
 			goto out;
 
 		memcpy(ins_attr, attr, asize);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0922/2077] fs/ntfs3: fix mount failure on 64K page-size kernels
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (920 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0921/2077] ntfs3: avoid another -Wmaybe-uninitialized warning Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0923/2077] drm/amd/display: Add missing kdoc for ALLM parameters Greg Kroah-Hartman
                   ` (75 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Matthew R. Ochs, Jamie Nguyen,
	Konstantin Komarov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jamie Nguyen <jamien@nvidia.com>

[ Upstream commit b7a9125cac8645245d2473c6c0a50e338280ad23 ]

On 64K page-size kernels, mounting NTFS volumes smaller than ~650 MB
fails with EINVAL. The issue is in log_replay(): the initial log page
size probe uses PAGE_SIZE (65536) instead of DefaultLogPageSize (4096)
when PAGE_SIZE exceeds DefaultLogPageSize * 2.

This makes norm_file_page() require the $LogFile to be at least
50 * 65536 = 3.2 MB, but mkfs.ntfs creates a $LogFile of only ~1.5 MB
for a typical 300 MB volume. norm_file_page() returns 0 and the mount
is rejected with EINVAL.

On 4K kernels the #if guard evaluates to true, so use_default=true is
passed and DefaultLogPageSize (4096) is used, requiring only ~200 KB.
This path works fine.

Fix this by always passing use_default=true, which forces the initial
probe to use DefaultLogPageSize regardless of the kernel's PAGE_SIZE.
This is safe because, after reading the on-disk restart area, log_replay()
already re-adjusts log->page_size to match the volume's actual
sys_page_size.

Also fix read_log_page() to pass log->page_size instead of PAGE_SIZE to
ntfs_fix_post_read(), matching the actual buffer size.

Fixes: b46acd6a6a62 ("fs/ntfs3: Add NTFS journal")
Tested-by: Matthew R. Ochs <mochs@nvidia.com>
Signed-off-by: Jamie Nguyen <jamien@nvidia.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs3/fslog.c | 6 +-----
 1 file changed, 1 insertion(+), 5 deletions(-)

diff --git a/fs/ntfs3/fslog.c b/fs/ntfs3/fslog.c
index 0504e5e8a5087a..3c320e7a4c12fb 100644
--- a/fs/ntfs3/fslog.c
+++ b/fs/ntfs3/fslog.c
@@ -1172,7 +1172,7 @@ static int read_log_page(struct ntfs_log *log, u32 vbo,
 		goto out;
 
 	if (page_buf->rhdr.sign != NTFS_FFFF_SIGNATURE)
-		ntfs_fix_post_read(&page_buf->rhdr, PAGE_SIZE, false);
+		ntfs_fix_post_read(&page_buf->rhdr, log->page_size, false);
 
 	if (page_buf != *buffer)
 		memcpy(*buffer, Add2Ptr(page_buf, page_off), bytes);
@@ -3799,11 +3799,7 @@ int log_replay(struct ntfs_inode *ni, bool *initialized)
 	log->l_size = log->orig_file_size = ni->vfs_inode.i_size;
 
 	/* Get the size of page. NOTE: To replay we can use default page. */
-#if PAGE_SIZE >= DefaultLogPageSize && PAGE_SIZE <= DefaultLogPageSize * 2
 	log->page_size = norm_file_page(PAGE_SIZE, &log->l_size, true);
-#else
-	log->page_size = norm_file_page(PAGE_SIZE, &log->l_size, false);
-#endif
 	if (!log->page_size) {
 		err = -EINVAL;
 		goto out;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0923/2077] drm/amd/display: Add missing kdoc for ALLM parameters
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (921 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0922/2077] fs/ntfs3: fix mount failure on 64K page-size kernels Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0924/2077] thunderbolt: debugfs: Fix margining error counter buffer leak Greg Kroah-Hartman
                   ` (74 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Roman Li, Alex Hung, Tom Chung,
	Aurabindo Pillai, Wayne Lin, Nicholas Kazlauskas,
	Bhawanpreet Lakha, Srinivasan Shanmugam, Alex Deucher,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>

[ Upstream commit d4c6ec729fb7a8bf8a27b19bd70a1b945ad93dac ]

Add descriptions for the missing parameters for ALLMEnabled and
ALLMValue  to keep the function documentation synchronized with the
function prototype mod_build_hf_vsif_infopacket().

Fixes the below with gcc W=1:
../display/modules/info_packet/info_packet.c:507 function parameter 'ALLMEnabled' not described in 'mod_build_hf_vsif_infopacket'
../display/modules/info_packet/info_packet.c:507 function parameter 'ALLMValue' not described in 'mod_build_hf_vsif_infopacket'

Fixes: 3c2381b92cba ("drm/amd/display: add support for VSIP info packet")
Cc: Roman Li <roman.li@amd.com>
Cc: Alex Hung <alex.hung@amd.com>
Cc: Tom Chung <chiahsuan.chung@amd.com>
Cc: Aurabindo Pillai <aurabindo.pillai@amd.com>
Cc: Wayne Lin <Wayne.Lin@amd.com>
Cc: Nicholas Kazlauskas <Nicholas.Kazlauskas@amd.com>
Cc: Bhawanpreet Lakha <Bhawanpreet.Lakha@amd.com>
Signed-off-by: Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>
Reviewed-by: Alex Hung <alex.hung@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/amd/display/modules/info_packet/info_packet.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/gpu/drm/amd/display/modules/info_packet/info_packet.c b/drivers/gpu/drm/amd/display/modules/info_packet/info_packet.c
index 00473c6284d5cc..614db22d62f38b 100644
--- a/drivers/gpu/drm/amd/display/modules/info_packet/info_packet.c
+++ b/drivers/gpu/drm/amd/display/modules/info_packet/info_packet.c
@@ -502,6 +502,8 @@ void mod_build_vsc_infopacket(const struct dc_stream_state *stream,
  *
  *  @stream:      contains data we may need to construct VSIF (i.e. timing_3d_format, etc.)
  *  @info_packet: output structure where to store VSIF
+ *  @ALLMEnabled: indicates whether ALLM HF-VSIF should be generated
+ *  @ALLMValue:   ALLM bit value to advertise in HF-VSIF
  */
 void mod_build_hf_vsif_infopacket(const struct dc_stream_state *stream,
 		struct dc_info_packet *info_packet)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0924/2077] thunderbolt: debugfs: Fix margining error counter buffer leak
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (922 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0923/2077] drm/amd/display: Add missing kdoc for ALLM parameters Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0925/2077] dmaengine: imx-sdma: Refine spba bus searching in probe Greg Kroah-Hartman
                   ` (73 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Xu Rao, Mika Westerberg, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xu Rao <raoxu@uniontech.com>

[ Upstream commit 503c5ae1e72aa9ed91925dafa3d82ee2e992747f ]

When USB4 lane margining debugfs write support is enabled,
margining_error_counter_write() copies the user input with
validate_and_copy_from_user(). This allocates a temporary page that is
only needed while parsing the requested error counter mode.

The function currently returns without freeing that page. This leaks one
page per write to the error_counter debugfs file, including successful
writes and writes that later fail while taking the domain lock or because
software margining is not enabled.

Free the temporary page once parsing has completed, and also before
returning from the invalid-input path.

Fixes: 10904df3f20c ("thunderbolt: Improve software receiver lane margining")
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/thunderbolt/debugfs.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/drivers/thunderbolt/debugfs.c b/drivers/thunderbolt/debugfs.c
index 042f6a0d0f7f06..25f6ea6ea09472 100644
--- a/drivers/thunderbolt/debugfs.c
+++ b/drivers/thunderbolt/debugfs.c
@@ -956,7 +956,9 @@ margining_error_counter_write(struct file *file, const char __user *user_buf,
 	else if (!strcmp(buf, "stop"))
 		error_counter = USB4_MARGIN_SW_ERROR_COUNTER_STOP;
 	else
-		return -EINVAL;
+		goto err_free;
+
+	free_page((unsigned long)buf);
 
 	scoped_cond_guard(mutex_intr, return -ERESTARTSYS, &tb->lock) {
 		if (!margining->software)
@@ -966,6 +968,10 @@ margining_error_counter_write(struct file *file, const char __user *user_buf,
 	}
 
 	return count;
+
+err_free:
+	free_page((unsigned long)buf);
+	return -EINVAL;
 }
 
 static int margining_error_counter_show(struct seq_file *s, void *not_used)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0925/2077] dmaengine: imx-sdma: Refine spba bus searching in probe
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (923 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0924/2077] thunderbolt: debugfs: Fix margining error counter buffer leak Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:09 ` [PATCH 7.1 0926/2077] dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional Greg Kroah-Hartman
                   ` (72 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shengjiu Wang, Frank Li, Vinod Koul,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shengjiu Wang <shengjiu.wang@nxp.com>

[ Upstream commit d52d42e2e5d9f13166e81ac837ebb023d1306e61 ]

There are multi spba-busses for i.MX8M* platforms, if only search for
the first spba-bus in DT, the found spba-bus may not the real bus of
audio devices, which cause issue for sdma p2p case, as the sdma p2p
script presently does not deal with the transactions involving two devices
connected to the AIPS bus.

Search the SDMA parent node first, which should be the AIPS bus, then
search the child node whose compatible string is spba-bus under that AIPS
bus for the above multi spba-busses case.

Fixes: 8391ecf465ec ("dmaengine: imx-sdma: Add device to device support")
Signed-off-by: Shengjiu Wang <shengjiu.wang@nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260407032755.2758049-1-shengjiu.wang@nxp.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dma/imx-sdma.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/dma/imx-sdma.c b/drivers/dma/imx-sdma.c
index 3d527883776b40..36368835a845c9 100644
--- a/drivers/dma/imx-sdma.c
+++ b/drivers/dma/imx-sdma.c
@@ -2364,7 +2364,9 @@ static int sdma_probe(struct platform_device *pdev)
 			return dev_err_probe(&pdev->dev, ret,
 					     "failed to register controller\n");
 
-		spba_bus = of_find_compatible_node(NULL, NULL, "fsl,spba-bus");
+		struct device_node *sdma_parent_np __free(device_node) = of_get_parent(np);
+
+		spba_bus = of_get_compatible_child(sdma_parent_np, "fsl,spba-bus");
 		ret = of_address_to_resource(spba_bus, 0, &spba_res);
 		if (!ret) {
 			sdma->spba_start_addr = spba_res.start;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0926/2077] dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (924 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0925/2077] dmaengine: imx-sdma: Refine spba bus searching in probe Greg Kroah-Hartman
@ 2026-07-21 15:09 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0927/2077] perf: Fix off-by-one stack buffer overflow in kallsyms__parse() Greg Kroah-Hartman
                   ` (71 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:09 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Akhil R, Rob Herring (Arm),
	Thierry Reding, Jon Hunter, Vinod Koul, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Akhil R <akhilrajeev@nvidia.com>

[ Upstream commit cc6049bd3fa8501ee27042df469a19ed69cf406d ]

On Tegra264, GPCDMA reset control is not exposed to Linux and is handled
by the boot firmware.

Although reset was not exposed in Tegra234 as well, the firmware supported
a dummy reset which just returns success on reset without doing an actual
reset. This is also not supported in Tegra264 BPMP. Therefore mark 'reset'
and 'reset-names' properties as required only for devices prior to
Tegra264.

This also necessitates that the Tegra264 compatible be standalone and
cannot have the fallback compatible of Tegra186. Since there is no
functional impact, we keep reset as required for Tegra234 to avoid
breaking the ABI.

Fixes: bb8c97571db5 ("dt-bindings: dma: Add Tegra264 compatible string")
Signed-off-by: Akhil R <akhilrajeev@nvidia.com>
Acked-by: Rob Herring (Arm) <robh@kernel.org>
Acked-by: Thierry Reding <treding@nvidia.com>
Reviewed-by: Jon Hunter <jonathanh@nvidia.com>
Link: https://patch.msgid.link/20260331102303.33181-2-akhilrajeev@nvidia.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../bindings/dma/nvidia,tegra186-gpc-dma.yaml | 23 +++++++++++++------
 1 file changed, 16 insertions(+), 7 deletions(-)

diff --git a/Documentation/devicetree/bindings/dma/nvidia,tegra186-gpc-dma.yaml b/Documentation/devicetree/bindings/dma/nvidia,tegra186-gpc-dma.yaml
index 0dabe9bbb219ba..64f1e9d9896df3 100644
--- a/Documentation/devicetree/bindings/dma/nvidia,tegra186-gpc-dma.yaml
+++ b/Documentation/devicetree/bindings/dma/nvidia,tegra186-gpc-dma.yaml
@@ -15,16 +15,14 @@ maintainers:
   - Jon Hunter <jonathanh@nvidia.com>
   - Rajesh Gumasta <rgumasta@nvidia.com>
 
-allOf:
-  - $ref: dma-controller.yaml#
-
 properties:
   compatible:
     oneOf:
-      - const: nvidia,tegra186-gpcdma
+      - enum:
+          - nvidia,tegra264-gpcdma
+          - nvidia,tegra186-gpcdma
       - items:
           - enum:
-              - nvidia,tegra264-gpcdma
               - nvidia,tegra234-gpcdma
               - nvidia,tegra194-gpcdma
           - const: nvidia,tegra186-gpcdma
@@ -60,12 +58,23 @@ required:
   - compatible
   - reg
   - interrupts
-  - resets
-  - reset-names
   - "#dma-cells"
   - iommus
   - dma-channel-mask
 
+allOf:
+  - $ref: dma-controller.yaml#
+  - if:
+      properties:
+        compatible:
+          contains:
+            enum:
+              - nvidia,tegra186-gpcdma
+    then:
+      required:
+        - resets
+        - reset-names
+
 additionalProperties: false
 
 examples:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0927/2077] perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (925 preceding siblings ...)
  2026-07-21 15:09 ` [PATCH 7.1 0926/2077] dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0928/2077] perf annotate: Fix crashes on empty annotate windows Greg Kroah-Hartman
                   ` (70 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rui Qi, Namhyung Kim, Adrian Hunter,
	Alexander Shishkin, Ian Rogers, Ingo Molnar, James Clark,
	Jiri Olsa, Mark Rutland, Peter Zijlstra, Arnaldo Carvalho de Melo,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rui Qi <qirui.001@bytedance.com>

[ Upstream commit 68018df3f55eba96a20dd703f5f276a6518f4963 ]

In kallsyms__parse(), the loop reading symbol names iterates with i <
sizeof(symbol_name), which allows i to reach sizeof(symbol_name) upon
loop exit. The subsequent symbol_name[i] = '\0' then writes one byte
past the end of the stack-allocated symbol_name[] array.

Fix this by changing the loop bound to KSYM_NAME_LEN, so the null
terminator always lands within the array. The overflow is triggerable by
a kallsyms entry with a symbol name of KSYM_NAME_LEN+1 or more
characters (e.g., long Rust mangled names or a malicious
/proc/kallsyms).

Fixes: 53df2b9344128984 ("libsymbols kallsyms: Parse using io api")
Signed-off-by: Rui Qi <qirui.001@bytedance.com>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Ian Rogers <irogers@google.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Mark Rutland <mark.rutland@arm.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/lib/symbol/kallsyms.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/tools/lib/symbol/kallsyms.c b/tools/lib/symbol/kallsyms.c
index e335ac2b9e1972..d64bd9cc82a90e 100644
--- a/tools/lib/symbol/kallsyms.c
+++ b/tools/lib/symbol/kallsyms.c
@@ -60,7 +60,7 @@ int kallsyms__parse(const char *filename, void *arg,
 			read_to_eol(&io);
 			continue;
 		}
-		for (i = 0; i < sizeof(symbol_name); i++) {
+		for (i = 0; i < KSYM_NAME_LEN; i++) {
 			ch = io__get_char(&io);
 			if (ch < 0 || ch == '\n')
 				break;
@@ -68,6 +68,9 @@ int kallsyms__parse(const char *filename, void *arg,
 		}
 		symbol_name[i]  = '\0';
 
+		if (i == KSYM_NAME_LEN)
+			read_to_eol(&io);
+
 		err = process_symbol(arg, symbol_name, symbol_type, start);
 		if (err)
 			break;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0928/2077] perf annotate: Fix crashes on empty annotate windows
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (926 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0927/2077] perf: Fix off-by-one stack buffer overflow in kallsyms__parse() Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0929/2077] perf tools: Guard test_bit from out-of-bounds sample CPU Greg Kroah-Hartman
                   ` (69 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, James Clark, Namhyung Kim,
	Adrian Hunter, Alexander Shishkin, Ian Rogers, Ingo Molnar,
	Jiri Olsa, Mark Rutland, Peter Zijlstra, Arnaldo Carvalho de Melo,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: James Clark <james.clark@linaro.org>

[ Upstream commit 74802634e4a7e556429417963a8cbda27dd8b4b3 ]

Annotate can open with an empty window if the disassembly tool fails.
After the linked change, the TUI started assuming there was a current
annotation line and could assert or segfault in the seek, refresh, and
source-toggle paths.

Handle empty annotate windows explicitly: set the asm entry count before
resetting the browser, return early when refreshing an empty list, and
ignore source line toggle when there is no current annotation line.

Fixes the following when opening an annotation:

  perf: ui/browser.c:125: ui_browser__list_head_seek: Assertion `pos != NULL' failed.
  Aborted

Fixes: e201757f7a0a901e ("perf annotate: Fix source code annotate with objdump")
Assisted-by: GitHub Copilot:GPT-5.4
Signed-off-by: James Clark <james.clark@linaro.org>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Ian Rogers <irogers@google.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Mark Rutland <mark.rutland@arm.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/ui/browser.c           | 3 +++
 tools/perf/ui/browsers/annotate.c | 5 ++++-
 2 files changed, 7 insertions(+), 1 deletion(-)

diff --git a/tools/perf/ui/browser.c b/tools/perf/ui/browser.c
index dc88427b4ae5af..321187b204d38d 100644
--- a/tools/perf/ui/browser.c
+++ b/tools/perf/ui/browser.c
@@ -513,6 +513,9 @@ unsigned int ui_browser__list_head_refresh(struct ui_browser *browser)
 	struct list_head *head = browser->entries;
 	int row = 0;
 
+	if (browser->nr_entries == 0)
+		return 0;
+
 	if (browser->top == NULL || browser->top == browser->entries)
                 browser->top = ui_browser__list_head_filter_entries(browser, head->next);
 
diff --git a/tools/perf/ui/browsers/annotate.c b/tools/perf/ui/browsers/annotate.c
index ea17e6d29a7e49..0261cd92218344 100644
--- a/tools/perf/ui/browsers/annotate.c
+++ b/tools/perf/ui/browsers/annotate.c
@@ -449,6 +449,9 @@ static bool annotate_browser__toggle_source(struct annotate_browser *browser,
 	struct annotation_line *al;
 	off_t offset = browser->b.index - browser->b.top_idx;
 
+	if (browser->b.nr_entries == 0)
+		return false;
+
 	browser->b.seek(&browser->b, offset, SEEK_CUR);
 	al = list_entry(browser->b.top, struct annotation_line, node);
 
@@ -542,8 +545,8 @@ static void annotate_browser__show_full_location(struct ui_browser *browser)
 static void ui_browser__init_asm_mode(struct ui_browser *browser)
 {
 	struct annotation *notes = browser__annotation(browser);
-	ui_browser__reset_index(browser);
 	browser->nr_entries = notes->src->nr_asm_entries;
+	ui_browser__reset_index(browser);
 }
 
 static int sym_title(struct symbol *sym, struct map *map, char *title,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0929/2077] perf tools: Guard test_bit from out-of-bounds sample CPU
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (927 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0928/2077] perf annotate: Fix crashes on empty annotate windows Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0930/2077] perf sched: Fix thread reference leak in latency_switch_event Greg Kroah-Hartman
                   ` (68 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anton Blanchard, sashiko-bot,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit a5498ccf8079fc91c938f122ff9697b0c526b2fd ]

When PERF_SAMPLE_CPU is absent from a perf.data file, sample->cpu is
initialized to (u32)-1 by evsel__parse_sample().  Five call sites pass
this value directly to test_bit(sample->cpu, cpu_bitmap), reading
massively out of bounds past the DECLARE_BITMAP(..., MAX_NR_CPUS)
allocation of 4096 bits.

Add a sample->cpu >= MAX_NR_CPUS guard before each test_bit() call,
matching the existing safe pattern in builtin-kwork.c.  This catches
both the (u32)-1 sentinel and any corrupted CPU value exceeding the
bitmap size.

Fixes: 5d67be97f890 ("perf report/annotate/script: Add option to specify a CPU range")
Cc: Anton Blanchard <anton@samba.org>
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-annotate.c | 3 ++-
 tools/perf/builtin-diff.c     | 3 ++-
 tools/perf/builtin-report.c   | 3 ++-
 tools/perf/builtin-sched.c    | 6 ++++--
 4 files changed, 10 insertions(+), 5 deletions(-)

diff --git a/tools/perf/builtin-annotate.c b/tools/perf/builtin-annotate.c
index 5e57b78548f421..bdc7adc83b4711 100644
--- a/tools/perf/builtin-annotate.c
+++ b/tools/perf/builtin-annotate.c
@@ -298,7 +298,8 @@ static int process_sample_event(const struct perf_tool *tool,
 		goto out_put;
 	}
 
-	if (ann->cpu_list && !test_bit(sample->cpu, ann->cpu_bitmap))
+	if (ann->cpu_list && (sample->cpu >= MAX_NR_CPUS ||
+			     !test_bit(sample->cpu, ann->cpu_bitmap)))
 		goto out_put;
 
 	if (!al.filtered &&
diff --git a/tools/perf/builtin-diff.c b/tools/perf/builtin-diff.c
index 1b3df868849a99..29db0afc53ca07 100644
--- a/tools/perf/builtin-diff.c
+++ b/tools/perf/builtin-diff.c
@@ -416,7 +416,8 @@ static int diff__process_sample_event(const struct perf_tool *tool,
 		goto out;
 	}
 
-	if (cpu_list && !test_bit(sample->cpu, cpu_bitmap)) {
+	if (cpu_list && (sample->cpu >= MAX_NR_CPUS ||
+			!test_bit(sample->cpu, cpu_bitmap))) {
 		ret = 0;
 		goto out;
 	}
diff --git a/tools/perf/builtin-report.c b/tools/perf/builtin-report.c
index 0b0966d94128ee..3a5cf1b64adb0d 100644
--- a/tools/perf/builtin-report.c
+++ b/tools/perf/builtin-report.c
@@ -300,7 +300,8 @@ static int process_sample_event(const struct perf_tool *tool,
 	if (symbol_conf.hide_unresolved && al.sym == NULL)
 		goto out_put;
 
-	if (rep->cpu_list && !test_bit(sample->cpu, rep->cpu_bitmap))
+	if (rep->cpu_list && (sample->cpu >= MAX_NR_CPUS ||
+			     !test_bit(sample->cpu, rep->cpu_bitmap)))
 		goto out_put;
 
 	if (sort__mode == SORT_MODE__BRANCH) {
diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 241c2f808f7b02..3dcd1f3525fde9 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -2175,7 +2175,8 @@ static void timehist_print_sample(struct perf_sched *sched,
 	char nstr[30];
 	u64 wait_time;
 
-	if (cpu_list && !test_bit(sample->cpu, cpu_bitmap))
+	if (cpu_list && (sample->cpu >= MAX_NR_CPUS ||
+			!test_bit(sample->cpu, cpu_bitmap)))
 		return;
 
 	timestamp__scnprintf_usec(t, tstr, sizeof(tstr));
@@ -2857,7 +2858,8 @@ static int timehist_sched_change_event(const struct perf_tool *tool,
 	}
 
 	if (!sched->idle_hist || thread__tid(thread) == 0) {
-		if (!cpu_list || test_bit(sample->cpu, cpu_bitmap))
+		if (!cpu_list || (sample->cpu < MAX_NR_CPUS &&
+				 test_bit(sample->cpu, cpu_bitmap)))
 			timehist_update_runtime_stats(tr, t, tprev);
 
 		if (sched->idle_hist) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0930/2077] perf sched: Fix thread reference leak in latency_switch_event
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (928 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0929/2077] perf tools: Guard test_bit from out-of-bounds sample CPU Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0931/2077] perf sched: Replace BUG_ON on invalid CPU with graceful skip Greg Kroah-Hartman
                   ` (67 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 66ea9de60396a4dea5276bc87025884691876c36 ]

In latency_switch_event(), after acquiring thread references for
sched_out and sched_in via machine__findnew_thread(), the first
add_sched_out_event() failure path does 'return -1', bypassing the
out_put label that calls thread__put() on both references.

The second and third add_sched_out_event() failures correctly use
'goto out_put'.  Fix the first one to match.

Fixes: b91fc39f4ad7 ("perf machine: Protect the machine->threads with a rwlock")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 3dcd1f3525fde9..c6a96d0dd77d94 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -1177,7 +1177,7 @@ static int latency_switch_event(struct perf_sched *sched,
 		}
 	}
 	if (add_sched_out_event(out_events, prev_state, timestamp))
-		return -1;
+		goto out_put;
 
 	in_events = thread_atoms_search(&sched->atom_root, sched_in, &sched->cmp_pid);
 	if (!in_events) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0931/2077] perf sched: Replace BUG_ON on invalid CPU with graceful skip
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (929 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0930/2077] perf sched: Fix thread reference leak in latency_switch_event Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0932/2077] perf sched: Fix NULL dereference in latency_runtime_event Greg Kroah-Hartman
                   ` (66 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Arnaldo Carvalho de Melo,
	Sasha Levin, sashiko-bot

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 1e2c83f732deb329ebce23e26cbc482f4c4bf194 ]

latency_switch_event(), latency_runtime_event(), and map_switch_event()
use BUG_ON(cpu >= MAX_CPUS || cpu < 0) to validate the sample CPU.
When PERF_SAMPLE_CPU is absent from the sample type,
evsel__parse_sample() initializes sample->cpu to (u32)-1.  Casting
this to int yields -1, which triggers the BUG_ON and aborts perf sched.

The central CPU validation in perf_session__deliver_event() intentionally
preserves the (u32)-1 sentinel for downstream tools like perf script
and perf inject, so leaf callbacks must handle it themselves.

Replace the three BUG_ON calls with graceful skips using pr_warning(),
matching the existing pattern in process_sched_switch_event() and
process_sched_runtime_event() earlier in the same file.  Include the
file offset for cross-referencing with perf report -D.

Reported-by: sashiko-bot@kernel.org # Running on a local machine
Reviewed-by: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: 8cbca8a480e1 ("perf sched: Fix NULL dereference in latency_runtime_event")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 22 +++++++++++++++++++---
 1 file changed, 19 insertions(+), 3 deletions(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index c6a96d0dd77d94..adff5d40a15c95 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -1147,7 +1147,12 @@ static int latency_switch_event(struct perf_sched *sched,
 	int cpu = sample->cpu, err = -1;
 	s64 delta;
 
-	BUG_ON(cpu >= MAX_CPUS || cpu < 0);
+	/* perf.data is untrusted input — CPU may be absent or corrupted */
+	if (cpu >= MAX_CPUS || cpu < 0) {
+		pr_warning("WARNING: at offset %#" PRIx64 ": out-of-bound sample CPU %d, skipping sample\n",
+			   sample->file_offset, cpu);
+		return 0;
+	}
 
 	timestamp0 = sched->cpu_last_switched[cpu];
 	sched->cpu_last_switched[cpu] = timestamp;
@@ -1218,7 +1223,13 @@ static int latency_runtime_event(struct perf_sched *sched,
 	if (thread == NULL)
 		return -1;
 
-	BUG_ON(cpu >= MAX_CPUS || cpu < 0);
+	/* perf.data is untrusted input — CPU may be absent or corrupted */
+	if (cpu >= MAX_CPUS || cpu < 0) {
+		pr_warning("WARNING: at offset %#" PRIx64 ": out-of-bound sample CPU %d, skipping sample\n",
+			   sample->file_offset, cpu);
+		err = 0;
+		goto out_put;
+	}
 	if (!atoms) {
 		if (thread_atoms_insert(sched, thread))
 			goto out_put;
@@ -1647,7 +1658,12 @@ static int map_switch_event(struct perf_sched *sched, struct evsel *evsel,
 	const char *str;
 	int ret = -1;
 
-	BUG_ON(this_cpu.cpu >= MAX_CPUS || this_cpu.cpu < 0);
+	/* perf.data is untrusted input — CPU may be absent or corrupted */
+	if (this_cpu.cpu >= MAX_CPUS || this_cpu.cpu < 0) {
+		pr_warning("WARNING: at offset %#" PRIx64 ": out-of-bound sample CPU %d, skipping sample\n",
+			   sample->file_offset, this_cpu.cpu);
+		return 0;
+	}
 
 	if (this_cpu.cpu > sched->max_cpu.cpu)
 		sched->max_cpu = this_cpu;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0932/2077] perf sched: Fix NULL dereference in latency_runtime_event
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (930 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0931/2077] perf sched: Replace BUG_ON on invalid CPU with graceful skip Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0933/2077] perf sched: Fix comp_cpus heap overflow with cross-machine recordings Greg Kroah-Hartman
                   ` (65 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 8cbca8a480e15f6326ce94287570993f27a4b2d5 ]

latency_runtime_event() passes the return value of
machine__findnew_thread() directly to thread_atoms_search() at line
1216, before checking for NULL at line 1220.  thread_atoms_search()
calls pid_cmp() which dereferences the thread pointer via
thread__tid(), causing a NULL pointer dereference if the allocation
fails.

All other callers of thread_atoms_search() in this file
(latency_switch_event, latency_wakeup_event,
latency_migrate_task_event) correctly check for NULL first.

Move the atoms assignment after the NULL check to match the pattern
used by the other callers.

Fixes: b91fc39f4ad7 ("perf machine: Protect the machine->threads with a rwlock")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index adff5d40a15c95..13d9a15a553ec9 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -1216,13 +1216,15 @@ static int latency_runtime_event(struct perf_sched *sched,
 	const u32 pid	   = evsel__intval(evsel, sample, "pid");
 	const u64 runtime  = evsel__intval(evsel, sample, "runtime");
 	struct thread *thread = machine__findnew_thread(machine, -1, pid);
-	struct work_atoms *atoms = thread_atoms_search(&sched->atom_root, thread, &sched->cmp_pid);
+	struct work_atoms *atoms;
 	u64 timestamp = sample->time;
 	int cpu = sample->cpu, err = -1;
 
 	if (thread == NULL)
 		return -1;
 
+	atoms = thread_atoms_search(&sched->atom_root, thread, &sched->cmp_pid);
+
 	/* perf.data is untrusted input — CPU may be absent or corrupted */
 	if (cpu >= MAX_CPUS || cpu < 0) {
 		pr_warning("WARNING: at offset %#" PRIx64 ": out-of-bound sample CPU %d, skipping sample\n",
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0933/2077] perf sched: Fix comp_cpus heap overflow with cross-machine recordings
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (931 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0932/2077] perf sched: Fix NULL dereference in latency_runtime_event Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0934/2077] perf tools: Guard remaining test_bit calls from OOB sample CPU Greg Kroah-Hartman
                   ` (64 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Jiri Olsa,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit c8b04142078a9ccb9e402ab7c38de7123256f4a5 ]

setup_map_cpus() allocates comp_cpus based on
sysconf(_SC_NPROCESSORS_CONF), the host machine's CPU count.  But
map_switch_event() indexes comp_cpus using cpus_nr derived from
bitmap_weight(comp_cpus_mask, MAX_CPUS), where comp_cpus_mask is
declared as DECLARE_BITMAP(..., MAX_CPUS) with MAX_CPUS=4096.

When analyzing a perf.data recording from a machine with more CPUs
than the analysis host (e.g. 128-CPU server recording analyzed on an
8-CPU laptop), cpus_nr exceeds the allocation size, causing a heap
buffer overflow.

Also fix a type mismatch: comp_cpus is 'struct perf_cpu *' (2 bytes
per element) but was allocated with sizeof(int) (4 bytes per element).

Allocate comp_cpus with MAX_CPUS entries using the correct element
size, matching the comp_cpus_mask bitmap bounds.  Remove the
sysconf(_SC_NPROCESSORS_CONF) initialization of max_cpu — its only
consumer was the comp_cpus allocation, and max_cpu is dynamically
updated from the recording's events during processing.  Fix the
non-compact path to use max_cpu.cpu + 1 as cpus_nr, converting from
0-based index to count — sysconf() returned a count which masked
this off-by-one.

Fixes: 99623c628f54 ("perf sched: Add compact display option")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 13d9a15a553ec9..6f5d5f3ce715c7 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -1677,7 +1677,7 @@ static int map_switch_event(struct perf_sched *sched, struct evsel *evsel,
 			new_cpu = true;
 		}
 	} else
-		cpus_nr = sched->max_cpu.cpu;
+		cpus_nr = sched->max_cpu.cpu + 1;
 
 	timestamp0 = sched->cpu_last_switched[this_cpu.cpu];
 	sched->cpu_last_switched[this_cpu.cpu] = timestamp;
@@ -3577,10 +3577,8 @@ static int perf_sched__lat(struct perf_sched *sched)
 
 static int setup_map_cpus(struct perf_sched *sched)
 {
-	sched->max_cpu.cpu  = sysconf(_SC_NPROCESSORS_CONF);
-
 	if (sched->map.comp) {
-		sched->map.comp_cpus = calloc(sched->max_cpu.cpu, sizeof(int));
+		sched->map.comp_cpus = calloc(MAX_CPUS, sizeof(*sched->map.comp_cpus));
 		if (!sched->map.comp_cpus)
 			return -1;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0934/2077] perf tools: Guard remaining test_bit calls from OOB sample CPU
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (932 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0933/2077] perf sched: Fix comp_cpus heap overflow with cross-machine recordings Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0935/2077] perf tools: Add bounds check to cpu__get_node() Greg Kroah-Hartman
                   ` (63 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Adrian Hunter,
	Anton Blanchard, Jiri Olsa, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 7ccd2e6cecd5bb02a5a15f0dd7199d1e81380bda ]

auxtrace.c:filter_cpu() and builtin-script.c:filter_cpu() call
test_bit(cpu, cpu_bitmap) where cpu_bitmap is declared with
MAX_NR_CPUS bits.  When the CPU value from a perf.data event is
corrupt or absent (e.g. negative or >= MAX_NR_CPUS), test_bit reads
out of bounds.

Add bounds checks before test_bit(): >= 0 for the int16_t cpu.cpu in
auxtrace (which also covers the -1 sentinel), and < MAX_NR_CPUS for
both sites.  Matches the pattern applied in the previous series for
builtin-annotate.c, builtin-diff.c, builtin-report.c, and
builtin-sched.c.

Fixes: 644e0840ad46 ("perf auxtrace: Add CPU filter support")
Fixes: 5d67be97f890 ("perf report/annotate/script: Add option to specify a CPU range")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Anton Blanchard <anton@samba.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-script.c | 2 +-
 tools/perf/util/auxtrace.c  | 3 ++-
 2 files changed, 3 insertions(+), 2 deletions(-)

diff --git a/tools/perf/builtin-script.c b/tools/perf/builtin-script.c
index fd0b4609516b3e..ed372762276bce 100644
--- a/tools/perf/builtin-script.c
+++ b/tools/perf/builtin-script.c
@@ -2638,7 +2638,7 @@ static int cleanup_scripting(void)
 
 static bool filter_cpu(struct perf_sample *sample)
 {
-	if (cpu_list && sample->cpu != (u32)-1)
+	if (cpu_list && sample->cpu != (u32)-1 && sample->cpu < MAX_NR_CPUS)
 		return !test_bit(sample->cpu, cpu_bitmap);
 	return false;
 }
diff --git a/tools/perf/util/auxtrace.c b/tools/perf/util/auxtrace.c
index a224687ffbc1b5..47e2004b91d739 100644
--- a/tools/perf/util/auxtrace.c
+++ b/tools/perf/util/auxtrace.c
@@ -372,7 +372,8 @@ static bool filter_cpu(struct perf_session *session, struct perf_cpu cpu)
 {
 	unsigned long *cpu_bitmap = session->itrace_synth_opts->cpu_bitmap;
 
-	return cpu_bitmap && cpu.cpu != -1 && !test_bit(cpu.cpu, cpu_bitmap);
+	return cpu_bitmap && cpu.cpu >= 0 && cpu.cpu < MAX_NR_CPUS &&
+	       !test_bit(cpu.cpu, cpu_bitmap);
 }
 
 static int auxtrace_queues__add_buffer(struct auxtrace_queues *queues,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0935/2077] perf tools: Add bounds check to cpu__get_node()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (933 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0934/2077] perf tools: Guard remaining test_bit calls from OOB sample CPU Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0936/2077] perf sched: Fix thread reference leaks in timehist_get_thread() Greg Kroah-Hartman
                   ` (62 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Jiri Olsa,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 1e7921d7227de5da0dfc167943092c823ec7e49b ]

cpu__get_node() accesses cpunode_map[cpu.cpu] without checking against
max_cpu_num, the allocation size of cpunode_map.  Callers such as
builtin-kmem.c:evsel__process_alloc_event() pass sample->cpu from
perf.data events, which may exceed the host's CPU count when analyzing
cross-machine recordings.

Add a bounds check against max_cpu_num before indexing, returning -1
for out-of-range values.  This is a central fix that protects all
callers.

Fixes: 86895b480a2f ("perf stat: Add --per-node agregation support")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/cpumap.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/tools/perf/util/cpumap.c b/tools/perf/util/cpumap.c
index 11922e1ded844a..19783c83765726 100644
--- a/tools/perf/util/cpumap.c
+++ b/tools/perf/util/cpumap.c
@@ -548,6 +548,10 @@ int cpu__get_node(struct perf_cpu cpu)
 		return -1;
 	}
 
+	/* cpunode_map allocated for max_cpu_num entries; input may be untrusted */
+	if (cpu.cpu < 0 || cpu.cpu >= max_cpu_num.cpu)
+		return -1;
+
 	return cpunode_map[cpu.cpu];
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0936/2077] perf sched: Fix thread reference leaks in timehist_get_thread()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (934 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0935/2077] perf tools: Add bounds check to cpu__get_node() Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0937/2077] perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing Greg Kroah-Hartman
                   ` (61 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Namhyung Kim,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit fa20c1f8f4e094abe0169d39fce8181bc26d6dab ]

timehist_get_thread() acquires a thread reference via
machine__findnew_thread() and an idle thread reference via
get_idle_thread() (which calls thread__get()).  Two error paths in
the idle_hist block return NULL without releasing these references:

 - When get_idle_thread() fails, the thread reference leaks.
 - When thread__priv(idle) returns NULL, both idle and thread leak.

Additionally, the idle thread reference acquired on the success path
is never released, leaking a reference on every sample when
--idle-hist is active.

Add thread__put() calls on both error paths and release the idle
reference after use on the success path.

Fixes: 5d8f17fb5822 ("perf sched timehist: Add -I/--idle-hist option")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 6f5d5f3ce715c7..7503fc00ff20a3 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -2547,12 +2547,16 @@ static struct thread *timehist_get_thread(struct perf_sched *sched,
 			idle = get_idle_thread(sample->cpu);
 			if (idle == NULL) {
 				pr_err("Failed to get idle thread for cpu %d.\n", sample->cpu);
+				thread__put(thread);
 				return NULL;
 			}
 
 			itr = thread__priv(idle);
-			if (itr == NULL)
+			if (itr == NULL) {
+				thread__put(idle);
+				thread__put(thread);
 				return NULL;
+			}
 
 			thread__put(itr->last_thread);
 			itr->last_thread = thread__get(thread);
@@ -2560,6 +2564,8 @@ static struct thread *timehist_get_thread(struct perf_sched *sched,
 			/* copy task callchain when entering to idle */
 			if (evsel__intval(evsel, sample, "next_pid") == 0)
 				save_idle_callchain(sched, itr, sample);
+
+			thread__put(idle);
 		}
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0937/2077] perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (935 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0936/2077] perf sched: Fix thread reference leaks in timehist_get_thread() Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0938/2077] perf sched: Fix register_pid() overflow, strcpy, and BUG_ON Greg Kroah-Hartman
                   ` (60 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Ahern, sashiko-bot,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 06e7994427ab56e32699a5e45d048ff0826f3d53 ]

perf_timehist__process_sample() updates sched->max_cpu from the
sample CPU without bounds checking.  Later code uses max_cpu + 1 as
an iteration count over arrays allocated with MAX_CPUS entries
(curr_thread, cpu_last_switched).  A recording with CPU IDs >= MAX_CPUS
causes out-of-bounds array accesses.

Also cap the env->nr_cpus_online initialization of max_cpu in
perf_sched__timehist(), which could exceed MAX_CPUS on very large
systems.

Add bounds checks before both max_cpu updates, matching the pattern
already used in map_switch_event().

Fixes: 49394a2a24c7 ("perf sched timehist: Introduce timehist command")
Reviewed-by: David Ahern <dsahern@kernel.org>
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 7503fc00ff20a3..7cb27fba12a909 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -3219,7 +3219,9 @@ static int perf_timehist__process_sample(const struct perf_tool *tool,
 		.cpu = sample->cpu,
 	};
 
-	if (this_cpu.cpu > sched->max_cpu.cpu)
+	/* max_cpu indexes arrays allocated with MAX_CPUS entries */
+	if (this_cpu.cpu >= 0 && this_cpu.cpu < MAX_CPUS &&
+	    this_cpu.cpu > sched->max_cpu.cpu)
 		sched->max_cpu = this_cpu;
 
 	if (evsel->handler != NULL) {
@@ -3389,8 +3391,8 @@ static int perf_sched__timehist(struct perf_sched *sched)
 		perf_session__set_tracepoints_handlers(session, migrate_handlers))
 		goto out;
 
-	/* pre-allocate struct for per-CPU idle stats */
-	sched->max_cpu.cpu = env->nr_cpus_online;
+	/* pre-allocate struct for per-CPU idle stats; cap to array bounds */
+	sched->max_cpu.cpu = min(env->nr_cpus_online, MAX_CPUS);
 	if (sched->max_cpu.cpu == 0)
 		sched->max_cpu.cpu = 4;
 	if (init_idle_threads(sched->max_cpu.cpu))
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0938/2077] perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (936 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0937/2077] perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0939/2077] perf mmap: Guard cpu__get_node() return in aio_bind() Greg Kroah-Hartman
                   ` (59 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ingo Molnar,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 5949d339f5ec98752d56dcd4e36f619a59d513a5 ]

register_pid() has several issues when processing untrusted perf.data:

1. Integer overflow: (pid + 1) * sizeof(struct task_desc *) can wrap
   to a small value on 32-bit systems when pid is large (e.g.
   0x40000000), causing realloc to return a tiny buffer followed by
   out-of-bounds writes in the initialization loop.

2. Heap buffer overflow: strcpy(task->comm, comm) copies the
   untrusted comm string into a fixed 20-byte COMM_LEN buffer with
   no length check.

3. BUG_ON on allocation failure: perf.data is untrusted input, so
   allocation failures should be handled gracefully rather than
   killing the process.

4. Realloc of sched->tasks assigned directly back, leaking the old
   pointer on failure; nr_tasks incremented before the realloc,
   leaving corrupted state on failure.

Cap pid at PID_MAX_LIMIT (4194304, matching the kernel's maximum
on 64-bit), replace strcpy with strlcpy, guard against NULL comm,
replace BUG_ON with NULL returns using safe realloc patterns, and
add NULL checks in callers that dereference the result.

Fixes: ec156764d424 ("perf sched: Import schedbench.c")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Ingo Molnar <mingo@elte.hu>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 40 ++++++++++++++++++++++++++++----------
 1 file changed, 30 insertions(+), 10 deletions(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 7cb27fba12a909..cca9719558463b 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -54,6 +54,7 @@
 #define COMM_LEN		20
 #define SYM_LEN			129
 #define MAX_PID			1024000
+#define PID_MAX_LIMIT		4194304 /* kernel limit on 64-bit */
 #define MAX_PRIO		140
 #define SEP_LEN			100
 
@@ -448,17 +449,28 @@ static void add_sched_event_sleep(struct perf_sched *sched, struct task_desc *ta
 static struct task_desc *register_pid(struct perf_sched *sched,
 				      unsigned long pid, const char *comm)
 {
-	struct task_desc *task;
+	struct task_desc *task, **tasks_p;
 	static int pid_max;
 
+	/* perf.data is untrusted — cap pid to prevent overflow in size calculations */
+	if (pid >= PID_MAX_LIMIT) {
+		pr_err("pid %lu exceeds limit %d, skipping\n", pid, PID_MAX_LIMIT);
+		return NULL;
+	}
+
 	if (sched->pid_to_task == NULL) {
 		if (sysctl__read_int("kernel/pid_max", &pid_max) < 0)
 			pid_max = MAX_PID;
-		BUG_ON((sched->pid_to_task = calloc(pid_max, sizeof(struct task_desc *))) == NULL);
+		sched->pid_to_task = calloc(pid_max, sizeof(struct task_desc *));
+		if (sched->pid_to_task == NULL)
+			return NULL;
 	}
 	if (pid >= (unsigned long)pid_max) {
-		BUG_ON((sched->pid_to_task = realloc(sched->pid_to_task, (pid + 1) *
-			sizeof(struct task_desc *))) == NULL);
+		void *p = realloc(sched->pid_to_task, (pid + 1) * sizeof(struct task_desc *));
+
+		if (p == NULL)
+			return NULL;
+		sched->pid_to_task = p;
 		while (pid >= (unsigned long)pid_max)
 			sched->pid_to_task[pid_max++] = NULL;
 	}
@@ -469,9 +481,11 @@ static struct task_desc *register_pid(struct perf_sched *sched,
 		return task;
 
 	task = zalloc(sizeof(*task));
+	if (task == NULL)
+		return NULL;
 	task->pid = pid;
-	task->nr = sched->nr_tasks;
-	strcpy(task->comm, comm);
+	if (comm)
+		strlcpy(task->comm, comm, sizeof(task->comm));
 	/*
 	 * every task starts in sleeping state - this gets ignored
 	 * if there's no wakeup pointing to this sleep state:
@@ -479,10 +493,12 @@ static struct task_desc *register_pid(struct perf_sched *sched,
 	add_sched_event_sleep(sched, task, 0);
 
 	sched->pid_to_task[pid] = task;
-	sched->nr_tasks++;
-	sched->tasks = realloc(sched->tasks, sched->nr_tasks * sizeof(struct task_desc *));
-	BUG_ON(!sched->tasks);
-	sched->tasks[task->nr] = task;
+	tasks_p = realloc(sched->tasks, (sched->nr_tasks + 1) * sizeof(struct task_desc *));
+	if (!tasks_p)
+		return NULL;
+	sched->tasks = tasks_p;
+	sched->tasks[sched->nr_tasks] = task;
+	task->nr = sched->nr_tasks++;
 
 	if (verbose > 0)
 		printf("registered task #%ld, PID %ld (%s)\n", sched->nr_tasks, pid, comm);
@@ -841,6 +857,8 @@ replay_wakeup_event(struct perf_sched *sched,
 
 	waker = register_pid(sched, sample->tid, "<unknown>");
 	wakee = register_pid(sched, pid, comm);
+	if (waker == NULL || wakee == NULL)
+		return -1;
 
 	add_sched_event_wakeup(sched, waker, sample->time, wakee);
 	return 0;
@@ -882,6 +900,8 @@ static int replay_switch_event(struct perf_sched *sched,
 
 	prev = register_pid(sched, prev_pid, prev_comm);
 	next = register_pid(sched, next_pid, next_comm);
+	if (prev == NULL || next == NULL)
+		return -1;
 
 	sched->cpu_last_switched[cpu] = timestamp;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0939/2077] perf mmap: Guard cpu__get_node() return in aio_bind()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (937 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0938/2077] perf sched: Fix register_pid() overflow, strcpy, and BUG_ON Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0940/2077] perf stat: Bounds-check CPU index in topology aggregation callbacks Greg Kroah-Hartman
                   ` (58 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Alexey Budankov,
	Jiri Olsa, Namhyung Kim, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit f32dc302a090f48893477ef297a888db109ec0bd ]

perf_mmap__aio_bind() passes the cpu__get_node() return value directly
to an unsigned long variable (node_index).  When cpu__get_node() returns
-1 for an unknown CPU, the implicit int-to-unsigned-long conversion
sign-extends it to ULONG_MAX.

This causes bitmap_zalloc(ULONG_MAX + 1) which wraps to
bitmap_zalloc(0), returning a zero-sized allocation.  The subsequent
__set_bit(ULONG_MAX, node_mask) then writes massively out of bounds.

Check the return value in a signed temporary before assigning to
node_index, and skip the NUMA binding when the node is unknown.

Fixes: c44a8b44ca9f ("perf record: Bind the AIO user space buffers to nodes")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Alexey Budankov <alexey.budankov@linux.intel.com>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/mmap.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/tools/perf/util/mmap.c b/tools/perf/util/mmap.c
index b69f926d314b14..4404a99eee45f9 100644
--- a/tools/perf/util/mmap.c
+++ b/tools/perf/util/mmap.c
@@ -104,9 +104,15 @@ static int perf_mmap__aio_bind(struct mmap *map, int idx, struct perf_cpu cpu, i
 	int err = 0;
 
 	if (affinity != PERF_AFFINITY_SYS && cpu__max_node() > 1) {
+		int node;
+
 		data = map->aio.data[idx];
 		mmap_len = mmap__mmap_len(map);
-		node_index = cpu__get_node(cpu);
+		node = cpu__get_node(cpu);
+		/* -1 sign-extends to ULONG_MAX, wrapping bitmap_zalloc(0) and OOB __set_bit */
+		if (node < 0)
+			return 0;
+		node_index = node;
 		node_mask = bitmap_zalloc(node_index + 1);
 		if (!node_mask) {
 			pr_err("Failed to allocate node mask for mbind: error %m\n");
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0940/2077] perf stat: Bounds-check CPU index in topology aggregation callbacks
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (938 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0939/2077] perf mmap: Guard cpu__get_node() return in aio_bind() Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0941/2077] perf c2c: Bounds-check CPU and node IDs before bitmap and array access Greg Kroah-Hartman
                   ` (57 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers, Jiri Olsa,
	Namhyung Kim, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 52e69b1c5b606b513d403dd4addc784c27a0c8e2 ]

Six perf_env__get_*_aggr_by_cpu() functions access env->cpu[cpu.cpu]
after only checking cpu.cpu != -1.  env->cpu[] is allocated with
env->nr_cpus_avail entries, so a CPU index from an untrusted perf.data
file that exceeds that count causes an out-of-bounds heap read.

Replace the != -1 guard with >= 0 && < env->nr_cpus_avail in all six
functions.  The >= 0 check also catches -1 and any other negative values
that could bypass the old check.

Affected functions:
  - perf_env__get_socket_aggr_by_cpu()
  - perf_env__get_die_aggr_by_cpu()
  - perf_env__get_cache_aggr_by_cpu()
  - perf_env__get_cluster_aggr_by_cpu()
  - perf_env__get_core_aggr_by_cpu()
  - perf_env__get_cpu_aggr_by_cpu()

Fixes: 68d702f7a120 ("perf stat report: Add support to initialize aggr_map from file")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Ian Rogers <irogers@google.com>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-stat.c | 13 +++++++------
 1 file changed, 7 insertions(+), 6 deletions(-)

diff --git a/tools/perf/builtin-stat.c b/tools/perf/builtin-stat.c
index 99d7db372b4808..9a045811c4197c 100644
--- a/tools/perf/builtin-stat.c
+++ b/tools/perf/builtin-stat.c
@@ -1638,7 +1638,8 @@ static struct aggr_cpu_id perf_env__get_socket_aggr_by_cpu(struct perf_cpu cpu,
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
 
-	if (cpu.cpu != -1)
+	/* env->cpu[] has env->nr_cpus_avail entries; reject untrusted indices */
+	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail)
 		id.socket = env->cpu[cpu.cpu].socket_id;
 
 	return id;
@@ -1649,7 +1650,7 @@ static struct aggr_cpu_id perf_env__get_die_aggr_by_cpu(struct perf_cpu cpu, voi
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
 
-	if (cpu.cpu != -1) {
+	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail) {
 		/*
 		 * die_id is relative to socket, so start
 		 * with the socket ID and then add die to
@@ -1705,7 +1706,7 @@ static struct aggr_cpu_id perf_env__get_cache_aggr_by_cpu(struct perf_cpu cpu,
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
 
-	if (cpu.cpu != -1) {
+	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail) {
 		u32 cache_level = (perf_stat.aggr_level) ?: stat_config.aggr_level;
 
 		id.socket = env->cpu[cpu.cpu].socket_id;
@@ -1722,7 +1723,7 @@ static struct aggr_cpu_id perf_env__get_cluster_aggr_by_cpu(struct perf_cpu cpu,
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
 
-	if (cpu.cpu != -1) {
+	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail) {
 		id.socket = env->cpu[cpu.cpu].socket_id;
 		id.die = env->cpu[cpu.cpu].die_id;
 		id.cluster = env->cpu[cpu.cpu].cluster_id;
@@ -1736,7 +1737,7 @@ static struct aggr_cpu_id perf_env__get_core_aggr_by_cpu(struct perf_cpu cpu, vo
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
 
-	if (cpu.cpu != -1) {
+	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail) {
 		/*
 		 * core_id is relative to socket, die and cluster, we need a
 		 * global id. So we set socket, die id, cluster id and core id.
@@ -1755,7 +1756,7 @@ static struct aggr_cpu_id perf_env__get_cpu_aggr_by_cpu(struct perf_cpu cpu, voi
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
 
-	if (cpu.cpu != -1) {
+	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail) {
 		/*
 		 * core_id is relative to socket and die,
 		 * we need a global id. So we set
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0941/2077] perf c2c: Bounds-check CPU and node IDs before bitmap and array access
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (939 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0940/2077] perf stat: Bounds-check CPU index in topology aggregation callbacks Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0942/2077] perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop Greg Kroah-Hartman
                   ` (56 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Jiri Olsa, Namhyung Kim,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 65117c3da50f749f4c22eb7a7effc53453dff57f ]

c2c_he__set_cpu() passes sample->cpu directly to __set_bit(cpu, cpuset)
after only checking for the (u32)-1 sentinel.  The cpuset bitmap is
allocated with c2c.cpus_cnt bits (from env->nr_cpus_avail), so a crafted
perf.data with CPU IDs exceeding that count causes out-of-bounds heap
writes.

c2c_he__set_node() similarly passes the node ID from mem2node__node()
to __set_bit(node, nodeset) after only checking for negative values.
The nodeset bitmap is sized to c2c.nodes_cnt (from env->nr_numa_nodes),
so a node ID exceeding that causes OOB writes.

process_sample_event() indexes c2c.cpu2node[cpu] and
c2c_he->node_stats[node] without bounds checking.  Both arrays are
sized to c2c.cpus_cnt and c2c.nodes_cnt respectively.

Add bounds checks in all three paths:
  - c2c_he__set_cpu(): return if sample->cpu >= c2c.cpus_cnt
  - c2c_he__set_node(): return if node >= c2c.nodes_cnt
  - process_sample_event(): clamp cpu to 0 if >= cpus_cnt,
    guard node_stats access with bounds check

Fixes: 1e181b92a2da ("perf c2c report: Add 'node' sort key")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-c2c.c | 19 +++++++++++++++++--
 1 file changed, 17 insertions(+), 2 deletions(-)

diff --git a/tools/perf/builtin-c2c.c b/tools/perf/builtin-c2c.c
index 72a7802775ee96..e2a7ffd4192e47 100644
--- a/tools/perf/builtin-c2c.c
+++ b/tools/perf/builtin-c2c.c
@@ -241,6 +241,10 @@ static void c2c_he__set_cpu(struct c2c_hist_entry *c2c_he,
 		      "WARNING: no sample cpu value"))
 		return;
 
+	/* cpuset bitmap has c2c.cpus_cnt bits from env->nr_cpus_avail */
+	if (sample->cpu >= (unsigned int)c2c.cpus_cnt)
+		return;
+
 	__set_bit(sample->cpu, c2c_he->cpuset);
 }
 
@@ -258,6 +262,10 @@ static void c2c_he__set_node(struct c2c_hist_entry *c2c_he,
 	if (WARN_ONCE(node < 0, "WARNING: failed to find node\n"))
 		return;
 
+	/* nodeset bitmap has c2c.nodes_cnt bits from env->nr_numa_nodes */
+	if (node >= c2c.nodes_cnt)
+		return;
+
 	__set_bit(node, c2c_he->nodeset);
 
 	if (c2c_he->paddr != sample->phys_addr) {
@@ -386,7 +394,12 @@ static int process_sample_event(const struct perf_tool *tool __maybe_unused,
 		 * Doing node stats only for single callchain data.
 		 */
 		int cpu = sample->cpu == (unsigned int) -1 ? 0 : sample->cpu;
-		int node = c2c.cpu2node[cpu];
+		int node;
+
+		/* cpu2node[] has c2c.cpus_cnt entries; large u32 wraps signed negative */
+		if (cpu < 0 || cpu >= c2c.cpus_cnt)
+			cpu = 0;
+		node = c2c.cpu2node[cpu];
 
 		c2c_hists = he__get_c2c_hists(he, c2c.cl_sort, 2, machine->env);
 		if (!c2c_hists) {
@@ -405,7 +418,9 @@ static int process_sample_event(const struct perf_tool *tool __maybe_unused,
 		c2c_he = container_of(he, struct c2c_hist_entry, he);
 		c2c_add_stats(&c2c_he->stats, &stats);
 		c2c_add_stats(&c2c_hists->stats, &stats);
-		c2c_add_stats(&c2c_he->node_stats[node], &stats);
+		/* node_stats[] has c2c.nodes_cnt entries */
+		if (node >= 0 && node < c2c.nodes_cnt)
+			c2c_add_stats(&c2c_he->node_stats[node], &stats);
 
 		compute_stats(c2c_he, &stats, sample->weight);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0942/2077] perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (940 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0941/2077] perf c2c: Bounds-check CPU and node IDs before bitmap and array access Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0943/2077] perf sched: Clean up idle_threads entry on init failure Greg Kroah-Hartman
                   ` (55 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Jiri Olsa, Namhyung Kim,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 5fb2e6ad8c5d6b3b380f94c7456595511f3731be ]

setup_nodes() iterates CPU maps from the perf.data topology header and
uses cpu.cpu directly as an array index into cpu2node[] (allocated with
c2c.cpus_cnt = env->nr_cpus_avail entries) and __set_bit(cpu.cpu, set)
(bitmap also sized to c2c.cpus_cnt).

A crafted perf.data with topology CPU IDs exceeding nr_cpus_avail causes
out-of-bounds heap writes into both the cpu2node array and the per-node
bitmap.

Add a bounds check to skip CPU IDs that fall outside the valid range.

Fixes: 1e181b92a2da ("perf c2c report: Add 'node' sort key")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-c2c.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/tools/perf/builtin-c2c.c b/tools/perf/builtin-c2c.c
index e2a7ffd4192e47..8296ec85e8595c 100644
--- a/tools/perf/builtin-c2c.c
+++ b/tools/perf/builtin-c2c.c
@@ -2366,6 +2366,10 @@ static int setup_nodes(struct perf_session *session)
 		nodes[node] = set;
 
 		perf_cpu_map__for_each_cpu_skip_any(cpu, idx, map) {
+			/* topology CPU IDs from perf.data may exceed nr_cpus_avail */
+			if (cpu.cpu < 0 || cpu.cpu >= c2c.cpus_cnt)
+				continue;
+
 			__set_bit(cpu.cpu, set);
 
 			if (WARN_ONCE(cpu2node[cpu.cpu] != -1, "node/cpu topology bug"))
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0943/2077] perf sched: Clean up idle_threads entry on init failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (941 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0942/2077] perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0944/2077] perf sched: Use is_idle_sample() for idle thread runtime cast guard Greg Kroah-Hartman
                   ` (54 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, David Ahern,
	Namhyung Kim, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit cda5a94ad9181cd60cbf04be11d524201bf489a2 ]

get_idle_thread() allocates a thread via thread__new() and stores it in
idle_threads[cpu], then calls init_idle_thread() to set up the private
data.  If init_idle_thread() fails (e.g. OOM for the idle_thread_runtime
struct), the function returns NULL but leaves the partially initialized
thread in idle_threads[cpu].

On subsequent calls for the same CPU, get_idle_thread() finds a non-NULL
idle_threads[cpu], skips allocation, and returns thread__get() on a
thread that has no priv data.  Callers then get a thread whose
thread__priv() returns NULL, leading to unexpected behavior.

Release the thread and reset the slot to NULL on init failure so the
entry doesn't persist in a corrupted state.

Fixes: 49394a2a24c7 ("perf sched timehist: Introduce timehist command")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: David Ahern <dsahern@gmail.com>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index cca9719558463b..fc8ae0342dd6c2 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -2514,8 +2514,11 @@ static struct thread *get_idle_thread(int cpu)
 		idle_threads[cpu] = thread__new(0, 0);
 
 		if (idle_threads[cpu]) {
-			if (init_idle_thread(idle_threads[cpu]) < 0)
+			if (init_idle_thread(idle_threads[cpu]) < 0) {
+				/* clean up so next call doesn't find a half-initialized thread */
+				thread__zput(idle_threads[cpu]);
 				return NULL;
+			}
 		}
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0944/2077] perf sched: Use is_idle_sample() for idle thread runtime cast guard
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (942 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0943/2077] perf sched: Clean up idle_threads entry on init failure Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0945/2077] perf sched: Fix thread reference leak in idle hist processing Greg Kroah-Hartman
                   ` (53 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Namhyung Kim,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit c9b3054c99cafd5f5f92158101760992a83e5a5e ]

timehist_sched_change_event() uses thread__tid(thread) == 0 to decide
whether to cast thread_runtime to idle_thread_runtime.  However, a
crafted perf.data can set common_pid=0 and common_tid=0 (the perf_sample
fields) while prev_pid != 0 (the tracepoint field).  is_idle_sample()
returns false (it checks prev_pid for sched_switch), so
timehist_get_thread() goes through machine__findnew_thread() and returns
the machine's TID 0 thread — whose priv data is a regular thread_runtime,
not the larger idle_thread_runtime allocated by init_idle_thread().

The subsequent cast to idle_thread_runtime reads past the thread_runtime
allocation, accessing itr->last_thread, itr->cursor, and itr->callchain
from adjacent heap memory.  Writing to itr->last_thread corrupts the
heap; calling thread__put() on the OOB value frees an arbitrary pointer.

Replace the thread__tid() == 0 check with is_idle_sample(), which uses
the tracepoint-specific prev_pid field and correctly identifies whether
the sample originated from an idle thread with idle_thread_runtime priv.

Fixes: 5d8f17fb5822 ("perf sched timehist: Add -I/--idle-hist option")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index fc8ae0342dd6c2..9ea3416f30ac6d 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -2904,7 +2904,13 @@ static int timehist_sched_change_event(const struct perf_tool *tool,
 			t = ptime->end;
 	}
 
-	if (!sched->idle_hist || thread__tid(thread) == 0) {
+	/*
+	 * Use is_idle_sample() not thread__tid() == 0: a crafted perf.data
+	 * can set common_pid=0 with prev_pid!=0, giving us a machine thread
+	 * whose priv is thread_runtime, not idle_thread_runtime — the cast
+	 * below would read past the allocation.
+	 */
+	if (!sched->idle_hist || is_idle_sample(sample)) {
 		if (!cpu_list || (sample->cpu < MAX_NR_CPUS &&
 				 test_bit(sample->cpu, cpu_bitmap)))
 			timehist_update_runtime_stats(tr, t, tprev);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0945/2077] perf sched: Fix thread reference leak in idle hist processing
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (943 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0944/2077] perf sched: Use is_idle_sample() for idle thread runtime cast guard Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0946/2077] perf sched: Use thread__put() in free_idle_threads() Greg Kroah-Hartman
                   ` (52 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, David Ahern,
	Namhyung Kim, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 662d56d48e527ee21a0b03082ee318258a6f7919 ]

timehist_sched_change_event() sets itr->last_thread to NULL at the end
of idle hist processing without calling thread__put() first.  The
thread reference was acquired via thread__get() in timehist_get_thread()
(line 2581), so every idle context switch leaks a thread reference when
--idle-hist is active.

Use thread__zput() to properly release the reference before clearing
the pointer.

Fixes: 5d8f17fb5822 ("perf sched timehist: Add -I/--idle-hist option")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: David Ahern <dsahern@gmail.com>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 9ea3416f30ac6d..7222fe428e7fa7 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -2942,7 +2942,7 @@ static int timehist_sched_change_event(const struct perf_tool *tool,
 			if (itr->cursor.nr)
 				callchain_append(&itr->callchain, &itr->cursor, t - tprev);
 
-			itr->last_thread = NULL;
+			thread__zput(itr->last_thread);
 		}
 
 		if (!sched->summary_only)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0946/2077] perf sched: Use thread__put() in free_idle_threads()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (944 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0945/2077] perf sched: Fix thread reference leak in idle hist processing Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0947/2077] perf sched: Replace BUG_ON and add NULL checks in replay event helpers Greg Kroah-Hartman
                   ` (51 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, David Ahern,
	Namhyung Kim, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit a99d6394cd48fed75b1d24733d5afe6837a61a3f ]

free_idle_threads() calls thread__delete() directly instead of
thread__put(), bypassing the reference counting lifecycle.  Under
REFCNT_CHECKING builds, this leaks the pointer handle since
thread__delete() frees the object without going through the refcount
wrapper.

The idle threads are created via thread__new() (refcount=1) in
get_idle_thread().  Callers get additional references via thread__get()
which they release with thread__put().  free_idle_threads() drops the
base reference — thread__put() is the correct call, matching the
thread__new() acquisition.

Fixes: 49394a2a24c7 ("perf sched timehist: Introduce timehist command")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: David Ahern <dsahern@gmail.com>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 7222fe428e7fa7..3646b0eaf44438 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -2481,7 +2481,7 @@ static void free_idle_threads(void)
 			if (itr)
 				thread__put(itr->last_thread);
 
-			thread__delete(idle);
+			thread__put(idle);
 		}
 	}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0947/2077] perf sched: Replace BUG_ON and add NULL checks in replay event helpers
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (945 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0946/2077] perf sched: Use thread__put() in free_idle_threads() Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0948/2077] perf mmap: Fix NULL deref in aio cleanup on alloc failure Greg Kroah-Hartman
                   ` (50 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ingo Molnar,
	Namhyung Kim, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 75eafe4a3a93a0143a20c0cc286bfb9008ac1478 ]

get_new_event() has three issues:

1. The zalloc() result is dereferenced without a NULL check, crashing
   on allocation failure.

2. BUG_ON(!task->atoms) kills the process when realloc() fails.
   Since perf.data is untrusted input, this should be a graceful error.

3. The realloc pattern assigns directly to task->atoms, losing the old
   pointer on failure.  task->nr_events is also incremented before the
   realloc, leaving corrupted state on failure.

Fix get_new_event() to:
  - Check the zalloc() result before dereferencing
  - Use a temporary for realloc() to avoid losing the old pointer
  - Increment nr_events only after successful realloc
  - Return NULL instead of calling BUG_ON on failure

Also fix add_sched_event_wakeup() where zalloc() for wait_sem is
passed to sem_init() without a NULL check.

Update all callers (add_sched_event_run, add_sched_event_wakeup,
add_sched_event_sleep) to handle NULL returns by returning early.
The replay may produce incomplete output on OOM but will not crash.

Fixes: ec156764d424 ("perf sched: Import schedbench.c")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Ingo Molnar <mingo@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 28 +++++++++++++++++++++++++---
 1 file changed, 25 insertions(+), 3 deletions(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 3646b0eaf44438..70157fcd20f2cc 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -365,14 +365,25 @@ get_new_event(struct task_desc *task, u64 timestamp)
 	struct sched_atom *event = zalloc(sizeof(*event));
 	unsigned long idx = task->nr_events;
 	size_t size;
+	struct sched_atom **atoms_p;
+
+	if (event == NULL) {
+		pr_err("ERROR: sched: failed to allocate event\n");
+		return NULL;
+	}
 
 	event->timestamp = timestamp;
 	event->nr = idx;
 
+	size = sizeof(struct sched_atom *) * (task->nr_events + 1);
+	atoms_p = realloc(task->atoms, size);
+	if (!atoms_p) {
+		pr_err("ERROR: sched: failed to grow atoms array\n");
+		free(event);
+		return NULL;
+	}
+	task->atoms = atoms_p;
 	task->nr_events++;
-	size = sizeof(struct sched_atom *) * task->nr_events;
-	task->atoms = realloc(task->atoms, size);
-	BUG_ON(!task->atoms);
 
 	task->atoms[idx] = event;
 
@@ -403,6 +414,8 @@ static void add_sched_event_run(struct perf_sched *sched, struct task_desc *task
 	}
 
 	event = get_new_event(task, timestamp);
+	if (event == NULL)
+		return;
 
 	event->type = SCHED_EVENT_RUN;
 	event->duration = duration;
@@ -416,6 +429,8 @@ static void add_sched_event_wakeup(struct perf_sched *sched, struct task_desc *t
 	struct sched_atom *event, *wakee_event;
 
 	event = get_new_event(task, timestamp);
+	if (event == NULL)
+		return;
 	event->type = SCHED_EVENT_WAKEUP;
 	event->wakee = wakee;
 
@@ -430,6 +445,10 @@ static void add_sched_event_wakeup(struct perf_sched *sched, struct task_desc *t
 	}
 
 	wakee_event->wait_sem = zalloc(sizeof(*wakee_event->wait_sem));
+	if (!wakee_event->wait_sem) {
+		pr_err("ERROR: sched: failed to allocate semaphore\n");
+		return;
+	}
 	sem_init(wakee_event->wait_sem, 0, 0);
 	event->wait_sem = wakee_event->wait_sem;
 
@@ -441,6 +460,9 @@ static void add_sched_event_sleep(struct perf_sched *sched, struct task_desc *ta
 {
 	struct sched_atom *event = get_new_event(task, timestamp);
 
+	if (event == NULL)
+		return;
+
 	event->type = SCHED_EVENT_SLEEP;
 
 	sched->nr_sleep_events++;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0948/2077] perf mmap: Fix NULL deref in aio cleanup on alloc failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (946 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0947/2077] perf sched: Replace BUG_ON and add NULL checks in replay event helpers Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0949/2077] perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu Greg Kroah-Hartman
                   ` (49 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Alexey Budankov,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 25627346b10e6a564610ea2c49dc6dd54812226d ]

perf_mmap__aio_mmap() sets map->aio.nr_cblocks before allocating the
data array.  If calloc() for aiocb or cblocks fails before the data
array is allocated, the return -1 path leads to perf_mmap__aio_munmap()
which loops nr_cblocks times calling perf_mmap__aio_free().  Both
versions of perf_mmap__aio_free() (NUMA and non-NUMA) dereference
map->aio.data[idx] without checking if data is NULL, causing a NULL
pointer dereference.

Add NULL checks for map->aio.data at the top of both
perf_mmap__aio_free() variants so the cleanup path is safe when
allocation fails partway through perf_mmap__aio_mmap().

Fixes: d3d1af6f011a553a ("perf record: Enable asynchronous trace writing")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Alexey Budankov <alexey.budankov@linux.intel.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/mmap.c | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/tools/perf/util/mmap.c b/tools/perf/util/mmap.c
index 4404a99eee45f9..d64aec6c7c843e 100644
--- a/tools/perf/util/mmap.c
+++ b/tools/perf/util/mmap.c
@@ -89,10 +89,10 @@ static int perf_mmap__aio_alloc(struct mmap *map, int idx)
 
 static void perf_mmap__aio_free(struct mmap *map, int idx)
 {
-	if (map->aio.data[idx]) {
-		munmap(map->aio.data[idx], mmap__mmap_len(map));
-		map->aio.data[idx] = NULL;
-	}
+	if (!map->aio.data || !map->aio.data[idx])
+		return;
+	munmap(map->aio.data[idx], mmap__mmap_len(map));
+	map->aio.data[idx] = NULL;
 }
 
 static int perf_mmap__aio_bind(struct mmap *map, int idx, struct perf_cpu cpu, int affinity)
@@ -141,6 +141,8 @@ static int perf_mmap__aio_alloc(struct mmap *map, int idx)
 
 static void perf_mmap__aio_free(struct mmap *map, int idx)
 {
+	if (!map->aio.data)
+		return;
 	zfree(&(map->aio.data[idx]));
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0949/2077] perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (947 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0948/2077] perf mmap: Fix NULL deref in aio cleanup on alloc failure Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0950/2077] perf c2c: Fix use-after-free in he__get_c2c_hists() error path Greg Kroah-Hartman
                   ` (48 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit afa4363a91a19dff65dceb7fbce7bba689bbc854 ]

process_cpu_topology() in header.c frees env->cpu on old-format
perf.data files that predate topology information, but leaves
nr_cpus_avail set.  The six perf_env__get_*_aggr_by_cpu() functions
in builtin-stat.c pass the bounds check but dereference a NULL
env->cpu pointer, crashing on old recordings.

Introduce perf_env__get_cpu_topology() as a safe accessor that
validates env->cpu, cpu.cpu >= 0, and cpu.cpu < nr_cpus_avail in
one place, returning a struct cpu_topology_map pointer or NULL.
Convert all six topology aggregation callbacks to use it.

Fixes: 88031a0de7d68d13 ("perf stat: Switch to cpu version of cpu_map__get()")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-stat.c | 51 +++++++++++++++++++++------------------
 tools/perf/util/env.h     | 14 +++++++++++
 2 files changed, 42 insertions(+), 23 deletions(-)

diff --git a/tools/perf/builtin-stat.c b/tools/perf/builtin-stat.c
index 9a045811c4197c..a04466ea3b0a06 100644
--- a/tools/perf/builtin-stat.c
+++ b/tools/perf/builtin-stat.c
@@ -1637,10 +1637,10 @@ static struct aggr_cpu_id perf_env__get_socket_aggr_by_cpu(struct perf_cpu cpu,
 {
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
+	struct cpu_topology_map *topo = perf_env__get_cpu_topology(env, cpu);
 
-	/* env->cpu[] has env->nr_cpus_avail entries; reject untrusted indices */
-	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail)
-		id.socket = env->cpu[cpu.cpu].socket_id;
+	if (topo)
+		id.socket = topo->socket_id;
 
 	return id;
 }
@@ -1649,15 +1649,16 @@ static struct aggr_cpu_id perf_env__get_die_aggr_by_cpu(struct perf_cpu cpu, voi
 {
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
+	struct cpu_topology_map *topo = perf_env__get_cpu_topology(env, cpu);
 
-	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail) {
+	if (topo) {
 		/*
 		 * die_id is relative to socket, so start
 		 * with the socket ID and then add die to
 		 * make a unique ID.
 		 */
-		id.socket = env->cpu[cpu.cpu].socket_id;
-		id.die = env->cpu[cpu.cpu].die_id;
+		id.socket = topo->socket_id;
+		id.die = topo->die_id;
 	}
 
 	return id;
@@ -1705,12 +1706,13 @@ static struct aggr_cpu_id perf_env__get_cache_aggr_by_cpu(struct perf_cpu cpu,
 {
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
+	struct cpu_topology_map *topo = perf_env__get_cpu_topology(env, cpu);
 
-	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail) {
+	if (topo) {
 		u32 cache_level = (perf_stat.aggr_level) ?: stat_config.aggr_level;
 
-		id.socket = env->cpu[cpu.cpu].socket_id;
-		id.die = env->cpu[cpu.cpu].die_id;
+		id.socket = topo->socket_id;
+		id.die = topo->die_id;
 		perf_env__get_cache_id_for_cpu(cpu, env, cache_level, &id);
 	}
 
@@ -1722,11 +1724,12 @@ static struct aggr_cpu_id perf_env__get_cluster_aggr_by_cpu(struct perf_cpu cpu,
 {
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
+	struct cpu_topology_map *topo = perf_env__get_cpu_topology(env, cpu);
 
-	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail) {
-		id.socket = env->cpu[cpu.cpu].socket_id;
-		id.die = env->cpu[cpu.cpu].die_id;
-		id.cluster = env->cpu[cpu.cpu].cluster_id;
+	if (topo) {
+		id.socket = topo->socket_id;
+		id.die = topo->die_id;
+		id.cluster = topo->cluster_id;
 	}
 
 	return id;
@@ -1736,16 +1739,17 @@ static struct aggr_cpu_id perf_env__get_core_aggr_by_cpu(struct perf_cpu cpu, vo
 {
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
+	struct cpu_topology_map *topo = perf_env__get_cpu_topology(env, cpu);
 
-	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail) {
+	if (topo) {
 		/*
 		 * core_id is relative to socket, die and cluster, we need a
 		 * global id. So we set socket, die id, cluster id and core id.
 		 */
-		id.socket = env->cpu[cpu.cpu].socket_id;
-		id.die = env->cpu[cpu.cpu].die_id;
-		id.cluster = env->cpu[cpu.cpu].cluster_id;
-		id.core = env->cpu[cpu.cpu].core_id;
+		id.socket = topo->socket_id;
+		id.die = topo->die_id;
+		id.cluster = topo->cluster_id;
+		id.core = topo->core_id;
 	}
 
 	return id;
@@ -1755,18 +1759,19 @@ static struct aggr_cpu_id perf_env__get_cpu_aggr_by_cpu(struct perf_cpu cpu, voi
 {
 	struct perf_env *env = data;
 	struct aggr_cpu_id id = aggr_cpu_id__empty();
+	struct cpu_topology_map *topo = perf_env__get_cpu_topology(env, cpu);
 
-	if (cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail) {
+	if (topo) {
 		/*
 		 * core_id is relative to socket and die,
 		 * we need a global id. So we set
 		 * socket, die id and core id
 		 */
-		id.socket = env->cpu[cpu.cpu].socket_id;
-		id.die = env->cpu[cpu.cpu].die_id;
-		id.core = env->cpu[cpu.cpu].core_id;
-		id.cpu = cpu;
+		id.socket = topo->socket_id;
+		id.die = topo->die_id;
+		id.core = topo->core_id;
 	}
+	id.cpu = cpu;
 
 	return id;
 }
diff --git a/tools/perf/util/env.h b/tools/perf/util/env.h
index c7052ac1f8562c..25ba16290280d7 100644
--- a/tools/perf/util/env.h
+++ b/tools/perf/util/env.h
@@ -185,6 +185,20 @@ const char *perf_env__pmu_mappings(struct perf_env *env);
 
 int perf_env__read_cpu_topology_map(struct perf_env *env);
 
+/*
+ * Safe accessor for env->cpu[] topology array.  env->cpu can be NULL when
+ * reading old-format perf.data that predates topology information —
+ * process_cpu_topology() in header.c frees it while nr_cpus_avail remains
+ * set, so callers must not index env->cpu[] without this check.
+ */
+static inline struct cpu_topology_map *
+perf_env__get_cpu_topology(struct perf_env *env, struct perf_cpu cpu)
+{
+	if (env->cpu && cpu.cpu >= 0 && cpu.cpu < env->nr_cpus_avail)
+		return &env->cpu[cpu.cpu];
+	return NULL;
+}
+
 void cpu_cache_level__free(struct cpu_cache_level *cache);
 
 const char *perf_env__arch(struct perf_env *env);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0950/2077] perf c2c: Fix use-after-free in he__get_c2c_hists() error path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (948 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0949/2077] perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0951/2077] perf timechart: Fix cpu2y() OOB read on untrusted CPU index Greg Kroah-Hartman
                   ` (47 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Jiri Olsa,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 5e5e6196d737c5be03d20647428316b36621608d ]

he__get_c2c_hists() assigns c2c_he->hists before calling
c2c_hists__init().  If init fails, the error path calls free(hists)
but leaves c2c_he->hists pointing to freed memory.  On teardown,
c2c_he_free() finds the non-NULL pointer and calls
hists__delete_entries() on it, causing a use-after-free.

Set c2c_he->hists to NULL before freeing so teardown skips the
already-freed allocation.

Fixes: b2252ae67b687d2b ("perf c2c report: Decode c2c_stats for hist entries")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-c2c.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/tools/perf/builtin-c2c.c b/tools/perf/builtin-c2c.c
index 8296ec85e8595c..74ded7d238c800 100644
--- a/tools/perf/builtin-c2c.c
+++ b/tools/perf/builtin-c2c.c
@@ -221,6 +221,7 @@ he__get_c2c_hists(struct hist_entry *he,
 
 	ret = c2c_hists__init(hists, sort, nr_header_lines, env);
 	if (ret) {
+		c2c_he->hists = NULL;
 		free(hists);
 		return NULL;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0951/2077] perf timechart: Fix cpu2y() OOB read on untrusted CPU index
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (949 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0950/2077] perf c2c: Fix use-after-free in he__get_c2c_hists() error path Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0952/2077] perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num() Greg Kroah-Hartman
                   ` (46 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Stanislav Fomichev,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit e2496db45bfd8dfb6154ec415798fee330f1cc0a ]

cpu2y() indexes topology_map[cpu] without bounds checking.  The array
is allocated with nr_cpus entries (from env->nr_cpus_online), but
callers pass sample CPU values from perf.data which can exceed that
size with cross-machine recordings.

Track the topology_map allocation size and bounds-check the CPU
argument in cpu2y() before indexing.  Out-of-bounds CPUs fall back
to the identity mapping (cpu2slot(cpu)), which is the same behavior
as when no topology is available.

Fixes: c507999790438cde ("perf timechart: Add support for topology")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Stanislav Fomichev <stfomichev@yandex-team.ru>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/svghelper.c | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/tools/perf/util/svghelper.c b/tools/perf/util/svghelper.c
index e360e7736c7ba6..826bd2577344b2 100644
--- a/tools/perf/util/svghelper.c
+++ b/tools/perf/util/svghelper.c
@@ -47,13 +47,13 @@ static double cpu2slot(int cpu)
 }
 
 static int *topology_map;
+static int topology_map_size;
 
 static double cpu2y(int cpu)
 {
-	if (topology_map)
+	if (topology_map && cpu >= 0 && cpu < topology_map_size)
 		return cpu2slot(topology_map[cpu]) * SLOT_MULT;
-	else
-		return cpu2slot(cpu) * SLOT_MULT;
+	return cpu2slot(cpu) * SLOT_MULT;
 }
 
 static double time2pixels(u64 __time)
@@ -736,7 +736,8 @@ static int str_to_bitmap(char *s, cpumask_t *b, int nr_cpus)
 		return -1;
 
 	perf_cpu_map__for_each_cpu(cpu, idx, map) {
-		if (cpu.cpu >= nr_cpus) {
+		/* perf_cpu_map__new("") returns cpu.cpu == -1 */
+		if (cpu.cpu < 0 || cpu.cpu >= nr_cpus) {
 			ret = -1;
 			break;
 		}
@@ -794,6 +795,7 @@ int svg_build_topology_map(struct perf_env *env)
 		fprintf(stderr, "topology: no memory\n");
 		goto exit;
 	}
+	topology_map_size = nr_cpus;
 
 	for (i = 0; i < nr_cpus; i++)
 		topology_map[i] = -1;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0952/2077] perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (950 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0951/2077] perf timechart: Fix cpu2y() OOB read on untrusted CPU index Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0953/2077] perf sched: Free callchain nodes in idle thread cleanup Greg Kroah-Hartman
                   ` (45 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 33fa2bf5608fc36bc25231592145f4738f14f11b ]

set_max_cpu_num() assigns the sysfs "possible" CPU count to
max_cpu_num.cpu which is int16_t (struct perf_cpu).  On systems
with >32767 possible CPUs the value silently truncates, potentially
wrapping negative.  This causes cpunode_map to be underallocated
and subsequent cpu__get_node() calls to read out of bounds.

The matching check for max_present_cpu_num was added by commit
c760174401f6 ("perf cpumap: Reduce cpu size from int to int16_t")
but max_cpu_num was missed.  Add the same INT16_MAX guard.

Fixes: c760174401f605cf ("perf cpumap: Reduce cpu size from int to int16_t")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/cpumap.c | 21 +++++++++++++++++----
 1 file changed, 17 insertions(+), 4 deletions(-)

diff --git a/tools/perf/util/cpumap.c b/tools/perf/util/cpumap.c
index 19783c83765726..b754e331bdfe8c 100644
--- a/tools/perf/util/cpumap.c
+++ b/tools/perf/util/cpumap.c
@@ -466,6 +466,16 @@ static void set_max_cpu_num(void)
 	if (ret)
 		goto out;
 
+	/*
+	 * struct perf_cpu.cpu is int16_t (libperf ABI) — clamp to avoid
+	 * truncation to negative.  See tools/lib/perf/TODO for the ABI
+	 * widening plan.
+	 */
+	if (max > INT16_MAX) {
+		pr_warning("WARNING: max possible cpus %d exceeds int16_t, clamping to %d\n",
+			   max, INT16_MAX);
+		max = INT16_MAX;
+	}
 	max_cpu_num.cpu = max;
 
 	/* get the highest present cpu number for a sparse allocation */
@@ -478,11 +488,12 @@ static void set_max_cpu_num(void)
 	ret = get_max_num(path, &max);
 
 	if (!ret && max > INT16_MAX) {
-		pr_err("Read out of bounds max cpus of %d\n", max);
-		ret = -1;
+		pr_warning("WARNING: max present cpus %d exceeds int16_t, clamping to %d\n",
+			   max, INT16_MAX);
+		max = INT16_MAX;
 	}
 	if (!ret)
-		max_present_cpu_num.cpu = (int16_t)max;
+		max_present_cpu_num.cpu = max;
 out:
 	if (ret)
 		pr_err("Failed to read max cpus, using default of %d\n", max_cpu_num.cpu);
@@ -619,7 +630,9 @@ int cpu__setup_cpunode_map(void)
 		while ((dent2 = readdir(dir2)) != NULL) {
 			if (dent2->d_type != DT_LNK || sscanf(dent2->d_name, "cpu%u", &cpu) < 1)
 				continue;
-			cpunode_map[cpu] = mem;
+			/* cpunode_map allocated for max_cpu_num entries */
+			if (cpu < (unsigned int)max_cpu_num.cpu)
+				cpunode_map[cpu] = mem;
 		}
 		closedir(dir2);
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0953/2077] perf sched: Free callchain nodes in idle thread cleanup
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (951 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0952/2077] perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num() Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0954/2077] dt-bindings: clock: qcom: Add X1P42100 camera clock controller Greg Kroah-Hartman
                   ` (44 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Namhyung Kim,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit c3e51ed45ffa7547495a851e33ce332f81ef3665 ]

free_idle_threads() relies on the thread priv destructor (free()) to
clean up idle_thread_runtime structs.  But free() doesn't walk the
callchain_cursor linked list or the callchain_root tree allocated
by callchain_cursor__copy() and callchain_append() during --idle-hist
processing.  Every idle thread with callchain data leaks these nodes.

Introduce callchain_cursor_cleanup() to free the cursor's linked list
of callchain_cursor_node entries, and call it together with
free_callchain() in free_idle_threads() before thread__put().

Fixes: 225b24f569980ac9 ("perf sched timehist: Save callchain when entering idle")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c  |  5 ++++-
 tools/perf/util/callchain.c | 15 +++++++++++++++
 tools/perf/util/callchain.h |  1 +
 3 files changed, 20 insertions(+), 1 deletion(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 70157fcd20f2cc..defbf8dc26073c 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -2500,8 +2500,11 @@ static void free_idle_threads(void)
 			struct idle_thread_runtime *itr;
 
 			itr = thread__priv(idle);
-			if (itr)
+			if (itr) {
 				thread__put(itr->last_thread);
+				free_callchain(&itr->callchain);
+				callchain_cursor_cleanup(&itr->cursor);
+			}
 
 			thread__put(idle);
 		}
diff --git a/tools/perf/util/callchain.c b/tools/perf/util/callchain.c
index f031cbbeeba8b7..5e0498a1faf8a7 100644
--- a/tools/perf/util/callchain.c
+++ b/tools/perf/util/callchain.c
@@ -1578,6 +1578,21 @@ void free_callchain(struct callchain_root *root)
 	free_callchain_node(&root->node);
 }
 
+void callchain_cursor_cleanup(struct callchain_cursor *cursor)
+{
+	struct callchain_cursor_node *node, *next;
+
+	callchain_cursor_reset(cursor);
+
+	for (node = cursor->first; node; node = next) {
+		next = node->next;
+		free(node);
+	}
+	cursor->first = NULL;
+	cursor->last = &cursor->first;
+	cursor->curr = NULL;
+}
+
 static u64 decay_callchain_node(struct callchain_node *node)
 {
 	struct callchain_node *child;
diff --git a/tools/perf/util/callchain.h b/tools/perf/util/callchain.h
index 06d463ccc7a04f..60008f379b2289 100644
--- a/tools/perf/util/callchain.h
+++ b/tools/perf/util/callchain.h
@@ -290,6 +290,7 @@ int callchain_list_counts__printf_value(struct callchain_list *clist,
 					FILE *fp, char *bf, int bfsize);
 
 void free_callchain(struct callchain_root *root);
+void callchain_cursor_cleanup(struct callchain_cursor *cursor);
 void decay_callchain(struct callchain_root *root);
 int callchain_node__make_parent_list(struct callchain_node *node);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0954/2077] dt-bindings: clock: qcom: Add X1P42100 camera clock controller
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (952 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0953/2077] perf sched: Free callchain nodes in idle thread cleanup Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0955/2077] clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks Greg Kroah-Hartman
                   ` (43 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Jagadeesh Kona,
	Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jagadeesh Kona <jagadeesh.kona@oss.qualcomm.com>

[ Upstream commit 97a5e120be5d3d7cf7d221b8703921046b73f0d2 ]

Add X1P42100 camera clock controller support and clock bindings
for camera QDSS debug clocks which are applicable for both X1E80100
and X1P42100 platforms.

Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Jagadeesh Kona <jagadeesh.kona@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260507-purwa-videocc-camcc-v5-2-fc3af4130282@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 1e6ae74ac6f2 ("clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 .../devicetree/bindings/clock/qcom,x1e80100-camcc.yaml         | 1 +
 include/dt-bindings/clock/qcom,x1e80100-camcc.h                | 3 +++
 2 files changed, 4 insertions(+)

diff --git a/Documentation/devicetree/bindings/clock/qcom,x1e80100-camcc.yaml b/Documentation/devicetree/bindings/clock/qcom,x1e80100-camcc.yaml
index 938a2f1ff3fca8..b28614186cc098 100644
--- a/Documentation/devicetree/bindings/clock/qcom,x1e80100-camcc.yaml
+++ b/Documentation/devicetree/bindings/clock/qcom,x1e80100-camcc.yaml
@@ -23,6 +23,7 @@ properties:
   compatible:
     enum:
       - qcom,x1e80100-camcc
+      - qcom,x1p42100-camcc
 
   reg:
     maxItems: 1
diff --git a/include/dt-bindings/clock/qcom,x1e80100-camcc.h b/include/dt-bindings/clock/qcom,x1e80100-camcc.h
index d72fdfb06a7c71..06c316022fb0d2 100644
--- a/include/dt-bindings/clock/qcom,x1e80100-camcc.h
+++ b/include/dt-bindings/clock/qcom,x1e80100-camcc.h
@@ -115,6 +115,9 @@
 #define CAM_CC_SLEEP_CLK_SRC					105
 #define CAM_CC_SLOW_AHB_CLK_SRC					106
 #define CAM_CC_XO_CLK_SRC					107
+#define CAM_CC_QDSS_DEBUG_CLK					108
+#define CAM_CC_QDSS_DEBUG_CLK_SRC				109
+#define CAM_CC_QDSS_DEBUG_XO_CLK				110
 
 /* CAM_CC power domains */
 #define CAM_CC_BPS_GDSC						0
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0955/2077] clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (953 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0954/2077] dt-bindings: clock: qcom: Add X1P42100 camera clock controller Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0956/2077] docs: memfd_preservation: fix rendering of ABI documentation Greg Kroah-Hartman
                   ` (42 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Bryan ODonoghue,
	Jagadeesh Kona, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jagadeesh Kona <jagadeesh.kona@oss.qualcomm.com>

[ Upstream commit 1e6ae74ac6f28ace7a0eb84897c6e17bb044e5de ]

Add support for camera QDSS debug clocks on X1E80100 platform which
are required to be voted for camera icp and cpas usecases. This change
aligns the camcc driver to the new ABI exposed from X1E80100 camcc
bindings that supports these camcc QDSS debug clocks.

Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
Signed-off-by: Jagadeesh Kona <jagadeesh.kona@oss.qualcomm.com>
Fixes: 76126a5129b5 ("clk: qcom: Add camcc clock driver for x1e80100")
Link: https://lore.kernel.org/r/20260507-purwa-videocc-camcc-v5-4-fc3af4130282@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clk/qcom/camcc-x1e80100.c | 64 +++++++++++++++++++++++++++++++
 1 file changed, 64 insertions(+)

diff --git a/drivers/clk/qcom/camcc-x1e80100.c b/drivers/clk/qcom/camcc-x1e80100.c
index 81f579ff699334..c12994af42cfc4 100644
--- a/drivers/clk/qcom/camcc-x1e80100.c
+++ b/drivers/clk/qcom/camcc-x1e80100.c
@@ -1052,6 +1052,31 @@ static struct clk_rcg2 cam_cc_mclk7_clk_src = {
 	},
 };
 
+static const struct freq_tbl ftbl_cam_cc_qdss_debug_clk_src[] = {
+	F(19200000, P_BI_TCXO, 1, 0, 0),
+	F(60000000, P_CAM_CC_PLL8_OUT_EVEN, 8, 0, 0),
+	F(75000000, P_CAM_CC_PLL0_OUT_EVEN, 8, 0, 0),
+	F(150000000, P_CAM_CC_PLL0_OUT_EVEN, 4, 0, 0),
+	F(300000000, P_CAM_CC_PLL0_OUT_MAIN, 4, 0, 0),
+	{ }
+};
+
+static struct clk_rcg2 cam_cc_qdss_debug_clk_src = {
+	.cmd_rcgr = 0x13938,
+	.mnd_width = 0,
+	.hid_width = 5,
+	.parent_map = cam_cc_parent_map_0,
+	.freq_tbl = ftbl_cam_cc_qdss_debug_clk_src,
+	.hw_clk_ctrl = true,
+	.clkr.hw.init = &(const struct clk_init_data) {
+		.name = "cam_cc_qdss_debug_clk_src",
+		.parent_data = cam_cc_parent_data_0,
+		.num_parents = ARRAY_SIZE(cam_cc_parent_data_0),
+		.flags = CLK_SET_RATE_PARENT,
+		.ops = &clk_rcg2_shared_ops,
+	},
+};
+
 static const struct freq_tbl ftbl_cam_cc_sfe_0_clk_src[] = {
 	F(345600000, P_CAM_CC_PLL6_OUT_EVEN, 1, 0, 0),
 	F(432000000, P_CAM_CC_PLL6_OUT_EVEN, 1, 0, 0),
@@ -2182,6 +2207,42 @@ static struct clk_branch cam_cc_mclk7_clk = {
 	},
 };
 
+static struct clk_branch cam_cc_qdss_debug_clk = {
+	.halt_reg = 0x13a64,
+	.halt_check = BRANCH_HALT,
+	.clkr = {
+		.enable_reg = 0x13a64,
+		.enable_mask = BIT(0),
+		.hw.init = &(const struct clk_init_data) {
+			.name = "cam_cc_qdss_debug_clk",
+			.parent_hws = (const struct clk_hw*[]) {
+				&cam_cc_qdss_debug_clk_src.clkr.hw,
+			},
+			.num_parents = 1,
+			.flags = CLK_SET_RATE_PARENT,
+			.ops = &clk_branch2_ops,
+		},
+	},
+};
+
+static struct clk_branch cam_cc_qdss_debug_xo_clk = {
+	.halt_reg = 0x13a68,
+	.halt_check = BRANCH_HALT,
+	.clkr = {
+		.enable_reg = 0x13a68,
+		.enable_mask = BIT(0),
+		.hw.init = &(const struct clk_init_data) {
+			.name = "cam_cc_qdss_debug_xo_clk",
+			.parent_hws = (const struct clk_hw*[]) {
+				&cam_cc_xo_clk_src.clkr.hw,
+			},
+			.num_parents = 1,
+			.flags = CLK_SET_RATE_PARENT,
+			.ops = &clk_branch2_ops,
+		},
+	},
+};
+
 static struct clk_branch cam_cc_sfe_0_clk = {
 	.halt_reg = 0x133c0,
 	.halt_check = BRANCH_HALT,
@@ -2398,6 +2459,9 @@ static struct clk_regmap *cam_cc_x1e80100_clocks[] = {
 	[CAM_CC_PLL6_OUT_EVEN] = &cam_cc_pll6_out_even.clkr,
 	[CAM_CC_PLL8] = &cam_cc_pll8.clkr,
 	[CAM_CC_PLL8_OUT_EVEN] = &cam_cc_pll8_out_even.clkr,
+	[CAM_CC_QDSS_DEBUG_CLK] = &cam_cc_qdss_debug_clk.clkr,
+	[CAM_CC_QDSS_DEBUG_CLK_SRC] = &cam_cc_qdss_debug_clk_src.clkr,
+	[CAM_CC_QDSS_DEBUG_XO_CLK] = &cam_cc_qdss_debug_xo_clk.clkr,
 	[CAM_CC_SFE_0_CLK] = &cam_cc_sfe_0_clk.clkr,
 	[CAM_CC_SFE_0_CLK_SRC] = &cam_cc_sfe_0_clk_src.clkr,
 	[CAM_CC_SFE_0_FAST_AHB_CLK] = &cam_cc_sfe_0_fast_ahb_clk.clkr,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0956/2077] docs: memfd_preservation: fix rendering of ABI documentation
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (954 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0955/2077] clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0957/2077] mshv: add bounds check on vp_index in mshv_intercept_isr() Greg Kroah-Hartman
                   ` (41 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Pratyush Yadav (Google),
	Randy Dunlap, Mike Rapoport (Microsoft), Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pratyush Yadav (Google) <pratyush@kernel.org>

[ Upstream commit 3a358c78093f98a70d84c934b7054f636bc846f2 ]

The "memfd Live Update ABI" section in include/linux/kho/abi/memfd.h
currently does not render in the exported documentation. This is because
it should not include the "DOC:" in its reference. Drop it to ensure
correct rendering. Tested by running make htmldocs.

Fixes: 15fc11bb2cb6 ("docs: add documentation for memfd preservation via LUO")
Signed-off-by: Pratyush Yadav (Google) <pratyush@kernel.org>
Tested-by: Randy Dunlap <rdunlap@infradead.org>
Acked-by: Randy Dunlap <rdunlap@infradead.org>
Link: https://patch.msgid.link/20260605160645.3650271-1-pratyush@kernel.org
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 Documentation/mm/memfd_preservation.rst | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/Documentation/mm/memfd_preservation.rst b/Documentation/mm/memfd_preservation.rst
index a8a5b476afd306..c908a12dffa7c0 100644
--- a/Documentation/mm/memfd_preservation.rst
+++ b/Documentation/mm/memfd_preservation.rst
@@ -11,7 +11,7 @@ Memfd Preservation ABI
 ======================
 
 .. kernel-doc:: include/linux/kho/abi/memfd.h
-   :doc: DOC: memfd Live Update ABI
+   :doc: memfd Live Update ABI
 
 .. kernel-doc:: include/linux/kho/abi/memfd.h
    :internal:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0957/2077] mshv: add bounds check on vp_index in mshv_intercept_isr()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (955 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0956/2077] docs: memfd_preservation: fix rendering of ABI documentation Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0958/2077] dmaengine: qcom: gpi: set DMA_PRIVATE capability Greg Kroah-Hartman
                   ` (40 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuhao Jiang, Junrui Luo, Wei Liu,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Junrui Luo <moonafterrain@outlook.com>

[ Upstream commit a4ffc59238be84dd1c26bf1c001543e832674fc6 ]

mshv_intercept_isr() extracts vp_index from the hypervisor message
payload and uses it directly to index into pt_vp_array without
validation. handle_bitset_message() and handle_pair_message() already
validate vp_index against MSHV_MAX_VPS before array access.

Add the same MSHV_MAX_VPS bounds check for consistency with the other
message handlers.

Fixes: 621191d709b1 ("Drivers: hv: Introduce mshv_root module to expose /dev/mshv to VMMs")
Reported-by: Yuhao Jiang <danisjiang@gmail.com>
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
Signed-off-by: Wei Liu <wei.liu@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/hv/mshv_synic.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/hv/mshv_synic.c b/drivers/hv/mshv_synic.c
index 88170ce6b83f07..7c168e5a740dd2 100644
--- a/drivers/hv/mshv_synic.c
+++ b/drivers/hv/mshv_synic.c
@@ -384,6 +384,11 @@ mshv_intercept_isr(struct hv_message *msg)
 	 */
 	vp_index =
 	       ((struct hv_opaque_intercept_message *)msg->u.payload)->vp_index;
+	/* This shouldn't happen, but just in case. */
+	if (unlikely(vp_index >= MSHV_MAX_VPS)) {
+		pr_debug("VP index %u out of bounds\n", vp_index);
+		goto unlock_out;
+	}
 	vp = partition->pt_vp_array[vp_index];
 	if (unlikely(!vp)) {
 		pr_debug("failed to find VP %u\n", vp_index);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0958/2077] dmaengine: qcom: gpi: set DMA_PRIVATE capability
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (956 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0957/2077] mshv: add bounds check on vp_index in mshv_intercept_isr() Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0959/2077] dmaengine: Fix possible use after free Greg Kroah-Hartman
                   ` (39 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Icenowy Zheng, Dmitry Baryshkov,
	Vinod Koul, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Icenowy Zheng <zhengxingda@iscas.ac.cn>

[ Upstream commit 4e351f408743354d54ee1af5193fc78234f2044e ]

The GPI DMA controller is only responsible for QUP peripherals, and
cannot work as a general-purpose DMA accelerator.

Set DMA_PRIVATE capability for it.

This fixes error messages about GPI being shown when an async-tx
consumer is loaded.

Fixes: 5d0c3533a19f ("dmaengine: qcom: Add GPI dma driver")
Signed-off-by: Icenowy Zheng <zhengxingda@iscas.ac.cn>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://patch.msgid.link/20260602070344.3707256-1-zhengxingda@iscas.ac.cn
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dma/qcom/gpi.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/dma/qcom/gpi.c b/drivers/dma/qcom/gpi.c
index c9a6f610ffd9fa..a5055a6273af62 100644
--- a/drivers/dma/qcom/gpi.c
+++ b/drivers/dma/qcom/gpi.c
@@ -2260,6 +2260,7 @@ static int gpi_probe(struct platform_device *pdev)
 	/* clear and Set capabilities */
 	dma_cap_zero(gpi_dev->dma_device.cap_mask);
 	dma_cap_set(DMA_SLAVE, gpi_dev->dma_device.cap_mask);
+	dma_cap_set(DMA_PRIVATE, gpi_dev->dma_device.cap_mask);
 
 	/* configure dmaengine apis */
 	gpi_dev->dma_device.directions = BIT(DMA_DEV_TO_MEM) | BIT(DMA_MEM_TO_DEV);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0959/2077] dmaengine: Fix possible use after free
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (957 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0958/2077] dmaengine: qcom: gpi: set DMA_PRIVATE capability Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0960/2077] dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc Greg Kroah-Hartman
                   ` (38 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nuno Sá, Frank Li, Vinod Koul,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nuno Sá <nuno.sa@analog.com>

[ Upstream commit 92f853f0645aebf1d05d333e97ab7c342ace1892 ]

In dma_release_channel(), check chan->device->privatecnt after call
dma_chan_put(). However, dma_chan_put() call dma_device_put() which could
release the last reference of the device if the DMA provider is already
gone and hence free it.

Fixes it by moving dma_chan_put() after the check.

Fixes: 0f571515c332 ("dmaengine: Add privatecnt to revert DMA_PRIVATE property")
Signed-off-by: Nuno Sá <nuno.sa@analog.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260424-dma-dmac-handle-vunmap-v4-1-90f43412fdc0@analog.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dma/dmaengine.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index 405bd2fbb4a3b9..9049171df85786 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -905,11 +905,12 @@ void dma_release_channel(struct dma_chan *chan)
 	mutex_lock(&dma_list_mutex);
 	WARN_ONCE(chan->client_count != 1,
 		  "chan reference count %d != 1\n", chan->client_count);
-	dma_chan_put(chan);
 	/* drop PRIVATE cap enabled by __dma_request_channel() */
 	if (--chan->device->privatecnt == 0)
 		dma_cap_clear(DMA_PRIVATE, chan->device->cap_mask);
 
+	dma_chan_put(chan);
+
 	if (chan->slave) {
 		sysfs_remove_link(&chan->dev->device.kobj, DMA_SLAVE_NAME);
 		sysfs_remove_link(&chan->slave->kobj, chan->name);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0960/2077] dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (958 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0959/2077] dmaengine: Fix possible use after free Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0961/2077] dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor Greg Kroah-Hartman
                   ` (37 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nuno Sá, Frank Li, Vinod Koul,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nuno Sá <nuno.sa@analog.com>

[ Upstream commit 4910ce1b3b35687bb2a5e742c4bfbea3c647c980 ]

Use axi_dmac_free_desc() to free fully the descriptor at fail path when
call axi_dmac_alloc_desc() in axi_dmac_prep_peripheral_dma_vec().

Fixes: 74609e568670 ("dmaengine: dma-axi-dmac: Implement device_prep_peripheral_dma_vec")
Signed-off-by: Nuno Sá <nuno.sa@analog.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260424-dma-dmac-handle-vunmap-v4-2-90f43412fdc0@analog.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dma/dma-axi-dmac.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/dma/dma-axi-dmac.c b/drivers/dma/dma-axi-dmac.c
index 45c2c8e4bc451d..127c3cf80a0e50 100644
--- a/drivers/dma/dma-axi-dmac.c
+++ b/drivers/dma/dma-axi-dmac.c
@@ -769,7 +769,7 @@ axi_dmac_prep_peripheral_dma_vec(struct dma_chan *c, const struct dma_vec *vecs,
 	for (i = 0; i < nb; i++) {
 		if (!axi_dmac_check_addr(chan, vecs[i].addr) ||
 		    !axi_dmac_check_len(chan, vecs[i].len)) {
-			kfree(desc);
+			axi_dmac_free_desc(desc);
 			return NULL;
 		}
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0961/2077] dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (959 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0960/2077] dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0962/2077] clk: qcom: a53: Corrected frequency multiplier for 1152MHz Greg Kroah-Hartman
                   ` (36 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nuno Sá, Frank Li, Vinod Koul,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nuno Sá <nuno.sa@analog.com>

[ Upstream commit 9e942c8579130e62734c14338e9f451780669164 ]

For architectures like Microblaze or arm64 (where this IP is used),
DMA_DIRECT_REMAP is set which means that dma_alloc_coherent() might
remap (and hence vmalloc()) some memory. This became visible in a design
where dma_direct_use_pool() is not possible.

With the above, when calling dma_free_coherent(), vunmap() would be
called from softirq context and thus leading to a BUG().

To fix it, use a dma pool that is allocated in
.device_alloc_chan_resources() and allocate blocks from it. The key
point is that now dma_pool_free() is used in axi_dmac_free_desc() to
free the blocks and that just frees the blocks from the pool in the
sense they can be used again. In other words, no actual call to
dma_free_coherent() happens. That only happens when destroying the pool
in axi_dmac_free_chan_resources() which does not happen in any interrupt
context.

Fixes: 3f8fd25936ee ("dmaengine: axi-dmac: Allocate hardware descriptors")
Signed-off-by: Nuno Sá <nuno.sa@analog.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260424-dma-dmac-handle-vunmap-v4-4-90f43412fdc0@analog.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/dma/dma-axi-dmac.c | 66 +++++++++++++++++++++++---------------
 1 file changed, 40 insertions(+), 26 deletions(-)

diff --git a/drivers/dma/dma-axi-dmac.c b/drivers/dma/dma-axi-dmac.c
index 127c3cf80a0e50..ce5cabc460651e 100644
--- a/drivers/dma/dma-axi-dmac.c
+++ b/drivers/dma/dma-axi-dmac.c
@@ -13,6 +13,7 @@
 #include <linux/device.h>
 #include <linux/dma-mapping.h>
 #include <linux/dmaengine.h>
+#include <linux/dmapool.h>
 #include <linux/err.h>
 #include <linux/interrupt.h>
 #include <linux/io.h>
@@ -147,6 +148,7 @@ struct axi_dmac_chan {
 	struct virt_dma_chan vchan;
 
 	struct axi_dmac_desc *next_desc;
+	void *pool;
 	struct list_head active_descs;
 	enum dma_transfer_direction direction;
 
@@ -650,11 +652,17 @@ static void axi_dmac_issue_pending(struct dma_chan *c)
 	spin_unlock_irqrestore(&chan->vchan.lock, flags);
 }
 
+static void axi_dmac_free_desc(struct axi_dmac_desc *desc)
+{
+	for (unsigned int i = 0; i < desc->num_sgs; i++)
+		dma_pool_free(desc->chan->pool, desc->sg[i].hw, desc->sg[i].hw_phys);
+
+	kfree(desc);
+}
+
 static struct axi_dmac_desc *
 axi_dmac_alloc_desc(struct axi_dmac_chan *chan, unsigned int num_sgs)
 {
-	struct axi_dmac *dmac = chan_to_axi_dmac(chan);
-	struct device *dev = dmac->dma_dev.dev;
 	struct axi_dmac_hw_desc *hws;
 	struct axi_dmac_desc *desc;
 	dma_addr_t hw_phys;
@@ -666,22 +674,22 @@ axi_dmac_alloc_desc(struct axi_dmac_chan *chan, unsigned int num_sgs)
 	desc->num_sgs = num_sgs;
 	desc->chan = chan;
 
-	hws = dma_alloc_coherent(dev, PAGE_ALIGN(num_sgs * sizeof(*hws)),
-				&hw_phys, GFP_ATOMIC);
-	if (!hws) {
-		kfree(desc);
-		return NULL;
-	}
-
 	for (i = 0; i < num_sgs; i++) {
-		desc->sg[i].hw = &hws[i];
-		desc->sg[i].hw_phys = hw_phys + i * sizeof(*hws);
+		hws = dma_pool_zalloc(chan->pool, GFP_NOWAIT, &hw_phys);
+		if (!hws) {
+			desc->num_sgs = i;
+			axi_dmac_free_desc(desc);
+			return NULL;
+		}
 
-		hws[i].id = AXI_DMAC_SG_UNUSED;
-		hws[i].flags = 0;
+		desc->sg[i].hw = hws;
+		desc->sg[i].hw_phys = hw_phys;
+
+		hws->id = AXI_DMAC_SG_UNUSED;
 
 		/* Link hardware descriptors */
-		hws[i].next_sg_addr = hw_phys + (i + 1) * sizeof(*hws);
+		if (i)
+			desc->sg[i - 1].hw->next_sg_addr = hw_phys;
 	}
 
 	/* The last hardware descriptor will trigger an interrupt */
@@ -690,18 +698,6 @@ axi_dmac_alloc_desc(struct axi_dmac_chan *chan, unsigned int num_sgs)
 	return desc;
 }
 
-static void axi_dmac_free_desc(struct axi_dmac_desc *desc)
-{
-	struct axi_dmac *dmac = chan_to_axi_dmac(desc->chan);
-	struct device *dev = dmac->dma_dev.dev;
-	struct axi_dmac_hw_desc *hw = desc->sg[0].hw;
-	dma_addr_t hw_phys = desc->sg[0].hw_phys;
-
-	dma_free_coherent(dev, PAGE_ALIGN(desc->num_sgs * sizeof(*hw)),
-			  hw, hw_phys);
-	kfree(desc);
-}
-
 static struct axi_dmac_sg *axi_dmac_fill_linear_sg(struct axi_dmac_chan *chan,
 	enum dma_transfer_direction direction, dma_addr_t addr,
 	unsigned int num_periods, unsigned int period_len,
@@ -935,9 +931,26 @@ static struct dma_async_tx_descriptor *axi_dmac_prep_interleaved(
 	return vchan_tx_prep(&chan->vchan, &desc->vdesc, flags);
 }
 
+static int axi_dmac_alloc_chan_resources(struct dma_chan *c)
+{
+	struct axi_dmac_chan *chan = to_axi_dmac_chan(c);
+	struct device *dev = c->device->dev;
+
+	chan->pool = dma_pool_create(dev_name(dev), dev,
+				     sizeof(struct axi_dmac_hw_desc),
+				     __alignof__(struct axi_dmac_hw_desc), 0);
+	if (!chan->pool)
+		return -ENOMEM;
+
+	return 0;
+}
+
 static void axi_dmac_free_chan_resources(struct dma_chan *c)
 {
+	struct axi_dmac_chan *chan = to_axi_dmac_chan(c);
+
 	vchan_free_chan_resources(to_virt_chan(c));
+	dma_pool_destroy(chan->pool);
 }
 
 static void axi_dmac_desc_free(struct virt_dma_desc *vdesc)
@@ -1239,6 +1252,7 @@ static int axi_dmac_probe(struct platform_device *pdev)
 	dma_cap_set(DMA_SLAVE, dma_dev->cap_mask);
 	dma_cap_set(DMA_CYCLIC, dma_dev->cap_mask);
 	dma_cap_set(DMA_INTERLEAVE, dma_dev->cap_mask);
+	dma_dev->device_alloc_chan_resources = axi_dmac_alloc_chan_resources;
 	dma_dev->device_free_chan_resources = axi_dmac_free_chan_resources;
 	dma_dev->device_tx_status = dma_cookie_status;
 	dma_dev->device_issue_pending = axi_dmac_issue_pending;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0962/2077] clk: qcom: a53: Corrected frequency multiplier for 1152MHz
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (960 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0961/2077] dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0963/2077] sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store() Greg Kroah-Hartman
                   ` (35 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Phillip Varney, Konrad Dybcio,
	Dmitry Baryshkov, Bjorn Andersson, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Phillip Varney <pbvarney@protonmail.com>

[ Upstream commit bb56147ea9fce98ebde1d367335ba006cba61fbd ]

The 1152MHz frequency entry for the a53 currently selects a multiplier of 62, giving 1190MHz. This changes the mulitiplier to 60 giving the intended 1152MHz.

Signed-off-by: Phillip Varney <pbvarney@protonmail.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Fixes: 0c6ab1b8f894 ("clk: qcom: Add A53 PLL support")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260605005502.313928-1-pbvarney@protonmail.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/clk/qcom/a53-pll.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/clk/qcom/a53-pll.c b/drivers/clk/qcom/a53-pll.c
index 724a642311e50b..0549b214fcfc8b 100644
--- a/drivers/clk/qcom/a53-pll.c
+++ b/drivers/clk/qcom/a53-pll.c
@@ -20,7 +20,7 @@
 static const struct pll_freq_tbl a53pll_freq[] = {
 	{  998400000, 52, 0x0, 0x1, 0 },
 	{ 1094400000, 57, 0x0, 0x1, 0 },
-	{ 1152000000, 62, 0x0, 0x1, 0 },
+	{ 1152000000, 60, 0x0, 0x1, 0 },
 	{ 1209600000, 63, 0x0, 0x1, 0 },
 	{ 1248000000, 65, 0x0, 0x1, 0 },
 	{ 1363200000, 71, 0x0, 0x1, 0 },
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0963/2077] sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (961 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0962/2077] clk: qcom: a53: Corrected frequency multiplier for 1152MHz Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0964/2077] pNFS/filelayout: fix cheking if a layout is striped Greg Kroah-Hartman
                   ` (34 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hongling Zeng, Anna Schumaker,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hongling Zeng <zenghongling@kylinos.cn>

[ Upstream commit 37957478be021b92981aa4c99b69f308d3b784d0 ]

xprt_create_transport() never returns NULL, only valid pointers or
error pointers. Using IS_ERR_OR_NULL() is incorrect, and PTR_ERR(NULL)
would return 0, which indicates EOF in a sysfs store function.

Fix this by using IS_ERR() instead of IS_ERR_OR_NULL().

Fixes: df210d9b0951 ("sunrpc: Add a sysfs file for adding a new xprt")
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sunrpc/sysfs.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/sunrpc/sysfs.c b/net/sunrpc/sysfs.c
index a90480f8015480..49686bf740e694 100644
--- a/net/sunrpc/sysfs.c
+++ b/net/sunrpc/sysfs.c
@@ -348,7 +348,7 @@ static ssize_t rpc_sysfs_xprt_switch_add_xprt_store(struct kobject *kobj,
 	xprt_create_args.reconnect_timeout = xprt->max_reconnect_timeout;
 
 	new = xprt_create_transport(&xprt_create_args);
-	if (IS_ERR_OR_NULL(new)) {
+	if (IS_ERR(new)) {
 		count = PTR_ERR(new);
 		goto out_put_xprt;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0964/2077] pNFS/filelayout: fix cheking if a layout is striped
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (962 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0963/2077] sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store() Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0965/2077] xprtrdma: Use sendctx DMA state for Send signaling Greg Kroah-Hartman
                   ` (33 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sagi Grimberg, Anna Schumaker,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sagi Grimberg <sagi@grimberg.me>

[ Upstream commit 91668417d4e925c98cae4a55b1b9860380ddbf16 ]

A layout can still be striped with num_fh = 1 as it is perfectly possible
that both MDS and DSs can handle the same filehandle. Hence check according
to stripe_count > 1, which is the correct check to begin with.

We should not be called with flseg->dsaddr = NULL, but if for some reason
we do, return our best guess with is flseg->num_fh > 1.

Fixes: a6b9d2fa0024 ("pNFS/filelayout: Fix coalescing test for single DS")
Signed-off-by: Sagi Grimberg <sagi@grimberg.me>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/nfs/filelayout/filelayout.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/fs/nfs/filelayout/filelayout.c b/fs/nfs/filelayout/filelayout.c
index e85380e3b11d72..70f2cbd46960ff 100644
--- a/fs/nfs/filelayout/filelayout.c
+++ b/fs/nfs/filelayout/filelayout.c
@@ -778,6 +778,8 @@ filelayout_alloc_lseg(struct pnfs_layout_hdr *layoutid,
 static bool
 filelayout_lseg_is_striped(const struct nfs4_filelayout_segment *flseg)
 {
+	if (flseg->dsaddr)
+		return flseg->dsaddr->stripe_count > 1;
 	return flseg->num_fh > 1;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0965/2077] xprtrdma: Use sendctx DMA state for Send signaling
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (963 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0964/2077] pNFS/filelayout: fix cheking if a layout is striped Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0966/2077] xprtrdma: Decouple req recycling from RPC completion Greg Kroah-Hartman
                   ` (32 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chuck Lever, Anna Schumaker,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 2797ae7c929610fb2d2303a996a08173fa096730 ]

Send signaling matters only when the prepared Send has page
mappings to unmap. Today that test is expressed indirectly with
rl_kref, because the Send-side reference is taken only for Sends
with mapped SGEs.

Split the SGE DMA unmap loop into its own helper and use
sc_unmap_count directly for the signaling decision. This keeps the
current behavior but removes one dependency on the old rl_kref
semantics before the request lifetime rules are changed.

Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Stable-dep-of: e786233d2e0b ("xprtrdma: Decouple req recycling from RPC completion")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sunrpc/xprtrdma/frwr_ops.c |  2 +-
 net/sunrpc/xprtrdma/rpc_rdma.c | 22 +++++++++++++---------
 2 files changed, 14 insertions(+), 10 deletions(-)

diff --git a/net/sunrpc/xprtrdma/frwr_ops.c b/net/sunrpc/xprtrdma/frwr_ops.c
index 7f79a0a2601e65..e5c71cf705a33a 100644
--- a/net/sunrpc/xprtrdma/frwr_ops.c
+++ b/net/sunrpc/xprtrdma/frwr_ops.c
@@ -474,7 +474,7 @@ int frwr_send(struct rpcrdma_xprt *r_xprt, struct rpcrdma_req *req)
 		++num_wrs;
 	}
 
-	if ((kref_read(&req->rl_kref) > 1) || num_wrs > ep->re_send_count) {
+	if (req->rl_sendctx->sc_unmap_count || num_wrs > ep->re_send_count) {
 		send_wr->send_flags |= IB_SEND_SIGNALED;
 		ep->re_send_count = min_t(unsigned int, ep->re_send_batch,
 					  num_wrs - ep->re_send_count);
diff --git a/net/sunrpc/xprtrdma/rpc_rdma.c b/net/sunrpc/xprtrdma/rpc_rdma.c
index 0e0f219747109f..16b9987858d683 100644
--- a/net/sunrpc/xprtrdma/rpc_rdma.c
+++ b/net/sunrpc/xprtrdma/rpc_rdma.c
@@ -477,19 +477,11 @@ static void rpcrdma_sendctx_done(struct kref *kref)
 	rep->rr_rxprt->rx_stats.reply_waits_for_send++;
 }
 
-/**
- * rpcrdma_sendctx_unmap - DMA-unmap Send buffer
- * @sc: sendctx containing SGEs to unmap
- *
- */
-void rpcrdma_sendctx_unmap(struct rpcrdma_sendctx *sc)
+static void rpcrdma_sendctx_dma_unmap(struct rpcrdma_sendctx *sc)
 {
 	struct rpcrdma_regbuf *rb = sc->sc_req->rl_sendbuf;
 	struct ib_sge *sge;
 
-	if (!sc->sc_unmap_count)
-		return;
-
 	/* The first two SGEs contain the transport header and
 	 * the inline buffer. These are always left mapped so
 	 * they can be cheaply re-used.
@@ -498,7 +490,19 @@ void rpcrdma_sendctx_unmap(struct rpcrdma_sendctx *sc)
 	     ++sge, --sc->sc_unmap_count)
 		ib_dma_unmap_page(rdmab_device(rb), sge->addr, sge->length,
 				  DMA_TO_DEVICE);
+}
+
+/**
+ * rpcrdma_sendctx_unmap - DMA-unmap Send buffer
+ * @sc: sendctx containing SGEs to unmap
+ *
+ */
+void rpcrdma_sendctx_unmap(struct rpcrdma_sendctx *sc)
+{
+	if (!sc->sc_unmap_count)
+		return;
 
+	rpcrdma_sendctx_dma_unmap(sc);
 	kref_put(&sc->sc_req->rl_kref, rpcrdma_sendctx_done);
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0966/2077] xprtrdma: Decouple req recycling from RPC completion
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (964 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0965/2077] xprtrdma: Use sendctx DMA state for Send signaling Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0967/2077] NFSv4/pnfs: defer return_range callbacks until after inode unlock Greg Kroah-Hartman
                   ` (31 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chuck Lever, Anna Schumaker,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit e786233d2e0bbff9a82e43f02ae3a46ab4b08ec3 ]

rl_kref formerly served two distinct lifetimes through a single
refcount: it gated when a Reply could wake its RPC task, and it
gated when an rpcrdma_req could return to its free pool. The
marshal path took the Send-side reference only when SGEs needed
DMA-unmap (sc_unmap_count > 0), which made a Send carrying only
pre-registered buffers an exception: the Reply handler dropped
rl_kref from 1 to 0 and freed the req while the HCA might still
be DMA-reading from its send buffer.

Give rl_kref a narrower job. The RPC layer takes one reference
when slot allocation hands a req out. rpcrdma_prepare_send_sges()
takes a Send-side reference unconditionally after WR preparation
succeeds. xprt_rdma_free_slot() and xprt_rdma_bc_free_rqst() drop
the RPC-layer reference; rpcrdma_sendctx_unmap() drops the
Send-side reference. The req returns to its free pool only after
both owners have signed off.

The existing kref_init(&req->rl_kref) call in
rpcrdma_prepare_send_sges() is removed. Initialization moves to
the slot-allocation paths (xprt_rdma_alloc_slot and
rpcrdma_bc_rqst_get), and the release callback re-arms rl_kref
before the req returns to a free pool. A re-init in the marshal
path would discard the RPC-layer reference that already exists
on entry.

Three invariants follow:

  - Any rpcrdma_req held by an rpc_rqst has rl_kref >= 1.
    xprt_rdma_alloc_slot(), rpcrdma_bc_rqst_get(), and the
    backlog-wake branch in xprt_rdma_alloc_slot() each kref_init
    rl_kref before publishing the req. Without this invariant,
    an RPC task that aborts between slot allocation and marshal
    (gss_refresh failure or signal during call_connect, for
    example) would drive xprt_release() ->
    xprt_rdma_free_slot() -> kref_put against a refcount of
    zero, saturating refcount_t and stranding the slot.

  - The Send-side reference is taken only after WR prep
    succeeds. A mapping failure in rpcrdma_prepare_send_sges()
    runs rpcrdma_sendctx_cancel(), which DMA-unmaps the sendctx
    and clears sc_req without touching rl_kref. The sendctx
    ring walks in rpcrdma_sendctx_put_locked() and
    rpcrdma_sendctxs_destroy() skip entries with sc_req == NULL,
    so a burst of -EIO marshal failures cannot hold reqs off
    rb_send_bufs.

  - The release callback re-arms rl_kref so the next consumer
    enters with the invariant satisfied.

Replies now complete the RPC directly. rpcrdma_reply_handler()
calls rpcrdma_complete_rqst() in place of kref_put on the
non-LocalInv branch. The LocalInv branch already completes the
RPC from frwr_unmap_async() and is unaffected.

Because Send-side references can now outlive RPC completion,
connection teardown drains sendctx entries whose unsignaled
Sends never had a later signaled completion to walk the ring.
rpcrdma_sendctxs_destroy() walks the active range and runs
rpcrdma_sendctx_unmap() on each entry with a non-NULL sc_req
before the request buffers are reset, and is moved ahead of
rpcrdma_reqs_reset() in rpcrdma_xprt_disconnect() so the reqs
are still in their pre-reset state when the Send-side refs are
released.

The drain creates a teardown-ordering hazard on the backchannel
path. With the new lifetime, releasing a bc_prealloc req from
rpcrdma_req_release() re-adds it to bc_pa_list. The disconnect
in xprt_rdma_destroy() runs after xprt_destroy_backchannel() has
already emptied bc_pa_list, so the drained reqs would otherwise
leak. xprt_rdma_destroy() now runs xprt_rdma_bc_destroy(xprt, 0)
a second time after the disconnect to reclaim them.

Fixes: 0ab115237025 ("xprtrdma: Wake RPCs directly in rpcrdma_wc_send path")
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sunrpc/xprtrdma/backchannel.c |  5 ++-
 net/sunrpc/xprtrdma/rpc_rdma.c    | 47 +++++++++++---------------
 net/sunrpc/xprtrdma/transport.c   | 55 ++++++++++++++++++++++++++++---
 net/sunrpc/xprtrdma/verbs.c       | 29 +++++++++++++---
 net/sunrpc/xprtrdma/xprt_rdma.h   |  2 +-
 5 files changed, 97 insertions(+), 41 deletions(-)

diff --git a/net/sunrpc/xprtrdma/backchannel.c b/net/sunrpc/xprtrdma/backchannel.c
index 2f0f9618dd0580..e5b3463da25f91 100644
--- a/net/sunrpc/xprtrdma/backchannel.c
+++ b/net/sunrpc/xprtrdma/backchannel.c
@@ -159,9 +159,7 @@ void xprt_rdma_bc_free_rqst(struct rpc_rqst *rqst)
 	rpcrdma_rep_put(&r_xprt->rx_buf, rep);
 	req->rl_reply = NULL;
 
-	spin_lock(&xprt->bc_pa_lock);
-	list_add_tail(&rqst->rq_bc_pa_list, &xprt->bc_pa_list);
-	spin_unlock(&xprt->bc_pa_lock);
+	rpcrdma_req_put(req);
 	xprt_put(xprt);
 }
 
@@ -203,6 +201,7 @@ static struct rpc_rqst *rpcrdma_bc_rqst_get(struct rpcrdma_xprt *r_xprt)
 	rqst->rq_xprt = xprt;
 	__set_bit(RPC_BC_PA_IN_USE, &rqst->rq_bc_pa_state);
 	xdr_buf_init(&rqst->rq_snd_buf, rdmab_data(req->rl_sendbuf), size);
+	kref_init(&req->rl_kref);
 	return rqst;
 }
 
diff --git a/net/sunrpc/xprtrdma/rpc_rdma.c b/net/sunrpc/xprtrdma/rpc_rdma.c
index 16b9987858d683..69380f9dfa499d 100644
--- a/net/sunrpc/xprtrdma/rpc_rdma.c
+++ b/net/sunrpc/xprtrdma/rpc_rdma.c
@@ -467,16 +467,6 @@ static int rpcrdma_encode_reply_chunk(struct rpcrdma_xprt *r_xprt,
 	return 0;
 }
 
-static void rpcrdma_sendctx_done(struct kref *kref)
-{
-	struct rpcrdma_req *req =
-		container_of(kref, struct rpcrdma_req, rl_kref);
-	struct rpcrdma_rep *rep = req->rl_reply;
-
-	rpcrdma_complete_rqst(rep);
-	rep->rr_rxprt->rx_stats.reply_waits_for_send++;
-}
-
 static void rpcrdma_sendctx_dma_unmap(struct rpcrdma_sendctx *sc)
 {
 	struct rpcrdma_regbuf *rb = sc->sc_req->rl_sendbuf;
@@ -493,17 +483,26 @@ static void rpcrdma_sendctx_dma_unmap(struct rpcrdma_sendctx *sc)
 }
 
 /**
- * rpcrdma_sendctx_unmap - DMA-unmap Send buffer
+ * rpcrdma_sendctx_unmap - DMA-unmap Send buffer and release Send owner
  * @sc: sendctx containing SGEs to unmap
  *
  */
 void rpcrdma_sendctx_unmap(struct rpcrdma_sendctx *sc)
 {
-	if (!sc->sc_unmap_count)
-		return;
+	struct rpcrdma_req *req = sc->sc_req;
 
 	rpcrdma_sendctx_dma_unmap(sc);
-	kref_put(&sc->sc_req->rl_kref, rpcrdma_sendctx_done);
+	sc->sc_req = NULL;
+	rpcrdma_req_put(req);
+}
+
+/* No Send was posted. Release DMA mappings prepared for this
+ * sendctx, but leave the request reference count alone.
+ */
+static void rpcrdma_sendctx_cancel(struct rpcrdma_sendctx *sc)
+{
+	rpcrdma_sendctx_dma_unmap(sc);
+	sc->sc_req = NULL;
 }
 
 /* Prepare an SGE for the RPC-over-RDMA transport header.
@@ -695,8 +694,6 @@ static bool rpcrdma_prepare_noch_mapped(struct rpcrdma_xprt *r_xprt,
 					      tail->iov_len))
 			return false;
 
-	if (req->rl_sendctx->sc_unmap_count)
-		kref_get(&req->rl_kref);
 	return true;
 }
 
@@ -726,7 +723,6 @@ static bool rpcrdma_prepare_readch(struct rpcrdma_xprt *r_xprt,
 		len -= len & 3;
 		if (!rpcrdma_prepare_tail_iov(req, xdr, page_base, len))
 			return false;
-		kref_get(&req->rl_kref);
 	}
 
 	return true;
@@ -755,7 +751,6 @@ inline int rpcrdma_prepare_send_sges(struct rpcrdma_xprt *r_xprt,
 		goto out_nosc;
 	req->rl_sendctx->sc_unmap_count = 0;
 	req->rl_sendctx->sc_req = req;
-	kref_init(&req->rl_kref);
 	req->rl_wr.wr_cqe = &req->rl_sendctx->sc_cqe;
 	req->rl_wr.sg_list = req->rl_sendctx->sc_sges;
 	req->rl_wr.num_sge = 0;
@@ -783,10 +778,14 @@ inline int rpcrdma_prepare_send_sges(struct rpcrdma_xprt *r_xprt,
 		goto out_unmap;
 	}
 
+	/* The Send-side owner releases this reference when the
+	 * Send has completed.
+	 */
+	kref_get(&req->rl_kref);
 	return 0;
 
 out_unmap:
-	rpcrdma_sendctx_unmap(req->rl_sendctx);
+	rpcrdma_sendctx_cancel(req->rl_sendctx);
 out_nosc:
 	trace_xprtrdma_prepsend_failed(&req->rl_slot, ret);
 	return ret;
@@ -1364,14 +1363,6 @@ void rpcrdma_complete_rqst(struct rpcrdma_rep *rep)
 	goto out;
 }
 
-static void rpcrdma_reply_done(struct kref *kref)
-{
-	struct rpcrdma_req *req =
-		container_of(kref, struct rpcrdma_req, rl_kref);
-
-	rpcrdma_complete_rqst(req->rl_reply);
-}
-
 /**
  * rpcrdma_reply_handler - Process received RPC/RDMA messages
  * @rep: Incoming rpcrdma_rep object to process
@@ -1443,7 +1434,7 @@ void rpcrdma_reply_handler(struct rpcrdma_rep *rep)
 		frwr_unmap_async(r_xprt, req);
 		/* LocalInv completion will complete the RPC */
 	else
-		kref_put(&req->rl_kref, rpcrdma_reply_done);
+		rpcrdma_complete_rqst(rep);
 
 out_post:
 	rpcrdma_post_recvs(r_xprt,
diff --git a/net/sunrpc/xprtrdma/transport.c b/net/sunrpc/xprtrdma/transport.c
index 61706df5e485ac..5569f17fdd9b59 100644
--- a/net/sunrpc/xprtrdma/transport.c
+++ b/net/sunrpc/xprtrdma/transport.c
@@ -279,6 +279,13 @@ xprt_rdma_destroy(struct rpc_xprt *xprt)
 	cancel_delayed_work_sync(&r_xprt->rx_connect_worker);
 
 	rpcrdma_xprt_disconnect(r_xprt);
+
+	/* The disconnect's sendctx drain can return bc_prealloc reqs
+	 * to bc_pa_list after xprt_destroy_backchannel() emptied it.
+	 */
+#if defined(CONFIG_SUNRPC_BACKCHANNEL)
+	xprt_rdma_bc_destroy(xprt, 0);
+#endif
 	rpcrdma_buffer_destroy(&r_xprt->rx_buf);
 
 	xprt_rdma_free_addresses(xprt);
@@ -487,6 +494,45 @@ xprt_rdma_connect(struct rpc_xprt *xprt, struct rpc_task *task)
 	queue_delayed_work(system_long_wq, &r_xprt->rx_connect_worker, delay);
 }
 
+/* rl_kref has two owners while a Send is outstanding: the rpc_rqst
+ * owner and the sendctx. Replies complete the RPC but do not drop
+ * either reference. The req returns to its free pool only after
+ * xprt_rdma_free_slot() or xprt_rdma_bc_free_rqst() has dropped the
+ * RPC-layer reference and rpcrdma_sendctx_unmap() has dropped the
+ * Send-side reference.
+ */
+static void rpcrdma_req_release(struct kref *kref)
+{
+	struct rpcrdma_req *req =
+		container_of(kref, struct rpcrdma_req, rl_kref);
+	struct rpc_rqst *rqst = &req->rl_slot;
+	struct rpc_xprt *xprt = rqst->rq_xprt;
+	struct rpcrdma_xprt *r_xprt;
+
+	kref_init(&req->rl_kref);
+
+#if defined(CONFIG_SUNRPC_BACKCHANNEL)
+	if (bc_prealloc(rqst)) {
+		spin_lock(&xprt->bc_pa_lock);
+		list_add_tail(&rqst->rq_bc_pa_list, &xprt->bc_pa_list);
+		spin_unlock(&xprt->bc_pa_lock);
+		return;
+	}
+#endif
+
+	if (xprt_wake_up_backlog(xprt, rqst))
+		return;
+
+	r_xprt = rpcx_to_rdmax(xprt);
+	memset(rqst, 0, sizeof(*rqst));
+	rpcrdma_buffer_put(&r_xprt->rx_buf, req);
+}
+
+void rpcrdma_req_put(struct rpcrdma_req *req)
+{
+	kref_put(&req->rl_kref, rpcrdma_req_release);
+}
+
 /**
  * xprt_rdma_alloc_slot - allocate an rpc_rqst
  * @xprt: controlling RPC transport
@@ -505,6 +551,7 @@ xprt_rdma_alloc_slot(struct rpc_xprt *xprt, struct rpc_task *task)
 	req = rpcrdma_buffer_get(&r_xprt->rx_buf);
 	if (!req)
 		goto out_sleep;
+	kref_init(&req->rl_kref);
 	task->tk_rqstp = &req->rl_slot;
 	task->tk_status = 0;
 	return;
@@ -520,6 +567,7 @@ xprt_rdma_alloc_slot(struct rpc_xprt *xprt, struct rpc_task *task)
 	if (req) {
 		struct rpc_rqst *rqst = &req->rl_slot;
 
+		kref_init(&req->rl_kref);
 		if (!xprt_wake_up_backlog(xprt, rqst)) {
 			memset(rqst, 0, sizeof(*rqst));
 			rpcrdma_buffer_put(&r_xprt->rx_buf, req);
@@ -540,10 +588,7 @@ xprt_rdma_free_slot(struct rpc_xprt *xprt, struct rpc_rqst *rqst)
 		container_of(xprt, struct rpcrdma_xprt, rx_xprt);
 
 	rpcrdma_reply_put(&r_xprt->rx_buf, rpcr_to_rdmar(rqst));
-	if (!xprt_wake_up_backlog(xprt, rqst)) {
-		memset(rqst, 0, sizeof(*rqst));
-		rpcrdma_buffer_put(&r_xprt->rx_buf, rpcr_to_rdmar(rqst));
-	}
+	rpcrdma_req_put(rpcr_to_rdmar(rqst));
 }
 
 static bool rpcrdma_check_regbuf(struct rpcrdma_xprt *r_xprt,
@@ -716,7 +761,7 @@ void xprt_rdma_print_stats(struct rpc_xprt *xprt, struct seq_file *seq)
 		   r_xprt->rx_stats.mrs_allocated,
 		   r_xprt->rx_stats.local_inv_needed,
 		   r_xprt->rx_stats.empty_sendctx_q,
-		   r_xprt->rx_stats.reply_waits_for_send);
+		   0LU); /* was reply_waits_for_send; column preserved */
 }
 
 static int
diff --git a/net/sunrpc/xprtrdma/verbs.c b/net/sunrpc/xprtrdma/verbs.c
index aecf9c0a153f36..97b8b2376602c8 100644
--- a/net/sunrpc/xprtrdma/verbs.c
+++ b/net/sunrpc/xprtrdma/verbs.c
@@ -65,6 +65,8 @@
 
 static int rpcrdma_sendctxs_create(struct rpcrdma_xprt *r_xprt);
 static void rpcrdma_sendctxs_destroy(struct rpcrdma_xprt *r_xprt);
+static unsigned long rpcrdma_sendctx_next(struct rpcrdma_buffer *buf,
+					  unsigned long item);
 static void rpcrdma_sendctx_put_locked(struct rpcrdma_xprt *r_xprt,
 				       struct rpcrdma_sendctx *sc);
 static int rpcrdma_reqs_setup(struct rpcrdma_xprt *r_xprt);
@@ -571,9 +573,9 @@ void rpcrdma_xprt_disconnect(struct rpcrdma_xprt *r_xprt)
 
 	rpcrdma_xprt_drain(r_xprt);
 	rpcrdma_reps_unmap(r_xprt);
+	rpcrdma_sendctxs_destroy(r_xprt);
 	rpcrdma_reqs_reset(r_xprt);
 	rpcrdma_mrs_destroy(r_xprt);
-	rpcrdma_sendctxs_destroy(r_xprt);
 
 	if (rpcrdma_ep_put(ep))
 		rdma_destroy_id(id);
@@ -605,6 +607,20 @@ static void rpcrdma_sendctxs_destroy(struct rpcrdma_xprt *r_xprt)
 
 	if (!buf->rb_sc_ctxs)
 		return;
+
+	/* The QP is drained, but the final unsignaled Sends might not
+	 * have been walked by a signaled Send completion. Release those
+	 * Send owners before request buffers are reset.
+	 */
+	for (i = rpcrdma_sendctx_next(buf, buf->rb_sc_tail);
+	     i != rpcrdma_sendctx_next(buf, buf->rb_sc_head);
+	     i = rpcrdma_sendctx_next(buf, i)) {
+		struct rpcrdma_sendctx *sc = buf->rb_sc_ctxs[i];
+
+		if (sc && sc->sc_req)
+			rpcrdma_sendctx_unmap(sc);
+	}
+
 	for (i = 0; i <= buf->rb_sc_last; i++)
 		kfree(buf->rb_sc_ctxs[i]);
 	kfree(buf->rb_sc_ctxs);
@@ -739,15 +755,20 @@ static void rpcrdma_sendctx_put_locked(struct rpcrdma_xprt *r_xprt,
 	struct rpcrdma_buffer *buf = &r_xprt->rx_buf;
 	unsigned long next_tail;
 
-	/* Unmap SGEs of previously completed but unsignaled
-	 * Sends by walking up the queue until @sc is found.
+	/* Release previously completed but unsignaled Sends by walking
+	 * up the queue until @sc is found. Entries left behind by a
+	 * failed rpcrdma_prepare_send_sges() have sc_req cleared.
 	 */
 	next_tail = buf->rb_sc_tail;
 	do {
+		struct rpcrdma_sendctx *cur;
+
 		next_tail = rpcrdma_sendctx_next(buf, next_tail);
 
 		/* ORDER: item must be accessed _before_ tail is updated */
-		rpcrdma_sendctx_unmap(buf->rb_sc_ctxs[next_tail]);
+		cur = buf->rb_sc_ctxs[next_tail];
+		if (cur->sc_req)
+			rpcrdma_sendctx_unmap(cur);
 
 	} while (buf->rb_sc_ctxs[next_tail] != sc);
 
diff --git a/net/sunrpc/xprtrdma/xprt_rdma.h b/net/sunrpc/xprtrdma/xprt_rdma.h
index f53a7747272451..f879d9b9f57ef4 100644
--- a/net/sunrpc/xprtrdma/xprt_rdma.h
+++ b/net/sunrpc/xprtrdma/xprt_rdma.h
@@ -427,7 +427,6 @@ struct rpcrdma_stats {
 	/* accessed when receiving a reply */
 	unsigned long long	total_rdma_reply;
 	unsigned long long	fixup_copy_count;
-	unsigned long		reply_waits_for_send;
 	unsigned long		local_inv_needed;
 	unsigned long		nomsg_call_count;
 	unsigned long		bcall_count;
@@ -505,6 +504,7 @@ void rpcrdma_buffer_put(struct rpcrdma_buffer *buffers,
 			struct rpcrdma_req *req);
 void rpcrdma_rep_put(struct rpcrdma_buffer *buf, struct rpcrdma_rep *rep);
 void rpcrdma_reply_put(struct rpcrdma_buffer *buffers, struct rpcrdma_req *req);
+void rpcrdma_req_put(struct rpcrdma_req *req);
 
 bool rpcrdma_regbuf_realloc(struct rpcrdma_regbuf *rb, size_t size,
 			    gfp_t flags);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0967/2077] NFSv4/pnfs: defer return_range callbacks until after inode unlock
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (965 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0966/2077] xprtrdma: Decouple req recycling from RPC completion Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0968/2077] nfs: keep PG_UPTODATE clear after read errors in page groups Greg Kroah-Hartman
                   ` (30 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Dai Ngo, Anna Schumaker, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dai Ngo <dai.ngo@oracle.com>

[ Upstream commit 77b160b2d863d37f36b6c38e80a7d259ce939e69 ]

Sometimes unmounting an NFS filesystem mounted with pNFS SCSI
layouts triggers the following warning:

     BUG: scheduling while atomic: umount.nfs4/...

    __schedule_bug+0xbd/0x100
     schedule_debug.constprop.0+0x19f/0x220
     __schedule+0x10d/0x10a0
     schedule+0x74/0x190
     schedule_timeout+0xf5/0x220
     io_schedule_timeout+0xd5/0x160
     __wait_for_common+0x186/0x4b0
     blk_execute_rq+0x2ef/0x3a0
     scsi_execute_cmd+0x1ff/0x700
     sd_pr_out_command.isra.0+0x242/0x380 [sd_mod]
     bl_unregister_scsi.constprop.0+0x109/0x3c0 [blocklayoutdriver]
     bl_unregister_dev+0x175/0x1c0 [blocklayoutdriver]
     bl_free_device+0x1f/0x1b0 [blocklayoutdriver]
     bl_free_deviceid_node+0x12/0x30 [blocklayoutdriver]
     nfs4_put_deviceid_node+0x171/0x360 [nfsv4]
     ext_tree_remove+0x11c/0x1d0 [blocklayoutdriver]
     _pnfs_return_layout+0x416/0x900 [nfsv4]
     nfs4_evict_inode+0x108/0x130 [nfsv4]
     evict+0x316/0x750
     dispose_list+0xf1/0x1a0
     evict_inodes+0x33f/0x440
     generic_shutdown_super+0xc9/0x4e0
     kill_anon_super+0x3a/0x90
     nfs_kill_super+0x44/0x60 [nfs]
     deactivate_locked_super+0xb8/0x1b0
     cleanup_mnt+0x25a/0x380
     task_work_run+0x13e/0x210
     exit_to_user_mode_loop+0x169/0x400
     do_syscall_64+0x467/0x1550
     entry_SYSCALL_64_after_hwframe+0x76/0x7e

The warning occurs because the block layout driver unregisters the SCSI
device while the inode lock is still held. Device unregistration issues
a SCSI PR command, which may sleep, resulting in a "scheduling while
atomic" warning.

During layout return, ext_tree_remove() invokes the layout driver's
return_range callback while holding the inode lock. For block layouts,
this callback eventually calls bl_unregister_scsi(), which may block in
scsi_execute_cmd() while issuing PR commands to the device.

Fix this by deferring the return_range callbacks until after the inode
lock has been released. The layout header reference count is incremented
before invoking return_range(), ensuring that the layout header remains
valid while the layout driver removes extents from the extent tree.

Fixes: c88953d87f5c8 ("pnfs: add return_range method")
Signed-off-by: Dai Ngo <dai.ngo@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/nfs/callback_proc.c | 9 +++++----
 fs/nfs/pnfs.c          | 4 ++--
 2 files changed, 7 insertions(+), 6 deletions(-)

diff --git a/fs/nfs/callback_proc.c b/fs/nfs/callback_proc.c
index 4ea9221ded4264..10f2354ba3048f 100644
--- a/fs/nfs/callback_proc.c
+++ b/fs/nfs/callback_proc.c
@@ -257,6 +257,7 @@ static u32 initiate_file_draining(struct nfs_client *clp,
 	struct pnfs_layout_hdr *lo;
 	u32 rv = NFS4ERR_NOMATCHING_LAYOUT;
 	LIST_HEAD(free_me_list);
+	bool return_range = false;
 
 	ino = nfs_layout_find_inode(clp, &args->cbl_fh, &args->cbl_stateid);
 	if (IS_ERR(ino)) {
@@ -301,13 +302,13 @@ static u32 initiate_file_draining(struct nfs_client *clp,
 		/* Embrace your forgetfulness! */
 		rv = NFS4ERR_NOMATCHING_LAYOUT;
 
-		if (NFS_SERVER(ino)->pnfs_curr_ld->return_range) {
-			NFS_SERVER(ino)->pnfs_curr_ld->return_range(lo,
-				&args->cbl_range);
-		}
+		return_range = true;
 	}
 unlock:
 	spin_unlock(&ino->i_lock);
+	if (return_range && NFS_SERVER(ino)->pnfs_curr_ld->return_range)
+		NFS_SERVER(ino)->pnfs_curr_ld->return_range(lo,
+			&args->cbl_range);
 	pnfs_free_lseg_list(&free_me_list);
 	/* Free all lsegs that are attached to commit buckets */
 	nfs_commit_inode(ino, 0);
diff --git a/fs/nfs/pnfs.c b/fs/nfs/pnfs.c
index aee523134c0f33..b7dcf58f21c396 100644
--- a/fs/nfs/pnfs.c
+++ b/fs/nfs/pnfs.c
@@ -1463,8 +1463,6 @@ _pnfs_return_layout(struct inode *ino)
 	pnfs_clear_layoutcommit(ino, &tmp_list);
 	pnfs_mark_matching_lsegs_return(lo, &tmp_list, &range, 0);
 
-	if (NFS_SERVER(ino)->pnfs_curr_ld->return_range)
-		NFS_SERVER(ino)->pnfs_curr_ld->return_range(lo, &range);
 
 	/* Don't send a LAYOUTRETURN if list was initially empty */
 	if (!test_bit(NFS_LAYOUT_RETURN_REQUESTED, &lo->plh_flags) ||
@@ -1476,6 +1474,8 @@ _pnfs_return_layout(struct inode *ino)
 
 	send = pnfs_prepare_layoutreturn(lo, &stateid, &cred, NULL);
 	spin_unlock(&ino->i_lock);
+	if (NFS_SERVER(ino)->pnfs_curr_ld->return_range)
+		NFS_SERVER(ino)->pnfs_curr_ld->return_range(lo, &range);
 	if (send)
 		status = pnfs_send_layoutreturn(lo, &stateid, &cred, IOMODE_ANY,
 						0);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0968/2077] nfs: keep PG_UPTODATE clear after read errors in page groups
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (966 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0967/2077] NFSv4/pnfs: defer return_range callbacks until after inode unlock Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0969/2077] NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors Greg Kroah-Hartman
                   ` (29 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Clark Wang, Anna Schumaker,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Clark Wang <xiaoning.wang@nxp.com>

[ Upstream commit 3ff72e1cdf5c337b6acfcf3fcef748c5b9a5316b ]

When a read request is split into multiple subrequests, earlier
completions may advance PG_UPTODATE state for the page group once
their bytes fall within hdr->good_bytes. If a later subrequest in
the same group then completes with NFS_IOHDR_ERROR, the read path
needs to clear any accumulated PG_UPTODATE state and keep later
completions from rebuilding it.

Otherwise, a subsequent successful subrequest can re-enter
nfs_page_group_set_uptodate(), restore the page-group sync state,
and leave stale PG_UPTODATE behind for nfs_page_group_destroy()
to trip over in nfs_free_request().

Add a sticky page-group read-failed flag. Once any subrequest in
the group is known to be bad, mark the group failed, clear any
accumulated PG_UPTODATE state, and refuse further PG_UPTODATE
synchronization for the rest of the completion walk.

Fixes: 67d0338edd71 ("nfs: page group syncing in read path")
Signed-off-by: Clark Wang <xiaoning.wang@nxp.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/nfs/read.c            | 25 ++++++++++++++++++++++++-
 include/linux/nfs_page.h |  1 +
 2 files changed, 25 insertions(+), 1 deletion(-)

diff --git a/fs/nfs/read.c b/fs/nfs/read.c
index e1fe78d7b8d0ff..2b70bd2b934b9a 100644
--- a/fs/nfs/read.c
+++ b/fs/nfs/read.c
@@ -132,10 +132,32 @@ static void nfs_readpage_release(struct nfs_page *req, int error)
 
 static void nfs_page_group_set_uptodate(struct nfs_page *req)
 {
-	if (nfs_page_group_sync_on_bit(req, PG_UPTODATE))
+	bool uptodate = false;
+
+	nfs_page_group_lock(req);
+	if (!test_bit(PG_READ_FAILED, &req->wb_head->wb_flags) &&
+	    nfs_page_group_sync_on_bit_locked(req, PG_UPTODATE))
+		uptodate = true;
+	nfs_page_group_unlock(req);
+
+	if (uptodate)
 		folio_mark_uptodate(nfs_page_to_folio(req));
 }
 
+static void nfs_page_group_mark_read_failed(struct nfs_page *req)
+{
+	struct nfs_page *tmp;
+
+	nfs_page_group_lock(req);
+	set_bit(PG_READ_FAILED, &req->wb_head->wb_flags);
+	tmp = req;
+	do {
+		clear_bit(PG_UPTODATE, &tmp->wb_flags);
+		tmp = tmp->wb_this_page;
+	} while (tmp != req);
+	nfs_page_group_unlock(req);
+}
+
 static void nfs_read_completion(struct nfs_pgio_header *hdr)
 {
 	unsigned long bytes = 0;
@@ -172,6 +194,7 @@ static void nfs_read_completion(struct nfs_pgio_header *hdr)
 			if (bytes <= hdr->good_bytes)
 				nfs_page_group_set_uptodate(req);
 			else {
+				nfs_page_group_mark_read_failed(req);
 				error = hdr->error;
 				xchg(&nfs_req_openctx(req)->error, error);
 			}
diff --git a/include/linux/nfs_page.h b/include/linux/nfs_page.h
index afe1d8f09d89f8..4b9a35dbc062da 100644
--- a/include/linux/nfs_page.h
+++ b/include/linux/nfs_page.h
@@ -33,6 +33,7 @@ enum {
 	PG_TEARDOWN,		/* page group sync for destroy */
 	PG_UNLOCKPAGE,		/* page group sync bit in read path */
 	PG_UPTODATE,		/* page group sync bit in read path */
+	PG_READ_FAILED,		/* page group saw a read error */
 	PG_WB_END,		/* page group sync bit in write path */
 	PG_REMOVE,		/* page group sync bit in write path */
 	PG_CONTENDED1,		/* Is someone waiting for a lock? */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0969/2077] NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (967 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0968/2077] nfs: keep PG_UPTODATE clear after read errors in page groups Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0970/2077] NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write Greg Kroah-Hartman
                   ` (28 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mike Snitzer, Anna Schumaker,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mike Snitzer <snitzer@kernel.org>

[ Upstream commit 7a375cafc14ed151508f908ea5681caf0a9cc1d6 ]

Commit f06bedfa62d5 ("pNFS/flexfiles: don't attempt pnfs on fatal DS
errors") teaches ff_layout_{read,write}_pagelist() to return
PNFS_NOT_ATTEMPTED when nfs4_ff_layout_prepare_ds() fails with a
nfs_error_is_fatal() errno (e.g. -ETIMEDOUT from a SOFTCONN connect
deadline, -ENOMEM, -ERESTARTSYS), so that the client gives up instead
of spinning.  pnfs_do_{read,write}() then dispatches the I/O through
pnfs_{read,write}_through_mds() → nfs_pageio_reset_{read,write}_mds().

That fallback is unconditional and silently violates FF_FLAGS_NO_IO_THRU_MDS:
when the layout segment carries the flag (typically single-mirror
appliance layouts where MDS I/O is explicitly forbidden), the
out_failed: path's \`&& !ds_fatal_error\` clause overrides the flag's
short-circuit through ff_layout_avoid_mds_available_ds() and routes
the I/O to the MDS file handle anyway.

This is reachable in practice during a data-server restart: SOFTCONN
exhaustion produces -ETIMEDOUT, which is fatal per nfs_error_is_fatal(),
which triggers PNFS_NOT_ATTEMPTED, which silently goes to MDS.

Preserve the upstream "don't spin on fatal errors" intent for layouts
that permit MDS fallback.  For layouts with FF_FLAGS_NO_IO_THRU_MDS
set, mark the layout for return and request PNFS_TRY_AGAIN instead;
if the server cannot supply a usable layout the failure now surfaces
cleanly via pnfs_update_layout(), rather than via silent MDS I/O that
contradicts the flag.

Fixes: f06bedfa62d5 ("pNFS/flexfiles: don't attempt pnfs on fatal DS errors")
Assisted-by: Claude:claude-opus-4-7
Signed-off-by: Mike Snitzer <snitzer@kernel.org>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/nfs/flexfilelayout/flexfilelayout.c | 16 ++++++++++++++++
 1 file changed, 16 insertions(+)

diff --git a/fs/nfs/flexfilelayout/flexfilelayout.c b/fs/nfs/flexfilelayout/flexfilelayout.c
index e22a8e0daf2c50..80a3c43aaac052 100644
--- a/fs/nfs/flexfilelayout/flexfilelayout.c
+++ b/fs/nfs/flexfilelayout/flexfilelayout.c
@@ -2204,6 +2204,14 @@ ff_layout_read_pagelist(struct nfs_pgio_header *hdr)
 out_failed:
 	if (ff_layout_avoid_mds_available_ds(lseg) && !ds_fatal_error)
 		return PNFS_TRY_AGAIN;
+	if (ff_layout_no_fallback_to_mds(lseg)) {
+		/*
+		 * FF_FLAGS_NO_IO_THRU_MDS: force fresh LAYOUTGET,
+		 * never fall through to MDS I/O.
+		 */
+		pnfs_error_mark_layout_for_return(hdr->inode, lseg);
+		return PNFS_TRY_AGAIN;
+	}
 	trace_pnfs_mds_fallback_read_pagelist(hdr->inode,
 			hdr->args.offset, hdr->args.count,
 			IOMODE_READ, NFS_I(hdr->inode)->layout, lseg);
@@ -2289,6 +2297,14 @@ ff_layout_write_pagelist(struct nfs_pgio_header *hdr, int sync)
 out_failed:
 	if (ff_layout_avoid_mds_available_ds(lseg) && !ds_fatal_error)
 		return PNFS_TRY_AGAIN;
+	if (ff_layout_no_fallback_to_mds(lseg)) {
+		/*
+		 * FF_FLAGS_NO_IO_THRU_MDS: force fresh LAYOUTGET,
+		 * never fall through to MDS I/O.
+		 */
+		pnfs_error_mark_layout_for_return(hdr->inode, lseg);
+		return PNFS_TRY_AGAIN;
+	}
 	trace_pnfs_mds_fallback_write_pagelist(hdr->inode,
 			hdr->args.offset, hdr->args.count,
 			IOMODE_RW, NFS_I(hdr->inode)->layout, lseg);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0970/2077] NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (968 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0969/2077] NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0971/2077] nfs: use nfsi->rwsem to protect traversal of the file lock list Greg Kroah-Hartman
                   ` (27 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mike Snitzer, Anna Schumaker,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mike Snitzer <snitzer@kernel.org>

[ Upstream commit 1d62e659c0bf11649cf48e002c2a55d148f2610a ]

The FF_FLAGS_NO_IO_THRU_MDS flag lives on each lseg, so any fallback
decision made when there is no current lseg (e.g. between LAYOUTRETURN
and the next LAYOUTGET) cannot run the per-lseg check.

Introduce a sticky hdr-level ditto for FF_FLAGS_NO_IO_THRU_MDS in
struct nfs4_flexfile_layout::flags (NFS4_FF_HDR_NO_IO_THRU_MDS bit),
set whenever ff_layout_alloc_lseg() parses an lseg with the flag.  The
bit is never cleared for the lifetime of the layout hdr; the server is
assumed to be consistent in its no-fallback policy per file.
kzalloc() in ff_layout_alloc_layout_hdr() zero-initializes the field.

Use the new ff_layout_hdr_no_fallback_to_mds() helper to gate
ff_layout_pg_get_mirror_count_write(): when pnfs_update_layout() returns
NULL (e.g. NFS_LAYOUT_BULK_RECALL, pnfs_layout_io_test_failed,
pnfs_layoutgets_blocked) the existing code unconditionally calls
nfs_pageio_reset_write_mds().  This is a source of unwanted WRITE to
MDS.  Fix it by checking NFS4_FF_HDR_NO_IO_THRU_MDS bit, and if set
surface -EAGAIN instead; the writepage-side caller (nfs_do_writepage()
for buffered, nfs_direct_write_reschedule() for O_DIRECT) then
redirties the request so writeback retries via pNFS.

Fixes: 260074cd8413 ("pNFS/flexfiles: Add support for FF_FLAGS_NO_IO_THRU_MDS")
Assisted-by: Claude:claude-opus-4-7
Signed-off-by: Mike Snitzer <snitzer@kernel.org>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/nfs/flexfilelayout/flexfilelayout.c | 13 +++++++++++++
 fs/nfs/flexfilelayout/flexfilelayout.h | 16 ++++++++++++++++
 2 files changed, 29 insertions(+)

diff --git a/fs/nfs/flexfilelayout/flexfilelayout.c b/fs/nfs/flexfilelayout/flexfilelayout.c
index 80a3c43aaac052..2e7f857d5a8cb2 100644
--- a/fs/nfs/flexfilelayout/flexfilelayout.c
+++ b/fs/nfs/flexfilelayout/flexfilelayout.c
@@ -636,6 +636,9 @@ ff_layout_alloc_lseg(struct pnfs_layout_hdr *lh,
 	if (!p)
 		goto out_sort_mirrors;
 	fls->flags = be32_to_cpup(p);
+	if (fls->flags & FF_FLAGS_NO_IO_THRU_MDS)
+		set_bit(NFS4_FF_HDR_NO_IO_THRU_MDS,
+			&FF_LAYOUT_FROM_HDR(lh)->flags);
 
 	p = xdr_inline_decode(&stream, 4);
 	if (!p)
@@ -1185,6 +1188,16 @@ ff_layout_pg_get_mirror_count_write(struct nfs_pageio_descriptor *pgio,
 			0, NFS4_MAX_UINT64, IOMODE_RW,
 			NFS_I(pgio->pg_inode)->layout,
 			pgio->pg_lseg);
+	if (NFS_I(pgio->pg_inode)->layout &&
+	    ff_layout_hdr_no_fallback_to_mds(NFS_I(pgio->pg_inode)->layout)) {
+		/*
+		 * FF_FLAGS_NO_IO_THRU_MDS: no current lseg but the server's
+		 * policy forbids MDS fallback.  Surface -EAGAIN so writeback
+		 * retries rather than silently issuing the WRITE via MDS.
+		 */
+		pgio->pg_error = -EAGAIN;
+		goto out;
+	}
 	/* no lseg means that pnfs is not in use, so no mirroring here */
 	nfs_pageio_reset_write_mds(pgio);
 out:
diff --git a/fs/nfs/flexfilelayout/flexfilelayout.h b/fs/nfs/flexfilelayout/flexfilelayout.h
index 17a008c8e97ce9..a5bd00f69e8242 100644
--- a/fs/nfs/flexfilelayout/flexfilelayout.h
+++ b/fs/nfs/flexfilelayout/flexfilelayout.h
@@ -112,12 +112,16 @@ struct nfs4_ff_layout_segment {
 	struct nfs4_ff_layout_mirror	*mirror_array[] __counted_by(mirror_array_cnt);
 };
 
+/* nfs4_flexfile_layout::flags bit indices */
+#define NFS4_FF_HDR_NO_IO_THRU_MDS  0   /* any lseg has had FF_FLAGS_NO_IO_THRU_MDS */
+
 struct nfs4_flexfile_layout {
 	struct pnfs_layout_hdr generic_hdr;
 	struct pnfs_ds_commit_info commit_info;
 	struct list_head	mirrors;
 	struct list_head	error_list; /* nfs4_ff_layout_ds_err */
 	ktime_t			last_report_time; /* Layoutstat report times */
+	unsigned long		flags;
 };
 
 struct nfs4_flexfile_layoutreturn_args {
@@ -184,6 +188,18 @@ ff_layout_no_fallback_to_mds(struct pnfs_layout_segment *lseg)
 	return FF_LAYOUT_LSEG(lseg)->flags & FF_FLAGS_NO_IO_THRU_MDS;
 }
 
+/*
+ * Sticky hdr-level mirror of FF_FLAGS_NO_IO_THRU_MDS so callers that have
+ * no current lseg (e.g. between LAYOUTRETURN and the next LAYOUTGET) can
+ * still honor the no-MDS-fallback policy.
+ */
+static inline bool
+ff_layout_hdr_no_fallback_to_mds(struct pnfs_layout_hdr *lo)
+{
+	return test_bit(NFS4_FF_HDR_NO_IO_THRU_MDS,
+			&FF_LAYOUT_FROM_HDR(lo)->flags);
+}
+
 static inline bool
 ff_layout_no_read_on_rw(struct pnfs_layout_segment *lseg)
 {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0971/2077] nfs: use nfsi->rwsem to protect traversal of the file lock list
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (969 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0970/2077] NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0972/2077] PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro Greg Kroah-Hartman
                   ` (26 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Li Lingfeng, Yang Erkun, Jeff Layton,
	Anna Schumaker, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yang Erkun <yangerkun@huawei.com>

[ Upstream commit 4837fb36219e6c08b666bc31a86841bad8526358 ]

Lingfeng identified a bug and suggested two solutions, but both appear
to have issues.

Generally, we cannot release flc_lock while iterating over the file lock
list to avoid use-after-free (UAF) problems with file locks. However,
functions like nfs_delegation_claim_locks and nfs4_reclaim_locks cannot
adhere to this rule because recover_lock or nfs4_lock_delegation_recall
may take a long time. To resolve this, NFS switches to using nfsi->rwsem
for the same protection, and nfs_reclaim_locks follows this approach.
Although nfs_delegation_claim_locks uses so_delegreturn_mutex instead,
this is inadequate since a single inode can have multiple nfs4_state
instances. Therefore, the fix is to also use nfsi->rwsem in this case.

Furthermore, after commit c69899a17ca4 ("NFSv4: Update of VFS byte range
lock must be atomic with the stateid update"), the functions
nfs4_locku_done and nfs4_lock_done also break this rule because they
call locks_lock_inode_wait without holding nfsi->rwsem. Simply adding
this protection could cause many deadlocks, so instead, the call to
locks_lock_inode_wait is moved into _nfs4_proc_setlk. Regarding the bug
fixed by commit c69899a17ca4 ("NFSv4: Update of VFS byte range
lock must be atomic with the stateid update"), it has been resolved
after commit 0460253913e5 ("NFSv4: nfs4_do_open() is incorrectly triggering
state recovery") because all slots are drained before calling
nfs4_do_reclaim, which prevents concurrent stateid changes along this path.
Also, nfs_delegation_claim_locks does not cause this concurrency either
since when _nfs4_proc_setlk is called with NFS_DELEGATED_STATE, no RPC is
sent, so nfs4_lock_done is not called. Therefore,
nfs4_lock_delegation_recall from nfs_delegation_claim_locks is the first
time the stateid is set.

Reported-by: Li Lingfeng <lilingfeng3@huawei.com>
Closes: https://lore.kernel.org/all/20250419085709.1452492-1-lilingfeng3@huawei.com/
Closes: https://lore.kernel.org/all/20250715030559.2906634-1-lilingfeng3@huawei.com/
Fixes: c69899a17ca4 ("NFSv4: Update of VFS byte range lock must be atomic with the stateid update")
Signed-off-by: Yang Erkun <yangerkun@huawei.com>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/nfs/delegation.c     |  9 ++++++++-
 fs/nfs/nfs4proc.c       | 22 +++++++++++-----------
 include/linux/nfs_xdr.h |  1 -
 3 files changed, 19 insertions(+), 13 deletions(-)

diff --git a/fs/nfs/delegation.c b/fs/nfs/delegation.c
index 122fb3f14ffb8b..9546d2195c25f5 100644
--- a/fs/nfs/delegation.c
+++ b/fs/nfs/delegation.c
@@ -173,6 +173,7 @@ int nfs4_check_delegation(struct inode *inode, fmode_t type)
 static int nfs_delegation_claim_locks(struct nfs4_state *state, const nfs4_stateid *stateid)
 {
 	struct inode *inode = state->inode;
+	struct nfs_inode *nfsi = NFS_I(inode);
 	struct file_lock *fl;
 	struct file_lock_context *flctx = locks_inode_context(inode);
 	struct list_head *list;
@@ -182,6 +183,9 @@ static int nfs_delegation_claim_locks(struct nfs4_state *state, const nfs4_state
 		goto out;
 
 	list = &flctx->flc_posix;
+
+	/* Guard against reclaim and new lock/unlock calls */
+	down_write(&nfsi->rwsem);
 	spin_lock(&flctx->flc_lock);
 restart:
 	for_each_file_lock(fl, list) {
@@ -189,8 +193,10 @@ static int nfs_delegation_claim_locks(struct nfs4_state *state, const nfs4_state
 			continue;
 		spin_unlock(&flctx->flc_lock);
 		status = nfs4_lock_delegation_recall(fl, state, stateid);
-		if (status < 0)
+		if (status < 0) {
+			up_write(&nfsi->rwsem);
 			goto out;
+		}
 		spin_lock(&flctx->flc_lock);
 	}
 	if (list == &flctx->flc_posix) {
@@ -198,6 +204,7 @@ static int nfs_delegation_claim_locks(struct nfs4_state *state, const nfs4_state
 		goto restart;
 	}
 	spin_unlock(&flctx->flc_lock);
+	up_write(&nfsi->rwsem);
 out:
 	return status;
 }
diff --git a/fs/nfs/nfs4proc.c b/fs/nfs/nfs4proc.c
index c354b7b9029391..4db27f4eb01e94 100644
--- a/fs/nfs/nfs4proc.c
+++ b/fs/nfs/nfs4proc.c
@@ -7084,7 +7084,6 @@ static void nfs4_locku_done(struct rpc_task *task, void *data)
 	switch (task->tk_status) {
 		case 0:
 			renew_lease(calldata->server, calldata->timestamp);
-			locks_lock_inode_wait(calldata->lsp->ls_state->inode, &calldata->fl);
 			if (nfs4_update_lock_stateid(calldata->lsp,
 					&calldata->res.stateid))
 				break;
@@ -7352,11 +7351,6 @@ static void nfs4_lock_done(struct rpc_task *task, void *calldata)
 	case 0:
 		renew_lease(NFS_SERVER(d_inode(data->ctx->dentry)),
 				data->timestamp);
-		if (data->arg.new_lock && !data->cancelled) {
-			data->fl.c.flc_flags &= ~(FL_SLEEP | FL_ACCESS);
-			if (locks_lock_inode_wait(lsp->ls_state->inode, &data->fl) < 0)
-				goto out_restart;
-		}
 		if (data->arg.new_lock_owner != 0) {
 			nfs_confirm_seqid(&lsp->ls_seqid, 0);
 			nfs4_stateid_copy(&lsp->ls_stateid, &data->res.stateid);
@@ -7467,11 +7461,10 @@ static int _nfs4_do_setlk(struct nfs4_state *state, int cmd, struct file_lock *f
 	msg.rpc_argp = &data->arg;
 	msg.rpc_resp = &data->res;
 	task_setup_data.callback_data = data;
-	if (recovery_type > NFS_LOCK_NEW) {
-		if (recovery_type == NFS_LOCK_RECLAIM)
-			data->arg.reclaim = NFS_LOCK_RECLAIM;
-	} else
-		data->arg.new_lock = 1;
+
+	if (recovery_type == NFS_LOCK_RECLAIM)
+		data->arg.reclaim = NFS_LOCK_RECLAIM;
+
 	task = rpc_run_task(&task_setup_data);
 	if (IS_ERR(task))
 		return PTR_ERR(task);
@@ -7581,6 +7574,13 @@ static int _nfs4_proc_setlk(struct nfs4_state *state, int cmd, struct file_lock
 	up_read(&nfsi->rwsem);
 	mutex_unlock(&sp->so_delegreturn_mutex);
 	status = _nfs4_do_setlk(state, cmd, request, NFS_LOCK_NEW);
+	if (status)
+		goto out;
+
+	down_read(&nfsi->rwsem);
+	request->c.flc_flags &= ~(FL_SLEEP | FL_ACCESS);
+	status = locks_lock_inode_wait(state->inode, request);
+	up_read(&nfsi->rwsem);
 out:
 	request->c.flc_flags = flags;
 	return status;
diff --git a/include/linux/nfs_xdr.h b/include/linux/nfs_xdr.h
index fcbd21b5685f46..40417e3a7f85ad 100644
--- a/include/linux/nfs_xdr.h
+++ b/include/linux/nfs_xdr.h
@@ -580,7 +580,6 @@ struct nfs_lock_args {
 	struct nfs_lowner	lock_owner;
 	unsigned char		block : 1;
 	unsigned char		reclaim : 1;
-	unsigned char		new_lock : 1;
 	unsigned char		new_lock_owner : 1;
 };
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0972/2077] PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (970 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0971/2077] nfs: use nfsi->rwsem to protect traversal of the file lock list Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0973/2077] pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages Greg Kroah-Hartman
                   ` (25 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Li RongQing, Manivannan Sadhasivam,
	Krzysztof Wilczyński, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Li RongQing <lirongqing@baidu.com>

[ Upstream commit 282305d7e9c0e27fd8b4df34b7cd5506a1eccdd6 ]

The original PCIE_FTS_NUM_L0(x) macro was buggy due to improper operator
precedence, where ((x) & 0xff << 8) was evaluated as ((x) & 0xff00).

Instead of just fixing the parentheses, use the standard FIELD_PREP()
macro. This makes the code more robust by automatically handling masks
and shifts, while also adding compile-time type and range checking to
ensure the value fits within PCIE_FTS_NUM_MASK.

Fixes: 637cfacae96f ("PCI: mediatek: Add MediaTek PCIe host controller support")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
[mani: added the bitfield header include spotted by Sashiko]
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Reviewed-by: Krzysztof Wilczyński <kwilczynski@kernel.org>
Link: https://patch.msgid.link/20260515005552.2343-1-lirongqing@baidu.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/pcie-mediatek.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/pci/controller/pcie-mediatek.c b/drivers/pci/controller/pcie-mediatek.c
index 907ae4285ecb1b..f34d91e495bc11 100644
--- a/drivers/pci/controller/pcie-mediatek.c
+++ b/drivers/pci/controller/pcie-mediatek.c
@@ -7,6 +7,7 @@
  *	   Honghui Zhang <honghui.zhang@mediatek.com>
  */
 
+#include <linux/bitfield.h>
 #include <linux/clk.h>
 #include <linux/delay.h>
 #include <linux/iopoll.h>
@@ -61,7 +62,7 @@
 /* MediaTek specific configuration registers */
 #define PCIE_FTS_NUM		0x70c
 #define PCIE_FTS_NUM_MASK	GENMASK(15, 8)
-#define PCIE_FTS_NUM_L0(x)	((x) & 0xff << 8)
+#define PCIE_FTS_NUM_L0(x)	FIELD_PREP(PCIE_FTS_NUM_MASK, x)
 
 #define PCIE_FC_CREDIT		0x73c
 #define PCIE_FC_CREDIT_MASK	(GENMASK(31, 31) | GENMASK(28, 16))
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0973/2077] pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (971 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0972/2077] PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0974/2077] PCI: meson: Propagate devm_add_action_or_reset() failure Greg Kroah-Hartman
                   ` (24 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Biju Das, Uwe Kleine-König,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Biju Das <biju.das.jz@bp.renesas.com>

[ Upstream commit 898ab0f30e008e411ce93ddf81c4099abd9d4e46 ]

dev_err_probe() internally calls dev_err() which uses pr_fmt() and
printk(). Kernel log messages should end with a newline character
to ensure proper log formatting. Add missing '\n' at the end of
the error strings in rzg2l_gpt_probe().

Signed-off-by: Biju Das <biju.das.jz@bp.renesas.com>
Link: https://patch.msgid.link/20260604095647.108654-5-biju.das.jz@bp.renesas.com
Fixes: 061f087f5d0b ("pwm: Add support for RZ/G2L GPT")
Signed-off-by: Uwe Kleine-König <ukleinek@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pwm/pwm-rzg2l-gpt.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/pwm/pwm-rzg2l-gpt.c b/drivers/pwm/pwm-rzg2l-gpt.c
index 4856af080e8e9f..8534a2a9cf7505 100644
--- a/drivers/pwm/pwm-rzg2l-gpt.c
+++ b/drivers/pwm/pwm-rzg2l-gpt.c
@@ -408,14 +408,14 @@ static int rzg2l_gpt_probe(struct platform_device *pdev)
 
 	rate = clk_get_rate(clk);
 	if (!rate)
-		return dev_err_probe(dev, -EINVAL, "The gpt clk rate is 0");
+		return dev_err_probe(dev, -EINVAL, "The gpt clk rate is 0\n");
 
 	/*
 	 * Refuse clk rates > 1 GHz to prevent overflow later for computing
 	 * period and duty cycle.
 	 */
 	if (rate > NSEC_PER_SEC)
-		return dev_err_probe(dev, -EINVAL, "The gpt clk rate is > 1GHz");
+		return dev_err_probe(dev, -EINVAL, "The gpt clk rate is > 1GHz\n");
 
 	/*
 	 * Rate is in MHz and is always integer for peripheral clk
@@ -424,7 +424,7 @@ static int rzg2l_gpt_probe(struct platform_device *pdev)
 	 */
 	rzg2l_gpt->rate_khz = rate / KILO;
 	if (rzg2l_gpt->rate_khz * KILO != rate)
-		return dev_err_probe(dev, -EINVAL, "Rate is not multiple of 1000");
+		return dev_err_probe(dev, -EINVAL, "Rate is not multiple of 1000\n");
 
 	mutex_init(&rzg2l_gpt->lock);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0974/2077] PCI: meson: Propagate devm_add_action_or_reset() failure
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (972 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0973/2077] pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0975/2077] PCI: meson: Add missing remove callback Greg Kroah-Hartman
                   ` (23 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shuvam Pandey, Manivannan Sadhasivam,
	Neil Armstrong, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shuvam Pandey <shuvampandey1@gmail.com>

[ Upstream commit b12341b98d5ac52f48ca1390e1e371aed81346c8 ]

meson_pcie_probe_clock() enables a clock and then registers a devres
action to disable it during teardown. If devm_add_action_or_reset()
fails, it runs the action immediately, disabling the clock.

The return value is currently ignored, so on that failure path,
meson_pcie_probe_clock() returns the disabled clock and probe continues.
Return the error so the existing probe error path unwinds normally.

Fixes: 9c0ef6d34fdbf ("PCI: amlogic: Add the Amlogic Meson PCIe controller driver")
Signed-off-by: Shuvam Pandey <shuvampandey1@gmail.com>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/177909148011.9588.6639767953842842291@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/dwc/pci-meson.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/pci/controller/dwc/pci-meson.c b/drivers/pci/controller/dwc/pci-meson.c
index 0694084f612b79..8d495bcc3a41ae 100644
--- a/drivers/pci/controller/dwc/pci-meson.c
+++ b/drivers/pci/controller/dwc/pci-meson.c
@@ -204,7 +204,9 @@ static inline struct clk *meson_pcie_probe_clock(struct device *dev,
 		return ERR_PTR(ret);
 	}
 
-	devm_add_action_or_reset(dev, meson_pcie_disable_clock, clk);
+	ret = devm_add_action_or_reset(dev, meson_pcie_disable_clock, clk);
+	if (ret)
+		return ERR_PTR(ret);
 
 	return clk;
 }
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0975/2077] PCI: meson: Add missing remove callback
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (973 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0974/2077] PCI: meson: Propagate devm_add_action_or_reset() failure Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0976/2077] lockd: Correct kernel-doc status descriptions for NLMv4 GRANTED Greg Kroah-Hartman
                   ` (22 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shuvam Pandey, Manivannan Sadhasivam,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shuvam Pandey <shuvampandey1@gmail.com>

[ Upstream commit 4b0dc84b293984f75598881809fb2d3daf54a2a8 ]

meson_pcie_probe() powers on the PHY and registers the DesignWare host
bridge with dw_pcie_host_init(), but the driver has no remove callback.
On driver unbind or module unload, the driver core therefore proceeds to
devres cleanup without first unregistering the host bridge or powering off
the PHY.

Add a remove callback that deinitializes the DesignWare host bridge and
powers off the PHY while device-managed resources are still valid.

Fixes: 9c0ef6d34fdb ("PCI: amlogic: Add the Amlogic Meson PCIe controller driver")
Signed-off-by: Shuvam Pandey <shuvampandey1@gmail.com>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Link: https://patch.msgid.link/1a0c86ab264cdc1c79c917e984b90991af51d827.1779123847.git.shuvampandey1@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/dwc/pci-meson.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/drivers/pci/controller/dwc/pci-meson.c b/drivers/pci/controller/dwc/pci-meson.c
index 8d495bcc3a41ae..225d887cd0a3e1 100644
--- a/drivers/pci/controller/dwc/pci-meson.c
+++ b/drivers/pci/controller/dwc/pci-meson.c
@@ -453,6 +453,14 @@ static int meson_pcie_probe(struct platform_device *pdev)
 	return ret;
 }
 
+static void meson_pcie_remove(struct platform_device *pdev)
+{
+	struct meson_pcie *mp = platform_get_drvdata(pdev);
+
+	dw_pcie_host_deinit(&mp->pci.pp);
+	meson_pcie_power_off(mp);
+}
+
 static const struct of_device_id meson_pcie_of_match[] = {
 	{
 		.compatible = "amlogic,axg-pcie",
@@ -466,6 +474,7 @@ MODULE_DEVICE_TABLE(of, meson_pcie_of_match);
 
 static struct platform_driver meson_pcie_driver = {
 	.probe = meson_pcie_probe,
+	.remove = meson_pcie_remove,
 	.driver = {
 		.name = "meson-pcie",
 		.of_match_table = meson_pcie_of_match,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0976/2077] lockd: Correct kernel-doc status descriptions for NLMv4 GRANTED
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (974 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0975/2077] PCI: meson: Add missing remove callback Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0977/2077] virtio: add missing kernel-doc for map and vmap members Greg Kroah-Hartman
                   ` (21 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jeff Layton, Chuck Lever,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 5412049208e669925f7b08bbfabe3cd28a598c5b ]

NLM_GRANTED is a server-to-client callback; the local node
responds in the role of the client. The kernel-doc for
nlm4svc_proc_granted attributes NLM4_DENIED and
NLM4_DENIED_GRACE_PERIOD to "the server", but per the Open
Group XNFS specification the responder for this procedure is
the client host, and NLM4_DENIED_GRACE_PERIOD identifies the
client's own grace period after a reboot, not the server's.

Rewrite the descriptions to match the spec: NLM4_DENIED
reflects the generic internal-resource-constraint failure, and
NLM4_DENIED_GRACE_PERIOD attributes the grace period to the
client host that received the callback.

Fixes: 7a9f7c8f934e ("lockd: Use xdrgen XDR functions for the NLMv4 GRANTED procedure")
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/lockd/svc4proc.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/fs/lockd/svc4proc.c b/fs/lockd/svc4proc.c
index 3bf6cccae56858..f3ba2615ae77db 100644
--- a/fs/lockd/svc4proc.c
+++ b/fs/lockd/svc4proc.c
@@ -516,12 +516,12 @@ nlm4svc_proc_unlock(struct svc_rqst *rqstp)
  *   nlm4_res NLMPROC4_GRANTED(nlm4_testargs) = 5;
  *
  * Permissible procedure status codes:
- *   %NLM4_GRANTED:		The requested lock was granted.
- *   %NLM4_DENIED:		The server could not allocate the resources
- *				needed to process the request.
- *   %NLM4_DENIED_GRACE_PERIOD:	The server has recently restarted and is
- *				re-establishing existing locks, and is not
- *				yet ready to accept normal service requests.
+ *   %NLM4_GRANTED:		The granted lock was accepted.
+ *   %NLM4_DENIED:		The procedure failed, possibly due to
+ *				internal resource constraints.
+ *   %NLM4_DENIED_GRACE_PERIOD:	The client host recently restarted and
+ *				its NLM is re-establishing existing locks,
+ *				so it is not yet ready to accept callbacks.
  */
 static __be32
 nlm4svc_proc_granted(struct svc_rqst *rqstp)
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0977/2077] virtio: add missing kernel-doc for map and vmap members
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (975 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0976/2077] lockd: Correct kernel-doc status descriptions for NLMv4 GRANTED Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0978/2077] fs/ntfs3: prevent potential lcn remains uninitialized Greg Kroah-Hartman
                   ` (20 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Luis Felipe Hernandez,
	Christian Fontanez, Michael S. Tsirkin, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Fontanez <christfontanez@gmail.com>

[ Upstream commit ac2c52e9f869897b6f4c0a54cf07da380ef2b8d6 ]

Commit bee8c7c24b73 ("virtio: introduce map ops in virtio core") and
commit b16060c5c7d5 ("virtio: introduce virtio_map container union")
added 'map' and 'vmap' members to struct virtio_device but did not
update the kernel-doc comment block. This caused 'make htmldocs' to
emit warnings:

  ./include/linux/virtio.h:188 struct member 'map' not described in 'virtio_device'
  ./include/linux/virtio.h:188 struct member 'vmap' not described in 'virtio_device'

Add the missing entries in struct-declaration order to match the
existing convention in the file. After this patch, 'make htmldocs'
no longer emits these warnings.

Fixes: bee8c7c24b73 ("virtio: introduce map ops in virtio core")
Fixes: b16060c5c7d5 ("virtio: introduce virtio_map container union")
Reported-by: Luis Felipe Hernandez <luis.hernandez093@gmail.com>

Signed-off-by: Christian Fontanez <christfontanez@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260519013321.32511-1-christfontanez@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 include/linux/virtio.h | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/include/linux/virtio.h b/include/linux/virtio.h
index 3bbc4cb6a6727e..bf089e51970ec6 100644
--- a/include/linux/virtio.h
+++ b/include/linux/virtio.h
@@ -157,11 +157,13 @@ struct virtio_admin_cmd {
  * @id: the device type identification (used to match it with a driver).
  * @config: the configuration ops for this device.
  * @vringh_config: configuration ops for host vrings.
+ * @map: the map operations for mapping virtio device memory.
  * @vqs: the list of virtqueues for this device.
  * @features: the 64 lower features supported by both driver and device.
  * @features_array: the full features space supported by both driver and
  *		    device.
  * @priv: private pointer for the driver's use.
+ * @vmap: the map container with transport- or device-specific metadata.
  * @debugfs_dir: debugfs directory entry.
  * @debugfs_filter_features: features to be filtered set by debugfs.
  */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0978/2077] fs/ntfs3: prevent potential lcn remains uninitialized
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (976 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0977/2077] virtio: add missing kernel-doc for map and vmap members Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0979/2077] fs/ntfs3: resize log->one_page_buf when adopting on-disk page size Greg Kroah-Hartman
                   ` (19 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+c2cfe997245202e46f10,
	Edward Adam Davis, Konstantin Komarov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Edward Adam Davis <eadavis@qq.com>

[ Upstream commit 57ac2831c8e0f168090d38e3de758c6a59db44db ]

The target VCN being sought was not found within runs[0], causing
run_lookup() to return false. This causes run_lookup_entry() to return
false, which in turn results in a len value of 0, and the new parameter
passed to attr_data_get_block() is NULL. Collectively, these factors
ultimately cause attr_data_get_block_locked() to exit prematurely without
initializing lcn, thereby triggering [1].

To prevent [1], the clen check within ni_seek_data_or_hole() has been
moved to occur before the lcn check.

[1]
BUG: KMSAN: uninit-value in ni_seek_data_or_hole+0x24f/0x5f0 fs/ntfs3/frecord.c:2862
 ni_seek_data_or_hole+0x24f/0x5f0 fs/ntfs3/frecord.c:2862
 ntfs_llseek+0x22a/0x4a0 fs/ntfs3/file.c:1530
 vfs_llseek fs/read_write.c:391 [inline]

Fixes: c61326967728 ("fs/ntfs3: implement llseek SEEK_DATA/SEEK_HOLE by scanning data runs")
Reported-by: syzbot+c2cfe997245202e46f10@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c2cfe997245202e46f10
Signed-off-by: Edward Adam Davis <eadavis@qq.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs3/frecord.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/fs/ntfs3/frecord.c b/fs/ntfs3/frecord.c
index bb3348f256d997..974c55ae2c0145 100644
--- a/fs/ntfs3/frecord.c
+++ b/fs/ntfs3/frecord.c
@@ -2859,6 +2859,11 @@ loff_t ni_seek_data_or_hole(struct ntfs_inode *ni, loff_t offset, bool data)
 			return err;
 		}
 
+		if (!clen) {
+			/* Corrupted file. */
+			return -EINVAL;
+		}
+
 		if (lcn == RESIDENT_LCN) {
 			/* clen - resident size in bytes. clen == ni->vfs_inode.i_size */
 			if (offset >= clen) {
@@ -2909,10 +2914,6 @@ loff_t ni_seek_data_or_hole(struct ntfs_inode *ni, loff_t offset, bool data)
 			}
 		}
 
-		if (!clen) {
-			/* Corrupted file. */
-			return -EINVAL;
-		}
 	}
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0979/2077] fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (977 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0978/2077] fs/ntfs3: prevent potential lcn remains uninitialized Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0980/2077] platform/x86/intel/vsec: Restore BAR fallback for header walk Greg Kroah-Hartman
                   ` (18 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Carol L Soto, Jamie Nguyen,
	Konstantin Komarov, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jamie Nguyen <jamien@nvidia.com>

[ Upstream commit 5a35454179fe1041d9cd286f5d320ce0d448c12a ]

log_replay() allocates log->one_page_buf using the page size that was
chosen from the host PAGE_SIZE:

	log->one_page_buf = kmalloc(log->page_size, GFP_NOFS);

Later, when a restart area is found, the log page size recorded on disk
is adopted:

	t32 = le32_to_cpu(log->rst_info.r_page->sys_page_size);
	if (log->page_size != t32) {
		log->l_size = log->orig_file_size;
		log->page_size = norm_file_page(t32, &log->l_size,
						t32 == DefaultLogPageSize);
	}

If the on-disk page size is larger than the size used for the initial
allocation, log->page_size grows but one_page_buf is left at its
original, smaller size. A subsequent unaligned read_log_page() then
reads log->page_size bytes into the undersized scratch buffer:

	page_buf = page_off ? log->one_page_buf : *buffer;
	err = ntfs_read_run_nb_ra(ni->mi.sbi, &ni->file.run, page_vbo, page_buf,
				  log->page_size, NULL, &log->read_ahead);

overflowing the allocation. This is reachable when mounting a dirty
NTFS volume whose log was formatted with a page size larger than the
buffer initially allocated on the mounting host (for example a 64K-log
volume mounted on a host that allocated a 4K scratch buffer).

Grow one_page_buf when the adopted on-disk page size exceeds the size
used for the initial allocation. On krealloc() failure the original
buffer is left intact and freed by the existing error path.

Fixes: b46acd6a6a627 ("fs/ntfs3: Add NTFS journal")
Reported-by: Carol L Soto <csoto@nvidia.com>
Signed-off-by: Jamie Nguyen <jamien@nvidia.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 fs/ntfs3/fslog.c | 19 +++++++++++++++++++
 1 file changed, 19 insertions(+)

diff --git a/fs/ntfs3/fslog.c b/fs/ntfs3/fslog.c
index 3c320e7a4c12fb..a76d4c3cd3946b 100644
--- a/fs/ntfs3/fslog.c
+++ b/fs/ntfs3/fslog.c
@@ -3937,9 +3937,28 @@ int log_replay(struct ntfs_inode *ni, bool *initialized)
 	 */
 	t32 = le32_to_cpu(log->rst_info.r_page->sys_page_size);
 	if (log->page_size != t32) {
+		u32 old_page_size = log->page_size;
+
 		log->l_size = log->orig_file_size;
 		log->page_size = norm_file_page(t32, &log->l_size,
 						t32 == DefaultLogPageSize);
+
+		/*
+		 * If the adopted on-disk page size is larger than the size used
+		 * to allocate one_page_buf above, grow the scratch buffer so a
+		 * later read_log_page() cannot overflow it.
+		 */
+		if (log->page_size > old_page_size) {
+			void *buf;
+
+			buf = krealloc(log->one_page_buf, log->page_size,
+				       GFP_NOFS);
+			if (!buf) {
+				err = -ENOMEM;
+				goto out;
+			}
+			log->one_page_buf = buf;
+		}
 	}
 
 	if (log->page_size != t32 ||
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0980/2077] platform/x86/intel/vsec: Restore BAR fallback for header walk
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (978 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0979/2077] fs/ntfs3: resize log->one_page_buf when adopting on-disk page size Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0981/2077] perf tools: Fix get_max_num() size_t underflow on empty sysfs file Greg Kroah-Hartman
                   ` (17 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David E. Box, Michael J. Ruhl,
	Ilpo Järvinen, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David E. Box <david.e.box@linux.intel.com>

[ Upstream commit 375bbbbd112af028ee0b45d833a6233c23d19bbf ]

The base_addr refactor changed intel_vsec_walk_header() to pass
info->base_addr as the discovery-table base address. For the PCI VSEC
driver this info comes from driver_data, but exported callers may provide
their own static headers and leave base_addr unset.

For xe, this made the discovery-table base address zero instead of the BAR
selected by header->tbir, preventing PMT endpoints from being created.

Restore the previous behavior for the header-walk path by falling back to
pci_resource_start(pdev, header->tbir) when base_addr is not specified.
Keep explicit base_addr override behavior unchanged.

This preserves the refactor structure while fixing the functional
regression in manual-header users.

Fixes: 904b333fc51c ("platform/x86/intel/vsec: Refactor base_addr handling")
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: David E. Box <david.e.box@linux.intel.com>
Reviewed-by: Michael J. Ruhl <michael.j.ruhl@intel.com>
Link: https://patch.msgid.link/20260529183150.129744-1-david.e.box@linux.intel.com
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/platform/x86/intel/vsec.c | 17 ++++++++++++++++-
 1 file changed, 16 insertions(+), 1 deletion(-)

diff --git a/drivers/platform/x86/intel/vsec.c b/drivers/platform/x86/intel/vsec.c
index 18e4a892bf0f0f..439c0c8ac896c7 100644
--- a/drivers/platform/x86/intel/vsec.c
+++ b/drivers/platform/x86/intel/vsec.c
@@ -488,10 +488,25 @@ static int intel_vsec_walk_header(struct device *dev,
 				  const struct intel_vsec_platform_info *info)
 {
 	struct intel_vsec_header **header = info->headers;
+	u64 base_addr;
 	int ret;
 
 	for ( ; *header; header++) {
-		ret = intel_vsec_register_device(dev, *header, info, info->base_addr);
+		if (info->base_addr) {
+			base_addr = info->base_addr;
+		} else {
+			struct pci_dev *pdev;
+
+			if (!dev_is_pci(dev)) {
+				dev_err(dev, "non-PCI device without a base address\n");
+				return -EINVAL;
+			}
+
+			pdev = to_pci_dev(dev);
+			base_addr = pci_resource_start(pdev, (*header)->tbir);
+		}
+
+		ret = intel_vsec_register_device(dev, *header, info, base_addr);
 		if (ret)
 			return ret;
 	}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0981/2077] perf tools: Fix get_max_num() size_t underflow on empty sysfs file
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (979 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0980/2077] platform/x86/intel/vsec: Restore BAR fallback for header walk Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0982/2077] perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow Greg Kroah-Hartman
                   ` (16 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers, Don Zickus,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 0a012113bb3a44482c163f16f4db03ccaa37a339 ]

get_max_num() reads a sysfs file (cpu/possible, cpu/present, or
node/possible) and scans backward from the end to find the last
number.  If the file is empty, filename__read_str() returns num == 0.
The loop `while (--num)` decrements the size_t from 0 to SIZE_MAX,
reading backward across the heap until a comma or hyphen is found
or unmapped memory is hit.

Add an early return for empty files before the backward scan.

Fixes: 7780c25bae59fd04 ("perf tools: Allow ability to map cpus to nodes easily")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Don Zickus <dzickus@redhat.com>
Cc: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/cpumap.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/tools/perf/util/cpumap.c b/tools/perf/util/cpumap.c
index b754e331bdfe8c..59173db168f16f 100644
--- a/tools/perf/util/cpumap.c
+++ b/tools/perf/util/cpumap.c
@@ -420,6 +420,12 @@ static int get_max_num(char *path, int *max)
 
 	buf[num] = '\0';
 
+	/* empty file — nothing to parse */
+	if (num == 0) {
+		err = -1;
+		goto out;
+	}
+
 	/* start on the right, to find highest node num */
 	while (--num) {
 		if ((buf[num] == ',') || (buf[num] == '-')) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0982/2077] perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (980 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0981/2077] perf tools: Fix get_max_num() size_t underflow on empty sysfs file Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0983/2077] perf tools: Use perf_env__get_cpu_topology() in machine__resolve() Greg Kroah-Hartman
                   ` (15 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers, Jiri Olsa,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 7953a3a9b8e02e98c6e6958f291d0ae22393e46a ]

cpu_map__snprint() accumulates snprintf() return values in ret.
snprintf() returns the number of characters that *would have been
written* on truncation, not the actual count.  When a fragmented CPU
list exceeds the buffer, ret grows past size, causing `size - ret` to
underflow (both are size_t), and subsequent snprintf() calls write
past the end of the caller's stack buffer.

Switch to scnprintf() which returns the actual number of characters
written, making ret accumulation safe by construction.

Fixes: a24020e6b7cf6eb8 ("perf tools: Change cpu_map__fprintf output")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/cpumap.c | 18 +++++++++---------
 1 file changed, 9 insertions(+), 9 deletions(-)

diff --git a/tools/perf/util/cpumap.c b/tools/perf/util/cpumap.c
index 59173db168f16f..dbbec195cffdc1 100644
--- a/tools/perf/util/cpumap.c
+++ b/tools/perf/util/cpumap.c
@@ -664,21 +664,21 @@ size_t cpu_map__snprint(struct perf_cpu_map *map, char *buf, size_t size)
 		if (start == -1) {
 			start = i;
 			if (last) {
-				ret += snprintf(buf + ret, size - ret,
-						"%s%d", COMMA,
-						perf_cpu_map__cpu(map, i).cpu);
+				ret += scnprintf(buf + ret, size - ret,
+						 "%s%d", COMMA,
+						 perf_cpu_map__cpu(map, i).cpu);
 			}
 		} else if (((i - start) != (cpu.cpu - perf_cpu_map__cpu(map, start).cpu)) || last) {
 			int end = i - 1;
 
 			if (start == end) {
-				ret += snprintf(buf + ret, size - ret,
-						"%s%d", COMMA,
-						perf_cpu_map__cpu(map, start).cpu);
+				ret += scnprintf(buf + ret, size - ret,
+						 "%s%d", COMMA,
+						 perf_cpu_map__cpu(map, start).cpu);
 			} else {
-				ret += snprintf(buf + ret, size - ret,
-						"%s%d-%d", COMMA,
-						perf_cpu_map__cpu(map, start).cpu, perf_cpu_map__cpu(map, end).cpu);
+				ret += scnprintf(buf + ret, size - ret,
+						 "%s%d-%d", COMMA,
+						 perf_cpu_map__cpu(map, start).cpu, perf_cpu_map__cpu(map, end).cpu);
 			}
 			first = false;
 			start = i;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0983/2077] perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (981 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0982/2077] perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0984/2077] perf tools: NULL bitmap pointers after bitmap_free() Greg Kroah-Hartman
                   ` (14 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers, Kan Liang,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 5484b43a0ec8231c36fba6ead654cb72dbba8b8f ]

machine__resolve() accesses env->cpu[al->cpu].socket_id after checking
al->cpu >= 0 and env->cpu != NULL, but without validating al->cpu
against env->nr_cpus_avail.  Since al->cpu comes from the untrusted
perf.data sample, a crafted file with a large CPU index causes an
out-of-bounds heap read.

Use perf_env__get_cpu_topology() which validates both NULL and bounds.
Also bounds-check al->cpu before the cast to struct perf_cpu (int16_t):
without this, values like 65536 silently truncate to 0, bypassing the
accessor's internal check and returning CPU 0's topology.

Fixes: 0c4c4debb0adda4c ("perf tools: Add processor socket info to hist_entry and addr_location")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Kan Liang <kan.liang@intel.com>
Cc: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/event.c | 15 +++++++++++++--
 1 file changed, 13 insertions(+), 2 deletions(-)

diff --git a/tools/perf/util/event.c b/tools/perf/util/event.c
index 66f4843bb235df..ea75816d126a14 100644
--- a/tools/perf/util/event.c
+++ b/tools/perf/util/event.c
@@ -14,6 +14,7 @@
 #include <linux/perf_event.h>
 #include "cpumap.h"
 #include "dso.h"
+#include "env.h"
 #include "event.h"
 #include "debug.h"
 #include "hist.h"
@@ -836,8 +837,18 @@ int machine__resolve(struct machine *machine, struct addr_location *al,
 	if (al->cpu >= 0) {
 		struct perf_env *env = machine->env;
 
-		if (env && env->cpu)
-			al->socket = env->cpu[al->cpu].socket_id;
+		/*
+		 * Bounds-check al->cpu (s32) before casting to struct perf_cpu
+		 * (int16_t): without this, e.g. 65536 truncates to 0 and silently
+		 * returns CPU 0's topology.  Can go once perf_cpu.cpu is widened.
+		 */
+		if (env && al->cpu < env->nr_cpus_avail) {
+			struct cpu_topology_map *topo;
+
+			topo = perf_env__get_cpu_topology(env, (struct perf_cpu){ al->cpu });
+			if (topo)
+				al->socket = topo->socket_id;
+		}
 	}
 
 	/* Account for possible out-of-order switch events. */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0984/2077] perf tools: NULL bitmap pointers after bitmap_free()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (982 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0983/2077] perf tools: Use perf_env__get_cpu_topology() in machine__resolve() Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0985/2077] PCI: rcar-host: Remove unused LIST_HEAD(res) Greg Kroah-Hartman
                   ` (13 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers,
	Alexey Budankov, Alexey Bayduraev, Arnaldo Carvalho de Melo,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit a9e900bc5c5914aca750afafa459363e575d3046 ]

Two call sites free bitmaps without NULLing the pointer, risking
double-free if the structure is reused or cleanup is called twice:

 - mmap__munmap():                 map->affinity_mask.bits
 - record__mmap_cpu_mask_free():   mask->bits

Set each pointer to NULL after bitmap_free().

Fixes: 8384a2600c7ddfc8 ("perf record: Adapt affinity to machines with #CPUs > 1K")
Fixes: f466e5ed6c356d1d ("perf record: Extend --threads command line option")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Alexey Budankov <alexey.budankov@linux.intel.com>
Cc: Alexey Bayduraev <alexey.v.bayduraev@linux.intel.com>
Cc: Arnaldo Carvalho de Melo <acme@redhat.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-record.c | 1 +
 tools/perf/util/mmap.c      | 2 ++
 2 files changed, 3 insertions(+)

diff --git a/tools/perf/builtin-record.c b/tools/perf/builtin-record.c
index 708825747af5da..1593cf3a834bda 100644
--- a/tools/perf/builtin-record.c
+++ b/tools/perf/builtin-record.c
@@ -3080,6 +3080,7 @@ static int record__mmap_cpu_mask_alloc(struct mmap_cpu_mask *mask, int nr_bits)
 static void record__mmap_cpu_mask_free(struct mmap_cpu_mask *mask)
 {
 	bitmap_free(mask->bits);
+	mask->bits = NULL;
 	mask->nbits = 0;
 }
 
diff --git a/tools/perf/util/mmap.c b/tools/perf/util/mmap.c
index d64aec6c7c843e..358e70c4f3edd0 100644
--- a/tools/perf/util/mmap.c
+++ b/tools/perf/util/mmap.c
@@ -238,6 +238,8 @@ static void perf_mmap__aio_munmap(struct mmap *map __maybe_unused)
 void mmap__munmap(struct mmap *map)
 {
 	bitmap_free(map->affinity_mask.bits);
+	map->affinity_mask.bits = NULL;
+	map->affinity_mask.nbits = 0;
 
 	zstd_fini(&map->zstd_data);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0985/2077] PCI: rcar-host: Remove unused LIST_HEAD(res)
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (983 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0984/2077] perf tools: NULL bitmap pointers after bitmap_free() Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:10 ` [PATCH 7.1 0986/2077] perf sched: Bounds-check prio before test_bit() in timehist Greg Kroah-Hartman
                   ` (12 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lad Prabhakar, Manivannan Sadhasivam,
	Geert Uytterhoeven, Marek Vasut, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>

[ Upstream commit 6ba90ce2069ae923b0ec787aebdf2d786e5d2a58 ]

Remove the unused LIST_HEAD(res) declaration from rcar_pcie_hw_enable().

The macro instantiation defines an unused 'struct list_head res' variable,
which conflicts with a valid resource loop-local 'struct resource *res'
declaration further down in the function, triggering a compiler variable
shadowing warning:

 drivers/pci/controller/pcie-rcar-host.c:357:34: warning: declaration of 'res' shadows a previous local [-Wshadow]
 357 |                  struct resource *res = win->res;

Fixes: ce351636c67f75a9 ("PCI: rcar: Add suspend/resume")
Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Marek Vasut <marek.vasut+renesas@mailbox.org>
Link: https://patch.msgid.link/20260521091256.15737-1-prabhakar.mahadev-lad.rj@bp.renesas.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/pci/controller/pcie-rcar-host.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/pci/controller/pcie-rcar-host.c b/drivers/pci/controller/pcie-rcar-host.c
index 213028052aa589..cd9171eebc2891 100644
--- a/drivers/pci/controller/pcie-rcar-host.c
+++ b/drivers/pci/controller/pcie-rcar-host.c
@@ -346,7 +346,6 @@ static void rcar_pcie_hw_enable(struct rcar_pcie_host *host)
 	struct rcar_pcie *pcie = &host->pcie;
 	struct pci_host_bridge *bridge = pci_host_bridge_from_priv(host);
 	struct resource_entry *win;
-	LIST_HEAD(res);
 	int i = 0;
 
 	/* Try setting 5 GT/s link speed */
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0986/2077] perf sched: Bounds-check prio before test_bit() in timehist
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (984 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0985/2077] PCI: rcar-host: Remove unused LIST_HEAD(res) Greg Kroah-Hartman
@ 2026-07-21 15:10 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0987/2077] perf sched: Fix idle-hist callchain display using wrong rb_first variant Greg Kroah-Hartman
                   ` (11 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:10 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers, Yang Jihong,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 4477dc01fcfc7f404772a67e0c1e056541ceb61d ]

timehist_skip_sample() reads prio from untrusted tracepoint data via
perf_sample__intval(sample, "prev_prio") without bounds validation.
A crafted perf.data with prev_prio >= MAX_PRIO (140) causes test_bit()
to read past the end of the prio_bitmap, which is only MAX_PRIO bits.

Add a prio >= 0 guard before the test_bit() call and skip out-of-range
values (>= MAX_PRIO) that can never match the user's filter set.

The original prio != -1 already let all negatives other than -1 through
(after an undefined-behavior bitmap read); the new prio >= 0 guard
preserves that pass-through behavior — negative means "no priority
info", so the event is shown unfiltered — while fixing the OOB.
Values >= MAX_PRIO are skipped because they cannot be represented in
the filter bitmap.

Fixes: 9b3a48bbe20d9692 ("perf sched timehist: Add --prio option")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Yang Jihong <yangjihong@bytedance.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index defbf8dc26073c..6cf034f60c6667 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -2647,7 +2647,9 @@ static bool timehist_skip_sample(struct perf_sched *sched,
 		else if (evsel__name_is(evsel, "sched:sched_switch"))
 			prio = evsel__intval(evsel, sample, "prev_prio");
 
-		if (prio != -1 && !test_bit(prio, sched->prio_bitmap)) {
+		/* negative prio means no info; out-of-range prio can't match the filter */
+		if (prio >= 0 &&
+		    (prio >= MAX_PRIO || !test_bit(prio, sched->prio_bitmap))) {
 			rc = true;
 			sched->skipped_samples++;
 		}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0987/2077] perf sched: Fix idle-hist callchain display using wrong rb_first variant
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (985 preceding siblings ...)
  2026-07-21 15:10 ` [PATCH 7.1 0986/2077] perf sched: Bounds-check prio before test_bit() in timehist Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0988/2077] perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code Greg Kroah-Hartman
                   ` (10 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Davidlohr Bueso,
	Namhyung Kim, Ian Rogers, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit d9b99dc8148e0c1f5da3942131b47e0d21187a32 ]

timehist_print_idlehist_callchain() calls rb_first_cached() on
sorted_root, but the sort function (callchain_param.sort) populates it
via rb_insert_color() on the plain rb_root member — not the cached
variant.  This means rb_leftmost is never set, so rb_first_cached()
always returns NULL and the entire callchain summary is silently
dropped from --idle-hist output.

The original code in ba957ebb54893aca ("perf sched timehist: Show
callchains for idle stat") was correct — it used struct rb_root and
rb_first().  The bug was introduced when sorted_root was converted to
rb_root_cached without converting the sort insertion path to use
rb_insert_color_cached().

Use rb_first(&root->rb_root) to match how the tree was populated.

Fixes: cb4c13a5137766c3 ("perf sched: Use cached rbtrees")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Davidlohr Bueso <dave@stgolabs.net>
Cc: Namhyung Kim <namhyung@kernel.org>
Acked-by: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/builtin-sched.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/tools/perf/builtin-sched.c b/tools/perf/builtin-sched.c
index 6cf034f60c6667..2ccda1e382930a 100644
--- a/tools/perf/builtin-sched.c
+++ b/tools/perf/builtin-sched.c
@@ -3133,7 +3133,8 @@ static size_t timehist_print_idlehist_callchain(struct rb_root_cached *root)
 	size_t ret = 0;
 	FILE *fp = stdout;
 	struct callchain_node *chain;
-	struct rb_node *rb_node = rb_first_cached(root);
+	/* sort() uses rb_insert_color() on rb_root, not rb_root_cached */
+	struct rb_node *rb_node = rb_first(&root->rb_root);
 
 	printf("  %16s  %8s  %s\n", "Idle time (msec)", "Count", "Callchains");
 	printf("  %.16s  %.8s  %.50s\n", graph_dotted_line, graph_dotted_line,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0988/2077] perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (986 preceding siblings ...)
  2026-07-21 15:11 ` [PATCH 7.1 0987/2077] perf sched: Fix idle-hist callchain display using wrong rb_first variant Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0989/2077] perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name() Greg Kroah-Hartman
                   ` (9 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers, Jiri Olsa,
	Namhyung Kim, Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit b145137fec13dc8fc7fcb14193ce395a1164e3a1 ]

open() calls in dso.c and symbol-elf.c omit O_CLOEXEC, which leaks
file descriptors to child processes spawned during symbol resolution
(e.g., addr2line, objdump).  This can exhaust the fd limit during
long profiling sessions or when processing many DSOs.

Add O_CLOEXEC to all open() calls in both files (12 call sites).

Fixes: cdd059d731eeb466 ("perf tools: Move dso_* related functions into dso object")
Fixes: e5a1845fc0aeca85 ("perf symbols: Split out util/symbol-elf.c")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/dso.c        |  4 ++--
 tools/perf/util/symbol-elf.c | 20 ++++++++++----------
 2 files changed, 12 insertions(+), 12 deletions(-)

diff --git a/tools/perf/util/dso.c b/tools/perf/util/dso.c
index b791e1b6b2cf01..511e91843fbd8e 100644
--- a/tools/perf/util/dso.c
+++ b/tools/perf/util/dso.c
@@ -344,7 +344,7 @@ int filename__decompress(const char *name, char *pathname,
 	 * descriptor to the uncompressed file.
 	 */
 	if (!compressions[comp].is_compressed(name))
-		return open(name, O_RDONLY);
+		return open(name, O_RDONLY | O_CLOEXEC);
 
 	fd = mkstemp(tmpbuf);
 	if (fd < 0) {
@@ -1904,7 +1904,7 @@ static const u8 *__dso__read_symbol(struct dso *dso, const char *symfs_filename,
 	int saved_errno;
 
 	nsinfo__mountns_enter(dso__nsinfo(dso), &nsc);
-	fd = open(symfs_filename, O_RDONLY);
+	fd = open(symfs_filename, O_RDONLY | O_CLOEXEC);
 	saved_errno = errno;
 	nsinfo__mountns_exit(&nsc);
 	if (fd < 0) {
diff --git a/tools/perf/util/symbol-elf.c b/tools/perf/util/symbol-elf.c
index 7afa8a1171396b..0ba2c60ea5aaba 100644
--- a/tools/perf/util/symbol-elf.c
+++ b/tools/perf/util/symbol-elf.c
@@ -217,7 +217,7 @@ bool filename__has_section(const char *filename, const char *sec)
 	GElf_Shdr shdr;
 	bool found = false;
 
-	fd = open(filename, O_RDONLY);
+	fd = open(filename, O_RDONLY | O_CLOEXEC);
 	if (fd < 0)
 		return false;
 
@@ -871,7 +871,7 @@ static int read_build_id(const char *filename, struct build_id *bid)
 	if (size < BUILD_ID_SIZE)
 		goto out;
 
-	fd = open(filename, O_RDONLY);
+	fd = open(filename, O_RDONLY | O_CLOEXEC);
 	if (fd < 0)
 		goto out;
 
@@ -934,7 +934,7 @@ int sysfs__read_build_id(const char *filename, struct build_id *bid)
 	size_t size = sizeof(bid->data);
 	int fd, err = -1;
 
-	fd = open(filename, O_RDONLY);
+	fd = open(filename, O_RDONLY | O_CLOEXEC);
 	if (fd < 0)
 		goto out;
 
@@ -994,7 +994,7 @@ int filename__read_debuglink(const char *filename, char *debuglink,
 	if (err >= 0)
 		goto out;
 
-	fd = open(filename, O_RDONLY);
+	fd = open(filename, O_RDONLY | O_CLOEXEC);
 	if (fd < 0)
 		goto out;
 
@@ -1152,7 +1152,7 @@ int symsrc__init(struct symsrc *ss, struct dso *dso, const char *name,
 
 		type = dso__symtab_type(dso);
 	} else {
-		fd = open(name, O_RDONLY);
+		fd = open(name, O_RDONLY | O_CLOEXEC);
 		if (fd < 0) {
 			*dso__load_errno(dso) = errno;
 			return -1;
@@ -1945,7 +1945,7 @@ static int kcore__open(struct kcore *kcore, const char *filename)
 {
 	GElf_Ehdr *ehdr;
 
-	kcore->fd = open(filename, O_RDONLY);
+	kcore->fd = open(filename, O_RDONLY | O_CLOEXEC);
 	if (kcore->fd == -1)
 		return -1;
 
@@ -1978,7 +1978,7 @@ static int kcore__init(struct kcore *kcore, char *filename, int elfclass,
 	if (temp)
 		kcore->fd = mkstemp(filename);
 	else
-		kcore->fd = open(filename, O_WRONLY | O_CREAT | O_EXCL, 0400);
+		kcore->fd = open(filename, O_WRONLY | O_CREAT | O_EXCL | O_CLOEXEC, 0400);
 	if (kcore->fd == -1)
 		return -1;
 
@@ -2454,11 +2454,11 @@ static int kcore_copy__compare_files(const char *from_filename,
 {
 	int from, to, err = -1;
 
-	from = open(from_filename, O_RDONLY);
+	from = open(from_filename, O_RDONLY | O_CLOEXEC);
 	if (from < 0)
 		return -1;
 
-	to = open(to_filename, O_RDONLY);
+	to = open(to_filename, O_RDONLY | O_CLOEXEC);
 	if (to < 0)
 		goto out_close_from;
 
@@ -2876,7 +2876,7 @@ int get_sdt_note_list(struct list_head *head, const char *target)
 	Elf *elf;
 	int fd, ret;
 
-	fd = open(target, O_RDONLY);
+	fd = open(target, O_RDONLY | O_CLOEXEC);
 	if (fd < 0)
 		return -EBADF;
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0989/2077] perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (987 preceding siblings ...)
  2026-07-21 15:11 ` [PATCH 7.1 0988/2077] perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0990/2077] perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path Greg Kroah-Hartman
                   ` (8 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers, Song Liu,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit cab3a9331ed0b3f884dd61c8a25b3cf123705982 ]

Both functions accumulate formatted output via ret += snprintf(buf + ret,
size - ret, ...).  If the buffer is too small and snprintf() returns more
than the remaining space, ret exceeds size and the next 'size - ret'
underflows, causing snprintf() to write past the buffer end.

Switch to scnprintf() which returns the actual number of bytes written,
making the accumulation safe.

Fixes: 7b612e291a5affb1 ("perf tools: Synthesize PERF_RECORD_* for loaded BPF programs")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Song Liu <song@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/bpf-event.c | 11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

diff --git a/tools/perf/util/bpf-event.c b/tools/perf/util/bpf-event.c
index a27945c279efb7..2c09842469f1f2 100644
--- a/tools/perf/util/bpf-event.c
+++ b/tools/perf/util/bpf-event.c
@@ -36,7 +36,7 @@ static int snprintf_hex(char *buf, size_t size, unsigned char *data, size_t len)
 	size_t i;
 
 	for (i = 0; i < len; i++)
-		ret += snprintf(buf + ret, size - ret, "%02x", data[i]);
+		ret += scnprintf(buf + ret, size - ret, "%02x", data[i]);
 	return ret;
 }
 
@@ -140,7 +140,7 @@ static int synthesize_bpf_prog_name(char *buf, int size,
 	const struct btf_type *t;
 	int name_len;
 
-	name_len = snprintf(buf, size, "bpf_prog_");
+	name_len = scnprintf(buf, size, "bpf_prog_");
 	name_len += snprintf_hex(buf + name_len, size - name_len,
 				 prog_tags[sub_id], BPF_TAG_SIZE);
 	if (btf) {
@@ -153,9 +153,10 @@ static int synthesize_bpf_prog_name(char *buf, int size,
 			short_name = info->name;
 	} else
 		short_name = "F";
-	if (short_name)
-		name_len += snprintf(buf + name_len, size - name_len,
-				     "_%s", short_name);
+	if (short_name) {
+		name_len += scnprintf(buf + name_len, size - name_len,
+				      "_%s", short_name);
+	}
 	return name_len;
 }
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0990/2077] perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (988 preceding siblings ...)
  2026-07-21 15:11 ` [PATCH 7.1 0989/2077] perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name() Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0991/2077] perf tools: Use scnprintf() in build_id__snprintf() and hwmon read_events() Greg Kroah-Hartman
                   ` (7 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit 227a8748742f0263f1fe3131449b44563b77a209 ]

hists__scnprintf_title() accumulates formatted output into a buffer
using scnprintf() for all filter clauses except the UID filter, which
uses snprintf().  If the buffer fills up and snprintf() returns more
than the remaining space, printed exceeds size and the next 'size -
printed' underflows, causing later scnprintf() calls to write past
the buffer.

Switch the UID filter clause to scnprintf() to match the rest of the
function.

Fixes: 25c312dbf88ca402 ("perf hists: Move hists__scnprintf_title() away from the TUI code")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Arnaldo Carvalho de Melo <acme@redhat.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/hist.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/tools/perf/util/hist.c b/tools/perf/util/hist.c
index 747fdc455c80ec..2038c1d20acffa 100644
--- a/tools/perf/util/hist.c
+++ b/tools/perf/util/hist.c
@@ -2963,9 +2963,10 @@ int __hists__scnprintf_title(struct hists *hists, char *bf, size_t size, bool sh
 			   ev_name, sample_freq_str, enable_ref ? ref : " ", nr_events);
 
 
-	if (hists->uid_filter_str)
-		printed += snprintf(bf + printed, size - printed,
-				    ", UID: %s", hists->uid_filter_str);
+	if (hists->uid_filter_str) {
+		printed += scnprintf(bf + printed, size - printed,
+				     ", UID: %s", hists->uid_filter_str);
+	}
 	if (thread) {
 		if (hists__has(hists, thread)) {
 			printed += scnprintf(bf + printed, size - printed,
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0991/2077] perf tools: Use scnprintf() in build_id__snprintf() and hwmon read_events()
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (989 preceding siblings ...)
  2026-07-21 15:11 ` [PATCH 7.1 0990/2077] perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0992/2077] xprtrdma: Fix ep kref imbalance on ADDR_CHANGE Greg Kroah-Hartman
                   ` (6 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers,
	Arnaldo Carvalho de Melo, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arnaldo Carvalho de Melo <acme@redhat.com>

[ Upstream commit e33711d5e757011bb6d3506af4d6c97dad412b8f ]

build_id__snprintf() and hwmon_pmu__read_events() accumulate formatted
output via snprintf(), which returns the would-have-been-written count
on truncation.  In build_id__snprintf(), this inflates the return
value beyond the buffer size.  In hwmon_pmu__read_events(), len
overshoots out_buf_len and the next 'out_buf_len - len' underflows.

Switch both to scnprintf() which returns actual bytes written.

In build_id__snprintf(), also tighten the loop guard from
'offs < bf_size' to 'offs + 1 < bf_size': since scnprintf() returns
at most size-1, offs never reaches bf_size, and the original condition
would spin doing zero-byte writes once the buffer fills.

Fixes: fccaaf6fbbc59910 ("perf build-id: Change sprintf functions to snprintf")
Fixes: 53cc0b351ec99278 ("perf hwmon_pmu: Add a tool PMU exposing events from hwmon in sysfs")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 tools/perf/util/build-id.c  |  7 +++++--
 tools/perf/util/hwmon_pmu.c | 12 ++++++------
 2 files changed, 11 insertions(+), 8 deletions(-)

diff --git a/tools/perf/util/build-id.c b/tools/perf/util/build-id.c
index fdb35133fde43a..3c286cdbe6e0e6 100644
--- a/tools/perf/util/build-id.c
+++ b/tools/perf/util/build-id.c
@@ -93,8 +93,11 @@ int build_id__snprintf(const struct build_id *build_id, char *bf, size_t bf_size
 		return 0;
 	}
 
-	for (size_t i = 0; i < build_id->size && offs < bf_size; ++i)
-		offs += snprintf(bf + offs, bf_size - offs, "%02x", build_id->data[i]);
+	if (bf_size > 0)
+		bf[0] = '\0';
+
+	for (size_t i = 0; i < build_id->size && offs + 1 < bf_size; ++i)
+		offs += scnprintf(bf + offs, bf_size - offs, "%02x", build_id->data[i]);
 
 	return offs;
 }
diff --git a/tools/perf/util/hwmon_pmu.c b/tools/perf/util/hwmon_pmu.c
index fb3ffa8d32ad2a..dbf6a71af47f9a 100644
--- a/tools/perf/util/hwmon_pmu.c
+++ b/tools/perf/util/hwmon_pmu.c
@@ -442,12 +442,12 @@ static size_t hwmon_pmu__describe_items(struct hwmon_pmu *hwm, char *out_buf, si
 
 				buf[read_len] = '\0';
 				val = strtoll(buf, /*endptr=*/NULL, 10);
-				len += snprintf(out_buf + len, out_buf_len - len, "%s%s%s=%g%s",
-						len == 0 ? " " : ", ",
-						hwmon_item_strs[bit],
-						is_alarm ? "_alarm" : "",
-						(double)val / 1000.0,
-						hwmon_units[key.type]);
+				len += scnprintf(out_buf + len, out_buf_len - len, "%s%s%s=%g%s",
+						 len == 0 ? " " : ", ",
+						 hwmon_item_strs[bit],
+						 is_alarm ? "_alarm" : "",
+						 (double)val / 1000.0,
+						 hwmon_units[key.type]);
 			}
 			close(fd);
 		}
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0992/2077] xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (990 preceding siblings ...)
  2026-07-21 15:11 ` [PATCH 7.1 0991/2077] perf tools: Use scnprintf() in build_id__snprintf() and hwmon read_events() Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0993/2077] xprtrdma: Initialize re_id before removal registration Greg Kroah-Hartman
                   ` (5 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chris Mason, Chuck Lever,
	Anna Schumaker, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chris Mason <clm@meta.com>

[ Upstream commit af9b65b29af341932625c4283dc7a23cdb62688a ]

rpcrdma_cm_event_handler() falls through to the disconnected: label
on RDMA_CM_EVENT_ADDR_CHANGE and calls rpcrdma_ep_put() with no
matching get when the event arrives before RDMA_CM_EVENT_ESTABLISHED.
The kref then underflows during connect teardown and
rpcrdma_xprt_disconnect() operates on a freed ep.

Reference counts across a normal connection lifecycle:

    rpcrdma_ep_create()             kref_init     ->1
    rpcrdma_xprt_connect()          ep_get        ->2  (before post_recvs)
    RDMA_CM_EVENT_ESTABLISHED       ep_get        ->3
    RDMA_CM_EVENT_DISCONNECTED      ep_put        ->2
    rpcrdma_xprt_drain()            ep_put        ->1
    rpcrdma_xprt_disconnect() tail  ep_put        ->0  (ep_destroy)

The connect-time get in rpcrdma_xprt_connect(), taken just before
rpcrdma_post_recvs() "while there are outstanding Receives," is
balanced by rpcrdma_xprt_drain. ADDR_CHANGE before ESTABLISHED has
no get to consume, so its put drops the count to 1 and the drain
put then frees the ep while rpcrdma_xprt_disconnect() still holds a
pointer to it.

Fix by dispatching on the prior re_connect_status via xchg(): for
prev == 0 (pre-ESTABLISHED) wake the connect waiter and return with
no put; for prev == 1 call rpcrdma_force_disconnect() and return.
The case-1 arm relies on the subsequent RDMA_CM_EVENT_DISCONNECTED
event -- reliably delivered when rdma_disconnect() is called on a
still-connected cm_id -- to balance the ESTABLISHED get;
rpcrdma_xprt_drain() continues to balance only that connect-time
get. Any other prior value means teardown is already in flight.

Fixes: 2acc5cae2923 ("xprtrdma: Prevent dereferencing r_xprt->rx_ep after it is freed")
Assisted-by: kres:claude-opus-4-7
Signed-off-by: Chris Mason <clm@meta.com>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sunrpc/xprtrdma/verbs.c | 14 +++++++++++---
 1 file changed, 11 insertions(+), 3 deletions(-)

diff --git a/net/sunrpc/xprtrdma/verbs.c b/net/sunrpc/xprtrdma/verbs.c
index 97b8b2376602c8..5a36f35792e0d3 100644
--- a/net/sunrpc/xprtrdma/verbs.c
+++ b/net/sunrpc/xprtrdma/verbs.c
@@ -245,8 +245,17 @@ rpcrdma_cm_event_handler(struct rdma_cm_id *id, struct rdma_cm_event *event)
 		complete(&ep->re_done);
 		return 0;
 	case RDMA_CM_EVENT_ADDR_CHANGE:
-		ep->re_connect_status = -ENODEV;
-		goto disconnected;
+		switch (xchg(&ep->re_connect_status, -ENODEV)) {
+		case 0:
+			goto wake_connect_worker;
+		case 1:
+			/* The later DISCONNECTED event balances the
+			 * ESTABLISHED get; do not put here.
+			 */
+			rpcrdma_force_disconnect(ep);
+			return 0;
+		}
+		return 0;
 	case RDMA_CM_EVENT_ESTABLISHED:
 		rpcrdma_ep_get(ep);
 		ep->re_connect_status = 1;
@@ -269,7 +278,6 @@ rpcrdma_cm_event_handler(struct rdma_cm_id *id, struct rdma_cm_event *event)
 		return 0;
 	case RDMA_CM_EVENT_DISCONNECTED:
 		ep->re_connect_status = -ECONNABORTED;
-disconnected:
 		rpcrdma_force_disconnect(ep);
 		return rpcrdma_ep_put(ep);
 	default:
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0993/2077] xprtrdma: Initialize re_id before removal registration
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (991 preceding siblings ...)
  2026-07-21 15:11 ` [PATCH 7.1 0992/2077] xprtrdma: Fix ep kref imbalance on ADDR_CHANGE Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0994/2077] xprtrdma: Check frwr_wp_create() during connect Greg Kroah-Hartman
                   ` (4 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chris Mason, Chuck Lever,
	Anna Schumaker, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chris Mason <clm@meta.com>

[ Upstream commit bb7caa63e1db22fd03e8dc591b12169e99169dff ]

rpcrdma_create_id() registers ep->re_rn with the rpcrdma ib_client
before returning the new rdma_cm_id to rpcrdma_ep_create(). However
rpcrdma_ep_create() currently stores that pointer in ep->re_id only
after rpcrdma_create_id() returns.

A local administrator can race an NFS/RDMA mount against RDMA device
removal. If rpcrdma_remove_one() observes the just-registered
notification before rpcrdma_ep_create() assigns ep->re_id,
rpcrdma_ep_removal_done() calls trace_xprtrdma_device_removal(NULL).
The tracepoint dereferences id->device->name and copies
id->route.addr.dst_addr, so the callback can crash the kernel with a
NULL pointer dereference.

Store the rdma_cm_id in ep->re_id immediately before publishing
ep->re_rn. The existing error path still destroys the id directly if
registration fails; ep is then freed by the caller without using
ep->re_id. Remove the later duplicate assignment in rpcrdma_ep_create().

Fixes: 3f4eb9ff9234 ("xprtrdma: Handle device removal outside of the CM event handler")
Assisted-by: kres:openai-gpt-5
Signed-off-by: Chris Mason <clm@meta.com>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sunrpc/xprtrdma/verbs.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/sunrpc/xprtrdma/verbs.c b/net/sunrpc/xprtrdma/verbs.c
index 5a36f35792e0d3..9b2c186fd221b8 100644
--- a/net/sunrpc/xprtrdma/verbs.c
+++ b/net/sunrpc/xprtrdma/verbs.c
@@ -334,6 +334,7 @@ static struct rdma_cm_id *rpcrdma_create_id(struct rpcrdma_xprt *r_xprt,
 	if (rc)
 		goto out;
 
+	ep->re_id = id;
 	rc = rpcrdma_rn_register(id->device, &ep->re_rn, rpcrdma_ep_removal_done);
 	if (rc)
 		goto out;
@@ -406,7 +407,6 @@ static int rpcrdma_ep_create(struct rpcrdma_xprt *r_xprt)
 	}
 	__module_get(THIS_MODULE);
 	device = id->device;
-	ep->re_id = id;
 	reinit_completion(&ep->re_done);
 
 	ep->re_max_requests = r_xprt->rx_xprt.max_reqs;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0994/2077] xprtrdma: Check frwr_wp_create() during connect
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (992 preceding siblings ...)
  2026-07-21 15:11 ` [PATCH 7.1 0993/2077] xprtrdma: Initialize re_id before removal registration Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0995/2077] xprtrdma: Document and assert reply-handler invariants Greg Kroah-Hartman
                   ` (3 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chuck Lever, Anna Schumaker,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 0f13fc7c7d2e0427517e63c739277a4cd338b0c5 ]

frwr_wp_create() creates the singleton Memory Region used to encode
padding for Write chunks whose payload length is not XDR-aligned. Its
failure paths return a negative errno and leave ep->re_write_pad_mr set
to NULL.

rpcrdma_xprt_connect() currently ignores that return value. If
frwr_wp_create() fails after the rest of the connection setup succeeds,
xprt_rdma_connect_worker() treats the connection attempt as successful
and sets XPRT_CONNECTED. A later NFS/RDMA read with a non-4-byte-aligned
receive page length reaches rpcrdma_encode_write_list(), passes the NULL
write-pad MR to encode_rdma_segment(), and dereferences it.

This is locally triggerable on an NFS/RDMA client after a connect or
reconnect hits a local MR allocation, DMA-map, MR-map, or post-send
failure; a remote peer alone cannot force the local MR setup failure.

Check the return value and fail the connect as -ENOTCONN, matching the
adjacent setup failures. This keeps XPRT_CONNECTED clear and lets the
normal reconnect path retry.

Fixes: 21037b8c2258 ("xprtrdma: Provide a buffer to pad Write chunks of unaligned length")
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sunrpc/xprtrdma/verbs.c | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/net/sunrpc/xprtrdma/verbs.c b/net/sunrpc/xprtrdma/verbs.c
index 9b2c186fd221b8..d48d681bb49f44 100644
--- a/net/sunrpc/xprtrdma/verbs.c
+++ b/net/sunrpc/xprtrdma/verbs.c
@@ -549,7 +549,17 @@ int rpcrdma_xprt_connect(struct rpcrdma_xprt *r_xprt)
 		goto out;
 	}
 	rpcrdma_mrs_create(r_xprt);
-	frwr_wp_create(r_xprt);
+
+	/*
+	 * rpcrdma_encode_write_list() dereferences the write-pad
+	 * MR with no NULL check, so fail the connect rather than
+	 * publish a transport whose write-pad MR is NULL.
+	 */
+	rc = frwr_wp_create(r_xprt);
+	if (rc) {
+		rc = -ENOTCONN;
+		goto out;
+	}
 
 out:
 	trace_xprtrdma_connect(r_xprt, rc);
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0995/2077] xprtrdma: Document and assert reply-handler invariants
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (993 preceding siblings ...)
  2026-07-21 15:11 ` [PATCH 7.1 0994/2077] xprtrdma: Check frwr_wp_create() during connect Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0996/2077] xprtrdma: Resize reply buffers before reposting receives Greg Kroah-Hartman
                   ` (2 subsequent siblings)
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chuck Lever, Anna Schumaker,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 797943e8bd1ffcc63bfe79d24faad9a77054ec40 ]

The xprtrdma reply path has been the subject of recurring
LLM-driven review claims that 'an RPC can complete while
receive buffers are still DMA-mapped' or that 'the req can be
freed while the HCA still owns the send buffer.'  No runtime
reproducer has surfaced, but the absence of a written-down
invariant set lets each pass of automated review reach the
same hypothetical conclusion.  Subsequent fixes against
ce2f9a4d9ccc ('xprtrdma: Decouple req recycling from RPC
completion') closed the underlying races but did not document
the closure where future readers will look for it.

State the invariants explicitly in a comment above
rpcrdma_reply_handler() and back four of them with
WARN_ON_ONCE() probes positioned where each invariant is
locally checkable on the previous patch's cleaned-up
ownership state:

- I1 (Receive WR ownership): WARN at rpcrdma_post_recvs() that
  a rep pulled from rb_free_reps carries rr_rqst == NULL.

- I2 (rep attachment): WARN at rpcrdma_reply_put() that
  req->rl_reply was NULLed before the matching rep_put.

- I3 (Registered-MR fence): WARN at rpcrdma_complete_rqst()
  that req->rl_registered is empty.  Strong send-queue
  ordering of the LocalInv WR chain makes the last
  completion observe the ib_dma_unmap_sg() of every earlier
  MR, so 'list empty' implies 'all MRs unmapped'.

- I4 (Send-buffer release): WARN at rpcrdma_req_release()
  that req->rl_sendctx is NULL.  Reaching the kref release
  callback requires both the RPC-layer and Send-side
  references to have dropped; the Send-side drop runs in
  rpcrdma_sendctx_unmap(), which clears rl_sendctx
  (previous patch).  A non-NULL rl_sendctx here would mean
  the Send-side owner had not run -- a contradiction.

The XXX comment in xprt_rdma_free() about signal-driven
release racing the Send completion described the pre-decouple
state.  Replace it with a one-line note pointing at the
invariant set, since the kref scheme now holds the req across
the in-flight Send regardless of which path released the
rpc_task.

I5 (req lifecycle) is stated in the comment but not probed:
making it locally assertible would require moving kref_init
out of rpcrdma_req_release(), which in turn requires adding
kref_init to the bc_pa_list and backlog-wake reuse paths.
That restructuring is deferred -- the invariant is unchanged
either way.

Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Stable-dep-of: 234c0ff695ef ("xprtrdma: Resize reply buffers before reposting receives")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sunrpc/xprtrdma/rpc_rdma.c  | 69 +++++++++++++++++++++++++++++++++
 net/sunrpc/xprtrdma/transport.c | 13 +++++--
 net/sunrpc/xprtrdma/verbs.c     |  6 +++
 3 files changed, 84 insertions(+), 4 deletions(-)

diff --git a/net/sunrpc/xprtrdma/rpc_rdma.c b/net/sunrpc/xprtrdma/rpc_rdma.c
index 69380f9dfa499d..8121069472af22 100644
--- a/net/sunrpc/xprtrdma/rpc_rdma.c
+++ b/net/sunrpc/xprtrdma/rpc_rdma.c
@@ -1332,6 +1332,11 @@ void rpcrdma_complete_rqst(struct rpcrdma_rep *rep)
 	struct rpc_rqst *rqst = rep->rr_rqst;
 	int status;
 
+	/* I3: every registered MR has been invalidated and
+	 * ib_dma_unmap_sg()'d before complete_rqst runs.
+	 */
+	WARN_ON_ONCE(!list_empty(&rpcr_to_rdmar(rqst)->rl_registered));
+
 	switch (rep->rr_proc) {
 	case rdma_msg:
 		status = rpcrdma_decode_msg(r_xprt, rep, rqst);
@@ -1363,6 +1368,70 @@ void rpcrdma_complete_rqst(struct rpcrdma_rep *rep)
 	goto out;
 }
 
+/* Reply-side ownership invariants
+ *
+ * I1 (Receive WR ownership).  A struct rpcrdma_rep is owned by the
+ *    HCA between ib_post_recv() and the matching Receive completion.
+ *    After ib_dma_sync_single_for_cpu() in rpcrdma_wc_receive() it is
+ *    owned by the CPU until rpcrdma_rep_put() returns it to
+ *    rb_free_reps; a rep on rb_free_reps is not re-posted until
+ *    rpcrdma_post_recvs() pulls it off.  Asserted: rpcrdma_post_recvs()
+ *    WARNs that a pulled rep has rr_rqst == NULL.
+ *
+ * I2 (rep attachment).  While req->rl_reply == rep, the rep cannot be
+ *    re-posted.  rpcrdma_reply_put() NULLs req->rl_reply before handing
+ *    the rep to rpcrdma_rep_put().  Asserted: rpcrdma_reply_put() WARNs
+ *    that rl_reply is NULL after the put.
+ *
+ * I3 (Registered-MR fence).  On entry to rpcrdma_complete_rqst() every
+ *    MR that was on req->rl_registered has had its rkey invalidated
+ *    (remotely via IB_WC_WITH_INVALIDATE or locally via IB_WR_LOCAL_INV)
+ *    and its pages ib_dma_unmap_sg()'d.  The LocalInv chain is posted
+ *    on a single QP; strong send-queue ordering makes the last
+ *    completion (frwr_wc_localinv_done) observe the
+ *    ib_dma_unmap_sg() that ran from each earlier completion's
+ *    frwr_mr_put() before complete_rqst is called.  The inline
+ *    frwr_reminv() path unmaps its one MR synchronously before
+ *    rpcrdma_reply_handler() reaches complete_rqst.  Asserted:
+ *    rpcrdma_complete_rqst() WARNs that rl_registered is empty.
+ *
+ * I4 (Send-buffer release).  req->rl_kref carries two unconditional
+ *    owners while a Send is outstanding: the RPC-layer reference (set
+ *    at xprt_rdma_alloc_slot / xprt_rdma_bc_rqst_get / rpcrdma_req_release
+ *    pool-entry) and the Send-side reference (kref_get() in
+ *    rpcrdma_prepare_send_sges()).  rpcrdma_req_release() runs only
+ *    after both have dropped, so the req does not return to its free
+ *    pool until rpcrdma_sendctx_unmap() has fired -- the HCA has
+ *    released the send buffer before the req can be reused.  Asserted:
+ *    rpcrdma_req_release() WARNs that rl_sendctx is NULL.
+ *
+ * I5 (req lifecycle).  A req is owned by the RPC layer between slot
+ *    acquisition and the matching xprt_rdma_free_slot() (or, for the
+ *    backchannel, xprt_rdma_bc_free_rqst()).  While owned, rl_kref >= 1.
+ *    The pools (rb_send_bufs, bc_pa_list, backlog wake target) never
+ *    contain a req with outstanding Send-side or Reply-side work.
+ *
+ * Non-hazards.  The following claims have been raised by adversarial
+ * review and are each closed by the invariants above:
+ *
+ *   * "Reply completes the RPC while the HCA still holds the send
+ *     buffer" -- excluded by I4.  The Send-side kref reference is held
+ *     until rpcrdma_sendctx_unmap() runs from Send completion.
+ *
+ *   * "Signal-driven release races the in-flight Send" -- same
+ *     resolution.  xprt_rdma_free() does not touch rl_kref; the
+ *     Send-side reference keeps the req out of its pool until Send
+ *     completion fires.
+ *
+ *   * "Receive completion races rep reuse" -- excluded by I1.  A rep
+ *     is on rb_free_reps only after rpcrdma_rep_put() has been called
+ *     and rpcrdma_post_recvs() owns the next transition back to the HCA.
+ *
+ *   * "Pages still DMA-mapped when call_decode reads them" -- excluded
+ *     by I3.  The matching ib_dma_unmap_sg() for every MR has run on
+ *     the same CPU thread that calls rpcrdma_complete_rqst().
+ */
+
 /**
  * rpcrdma_reply_handler - Process received RPC/RDMA messages
  * @rep: Incoming rpcrdma_rep object to process
diff --git a/net/sunrpc/xprtrdma/transport.c b/net/sunrpc/xprtrdma/transport.c
index 5569f17fdd9b59..5ff8e5126a6c2b 100644
--- a/net/sunrpc/xprtrdma/transport.c
+++ b/net/sunrpc/xprtrdma/transport.c
@@ -509,6 +509,11 @@ static void rpcrdma_req_release(struct kref *kref)
 	struct rpc_xprt *xprt = rqst->rq_xprt;
 	struct rpcrdma_xprt *r_xprt;
 
+	/* I4: both the RPC-layer and Send-side owners have dropped,
+	 * so rpcrdma_sendctx_unmap() has cleared rl_sendctx.
+	 */
+	WARN_ON_ONCE(req->rl_sendctx);
+
 	kref_init(&req->rl_kref);
 
 #if defined(CONFIG_SUNRPC_BACKCHANNEL)
@@ -652,10 +657,10 @@ xprt_rdma_free(struct rpc_task *task)
 		frwr_unmap_sync(rpcx_to_rdmax(rqst->rq_xprt), req);
 	}
 
-	/* XXX: If the RPC is completing because of a signal and
-	 * not because a reply was received, we ought to ensure
-	 * that the Send completion has fired, so that memory
-	 * involved with the Send is not still visible to the NIC.
+	/* The Send-side rl_kref owner keeps req out of its free pool
+	 * until rpcrdma_sendctx_unmap() has fired -- see I4 above
+	 * rpcrdma_reply_handler() -- so signal-driven release here
+	 * does not let the HCA touch a recycled send buffer.
 	 */
 }
 
diff --git a/net/sunrpc/xprtrdma/verbs.c b/net/sunrpc/xprtrdma/verbs.c
index d48d681bb49f44..ee6c4b18105ba1 100644
--- a/net/sunrpc/xprtrdma/verbs.c
+++ b/net/sunrpc/xprtrdma/verbs.c
@@ -1250,6 +1250,10 @@ void rpcrdma_reply_put(struct rpcrdma_buffer *buffers, struct rpcrdma_req *req)
 		rpcrdma_rep_put(buffers, req->rl_reply);
 		req->rl_reply = NULL;
 	}
+	/* I2: rl_reply NULL after the put closes the
+	 * 'rep on rb_free_reps still referenced by req' window.
+	 */
+	WARN_ON_ONCE(req->rl_reply);
 }
 
 /**
@@ -1426,6 +1430,8 @@ void rpcrdma_post_recvs(struct rpcrdma_xprt *r_xprt, int needed)
 			rep = rpcrdma_rep_create(r_xprt);
 		if (!rep)
 			break;
+		/* I1: a rep on rb_free_reps must carry no rqst pointer. */
+		WARN_ON_ONCE(rep->rr_rqst);
 		if (!rpcrdma_regbuf_dma_map(r_xprt, rep->rr_rdmabuf)) {
 			rpcrdma_rep_put(buf, rep);
 			break;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0996/2077] xprtrdma: Resize reply buffers before reposting receives
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (994 preceding siblings ...)
  2026-07-21 15:11 ` [PATCH 7.1 0995/2077] xprtrdma: Document and assert reply-handler invariants Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0997/2077] xprtrdma: Fix bcall rep leak and unbounded peek Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0998/2077] xprtrdma: Sanitize the reply credit grant after parsing Greg Kroah-Hartman
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chuck Lever, Anna Schumaker,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 234c0ff695ef3ffb656931000e6b823d0c2f30fd ]

Commit 0e13dd9ea8be ("xprtrdma: Remove temp allocation of
rpcrdma_rep objects") made rpcrdma_rep objects survive disconnects.
That is normally fine, but it also means their receive regbufs keep
the size they had when they were first allocated.

Each rep's receive buffer is sized to ep->re_inline_recv when the rep
is created. rpcrdma_ep_create() resets that threshold to the
rdma_max_inline_read ceiling for every new endpoint, and the connect
handshake then shrinks it to the peer's advertised inline send size.
A rep allocated under a smaller negotiated threshold keeps that size:
on disconnect, rpcrdma_xprt_disconnect() drains and DMA-unmaps the
surviving reps but does not free or resize them.

The threshold can come back larger on the next connection. The first
peer may supply no RPC-over-RDMA CM private data, defaulting its send
size to 1024, while the reconnect target is an ordinary server
offering 4096; or, with rdma_max_inline_read raised above its default,
the reconnect target may advertise a larger svcrdma_max_req_size than
the first. rpcrdma_post_recvs() then reposts a surviving rep whose SGE
length is still the old, smaller value, and a larger inline Reply hits
a receive length error and forces another disconnect.

The undersized rep returns to the free list when its failed Receive
flushes, so the following reconnect reposts the same rep and fails the
same way. The transport flaps without making forward progress for as
long as the peer keeps advertising the larger inline size.

This is local/admin-triggerable rather than remote-triggerable: a local
administrator must create and maintain the NFS/RDMA mount, while the
server or reconnect target has to advertise a larger inline send size
and return a reply that uses it.

Fix this by checking each rep before it is reposted. If the receive
regbuf is smaller than the current endpoint's inline receive size,
reallocate it on the current RDMA device's NUMA node and reinitialize
the rep's xdr_buf before DMA-mapping and posting the Receive WR.

Fixes: 0e13dd9ea8be ("xprtrdma: Remove temp allocation of rpcrdma_rep objects")
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sunrpc/xprtrdma/verbs.c | 31 ++++++++++++++++++++++++++++++-
 1 file changed, 30 insertions(+), 1 deletion(-)

diff --git a/net/sunrpc/xprtrdma/verbs.c b/net/sunrpc/xprtrdma/verbs.c
index ee6c4b18105ba1..6a8370c8f43d9c 100644
--- a/net/sunrpc/xprtrdma/verbs.c
+++ b/net/sunrpc/xprtrdma/verbs.c
@@ -81,6 +81,8 @@ rpcrdma_regbuf_alloc_node(size_t size, enum dma_data_direction direction,
 			  int node);
 static struct rpcrdma_regbuf *
 rpcrdma_regbuf_alloc(size_t size, enum dma_data_direction direction);
+static bool rpcrdma_regbuf_realloc_node(struct rpcrdma_regbuf *rb,
+					size_t size, gfp_t flags, int node);
 static void rpcrdma_regbuf_dma_unmap(struct rpcrdma_regbuf *rb);
 static void rpcrdma_regbuf_free(struct rpcrdma_regbuf *rb);
 
@@ -1334,10 +1336,16 @@ rpcrdma_regbuf_alloc(size_t size, enum dma_data_direction direction)
  * returned, @rb is left untouched.
  */
 bool rpcrdma_regbuf_realloc(struct rpcrdma_regbuf *rb, size_t size, gfp_t flags)
+{
+	return rpcrdma_regbuf_realloc_node(rb, size, flags, NUMA_NO_NODE);
+}
+
+static bool rpcrdma_regbuf_realloc_node(struct rpcrdma_regbuf *rb,
+					size_t size, gfp_t flags, int node)
 {
 	void *buf;
 
-	buf = kmalloc(size, flags);
+	buf = kmalloc_node(size, flags, node);
 	if (!buf)
 		return false;
 
@@ -1349,6 +1357,23 @@ bool rpcrdma_regbuf_realloc(struct rpcrdma_regbuf *rb, size_t size, gfp_t flags)
 	return true;
 }
 
+static bool rpcrdma_rep_resize(struct rpcrdma_xprt *r_xprt,
+			       struct rpcrdma_rep *rep)
+{
+	struct rpcrdma_regbuf *rb = rep->rr_rdmabuf;
+	struct rpcrdma_ep *ep = r_xprt->rx_ep;
+	size_t size = ep->re_inline_recv;
+
+	if (likely(rdmab_length(rb) >= size))
+		return true;
+	if (!rpcrdma_regbuf_realloc_node(rb, size, XPRTRDMA_GFP_FLAGS,
+					 ibdev_to_node(ep->re_id->device)))
+		return false;
+
+	xdr_buf_init(&rep->rr_hdrbuf, rdmab_data(rb), rdmab_length(rb));
+	return true;
+}
+
 /**
  * __rpcrdma_regbuf_dma_map - DMA-map a regbuf
  * @r_xprt: controlling transport instance
@@ -1432,6 +1457,10 @@ void rpcrdma_post_recvs(struct rpcrdma_xprt *r_xprt, int needed)
 			break;
 		/* I1: a rep on rb_free_reps must carry no rqst pointer. */
 		WARN_ON_ONCE(rep->rr_rqst);
+		if (!rpcrdma_rep_resize(r_xprt, rep)) {
+			rpcrdma_rep_put(buf, rep);
+			break;
+		}
 		if (!rpcrdma_regbuf_dma_map(r_xprt, rep->rr_rdmabuf)) {
 			rpcrdma_rep_put(buf, rep);
 			break;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0997/2077] xprtrdma: Fix bcall rep leak and unbounded peek
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (995 preceding siblings ...)
  2026-07-21 15:11 ` [PATCH 7.1 0996/2077] xprtrdma: Resize reply buffers before reposting receives Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  2026-07-21 15:11 ` [PATCH 7.1 0998/2077] xprtrdma: Sanitize the reply credit grant after parsing Greg Kroah-Hartman
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chris Mason, Chuck Lever,
	Anna Schumaker, Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chris Mason <clm@meta.com>

[ Upstream commit c7653d5cebc8492c77ec0415b5e9c0fb3e644bc6 ]

rpcrdma_is_bcall() decodes a reply's first words to decide whether
the frame is a backchannel call. Two issues in that decode path
let a short or malformed reply leak the receive buffer and drain
the Receive queue.

First, the speculative peek

    p = xdr_inline_decode(xdr, 0);
    /* five p++ reads follow */

asks xdr_inline_decode() for zero bytes, which returns xdr->p
without consulting xdr->end. The five subsequent __be32 reads can
then walk up to 20 bytes past the wire payload into stale regbuf
contents and misclassify the reply as a backchannel call.

Second, after the post-peek

    p = xdr_inline_decode(xdr, 3 * sizeof(*p));
    if (unlikely(!p))
            return true;

the short-header arm returns true without calling
rpcrdma_bc_receive_call(). The contract with the caller is that a
true return transfers ownership of rep to the backchannel path:

    rpcrdma_reply_handler()
      if (rpcrdma_is_bcall(r_xprt, rep))
              return;        /* bare return, skips out_post */
      ...
    out_post:
      rpcrdma_post_recvs(r_xprt, credits + ...);

Because rpcrdma_bc_receive_call() never ran, no one took rep, but
rpcrdma_reply_handler still bare-returns past rpcrdma_rep_put()
and rpcrdma_post_recvs(). The rep, with its persistently
DMA-mapped receive buffer, is orphaned on rb_all_reps and freed
only at transport teardown. This completion reposts nothing, so
its slot is reclaimed only when a later forward-channel reply
reaches out_post and rpcrdma_post_recvs() allocates a fresh rep to
backfill; absent that traffic the Receive queue drains and the
peer's Sends draw RNR NAKs.

Fix by consulting xdr->end after the zero-length peek so the five
__be32 reads cannot run unless 20 bytes of wire payload remain. A
byte-precise comparison against xdr->end is required because a
non-4-aligned receive rounds the stream's word count up past the
true payload. Also return false from the short-header arm so the
reply falls through the normal out_norqst cleanup chain
(rpcrdma_rep_put() plus rpcrdma_post_recvs()).

Fixes: 41c8f70f5a3d ("xprtrdma: Harden backchannel call decoding")
Assisted-by: kres:claude-opus-4-7
Signed-off-by: Chris Mason <clm@meta.com>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sunrpc/xprtrdma/rpc_rdma.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/net/sunrpc/xprtrdma/rpc_rdma.c b/net/sunrpc/xprtrdma/rpc_rdma.c
index 8121069472af22..912d5de60abe81 100644
--- a/net/sunrpc/xprtrdma/rpc_rdma.c
+++ b/net/sunrpc/xprtrdma/rpc_rdma.c
@@ -1084,6 +1084,8 @@ rpcrdma_is_bcall(struct rpcrdma_xprt *r_xprt, struct rpcrdma_rep *rep)
 
 	/* Peek at stream contents without advancing. */
 	p = xdr_inline_decode(xdr, 0);
+	if ((char *)xdr->end - (char *)p < 5 * XDR_UNIT)
+		return false;
 
 	/* Chunk lists */
 	if (xdr_item_is_present(p++))
@@ -1108,7 +1110,7 @@ rpcrdma_is_bcall(struct rpcrdma_xprt *r_xprt, struct rpcrdma_rep *rep)
 	 */
 	p = xdr_inline_decode(xdr, 3 * sizeof(*p));
 	if (unlikely(!p))
-		return true;
+		return false;
 
 	rpcrdma_bc_receive_call(r_xprt, rep);
 	return true;
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

* [PATCH 7.1 0998/2077] xprtrdma: Sanitize the reply credit grant after parsing
  2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
                   ` (996 preceding siblings ...)
  2026-07-21 15:11 ` [PATCH 7.1 0997/2077] xprtrdma: Fix bcall rep leak and unbounded peek Greg Kroah-Hartman
@ 2026-07-21 15:11 ` Greg Kroah-Hartman
  997 siblings, 0 replies; 2097+ messages in thread
From: Greg Kroah-Hartman @ 2026-07-21 15:11 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chuck Lever, Anna Schumaker,
	Sasha Levin

7.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit c3a628aab2dc8f5fd7bff86ceaeae64de590e60a ]

The out_norqst exit in rpcrdma_reply_handler() branches away before
the credit clamp, so a reply that matches no pending request reaches
out_post carrying the raw credit value parsed from the wire.
rpcrdma_post_recvs() does not bound its @needed argument: the refill
loop allocates and chains Receive WRs until the count is satisfied or
allocation fails. A peer that sends a well-formed reply carrying an
unknown XID and an inflated credit grant therefore drives rep
allocation and Receive posting past re_max_requests on every such
reply.

Move the clamp to immediately after the credit field is parsed,
ahead of the first branch that can reach out_post, so every later
consumer sees a sanitized value. The cwnd update stays on the
matched-request path.

Fixes: 704f3f640f72 ("xprtrdma: Post receive buffers after RPC completion")
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/sunrpc/xprtrdma/rpc_rdma.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/net/sunrpc/xprtrdma/rpc_rdma.c b/net/sunrpc/xprtrdma/rpc_rdma.c
index 912d5de60abe81..9255d44960cca5 100644
--- a/net/sunrpc/xprtrdma/rpc_rdma.c
+++ b/net/sunrpc/xprtrdma/rpc_rdma.c
@@ -1468,6 +1468,14 @@ void rpcrdma_reply_handler(struct rpcrdma_rep *rep)
 	credits = be32_to_cpu(*p++);
 	rep->rr_proc = *p++;
 
+	/* The credit grant from the wire is not trustworthy;
+	 * sanitize it before any code path consumes it.
+	 */
+	if (credits == 0)
+		credits = 1;	/* don't deadlock */
+	else if (credits > r_xprt->rx_ep->re_max_requests)
+		credits = r_xprt->rx_ep->re_max_requests;
+
 	if (rep->rr_vers != rpcrdma_version)
 		goto out_badversion;
 
@@ -1484,10 +1492,6 @@ void rpcrdma_reply_handler(struct rpcrdma_rep *rep)
 	xprt_pin_rqst(rqst);
 	spin_unlock(&xprt->queue_lock);
 
-	if (credits == 0)
-		credits = 1;	/* don't deadlock */
-	else if (credits > r_xprt->rx_ep->re_max_requests)
-		credits = r_xprt->rx_ep->re_max_requests;
 	if (buf->rb_credits != credits)
 		rpcrdma_update_cwnd(r_xprt, credits);
 
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 2097+ messages in thread

end of thread, other threads:[~2026-07-21 19:02 UTC | newest]

Thread overview: 2097+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-21 14:54 [PATCH 7.1 0000/2077] 7.1.5-rc1 review Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0001/2077] crypto: algif_skcipher - force synchronous processing Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0002/2077] iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0003/2077] crypto: sun4i-ss - Remove insecure and unused rng_alg Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0004/2077] media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0005/2077] ALSA: hda/realtek: Add quirk for TongFang X6xx45xU Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0006/2077] ALSA: hda: conexant: Remove mic bias threshold override Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0007/2077] ALSA: hda: Fix cached processing coefficient verbs Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0008/2077] ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID 17aa:38a7 Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0009/2077] media: uvcvideo: Use hw timestaming if the clock buffer is full Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0010/2077] media: uvcvideo: Avoid partial metadata buffers Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0011/2077] media: uvcvideo: Fix buffer sequence in frame gaps Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0012/2077] media: uvcvideo: Fix dev_sof filtering in hw timestamp Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0013/2077] media: uvcvideo: Do not add clock samples with small sof delta Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0014/2077] media: uvcvideo: Relax the constrains for interpolating the hw clock Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0015/2077] media: uvcvideo: Fix sequence number when no EOF Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0016/2077] dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0017/2077] dt-bindings: power: imx93: Add MIPI PHY power domain Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0018/2077] serial: msm: Disable DMA for kernel console UART Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0019/2077] serial: max310x: implement gpio_chip::get_direction() Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0020/2077] serial: 8250_omap: clear rx_running on zero-length DMA completes Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0021/2077] rxrpc: serialize kernel accept preallocation with socket teardown Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0022/2077] rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0023/2077] rxrpc: Dont move a peeked OOB message onto the pending queue Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0024/2077] rxrpc: Fix UAF in rxgk_issue_challenge() Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0025/2077] rxrpc: Fix socket notification race Greg Kroah-Hartman
2026-07-21 14:54 ` [PATCH 7.1 0026/2077] rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0027/2077] rxrpc: Fix potential infinite loop in rxrpc_recvmsg() Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0028/2077] rxrpc: Fix rxrpc_rotate_tx_rotate() to check theres something to rotate Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0029/2077] rxrpc: Fix oob challenge leak in cleanup after notification failure Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0030/2077] rxrpc: Fix ACKALL packet handling Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0031/2077] rxrpc: Fix the reception of a reply packet before data transmission Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0032/2077] rxrpc: Fix leak of connection from OOB challenge Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0033/2077] rxrpc: Fix double unlock in rxrpc_recvmsg() Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0034/2077] afs: Fix netns teardown to cancel the preallocation charger Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0035/2077] afs: fix NULL pointer dereference in afs_get_tree() Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0036/2077] afs: handle CB.InitCallBackState3 requests without a server record Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0037/2077] afs: Fix further netns teardown to cancel the preallocation charger Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0038/2077] afs: Fix uncancelled rxrpc OOB message handler Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0039/2077] fbcon: fix NULL pointer dereference for a console without vc_data Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0040/2077] fbcon: Use correct type for vc_resize() return value Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0041/2077] soc: fsl: qe_ports_ic: Add missing cleanup on device removal Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0042/2077] openrisc: mm: Fix section mismatch between map_page and __set_fixmap Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0043/2077] clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0044/2077] accel/amdxdna: Fix leak when pinning ubuf pages Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0045/2077] drm/rockchip: inno-hdmi: Switch to drmm_kzalloc() Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0046/2077] drm/rockchip: dw_dp: " Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0047/2077] drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove() Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0048/2077] drm/rockchip: Test for imported buffers with drm_gem_is_imported() Greg Kroah-Hartman
2026-07-21 14:55   ` Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0049/2077] drm/tidss: Drop extra drm_mode_config_reset() call Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0050/2077] drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0051/2077] accel/amdxdna: Create shared functions for AIE2 and AIE4 Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0052/2077] accel/amdxdna: Adjust size for copy_to_user() Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0053/2077] accel/amdxdna: Handle DETACH_DEBUG_BO through config_debug_bo path Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0054/2077] accel/amdxdna: Fix iommu_map_sgtable() return value handling Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0055/2077] accel/amdxdna: Fix order of canceled mailbox messages Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0056/2077] dma-fence: Fix potential tracepoint null pointer dereferences Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0057/2077] accel/amdxdna: Fix fatal_error_info layout in firmware interface Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0058/2077] accel/amdxdna: Fix memory leak in amdxdna_iommu_alloc() Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0059/2077] drm/gpuvm: Do not prepare NULL objects Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0060/2077] accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0061/2077] drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0062/2077] drm/amdkfd: fix redundant MQD iterations in GFX v12.1 Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0063/2077] drm/radeon: fix integer overflow in radeon_align_pitch() Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0064/2077] drm/radeon: fix memory leak in radeon_ring_restore() on lock failure Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0065/2077] libbpf: Report error when a negative kprobe offset is specified Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0066/2077] selftests/bpf: Fix off-by-one in bpf_cpumask_populate related selftest Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0067/2077] dt-bindings: timer: Remove sifive,fine-ctr-bits property Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0068/2077] wifi: ath12k: Fix invalid IRQ requests during AHB probe Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0069/2077] libbpf: Fix deduplication of typedef with base definitions Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0070/2077] drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0071/2077] spi: atcspi200: fix use-after-free when driver unbind Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0072/2077] selftests/bpf: Use local type for flow_offload_tuple_rhash in xdp_flowtable Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0073/2077] selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0074/2077] Documentation: proc: fix section numbering in table of contents Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0075/2077] arm64: dts: rockchip: Fix vdec register blocks order on RK3576 Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0076/2077] arm64: dts: rockchip: Update vdec register blocks order on RK3588 Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0077/2077] arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Cobra Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0078/2077] arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0079/2077] ima: Fix sigv3 signature handling for EVM_IMA_XATTR_DIGSIG Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0080/2077] dt-bindings: net: bluetooth: qualcomm: Fix WCN6855 regulator names Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0081/2077] x86/bug: Add printf() validation to HAVE_ARCH_BUG_FORMAT_ARGS WARNs Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0082/2077] arm64: dts: qcom: milos: Reduce rmtfs_mem size to 2.5MiB Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0083/2077] arm64: dts: qcom: sdm845-oneplus: Drop address from framebuffer node Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0084/2077] arm64: dts: qcom: glymur: Fix USB simple_bus_reg warning Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0085/2077] arm64: dts: qcom: glymur: Fix cache and SRAM simple_bus_reg warnings Greg Kroah-Hartman
2026-07-21 14:55 ` [PATCH 7.1 0086/2077] arm64: dts: qcom: ipq5424: Fix USB " Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0087/2077] arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0088/2077] arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0089/2077] arm64: dts: qcom: fix temp-alarm probe failure for PMH0104 on Glymur Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0090/2077] arm64: dts: qcom: sdm845-shift-axolotl: Correct touchscreen sleep state Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0091/2077] hfsplus: Remove the duplicate attr inode dirty marking action Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0092/2077] hfsplus: Add a sanity check for btree node size Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0093/2077] wifi: cfg80211: fix grammar in MLO group key error message Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0094/2077] arm64: tegra: Fix Tegra234 MGBE PTP clock Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0095/2077] dt-bindings: pinctrl: nvidia,tegra234: Add missing required block Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0096/2077] pinctrl: pinconf-generic: fix properties bitmap leak in parse_fw_cfg() Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0097/2077] drm/amdkfd: Validate CRIU-restored IDs before idr_alloc Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0098/2077] driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0099/2077] gpu: nova-core: use correct fwsignature for GA100 Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0100/2077] wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0101/2077] wifi: rtw88: " Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0102/2077] wifi: rtw89: Correct data type for scan index to avoid infinite loop Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0103/2077] wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0104/2077] wifi: rtw89: add bounds check on firmware mac_id in link lookup Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0105/2077] kconfig: fix potential NULL pointer dereference in conf_askvalue Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0106/2077] soc: xilinx: Fix race condition in event registration Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0107/2077] soc: xilinx: Shutdown and free rx mailbox channel Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0108/2077] pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask() Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0109/2077] wifi: ath9k: fix OOB access from firmware tx status queue ID Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0110/2077] wifi: ath11k: cancel SSR work items during PCI shutdown Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0111/2077] ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0112/2077] ixgbe: fix unaligned u32 access in ixgbe_update_flash_X550() Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0113/2077] Documentation/rv: Replace stale website link Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0114/2077] watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0115/2077] watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0116/2077] watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0117/2077] media: cedrus: Fix failure to clean up hardware on probe failure Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0118/2077] media: v4l2-common: Add YUV24 format info Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0119/2077] drm: verisilicon: call atomic helpers plane state check even if no CRTC Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0120/2077] memory: tegra: Wire up system sleep PM ops Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0121/2077] objtool/klp: Fix is_uncorrelated_static_local() for Clang Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0122/2077] objtool/klp: Fix .data..once static local non-correlation Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0123/2077] objtool/klp: Fix create_fake_symbols() skipping entsize-based sections Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0124/2077] objtool/klp: Fix handling of zero-length .altinstr_replacement sections Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0125/2077] objtool/klp: Fix cloning of zero-length section symbols Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0126/2077] objtool/klp: Fix extraction of text annotations for alternatives Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0127/2077] objtool/klp: Fix relocation conversion failures for R_X86_64_NONE Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0128/2077] objtool: Replace iterator callback with for_each_sym_by_mangled_name() Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0129/2077] objtool: Fix reloc hash collision in find_reloc_by_dest_range() Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0130/2077] klp-build: Fix hang on out-of-date .config Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0131/2077] klp-build: Fix checksum comparison for changed offsets Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0132/2077] klp-build: Fix patch cleanup on interrupt Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0133/2077] crypto: qat - fix heartbeat error injection Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0134/2077] lib/vsprintf: Fix to check field_width and precision Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0135/2077] dts: spacemit: set console baud rate on bpif3 Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0136/2077] pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0137/2077] riscv: dts: microchip: gpio controllers on mpfs need 2 interrupt cells Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0138/2077] riscv: dts: microchip: remove gpio hogs from beaglev-fire Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0139/2077] dt-bindings: vendor-prefixes: Add Displaytech Ltd Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0140/2077] drm/gpuvm: take refcount on DRM device Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0141/2077] wifi: cfg80211: restrict LMR feedback check to TB and non-TB ranging Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0142/2077] drm/panel: Clean up SOFEF00 config dependencies Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0143/2077] drm/panel: Clean up S6E3FC2X01 " Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0144/2077] drm/panel: Clean up S6E3HA2 config dependencies and fill help text Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0145/2077] riscv: dts: microchip: update pic64gx gpio interrupts to better match the SoC Greg Kroah-Hartman
2026-07-21 14:56 ` [PATCH 7.1 0146/2077] riscv: dts: microchip: fix pic64gx gpio interrupt-cells Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0147/2077] arm64: dts: marvell: samsung-coreprimevelte: Increase touchscreen voltage Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0148/2077] ARM: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0149/2077] arm64: " Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0150/2077] arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0151/2077] arm64: dts: imx8x-colibri: Correct SODIMM PAD settings Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0152/2077] arm64: dts: imx8mn-vhip4-evalboard-v1: Correct interrupt flags Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0153/2077] arm64: dts: imx8mn-vhip4-evalboard-v2: " Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0154/2077] arm64: dts: imx8mp-ab2: " Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0155/2077] Revert "arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL signal" Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0156/2077] Revert "arm64: dts: imx8mp-kontron: " Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0157/2077] vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0158/2077] drm: renesas: rz-du: mipi_dsi: Fix return path on error Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0159/2077] alarmtimer: Remove stale return description from alarm_handle_timer() Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0160/2077] OPP: Fix race between OPP addition and lookup Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0161/2077] crypto: ccp - Reverse the cleanup order in psp_dev_destroy() Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0162/2077] crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0163/2077] crypto: ccp - Check for page allocation failure correctly in TIO Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0164/2077] crypto: ccp - Initialize data during __sev_snp_init_locked() Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0165/2077] crypto: atmel-sha204a - fix blocking and non-blocking rng logic Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0166/2077] crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0167/2077] crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0168/2077] ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0169/2077] accel/amdxdna: Fix clflush buffer size Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0170/2077] dlm: fix add msg handle in send_queue ordered Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0171/2077] nilfs2: fix backing_dev_info reference leak Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0172/2077] ntb: Store original DMA address for future release Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0173/2077] ntb: Use consistent DMA attributes when freeing DMA mappings Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0174/2077] media: qcom: camss: vfe: fix PIX subdev naming on VFE lite Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0175/2077] dts: riscv: spacemit: correct 32k clock frequency Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0176/2077] arm64: dts: qcom: sdm660: set cdsp compute-cbs regs properly Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0177/2077] arm64: dts: qcom: sdm630: set adsp " Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0178/2077] arm64: dts: qcom: lemans: Move PCIe devices into soc node Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0179/2077] media: iris: scale MMCX power domain on SM8250 Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0180/2077] media: venus: " Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0181/2077] iommu/amd: Fix a stale comment about which legacy mode is user visible Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0182/2077] soc: mediatek: mtk-mmsys: Restore MT8167 routing masks lost during merge Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0183/2077] bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0184/2077] uaccess: fix ignored_trailing logic in copy_struct_to_user() Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0185/2077] sockptr: fix usize check in copy_struct_from_sockptr() for user pointers Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0186/2077] arm64: dts: mediatek: mt7988a-bpi-r4pro: rework pcie gpio-hog handling Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0187/2077] arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0188/2077] workqueue: forbid TEST_WORKQUEUE from being built-in Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0189/2077] drm/amdgpu: fix error return code in mes_v12_1_map_test_bo Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0190/2077] arm64: dts: qcom: glymur-crd: Drop forced host mode for USB SS0 and SS1 Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0191/2077] arm64: dts: qcom: glymur: Mark USB SS1 and SS2 as role-switch capable Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0192/2077] rhashtable: give each instance its own lockdep class Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0193/2077] rust: alloc: fix `Vec::extend_with` SAFETY comment Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0194/2077] clk: scmi: Fix clock rate rounding Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0195/2077] arm64: dts: qcom: sm8750: Fix DSI1 phy reference clock rate Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0196/2077] arm64: dts: qcom: kodiak: Fix ICE reg size Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0197/2077] arm64: dts: qcom: sm8450: " Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0198/2077] platform/chrome: chromeos_privacy_screen: Check ACPI_COMPANION() Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0199/2077] platform/chrome: chromeos_tbmc: " Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0200/2077] platform/chrome: wilco_ec: event: " Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0201/2077] drm/hisilicon/hibmc: add updating link cap in DP detect() Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0202/2077] drm/hisilicon/hibmc: fix no showing when no connectors connected Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0203/2077] drm/hisilicon/hibmc: move display contrl config to hibmc_probe() Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0204/2077] drm/hisilicon/hibmc: use clock to look up the PLL value Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0205/2077] evm: terminate and bound the evm_xattrs read buffer Greg Kroah-Hartman
2026-07-21 14:57 ` [PATCH 7.1 0206/2077] thermal: hwmon: Fix critical temperature attribute removal Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0207/2077] thermal: hwmon: Register a hwmon device for each thermal zone Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0208/2077] clk: scpi: Unregister child clock providers on remove Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0209/2077] net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0210/2077] scsi: hisi_sas: Add slave_destroy interface for v3 hw Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0211/2077] crypto: ccp - Treat zero-length cert chain as query for blob lengths Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0212/2077] crypto: af_alg - Cap AEAD AD length to 0x80000000 Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0213/2077] crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0214/2077] crypto: safexcel - Fix potential memory leak in safexcel_pci_probe() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0215/2077] spi: hisi-kunpeng: Use dev_err_probe() for host registration failure Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0216/2077] net/sched: add qdisc_qlen_inc() and qdisc_qlen_dec() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0217/2077] net/sched: sch_dualpi2: annotate data-races in dualpi2_dump_stats() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0218/2077] net/sched: sch_htb: do not change sch->flags in htb_dump() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0219/2077] net/sched: sch_htb: annotate data-races (I) Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0220/2077] ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0221/2077] IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0222/2077] RDMA/hns: Fix arithmetic overflow in calc_hem_config() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0223/2077] RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0224/2077] RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0225/2077] RDMA/srpt: fix integer overflow in immediate data length check Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0226/2077] RDMA/hns: Initialize seqfile before creating file Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0227/2077] tools/rtla: Fix --dump-tasks usage in timerlat Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0228/2077] rtla: Stop the record trace on interrupt Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0229/2077] drm/syncobj: Fix memory leak in drm_syncobj_find_fence() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0230/2077] dm: limit target bio polling to one shot Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0231/2077] selftests/bpf: Override EXTRA_LDFLAGS for static builds Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0232/2077] selftests/bpf: Reject unsupported -k option in vmtest.sh Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0233/2077] selftests/bpf: Fix test for refinement of single-value tnum Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0234/2077] iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match table Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0235/2077] sched/fair: Update util_est after updating util_avg during dequeue Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0236/2077] selftests/mm: Fix resv_sz when parsing arm64 signal frame Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0237/2077] firmware: arm_ffa: Honor partition info descriptor size Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0238/2077] arm64: dts: freescale: imx95-verdin-ivy: fix RS485 RTS polarity Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0239/2077] arm64: dts: imx8dxl-evk: Remove unnecessary PCIe EP properties Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0240/2077] arm64: dts: imx8qxp-mek: Remove unnecessary PCIe EP vpcie-supply Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0241/2077] arm64: dts: imx95-19x19-evk: Fix " Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0242/2077] hfs: fix incorrect inode ID assignment in hfs_new_inode() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0243/2077] media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0244/2077] media: atomisp: gc2235: fix UAF and memory leak Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0245/2077] staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0246/2077] riscv: dts: spacemit: set console baud rate on Milk-V Jupiter Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0247/2077] riscv: dts: spacemit: fix uboot partition offset " Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0248/2077] firmware: smccc: Fix Arm SMCCC SOC_ID name call Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0249/2077] firmware: arm_scmi: Read sensor config as 32-bit value Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0250/2077] media: synopsys: Fix IPI using hardcoded datatype Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0251/2077] sysfs: clamp show() return value in sysfs_kf_read() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0252/2077] bitops: use common function parameter names Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0253/2077] regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0254/2077] tools/nolibc: getopt: Fix potential out of bounds access Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0255/2077] vfio: selftests: Fix out-of-tree build with make O= Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0256/2077] vfio: selftests: Allow builds when ARCH=x86 Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0257/2077] nilfs2: Fix return in nilfs_mkdir Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0258/2077] vfio/xe: avoid duplicate reset in xe_vfio_pci_reset_done Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0259/2077] net/sched: sch_drr: annotate data-races around cl->deficit Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0260/2077] regmap-i2c: fix sparse warning in regmap_smbus_word_write_reg16 Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0261/2077] media: rockchip: rga: fix too small buffer size Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0262/2077] firmware: arm_scmi: Fix OOB in scmi_power_name_get() Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0263/2077] arm64: dts: qcom: eliza-mtp: Fix the debug UART index Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0264/2077] arm64: dts: qcom: kaanapali: Add power-domain and iface clk for ice node Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0265/2077] arm64: dts: qcom: lemans: " Greg Kroah-Hartman
2026-07-21 14:58 ` [PATCH 7.1 0266/2077] arm64: dts: qcom: monaco: " Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0267/2077] arm64: dts: qcom: sc7180: " Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0268/2077] arm64: dts: qcom: kodiak: " Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0269/2077] arm64: dts: qcom: sm8450: " Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0270/2077] arm64: dts: qcom: sm8550: " Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0271/2077] arm64: dts: qcom: sm8650: " Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0272/2077] arm64: dts: qcom: sm8750: " Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0273/2077] tracing: Bound synthetic-field strings with seq_buf Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0274/2077] arm64: dts: qcom: lemans: Add eDP ref clock for eDP PHYs Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0275/2077] arm64: dts: qcom: glymur: Fix wrong interrupt number for i2c19 Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0276/2077] arm64: dts: qcom: sdm845-xiaomi-beryllium: Correct IPA FW path Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0277/2077] writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount() Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0278/2077] kernfs: fix suspicious RCU usage in kernfs_put() Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0279/2077] device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0280/2077] driver core: Use mod_delayed_work to prevent lost deferred probe work Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0281/2077] Revert "treewide: Fix probing of devices in DT overlays" Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0282/2077] of: dynamic: Fix overlayed devices not probing because of fw_devlink Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0283/2077] crypto: eip93 - fix reset ring register definition Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0284/2077] ASoC: mediatek: mt8189: Fix probe resource cleanup Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0285/2077] drm/msm/mdss: correct UBWC programming sequences Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0286/2077] cpufreq: Documentation: fix sampling_down_factor range Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0287/2077] cpufreq: conservative: Simplify frequency limit handling Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0288/2077] pwm: imx27: Fix variable truncation in .apply() Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0289/2077] RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0290/2077] tools/nolibc: stackprotector: Avoid stalling program startup if crng is not init yet Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0291/2077] bus: sunxi-rsb: Always check register address validity Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0292/2077] pinctrl: spacemit: fix NULL check in spacemit_pin_set_config Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0293/2077] ASoC: dapm: Fix widget lookup with prefixed names across DAPM contexts Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0294/2077] RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0295/2077] RDMA/rxe: Fix a use-after-free problem in rxe_mmap Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0296/2077] IB/mlx4: Fix refcount leak in add_port() error path Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0297/2077] gpu: nova-core: vbios: stop scanning at BIOS_MAX_SCAN_LEN Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0298/2077] gpu: nova-core: vbios: use checked arithmetic for bios image range end Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0299/2077] gpu: nova-core: vbios: avoid reading too far in read_more_at_offset Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0300/2077] gpu: nova-core: vbios: read BitToken using FromBytes Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0301/2077] gpu: nova-core: vbios: use checked ops and accesses in `FwSecBiosImage::ucode` Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0302/2077] gpu: nova-core: vbios: use checked access in `FwSecBiosImage::header` Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0303/2077] gpu: nova-core: vbios: use checked accesses in `setup_falcon_data` Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0304/2077] RDMA/hns: Fix warning in poll cq direct mode Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0305/2077] RDMA/hns: Fix log flood after cmd_mbox failure Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0306/2077] ACPI: PAD: Fix teardown ordering in acpi_pad_remove() Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0307/2077] RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0308/2077] pinctrl: meson: amlogic-a4: fix gpio output glitch Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0309/2077] PM: sleep: Use complete() in device_pm_sleep_init() Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0310/2077] MIPS: Fix big-endian stack argument fetching in o32 wrapper Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0311/2077] MIPS: DEC: Remove do_IRQ() call indirection Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0312/2077] mips: ralink: mt7621: add missing __iomem Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0313/2077] mips: n64: add __iomem for writel call Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0314/2077] driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0315/2077] driver core: Guard deferred probe timeout extension with delayed_work_pending() Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0316/2077] arm64: tegra: Fix address of Tegra264 main GPIO controller Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0317/2077] mtd: spi-nor: debugfs: Fix the flags list Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0318/2077] mtd: spi-nor: Drop duplicate Kconfig dependency Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0319/2077] wifi: ath12k: fix error unwind on arch_init() failure in PCI probe Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0320/2077] cpufreq: governor: Fix data races on per-CPU idle/nice baselines Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0321/2077] cpufreq: governor: Fix stale prev_cpu_nice spike when enabling ignore_nice_load Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0322/2077] ALSA: xen-front: Reset event channel state on stream clear Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0323/2077] ALSA: xen-front: Connect event channel after stream prepare Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0324/2077] ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0325/2077] ALSA: seq: midi: Serialize output teardown with event_input Greg Kroah-Hartman
2026-07-21 14:59 ` [PATCH 7.1 0326/2077] selftests: Fix Makefile target for nsfs Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0327/2077] pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0328/2077] pinctrl: cs42l43: Fix leaked pm reference on error path Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0329/2077] pinctrl: cs42l43: Fix polarity on debounce Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0330/2077] init/initramfs_test: wait_for_initramfs() before running Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0331/2077] nvmet-tcp: fix page fragment cache leak in error path Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0332/2077] nvmet-tcp: check return value of nvmet_tcp_set_queue_sock Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0333/2077] nvme-multipath: fix flex array size in struct nvme_ns_head Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0334/2077] nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0335/2077] workqueue: drop spurious * from print_worker_info() fn declaration Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0336/2077] ipv6: guard against possible NULL deref in __in6_dev_stats_get() Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0337/2077] net/sched: cls_bpf: prevent unbounded recursion in offload rollback Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0338/2077] iommu/amd: Fix premature break in init_iommu_one() Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0339/2077] ALSA: hda/realtek:ALC269 fixup for Yoga Pro 7 15ASH11 mic mute LED Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0340/2077] dt-bindings: vendor-prefixes: Add Verbatim Corporation Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0341/2077] rtla/actions: Restore continue flag in actions_perform() Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0342/2077] drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0343/2077] drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0344/2077] gpu: host1x: Allow entries in BO caches to be freed Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0345/2077] drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0346/2077] gpu: host1x: mipi: Fix device_node reference leak in tegra_mipi_request() Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0347/2077] drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0348/2077] gpu: host1x: Fix iommu_map_sgtable() return value check Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0349/2077] drm/tegra: " Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0350/2077] drm/nouveau/bios: specify correct display fuse register for Ampere and Ada Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0351/2077] libbpf: Harden parse_vma_segs() path parsing Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0352/2077] bpftool: Fix typo in struct_ops map FD generation for light skeleton Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0353/2077] libbpf: Fix UAF in strset__add_str() Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0354/2077] ARM: tegra: Add #{address,size}-cells to Chromium-based /firmware Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0355/2077] arm64: " Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0356/2077] rust: devres: add static bound to Devres<T> Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0357/2077] dax/kmem: account for partial discontiguous resource upon removal Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0358/2077] lib/base64: validate before writing in decode tail path Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0359/2077] rust: uaccess: use INLINE_COPY_TO_USER to guard copy_to_user() Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0360/2077] uaccess: unify inline vs outline copy_{from,to}_user() selection Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0361/2077] uaccess: minimize INLINE_COPY_USER-related ifdefery Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0362/2077] rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0363/2077] ocfs2: dont BUG_ON an invalid journal dinode Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0364/2077] ocfs2: kill osb->system_file_mutex lock Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0365/2077] crypto: hisilicon/qm - disable error report before flr Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0366/2077] crypto: inside-secure/eip93 - Add check for devm_request_threaded_irq Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0367/2077] crypto: tegra - Fix dma_free_coherent size error Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0368/2077] crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0369/2077] crypto: ccp/tsm - Enable the root port after the endpoint Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0370/2077] sched/deadline: Reject debugfs dl_server writes for offline CPUs Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0371/2077] drm/msm/dp: fix HPD state status bit shift value Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0372/2077] drm/msm/dp: Fix the ISR_* enum values Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0373/2077] firmware: samsung: acpm: Add devm_acpm_get_by_phandle helper Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0374/2077] firmware: samsung: acpm: remove compile-testing stubs Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0375/2077] drm/msm/a8xx: Make a8xx_recover IFPC safe Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0376/2077] drm/msm/a8xx: Fix RSCC offset Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0377/2077] EDAC/igen6: Fix call trace due to missing release() Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0378/2077] EDAC/igen6: Fix memory topology parsing for Panther Lake-H SoCs Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0379/2077] EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0380/2077] arm64: dts: st: Fix SAI addresses on stm32mp251 Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0381/2077] arm: dts: bcm2711: Fix typo in gpio-line-names Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0382/2077] RDMA/umem: Add ib_umem_is_contiguous() stub for !CONFIG_INFINIBAND_USER_MEM Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0383/2077] RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0384/2077] RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0385/2077] dts: riscv: spacemit: k3: Fix I/O power settings Greg Kroah-Hartman
2026-07-21 15:00 ` [PATCH 7.1 0386/2077] Revert "media: venus: hfi_platform: Correct supported codecs for sc7280" Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0387/2077] media: qcom: venus: drop extra padding in NV12 raw size calculation Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0388/2077] media: qcom: venus: relax encoder frame/blur dimension steps on v4 Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0389/2077] media: qcom: venus: relax encoder frame/blur step size on v6 Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0390/2077] amba: use generic driver_override infrastructure Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0391/2077] cdx: " Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0392/2077] Drivers: hv: vmbus: " Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0393/2077] rpmsg: " Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0394/2077] arm64: dts: renesas: r8a78000: Fix GIC-720AE View 1 Redistributor description Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0395/2077] arm64: dts: renesas: ironhide: Describe all reserved memory Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0396/2077] md/raid10: reset read_slot when reusing r10bio for discard Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0397/2077] md/raid1,raid10: fix deadlock in read error recovery path Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0398/2077] md/raid1,raid10: fix error-path detection with md_cloned_bio() Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0399/2077] md/raid1,raid10: fix bio accounting for split md cloned bios Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0400/2077] raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0401/2077] bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0402/2077] selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0403/2077] liveupdate: Use refcount_t for FLB reference counts Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0404/2077] liveupdate: Reference count incoming FLB data Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0405/2077] libbpf: Skip hash computation when loader generation failed Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0406/2077] libbpf: Skip endianness swap " Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0407/2077] liveupdate: skip serialization for context-preserving kexec Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0408/2077] liveupdate: fix TOCTOU race in luo_session_retrieve() Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0409/2077] liveupdate: block session mutations during reboot Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0410/2077] liveupdate: fix u-a-f in luo_file_unpreserve_files() and luo_file_finish() Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0411/2077] ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0412/2077] spi: atmel: fix DMA channel and bounce buffer leaks Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0413/2077] spi: imx: replace dmaengine_terminate_all() with dmaengine_terminate_sync() Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0414/2077] ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0415/2077] NFSD: Fix delegation reference leak in nfsd4_revoke_states Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0416/2077] ARM: imx3: Fix CCM node reference leak Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0417/2077] HID: wiimote: Fix table layout and whitespace errors Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0418/2077] wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0419/2077] wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic() Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0420/2077] wifi: ath12k: fix inconsistent arvif state in vdev_create error paths Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0421/2077] wifi: ath12k: fix NULL deref in change_sta_links for unready link Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0422/2077] ata: libata: Fix ata_exec_internal() Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0423/2077] ACPI: button: Fix lid_device value leak past driver removal Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0424/2077] ARM: imx31: Fix IIM mapping leak in revision check Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0425/2077] x86/cpu: Keep the PROCESSOR_SELECT menu together Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0426/2077] nvdimm/btt: Handle preemption in BTT lane acquisition Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0427/2077] tcp_bbr: fix SPDX-License-Identifier to be GPL-2.0 OR BSD-3-Clause Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0428/2077] scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans" Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0429/2077] bpf: Reject exclusive maps as inner maps in map-in-map Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0430/2077] libbpf: Reject non-exclusive metadata maps in the signed loader Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0431/2077] libbpf: Skip initial_value override on signed loaders Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0432/2077] libbpf: Skip max_entries " Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0433/2077] scsi: pm8001: Fix error code in non_fatal_log_show() Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0434/2077] scsi: ufs: Fix wrong value printed in unexpected UPIU response case Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0435/2077] bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0436/2077] mm/fake-numa: fix under-allocation detection in uniform split Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0437/2077] ext2: fix ignored return value of generic_write_sync() Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0438/2077] sched: restore timer_slack_ns when resetting RT policy on fork Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0439/2077] nvme: fix FDP fdpcidx bounds check Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0440/2077] driver core: Use system_percpu_wq instead of system_wq Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0441/2077] bpf: Reject exclusive maps for bpf_map_elem iterators Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0442/2077] tick/sched: Fix TOCTOU in nohz idle time fetch Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0443/2077] lib/test_meminit: use && for bools Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0444/2077] riscv: dts: sophgo: sg2044: use hex for CPU unit address Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0445/2077] riscv: dts: sophgo: sg2042: " Greg Kroah-Hartman
2026-07-21 15:01 ` [PATCH 7.1 0446/2077] configfs_lookup(): dont leave ->s_dentry dangling on failure Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0447/2077] lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0448/2077] lockdep/selftests: Restore sched_rt_mutex " Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0449/2077] ext4: fix fast commit wait/wake bit mapping on 64-bit Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0450/2077] irqchip/exynos-combiner: Remove useless spinlock Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0451/2077] drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0452/2077] drm/amd/pm: Add empty string validation to sysfs store functions Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0453/2077] drm/amdgpu: set sub_block_index for mca ras sub-blocks Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0454/2077] accel/amdxdna: Return errors for failed debug BO commands Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0455/2077] bpftool: Use libbpf error code for flow dissector query Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0456/2077] vhost: fix vhost_get_avail_idx for a non empty ring Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0457/2077] iommu/vt-d: Fix RB-tree corruption in probe error path Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0458/2077] mm: preserve PG_dropbehind flag during folio split Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0459/2077] eventpoll: rename attach_epitem() to ep_attach_file() Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0460/2077] eventpoll: split ep_insert() into alloc + register stages Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0461/2077] eventpoll: extract ep_deliver_event() from ep_send_events() Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0462/2077] eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0463/2077] perf/x86/amd/core: Always use the NMI latency mitigation Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0464/2077] perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0465/2077] perf/x86/intel/uncore: Fix PCI device refcount leak in UPI discovery Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0466/2077] perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0467/2077] xfrm: fix NAT-related field inheritance in SA migration Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0468/2077] wifi: wlcore: enable the right set of ciphers Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0469/2077] cxl/fwctl: Fix __fortify_panic Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0470/2077] cxl/test: " Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0471/2077] bpf: Take mmap_lock in zap_pages() Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0472/2077] drm/amdkfd: always resume_all after suspend_all Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0473/2077] of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0474/2077] ocfs2: rebase copied fsdlm LVB pointers in locking_state Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0475/2077] lib: kunit_iov_iter: repeatedly call alloc_pages_bulk() Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0476/2077] ocfs2: fix buffer head management in ocfs2_read_blocks() Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0477/2077] ocfs2: validate fast symlink target during inode read Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0478/2077] ocfs2: reject FITRIM ranges shorter than a cluster Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0479/2077] ocfs2/dlm: require a ref for locking_state debugfs open Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0480/2077] ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0481/2077] ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0482/2077] cxl/pci: Fix the incorrect check of pci_read_config_word() return Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0483/2077] cxl/pci: Convert PCIBIOS errors to errno on DVSEC config accesses Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0484/2077] netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0485/2077] netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0486/2077] netfilter: synproxy: drop packets if timestamp adjustment fails Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0487/2077] netfilter: synproxy: adjust duplicate timestamp options Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0488/2077] netfilter: synproxy: fix unaligned memory access in timestamp adjustment Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0489/2077] netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0490/2077] netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0491/2077] ALSA: usb-audio: qcom: Initialize offload control return value Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0492/2077] mm/slub: preserve original size in _kmalloc_nolock_noprof retry path Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0493/2077] x86/cpu: Remove obsolete aperfmperf_get_khz() declaration Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0494/2077] netfilter: conntrack: revert ct extension genid infrastructure Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0495/2077] netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0496/2077] ntfs: free link name from ntfs_name_cache Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0497/2077] RDMA/hfi1: Open-code rvt_set_ibdev_name() Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0498/2077] IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0499/2077] ALSA: hda: fix Kconfig dependency of HD Audio PCI Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0500/2077] RDMA/irdma: Fix OOB read during CQ MR registration Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0501/2077] RDMA/irdma: Initialize iwmr->access during " Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0502/2077] arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0503/2077] arm64: dts: imx94: fix DDR PMU interrupt number Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0504/2077] arm64: dts: imx95: Correct PCIe outbound address space configuration Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0505/2077] arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi Greg Kroah-Hartman
2026-07-21 15:02 ` [PATCH 7.1 0506/2077] arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0507/2077] arm64: dts: imx8mp-kontron: Fix GPIO for display power switch Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0508/2077] arm64: dts: freescale: fsl-ls1028a-tqmls1028a-mbls1028a: switch mmc aliases Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0509/2077] RDMA/siw: Fix endpoint/socket association handling Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0510/2077] selftests/bpf: Fix flaky file_reader test Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0511/2077] bpf: Clear rb node linkage when freeing bpf_rb_root Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0512/2077] bpf: Check tail zero of bpf_map_info Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0513/2077] bpf: Check tail zero of bpf_prog_info Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0514/2077] bpf: Update transport_header when encapsulating UDP tunnel in lwt Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0515/2077] kernfs: fix xattr race condition with multiple superblocks Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0516/2077] tmpfs: simplify constructing "security.foo" xattr names Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0517/2077] simple_xattr: change interface to pass struct simple_xattrs ** Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0518/2077] simpe_xattr: use per-sb cache Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0519/2077] kernfs: link kn to its parent before the LSM init hook Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0520/2077] wifi: wcn36xx: fix heap overflow from oversized firmware HAL response Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0521/2077] wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0522/2077] wifi: wcn36xx: fix OOB read from short trigger BA firmware response Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0523/2077] ALSA: seq: Fix partial userptr event expansion Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0524/2077] ALSA: pcm: Fix unlocked runtime state reads in xfer ioctls Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0525/2077] riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0526/2077] riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0527/2077] ALSA: seq: Clear variable event pointer on read Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0528/2077] riscv: alternative: Use IS_ENABLED() over ifdeffery for apply_vdso_alternatives() Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0529/2077] riscv: alternative: Pass vDSO start as parameter to apply_vdso_alternatives() Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0530/2077] riscv: alternative: Also patch the CFI vDSO Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0531/2077] bpf: Verifier support for sleepable tracepoint programs Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0532/2077] bpf: Reject sleepable BPF_LSM_CGROUP programs at load time Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0533/2077] netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0534/2077] filelock: fix break_lease() stub signature for CONFIG_FILE_LOCKING=n Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0535/2077] bpf: Fix NMI/tracepoint re-entry deadlock on lru locks Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0536/2077] kunit:tool: Dont write to stdout when it should be disabled Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0537/2077] wifi: mac80211: bound S1G TIM PVB walk to the TIM element Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0538/2077] powerpc/8xx: implement get_direction() in cpm1 Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0539/2077] bpf: Fix NULL pointer dereference in bpf_task_from_vpid() Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0540/2077] ACPI: IPMI: Fix message kref handling on dead device Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0541/2077] ACPI: processor: Add cpuidle driver check in acpi_processor_register_idle_driver() Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0542/2077] cpufreq: Documentation: fix conservative governor freq_step description Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0543/2077] thermal: testing: reject missing command arguments Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0544/2077] btrfs: dont force DIO writes to be serialized Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0545/2077] ntfs: validate resident attribute lists and harden the validator Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0546/2077] ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0547/2077] ntfs: bound the attribute-list entry in ntfs_read_inode_mount() Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0548/2077] ntfs: fix u16 truncation of restart-area length check Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0549/2077] IB/mlx5: Dont take the rereg_mr fallback without a new translation Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0550/2077] IB/mlx5: Properly support implicit ODP rereg_mr Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0551/2077] RDMA/nldev: Fix locking when accessing mr->pd Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0552/2077] IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift() Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0553/2077] IB/mlx5: Pull the pdn out of the depths of the umr machinery Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0554/2077] IB/mlx5: Dont mangle the mr->pd inside the rereg callback Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0555/2077] spi: ep93xx: fix double-free of zeropage on DMA setup failure Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0556/2077] ASoC: amd: acp-sdw-legacy: Bound DAI link iteration Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0557/2077] ASoC: amd: acp-sdw-sof: " Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0558/2077] firmware_loader: Fix recursive lock in device_cache_fw_images() Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0559/2077] configfs: fix lockless traversals of ->s_children Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0560/2077] watchdog: unregister PM notifier on watchdog unregister Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0561/2077] pinctrl: qcom: Fix resolving register base address from device node Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0562/2077] scsi: target: Fix hexadecimal CHAP_I handling Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0563/2077] scsi: ufs: core: Handle PM commands timeout before SCSI EH Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0564/2077] scsi: target: Remove tcm_loop target reset handling Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0565/2077] pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 Greg Kroah-Hartman
2026-07-21 15:03 ` [PATCH 7.1 0566/2077] pinctrl: mediatek: mt8167: " Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0567/2077] dt-bindings: pinctrl: realtek,rtd1625: Fix input voltage property name Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0568/2077] pinctrl: PINCTRL_STMFX should depend on CONFIG_OF Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0569/2077] iommufd: Take dma_resv lock before dma_buf_unpin() in release path Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0570/2077] iommufd: Destroy the pages content after detaching from dmabuf Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0571/2077] lib/test_hmm: fix memory leak in dmirror_migrate_to_system() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0572/2077] vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0573/2077] rust: kbuild: show the right `quiet_cmd_rustc_procmacrolibrary` Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0574/2077] remoteproc: qcom_q6v5_wcss: drop redundant wcss_q6_bcr_reset Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0575/2077] hwspinlock: qcom: avoid uninitialized struct members Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0576/2077] sched/fair: Fix cpu_util runnable_avg arithmetic Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0577/2077] ARM: configs: Drop duplicated CONFIG_EXT4_FS Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0578/2077] wifi: mt76: mt7925: clean up DMA on probe failure Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0579/2077] wifi: mt76: mt7921: fix resource leak in probe error path Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0580/2077] wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0581/2077] wifi: mt76: mt7996: add missing max_remain_on_channel_duration Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0582/2077] wifi: mt76: mt7996: Fix NULL pointer dereference in mt7996_init_tx_queues() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0583/2077] wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0584/2077] wifi: mt76: mt7925: keep TX BA state in the primary WCID Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0585/2077] wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0586/2077] wifi: mt76: mt7925: validate skb length in testmode query Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0587/2077] wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0588/2077] wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0589/2077] wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0590/2077] wifi: mt76: mt7996: remove redundant pdev->bus check in probe Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0591/2077] wifi: mt76: mt7996: limit work in set_bitrate_mask Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0592/2077] wifi: mt76: fix argument to ieee80211_is_first_frag() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0593/2077] wifi: mt76: mt7915: fix potential tx_retries underflow Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0594/2077] wifi: mt76: mt7921: " Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0595/2077] wifi: mt76: mt7925: " Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0596/2077] wifi: mt76: mt7996: " Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0597/2077] btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0598/2077] ALSA: aloop: Drop superfluous break Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0599/2077] gpio: mt7621: fix interrupt banks mapping on gpio chips Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0600/2077] wifi: ath12k: fix EAPOL TX failure caused by stale tcl_metadata bits Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0601/2077] wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is reported Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0602/2077] fbdev/arm: Export acorndata_8x8 font symbol for bootloader Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0603/2077] fbdev: sm501fb: Fix buffer errors in OF binding code Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0604/2077] memory: tegra186-emc: stop borrowing MC aggregate hook for EMC Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0605/2077] vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0606/2077] hwmon: (it87) Clamp negative values to zero in set_fan() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0607/2077] PM: QoS: Fix misc device registration unwind Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0608/2077] btrfs: zoned: dont account data relocation space-info in statfs free space Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0609/2077] btrfs: zoned: fix deadlock waiting for ticket during data relocation Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0610/2077] Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()" Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0611/2077] btrfs: zoned: always set max_active_zones for zoned devices Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0612/2077] btrfs: annotate lockless read of defrag_bytes in should_nocow() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0613/2077] btrfs: fix deadlock cloning inline extent when using flushoncommit Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0614/2077] btrfs: lzo: reject compressed segment that overflows the compressed input Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0615/2077] ixgbe: do not configure xps for XDP queues Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0616/2077] igc: skip RX timestamp header for frame preemption verification Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0617/2077] ASoC: sma1307: Fix uevent string leaks in fault worker Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0618/2077] IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0619/2077] NFSD: Handle layout stid in nfsd4_drop_revoked_stid() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0620/2077] lockd: Stop warning on nlm__int__drop_reply in !V4 cast_status Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0621/2077] lockd: Translate nlm__int__deadlock in __nlm4svc_proc_lock_msg() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0622/2077] lockd: Do not monitor when looking up the LOCK_MSG callback host Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0623/2077] lockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file() Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0624/2077] spi: meson-spifc: fix runtime PM leak on remove Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0625/2077] ASoC: codecs: aw88261: fix incorrect masks for boost regs Greg Kroah-Hartman
2026-07-21 15:04 ` [PATCH 7.1 0626/2077] bpf: Cancel special fields on map value recycle Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0627/2077] clocksource: move NXP timer selection to drivers/clocksource Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0628/2077] vduse: hold vduse_lock across IDR lookup in open path Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0629/2077] vhost/vdpa: validate virtqueue index in mmap and fault paths Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0630/2077] virtio: rtc: tear down old virtqueues before restore Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0631/2077] virtio_console: read size from config space during device init Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0632/2077] vduse: Requeue failed read to send_list head Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0633/2077] vhost/net: complete zerocopy ubufs only once Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0634/2077] tools/virtio: check mmap return value in vringh_test Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0635/2077] vduse: fix compat handling for VDUSE_IOTLB_GET_FD/VDUSE_VQ_GET_INFO Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0636/2077] vdpa/octeon_ep: Fix PF->VF mailbox data address calculation Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0637/2077] vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0638/2077] iomap: pass the correct len to fserror_report_io in __iomap_write_begin Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0639/2077] ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0640/2077] ASoC: cs35l56: Prevent double-free of debugfs Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0641/2077] ASoC: cs35l56: Cleanup if component_probe fails Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0642/2077] ASoC: cs35l56: Dont leave parent IRQ disabled if system_suspend fails Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0643/2077] hwmon: (gpd-fan): drop global driver data and use per-device allocation Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0644/2077] hwmon: (gpd-fan): Initialize EC before registering hwmon device Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0645/2077] hwmon: (gpd-fan): fix race condition between device removal and sysfs access Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0646/2077] ext4: fix ERR_PTR(0) in ext4_mkdir() Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0647/2077] tools: missed broadcast_neigh if_link uapi header Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0648/2077] netlink: specs: rt-link: missed broadcast-neigh Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0649/2077] bonding: 3ad: add lacp_strict configuration knob Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0650/2077] bonding: 3ad: fix carrier when no usable slaves Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0651/2077] bonding: 3ad: fix mux port state on oper down Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0652/2077] ext4: fix kernel BUG in ext4_write_inline_data_end Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0653/2077] ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0654/2077] selftests/bpf: Fix bpf_iter/task_vma test Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0655/2077] cxl/test: Verify cmd->size_in before accessing payload Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0656/2077] cxl/test: Fix integer overflow in mock LSA bounds checks Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0657/2077] cxl/test: Zero out LSA backing memory to avoid leaking to user Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0658/2077] of: cpu: add check in __of_find_n_match_cpu_property() Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0659/2077] vfio/qat: fix f_pos race in qat_vf_resume_write() Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0660/2077] bpf: Tighten cgroup storage cookie checks for prog arrays Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0661/2077] m68k: mcf5441x: fix clocks numbering Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0662/2077] pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0663/2077] pinctrl: airoha: an7581: add missed gpio32 pin group Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0664/2077] pinctrl: airoha: an7583: " Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0665/2077] pinctrl: airoha: an7581: fix misprint in gpio19 pinconf Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0666/2077] pinctrl: airoha: an7583: " Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0667/2077] pinctrl: airoha: an7581: fix incorrect led mapping in phy4_led1 pin function Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0668/2077] pinctrl: airoha: an7583: " Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0669/2077] pinctrl: airoha: fix pwm pin function for an7581 and an7583 Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0670/2077] pinctrl: airoha: an7583: fix gpio21 pin group Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0671/2077] pinctrl: airoha: an7583: add missed gpio22 " Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0672/2077] pinctrl: airoha: an7583: fix phy1_led1 pin function Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0673/2077] pinctrl: airoha: an7583: remove undefined groups from pcm_spi " Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0674/2077] arm64: dts: allwinner: a523: Add missing GPIO interrupt Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0675/2077] ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0676/2077] s390/process: Fix kernel thread function pointer type Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0677/2077] Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0678/2077] Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() " Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0679/2077] Bluetooth: eir: Fix stack OOB write when prepending the Flags AD Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0680/2077] Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0681/2077] Bluetooth: hci_core: Fix UAF in hci_unregister_dev() Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0682/2077] Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0683/2077] Bluetooth: btintel_pcie: Load IOSF debug regs by controller variant Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0684/2077] Bluetooth: hci: validate codec capability element length Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0685/2077] Bluetooth: vhci: validate devcoredump state before side effects Greg Kroah-Hartman
2026-07-21 15:05 ` [PATCH 7.1 0686/2077] RDMA/mlx5: Fix mkey creation error flow rollback Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0687/2077] RDMA/mlx5: Fix TPH extraction in FRMR pool key Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0688/2077] RDMA/core: Fix skipped usage for driver built FRMR key Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0689/2077] RDMA/core: Fix FRMR aging push to queue error flow Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0690/2077] RDMA/core: Fix FRMR set pinned push error path Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0691/2077] RDMA/core: Avoid NULL dereference on FRMR bad usage Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0692/2077] RDMA/core: Fix FRMR handle leak on push failure Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0693/2077] RDMA/core: Add ib_frmr_pool_drop for unrecoverable handles Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0694/2077] RDMA/mlx5: Drop FRMR pool handle on UMR revoke failure Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0695/2077] fs: efs: remove unneeded debug prints Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0696/2077] RDMA/mlx5: Remove DCT restrack tracking Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0697/2077] RDMA/mlx5: Remove raw RSS QP " Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0698/2077] RDMA/mlx5: Fix undefined shift of user RQ WQE size Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0699/2077] RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0700/2077] ASoC: cs35l56: Fix wrong error test on simple_write_to_buffer() Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0701/2077] ASoC: SOF: Intel: select SND_SOC_SDW_UTILS=y from SND_SOC_SOF_HDA_GENERIC=y Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0702/2077] ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0703/2077] ASoC: codecs: hdac_hdmi: Validate written enum value Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0704/2077] ASoC: meson: aiu: Validate written enum values Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0705/2077] ASoC: fsl: fsl_audmix: " Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0706/2077] ASoC: tegra: tegra210_ahub: Validate written enum value Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0707/2077] ASoC: topology: Check PCM and DAI name strings before use Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0708/2077] net: dsa: qca8k: fix led devicename when using external mdio bus Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0709/2077] net/sched: cls_flow: Dont expose folded kernel pointers Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0710/2077] ipv4: fib: Dont dump dying fib_info in fib_leaf_notify() Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0711/2077] net: fib_rules: Dont dump dying fib_rule in fib_rules_dump() Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0712/2077] bridge: cfm: reject invalid CCM interval at configuration time Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0713/2077] sctp: validate embedded address parameter length Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0714/2077] net: pfcp: allocate per-cpu tstats for PFCP netdevs Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0715/2077] net: Stop leased rxq before uninstalling its memory provider Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0716/2077] net/sched: sch_hfsc: Dont make class passive twice Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0717/2077] tipc: require net admin for TIPCv2 netlink mutators Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0718/2077] tipc: prevent snt_unacked underflow on CONN_ACK Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0719/2077] tipc: reject inverted service ranges from peer bindings Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0720/2077] cxl/test: Unregister cxl_acpi in cxl_test_init() error path Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0721/2077] cxl/test: Add check after kzalloc() memory in alloc_mock_res() Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0722/2077] crypto: marvell/octeontx - fix DMA cleanup using wrong loop index Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0723/2077] crypto: cavium/cpt " Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0724/2077] crypto: rng - Free default RNG on module exit Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0725/2077] ALSA: usb-audio: qcom: Guard sideband endpoint removal Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0726/2077] ALSA: seq: Fix kernel heap address leak in bounce_error_event() Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0727/2077] iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0728/2077] iommufd: Clarify IOAS_MAP_FILE dma-buf support Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0729/2077] spi: xilinx: use FIFO occupancy register to determine buffer size Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0730/2077] iommu: Avoid copying the user array twice in the full-array copy helper Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0731/2077] ASoC: sdw_utils: fix missing component_name for cs42l43 part_id 0x2A3B Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0732/2077] cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach() Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0733/2077] cxl/region: Fill first free targets[] slot during auto-discovery Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0734/2077] vfio: selftests: Ensure libvfio output dirs are always created Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0735/2077] ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0736/2077] cxl/region: Block region delete during region creation Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0737/2077] cxl/region: Resolve region deletion races Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0738/2077] cxl/memdev: Pin parents for entire memdev lifetime Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0739/2077] power: supply: core: fix supplied_from allocations Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0740/2077] handshake: Require admin permission for DONE command Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0741/2077] bnxt: fix head underflow on XDP head-grow Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0742/2077] tcp: clear sock_ops cb flags before force-closing a child socket Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0743/2077] virtio_net: do not allow tunnel csum offload for non GSO packets Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0744/2077] net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0745/2077] net/sched: sch_codel: " Greg Kroah-Hartman
2026-07-21 15:06 ` [PATCH 7.1 0746/2077] net/sched: sch_dualpi2: " Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0747/2077] net: mana: initialize gdma queue id to INVALID_QUEUE_ID Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0748/2077] net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0749/2077] net: watchdog: fix refcount tracking races Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0750/2077] net: ethernet: mtk_wed: fix loading WO firmware for MT7986 Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0751/2077] net/sched: sch_dualpi2: Add missing module alias Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0752/2077] bpf: Run generic devmap egress prog on private skb Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0753/2077] net/mlx5: Check max_macs devlink param value against max capability Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0754/2077] bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0755/2077] octeontx2-af: npc: Fix size of entry2cntr_map Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0756/2077] net: airoha: Fix error handling in airoha_ppe_flush_sram_entries() Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0757/2077] net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show() Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0758/2077] net: wwan: t7xx: check skb_clone in control TX Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0759/2077] dpll: fix stale iteration in dpll_pin_on_pin_unregister() Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0760/2077] dpll: send delete notification before unregister in on-pin rollback Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0761/2077] dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister() Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0762/2077] dpll: guard sync-pair removal on full pin unregister Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0763/2077] dpll: balance create/delete notifications in __dpll_pin_(un)register Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0764/2077] landlock: Fix unmarked concurrent access to socket family Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0765/2077] net: bcmgenet: Use weighted round-robin TX DMA arbitration Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0766/2077] octeontx2-af: fix NPC mailbox codes in mbox.h Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0767/2077] net: airoha: Fix register index for Tx-fwd counter configuration Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0768/2077] net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0769/2077] kcm: use WRITE_ONCE() when changing lower socket callbacks Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0770/2077] ALSA: seq: oss: Serialize readq reset state with q->lock Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0771/2077] ALSA: seq: avoid stale FIFO cells during resize Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0772/2077] netfilter: nf_conncount: callers must hold rcu read lock Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0773/2077] netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0774/2077] geneve: Fix off-by-one comparing with GRO_LEGACY_MAX_SIZE Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0775/2077] ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0776/2077] smb: client: fix conflicting option validation for new mount API Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0777/2077] cifs: remove all cifs files before kill super Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0778/2077] smb/client: always return a value for FS_IOC_GETFLAGS Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0779/2077] btrfs: Drop WQ_PERCPU from ordered_flags in btrfs_init_workqueues() Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0780/2077] bpf: Guard __get_user acesss with access_ok for uprobe_multi data Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0781/2077] selftests/bpf: Fix typo in verify_umulti_link_info Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0782/2077] selftests/bpf: Initialize operation name before use Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0783/2077] bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0784/2077] udf: fix nls leak on udf_fill_super() failure Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0785/2077] bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0786/2077] sockmap: Fix use-after-free in udp_bpf_recvmsg() Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0787/2077] bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0788/2077] MIPS: mm: Fix out-of-bounds write in maar_res_walk() Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0789/2077] powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0790/2077] powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0791/2077] powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0792/2077] KEYS: Use acquire when reading state in keyring search Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0793/2077] tipc: fix UAF in tipc_l2_send_msg() Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0794/2077] tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0795/2077] net: airoha: Fix always-true condition in PPE1 queue reservation loop Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0796/2077] net: ti: icssg-prueth: Fix AF_XDP fill ring alloc and wakeup condition Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0797/2077] net: ti: icssg: Use undirected TX tag for native XDP in HSR offload mode Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0798/2077] net: ti: icssg: Use undirected TX tag for XDP zero copy " Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0799/2077] net: ethernet: oa_tc6: mdiobus->parent initialized with NULL Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0800/2077] net: ethernet: oa_tc6: Remove FCS size in RX frame Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0801/2077] dt-bindings: net: updated interrupt type to be active low, level triggered Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0802/2077] ionic: Fix check in ionic_get_link_ext_stats Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0803/2077] RDMA/bnxt_re: Initialize dpi variable to zero Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0804/2077] RDMA/bnxt_re: Free SRQ toggle page after firmware teardown Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0805/2077] RDMA/bnxt_re: Free CQ " Greg Kroah-Hartman
2026-07-21 15:07 ` [PATCH 7.1 0806/2077] RDMA/bnxt_re: Avoid displaying the kernel pointer Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0807/2077] RDMA/bnxt_re: Refactor bnxt_re_init_user_qp() Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0808/2077] RDMA/bnxt_re: Update msn table size for app allocated QPs Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0809/2077] RDMA/bnxt_re: Enhance dbr usecnt logic in doorbell uapis Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0810/2077] RDMA/bnxt_re: Support doorbells for app allocated QPs Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0811/2077] RDMA/bnxt_re: Enable " Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0812/2077] RDMA/bnxt_re: Add a max slot check for SQ Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0813/2077] RDMA/bnxt_re: Proper rollback if the ioremap fails Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0814/2077] RDMA/bnxt_re: Avoid repeated requests to allocate WC pages Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0815/2077] RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0816/2077] RDMA/bnxt_re: Reject GET_TOGGLE_MEM when toggle page was not allocated Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0817/2077] RDMA/hns: Fix memory leak of bonding resources Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0818/2077] RDMA/irdma: Replace waitqueue and flag with completion Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0819/2077] net: serialize netif_running() check in enqueue_to_backlog() Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0820/2077] ksmbd: fix use-after-free in same_client_has_lease() Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0821/2077] mfd: bd72720: Drop BUCK11 ID Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0822/2077] mfd: rsmu: Fix page register setup Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0823/2077] mfd: cs42l43: Sanity check firmware size Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0824/2077] ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0825/2077] 9p: avoid returning ERR_PTR(0) from mkdir operations Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0826/2077] net/9p: fix race condition on rdma->state in trans_rdma.c Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0827/2077] 9p: Add missing read barrier in virtio zero-copy path Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0828/2077] eventpoll: expand top-of-file overview / locking doc Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0829/2077] eventpoll: rename epi->next and txlist for clarity Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0830/2077] eventpoll: Fix epoll_wait() report false negative Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0831/2077] gpiolib: acpi: Only trigger ActiveBoth interrupts on boot Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0832/2077] i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845 Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0833/2077] staging: rtl8723bs: fix stainfo check in rtw_aes_decrypt Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0834/2077] staging: nvec: fix use-after-free in nvec_rx_completed() Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0835/2077] perf dwarf-aux: Fix libdw segmentation fault in cu_walk_functions_at Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0836/2077] perf dwarf-aux: Fix libdw API contract violations Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0837/2077] perf libdw: Fix libdw API contract violations and memory leaks Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0838/2077] perf probe-finder: Fix libdw API contract violations Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0839/2077] perf annotate-data: " Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0840/2077] perf debuginfo: " Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0841/2077] perf callchain: Handle multiple address spaces Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0842/2077] coresight: cti: Fix DT filter signals silently ignored Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0843/2077] soundwire: dont program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0844/2077] soundwire: fix bug in sdw_add_element_group_count found by syzkaller Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0845/2077] coresight: tmc: Fix overflow when calculating is bigger than 2GiB Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0846/2077] coresight: ete: Always save state on power down Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0847/2077] coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0848/2077] PCI/ASPM: Dont reconfigure ASPM entering low-power state Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0849/2077] PCI: Introduce named defines for PCI ROM Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0850/2077] PCI: Check ROM header and data structure addr before accessing Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0851/2077] x86/platform/olpc: xo15: Drop wakeup source on driver removal Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0852/2077] platform/x86: xo15-ebook: Fix wakeup source and GPE handling Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0853/2077] perf sched: Add missing mmap2 handler in timehist Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0854/2077] perf tool: Fix missing schedstat delegates and dont_split_sample_group in delegate_tool Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0855/2077] PCI: intel-gw: Move interrupt enable to own function Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0856/2077] PCI: intel-gw: Enable clock before PHY init Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0857/2077] PCI: intel-gw: Add .start_link() callback Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0858/2077] PCI: loongson: Do not ignore downstream devices on external bridges Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0859/2077] rust: alloc: fix assert in `Vec::reserve` doc test Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0860/2077] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0861/2077] bus: mhi: ep: Add missing state_lock protection for mhi_state access Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0862/2077] coresight: fix missing error code when trace ID is invalid Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0863/2077] clk: qcom: cmnpll: Account for reference clock divider Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0864/2077] dt-bindings: clock: qcom,sm6125-dispcc: reference qcom,gcc.yaml Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0865/2077] PCI: dwc: Apply ECRC workaround for DesignWare cores prior to 5.10a Greg Kroah-Hartman
2026-07-21 15:08 ` [PATCH 7.1 0866/2077] PCI: qcom: Set max OPP before DBI access during resume Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0867/2077] phy: phy-can-transceiver: Check driver match and driver data against NULL Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0868/2077] perf pmu-events AMD: Switch l2_itlb_misses to bp_l1_tlb_miss_l2_tlb_miss.all Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0869/2077] perf unwind: Refactor get_entries to allow dynamic libdw/libunwind selection Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0870/2077] perf pmu: Skip test on Arm64 when #slots is zero Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0871/2077] clk: at91: sam9x7: Fix gmac_gclk clock definition Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0872/2077] iio: light: acpi-als: Check ACPI_COMPANION() against NULL Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0873/2077] soundwire: intel_ace2x: release bpt_stream when close it Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0874/2077] coresight: Fix source not disabled on idr_alloc_u32 failure Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0875/2077] coresight: Handle helper enable failure properly Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0876/2077] PCI: mediatek-gen3: Do full device power down on removal Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0877/2077] mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr() Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0878/2077] mailbox: mtk-adsp: fix UAF during device teardown Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0879/2077] mailbox: dont free the channel if the startup callback failed Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0880/2077] PCI/pwrctrl: Lock device when calling device_is_bound() Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0881/2077] coresight: platform: defer connection counter increment until alloc succeeds Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0882/2077] PCI: dwc: Fix signedness bug in fault injection test code Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0883/2077] PCI: mediatek-gen3: Fix incorrectly skipped pwrctrl error message Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0884/2077] platform/x86: classmate-laptop: Address memory leaks on driver removal Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0885/2077] clk: microchip: mpfs-ccc: fix peripheral driver registration failures after oob fix Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0886/2077] perf build-id: Fix off-by-one bug when printing kernel/module build-id Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0887/2077] perf event: Fix size of synthesized sample with branch stacks Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0888/2077] perf inject: Fix itrace branch stack synthesis Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0889/2077] staging: most: video: avoid double free on video register failure Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0890/2077] usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0891/2077] usb: host: max3421: Reject hub port requests for non-existent ports Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0892/2077] perf test amd ibs: Fix incorrect kernel version check Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0893/2077] gpib: Fix inappropriate ioctl error return Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0894/2077] char: tlclk: fix use-after-free in tlclk_cleanup() Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0895/2077] hpet: Check ACPI_COMPANION() against NULL at probe time Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0896/2077] sonypi: " Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0897/2077] gpib: fix double decrement of descriptor_busy in command_ioctl() Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0898/2077] gpib: cb7210: Fix region leak when request_irq fails Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0899/2077] clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0900/2077] docs: threat-model: add missing closing parenthesis Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0901/2077] powerpc tools perf: Initialize error code in auxtrace_record_init function Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0902/2077] PCI: qcom: Disable ASPM L0s for SA8775P Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0903/2077] timers/migration: Update stale @online doc to @available Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0904/2077] perf header: Sanity check HEADER_EVENT_DESC attr.size before swap Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0905/2077] perf header: Validate bitmap size before allocating in do_read_bitmap() Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0906/2077] iio: light: si1133: reset counter to prevent race condition Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0907/2077] iio: light: si1133: prevent race condition on timeout Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0908/2077] iio: magnetometer: ak8975: fix potential kernel stack memory leak Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0909/2077] iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0910/2077] iio: accel: mma8452: handle I2C read error(s) in mma8452_read() Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0911/2077] iio: tcs3472: power down chip on probe failure Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0912/2077] clk: at91: keep securam node alive while mapping it Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0913/2077] HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0914/2077] docs: changes.rst: restore pahole 1.26 minimum (regressed by sort) Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0915/2077] clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0916/2077] clk: spacemit: k3: Fix PCIe clock register offset Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0917/2077] fs/ntfs3: add bounds check to run_get_highest_vcn() Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0918/2077] fs/ntfs3: fix wrong LCN in run_remove_range() when splitting a run Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0919/2077] fs/ntfs3: call _ntfs_bad_inode() when failing to rename Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0920/2077] ntfs3: Allocate iomap inline_data using alloc_page Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0921/2077] ntfs3: avoid another -Wmaybe-uninitialized warning Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0922/2077] fs/ntfs3: fix mount failure on 64K page-size kernels Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0923/2077] drm/amd/display: Add missing kdoc for ALLM parameters Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0924/2077] thunderbolt: debugfs: Fix margining error counter buffer leak Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0925/2077] dmaengine: imx-sdma: Refine spba bus searching in probe Greg Kroah-Hartman
2026-07-21 15:09 ` [PATCH 7.1 0926/2077] dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0927/2077] perf: Fix off-by-one stack buffer overflow in kallsyms__parse() Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0928/2077] perf annotate: Fix crashes on empty annotate windows Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0929/2077] perf tools: Guard test_bit from out-of-bounds sample CPU Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0930/2077] perf sched: Fix thread reference leak in latency_switch_event Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0931/2077] perf sched: Replace BUG_ON on invalid CPU with graceful skip Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0932/2077] perf sched: Fix NULL dereference in latency_runtime_event Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0933/2077] perf sched: Fix comp_cpus heap overflow with cross-machine recordings Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0934/2077] perf tools: Guard remaining test_bit calls from OOB sample CPU Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0935/2077] perf tools: Add bounds check to cpu__get_node() Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0936/2077] perf sched: Fix thread reference leaks in timehist_get_thread() Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0937/2077] perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0938/2077] perf sched: Fix register_pid() overflow, strcpy, and BUG_ON Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0939/2077] perf mmap: Guard cpu__get_node() return in aio_bind() Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0940/2077] perf stat: Bounds-check CPU index in topology aggregation callbacks Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0941/2077] perf c2c: Bounds-check CPU and node IDs before bitmap and array access Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0942/2077] perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0943/2077] perf sched: Clean up idle_threads entry on init failure Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0944/2077] perf sched: Use is_idle_sample() for idle thread runtime cast guard Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0945/2077] perf sched: Fix thread reference leak in idle hist processing Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0946/2077] perf sched: Use thread__put() in free_idle_threads() Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0947/2077] perf sched: Replace BUG_ON and add NULL checks in replay event helpers Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0948/2077] perf mmap: Fix NULL deref in aio cleanup on alloc failure Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0949/2077] perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0950/2077] perf c2c: Fix use-after-free in he__get_c2c_hists() error path Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0951/2077] perf timechart: Fix cpu2y() OOB read on untrusted CPU index Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0952/2077] perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num() Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0953/2077] perf sched: Free callchain nodes in idle thread cleanup Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0954/2077] dt-bindings: clock: qcom: Add X1P42100 camera clock controller Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0955/2077] clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0956/2077] docs: memfd_preservation: fix rendering of ABI documentation Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0957/2077] mshv: add bounds check on vp_index in mshv_intercept_isr() Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0958/2077] dmaengine: qcom: gpi: set DMA_PRIVATE capability Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0959/2077] dmaengine: Fix possible use after free Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0960/2077] dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0961/2077] dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0962/2077] clk: qcom: a53: Corrected frequency multiplier for 1152MHz Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0963/2077] sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store() Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0964/2077] pNFS/filelayout: fix cheking if a layout is striped Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0965/2077] xprtrdma: Use sendctx DMA state for Send signaling Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0966/2077] xprtrdma: Decouple req recycling from RPC completion Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0967/2077] NFSv4/pnfs: defer return_range callbacks until after inode unlock Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0968/2077] nfs: keep PG_UPTODATE clear after read errors in page groups Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0969/2077] NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0970/2077] NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0971/2077] nfs: use nfsi->rwsem to protect traversal of the file lock list Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0972/2077] PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0973/2077] pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0974/2077] PCI: meson: Propagate devm_add_action_or_reset() failure Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0975/2077] PCI: meson: Add missing remove callback Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0976/2077] lockd: Correct kernel-doc status descriptions for NLMv4 GRANTED Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0977/2077] virtio: add missing kernel-doc for map and vmap members Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0978/2077] fs/ntfs3: prevent potential lcn remains uninitialized Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0979/2077] fs/ntfs3: resize log->one_page_buf when adopting on-disk page size Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0980/2077] platform/x86/intel/vsec: Restore BAR fallback for header walk Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0981/2077] perf tools: Fix get_max_num() size_t underflow on empty sysfs file Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0982/2077] perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0983/2077] perf tools: Use perf_env__get_cpu_topology() in machine__resolve() Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0984/2077] perf tools: NULL bitmap pointers after bitmap_free() Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0985/2077] PCI: rcar-host: Remove unused LIST_HEAD(res) Greg Kroah-Hartman
2026-07-21 15:10 ` [PATCH 7.1 0986/2077] perf sched: Bounds-check prio before test_bit() in timehist Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0987/2077] perf sched: Fix idle-hist callchain display using wrong rb_first variant Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0988/2077] perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0989/2077] perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name() Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0990/2077] perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0991/2077] perf tools: Use scnprintf() in build_id__snprintf() and hwmon read_events() Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0992/2077] xprtrdma: Fix ep kref imbalance on ADDR_CHANGE Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0993/2077] xprtrdma: Initialize re_id before removal registration Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0994/2077] xprtrdma: Check frwr_wp_create() during connect Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0995/2077] xprtrdma: Document and assert reply-handler invariants Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0996/2077] xprtrdma: Resize reply buffers before reposting receives Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0997/2077] xprtrdma: Fix bcall rep leak and unbounded peek Greg Kroah-Hartman
2026-07-21 15:11 ` [PATCH 7.1 0998/2077] xprtrdma: Sanitize the reply credit grant after parsing Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.